Guide

The Article 50 check you can run on your own stack in an afternoon

3 August 2026

Article 50 of the EU AI Act became applicable yesterday. If you run operations at a company between 80 and 250 people, you have probably approved two or three AI tools in the last eighteen months and have not had a reason to look closely at any of them since.

This is that reason. It is smaller than it sounds, and it is worth doing properly once rather than badly three times.

What changed, and what did not

Two deadlines were pointed at 2 August 2026. Only one arrived.

The high-risk obligations moved. The Annex III regime, the one with conformity assessments and technical documentation and the genuinely expensive programme behind it, was deferred to 2 December 2027 under the Digital Omnibus. If someone quoted you a six-figure readiness project for August, that timeline no longer holds.

The transparency obligations did not move. Article 50 applied on schedule. It is the short, cheap, unglamorous part of the Act: tell people when they are dealing with a machine.

The practical consequence is that the work in front of you this quarter is mostly writing a few sentences and putting them in the right places. Not a programme. Do not let it be sold to you as one.

The four questions that decide whether you owe anything

Answer these about your own organisation. Yes to any of them means you have something to do.

  1. Does anything we run talk to people?A support chat widget, an AI assistant in a customer portal, a voice bot on the phone line. Worth knowing who carries this one: Article 50(1) puts the duty to build in the “you are talking to an AI” disclosure on the provider, not on you. Your job is to check that the product you bought actually does it, because you are the one operating a system that has to. If the notice is missing, that is a question for your vendor before it is a task for your team.
  2. Do we publish AI-written text? Marketing copy, help-centre articles, product descriptions, LinkedIn posts from a company page. This one has a carve-out worth knowing: if a person with relevant knowledge genuinely reviewed the substance and someone holds editorial responsibility, no label is needed. Disclosure is the default and human review is the exemption, which is the opposite of what most people assume.
  3. Does anything infer emotion or categorise people biometrically? Sentiment scoring on support calls, engagement analytics on employee surveys, tone analysis in a recruiting tool. The people exposed to it have to be told it is running.
  4. Do we publish synthetic images, audio or video of real people? Rarer in mid-market B2B, but if you have used an AI avatar in a training video, it counts.

The part that catches people: you did not turn it on

Most operations leads answer question one with “no, we do not have a chatbot” and move on. Then it turns out the helpdesk platform shipped an AI assistant in a release note last spring, and it was enabled for everyone by default.

Nobody in your organisation made a decision about most of these. They arrived in a product update, switched on, and the release note went to whoever administers the tool rather than to whoever answers for it.

Three where the vendor’s own documentation says it plainly. Every quotation below has been matched word for word against a dated copy of the page we took it from, so you can check us:

VendorFeatureWhat the vendor documentation says
HubSpotBreeze CopilotBy default, this setting will be toggled on.
HubSpotGenerative AI features (account-wide)By default, this setting is toggled on. This setting must be turned on to use any generative AI features.
GrammarlyAI agents in docsWhen docs is enabled, agents are on by default. Admins can adjust agent access on the Agent access page.
Cornerstone OnDemandCross-Portal Content RecommendationsThe Cross-Portal Content Recommendations setting is enabled by default. To disable this setting, toggle the switch to the Off position.

Each is dated and linked to the source on the heatmap. The wider corpus records a default state for many more features, but often from a page describing what the feature does rather than one stating whether it is on. We are separating those two things, and until that is finished, treat any default state as a question to put to your administrator rather than an answer. Your own tenant settles it either way.

What that looks like across 105 vendors

Ninety seconds, no sound needed.

The afternoon itself

Four steps. One person. No budget approval required.

  1. List what you actually own. Pull the software line items from the last two quarters of spend. Not the IT asset register, the invoices. The register is always out of date and the invoices are not.
  2. For each one, find the AI features and their default state. Check the heatmap first, then confirm in your own admin console. Your tenant is the authority, not our research and not the vendor’s marketing page.
  3. Run the five-question self-check. The transparency check takes about two minutes and tells you which of the four obligations above actually land on you.
  4. Write the notices. Copy-paste starting points for chatbot, AI-content and emotion-recognition notices are on the disclosures page. Have your lawyer read them once. They are short.

If you find something uncomfortable: the usual outcome is a notice, not a project. A support bot missing a disclosure line is fixed in an afternoon. Where it gets more serious is emotion inference on employees or candidates, because that touches GDPR and works-council territory as well. Flag those to counsel and keep the rest in-house.

What this is not

This page is a structured self-check, not legal advice and not a compliance determination. It tells you whether the question deserves your legal team’s time, which for most mid-market companies is the honest answer to a regulation everyone is talking about and few have actually read.

Ravna is free to use and requires no account. Findings are machine-generated and every one carries its sources, a verbatim excerpt from the vendor’s documentation, and the date it was captured, so you can check the work rather than take our word for it.