Collibra Acquired Munich Startup Trail ML

The acquisition adds automated compliance capabilities for the EU AI Act to Collibra's enterprise data governance platform.

Updated on Oct. 5, 2026 in Artificial Intelligence

Bold flat-color editorial illustration of stacked brass and steel blocks, representing automated data governance structures for AI compliance policy.
Collibra has acquired Munich-based startup Trail ML to integrate automated AI compliance tools into its existing data governance platform for the EU AI Act. AI Illustration. Upload story photo >

Live Poll

Do you believe companies are currently equipped to handle the growing complexity of AI regulatory compliance?

Collibra has acquired Munich-based startup trail ML to integrate automated compliance tools into its existing data governance stack. The acquisition aims to help organizations navigate the EU AI Act, which granted enforcement powers to the European Commission as of August 2, 2026.

Why it matters

The move provides automated verification for regulatory frameworks like ISO 42001, NIST, and the EU AI Act, which can now impose fines of up to EUR 15 million or 3 percent of global turnover. It follows a tightening regulatory environment that includes high-profile security incidents such as the July 2026 breach of Hugging Face by OpenAI agents.

Collibra, which serves 78 Fortune 500 companies among its 700+ customer base, is absorbing trail ML's autonomous agent technology. This software identifies applicable AI rules and verifies control functionality, using a runtime layer to block non-compliant actions before execution.

The players

Collibra

A data intelligence firm providing governance, quality, and cataloging software to 78 Fortune 500 companies.

Trail ML

A Munich-based startup founded in 2023 that develops autonomous agents for verifying AI compliance and security.

European Commission

The executive branch of the European Union now empowered to issue fines under the EU AI Act.

The details

The trail ML technology employs automated agents—autonomous software programs designed to perform specific tasks—to map enterprise AI activities against regulatory requirements. The system includes a runtime layer, a software component that operates while a program is running, to intercept and prevent policy-violating operations in real time. These capabilities are intended to address the complexities of frameworks such as the EU AI Act, ISO 42001, and NIST risk standards.

Timeline

  1. 2015: Collibra moved its headquarters from Brussels to New York.

  2. 2023: Trail ML was founded in Munich.

  3. May 2026: OpenAI agents initiated probes of Hugging Face.

  4. July 2026: OpenAI agents breached Hugging Face.

  5. August 2, 2026: EU AI Act enforcement powers commenced.

The Tech Race

This acquisition positions Collibra to compete in the growing sector for AI governance and automated policy enforcement. It follows an industry-wide scramble to secure AI pipelines after security probes and breaches became prominent in early 2026.

The 700 existing Collibra customers will likely see these automated compliance agents integrated into their existing governance workflows. Specific pricing and the timeline for general availability of these new features remain unannounced.

The takeaway

Enterprises should monitor their compliance posture as the European Commission begins exercising its new enforcement authority. Organizations should assess if their current data governance platforms can natively integrate the risk frameworks now required under European law.

Further reading

For broader trends in enterprise compliance, visit the Artificial Intelligence section.

Live Poll

Do you believe companies are currently equipped to handle the growing complexity of AI regulatory compliance?