Getting security approval for AI coding tools requires replacing verbal assurances with repository-level evidence: a live inventory of which models, SDKs, and MCP servers exist in your codebase, enforced policy at the pull request stage, and exportable audit records.
Letting AI touch CAPA: the validation question nobody actually answers