AIS Logo
New · Agentic research assistant

Ask AIS Insights

Get research-backed answers to the questions you’re actually facing.

Try:

Browse the library 58 papers

All
New Responsible artificial intelligence governance: A review and research framework
(2025) AI Processed Human Reviewed

Responsible artificial intelligence governance:A review and research framework

Emmanouil Papagiannidis, Patrick Mikalef, Kieran Conboy
This scoping review synthesizes existing research on responsible artificial intelligence (AI) principles and governance practices across the complete AI project lifecycle. The study develops a holistic conceptual framework that details structural, procedural, and relational practices along with their antecedents and organizational and societal effects. Problem Despite widespread guidelines and high-level principles for ethical AI, organizations struggle to translate abstract concepts into actionable practices. Literature in this domain remains disparate and lacks clarity on how to operationalize responsible AI governance while balancing business competitiveness, ethical risks, and compliance requirements. Outcome - Synthesizes prior research on responsible AI into seven core principles: accountability, diversity and fairness, human agency and oversight, privacy and data governance, technical robustness and safety, transparency, and social and environmental well-being.
- Establishes a tripartite framework for responsible AI governance comprising structural (roles and authority), procedural (processes and evaluation), and relational (collaboration and literacy) practices.
- Maps the contextual antecedents of AI governance, including evolving societal norms and organizational values, as well as its effects on business value and social assessment.
- Formulates a detailed research agenda with key questions to guide future academic inquiry and practical implementation.
What it means for you
  • CIO / IT Executive: On Monday morning, initiate a review of your organization's current AI project lifecycle documentation to identify where the seven core responsible AI principles (accountability, diversity & fairness, human agency & oversight, privacy & data governance, technical robustness & safety, transparency, and social & environmental well-being) are explicitly addressed and where gaps exist, preparing to assign ownership for these areas.
  • IT Manager: On Monday morning, schedule a 30-minute meeting with your team responsible for AI development or deployment to collaboratively identify one specific AI project that could benefit from enhanced procedural practices (e.g., implementing a new risk assessment checklist based on transparency principles) and assign a team member to draft this enhancement by Friday.
  • Business Strategist: On Monday morning, dedicate an hour to researching how responsible AI governance (structural, procedural, and relational practices) could directly contribute to your organization's stated business objectives and competitive advantage, identifying at least one concrete opportunity to explore further.
  • Researcher: On Monday morning, select one of the seven core responsible AI principles that you find most underdeveloped in current practice and spend two hours identifying three specific research questions from the provided framework that directly address operationalizing this principle, preparing to draft a short proposal for investigation.
  • Policymaker: On Monday morning, dedicate an hour to identifying which of the seven core responsible AI principles your current regulatory framework or internal policies address most weakly, and then draft a one-page summary of potential areas for future policy development or amendment, focusing on bridging the gap between abstract principles and actionable practices.
Artificial intelligence, Responsible AI governance, Governance practices, AI implementation, AI lifecycle, Trustworthy AI
New Efficacy Beliefs and Outcomes: Socio-Cognitive Perspectives on a Faculty-Led coP
AIS SIGED International Conference on Information Systems Education and Research (SIGED) (2023) AI Processed Human Reviewed

