← Latest papers
🤖 AI

AI Deployment and Cyber Governance Failures in Public-Sector Organizations: A Typological Analysis

This paper addresses the literature gap regarding AI-driven cybersecurity failures in public-sector organizations by proposing a seven-domain typology and three-pathway failure model to demonstrate that existing governance frameworks inadequately address critical issues like Shadow AI and speed asymmetry, thereby providing a design specification for a new AI-enabled cybersecurity maturity model.

Original authors: Md Salahuddin, James Rooney, Fida Hasan

Published 2026-07-29
📖 4 min read☕ Coffee break read

Original authors: Md Salahuddin, James Rooney, Fida Hasan

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the world of computer security as a giant, high-stakes game of chess played by governments. For decades, the players have been trying to protect their "king" (citizen data) from sneaky "knights" (hackers) using a set of established rules called governance. These rules tell the government how to buy new tools, who is in charge of fixing problems, and how to make sure no one cheats. But recently, a new, wild card has been shuffled into the deck: Artificial Intelligence (AI). This isn't just a new chess piece; it's like a robot that can learn the game faster than the human players can write the rulebook. The big question everyone is asking is: When governments start using these super-fast, super-smart AI tools, do their old safety rules still work, or does the whole game fall apart? This paper dives into that exact mess, looking at why governments are struggling to keep their AI use safe and what happens when the rules can't keep up with the robots.

The authors of this study, Md Salahuddin, James Rooney, and Fida Hasan, argue that the problem isn't just that AI is tricky; it's that the government's "rulebook" is moving at a completely different speed than the technology itself. They call this Speed Asymmetry. Think of it like this: imagine a teenager can download a new, super-cool app on their phone in about five minutes. But for the government to write a law saying whether that app is safe or not, it takes years of meetings, debates, and paperwork. In that gap between "five minutes" and "years," there is a dangerous, unguarded zone where things can go wrong.

The paper suggests that because of this speed gap, a specific type of trouble is happening called Shadow AI. This is when government employees, trying to get their work done faster, start using AI tools that the government doesn't know about or approve of. It's like a student bringing a hidden calculator into a math exam. The problem is that these hidden tools might be sending secret government data to foreign servers, creating a massive leak that no one is watching. The authors found that current safety checklists and rules (like the ones from NIST or ISO) are largely ineffective against this. They are like a map of a city that was drawn ten years ago; they show the old streets, but they don't show the new, secret tunnels the AI is digging right now.

The researchers built a new "map" of the problem, identifying ten specific reasons why AI governance fails in the public sector. They grouped these into seven domains, which are like different rooms in a house where the trouble can start. For example, one room is "Procurement," where the government buys things. The paper says the rules for buying AI are missing entirely, so the government is buying tools without checking if they are safe. Another room is "Workforce," where employees might be too tired or confused to use AI correctly, leading to Alert Fatigue—a state where security guards are so overwhelmed by false alarms that they miss the real danger.

The paper also introduces a "Three-Pathway Failure Model." Imagine a house where the plumbing, the electricity, and the locks are all connected. If the plumbing bursts (Accountability Failure), the electricity shorts out (Operational Resilience Failure), and the locks break (Compliance Failure). The authors show that these three failures feed into each other, making the whole system collapse faster than anyone expected. They tested five major existing safety frameworks against their new map and found a critical result: none of them have specific rules for Shadow AI or Speed Asymmetry. While some frameworks offer partial guidance on the "Governance Vacuum" (the empty space where no one knows who is in charge) and full coverage on supply chain risks, they completely lack the specific operational controls needed to manage unsanctioned AI use and the speed gap itself.

So, what's the solution? The authors don't claim to have a magic fix, but they propose a new design for a "Maturity Model." Think of this as a new, dynamic rulebook that changes as fast as the technology does. It would require governments to constantly check what AI tools their employees are using, hire more people to manage the alerts, and rewrite their laws to cover these new risks. The paper suggests that until governments stop treating AI as just another computer program and start treating it as a structural challenge that breaks their old rules, they will keep facing these governance failures. The key takeaway is that you can't just patch the software; you have to redesign the entire house to handle the new, faster, and more unpredictable guests.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →