Paper Type

Complete

Abstract

Organizations are adopting AI faster than governance and security practices mature, creating gaps for digital risk management. To understand how well the literature aligns with governance and risk frameworks, we constructed a multi-database corpus and applied topic modeling techniques to uncover the hidden structure. The resulting themes cluster around (1) AI for cyber defense and detection, (2) AI-enabled attacks and security vulnerabilities, (3) sector and infrastructure applications, (4) governance, societal issues of AI, and (5) foundational technological enablers of AI. We map these themes to relevant governance and lifecycle guidance and risk management frameworks. Results show that threat/control topics dominate, while governance-societal impact, and AI used for attack appear less, revealing gaps between governance intent and implementable security controls. We discuss implications for policy and present an integrated mapping approach to help organizations bridge technology, processes, and people in AI risk governance.

Paper Number

1742

Comments

SIG CULTURE

Share

COinS
Top 25 Paper Badge
 
Aug 15th, 12:00 AM

Bridging AI Governance and Cybersecurity Risk Management: Topic Modeling and Framework-Based Gap Analysis

Organizations are adopting AI faster than governance and security practices mature, creating gaps for digital risk management. To understand how well the literature aligns with governance and risk frameworks, we constructed a multi-database corpus and applied topic modeling techniques to uncover the hidden structure. The resulting themes cluster around (1) AI for cyber defense and detection, (2) AI-enabled attacks and security vulnerabilities, (3) sector and infrastructure applications, (4) governance, societal issues of AI, and (5) foundational technological enablers of AI. We map these themes to relevant governance and lifecycle guidance and risk management frameworks. Results show that threat/control topics dominate, while governance-societal impact, and AI used for attack appear less, revealing gaps between governance intent and implementable security controls. We discuss implications for policy and present an integrated mapping approach to help organizations bridge technology, processes, and people in AI risk governance.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.