Discussion about this post

User's avatar
Alireza Rahmani Khalili's avatar

The "bring your own data" trap is the sharpest point here. Most banks think retraining on proprietary data is routine customization. Whether it crosses into substantial modification entirely depends on whether the vendor's conformity assessment explicitly scoped it and most don't.

The cumulative drift question is the one that'll produce the first major enforcement case. Each step is foreseen, the destination isn't. Nobody has an answer for that yet.

I build production AI systems in regulated environments this is exactly the compliance surface I think about. Worth a subscribe here too.

4 more comments...

No posts

Ready for more?