Modern BI

What Happens When AI Can Change the Numbers Everyone Trusts?

AI can now change measures and data models, not just query them. See how a governed semantic layer keeps AI-made analytics changes under control.

Nikola Gemeš
•
September 24, 2026
•
6 min
read
What Happens When AI Can Change the Numbers Everyone Trusts?

Asking an AI assistant to explain your revenue numbers is one thing.

Asking it to change how revenue is calculated is another.

Imagine Finance and Sales both rely on the same Monthly Sales measure. It feeds the CFO’s Excel workbook, the sales dashboard, and the answers people get when they ask AI about revenue.

An analyst spots a problem with the calculation and asks Claude to fix it.

Claude does.

Now what?

Does the change immediately become the new definition of Monthly Sales? Can you see exactly what changed? Can you undo it? What happens to everything downstream? And does any of this change if another team uses ChatGPT instead?

These weren’t particularly urgent questions when AI could only ask questions about analytics.

They become very real once AI can change the analytics underneath them.

AI is moving from answers to work

Much of the conversation around AI governance in analytics has focused on what an assistant is allowed to see.

Can it access this row? Should that column be masked? Does this user have permission to query that data?

Those controls still matter. Semantic-layer platforms increasingly apply permissions and business definitions between the AI and the underlying data, rather than expecting the model itself to decide what it should access.

But AI assistants are starting to do more than query what somebody else has built.

Connect an assistant to Astrato through MCP and it can work with the semantic layer itself. Depending on the user's permissions, it can:

  • find existing measures, dimensions and joins
  • check the model for problems
  • create or change measures and dimensions
  • save named versions
  • publish changes when asked
  • answer business questions already defined in the model

It works on the user's behalf and within the same permissions they already have.

That changes the risk.

One wrong answer can mislead one person. One wrong shared definition can affect everyone who uses it.

Change the definition of revenue, ARR or active customers and the consequences can travel much further than one AI conversation. The same definition may be feeding dashboards, spreadsheets and other analytics experiences.

So the question is no longer simply whether AI should be allowed to touch the model.

It’s what happens to an AI-made change before everyone else starts relying on it.

Give AI somewhere safe to work

This is where the way the semantic layer handles change becomes important.

An edit doesn't have to become production simply because an AI assistant made it.

In Astrato, semantic-layer changes happen in a working copy. Changes are recorded in version history, known model issues can block publishing, and publishing determines when the new model reaches the workbooks and dashboards that depend on it.

In simplified form:

Governed change · AI workflow

How an AI-made change moves from edit to live use

AI can do the work without getting a separate route around the controls protecting the shared model.

01
AI edit
An assistant creates or changes a measure, dimension or model definition.
→
02
Working copy
The change can exist without immediately replacing the live definition.
→
03
History + validation
Changes are recorded and known model issues can block publishing.
→
04
Publish
Publishing is the defined point where the updated model becomes live.
→
05
Downstream use
Dashboards and other consumers can use the updated definition.
The boundary: doing the work and making that work authoritative are separate steps.

Go back to our Monthly Sales example.

You ask Claude to fix the measure. It can find the definition and make the change without you opening the Semantic Layer Editor and doing the work manually.

But the edit still enters the same change-management system as other semantic-layer work. It can be inspected in version history. If the model contains validation issues, publishing is blocked until they're resolved. And if the change turns out to be wrong, earlier versions can be compared and restored.

The AI gets to do useful work without getting a separate route around the controls already protecting the shared model.

That’s a much more useful boundary than “AI can read, but AI can never change anything.”

The assistant can change. The business context doesn't have to.

There’s another problem waiting behind AI adoption: different teams aren't necessarily going to choose the same assistant.

Your organization might eventually look something like this:

One model · Many interfaces

Different teams can work in different tools

The interface can change while teams keep working from the same shared business definitions.

Team

Where they work

Shared context

Data

Claude or IDE

Measures, dimensions and model definitions

Marketing

ChatGPT

The same governed business definitions

Developers

VS Code or Codex

The same semantic model and permissions

Finance

Excel

Trusted measures used in financial analysis

BI teams

Astrato

Dashboards, reports and data apps on the same definitions

The assistant can change. The business context doesn’t have to.

