# Model release and change-management gate

- **Record type**: Control
- **Kind**: Process
- **Owner**: Release manager
- **Frequency**: At launch and on material change
- **Duties served**: 5

## What the control achieves

Makes every release, retraining and material change to an AI system pass through a documented decision that confirms the required assessments, tests and documentation are complete and current.

## How it is typically implemented

A release checklist tied to the system's risk tier lists the artefacts that must exist and be current before go-live: risk and impact assessments, test reports, documentation, oversight design, notices, monitoring plan and, where relevant, conformity and registration records. A change-classification rule distinguishes routine updates from material changes that re-open the assessments. The gate is applied in the deployment pipeline where possible, with a human approver for higher tiers, and decisions, deferrals and conditions are recorded. Decommissioning follows the same path in reverse, with data, logs and documentation retained as required.

## Evidence it produces

- Release or change approval record (approval_record): Checklist outcome, approver, conditions and date for one release or material change.
- Release and change-classification procedure (procedure)

## Legal duties this control serves

- Operate a quality management system — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-quality-management-system
- Providers must take corrective action and inform the supply chain about non-conforming high-risk AI — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-20-corrective-actions-and-information
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-25-value-chain-becoming-provider
- Providers of GPAI models must maintain technical documentation and inform downstream providers — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-53-gpai-technical-and-downstream-documentation
- Frontier developers must publish a transparency report before deploying a new frontier model — California SB 53, California (United States) (supports): https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Clause 8.1; Annex A.6.2.5, A.6.1.3
- NIST AI RMF 1.0: MANAGE 1.1, 2.3; GOVERN 1.7
- ISO/IEC 27001:2022: Annex A 8.32 Change management

## MIT AI Risk Repository subdomains addressed

7.3, 6.5

## Provenance

- **Record page**: https://aipolicytracker.org/controls/model-release-and-change-management-gate
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: medium
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
