# Method Notes and Source Boundaries

The AI Change Record is a small documentation pattern for material change. It is an interpretation and implementation aid, not a compliance instrument, risk score, legal framework, certification, or safety case.

## Why the record asks about lifecycle and context

NIST’s AI RMF describes AI risk management as voluntary, context-sensitive, lifecycle work across GOVERN, MAP, MEASURE, and MANAGE functions. It notes that changing data, integrated components, operational context, and incomplete visibility can affect risk management and accountability. This supports documenting **what changed** and the context that changed with it; it does not prescribe this template. [1]

## Why the record asks for source, evidence, and re-checks

NIST’s Generative AI Profile highlights governance, content provenance, pre-deployment testing, and incident disclosure as primary considerations. The record uses a narrow evidence/re-check field so a reviewer can distinguish a stated expectation from observed evidence. A record is still not proof that an AI system is safe, reliable, compliant, or fit for purpose. [2]

## Why the record asks for monitoring and pause conditions

Article 72 of the EU AI Act concerns post-market monitoring requirements for high-risk AI systems within its scope. It describes active and systematic collection, documentation, and analysis of relevant data throughout a system’s lifetime. The AI Change Record borrows the practical idea of naming an observable condition and a pause path; it does not state or imply that all users are subject to Article 72. [3]

## Why dependencies and permissions may be material surfaces

OWASP’s Top 10 for LLM and GenAI Applications identifies risks across development, deployment, and management, including supply chain, data/model poisoning, excessive agency, and unbounded consumption. The record therefore prompts teams to consider changes in external tools, sources, permissions, and resource envelopes. It does not discover vulnerabilities or replace security testing. [4]

## References

[1] [NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0)](https://doi.org/10.6028/NIST.AI.100-1)  
[2] [NIST AI 600-1, Generative Artificial Intelligence Profile](https://doi.org/10.6028/NIST.AI.600-1)  
[3] [EU AI Act Service Desk, Article 72: Post-market monitoring](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-72)  
[4] [OWASP Top 10 for LLM and GenAI Applications](https://genai.owasp.org/llm-top-10/)