Trying to solve AI governance inside each interface creates a moving target.

The alternative is to keep the shared business context underneath them.

Astrato's MCP connection has already been tested with Claude, ChatGPT, VS Code, Claude Code, Snowflake CoCo and OpenAI Codex, with support for other MCP clients as well. Each connects to the semantic layer rather than maintaining its own independent definition of the business.

Shared context · Multiple experiences

One definition. Many analytics experiences.

A shared semantic layer keeps business definitions in one place while people work through different analytics and AI interfaces.

Astrato semantic layer
Shared business definitions
Measures · dimensions · relationships · permissions · versioned changes
↓
Dashboards
People see the same defined measures in BI.
Excel
Finance can work with the same governed definitions.
Data apps
Operational experiences reuse the same business logic.
AI assistants
Different assistants can work from shared context instead of inventing their own.

Change the interface without redefining the business every time.

That means “Monthly Sales” doesn't have to become one thing in Claude and something slightly different in ChatGPT.

The measure lives in the semantic layer.

The assistant can change. The business context doesn't have to.

That's the more interesting version of bring-your-own-AI. You aren't simply adding more AI integrations. You're separating the place where people choose to work from the place where the business decides what its data means.

Governance doesn't mean keeping AI away from the model

There are two easy answers to AI write access.

Keep AI read-only.
The assistant can identify the problem, but the analyst still has to leave the conversation, open another tool, find the definition and make the change manually.

Give AI unrestricted control.
Now you've removed the friction, but you've also removed the useful boundary between doing work and trusting that work.

Neither is particularly satisfying.

The better model is familiar because we already use it for people:

Let AI work inside the governed development process instead of creating a shortcut around it.

Astrato's semantic-layer workflow separates the working copy from what is currently live. Version history records changes. Validation prevents a model with known issues from being published. Publishing controls when the new definition reaches downstream consumers.

And if you explicitly ask a connected AI assistant to publish, it can do that too — subject to your permissions.

That's an important distinction.

Governance isn't necessarily about requiring a human to click every button. It's about making sure AI operates through the same controlled system rather than outside it.

What these controls can — and can't — protect

The mechanics can protect quite a lot:

  • Identity and permissions: the assistant acts with the access of the person connecting it.
  • Working copy: edits can exist without immediately changing what everyone downstream sees.
  • Version history: changes are recorded and earlier states can be compared or restored.
  • Validation: known model problems can prevent publishing.
  • Publishing: there is a defined point where changes move from the working model to live use.

But none of that can decide what Monthly Sales should mean.

A measure can be technically valid and still be wrong for the business.

Maybe Finance defines revenue net of refunds while Sales has been using gross sales. Validation can check whether a formula is structurally sound. It can't settle that disagreement.

Astrato makes a similar distinction with its own AI-generated measure and dimension suggestions: a suggested formula may be reasonable based on the data, but only the business knows whether something like Gross Margin should include or exclude particular costs.

That's where people remain important.

The useful human role isn't necessarily making every edit manually.

It's owning the definitions and deciding what should become trusted business context.

The bigger shift isn't MCP

MCP is what makes it practical for different AI assistants to work with external tools and context. But the protocol isn't the most important part of this change.

The bigger shift is what we're starting to ask AI to do.

The first wave of AI analytics was largely about making data easier to question. Ask in natural language, get an answer.

Now AI is moving further into the work itself: finding definitions, fixing measures, creating new ones and changing the model those answers depend on.

That demands a different kind of trust.

Not trust that AI will always be right.

Not trust that every employee will use the same AI assistant.

And not a governance model that assumes keeping AI read-only is the only safe option.

What you need is a system where AI can do meaningful analytics work without bypassing the controls that make that work trustworthy.

That's a much more interesting future than another chatbot sitting on top of a dashboard.

And we're already starting to build it.

Ready to experience next-gen analytics?

See how Astrato runs natively in your warehouse.