The generative AI development paradox: Democratizing enterprise system development while deepening corporate governance risks
Abstract
Generative artificial intelligence (AI) is changing how digital solutions are developed within organizations. Through low-code platforms and AI-assisted development tools, non-engineering employees can now create internal applications, dashboards, workflow automations, and other digital assets with limited programming knowledge. This offers clear benefits, particularly for organizations facing limited information technology (IT) resources, long development backlogs, and pressure to respond quickly to operational needs. However, it also creates a significant governance challenge. Business users may understand the operational problem they wish to solve, but often lack sufficient knowledge of system architecture, cybersecurity, data governance, integration dependencies, and long-term maintenance. This paper conceptualizes this tension as the Generative AI Development Paradox: AI-enabled development can improve productivity and local innovation while simultaneously weakening enterprise-level visibility, accountability, and control. Drawing on research concerning shadow IT, business-managed IT, low-code development, and AI governance, the study argues that this is not only a technical issue but also a corporate governance concern involving oversight, risk ownership, compliance, and internal control. Using a governance-oriented conceptual and qualitative approach, the study examines how non-engineers use generative AI tools to develop business-relevant systems. Preliminary findings indicate a dual effect. Generative AI accelerates experimentation, reduces dependence on technical teams, and supports closer alignment with business needs. At the same time, it can result in weak documentation, unclear ownership, limited testing, and insufficient understanding of data exposure and system risk. The paper concludes that organizations should adopt a model of controlled democratization, allow innovation while strengthen documentation, review, accountability, security, and risk management.