Model behavior changes. Providers update weights, retrieval indexes evolve, prompt injections propagate, and downstream data shifts. The model that passed evaluation on the day of launch is not the model that is running six months later. An organization that treats deployment as the end of the AI product cycle is running an uncontrolled experiment on its customers.
The operating discipline is drift governance: a named owner, a defined evaluation regression cadence, thresholds for automated alerting, and a documented decision authority for rollback, retraining, or model substitution. None of this is exotic. All of it is routinely absent.
The evaluation set itself is a product artifact and must be versioned. Adversarial and safety cases are refreshed as new failure modes are observed, and the evaluation coverage report is a standing input to executive review — not an engineering internal.
In regulated environments, drift governance is increasingly a procurement requirement in its own right. Enterprise buyers ask not whether the vendor evaluated the model at launch, but whether the vendor can demonstrate ongoing evaluation, drift monitoring, and a defined rollback authority. Those without a written answer are removed from consideration.