Paper Type
Complete
Abstract
Organizations are adopting AI faster than governance and security practices mature, creating gaps for digital risk management. To understand how well the literature aligns with governance and risk frameworks, we constructed a multi-database corpus and applied topic modeling techniques to uncover the hidden structure. The resulting themes cluster around (1) AI for cyber defense and detection, (2) AI-enabled attacks and security vulnerabilities, (3) sector and infrastructure applications, (4) governance, societal issues of AI, and (5) foundational technological enablers of AI. We map these themes to relevant governance and lifecycle guidance and risk management frameworks. Results show that threat/control topics dominate, while governance-societal impact, and AI used for attack appear less, revealing gaps between governance intent and implementable security controls. We discuss implications for policy and present an integrated mapping approach to help organizations bridge technology, processes, and people in AI risk governance.
Paper Number
1742
Recommended Citation
Wei, Wei; Chang, Hsia-ching; and Sha, Kewei, "Bridging AI Governance and Cybersecurity Risk Management: Topic Modeling and Framework-Based Gap Analysis" (2026). AMCIS 2026 Proceedings. 5.
https://aisel.aisnet.org/amcis2026/ai_sigculture/ai_sigculture/5
Bridging AI Governance and Cybersecurity Risk Management: Topic Modeling and Framework-Based Gap Analysis
Organizations are adopting AI faster than governance and security practices mature, creating gaps for digital risk management. To understand how well the literature aligns with governance and risk frameworks, we constructed a multi-database corpus and applied topic modeling techniques to uncover the hidden structure. The resulting themes cluster around (1) AI for cyber defense and detection, (2) AI-enabled attacks and security vulnerabilities, (3) sector and infrastructure applications, (4) governance, societal issues of AI, and (5) foundational technological enablers of AI. We map these themes to relevant governance and lifecycle guidance and risk management frameworks. Results show that threat/control topics dominate, while governance-societal impact, and AI used for attack appear less, revealing gaps between governance intent and implementable security controls. We discuss implications for policy and present an integrated mapping approach to help organizations bridge technology, processes, and people in AI risk governance.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.

Comments
SIG CULTURE