Inspiration
AI features are increasingly embedded into software products through chatbots, assistants, summarization tools, recommendation systems, and other user-facing experiences.
The technical integration may work perfectly, but teams can still forget something important: clearly informing users that they are interacting with AI.
I wanted to build an agent that could detect this automatically before release instead of relying on a manual checklist.
That became Article 50 AutoDisclosure.
What it does
Article 50 AutoDisclosure analyzes a software repository and looks for direct user-facing AI interactions.
Instead of only checking whether an AI SDK exists, it reconstructs the actual application flow:
Frontend → API → Backend → AI provider
It then checks whether the relevant user interface contains a clear AI transparency disclosure.
If the disclosure is missing, the system:
- Creates an evidence-backed Article 50 readiness finding
- Identifies the affected source files
- Generates a minimal remediation patch
- Shows the exact code diff to the developer
- Requires explicit human approval
- Applies the approved patch
- Re-scans the affected interaction
- Verifies whether the disclosure is now present
The result can move automatically from:
ACTION REQUIRED → PASS
The project is intended as an Article 50 readiness tool for developers, not as legal advice or legal certification.
How I built it
The application uses:
- Strands Agents SDK for agent orchestration and repository reasoning
- Amazon Bedrock for foundation model inference
- Claude Sonnet 4.6 through Amazon Bedrock
- FastAPI + Python for the backend
- React + TypeScript for the frontend
- Git-based repository workspaces for repository analysis and remediation
- Deterministic safety controls for patch validation, application, rollback, and verification
The agent combines model reasoning with deterministic tools.
The AI helps understand repository structure, reconstruct AI interaction flows, analyze transparency context, and generate remediation proposals.
However, critical code-changing operations are not left entirely to the model.
Before a patch can be applied:
- paths are validated
- patch size is limited
- only expected files may be modified
- repository code is never executed
- a snapshot is created
- explicit human approval is required
After the change, the system performs a targeted static re-analysis to verify the remediation.
Human-in-the-loop design
One of the main design decisions was that the agent should not silently modify source code.
The workflow is:
Detect → Explain → Propose → Human Approves → Apply → Verify
This makes the agent autonomous for repetitive analysis while keeping developers in control of important code changes.
Challenges I faced
One major challenge was going beyond simple dependency detection.
Finding an AI package is easy, but understanding whether that AI functionality is actually exposed directly to a user requires connecting evidence across multiple layers of an application.
Another challenge was remediation safety.
Generating code is straightforward, but safely modifying an unknown repository requires much stronger controls. I therefore separated agent reasoning from deterministic patch validation and application logic.
I also faced an AWS account-level Amazon Bedrock access issue during the hackathon. IAM permissions and model entitlement were correct, but Bedrock Runtime inference was temporarily restricted at the account level. After working with AWS Support, live Bedrock inference was restored and the application was validated using the real Strands → Amazon Bedrock path.
What I learned
The biggest lesson was that useful software agents need more than good model output.
The strongest architecture combines:
Agent reasoning + deterministic tools + human approval + verification
I also learned that verification is just as important as generation. An agent should not only propose a change; it should prove that the change actually solved the problem.
Finally, I gained a much better understanding of the Strands Agents SDK, Amazon Bedrock model access, structured agent tooling, safe repository automation, and human-in-the-loop software engineering workflows.
What's next
Future improvements could include:
- GitHub pull request integration
- Private repository support
- CI/CD release gates
- Additional Article 50 transparency scenarios
- Detection of AI-generated content labeling requirements
- Support for more programming languages and frameworks
- Amazon Bedrock AgentCore deployment
- Team-level audit history and reporting
The goal is to eventually make AI transparency checks part of the normal software delivery lifecycle.
Built With
- ai
- ai-agents
- amazon-bedrock
- claude-sonnet-4.6
- eu
- fastapi
- human-in-the-loop
- python
- react
- strands-agents-sdk
- typescript
Log in or sign up for Devpost to join the conversation.