Paper Type
ERF
Abstract
Organizations increasingly emphasize AI in their corporate disclosures, but research has treated this as a single construct, overlooking that AI is directed toward different strategic domains. We draw on Organizational Information Processing Theory and the attack surface framework to theorize that each AI application domain generates a distinct profile of cybersecurity demands, varying along data sensitivity, external interfaces, real-time processing, and governance complexity. Breach risk rises when these demands exceed an organization's monitoring and governance capacity. Using Top2Vec topic modeling on 10-K filings of U.S.-listed organizations, we disaggregate AI strategic emphasis into seven application domains and examine associations with subsequent data breach likelihood. Customer engagement emphasis shows the strongest positive association with breach likelihood, while risk management reveals a theoretically ambiguous relationship. Findings reveal that AI's cybersecurity implications operate through domain-level demand profiles, offering a refined lens on when and where AI strategy elevates breach risk.
Paper Number
1402
Recommended Citation
Jun, Soyoung, "Disaggregating AI Disclosures: Domain Emphasis and Breach Risk" (2026). AMCIS 2026 Proceedings. 11.
https://aisel.aisnet.org/amcis2026/sig_sec/sig_sec/11
Disaggregating AI Disclosures: Domain Emphasis and Breach Risk
Organizations increasingly emphasize AI in their corporate disclosures, but research has treated this as a single construct, overlooking that AI is directed toward different strategic domains. We draw on Organizational Information Processing Theory and the attack surface framework to theorize that each AI application domain generates a distinct profile of cybersecurity demands, varying along data sensitivity, external interfaces, real-time processing, and governance complexity. Breach risk rises when these demands exceed an organization's monitoring and governance capacity. Using Top2Vec topic modeling on 10-K filings of U.S.-listed organizations, we disaggregate AI strategic emphasis into seven application domains and examine associations with subsequent data breach likelihood. Customer engagement emphasis shows the strongest positive association with breach likelihood, while risk management reveals a theoretically ambiguous relationship. Findings reveal that AI's cybersecurity implications operate through domain-level demand profiles, offering a refined lens on when and where AI strategy elevates breach risk.
When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.
Comments
SIG SEC