Enterprises can’t govern AI by simply blocking access to models. Employees may turn to personal accounts instead, which creates bigger data and security risks. That is the argument from Kunal Das, a core contributor to Kimchi, an open-source, multi-model AI governance platform.
Das, who is also Developer Advocate for APAC at Cast AI, made the case in a talk titled How to Govern AI, Even If It’s Hard to Predict at Cypher 2026.
Why AI Is Hard to Govern
AI doesn’t behave like conventional enterprise software. The same prompt can produce different answers, which makes outcomes hard to predict and traditional controls hard to apply.
Das said enterprises should build governance into the infrastructure layer, and in particular the routing layer between an employee’s device and an AI model. That is where an organisation can decide which models are used, what they cost, what data is sent to them, and which actions need a human to step in.
The economics already make this a governance problem. Das said his team of about 200 engineers spent nearly $200,000 on Claude Code over a year, without a clear link between that usage and productivity. More AI use, he noted, doesn’t automatically mean more output.
Match the Task to the Model
Das argued that enterprises should stop treating the most capable model as the default. Most routine work, like fixing bugs or summarising PDFs, doesn’t need a flagship model. He advocates routing each task to a model based on its complexity, cost and requirements.
He gave an example from a workshop with 100 participants, who built projects over three hours. Their requests were first routed through a system that used cheaper models, and the total cost came to about $54. Running the same work only on a flagship model would have cost about $3,800, he said.
We use a very small cheaper model to decide which model is best for that prompt. That changes the game, Das said. This kind of routing also lets companies control AI spending before costs pile up, instead of auditing usage after the fact.
Four Areas of Governance
Das outlined four areas enterprises should focus on: spending, perimeter, resilience, and control. The approach puts governance below the model-output layer. Instead of trying to check whether every AI response is correct, companies control the infrastructure through which models receive data, carry out tasks and return results.
He compared this shift to the early days of cloud computing, when organisations adopted large amounts of compute before they had mature systems to track and control it.
Kimchi is also working on a teleport feature. It would move long-running agent tasks to a temporary cloud sandbox, so the work can continue without being tied to a developer’s laptop.
What Governance Can’t Fix
Das was open about the limits. Review and monitoring tools can show how AI is being used, but they can’t fix poorly written code or prompts. Data that has already gone to an external AI provider is a harder problem still. Once sensitive information is shared, an organisation may not be able to recover it or control how the provider handles it. We can’t fix all those things, he said.
The takeaway is that AI governance can’t rest on the model alone. Companies need controls around the models that decide where data goes, which model handles a task, what it costs, and when a human must take over. You cannot predict AI, Das said. But we can make sure that the decision that we’re taking is properly covered and we have all the things in place to track it.


