When the System Changes Without a Release
Healthcare AI systems increasingly depend on externally managed models, APIs, retrieval corpora, identity services, policies, data pipelines and tools that may change without a corresponding local software release. This creates an assurance problem: evidence that supported a clinical, safety, privacy, provenance or oversight claim at one point in time may no longer remain valid even though the deployed application appears unchanged. This preprint examines how assurance should be reassessed under such partially observable dependency change. Building on prior work in software change-impact analysis, medical-device change control, dynamic assurance cases, SBOM/AIBOM and continuous assurance, it proposes a claim-centred method for determining when prior evidence may be retained, when a claim should be reopened for targeted reassessment, and when existing evidence has been contradicted. The approach explicitly links assurance claims to their supporting dependencies, assumptions and evidence envelopes, and distinguishes observable local state from the broader system state on which assurance may actually depend. A set of synthetic executable cases illustrates the decision logic, including a counterexample showing how an incomplete dependency map can preserve false assurance. The contribution is deliberately bounded: it does not claim clinical validation or introduce selective revalidation as a new concept. It focuses on the continuity of assurance in composed healthcare AI systems when relevant upstream dependencies change without a local release.
Authors
- Fatima Azzahra MASTARI
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-14
- DOI
- https://doi.org/10.5281/zenodo.22747164
- Primary Topic
- Safety Systems Engineering in Autonomy
- Type
- preprint