Why we never say "compliant"
DisclosureProof will never tell you that your site is compliant with the EU AI Act. Not on the free scan, not in a paid Evidence Pack, not if you ask us to. This is not caution for its own sake, and it is not a disclaimer bolted onto the bottom of a report. It is a rule the product is built around, and it changes what the findings are worth.
The short version: compliance is a legal conclusion about your organisation, and a scanner is a witness to facts about your website. Those are different things. A tool that blurs them produces a document that falls apart the moment anyone with authority reads it closely.
What a scanner can actually see
We load your site in a real browser, the way a first-time visitor would. We accept the cookie wall if one is in the way, click the chat widget open, read the first message it shows before anyone types anything, and (on sites you have proven you own) ask it directly whether you are chatting with a person or an AI, then read its answer. Whether it admits to being AI when asked is recorded as its own fact, separate from whether it discloses at the first interaction: Article 50(1) requires the second one, so an assistant that owns up only when questioned has still not met it. We sample your published images for machine-readable provenance marking. We look for visible AI-content labels on article-like pages, and for a policy page describing how you use AI.
Every one of those is an observation with a timestamp and a screenshot behind it. None of them is a legal conclusion. Consider what stands between the two:
- Scope. Whether Article 50 applies to you at all depends on what your system does, who operates it, and where your users are. A page fetch cannot establish any of that.
- Role. The Act divides duties between the provider that builds an AI system and the deployer that puts it in front of people. Which one you are is a question about contracts, not about markup.
- Exemptions. Article 50(4) has a carve-out for AI-generated text under human editorial review with a named responsible person. Whether you qualify depends on an editorial process no crawler can inspect.
- What we did not look at. A free scan reads one page. Even a full crawl reads the pages it could reach, at one moment, from one country, as one kind of visitor.
A tool that answers "compliant: yes" has silently guessed at all four. We would rather hand you something narrower and true.
The five things a finding can say
Every check resolves to one of these, and each one is a statement about evidence, not about law.
| State | What it means | What it does not mean |
|---|---|---|
| Pass | We looked for the thing the duty is about, and observed it. For example: an AI disclosure appeared in the chat widget's first message. | That you are compliant. It means this specific check found this specific thing on the day we looked. |
| Fail | Something the site itself asserts is contradicted by what a visitor sees. The bar is deliberately high: the assistant replied automatically and disclosed nothing, or a page's own markup declares its content machine-generated while showing the reader no label. | That you have broken the law. It means your own site is saying two different things, and a regulator would see the same contradiction we did. |
| Attention | We observed something worth a human look, but the evidence does not settle it. Most real findings live here. | A violation, or an accusation. It is a pointer to a page and a reason. |
| Unverified | We could not complete the check. The widget would not open, the panel was unreadable, the page timed out. | That anything is wrong. An honest "we could not see this" is more useful than a guess, and it is why this state exists at all. |
| Not assessed | The duty does not engage on what we saw. No chat widget means no Article 50(1) finding. | That the duty never applies to you. It means it did not apply to what was on this page. |
There is a sixth state, Attested, for the duties nobody outside your organisation can observe. You answer a fixed questionnaire, we seal your answers alongside what the scan saw, and the report labels it self-attested everywhere it appears. Your statement carries your name, not ours.
Confidence is part of the finding, not a footnote
Detection is not binary. Recognising a chat widget by its vendor's script host is strong evidence. Recognising it because a CSS class name looked familiar is weak evidence, and a report that presents both the same way is misleading. So the confidence level travels with the finding, in the sentence you read, not buried in a data field.
The same discipline applies to the seal on your evidence. Anyone holding an Evidence Pack can recompute the SHA-256 hashes themselves and prove the files are unaltered; that check needs nothing from us. Whether we sealed it is a shared-secret signature only we can confirm, so the verification page reports those two answers separately and says which one relies on trusting us. We would rather say that out loud than imply more.
What we deliberately refuse to measure
We do not detect AI-written text
- No statistical "this reads like AI" scoring, and no likelihood percentage.
- Those classifiers are not reliable enough to seal into evidence, and they misfire on non-native English writing in particular.
- A false positive would be an accusation carrying our signature.
- Article 50(4) still reaches a finding, through a route that cannot misfire: your own machine-readable declaration, or your own attestation.
We do report what the site emits
- IPTC
digitalSourceType, C2PA manifests, schema.org software authorship. - A generator tag naming a machine writer.
- Visible labels, in the six languages we grade in.
- All publisher-emitted: facts your site published about itself, quoted back with a hash.
Why this is worth more to you, not less
A vendor that stamps "COMPLIANT" on a dashboard has given you a document you cannot forward. Counsel will not stand behind a conclusion drawn by a crawler, and a supervisory authority has no reason to accept one. When the question is asked seriously (was the disclosure visible to a first-time visitor on mobile, on this date?) what has to survive scrutiny is the evidence, not the adjective.
What we produce is a dated, hashed record of what your site showed a visitor, with each observation tied to the specific duty it bears on, and with the limits of the observation stated in the same sentence. That is the artefact a lawyer can attach to a file. The compliance conclusion is theirs to draw, and it should be.
Where this is written down
This is not a stance we can quietly drop. It is enforced in the rule-pack that grades every scan: the wording of each finding lives in a versioned file, every report prints the pack version it was graded under, and the changelog records each change to that wording with its date. If we ever softened this, the diff would be public and dated.
You can see the whole thing on a real scan without giving us anything: the diagnosis is free and always will be. Read a sample report first if you would rather see the shape of it before pointing it at your own site.