Efficacy Beliefs and Outcomes:Socio-Cognitive Perspectives on a Faculty-Led coP

John Michael Muraski, Donald H. Heath, Michael A. Eierman, Michael Patton
This study examines the collaborative redesign of an introductory information systems course at a US university through the theoretical lenses of Communities of Practice and Social Cognitive Theory. Using a participatory action research approach, the authors analyzed qualitative interview data, field notes, and student pre- and post-test assessment scores to evaluate the impact on course quality and instructor self-efficacy. Problem Introductory multi-section university courses frequently suffer from inconsistent instructional quality, varying depth of coverage, and minimal collaboration among instructors. Additionally, standard faculty development models often fail to provide experienced instructors with effective collaborative mechanisms that enhance their confidence to adopt shared pedagogical practices. Outcome - Student performance showed consistent, measurable gains across multiple semesters following the course redesign, as demonstrated by improved pre- and post-test assessment deltas.
- Participation in the community of practice positively impacted instructors' self-efficacy beliefs, with vicarious learning and peer verbal persuasion emerging as key drivers of confidence.
- The collaborative approach established high course consistency across sections while creating a durable, supportive framework for peer mentoring and ongoing curriculum enhancement.
What it means for you
  • CIO / IT Executive: On Monday morning, schedule a 30-minute meeting with your IT academic technology support lead to explore a pilot program implementing a Communities of Practice model for a high-enrollment introductory course, using the provided research as a framework for discussion on potential student outcome improvements and faculty development.
  • IT Manager: On Monday morning, gather the instructors for the introductory information systems course for a 45-minute session. Share the key findings of this research, specifically highlighting the gains in student performance and instructor self-efficacy. Then, collaboratively brainstorm one small, concrete change to the course syllabus or assessment that can be implemented next semester as a collective first step towards greater consistency.
  • Business Strategist: On Monday morning, analyze the current onboarding and ongoing professional development process for new faculty teaching foundational courses. Identify any gaps in collaborative support and informal learning opportunities, and consider how principles from this research, such as vicarious learning and peer persuasion, could be integrated into existing programs to improve faculty confidence and course consistency.
  • Researcher: On Monday morning, begin drafting a proposal for a follow-up study. Focus on investigating the specific mechanisms of vicarious learning and peer verbal persuasion within the identified Community of Practice, perhaps through targeted surveys or observation protocols, to quantify their impact on instructor self-efficacy and to better understand how to scale these findings.
  • Policymaker: On Monday morning, initiate a discussion with the Provost's office and the Faculty Senate leadership to present the findings of this research. Propose the development of a university-wide framework or grant program that incentivizes and supports the formation of faculty Communities of Practice for foundational courses, emphasizing the potential for improved student learning outcomes and faculty development.
Community of Practice, Self-Efficacy, Course Redesign, Social Cognitive Theory, Information Systems Education, Participatory Action Research
New Boundary Spanning and Practical Impact in IS Research: A Bourdieusian Analysis
Information Systems Journal (ISJ) (2025) AI Processed Human Reviewed

Boundary Spanning and Practical Impact in IS Research:A Bourdieusian Analysis

Stephen McCarthy, Hendrik Scholta, Geir Inge Hausvik, Peter André Busch
This study investigates how information systems (IS) practitioner doctorates bridge the gap between academic research and practical industry application. Utilizing Pierre Bourdieu's Theory of Practice, the authors examine a multi-case study of 10 research projects using data from 24 semi-structured interviews and participant observations. The research explores the boundary spanning activities and environmental forces that enable researchers to achieve practical impact across three stages of development. Problem Demonstrating real-world practical impact alongside theoretical contributions remains a major challenge in information systems research due to the traditional divide between academia and practice. Existing literature lacks empirical insights into how transitional agents, such as practitioner doctorates, navigate cross-field boundaries, overcome institutional norms, and align divergent goals to create actionable outcomes. Outcome - IS practitioner doctorates facilitate knowledge exchange through boundary-spanning activities including research design adaptation, multi-channel dissemination, and creating symbolic discourse.
- Practical impact progresses through proof-of-concept, proof-of-value, and proof-of-use stages, each requiring different combinations of social, cultural, economic, and symbolic capital.
- Environmental forces such as academic vs. practice doxa (institutional norms) and habitus (professional dispositions) create positional conflicts that require active negotiation and tailored incentives to sustain engagement.
What it means for you
  • CIO / IT Executive: On Monday morning, schedule a 30-minute meeting with your direct reports to initiate a 'practice impact review' focused on one ongoing IS project. Ask each person to identify one specific academic insight or research finding from a recent external study or internal research initiative that could be directly applied to improve that project's current proof-of-concept or proof-of-value stage, and assign them to explore this application by end of week.
  • IT Manager: On Monday morning, identify one specific, recent academic paper or conference proceeding relevant to a current team challenge. Forward this paper to your team with a concise note asking for a brief, 1-2 sentence summary of its most practical takeaway and how it *might* apply to your current proof-of-value stage objective by Tuesday afternoon.
  • Business Strategist: On Monday morning, review the key performance indicators (KPIs) of one strategic business initiative currently underway. Identify which KPIs are not meeting expectations and, using the 'proof-of-value' framework, draft a one-page hypothesis on how a novel IS application or process, potentially informed by academic research, could demonstrably improve these specific KPIs within the next quarter.
  • Researcher: On Monday morning, select one recent academic publication where you are the lead author and identify its 'proof-of-use' stage potential. Draft a single-slide executive summary that articulates the core problem addressed, the practical solution proposed, and one tangible benefit for a specific industry practitioner role (e.g., IT manager, business analyst), and share it with three relevant practitioner contacts for feedback by Wednesday.
  • Policymaker: On Monday morning, review the current grant application criteria for technology innovation funding. Identify if and how 'demonstrable practical impact' is explicitly assessed, and draft a brief proposal to incorporate a specific requirement for applicants to detail their strategy for achieving 'proof-of-value' or 'proof-of-use' within a defined timeframe, alongside theoretical contributions.
academia-practice gap, boundary spanning, design science research, engaged IS scholarship, practical impact, theory of practice
New Process science: the interdisciplinary study of socio-technical change
Process Science (2024) AI Processed Human Reviewed

