Most of the AI standards on the horizon are still in ballot or development. AAMI CR515 is published, and more than that, the FDA has added it to its database of recognized consensus standards. For a manufacturer writing a submission this year, that recognition is the whole point. You can cite it now, and a reviewer already knows what it is.
CR515 covers the cybersecurity considerations that are unique to machine learning-enabled medical device software. It deliberately skips the threats that ordinary security practice already handles and focuses on the ones that are new or that behave differently for ML, across the full arc: data collection, product design, deployment, use, and maintenance. AAMI shipped it as a consensus report rather than a slower technical standard precisely because the threat picture was moving too fast to wait.
Treat CR515 as the bridge between the FDA's threat list and your actual program. The January 2025 draft tells you the agency cares about poisoning, evasion, model theft, and the rest. CR515 gives you a recognized document that walks those considerations across the lifecycle, so your rationale points at something the reviewer accepts instead of your own internal memo.
It is guidance, not a pass or fail bar, so it will not carry a submission by itself. What it does is lower the friction. Of everything arriving, this is the one I would reach for first, because recognition is worth more in a review than novelty.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.