The FDA's January 2025 AI-Enabled Device guidance identifies seven AI-specific cyber threats. Only one of them, model evasion, lives at runtime on the device. The other six attack the pipeline: training data, model registries, evaluation logic, and deployment.
Most testing programs today only cover the deployed model. That means they are addressing one-seventh of what the FDA is explicitly asking about. Data poisoning, model inversion and stealing, data leakage, overfitting, model bias, and performance drift all sit upstream of the running model.
Our approach expands the digital twin to include the full AI pipeline as an associated system, then structures testing to cover the whole lifecycle. Runtime testing stays focused and purpose-built. Every test case maps back to a specific FDA-identified threat, executed against real pipeline components, producing defensible evidence for premarket and postmarket.
This is not "test the model." It is "test everything that touches the model."
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.
One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.
The FDA's January 2025 AI-Enabled Device guidance names seven AI-specific cyber threats: data poisoning, model inversion and stealing, data leakage, overfitting, model bias, performance drift, and model evasion. Only model evasion lives at runtime on the device. The other six attack the pipeline that produces the model.
No. A program scoped to the deployed model covers one of the seven threats the FDA names, model evasion. The other six sit upstream in training data, model registries, evaluation logic and deployment, which means runtime-only testing addresses roughly one seventh of what the guidance asks about.
The AI pipeline is everything that touches the model before it runs: training data, model registries, evaluation logic and deployment. Treating that pipeline as an associated system inside the device model is what lets testing cover the whole lifecycle instead of stopping at the version that ships.
Map every test case back to a specific FDA-identified threat and execute it against real pipeline components. That mapping is what turns test activity into evidence a reviewer can follow for premarket and postmarket, because each result points at the named threat it answers.
No. Runtime testing stays in scope and stays focused, because model evasion is a runtime threat. The guidance widens the scope rather than shifting it. The instruction is not to test the model. It is to test everything that touches the model.