Public Sector AI Deployments Face Cyber Governance Failures

Md Salahuddin, James Rooney, Fida Hasan· July 29, 2026 View original

Summary

A new paper analyzes how AI adoption causes cybersecurity governance failures in government organizations, proposing a seven-domain typology of ten specific AI-driven failure causes and a three-pathway failure model.

The intersection of AI adoption, cybersecurity governance, and public sector institutional constraints has been an under-examined area. Existing literature often addresses these topics in isolation, failing to explain how AI specifically leads to cybersecurity governance failures within government organizations or to test current governance instruments against AI-specific public sector challenges. This research bridges that gap by proposing a seven-domain typology that identifies ten specific AI-driven cyber governance failure causes, grounded in an analysis of public sector institutions. It also presents a three-pathway failure model, illustrating how accountability, operational resilience, and compliance failures interact and reinforce each other in the context of AI deployment. The paper includes a structured coverage matrix, evaluating five major governance frameworks (NIST CSF 2.0, ISO/IEC 27001, COBIT, NIST AI RMF, and ISO/IEC 42001) against its typology. The findings indicate that no single instrument adequately addresses critical issues like "Shadow AI," "speed asymmetry," or "governance vacuum" with the operational specificity required for public sector application. The concept of "speed asymmetry" is introduced as a new structural construct with a defined mechanism, and the overall framework provides a design specification for an AI-enabled cybersecurity maturity model tailored for government organizations.

Why it matters

For public sector professionals and those working with government clients, this research provides a critical framework for understanding and mitigating the unique cybersecurity governance risks associated with AI deployment, highlighting gaps in existing frameworks.

How to implement this in your domain

  1. 1Conduct a comprehensive audit of existing AI deployments within public sector organizations for "Shadow AI" instances.
  2. 2Develop and implement AI-specific cybersecurity policies that address speed asymmetry and governance vacuums.
  3. 3Evaluate current governance frameworks against the proposed typology to identify and fill gaps in AI cybersecurity.
  4. 4Invest in training programs for public sector IT and leadership on AI-specific cyber risks and governance best practices.
  5. 5Collaborate with policymakers to develop tailored AI-enabled cybersecurity maturity models for government.

Who benefits

GovernmentCybersecurityPublic PolicyConsultingDefense

Key takeaways

  • AI adoption introduces unique cyber governance failures in the public sector.
  • Existing governance frameworks have gaps for AI-specific risks.
  • "Shadow AI" and "speed asymmetry" are critical unaddressed issues.
  • A new typology and failure model aid in understanding these risks.

Original post by Md Salahuddin, James Rooney, Fida Hasan

"arXiv:2607.25368v1 Announce Type: new Abstract: The intersection of artificial intelligence adoption, cybersecurity governance, and public sector institutional constraints has not been examined as a unified analytical problem in the existing literature. Studies address AI cyberse…"

View on X

Originally posted by Md Salahuddin, James Rooney, Fida Hasan on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses