What exactly is AI governance, as distinct from AI security?
The two are routinely conflated and solve different problems. Security concerns access control, encryption, injection resistance and infrastructure hardening — keeping the wrong people out. Governance concerns whether the right people, doing permitted things, produce outcomes the organization can defend: whether restricted categories were excluded before indexing, whether an answer can be traced to approved sources, whether the rules in force are the rules that were meant to be. A perfectly secure system can be ungoverned, answering confidently from material nobody approved.
Centralpoint's governance layer operates on content rather than perimeter: classification and redaction during ingestion, audience scoping carried by each record, versioned prompts and skills, and an interaction log tying each answer to the rules that produced it. Security remains necessary and is a separate discipline — governance is what lets you state, afterwards, why the system answered as it did.