Pith. sign in

REVIEW 4 major objections 4 minor 38 references

Public-sector AI cyber governance fails because adoption outruns governance, and no major framework addresses the resulting gaps: Shadow AI, speed asymmetry, and governance vacuum.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · deepseek-v4-flash

2026-08-01 02:37 UTC pith:E2OXPIFL

load-bearing objection Useful typology and a worthwhile read, but the coverage matrix that drives the main claim has one direct internal inconsistency and ratings that won't reproduce without a coding protocol. the 4 major comments →

arxiv 2607.25368 v1 pith:E2OXPIFL submitted 2026-07-28 cs.AI

AI Deployment and Cyber Governance Failures in Public-Sector Organizations: A Typological Analysis

classification cs.AI
keywords cybersecurity governanceartificial intelligencepublic sectorShadow AIgovernance failurematurity modelspeed asymmetryinstitutional constraints
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

This paper tries to establish that public-sector AI cybersecurity governance fails in a patterned way that existing technical and AI risk frameworks do not capture. The pattern starts with speed asymmetry: employees can adopt a new AI tool in minutes, while governance reform takes months or years, leaving an ungoverned interval where failures accumulate. The paper names ten AI-specific failure causes organized into seven institutional domains, including Shadow AI—employee use of AI tools outside organizational governance awareness—and shows how three pathways (accountability, operational resilience, and compliance) compound one another. Its coverage matrix then rates five major governance frameworks against these causes and finds none addresses Shadow AI, speed asymmetry, or the governance vacuum at the operational specificity the public sector requires. If correct, the finding means governments cannot close the gap with technical controls alone, and the paper supplies functional requirements for a purpose-built AI-enabled cybersecurity maturity model.

Core claim

The central discovery is a demonstrated coverage gap. The paper tests NIST CSF 2.0, ISO/IEC 27001, COBIT, NIST AI RMF, and ISO/IEC 42001 against a ten-cause typology using Full/Partial/None ratings derived from the text of each instrument. Supply chain exposure and data sovereignty are the best-covered causes; Shadow AI gets None from every framework, and speed asymmetry receives None from three and only Partial from NIST AI RMF, while governance vacuum is at best Partial across all five. Taken together, the matrix shows that no instrument addresses Shadow AI, speed asymmetry, or governance vacuum at the operational specificity required for public-sector application. Alongside the matrix, th

What carries the argument

Speed asymmetry is the named construct doing the explanatory work: the structural differential between individual AI adoption velocity and institutional governance reform speed. The paper argues it is not itself a failure type but the master condition that widens the interval between risk emergence and response and amplifies all ten causes. The other load-bearing mechanism is the coverage matrix, a rating procedure that maps each failure cause onto explicit provisions in each framework's text; it is the instrument that produces the paper's central claim. The paper's five-layer conceptual framework (constitutional accountability frame, AI governance and assurance bridge, dual operational doma

Load-bearing premise

The central gap finding assumes the authors' reading of the five framework documents is accurate and complete, and that 'operational specificity required for public sector application' means what their typology says it means; if another coder reads the same provisions differently, the no-instrument-addresses conclusion could change.

What would settle it

Search the text of the five framework instruments (or any later editions) for provisions that name unsanctioned employee AI tool use, detection of unauthorised AI data flows, or a governance mechanism explicitly keyed to the difference between AI adoption speed and reform speed. If a provision is found that the paper's own definitions would rate as Full, the claim that no instrument addresses these causes is empirically wrong.

Watch this falsifier. Get emailed when new claim-graph text bears on it.

