Glossary
What AI model governance is.
The controls that keep AI models and agents accountable once they are in regulated use, from versioning through to a named owner.
AI model governance is the set of controls that keep AI models and agents accountable in regulated use: versioning so every change is recorded, change control over what ships, scoped access to data and tools, ongoing monitoring of behavior, and a named person accountable for each output. It defines who is responsible when a model is in production.
Governance is what carries a model past the demo. A model can pass its checks on Tuesday and quietly drift by the next quarter as data and prompts change around it. Versioning and change control catch that, monitoring shows when behavior moves, and a named owner means there is always someone who answers for a given output rather than the tool. This is the operating discipline behind audit-ready AI agents.
In pharma the controls map onto rules teams already work to. Change control and versioned records line up with 21 CFR Part 11, the lifecycle expectations sit inside GAMP 5, and scoped access keeps each agent to the minimum data its task needs. We build inside the client's own Claude Enterprise tenancy so the access, logging and sign-off stay under their control. See how that fits GAMP 5 for AI agents and the wider security model.
Common questions
How is AI model governance different from a one-time validation?
Validation proves a model worked on the day you checked it. Governance is the running discipline that keeps it controlled after that: every version recorded, every change approved, behavior monitored, and a named owner who answers for what it does in production.
Does AI model governance apply to agents, not just models?
Yes. An agent adds tool use and data access on top of the underlying model, so it needs the same versioning and change control plus access scoping and monitoring of what it actually did. The accountable human signs for the agent output, the same way they would for a model.
15 min. 5-day written diagnosis. No deck.