The AI Compliance Brief · Issue 04
The AI Compliance Brief — Issue 04
Independent editorial briefing on AI regulation, enforcement, and verification. Published weekly.

Issue 04 | September 2026 | Clause5AFE Systems, Inc.
Independent editorial briefing on AI regulation, enforcement, and verification. Published weekly.
In this issue
• The European Commission is expanding EU capacity for third-party AI model assessment, with new evaluation capability expected to become operational in 2027.
• The EU AI Act already contains specific independence requirements for notified bodies, including restrictions designed to separate conformity assessment from system design, development, use, and certain consultancy relationships.
• Illinois has enacted annual independent third-party compliance audits for qualifying large frontier AI developers beginning in 2028, including requirements addressing auditor competence and financial conflicts.
• Massachusetts lawmakers are considering how independent model evaluation and evaluator qualification could fit into the state’s emerging frontier AI framework.
THE LEAD
The next phase of AI governance is creating a problem regulators cannot solve simply by requiring more audits.
They must determine who is qualified to perform them.
Europe is beginning to confront that question.
As of August 2, 2026, key enforcement provisions of the EU AI Act are now in effect, including the European Commission’s enforcement powers over general-purpose AI models.
The AI Office can request information and technical documentation from providers, obtain access to models for evaluation, require corrective measures, and impose penalties for certain violations.
At the same time, the European Commission is expanding EU capacity for third-party AI model assessment.
The Commission has announced plans to increase Europe’s capacity to evaluate AI models before they are placed on the market. That capability is expected to become operational in 2027 and is intended to strengthen third-party assessment of AI capabilities and risks while supporting the regulatory function of the AI Office.
The development raises a governance question that becomes increasingly important as independent evaluation moves deeper into regulatory architecture:
Who checks the checkers?
Requiring independent evaluation is only the beginning.
Regulators must also determine what independence means, what competence an evaluator must demonstrate, what evidence an evaluator must be permitted to examine, what conflicts are unacceptable, and what methodology makes an assessment credible.
Those questions are no longer theoretical.
Parts of the regulatory architecture are already beginning to answer them.
KEY FACTS
Regulation: EU Artificial Intelligence Act, Regulation (EU) 2024/1689
Current enforcement phase: Key provisions became applicable on August 2, 2026, including Commission enforcement authority over general-purpose AI models.
AI Office authority: The Commission can request information and documentation from general-purpose AI model providers and, under specified circumstances, obtain access to models for evaluation.
Who may conduct evaluations: Evaluations may involve the AI Office and independent experts appointed in support of its supervisory functions.
EU evaluation capacity: The European Commission has announced plans to increase EU capacity for AI model evaluation before models enter the European market.
Expected operational date: 2027.
Purpose: Strengthen third-party assessment of AI capabilities and risks and support the regulatory work of the AI Office.
Existing independence precedent: Article 31 of the AI Act establishes independence requirements for notified bodies performing conformity-assessment functions.
Conflict restrictions: Personnel responsible for conformity-assessment activities must satisfy independence requirements, including restrictions concerning involvement in the design, development, marketing or use of systems they assess and activities that could compromise independent judgment.
Illinois: Large frontier AI developers subject to Illinois’ Artificial Intelligence Safety Measures Act will be required to retain a third party annually for an independent compliance audit beginning January 1, 2028, or 90 days after qualifying, whichever is later.
Illinois auditor requirements: The statutory framework addresses auditor competence and financial conflicts between the auditor and developer.
Massachusetts: State lawmakers are considering frontier AI proposals that could further define independent model evaluation and standards for qualifying third-party evaluators.
WHY IT MATTERS
“Third party” and “independent” are not necessarily interchangeable.
An assessment can be performed by an outside organization and still raise questions about financial relationships, prior consulting work, technical competence, methodology or incentives.
That distinction becomes more important as governments increasingly rely on external evaluation to determine whether AI systems or models satisfy regulatory requirements.
The EU AI Act already recognizes this problem within its conformity-assessment architecture.
Article 31 requires notified bodies to maintain independence and places restrictions around relationships that could compromise impartiality.
That principle has significant implications for AI governance.
If an organization participates in designing the controls, processes or systems that will later be examined, its ability to independently judge those same controls becomes more difficult to establish.
Likewise, an evaluator without sufficient technical access may be independent in organizational terms but incapable of conducting a meaningful assessment.
An evaluator with technical competence but material financial conflicts may create a different credibility problem.
Independent verification therefore depends on more than organizational separation.
It requires a combination of independence, competence, methodology, access and evidence.
