Discussion about this post

User's avatar
ToxSec's avatar

now that i've published enforcement timelines for three separate regulatory deadlines, i fully expect all of them to get delayed by at least six months. you're welcome. consider this article a public service.

John Holman's avatar

Buddy the audit trail gap you described is real…

so we built something about it.

Compliance Labs produces mechanistic interpretability audits of fine-tuned AI models — basically, we open the model, measure every internal feature the fine-tuning created, modified, or eliminated, and produce a signed technical document of what the model actually learned. Layer by layer. Statistically validated. PhD-signed and ready to file.

The thing your readers are going to hit: Article 13 doesn't just want a policy document. It wants technical documentation of what changed between your base model and your deployed version. Most teams have no idea how to produce that. We do.

Our methodology just went into NeurIPS 2026 review. One of our core findings is that output testing alone isn't enough — a model can show major internal reorganization while outputs look totally normal on standard evals. Neither measurement alone is sufficient. (We call it the two-measurement requirement, because naming things is fun.)

If you've got readers staring down August 2 with a fine-tuned model and no documentation — http://compliance-labs.ai. The math against €35M works out pretty fast.

Great breakdown as always. The shadow AI inventory problem is going to age like milk.

34 more comments...

No posts

Ready for more?