Process science:the interdisciplinary study of socio-technical change

Jan vom Brocke, Wil M. P. van der Aalst, Nicholas Berente, Boudewijn van Dongen, Thomas Grisold, Waldemar Kremser, Jan Mendling, Brian T. Pentland, Maximilian Roeglinger, Michael Rosemann, Barbara Weber
This editorial paper introduces and conceptualizes process science as an interdisciplinary field dedicated to the study of socio-technical processes over time. It examines how human actions and digital technologies interact dynamically, leveraging digital trace data and computational techniques to observe, explain, and guide change. The study establishes core tenets, taxonomy distinctions, and a research framework linking practical socio-technical processes with scientific knowledge creation. Problem Traditional research disciplines frequently prioritize an 'entity-first' view, focusing on static structures rather than ongoing, dynamic changes. However, contemporary phenomena—such as generative AI, platform economies, and societal transformations—are inherently socio-technical and continuously evolving, producing massive amounts of digital trace data that static analytical frameworks cannot adequately capture. Outcome - Defines process science as an interdisciplinary domain aimed at capturing, understanding, and intervening in socio-technical change across multiple levels of abstraction.
- Categorizes key activities of process science into discovery (detecting patterns via event data), explanation (identifying cause-effect relations), and intervention (shaping process trajectories).
- Advocates for shifting from an 'entity-first' to a 'process-first' perspective to identify analogies across diverse domains and support computationally intensive theory building.
- Introduces a research framework that integrates digital trace data from practice with theoretical foundations to solve real-world problems and drive societal impact.
What it means for you
  • CIO / IT Executive: On Monday morning, initiate a review of your organization's current digital infrastructure and data collection capabilities to identify which systems generate 'digital trace data' relevant to socio-technical processes. Prioritize understanding the flow of this data and its potential for analysis.
  • IT Manager: On Monday morning, investigate your team's current methods for logging and tracking user interactions with key IT systems. Identify specific 'events' that could be captured and analyzed to reveal patterns of socio-technical change within your department.
  • Business Strategist: On Monday morning, schedule a brainstorming session with your core team to identify one specific business process currently undergoing significant change (e.g., customer onboarding, product development). Brainstorm what digital 'trace data' this process generates and how understanding its dynamics could inform strategy.
  • Researcher: On Monday morning, start cataloging existing datasets within your research domain that represent 'digital traces' of human-technology interaction. Begin exploring computational tools that can analyze event sequences rather than just static entities.
  • Policymaker: On Monday morning, identify a specific public policy area (e.g., digital inclusion, citizen engagement) that is experiencing rapid socio-technical evolution. Begin researching existing digital platforms and services that generate trace data related to this policy area.
Process Science, Socio-Technical Processes, Digital Trace Data, Process Mining, Organizational Change, Interdisciplinary Research
New Affordance-Based Pathway Model of Social Inclusion: A Case Study of Virtual Worlds and People With Lifelong Disability
Journal of the Association for Information Systems (2026) AI Processed Human Reviewed

