Security programs are built around moments of closure: the finding is closed, the control passed, and the release can move forward. AI security refuses to cooperate with that model. A passing test is useful evidence, but only for a specific system, configuration, and moment.