Share X Bluesky LinkedIn Reddit HN

If this is right

  • Governments should stop relying on existing cybersecurity and AI governance frameworks as complete answers for AI cyber risk in the public sector; the matrix identifies specific unaddressed causes.
  • Shadow AI needs its own controls—approved-use policy, detection capability, staff reporting mechanisms, and data classification enforcement—since no reviewed framework currently provides them.
  • Speed asymmetry and governance vacuum require mandate redesign and explicit accountability assignment, not just extra technical controls.
  • The typology can be used as a self-assessment instrument, and the matrix can guide targeted investment toward areas like supply chain and data sovereignty where coverage already exists.
  • The paper's functional requirements table gives the specification for building an AI-enabled cybersecurity maturity model for government use.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • If speed asymmetry is the master amplifier, a similar typology should apply to other regulated sectors such as healthcare, finance, and critical infrastructure, where consumer-grade AI adoption outpaces compliance cycles; the paper's public-sector bound may understate the reach of the construct.
  • The coverage matrix is a snapshot of specific instrument editions; as these frameworks are revised, the paper effectively provides a checklist of controls each must add to close the identified gaps.
  • Because the Full/Partial/None ratings are analytical judgements, a natural next test is inter-rater reliability: independent coders reading the same framework texts should reach the same ratings for the central gap finding to be robust.
  • The three-pathway compounding model suggests a measurable prediction: agencies that close the Shadow AI and governance-vacuum gaps should show shorter breach detection and response times and fewer data-sovereignty incidents than comparable agencies that do not; a comparative case study could test that.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. The paper argues that AI-driven cybersecurity governance failure in public-sector organizations is a distinct institutional problem that existing technical risk frameworks and generic AI governance instruments do not address. It proposes a seven-domain typology of ten AI-specific governance failure causes, a three-pathway failure model (accountability, operational resilience, compliance), and a coverage matrix comparing NIST CSF 2.0, ISO/IEC 27001, COBIT, NIST AI RMF, and ISO/IEC 42001 against the typology. The central claim is that no reviewed instrument addresses Shadow AI, speed asymmetry, or governance vacuum at the operational specificity required for public-sector application. The paper also introduces 'speed asymmetry' as a named structural construct and derives functional requirements for an AI-enabled cybersecurity maturity model (Section 6, Table 2).

Significance. If the central coverage-matrix finding is valid, the paper makes a useful contribution by integrating three previously separate research streams—AI cybersecurity risk, public-sector governance, and framework adequacy—and by providing a concrete agenda for public-sector AI governance. The typology is well organized, the limitations are explicitly acknowledged (Section 7), and the requirements table (Table 2) is a practical output. The paper does not ship machine-checked proofs or code, but it does offer a falsifiable mapping: the Full/Partial/None ratings in Table 1 can be checked against framework texts. That testability is a strength, but it also exposes the main risk: the central conclusion rests entirely on ratings generated by the authors' analytical judgement, with no coding protocol or inter-rater checks, and at least one rating appears internally inconsistent with the paper's own Section 3 argument. The contribution is therefore promising but not yet robust enough for publication without substantial revision.

