Paper Type

Complete

Abstract

Artificial intelligence (AI) has shifted from boardroom aspiration to organizational imperative, yet governance readiness lags deployment pace. Drawing on dynamic capabilities and institutional decoupling, we investigate how trust readiness (governance capability) and integration readiness (implementation capability) shape AI governance outcomes. Triangulating MITRE ATLAS, the AI Incident Database, and the U.S. Federal AI Use Case Inventory (1,757 deployments), our analysis reveals governance theater: a majority of AI deployments report internal review approval, yet only a small fraction report substantive safeguards. Risk-tiering does not rescue governance depth. Splitting trust readiness uncovers a suppression effect: surface approvals facilitate deployment while substantive safeguards dampen it. Integration readiness remains the dominant predictor of operational deployment. Evaluability constraints—limits on control rights and system access in vendor-developed systems—emerge as a structural antecedent of governance failure. These findings offer IS researchers a replicable framework for governance gap analysis and provide CIOs with actionable guidance on bundle-based capability building and procurement governance.

Paper Number

1743

Comments

SIG OSRA

Share

COinS
 
Aug 15th, 12:00 AM

Governance Readiness Gaps in Organizational AI Deployment: A Triangulated Analysis of Threats, Incidents, and Practice

Artificial intelligence (AI) has shifted from boardroom aspiration to organizational imperative, yet governance readiness lags deployment pace. Drawing on dynamic capabilities and institutional decoupling, we investigate how trust readiness (governance capability) and integration readiness (implementation capability) shape AI governance outcomes. Triangulating MITRE ATLAS, the AI Incident Database, and the U.S. Federal AI Use Case Inventory (1,757 deployments), our analysis reveals governance theater: a majority of AI deployments report internal review approval, yet only a small fraction report substantive safeguards. Risk-tiering does not rescue governance depth. Splitting trust readiness uncovers a suppression effect: surface approvals facilitate deployment while substantive safeguards dampen it. Integration readiness remains the dominant predictor of operational deployment. Evaluability constraints—limits on control rights and system access in vendor-developed systems—emerge as a structural antecedent of governance failure. These findings offer IS researchers a replicable framework for governance gap analysis and provide CIOs with actionable guidance on bundle-based capability building and procurement governance.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.