Here's what most enterprise AI deployments don't have a process for.
You go through the work of validating an AI tool. Legal reviews it. Compliance signs off. You document the outputs, establish the guardrails, get the right people in the room. Everyone approves. You go live.
Three months later, the AI provider has shipped two new model versions. Your deployment, unless someone explicitly locked it, is now running on a model that nobody reviewed, nobody approved, and nobody tested against your use case.
The sign-off happened. The AI kept moving. And nobody built a bridge between those two things.
This is different from how traditional software works, and most organizations haven't caught up to that yet.
When your case management software updates, the logic stays the same. A process that worked before the update works after it. You're patching bugs, closing security gaps, adding features. The core behavior is stable.
AI models don't update that way. When Anthropic ships a new Claude version, or OpenAI rolls out a GPT update, the model's reasoning patterns change. Its tone changes. The way it handles edge cases changes. The same input can produce a meaningfully different output — not because something broke, but because the model itself is different.
I've watched this play out across legal, healthcare, and financial services. A team validates an AI tool properly for a specific workflow, contract review, clinical documentation, claims processing. They do the work. Six months later, someone from compliance asks: "Is this the same AI we approved?" The honest answer is: probably not, and nobody checked.
Why this matters more in regulated industries than anywhere else
In a consumer app, a model update that shifts output style is a product consideration. You iterate. In legal, healthcare, insurance, and wealth management, the stakes are different. The output of an AI tool can directly affect a legal argument, a clinical decision, a coverage determination, a financial recommendation. In those contexts, "the model changed" isn't a neutral statement, it's a provenance question and, increasingly, a regulatory one.
The EU AI Act, now in active enforcement, requires organizations to maintain documentation of the AI systems they deploy, including what those systems are built on. Regulators in the US are moving in the same direction: the question of what was running when a particular output was produced is starting to appear in audits and reviews across financial services and healthcare. Not universally yet, but the direction is clear.
Most organizations cannot answer that question today. Not because they were negligent, because nobody built a process for it. The industry moved faster than the governance did.
What the organizations handling this well have figured out
The ones getting this right made one foundational decision early: they treat a model update the way they treat a software release. It goes through a gate before it touches production.
In practice, this doesn't require a large engineering team or expensive tooling. It means pinning to a specific model version in your API settings, something every major AI provider supports, so updates don't happen automatically without review. It means running your most important use cases through the new version before you adopt it, and keeping a simple log of which model version was in use and when. Most of the organizations I've seen do this well started with a shared document and a policy decision. The infrastructure came later.
The other thing they track is something easy to overlook: not just what model was running, but what the output looked like before and after an update. That comparison is what makes it possible to show a regulator or a client that you managed the transition deliberately, that the change was a decision, not an accident.
The question worth asking this week
If your organization is running AI in any workflow that touches a client, a patient, a claimant, or a financial decision, do you know which model version is running today?
Not which product. Which model version.
If the answer is "I'd have to check", that's worth knowing now, before someone else asks first.
The pace of AI development is not slowing down. New model versions are shipping faster than they were a year ago, and that pace will keep accelerating. The organizations building governance around that reality now are the ones that won't be scrambling to reconstruct their AI history when the question becomes urgent.
AI in Production is a weekly newsletter for leaders navigating AI deployment in high-stakes industries. If your organization is past the pilot stage, or about to be, subscribe for a practical perspective on what it actually takes to make AI work in the real world.
If this resonated, share it with someone on your team who owns your AI rollout. Link to subscribe is in the comments.