Affordance-Based Pathway Model of Social Inclusion:A Case Study of Virtual Worlds and People With Lifelong Disability

Karen Stendal, Maung K. Sein, Devinder Thapa
This study investigates how individuals with lifelong disabilities utilize virtual worlds, specifically Second Life, to move from social isolation to social inclusion. Through a qualitative research design involving participant observation and in-depth interviews, the authors trace how users perceive and actualize virtual world capabilities. The paper develops an affordance-based pathway model outlining how technology features enable interpersonal relationships and community participation. Problem People with lifelong disabilities frequently face severe social exclusion, isolation, and physical barriers that limit their full participation in everyday social activities. While digital environments offer potential solutions, the underlying mechanisms and technological pathways through which virtual tools lead to meaningful social inclusion remain insufficiently understood. Outcome - Identified three functional affordances (communicability, mobility, and personalizability) and two social affordances (engageability and self-actualizability) crucial for social inclusion.
- Established that the actualization of functional affordances enables and dynamically interacts with social affordances to foster interpersonal relationships and community participation.
- Discovered that outcomes achieved by actualizing specific affordances serve as facilitating conditions that support the perception and realization of additional affordances.
- Extended affordance theory by demonstrating a feedback loop where social engagement refines and enhances the perception and use of basic functional capabilities.
What it means for you
  • CIO / IT Executive: On Monday morning, task your accessibility team to conduct an initial assessment of our current platform's 'communicability' features (e.g., real-time chat, group messaging, avatar-based interaction quality) against the research's identified functional affordances to understand potential barriers and opportunities for individuals with disabilities.
  • IT Manager: On Monday morning, schedule a 30-minute working session with your frontline support staff to review existing user feedback logs for mentions of difficulty with navigation, communication, or customization within our virtual environment, specifically looking for patterns that might align with limitations in perceived 'mobility' or 'personalizability' affordances.
  • Business Strategist: On Monday morning, initiate a competitive analysis focusing on how emerging virtual platforms or digital communities are leveraging 'engageability' and 'self-actualizability' affordances to foster user connection and content creation, particularly noting any strategies that might appeal to or benefit users with disabilities.
  • Researcher: On Monday morning, begin drafting a protocol for a pilot study within our organization's virtual world that focuses on measuring the impact of enhanced 'communicability' features on user-reported feelings of 'engageability' and 'self-actualizability' among a diverse user group, potentially including participants with disabilities.
  • Policymaker: On Monday morning, convene a brief meeting with your advisory committee to discuss how current digital inclusion policies might be strengthened by explicitly incorporating the research's identified 'functional affordances' (communicability, mobility, personalizability) and 'social affordances' (engageability, self-actualizability) as measurable criteria for assessing technological accessibility and support for social participation.
Social Inclusion, Virtual Worlds, People With Lifelong Disability, Affordances, Second Life, ICT
New Exploring Digital Sustainability: A Multidimensional Framework for IS Scholarship
International Conference on Information Systems (ICIS) (2025) AI Processed Human Reviewed

