惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Jina AI
Jina AI
The Cloudflare Blog
V
Visual Studio Blog
博客园_首页
量子位
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
爱范儿
爱范儿
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
博客园 - 司徒正美
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
V
V2EX
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
博客园 - Franky

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide
Your AI Governance Policy Should Survive Your Next Model ...
Check Point Team · 2026-07-28 · via Check Point Blog

The model migration is ready for approval.

Tests show better performance and lower costs. The application will serve the same users, process the same data, and support the same business workflow. The product team expects a straightforward technical sign-off.

Then security asks the question that changes the review: which controls will survive the switch?

Access rules, data protection, logging, and human approval may depend on settings provided by the current model platform. A migration can alter the organization’s effective policy even when the business use stays exactly the same.

Models and providers will keep changing. The requirements attached to business purpose, sensitive data, accountability, and permitted action need to travel with the use case.

AI Diversity Makes Governance Consistency Harder

Enterprises will use multiple models and platforms. Developers may prioritize performance, regulated workflows may require particular environments, and employees may rely on AI features embedded in business applications.

Each new model, tool, or interface creates another place where teams must interpret enterprise policy.

One team may record only prompts, leaving tool calls outside the audit trail. Another may inspect uploaded files while information retrieved from an enterprise repository passes unchecked. A similar workflow elsewhere may apply different human-approval requirements.

The organization still has an AI policy. Its practical meaning changes from one implementation to the next. Governance drift grows in the gap between the rules the organization believes it has and the controls its AI systems actually apply.

Make the Use Case the Anchor for Governance

Approved-model lists help organizations evaluate providers, reduce obvious exposure, and give teams safer options. Provider approval establishes a trusted option; safe use still depends on context.

An approved model may be suitable for public content and unsuitable for unreleased financial information. A sanctioned assistant may support drafting while a consequential decision requires human review.

The use case provides a more durable governance anchor: who or what is using AI, for which business purpose, with what data, and with the ability to produce which outcome.

As we discussed in AI Has Moved From Assistance to Action, governance must address what AI does with access. That answer needs to remain stable when the underlying model changes.

Model selection is an implementation decision. Business intent and acceptable risk are governance decisions.

One Governance Contract Across Changing Models

Five Requirements That Should Travel With the Use Case

Portable governance establishes a consistent set of requirements that each AI implementation satisfies according to its risk.

1. Identity and accountability

Every interaction should be associated with a known user, application, service, or agent. Every use case also needs a business owner accountable for its purpose and risk.

2. Permitted purpose

Tool approval determines whether a service may be used. Purpose defines the activities it may perform. Summarizing public information, analyzing customer records, and changing an account require different levels of oversight.

3. Data boundaries

Rules for personal data, source code, credentials, intellectual property, and regulated information should follow the data across prompts, uploads, retrieval systems, and connected tools.

4. Output and action boundaries

Governance must define what a system may generate or execute. A high-impact action may require human confirmation, a second approval, or a hard prohibition.

5. Evidence and assurance

Organizations need enough evidence to understand important AI outcomes and verify that controls worked. Evidence requirements should preserve the ability to investigate, demonstrate control, and test the system through provider changes.

Together, these requirements create a governance contract around the use case. Technology can change underneath it while the agreed conditions remain in force.

Apply the Model-Change Test

To find where governance remains tied to a tool, imagine that an AI application changes model providers tomorrow. Then ask:

  1. Would the same users and services remain authorized?
  2. Would the same data and retention requirements apply?
  3. Would prohibited uses and actions still be prevented?
  4. Would human-approval boundaries remain in place?
  5. Would security retain the same evidence and visibility?
  6. Would the change trigger appropriate testing?

Several “no” answers reveal provider-specific governance and gaps in portability.

The same test applies when an employee moves from a public assistant to an embedded copilot, a prototype enters production, an application gains enterprise data, or a workflow gains the ability to act.

Scale Controls to the Risk

An internal summarization tool can follow a lighter review path than an agent that accesses customer data and executes financial workflows. Different providers also introduce different capabilities and failure modes.

Consistent decision-making can support different control depths. Higher-risk uses require stronger evidence, narrower boundaries, deeper testing, and more immediate intervention. Lower-risk uses can move through a lighter process.

Teams gain predictable requirements, while security concentrates effort where failure would matter most.

From Portable Policy to a Common Control Plane

Defining consistent requirements is the first step. As AI adoption spreads across teams, applications, tools, and models, separate implementations of the same policy become difficult to govern.

Organizations need a practical way to govern access, monitor usage, manage risk, and apply policy across distributed AI activity. An AI Gateway can provide a common control plane between enterprise AI use and the models supporting it.

Governance defines what must remain consistent. AI Gateway provides a place to observe and enforce those requirements across teams, tools, and models.

Check Point’s AI Defense Plane extends this model across the enterprise by unifying discovery, protection, and governance across workforce AI, applications, and agents. It provides the broader architecture for applying policy wherever AI is used, embedded, and allowed to act.

Live webinar

See AI Gateway Governance in Practice

Join us July 30 to see how an AI Gateway can centralize access, usage, and risk controls across teams, tools, and models.

Register now →

Governance Should Outlive the Model

Models will improve, providers will change, and teams will keep finding new uses for AI. A durable governance model accommodates this movement while holding enterprise requirements steady.

The responsible identity, permitted purpose, data boundaries, acceptable actions, and evidence requirements should remain connected to the business activity as technology evolves.

For a practical model covering workforce AI, AI applications, and autonomous agents, download the AI Security Governance Framework.