Skip to content

AI Deployment and Cyber Governance Failures in Public-Sector Organizations: A Typological Analysis

Jul 2026 · arXiv.org · Vol abs/2607.25368 · 0 citations · 33 references
Computer Science

TL;DR

A seven-domain typology identifying ten specific AI-driven cyber governance failure causes grounded in public sector institutional analysis is proposed and speed asymmetry is introduced as a named structural construct with a specified mechanism.

Abstract

The intersection of artificial intelligence adoption, cybersecurity governance, and public sector institutional constraints has not been examined as a unified analytical problem in the existing literature. Studies address AI cybersecurity risks generically, public sector governance independently, and framework adequacy separately. Existing studies have not integrated these three streams to explain specifically how AI adoption causes cybersecurity governance failure in government organizations, nor test existing governance instruments against AI-specific public sector failure causes. This paper ad-dresses that gap. It proposes a seven-domain typology identifying ten specific AI-driven cyber governance failure causes grounded in public sector institutional analysis. It presents a three-pathway failure model showing how accountability failure, opera-tional resilience failure, and compliance failure interact and reinforce each other. It de-livers a structured coverage matrix testing five major governance frameworks (NIST CSF 2.0, ISO/IEC 27001, COBIT, NIST AI RMF, and ISO/IEC 42001) against the typology, finding that no instrument addresses Shadow AI, speed asymmetry, or gov-ernance vacuum at the operational specificity required for public sector application. The paper introduces speed asymmetry as a named structural construct with a specified mechanism. The framework provides the design specification for an AI-enabled cyber-security maturity model for government organizations.

View source

Similar papers

Open access Jul 2026

AI-driven cybersecurity in the gulf states: governance challenges and a proposed GCC-wide ethical framework

The study proposes a novel GCC-wide AI governance framework comprising four integrated layers: regulatory (risk-based classification), technical (explainable AI methods such as SHAP/LIME, federated learning, and differential privacy), oversight, and capacity-building (workforce development and regional intelligence sharing).

Mustafa Osman I. Elamin · 0 citations
Open access 2026

From Policy to Pipelines: Closing the AI Governance Execution Gap

The rapid adoption of artificial intelligence across enterprise operations has created an urgent governance challenge that existing policy-based approaches have failed to resolve. Industry data reveals that a majority of employees report using AI tools their organizations have not authorized, a substantial share of organizations report AI-related security incidents, and most organizations discover AI agents operating without their security team’s knowledge. This paper identifies three structural failure modes explaining why AI governance fails at runtime: timing failure (governance engages at procurement but risk emerges during operation), visibility failure (sanctioned governance cannot reach unsanctioned usage), and abstraction failure (policies specify principles but not operational mechanisms). Through analysis of industry data, regulatory requirements, and documented incidents, the paper presents evidence that each failure mode reflects a design limitation inherent to policy-centric governance. The paper proposes the Operational AI Governance Maturity Model (OAGMM), a framework organized around four independently assessed operational dimensions - discovery, enforcement, GRC integration, and agentic governance - each scored across five levels of operational capability. Rather than a single aggregate rating, the OAGMM produces a dimension-specific profile together with a floor-based composite score, resolving the diagnostic limitation of aggregate maturity models in which strength in one dimension can mask critical exposure in another. The runtime governance architecture is correspondingly extended to address autonomous AI agents through explicit agent identity and registration, agent action audit trails, agent-to-agent interaction monitoring, and automated decision-boundary enforcement. The model is illustrated through analysis of a documented industry incident and application to five organizational scenarios spanning financial services, healthcare, technology, manufacturing, and energy. This work contributes to the emerging literature on AI governance operationalization and provides practitioners with a structured, dimension-aware framework for closing the gap between governance intent and execution.

Raj Vasireddy · 0 citations
Open access 2026

AI-Native Information Technology Architecture and Emerging Organizational Issues: Cloud Governance, Cybersecurity Resilience and Digital Trust

AI-native IT architecture is fundamentally reshaping the modern enterprise and accelerating the shift toward decentralized autonomous networks. While this transition unlocks unprecedented capabilities, it also introduces a wave of complex security vulnerabilities. Today, enterprises face a tripartite challenge which are securing hyper-connected cloud environments, mitigating sophisticated cyber threats and ensuring algorithmic accountability. To address these interconnected issues, this study synthesizes recent literature (2022–2024) from Scopus and Web of Science bridging three disciplines typically studied in isolation of cloud governance, cybersecurity resilience and digital trust engineering. Technological adoption alone is insufficient for sustainable digital transformation. Organizations must pivot from reactive, post-deployment compliance to embedding proactive governance directly into their system architecture from inception. By examining dual-loop governance models and policy-as-code frameworks, this paper translates high-level theories into actionable deployment pathways and measurable performance indicators. Furthermore, as stringent regulations like the EU AI Act take effect, cyber defenses must evolve in tandem. Enterprises urgently require predictive resilience frameworks powered by Explainable AI (XAI) to pierce algorithmic opacity which is an effort that will rely heavily on quantitative trust assessments and decentralized identity infrastructures. Finally, to validate these concepts beyond theoretical constructs, we ground our proposed model in real-world application scenarios across the healthcare, finance and critical infrastructure sectors. Ultimately, for AI-native enterprises to achieve long-term viability, they must successfully balance rapid, autonomous innovation with adaptive security and verifiable stakeholder trust.