Exploring Digital Sustainability:A Multidimensional Framework for IS Scholarship

Dina Jill Maya Mertens, Thomas Haskamp, Jan vom Brocke
This study conducts a systematic literature review of 40 scholarly articles to synthesize current knowledge on digital sustainability in Information Systems research. It conceptualizes how organizations utilize digital technologies to drive environmental performance and sustainability goals. The authors develop a multidimensional framework that structures antecedents, moderating mechanisms, and economic and environmental consequences. Problem Despite growing interest in leveraging digital technology to address climate challenges, digital sustainability research suffers from conceptual ambiguity. Existing literature across Green IT and Green IS lacks a unified theoretical foundation to explain how digital artifacts generate sustainable value. This lack of clarity hinders organizations from effectively implementing digital tools for environmental objectives. Outcome - Synthesized literature into a multidimensional framework detailing the antecedents, moderators, and outcomes of digital sustainability.
- Identified 14 sustainability-enabling logics showing how digital technology drives value creation, such as automatization, prediction, tokenization, and servitization.
- Categorized consequences into economic benefits, enhanced green employee/customer behavior, and improved environmental performance, alongside critical considerations like digital energy consumption.
- Proposed a research agenda around three main avenues: organizational transformation, product-level value creation mechanisms, and managing the duality/paradox of digital sustainability.
What it means for you
  • CIO / IT Executive: On Monday morning, initiate a review of your organization's current digital infrastructure against the 'antecedents' dimension of the digital sustainability framework. Prioritize identifying at least one area where technology can be leveraged for 'automatization' to reduce physical resource consumption (e.g., paperless workflows, virtual meetings replacing travel).
  • IT Manager: On Monday morning, identify one specific digital tool or process currently in use (e.g., cloud storage, software updates) and evaluate its potential 'digital energy consumption.' Research and propose to your team one tangible step to optimize its energy efficiency, such as scheduling software updates during off-peak hours or reviewing cloud storage policies for unused data.
  • Business Strategist: On Monday morning, examine your current product or service offerings and identify an opportunity to apply one of the 'sustainability-enabling logics' presented in the research. For example, explore how 'servitization' (offering a service instead of a product) could reduce material waste and extend product lifespan.
  • Researcher: On Monday morning, focus on the 'product-level value creation mechanisms' research agenda. Select one of the 14 identified logics (e.g., 'prediction') and brainstorm how it could be applied to develop a testable hypothesis related to reducing a specific environmental impact within an organizational context. Outline the initial steps for designing a pilot study.
  • Policymaker: On Monday morning, review existing digital infrastructure policies and identify areas where incentives can be introduced or strengthened to encourage 'enhanced green employee/customer behavior' through digital means. For example, consider proposing a policy that rewards teams who demonstrably reduce their digital carbon footprint through technology adoption.
Digital Sustainability, Digital Technology, Green IS, Green IT, Sustainable Value Creation, Literature Review
New The Philosopher’s Corner: The “Immersed Flesh”: A Phenomenological Conceptualization of Immersive Virtual Reality Embodiment
(2025) AI Processed Human Reviewed

The Philosopher’s Corner:The “Immersed Flesh”: A Phenomenological Conceptualization of Immersive Virtual Reality Embodiment

Amir Haj-Bolouri
This study explores how Maurice Merleau-Ponty's phenomenological view on embodiment and ontology of the Flesh can be applied to conceptualize immersive virtual reality (IVR) embodiment within Information Systems research. It proposes the novel concept of 'Immersed Flesh' to capture the rich, sensory experience of virtual immersion beyond simple technical representations. The paper demonstrates the framework's utility through three illustrative use cases and provides theoretical grounding for future IVR research. Problem Mainstream Information Systems literature on virtual embodiment largely relies on non-immersive VR contexts and technological deterministic or instrumentalist perspectives. These traditional views reduce the virtual body to an external representation or object, failing to address the lived, sensory, and existential dimensions of modern IVR experiences. Consequently, there is a lack of a non-dualistic theoretical foundation for understanding how users sense and make meaning of embodiment in immersive environments. Outcome - Conceptualizes IVR embodiment through the new concept of 'Immersed Flesh', defined as a dynamic matrix that merges physical and virtual worlds into a co-extensive reality.
- Adapts Merleau-Ponty's ontology of the Flesh into key structural elements for IS, including Actual Grip, Apparent Grip, Circuit, Chiasma, Interworld, Measuring Body, and Reversibility.
- Illustrates the practical and theoretical value of the framework through three distinct IVR scenarios: expressing the living body (e.g., IVR dancing), intersubjective perspective-taking (e.g., embodying a tree), and experiencing the objective body of passing entities (e.g., avatars of deceased relatives).
- Generates research questions for future IS inquiry into user self-agency, bodily empathy, and ethical considerations surrounding virtual presence.
What it means for you
  • CIO / IT Executive: On Monday morning, schedule a 30-minute briefing for your senior IT team to introduce the concept of 'Immersed Flesh' as a potential lens for evaluating our next-generation immersive technology investments, specifically focusing on how it moves beyond purely functional metrics to consider user experience and embodiment.
  • IT Manager: On Monday morning, gather your team responsible for VR development or deployment and ask them to review our current IVR platforms and identify one specific feature or interaction where users might be experiencing something akin to 'Actual Grip' or 'Apparent Grip' as described in the 'Immersed Flesh' concept.
  • Business Strategist: On Monday morning, dedicate one hour to brainstorm three hypothetical business use cases where fostering 'bodily empathy' or enhancing 'user self-agency' through IVR, inspired by the 'Immersed Flesh' framework, could provide a competitive advantage or solve a current business challenge.
  • Researcher: On Monday morning, draft a preliminary research proposal outline that incorporates at least two of the structural elements from the 'Immersed Flesh' framework (e.g., Chiasma, Interworld) to investigate user embodiment in a specific IVR application relevant to our field.
  • Policymaker: On Monday morning, request a brief (1-page) summary of the 'Immersed Flesh' concept from your policy research unit, specifically asking them to highlight any potential ethical implications or policy considerations related to virtual presence and user embodiment in immersive technologies.
Immersive Virtual Reality, Embodiment, Phenomenology, Information Systems, Merleau-Ponty
New Transform or be transformed: the importance of research on managing and sustaining digital transformations
European Journal of Information Systems (2023) AI Processed Human Reviewed

