Skip to content
Review Open access

Ethical Governance of AI-Driven Information Security: Balancing Data Privacy, Cyber Resilience, and Digital Trust in Organizations

2026 · International journal of research and scientific innovation · 0 citations

TL;DR

A novel, unified governance framework centred on digital trust is proposed that distinctly integrates the AI Trust Framework and Maturity Model (AI TMM), the Tiered Ethical Cybersecurity Model (TECM), and privacy preserving technologies such as federated learning to operationalize ethics by design.

Abstract

Cyber threats represent a critical risk to global organisations, with cybercrime damages projected to exceed USD 10.5 trillion annually by 2025. Consequently, enterprises are rapidly adopting Artificial Intelligence (AI) to augment their security architectures, as traditional, rule based Security Information Systems (SIS) struggle to mitigate sophisticated, multi stage attacks. However, the application of AI in security raises significant ethical questions around data privacy, algorithmic transparency, and the balance between automated surveillance and civil liberties. As a conceptual paper, this study investigates how businesses can govern AI-Driven security solutions by bridging the theoretical divide between technical efficacy and ethical responsibility. To build this theoretical foundation, a systematic review of 32 peer reviewed articles was conducted using the PRISMA paradigm, synthesizing existing evidence across four core governance dimensions: technical performance, stakeholder accountability, regulatory compliance, and organisational process. Our conceptual analysis reveals a persistent "principles to practices gap"; while AI based SIS significantly outperform traditional systems in anomaly detection and incident response, these technological advancements have outpaced the operationalization of ethical norms within organisations. To address this gap, the paper proposes a novel, unified governance framework centred on digital trust. This model distinctly integrates the AI Trust Framework and Maturity Model (AI TMM), the Tiered Ethical Cybersecurity Model (TECM), and privacy preserving technologies such as federated learning to operationalize ethics by design. The article concludes with actionable policy pathways for legislators, organisational leaders, and researchers to increase cyber resilience while strictly respecting individual privacy rights.

Read PDF

Similar papers

Open access Jul 2026

AI-driven cybersecurity in the gulf states: governance challenges and a proposed GCC-wide ethical framework

The study proposes a novel GCC-wide AI governance framework comprising four integrated layers: regulatory (risk-based classification), technical (explainable AI methods such as SHAP/LIME, federated learning, and differential privacy), oversight, and capacity-building (workforce development and regional intelligence sharing).

Mustafa Osman I. Elamin · 0 citations
Open access 2026

Trustworthy AI: Operationalizing Responsibility in Lifecycle-Aware AI Threat Modeling through RACI

: Artificial Intelligence (AI) is a key driver of digital transformation across sectors. However, its rapid adoption introduces significant challenges in governance, security, and accountability. Modern AI systems, particularly generative and adaptive models, exhibit non-deterministic behavior, evolving data dependencies, and distributed ownership. These characteristics limit the effectiveness of traditional threat modeling approaches. At the same time, existing governance frameworks treat accountability primarily as a managerial concern and do not integrate it into technical threat modeling processes. This disconnect leads to fragmented oversight, unclear role ownership, and increased security and compliance risks across the AI lifecycle. To address this gap, this paper proposes a lifecycle-aware threat modeling framework for Secure and Trustworthy AI that embeds RACI (Responsible, Accountable, Consulted, Informed) roles into each stage of the threat modeling process. By linking technical threat analysis with explicit accountability, the framework transforms governance into an operational security mechanism. It enables systematic identification of AI-specific risks while ensuring trace-able decision-making and clear risk ownership. The framework further extends to distributed AI ecosystems (RACI+X) by incorporating external actors into the accountability structure. Overall, the approach strengthens resilience against evolving risks and supports secure, transparent, and accountable AI deployment.

Faiza Tahir, Ubaid Ullah, Eric Bodden · 0 citations
Review Open access Sep 2026

Auditing as a Governance Mechanism for Artificial Intelligence: Institutional Design, Accountability, and Ethical Oversight

The rapid diffusion of artificial intelligence (AI) across organisational and societal settings has heightened concerns about accountability, transparency, and ethical oversight. Existing governance mechanisms, including regulation and principle-based ethics frameworks, often struggle to address the scale, opacity, and socio-technical complexity of AI systems. In response, auditing has increasingly been proposed as a means of implementing accountability by translating ethical and legal expectations into structured oversight practices. The study employs a structured literature review methodology, analysing 71 peer-reviewed articles published between 2020 and 2025, retrieved from Scopus, Web of Science, and ProQuest. Through thematic synthesis, the review shows that AI auditing has evolved beyond technical verification towards a socio-technical governance infrastructure grounded in transparency, independence, ethics integration, and professionalisation. However, its effectiveness is constrained by persistent challenges, including algorithmic opacity, regulatory lag, fragmented standards, capability gaps, and risks of symbolic compliance. The study positions auditing as both a central tool and a critical institutional challenge within AI governance, offering insights for scholars, regulators, and practitioners seeking durable accountability mechanisms for responsible AI.

Alexander Oluka · 0 citations
Open access 2026

AI-Native Information Technology Architecture and Emerging Organizational Issues: Cloud Governance, Cybersecurity Resilience and Digital Trust

AI-native IT architecture is fundamentally reshaping the modern enterprise and accelerating the shift toward decentralized autonomous networks. While this transition unlocks unprecedented capabilities, it also introduces a wave of complex security vulnerabilities. Today, enterprises face a tripartite challenge which are securing hyper-connected cloud environments, mitigating sophisticated cyber threats and ensuring algorithmic accountability. To address these interconnected issues, this study synthesizes recent literature (2022–2024) from Scopus and Web of Science bridging three disciplines typically studied in isolation of cloud governance, cybersecurity resilience and digital trust engineering. Technological adoption alone is insufficient for sustainable digital transformation. Organizations must pivot from reactive, post-deployment compliance to embedding proactive governance directly into their system architecture from inception. By examining dual-loop governance models and policy-as-code frameworks, this paper translates high-level theories into actionable deployment pathways and measurable performance indicators. Furthermore, as stringent regulations like the EU AI Act take effect, cyber defenses must evolve in tandem. Enterprises urgently require predictive resilience frameworks powered by Explainable AI (XAI) to pierce algorithmic opacity which is an effort that will rely heavily on quantitative trust assessments and decentralized identity infrastructures. Finally, to validate these concepts beyond theoretical constructs, we ground our proposed model in real-world application scenarios across the healthcare, finance and critical infrastructure sectors. Ultimately, for AI-native enterprises to achieve long-term viability, they must successfully balance rapid, autonomous innovation with adaptive security and verifiable stakeholder trust.

Uthayashankari A/P Shumugam, Nurshahida Binti Muhamad Razali, Syed Mohsen Bin Syed Abu Bakar Alkaff et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.