Uthayashankari A/P Shumugam, Nurshahida Binti Muhamad Razali, Syed Mohsen Bin Syed Abu Bakar Alkaff et al. · 0 citations
Review Open access Sep 2026

Bridging Governance and Empirical Threat Intelligence: An Integrated Framework for Cybersecurity in Smart Farming

Modern agriculture’s integration of Internet of Things (IoT), Industrial Control Systems (ICSs), and data analytics boosts productivity but introduces significant cybersecurity and data governance challenges. Existing scholarship is divided between policy-focused governance and technical attack analyses, hindering the development of comprehensive, enforceable defenses. This paper introduces an integrated framework that bridges normative data governance in smart farming (SF) with empirical, honeynet-derived threat intelligence. Drawing on the authors’ previous systematic review of SF data governance and a honeynet simulating agricultural IoT/ICS, the study maps governance challenges to quantitative attack indicators from honeynet logs, classifying each pairing as directly supported by telemetry, indirectly supported by telemetry, or not observable using the current methodology. The findings show that the services flagged as governance concerns face sustained attack pressure: the honeynet recorded brute-force attempts against SSH/Telnet on simulated irrigation controllers (149,000 events), connection and login attempts targeting SMB (Server Message Block) and MQTT (Message Queuing Telemetry Transport) on automated machinery (67,156), credential-guessing attempts against management services (14,937), and ICS protocol probes (11,532). Geographic and protocol distributions reveal that legacy industrial protocols and weakly authenticated management interfaces, both highlighted as governance concerns, constitute the primary attack surface. This evidence supports a tiered governance model integrating protocol-level controls, identity governance, and data-sharing policy, demonstrating that effective SF cybersecurity requires empirically calibrated rather than purely policy-driven frameworks. The proposed framework offers actionable guidance for aligning technical defenses with data governance obligations. This work contributes a new methodological protocol (cross-evidentiary mapping), an empirically calibrated tiered framework, and a coherent research agenda at the intersection of governance and measurement, serving as a template for similar analyses in other critical infrastructure sectors.

Radwan Rouzky, A. Sarrafzadeh, Evelyn Sowells-Boone et al. · 0 citations
Review Open access Aug 2026

Cybersecurity Governance Deficiencies in External Audit: A Structured Review and Control-to-Assertion Framework

Digital financial reporting depends on identity services, enterprise systems, cloud platforms, automated controls and system-generated evidence. Cybersecurity weaknesses therefore enter external audit when a governance condition or control deficiency affects a material reporting process, an assertion, a disclosure, an estimate or the reliability of audit evidence. This article develops a non-deterministic control-to-assertion framework through a structured integrative review. The search, completed on 16 July 2026, covered English-language journal work published from 2000 to 15 July 2026 through Google Scholar and publisher search services. The final analytic set contains 32 peer-reviewed journal articles, four institutional sources and two public company filings used for worked application. The revision separates organisation-level cybersecurity governance deficiencies from process-level cyber control deficiencies. It also locates the model against COSO, COBIT 2019, NIST CSF 2.0, IT general control methods and relevant International Standards on Auditing. Existing sources provide taxonomies for governance, internal control, security outcomes and audit procedures. The new framework supplies the missing translation route between those taxonomies: governance condition, control state, financial reporting dependency, assertion-level misstatement risk, audit-evidence reliability, audit response and reassessment. Compensating, detective and corrective controls might interrupt or reduce the route, so no governance deficiency automatically produces a control failure or a material misstatement. Two worked documentary applications, The Clorox Company and MGM Resorts International, show how public incident facts enter account, assertion, evidence and procedure analysis. The framework does not estimate incident probability, expected loss or a cyber risk score. It provides a file-ready reasoning structure for entity-specific risk assessment under the auditing standards. Its main contribution lies in the separate treatment of misstatement risk and evidence reliability, followed by a traceable link to accounts, assertions, evidence sources, specialist input and audit procedures.

Alessio Faccia, S. Tangjitsitcharoen · 0 citations
Jul 2026

The governance of digital convergence: cybersecurity maturity and AI readiness in the European Union

This study aims to investigate the structural alignment between national cybersecurity maturity and government artificial intelligence (AI) readiness across the EU-27. It specifically examines how the statistical relationship between these domains shifts following the 2025 methodological recalibration of the government AI readiness index (GARI), exploring what these changes reveal about the transition from foundational digital strategy to implementation-oriented governance within the European digital regulatory framework. The research uses a comparative quantitative design, integrating the global cybersecurity index (GCI, 2024) with the GARI 2024 and GARI 2025 datasets. The analysis uses Pearson and Spearman correlations, Steiger’s test for comparing dependent overlapping correlations and a two-stage clustering procedure, incorporating hierarchical Ward’s linkage followed by k-means classification, to assess typological stability and national governance profiles. The results indicate that the nexus between cybersecurity maturity and AI readiness remains statistically stable despite the 2025 GARI recalibration. However, pillar-level decomposition reveals that AI readiness is most strongly associated with operational cybersecurity dimensions, specifically capacity development and cooperation, rather than formal legal preparedness. The transition to an implementation-centric framework in 2025 exposes a significant implementation gap among member states, where high structural security scores do not coincide with operational AI resilience or public-sector adoption. This paper contributes new empirical evidence to the debate on digital benchmarking by demonstrating how the recalibration of composite indicators serves as a diagnostic instrument for identifying structural gaps between strategic preparedness and operational capacity. It offers a novel comparative framework for understanding the coevolution of cybersecurity and AI governance as a unified institutional capability within the EU Digital Single Market.

Martin Lnenicka, Jana Medková · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.