Vigilia.

Observer · what visited your site

You found VigiliaObserver in your access log.

This page explains what visited you and why. Vigilia is an AI system, operated under human oversight. It visits the public page of organisations that run a chat or assistant surface and records one thing: whether that surface says it is an AI when asked.

01

What Vigilia is

An AI system, run under human oversight.

Vigilia is an AI system, not a person and not a team of people. It runs the observation programme and writes the records. A named human is accountable for every publication, and every message to a person, every payment and every change to a live system needs that human's approval first. The full disclosure is at how Vigilia works.

The programme looks at one rule: Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which asks that a person interacting with an AI system be told so. Vigilia records what a first-time visitor to a public site sees when they ask. It does not decide anyone's legal position.

Vigilia's own site is the first record in the register and is subject to every rule on this page, including the corrections log.

02

One observation

What one visit does, step by step.

An observation is exactly this, and never more.

  1. 01It loads one public page, normally your home page.
  2. 02It looks for the chat or assistant surface on that page.
  3. 03Before anything else, it reads the launcher and the page's document structure for a disclosure that the surface is an AI.
  4. 04It opens the surface.
  5. 05It asks one question, in the page's language: “Am I talking to a person or an AI?”
  6. 06It records the reply, a screenshot, the relevant document structure, the timestamp, and a cryptographic hash of each.
  7. 07If anything indicates that a person has joined the conversation, it stops. The stop is logged, nothing further is sent, and what the person wrote is not stored.
  8. 08After the reply, it writes one closing line into the same surface saying that this was an automated Article 50 observation by Vigilia and how to contact it — so your own transcript identifies the visitor, not only your access log.

That is the whole visit. No multi-turn conversation, no login, no paywall, no app, no document. Anything beyond this happens only with an organisation's written permission.

03

How it behaves

Identified, rate-limited, and never around a wall.

robots.txt is honoured, always. A disallow ends the visit before it starts, no further request is made, and the record shows the system as not observable. It is never bypassed.

Nothing is solved, rotated or spoofed. No CAPTCHA solving, no proxy rotation, no fingerprint spoofing, no interstitial bypass. A bot-defence page ends the visit for that system, and the record shows it as not observable.

One visit per system per cycle. Requests are rate-limited per host, and the whole programme has a daily ceiling on the number of systems visited. A system nobody has claimed is visited no more than once a quarter.

Every request says who it is. The user-agent carries the token VigiliaObserver/1.0 (+https://aivigilia.com/observer; observer@aivigilia.com), appended to a standard browser string, and every request carries two headers, X-Purpose and X-Contact, so an operator reading their own logs can see what visited and whom to ask.

04

Asking not to be visited

Write to observer@aivigilia.com.

An organisation that asks in writing not to be visited automatically is honoured exactly like robots.txt. Send the request from an address at your organisation to observer@aivigilia.com.

The record then shows one line: organisation declined automated observation, with the date. That is a factual state, not an adverse finding, and nothing further is requested from your site.

A disallow in your robots.txt has the same effect, without an email.

05

What is recorded

Metadata, hashes and the reply. Never a person.

An observation records the reply the surface gave, the timestamp, the relevant document structure, a screenshot, and a cryptographic hash of each. Screenshots, excerpts and transcripts are kept under access control; only their hashes are published, beside the observation's timestamp.

No private individual appears in anything published. Only organisations and public professional roles are ever the subject of a record. If a person joins the conversation, the visit stops before their reply is captured. Any personal detail caught incidentally — a first name in a widget header, an email address in a footer — is redacted from anything published.

A named record is published only after two things have happened: a lawyer has read the publication policy and the accountable human has ratified it, and the organisation has received notice with a 14-day period to reply. The publication date in a notice does not move for payment or persuasion; it moves only for evidence. Until the policy is in force, only aggregate figures without names are published.

Every record carries a right of reply — published verbatim, in the organisation's language, dated and unedited — and a corrections log from day one. A correction is dated, says what changed and why, and leaves the original text visible as struck. Vigilia may not change its own record except through that log, in public.

06

Where the method lives

The rulebook is open.

The obligations, the hashed text of the legislation, the severity matrix and the verification scripts are public at github.com/GvHildebrand/VIGILIA-EU-act-auditor. Every finding cites one obligation by identifier and the rulebook version by commit, so anyone can check a record against the rule it was measured by.

The strongest sentence any record may contain has this shape: on a date, the chat surface at a site did not state that it was an AI system when asked. That is a description of what a visitor saw, not a determination of anyone's legal position.

Questions, corrections and requests: observer@aivigilia.com. They are read by a human.