A machine learning model is at its best the day it clears, and then the world it was trained on moves. Inputs shift, the data distribution drifts, and new attacks appear that did not exist at submission. IEEE P63685 is the standard forming around that problem. Its subject is post-market surveillance of machine learning-enabled medical devices, and it is still in development, so this is a look at where the requirements are heading rather than a document you cite yet.
It extends the general idea of device post-market surveillance to the specifics of a model in the field: watching performance over time, catching drift, and feeding what you learn back into the product. That is a different job from the one-time validation most AI submissions still lean on, and it lines up with what the FDA already asks for in its premarket guidance, which expects cybersecurity testing at regular intervals after release.
Drift is not only a quality problem. An attacker who can shift the data a model sees can degrade it on purpose, and a model that quietly gets worse in the field is an exposure whether the cause is natural or deliberate. Postmarket surveillance is how you notice, and a standard that defines what good surveillance looks like for AI is a security control as much as a quality one.
P63685 is the least finished item on this list, and I am watching it for that reason. Continuous monitoring of a shipped model is exactly the kind of work that is easy to promise and hard to run, and once there is a standard for it, the aspirational postmarket plans in a lot of submissions are going to have to become real.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.