major comments (4)
  1. [§5, Table 1 and §3] Table 1 rates ISO/IEC 27001 as 'Full' for 'Supply chain exposure', but Section 3 explicitly claims that existing supply chain frameworks, including 'ISO 27001 supplier controls, were designed for software acquisition, not live model inference accessed through API subscriptions', identifying a governance gap specific to AI-as-a-service. A framework whose relevant controls are argued to be insufficient for AI delivery cannot receive the highest coverage rating for that cause under the paper's own definitions. This internal contradiction undermines the reliability of the coverage matrix. The authors should either revise the Section 3 claim or downgrade the Table 1 rating to 'Partial' with clause-level justification.
  2. [§5, Table 1, §7 Limitations] The central conclusion—'no instrument addresses Shadow AI, speed asymmetry, or governance vacuum at the operational specificity required'—rests entirely on the Full/Partial/None ratings in Table 1. The paper's own limitations section admits these 'represent analytical judgements based on published framework documentation' with no coding protocol, no inter-rater reliability assessment, and no defined threshold for 'operational specificity'. This is load-bearing because a different coding rule could change the headline rows. For example, ISO/IEC 27001 A.5.23 ('Information security for use of cloud services') and A.5.9 (asset inventory) are relevant general guidance for controlling Shadow AI, which under the paper's own definition of 'Partial' would make Shadow AI 'Partial', not 'None'. Similarly, NIST CSF 2.0 ID.AM could be argued to partially address Shadow AI. If any of these three headl
  3. [Abstract, §5, Conclusion] The paper repeatedly states that 'no instrument addresses Shadow AI, speed asymmetry, or governance vacuum', but Table 1 itself gives 'Partial' for governance vacuum across all five frameworks and 'Partial' for speed asymmetry for NIST AI RMF. This wording overstates the evidence. The accurate claim, supported by the matrix, is that no instrument provides 'operational specificity' as defined by the authors—but the definition of that threshold is never given. Without a clear criterion for what separates 'Partial' from 'Full' in terms of operational specificity, the central conclusion is not falsifiable. The authors should either define the threshold explicitly or soften the claim to say that no instrument provides sufficiently operational controls for these causes.
  4. [§3, Typology construction] The typology is presented as the external criterion set against which frameworks are tested. The paper states that databases and search terms were used and that causes were retained only when 'traceable to documented evidence and attributable to a mechanism distinct from all others', but it provides no inclusion/exclusion counts, no screening procedure, no quality appraisal of sources, and no discussion of how the final set of ten causes was determined to be complete. If the typology is incomplete, the coverage matrix could miss frameworks that address omitted causes, and the 'no instrument addresses' finding would be an artifact of the typology's boundaries. This is a standard concern for typological reviews; it should be addressed by documenting the review protocol more transparently or by explicitly reframing the typology as a preliminary, non-exhaustive analytical instrument.
minor comments (4)
  1. [§5, Table 1 caption] The manuscript contains the placeholder text 'Table captions should be placed above the tables.' This must be replaced with a proper descriptive caption.
  2. [§3, Speed asymmetry] The paper claims speed asymmetry is a 'named theoretical construct with a specified mechanism', but the mechanism is described only narratively (the differential between adoption velocity and reform speed). A formal definition with measurable components (e.g., typical adoption time vs. policy revision cycle) would strengthen the claim of theoretical novelty and testability.
  3. [§5, Rating definitions] The definitions of Full/Partial/None are brief. The phrase 'relevant general guidance requiring substantial organizational adaptation' is vague and leaves room for wide interpretation. Providing examples of what counts as 'substantial' would improve replicability.
  4. [§7, 'External criterion set'] The paper contrasts its coverage matrix with 'self-assessment against each framework's own stated objectives'. The term 'external criterion set' is appropriate, but it should be clarified that the criteria come from the authors' literature-derived typology, not from an independent standard; otherwise readers may over-interpret the objectivity of the matrix.

Circularity Check

0 steps flagged

No significant circularity; central gap claim rests on acknowledged analytical judgments, not on a derivation forced by definition.

full rationale

The paper's derivation chain runs from a literature-based typology (Section 3) through a coverage matrix (Section 5) to the conclusion that no instrument addresses Shadow AI, speed asymmetry, or governance vacuum at the required public-sector specificity. No equations or fitted parameters are involved. The matrix uses stated criteria: "Full: explicit operational controls or accountability structures for the cause. Partial: relevant general guidance requiring substantial organizational adaptation. None: no relevant provision identified in the framework text." The authors explicitly acknowledge analytical judgment in the Limitations: "The coverage matrix assessments represent analytical judgements based on published framework documentation; practitioners may achieve different coverage levels through supplementary guidance and organizational adaptation." This is an evidence-quality limitation, not circularity: under the stated criteria the frameworks could have scored differently or the same, and the conclusion is not entailed by the definitions alone. There is an internal inconsistency between Section 3, which says ISO 27001 supplier controls were designed for software acquisition rather than AI-as-a-service, and Table 1, which gives ISO 27001 "Full" for supply chain exposure; that undermines confidence in the rating but does not make it circular. Speed asymmetry is named in this paper, but the paper checks for a substantive temporal-governance mechanism rather than requiring the label to appear, e.g., NIST AI RMF receives Partial because GV.OC-04 addresses keeping pace with AI evolution. No self-citations are load-bearing and no uniqueness theorem is imported. The derivation is therefore self-contained; the main risk is validity/reproducibility of the manual ratings, not circularity.

