The model migration is ready for approval.

By Shayimamba Conco, security evangelist: Africa at Check Point Software Technologies

Tests show better performance and lower costs. The application will serve the same users, process the same data, and support the same business workflow. The product team expects a straightforward technical sign-off.

Then security asks the question that changes the review: which controls will survive the switch?

Access rules, data protection, logging, and human approval may depend on settings provided by the current model platform. A migration can alter the organisation’s effective policy even when the business use stays exactly the same.

Models and providers will keep changing. The requirements attached to business purpose, sensitive data, accountability, and permitted action need to travel with the use case.

 

AI Diversity Makes Governance Consistency Harder

Enterprises will use multiple models and platforms. Developers may prioritise performance, regulated workflows may require particular environments, and employees may rely on AI features embedded in business applications.

Each new model, tool, or interface creates another place where teams must interpret enterprise policy.

One team may record only prompts, leaving tool calls outside the audit trail. Another may inspect uploaded files while information retrieved from an enterprise repository passes unchecked. A similar workflow elsewhere may apply different human-approval requirements.

The organisation still has an AI policy. Its practical meaning changes from one implementation to the next. Governance drift grows in the gap between the rules the organisation believes it has, and the controls its AI systems actually apply.

 

Make the Use Case the Anchor for Governance

Approved-model lists help organisations evaluate providers, reduce obvious exposure, and give teams safer options. Provider approval establishes a trusted option; safe use still depends on context.

An approved model may be suitable for public content and unsuitable for unreleased financial information. A sanctioned assistant may support drafting while a consequential decision requires human review.

The use case provides a more durable governance anchor: who or what is using AI, for which business purpose, with what data, and with the ability to produce which outcome.

As we discussed in AI Has Moved From Assistance to Action, governance must address what AI does with access. That answer needs to remain stable when the underlying model changes.

Model selection is an implementation decision. Business intent and acceptable risk are governance decisions.

 

Five Requirements That Should Travel with the Use Case

Portable governance establishes a consistent set of requirements that each AI implementation satisfies according to its risk.

  • Identity and accountability – Every interaction should be associated with a known user, application, service, or agent. Every use case also needs a business owner accountable for its purpose and risk.
  • Permitted purpose – Tool approval determines whether a service may be used. Purpose defines the activities it may perform. Summarizing public information, analysing customer records, and changing an account require different levels of oversight.
  • Data boundaries – Rules for personal data, source code, credentials, intellectual property, and regulated information should follow the data across prompts, uploads, retrieval systems, and connected tools.
  • Output and action boundaries – Governance must define what a system may generate or execute. A high-impact action may require human confirmation, a second approval, or a hard prohibition.
  • Evidence and assurance – Organisations need enough evidence to understand important AI outcomes and verify that controls worked. Evidence requirements should preserve the ability to investigate, demonstrate control, and test the system through provider changes.

Together, these requirements create a governance contract around the use case. Technology can change underneath it while the agreed conditions remain in force.

 

Apply the Model-Change Test

To find where governance remains tied to a tool, imagine that an AI application changes model providers tomorrow. Then ask:

  • Would the same users and services remain authorised?
  • Would the same data and retention requirements apply?
  • Would prohibited uses and actions still be prevented?
  • Would human-approval boundaries remain in place?
  • Would security retain the same evidence and visibility?
  • Would the change trigger appropriate testing?

Several “no” answers reveal provider-specific governance and gaps in portability.

The same test applies when an employee moves from a public assistant to an embedded copilot, a prototype enters production, an application gains enterprise data, or a workflow gains the ability to act.

 

Scale Controls to the Risk

An internal summarisation tool can follow a lighter review path than an agent that accesses customer data and executes financial workflows. Different providers also introduce different capabilities and failure modes.

Consistent decision-making can support different control depths. Higher-risk uses require stronger evidence, narrower boundaries, deeper testing, and more immediate intervention. Lower-risk uses can move through a lighter process.

Teams gain predictable requirements, while security concentrates effort where failure would matter most.

 

From Portable Policy to a Common Control Plane

Defining consistent requirements is the first step. As AI adoption spreads across teams, applications, tools, and models, separate implementations of the same policy become difficult to govern.

Organisations need a practical way to govern access, monitor usage, manage risk, and apply policy across distributed AI activity. An AI Gateway can provide a common control plane between enterprise AI use and the models supporting it.

Governance defines what must remain consistent. AI Gateway provides a place to observe and enforce those requirements across teams, tools, and models.

Check Point’s AI Defense Plane extends this model across the enterprise by unifying discovery, protection, and governance across workforce AI, applications, and agents. It provides the broader architecture for applying policy wherever AI is used, embedded, and allowed to act.

 

Governance Should Outlive the Model

Models will improve, providers will change, and teams will keep finding new uses for AI. A durable governance model accommodates this movement while holding enterprise requirements steady.

The responsible identity, permitted purpose, data boundaries, acceptable actions, and evidence requirements should remain connected to the business activity as technology evolves.