Ethical Governance of AI-Driven Information Security: Balancing Data Privacy, Cyber Resilience, and Digital Trust in Organizations
Cyber threats represent a critical risk to global organisations, with cybercrime damages projected to exceed USD 10.5 trillion annually by 2025. Consequently, enterprises are rapidly adopting Artificial Intelligence (AI) to augment their security architectures, as traditional, rule based Security Information Systems (SIS) struggle to mitigate sophisticated, multi stage attacks. However, the application of AI in security raises significant ethical questions around data privacy, algorithmic transparency, and the balance between automated surveillance and civil liberties. As a conceptual paper, this study investigates how businesses can govern AI-Driven security solutions by bridging the theoretical divide between technical efficacy and ethical responsibility. To build this theoretical foundation, a systematic review of 32 peer reviewed articles was conducted using the PRISMA paradigm, synthesizing existing evidence across four core governance dimensions: technical performance, stakeholder accountability, regulatory compliance, and organisational process. Our conceptual analysis reveals a persistent "principles to practices gap"; while AI based SIS significantly outperform traditional systems in anomaly detection and incident response, these technological advancements have outpaced the operationalization of ethical norms within organisations. To address this gap, the paper proposes a novel, unified governance framework centred on digital trust. This model distinctly integrates the AI Trust Framework and Maturity Model (AI TMM), the Tiered Ethical Cybersecurity Model (TECM), and privacy preserving technologies such as federated learning to operationalize ethics by design. The article concludes with actionable policy pathways for legislators, organisational leaders, and researchers to increase cyber resilience while strictly respecting individual privacy rights.