Axiom & Free-Parameter Ledger

0 free parameters · 5 axioms · 1 invented entities

No numerical fitting is performed; the analytic choices are the 10 causes, 7 domains, 3 pathways, 5 layers, and the Full/Partial/None ratings, all set by author judgment. The main invented construct is speed asymmetry, which lacks independent measurement.

axioms (5)
  • domain assumption Public-sector organizations operate under democratic accountability, fixed procurement cycles, and civil service staffing constraints that slow governance reform relative to AI adoption.
    Introduced in Section 2 and attributed to Christou [8] and NAO [21]; adopted as background truth without direct empirical test in this paper.
  • domain assumption Vendor/industry surveys (UpGuard 2025, SANS 2025, ISC2 2024) accurately represent public-sector AI usage and security-operations conditions.
    Used in Section 3 to establish prevalence of Shadow AI, alert fatigue, and literacy deficit; these are non-peer-reviewed industry reports whose generalizability to government is assumed.
  • ad hoc to paper The set of ten failure causes retained through the stated selection rule is complete and distinct.
    Section 3 states causes were retained when 'traceable to documented evidence' and 'distinct from all others,' but no systematic search protocol or proof of coverage is provided, so completeness is an authorial assertion.
  • domain assumption The five selected frameworks are the operative governance instruments for public-sector AI cybersecurity, and their published texts are sufficient to assess coverage.
    Section 5 chooses NIST CSF 2.0, ISO/IEC 27001, COBIT, NIST AI RMF, and ISO/IEC 42001 and rates them from text; there is no demonstration that these are the instruments government organizations actually use, nor that supplementary guidance is irrelevant.
  • ad hoc to paper Typological synthesis from literature constitutes an 'external criterion set' for testing framework coverage.
    The paper states the coverage matrix is an external test rather than self-assessment (Section 1), but the criteria are the authors' own constructs; this is an internal analytical standard, not an external benchmark.
invented entities (1)
  • speed asymmetry (named structural construct) no independent evidence
    purpose: Names the differential between individual AI adoption speed and institutional governance reform speed, and claims it amplifies all other failure causes.
    The paper acknowledges prior literature observed the governance-adoption lag but says naming/mechanizing it is original (Sections 1 and 3). No measurement protocol, indicator, or dataset is given, so the construct has no falsifiable handle outside the paper.

pith-pipeline@v1.3.0-alltime-deepseek · 10243 in / 13182 out tokens · 127584 ms · 2026-08-01T02:37:15.922689+00:00 · methodology

0 comments
Cite this review

Pith. "Pith review of AI Deployment and Cyber Governance Failures in Public-Sector Organizations: A Typological Analysis." pith.science (2026). https://pith.science/paper/E2OXPIFL

@misc{pith2026260725368,
  author       = {Pith},
  title        = {Pith review of: AI Deployment and Cyber Governance Failures in Public-Sector Organizations: A Typological Analysis},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/E2OXPIFL}},
  note         = {Machine review of arXiv:2607.25368}
}
Share X Bluesky LinkedIn Reddit HN
read the original abstract

The intersection of artificial intelligence adoption, cybersecurity governance, and public sector institutional constraints has not been examined as a unified analytical problem in the existing literature. Studies address AI cybersecurity risks generically, public sector governance independently, and framework adequacy separately. Existing studies have not integrated these three streams to explain specifically how AI adoption causes cybersecurity governance failure in government organizations, nor test existing governance instruments against AI-specific public sector failure causes. This paper ad-dresses that gap. It proposes a seven-domain typology identifying ten specific AI-driven cyber governance failure causes grounded in public sector institutional analysis. It presents a three-pathway failure model showing how accountability failure, opera-tional resilience failure, and compliance failure interact and reinforce each other. It de-livers a structured coverage matrix testing five major governance frameworks (NIST CSF 2.0, ISO/IEC 27001, COBIT, NIST AI RMF, and ISO/IEC 42001) against the typology, finding that no instrument addresses Shadow AI, speed asymmetry, or gov-ernance vacuum at the operational specificity required for public sector application. The paper introduces speed asymmetry as a named structural construct with a specified mechanism. The framework provides the design specification for an AI-enabled cyber-security maturity model for government organizations.

Figures

Figures reproduced from arXiv: 2607.25368 by Fida Hasan, James Rooney, Md Salahuddin.

Figure 1
Figure 1. Figure 1: AI as a disruptive force across the two-domain public sector governance architecture, with ten cross-cutting failures causes as mediating tensions. Capacity overload is a structural quantitative mismatch between cybersecurity unit staffing and AI-era threat volumes [24, 25]. Cybersecurity unit staffing is calibrated to pre-AI threat volumes and incident categories. AI deployments increase security alert fr… view at source ↗
Figure 2
Figure 2. Figure 2: Five-layer AI governance framework for public-sector organizations, showing the relationship between democratic accountability, AI assurance, cy￾bersecurity governance, public-service delivery, cross-cutting failure causes, and foundation enablers and constraints [PITH_FULL_IMAGE:figures/full_fig_p011_2.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

38 extracted references · 7 canonical work pages

  1. [1]

    Cabinet Office, London (2023, updated January 2024)

    UK Cabinet Office, Government Digital Service, Central Digital and Data Office: Guidance to Civil Servants on Use of Generative AI. Cabinet Office, London (2023, updated January 2024). https://www.gov.uk/government/publications/guidance -to-civil-servants-on-use-of- generative-ai/guidance-to-civil-servants-on-use-of-generative-ai

  2. [2]

    ASD, Canberra (2024)

    Australian Signals Directorate: Guidelines for the Use of Artificial Intelligence in Govern- ment Systems. ASD, Canberra (2024)

  3. [3]

    NCSC (2023)

    UK National Cyber Security Centre: Guidelines for Secure AI System Development. NCSC (2023). https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development

  4. [4]

    NIST, Gaithersburg, MD (2024)

    National Institute of Standards and Technology: Cybersecurity Framework 2.0. NIST, Gaithersburg, MD (2024). https://doi.org/10.6028/NIST.CSWP.29 AI Deployment and Cyber Governance Failures in Public -Sector Organizations 15

  5. [5]

    ISO, Geneva (2022)

    International Organization for Standardization: ISO/IEC 27001:2022 — Information Secu- rity, Cybersecurity and Privacy Protection. ISO, Geneva (2022)

  6. [6]

    ISACA, Schaumburg (2019)

    ISACA: COBIT 2019 Framework: Governance and Management Objectives. ISACA, Schaumburg (2019)

  7. [7]

    Von Solms, R., Van Niekerk, J.: From information security to cyber security. Comput. Se- cur. 38, 97–102 (2013). https://doi.org/10.1016/j.cose.2013.04.004

  8. [8]

    Springer, Cham (2016)

    Christou, G.: Cybersecurity in the European Union: Resilience and Adaptability in Govern- ance Policy. Springer, Cham (2016)

  9. [9]

    Frandell, A., Feeney, M.: Cybersecurity threats in local government: a sociotechnical per- spective. Am. Rev. Public Admin. 52(8), 558 –572 (2022). https://doi.org/10.1177/02750740221125432

  10. [10]

    OECD Digital Government Studies, OECD Pub- lishing, Paris (2024)

    OECD: Generative AI in the Public Sector. OECD Digital Government Studies, OECD Pub- lishing, Paris (2024). https://www.oecd.org/en/publications/generative-ai-in-the-public-sec- tor_b4e89d81-en.html

  11. [11]

    In: ECIS 2015 Completed Re- search Papers, Paper 108, Association for Information Systems (2015)

    Köffer, S., Anlauf, L., Ortbach, K., Niehaves, B.: The intensified blurring of boundaries between work and private life through IT consumerisation. In: ECIS 2015 Completed Re- search Papers, Paper 108, Association for Information Systems (2015). https://aisel.aisnet.org/ecis2015_cr/108/

  12. [12]

    ISO, Geneva (2023)

    International Organisation for Standardisation: ISO/IEC 42001:2023 — Artificial Intelli- gence Management System. ISO, Geneva (2023)

  13. [13]

    et al.: Artificial intelligence in cyber security: research advances, challenges, and opportunities

    Zhang, Z. et al.: Artificial intelligence in cyber security: research advances, challenges, and opportunities. Artif. Intell. Rev. 55(2), 1029 –1053 (2022). https://doi.org/10.1007/s10462- 021-09976-0

  14. [14]

    AI Ethics 5(2), 883–910 (2025)

    Malatji, M., Tolah, A.: Artificial intelligence cybersecurity dimensions: a comprehensive framework for understanding adversarial and offensive AI. AI Ethics 5(2), 883–910 (2025). https://doi.org/10.1007/s43681-024-00427-4

  15. [15]

    NSA Cybersecurity Information Sheet, Washington, D.C

    National Security Agency (NSA), CISA, FBI et al.: Deploying AI Systems Securely: Best Practices for Deploying Secure and Resilient AI Systems. NSA Cybersecurity Information Sheet, Washington, D.C. (2024). https://www.cisa.gov/news- events/alerts/2024/04/15/joint-guidance-deploying-ai-systems-securely

  16. [16]

    Verizon Enterprise Solutions (2024)

    Verizon: Data Breach Investigations Report. Verizon Enterprise Solutions (2024). https://www.verizon.com/business/resources/reports/dbir

  17. [17]

    Becker, J., Knackstedt, R., Pöppelbuß, J.: Developing maturity models for IT management. Bus. Inf. Syst. Eng. 1(3), 213–222 (2009). https://doi.org/10.1007/s12599-009-0044-5

  18. [18]

    Procedia Comput

    Proença, D., Borbinha, J.: Maturity models for information systems — a state of the art. Procedia Comput. Sci. 100, 1044–1051 (2016). https://doi.org/10.1016/j.procs.2016.09.279

  19. [19]

    NIST AI 100-1 (2023)

    National Institute of Standards and Technology: Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1 (2023). https://doi.org/10.6028/NIST.AI.100-1

  20. [20]

    OECD Public Governance Policy Papers, No

    OECD: 2023 OECD Digital Government Index: Results and Key Findings. OECD Public Governance Policy Papers, No. 44, OECD Publishing, Paris (2024). https://doi.org/10.1787/1a89ed5e-en

  21. [21]

    National Audit Office: Digital Transformation in Government: Addressing the Barriers to Efficiency. HC 1171. NAO, London (2023). https://www.nao.org.uk/reports/digital -trans- formation-in-government-addressing-the-barriers/

  22. [22]

    arXiv:2305.06972 (2023)

    Hazell, J.: Spear Phishing With Large Language Models. arXiv:2305.06972 (2023). https://arxiv.org/abs/2305.06972

  23. [23]

    UpGuard Re- search Report (2025)

    UpGuard: The State of Shadow AI: Usage, Risks and Enterprise Governance. UpGuard Re- search Report (2025). https://www.upguard.com/resources/the-state-of-shadow-ai 16 M.Salahuddin et al

  24. [24]

    ISC2, Clearwater, FL (2024)

    ISC2: Cybersecurity Workforce Study 2024. ISC2, Clearwater, FL (2024). https://www.isc2.org/Research/Workforce-Study

  25. [25]

    SANS Insti- tute (2025)