As third-party evaluation becomes more prominent, regulators will increasingly have to define all five.
COMPLIANCE IMPLICATIONS
For AI developers: Selecting an outside evaluator may eventually require more diligence than confirming technical expertise. Organizations should expect evaluator independence, conflicts, competence and methodology to receive greater regulatory attention as third-party assessment frameworks mature.
For organizations using external AI governance consultants: Advisory and independent assessment functions may increasingly need to be clearly separated. An organization that helped design or implement controls may face questions about whether it can subsequently provide an independent judgment of those same controls.
For boards and executive leadership: A third-party report should not automatically be treated as equivalent to independent verification. Leadership may need to understand who performed the evaluation, what evidence was examined, which methodology was used, and what relationships existed between evaluator and evaluated organization.
For procurement and enterprise risk teams: Vendor claims of “independent assessment” may require additional scrutiny. The identity, competence and independence of the assessor can become part of the evidence supporting the underlying claim.
For evaluators and certification bodies: Technical capability alone may not be sufficient. Regulatory frameworks increasingly point toward demonstrable independence, documented methodologies, appropriate evidence access, conflict controls and qualified personnel.
RELATED DEVELOPMENTS
Illinois has moved from debate to statutory requirement. The state’s Artificial Intelligence Safety Measures Act requires qualifying large frontier AI developers to undergo annual independent third-party compliance audits beginning in 2028. The law also addresses auditor competence and financial interests, making Illinois an important US example of independent AI auditing moving from governance principle into statutory architecture.
Massachusetts is still determining its model. Unlike Illinois, Massachusetts remains in the legislative process. Current frontier AI proposals have raised questions about independent model evaluations, evaluator qualification and what role state authorities should play in establishing an evaluator ecosystem. The distinction matters: Illinois has enacted its framework, while Massachusetts remains a developing policy model.
Europe already has an independence framework to draw from. Article 31’s notified-body requirements provide an existing regulatory analogue for how evaluator independence can be defined. Although notified bodies and emerging AI model evaluators should not automatically be treated as identical regulatory categories, the conformity-assessment framework demonstrates that independence can be translated into specific institutional and conflict-of-interest requirements.
AI Office evaluation capability is expanding alongside enforcement authority. The Commission’s plans for additional model-evaluation capacity indicate that enforcement will depend not only on obtaining documentation but also on the ability to test and evaluate increasingly capable models.
Evaluator methodology may become the next standards question. Once independent evaluation is required or relied upon, regulators must determine whether different evaluators using different methodologies can produce sufficiently consistent and comparable conclusions.
WATCH LIST
EU evaluator criteria: How the European Commission defines competence, independence and methodology for third-party AI model assessment.
The 2027 evaluation capability: Details of the Commission’s initiative to increase EU model-evaluation capacity, including who will perform assessments and what institutional structure will govern them.
Article 31 as a precedent: Whether the independence and conflict-of-interest principles already applied to notified bodies influence future requirements for other categories of AI evaluators.
Illinois implementation: How “demonstrated competence” and financial independence are interpreted as the state’s 2028 audit requirement approaches.
Massachusetts legislation: Whether final legislation establishes qualification standards, licensing, registration or another mechanism governing independent evaluators.
Evaluator conflicts: Whether regulators begin drawing explicit boundaries between organizations providing AI implementation or remediation services and organizations providing independent evaluation.
THE CLAUSE5AFE PERSPECTIVE
Independent verification only works when independence itself is protected.
An evaluator cannot credibly help design the controls being examined and then independently determine whether those same controls withstand scrutiny.
As AI governance moves toward third-party verification, regulators and markets will increasingly need to examine not only the evidence being evaluated, but the competence, methodology and conflicts of the evaluator itself.
A verification requirement is only as meaningful as the independence of the verifier.
SOURCES
• European Union, Regulation (EU) 2024/1689, Artificial Intelligence Act
• European Commission, AI Act governance and enforcement materials
• European Commission, AI Office enforcement materials for general-purpose AI models
• European Commission, EU AI model evaluation and third-party assessment initiatives
• European Commission, Article 31 requirements governing notified bodies
• Illinois General Assembly, Artificial Intelligence Safety Measures Act
• Massachusetts Legislature, frontier artificial intelligence safety legislation and related proposals
Clause5AFE Systems, Inc. Independent third-party AI certification authority. One standard. All frameworks.
clause5afe.com
The AI Compliance Brief is published weekly. Editorial responsibility rests with Clause5AFE Systems, Inc. This brief is informational and does not constitute legal advice.