Skip to content
Review Open access

Governance, risk, and compliance frameworks for AI Security: A review of emerging standards and challenges

Jul 2026 · Magna Scientia Advanced Research and Reviews · 0 citations

TL;DR

This paper reviews emerging AI-GRC frameworks and regulations, including the OECD AI Principles, ISO/IEC 42001, the NIST AI Risk Management Framework, and the EU AI Act, alongside industry standards from Microsoft, Google, and IBM, to reveal a fragmented ecosystem with overlapping principles but inconsistent enforcement and technical depth.

Abstract

Artificial intelligence (AI) adoption is accelerating across industries, introducing novel governance, risk, and compliance (GRC) challenges that traditional cybersecurity frameworks cannot fully address. Standards such as ISO/IEC 27001 and the NIST Risk Management Framework safeguard IT assets but do not comprehensively mitigate AI-specific risks like adversarial attacks, model drift, and ethical concerns such as fairness and accountability. This gap raises critical questions about how organizations can govern AI responsibly while maintaining security and compliance. This paper reviews emerging AI-GRC frameworks and regulations, including the OECD AI Principles, ISO/IEC 42001, the NIST AI Risk Management Framework, and the EU AI Act, alongside industry standards from Microsoft, Google, and IBM. Through comparative analysis, we examine how these frameworks address governance structures, risk assessment methodologies, compliance mechanisms, and transparency requirements. We also explore integration strategies with existing cybersecurity and enterprise risk models. Our findings reveal a fragmented ecosystem with overlapping principles but inconsistent enforcement and technical depth. While global standards emphasize values such as transparency and accountability, operational guidance on adversarial robustness and lifecycle risk monitoring remains limited. The review identifies best practices for embedding GRC into AI development pipelines, including continuous monitoring, documentation artifacts, and risk-tiering strategies. It also highlights gaps in interoperability, audit tooling, and liability regimes. This research speaks to policymakers, compliance officers, cybersecurity professionals, and AI developers seeking harmonized governance approaches. Future work should prioritize unified audit standards, empirical evaluation of governance effectiveness, and integration of AI risk metrics into ESG reporting to ensure trustworthy and sustainable AI deployment.

Read PDF

Similar papers

Review Open access 2026

Ethical Governance of AI-Driven Information Security: Balancing Data Privacy, Cyber Resilience, and Digital Trust in Organizations

Cyber threats represent a critical risk to global organisations, with cybercrime damages projected to exceed USD 10.5 trillion annually by 2025. Consequently, enterprises are rapidly adopting Artificial Intelligence (AI) to augment their security architectures, as traditional, rule based Security Information Systems (SIS) struggle to mitigate sophisticated, multi stage attacks. However, the application of AI in security raises significant ethical questions around data privacy, algorithmic transparency, and the balance between automated surveillance and civil liberties. As a conceptual paper, this study investigates how businesses can govern AI-Driven security solutions by bridging the theoretical divide between technical efficacy and ethical responsibility. To build this theoretical foundation, a systematic review of 32 peer reviewed articles was conducted using the PRISMA paradigm, synthesizing existing evidence across four core governance dimensions: technical performance, stakeholder accountability, regulatory compliance, and organisational process. Our conceptual analysis reveals a persistent "principles to practices gap"; while AI based SIS significantly outperform traditional systems in anomaly detection and incident response, these technological advancements have outpaced the operationalization of ethical norms within organisations. To address this gap, the paper proposes a novel, unified governance framework centred on digital trust. This model distinctly integrates the AI Trust Framework and Maturity Model (AI TMM), the Tiered Ethical Cybersecurity Model (TECM), and privacy preserving technologies such as federated learning to operationalize ethics by design. The article concludes with actionable policy pathways for legislators, organisational leaders, and researchers to increase cyber resilience while strictly respecting individual privacy rights.

Muhammad Faris bin Nordin, Muhammad Din bin Khalid, Normal Mat Jusoh · 0 citations
Open access Jul 2026

Analysis of systems-level ethical AI compliance architecture for U.S. corporations: Integrating governance, risk management, and automated accountability

The purpose of this study is to analyze the systems-level ethical AI compliance architecture for corporations in the US by integrating governance frameworks, risk management systems, automated accountability mechanisms, and legal alignment strategies. This study examines the rapid transformation of the ways that corporations operate due to these AI technologies, concurrent with ethical, legal, and operational challenges involving algorithmic bias, privacy breaches, cybersecurity risk, and transparency. Results showed that various governance models, including the National Institute of Standards and Technology AI Risk Management Framework (AI RMF), enhance organizational accountability, transparency, and regulatory compliance. Compliance-by-design measures, explainable AI systems, and automated auditing technologies also strengthen AI governance and regulatory adherence. The study also found that integrated ethical AI compliance architectures are critical for innovation in the responsible application of cutting-edge technologies, organizational sustainability, stakeholder trust, and long-term corporate resilience as businesses operate in an increasingly technology-driven environment. Keywords: Artificial Intelligence Governance, Ethical AI Compliance, Risk Management, Automated Accountability, Legal Alignment.

Joy Oluchi Nwachukwu, Thaddaeuse Odhiambo, Dorcas Akorkor Apaflo et al. · 0 citations
Preprint Jul 2026

AI Deployment and Cyber Governance Failures in Public-Sector Organizations: A Typological Analysis

The intersection of artificial intelligence adoption, cybersecurity governance, and public sector institutional constraints has not been examined as a unified analytical problem in the existing literature. Studies address AI cybersecurity risks generically, public sector governance independently, and framework adequacy separately. Existing studies have not integrated these three streams to explain specifically how AI adoption causes cybersecurity governance failure in government organizations, nor test existing governance instruments against AI-specific public sector failure causes. This paper ad-dresses that gap. It proposes a seven-domain typology identifying ten specific AI-driven cyber governance failure causes grounded in public sector institutional analysis. It presents a three-pathway failure model showing how accountability failure, opera-tional resilience failure, and compliance failure interact and reinforce each other. It de-livers a structured coverage matrix testing five major governance frameworks (NIST CSF 2.0, ISO/IEC 27001, COBIT, NIST AI RMF, and ISO/IEC 42001) against the typology, finding that no instrument addresses Shadow AI, speed asymmetry, or gov-ernance vacuum at the operational specificity required for public sector application. The paper introduces speed asymmetry as a named structural construct with a specified mechanism. The framework provides the design specification for an AI-enabled cyber-security maturity model for government organizations.

Muflihah Salahuddin, James Rooney, Fida Hasan · 0 citations
Open access Jul 2026

Data Governance, Bias Mitigation, And Legal Risk: A Holistic AI Compliance Framework for U.S. Companies in High Stakes Sectors

It is concluded that a holistic AI compliance framework integrating data governance, bias mitigation strategies, legal oversight, cybersecurity, and ethical accountability is essential for ensuring responsible and trustworthy AI deployment in high-stakes environments.

Joy Oluchi Nwachukwu, Thaddaeuse Odhiambo, Dorcas Akorkor Apaflo et al. · 0 citations
Open access Jul 2026

Architecting Privacy by Design Frameworks for Critical Infrastructure: A Governance Model for Regulatory Resilience

This study investigates the integration of privacy-by-design principles within critical infrastructure systems, emphasizing governance frameworks that align regulatory compliance, cybersecurity resilience, and technical system design.

Babatunde Ogunsipe · 0 citations
Open access Jul 2026

AI-driven cybersecurity in the gulf states: governance challenges and a proposed GCC-wide ethical framework

Artificial intelligence (AI) presents substantial opportunities to strengthen national cybersecurity in the Gulf States while raising significant governance challenges related to algorithmic bias, privacy protection, accountability, and potential misuse. This study examines the deployment and governance of AI for cybersecurity in Qatar, Saudi Arabia, and the United Arab Emirates (UAE). It assesses the effectiveness of AI applications in threat detection and response, identifies regulatory gaps relative to international standards, and proposes a regionally tailored governance framework. Guided by Technological Governance Theory, which emphasizes multi-stakeholder collaboration and adaptive policymaking, and the Strategic Alignment Model, which evaluates the coherence between technological initiatives and national security objectives, the research employs a mixed-methods approach. Quantitative analysis draws on aggregated cyber incident data (2018–2025) from GCC cybersecurity agencies, with conservative estimates and sensitivity analyses to account for under-reporting (60–100% completeness range). Qualitative components include thematic analysis of policy documents (e.g., Qatar’s National AI Strategy and the EU AI Act), comparative case studies of facial recognition systems, predictive threat intelligence, and smart policing applications, and 12 semi-structured expert interviews. Results indicate meaningful efficiency gains, such as reduced breach response times and strong domain-specific detection rates, though these are caveated by data limitations and varying audit coverage. The study proposes a novel GCC-wide AI governance framework comprising four integrated layers: regulatory (risk-based classification), technical (explainable AI methods such as SHAP/LIME, federated learning, and differential privacy), oversight (mandatory bias audits, human-in-the-loop requirements, and an independent GCC AI Ethics Council), and capacity-building (workforce development and regional intelligence sharing). This framework differentiates itself from the EU AI Act through enhanced focus on state sovereignty and cultural alignment, and from Singapore’s Model by incorporating stronger enforcement and data localization mechanisms for critical infrastructure. The findings contribute to the literature by offering an operational model that balances security effectiveness with ethical imperatives. The Gulf States are positioned to play a leading role in responsible AI governance, contingent on robust implementation and enforcement.

Mustafa Osman I. Elamin · 0 citations