A one-off project creates a one-time governance checkpoint. Without continuous oversight, AI-generated code introduces new architectural anti-patterns, security vulnerabilities, and compliance gaps that are harder to detect than the original debt. This is governance debt.\n- Problem: AI modernizes an auth system but introduces OAuth misconfigurations not in the original spec.\n- Solution: AI TRiSM-informed guardrails embedded in the CI/CD pipeline, performing continuous SAST, license compliance, and architecture rule checks.