AI & Machine Learning
Emerging AI governance, model risk, and algorithmic accountability
AI and machine learning systems face emerging governance requirements around algorithmic accountability, bias prevention, and model risk management. Thalorin helps AI companies navigate the evolving regulatory landscape while implementing robust controls for AI system development and deployment.
Two things happened to the EU AI Act within a fortnight. On 27 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force and moved the high-risk obligations for stand-alone Annex III systems to 2 December 2027 and for AI embedded as a safety component in products covered by Annex I legislation to 2 August 2028. On 2 August 2026 the Commission's power to fine providers of general-purpose AI models under Article 101 became exercisable, at up to 3% of worldwide annual turnover or EUR 15 million, whichever is higher.
The United States is moving in the other direction and not in a single line. California's Transparency in Frontier Artificial Intelligence Act took effect on 1 January 2026: a large frontier developer must publish a frontier AI framework, and any frontier developer must report a critical safety incident to the Office of Emergency Services within fifteen days. Colorado repealed its own AI Act on 14 May 2026 before it applied. Executive Order 14365 of 11 December 2025 put an AI Litigation Task Force in the Justice Department to challenge state AI laws.
Classification is the part consistently underestimated, because it is settled by facts about the product rather than by the governance function. Article 25 makes a third party the provider of a high-risk system by putting its name on one, substantially modifying one, or changing a system's intended purpose so that it becomes high-risk — decisions taken in a release, not in a review. The training-content summary under Article 53(1)(d) has the same shape: it is answerable only from records kept while the model was trained.
A deferral is only useful if the artifacts age with the system that produced them. The model, its dataset lineage, its evaluation runs and its declared intended purpose are held in Thalorin as one dated object, so when Annex III arrives in December 2027, or a state statute is repealed and replaced beneath it, the classification is re-projected against evidence that already exists rather than reconstructed from a codebase and a storage bucket two years further on.
Technology companies must prove their security
A deferral is not a repeal
Regulation (EU) 2026/1744 moved Annex III obligations to 2 December 2027. The records they demand — data governance, logging, evaluation results — are produced during development, so the extra time only helps teams already capturing them.
Article 50 binds systems that are not high-risk
Transparency duties apply from 2 August 2026, and only systems already on the market by then get until 2 December 2026 for machine-readable marking. Teams that concluded they sat outside the high-risk annex often concluded they sat outside the Act entirely.
Training-content summaries are written backwards
Article 53(1)(d) requires a sufficiently detailed public summary on the AI Office template, covering licensed corpora, scraped domains, user data and synthetic data. Reconstructing that after training is a forensic exercise against storage rather than a documentation task.
State law is contested, not settled
Colorado repealed and reenacted its AI Act before it applied, California's frontier statute is live, and Executive Order 14365 has a Justice Department task force challenging state AI laws. Building an assessment to one state's text is a bet on litigation.
How Thalorin helps
AI governance framework implementation
Run ISO/IEC 42001 clauses and the NIST AI Risk Management Framework functions against one control set, so an AI management system audit and a customer questionnaire built on the RMF read the same record.
Model risk documentation
Version technical documentation against the model release it describes, so an Annex IV file names the weights, the evaluation run and the intended purpose that were in force at that version.
Algorithmic impact assessment
Scope assessments by the decision the system influences rather than by the model, which is how both the CCPA automated decisionmaking rules and Colorado Senate Bill 26-189 draw the boundary.
Training data compliance
Capture dataset provenance, licence terms and scraped-domain records as the corpus is assembled, in the fields the AI Office training-content template asks for rather than in a later reconstruction.
AI system security controls
Treat model artifacts, training pipelines and inference endpoints as assets carrying their own controls, so access records and evaluation results bind to the version actually deployed.
Regulatory change tracking
Hold applicability per system, so a moved date such as Annex III shifting to 2 December 2027, or a repealed state statute, changes which obligations are live without reopening the underlying assessment.
AI & Machine Learning: common questions
Did the EU AI Act high-risk deadline of 2 August 2026 actually move?
Yes. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Obligations for stand-alone high-risk systems under Annex III now apply from 2 December 2027, and for AI systems that are safety components of products covered by the legislation listed in Annex I, from 2 August 2028. The prohibitions, the general-purpose AI obligations and the Article 50 transparency duties were not deferred.
What applies from 2 August 2026 if our system is not high-risk?
Two things. Article 50 transparency: people must be told when they are interacting with an AI system, and synthetic audio, image, video or text must be marked in a machine-readable format, with a four-month transitional period to 2 December 2026 for systems placed on the market before 2 August 2026. And enforcement: from 2 August 2026 the Commission may fine providers of general-purpose AI models under Article 101, up to 3% of worldwide annual turnover or EUR 15 million, and may require evaluations or restrict a model on the EU market.
Is the Colorado AI Act still in force?
No, and it never applied. Senate Bill 24-205's start date moved from 1 February 2026 to 30 June 2026, and on 14 May 2026 Governor Polis signed Senate Bill 26-189, repealing and reenacting those provisions as a narrower regime for automated decision-making technology used in consequential decisions, with obligations biting from 1 January 2027. The duty of care against algorithmic discrimination, the annual impact assessments and the risk management programme are gone; developer documentation, consumer notice, a plain-language explanation within thirty days of an adverse outcome and a right to meaningful human review remain.
If we fine-tune a third-party model and ship it under our brand, are we the provider?
Very possibly. Article 25 makes a third party the provider of a high-risk AI system where it puts its name or trademark on one already on the market, substantially modifies one that remains high-risk, or modifies the intended purpose of a system — including a general-purpose AI system — so that it becomes high-risk. The original provider then drops out and owes you technical documentation, known limitations and testing access, unless it had clearly specified that its system was not to be changed into a high-risk one.
Does ISO/IEC 42001 certification satisfy the EU AI Act?
No. ISO/IEC 42001, published in December 2023, certifies an AI management system — the governing process by which AI risks are identified, treated and reviewed — and is assessed by an accredited certification body. The AI Act imposes obligations on specific systems and models, has its own route to presumption of conformity through harmonised standards, and is not satisfied by a management system certificate. The two are complementary, since a working management system produces most of the records the Act asks for.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about AI & Machine Learning.
See how one evidence artifact satisfies AI & Machine Learning requirements alongside every other framework you carry.