Software That Earns Its Approval: The Living Device

The thesis
We approve AI-enabled devices by freezing them — locking the model at submission as if it were a chemical pill. Then we act surprised that a static model degrades as the world drifts around it. We are regulating learning software with the physics of tablets.
Approve the process, not the snapshot
Shift the unit of approval from the frozen model to the learning system and its guardrails: the data pipeline, the validation gates, the drift monitors, the rollback triggers, the change-control plan. A device that can prove it only updates within a pre-authorised envelope should be allowed to improve after it ships.
The safety machinery
- Predetermined change control — the boundaries of allowed learning are approved up front.
- Continuous performance monitoring with automatic rollback if real-world metrics slip.
- Cryptographic model provenance — every deployed version is signed, logged and reproducible.
- Shadow deployment — new versions prove themselves silently before they touch a decision.
Why this is safer than freezing
A frozen model is not safe — it is unmonitored. A living device that watches its own accuracy and reverts on degradation is far safer than one certified once in 2024 and blindly trusted in 2029.
Provocation
The regulator that masters "approve the process" will unlock a generation of devices that get safer every month. The one that keeps freezing snapshots will preside over a fleet quietly rotting in the field.
A first-principles provocation from the Anxya Health Futures desk. Directional and informational — not medical, legal, financial or regulatory advice. The point is to move the debate, then do the hard validation work.