    SANS Institute: 2025 SOC Survey: The State of Security Operations Centres. SANS Insti- tute (2025)

  26. [26]

    arXiv:2604.06215 (2026)

    Xavier, F.C.: Governing frontier general-purpose AI in the public sector: adaptive risk man- agement and policy capacity under uncertainty through 2030. arXiv:2604.06215 (2026). https://arxiv.org/abs/2604.06215

  27. [27]

    In: Proceedings of the 1st Workshop for Research on Agent Language Models (REALM 2025), Association for Computational Linguistics (2025)

    Schmitz, C., Rystrøm, J., Batzner, J.: Oversight structures for agentic AI in public -sector organisations. In: Proceedings of the 1st Workshop for Research on Agent Language Models (REALM 2025), Association for Computational Linguistics (2025). arXiv:2506. 04836. https://arxiv.org/abs/2506.04836

  28. [28]

    In: AI for Public Missions Workshop, AAAI 2025

    Lee, K., Kim, H., Whang, J.J.: SAIF: A comprehensive framework for evaluating the risks of generative AI in the public sector. In: AI for Public Missions Workshop, AAAI 2025. arXiv:2501.08814 (2025). https://arxiv.org/abs/2501.08814

  29. [29]

    NIST SP 800 -161r1

    National Institute of Standards and Technology: Cybersecurity Supply Chain Risk Manage- ment Practices for Systems and Organisations. NIST SP 800 -161r1. NIST, Gaithersburg, MD (2022). https://doi.org/10.6028/NIST.SP.800-161r1

  30. [30]

    Computer

    Silic, M., Back, A.: Shadow IT — a view from behind the curtain. Computer. Security. 45, 274–283 (2014). https://doi.org/10.1016/j.cose.2014.06.003

  31. [31]

    Wirtz, B.W., Weyerer, J.C., Geyer, C.: Artificial intelligence and the public sector — appli- cations and challenges. Int. J. Public Adm. 42(7), 596 –615 (2019). https://doi.org/10.1080/01900692.2018.1498103

  32. [32]

    Diakopoulos, N.: Accountability in algorithmic decision making. Commun. ACM 59(2), 56–62 (2016). https://doi.org/10.1145/2844110

  33. [33]

    Goddard, K., Roudsari, A., Wyatt, J.C.: Automation bias: a systematic review of frequency, effect mediators, and mitigators. J. Am. Med. Inform. Assoc. 19(1), 121 –127 (2012). https://doi.org/10.1136/amiajnl-2011-000089

  34. [34]

    Policy Soc

    Taeihagh, A.: Governance of artificial intelligence. Policy Soc. 40(2), 137 –157 (2021). https://doi.org/10.1080/14494035.2021.1929693

  35. [35]

    Zuiderwijk, A., Chen, Y.C., Salem, F.: Implications of the use of artificial intelligence in public governance: a systematic literature review and a research agenda. Gov. Inf. Q. 38(3), 101577 (2021). https://doi.org/10.1016/j.giq.2021.101577

  36. [36]

    Van Noordt, C., Misuraca, G.: Artificial intelligence for the public sector: results of land- scaping the use of AI in government across the European Union. Gov. Inf. Q. 39(3), 101714 (2022). https://doi.org/10.1016/j.giq.2022.101714

  37. [37]

    Valle-Cruz, D., García -Contreras, R., Gil -Garcia, J.R.: Exploring the negative impacts of artificial intelligence in government: the dark side of intelligent algorithms and cognitive machines. Int. Rev. Adm. Sci. 90(1), 99 –116 (2024). https://doi.org/10.1177/00208523231187051

  38. [38]

    From Shadow It to Shadow AI –Threats, Risks and Opportunities for Organizations

    Silic, M., D. Silic, and K. Kind -Trüller. 2025. “From Shadow It to Shadow AI –Threats, Risks and Opportunities for Organizations.” Strategic Change1 –16. https://doi.org/10.1002/jsc.2682