Transform or be transformed:the importance of research on managing and sustaining digital transformations

Noel Carroll, Nik Rushdi Hassan, Iris Junglas, Thomas Hess, Lorraine Morgan
This editorial outlines the critical challenges and research directions associated with managing and sustaining digital transformations within the Information Systems field. It discusses the gap between short-term adoption studies and long-term organizational normalization, providing a framework for future scholarly inquiry. Additionally, it introduces four selected papers from the Special Issue that explore leadership, theoretical metaphors, scaling tensions, and small business readiness. Problem Although initiating a digital transformation is widely emphasized, organizations face high failure rates because sustaining long-term transformation remains difficult and under-researched. Existing Information Systems literature often focuses on short timeframes and successful case studies, creating a disconnect with real-world complexities, cultural barriers, and structural obstacles. Outcome - Emphasizes the need for longitudinal research designs to observe how digital transformations unfold, normalize, and sustain over extended periods.
- Identifies key research challenges, including the misuse of terminology, unexamined assumptions, root causes of failure, and the dark side of digital transformations.
- Introduces the concept of an 'execution engine' to fundamentally adapt decision-making processes and performance rhythms for long-term transformation success.
- Showcases four special issue papers focusing on healthcare value landscapes, CIO-CDO role alignment, prototype ambiguity in scaling, and microbusiness owner-manager mindsets.
What it means for you
  • CIO / IT Executive: On Monday morning, schedule a 30-minute meeting with your direct reports to discuss the 'execution engine' concept and brainstorm one specific process within your IT department that needs fundamental adaptation for long-term digital transformation success. Assign one person to draft a brief proposal by end-of-week.
  • IT Manager: On Monday morning, identify one digital initiative currently underway that is showing signs of slowing adoption or unexpected friction. Gather the project team for a 1-hour 'root cause analysis' session, focusing specifically on potential cultural or structural obstacles, not just technical issues, and document the top 2-3 hypothesized causes.
  • Business Strategist: On Monday morning, review your organization's current digital transformation roadmap and flag any objectives that are solely focused on short-term adoption metrics. Draft a list of 3-5 questions to explore how these objectives will be sustained and normalized over the next 1-3 years, and schedule a preliminary discussion with your team by Wednesday.
  • Researcher: On Monday morning, analyze your current research project's data collection plan. Identify if it allows for longitudinal observation of digital transformation normalization (beyond initial adoption) and, if not, sketch out one modification to incorporate this perspective in future data gathering or analysis.
  • Policymaker: On Monday morning, review existing public funding guidelines or incentives for digital transformation. Identify one specific criterion or reporting requirement that might unintentionally discourage longitudinal sustainability efforts and draft a brief memo suggesting a minor amendment to encourage long-term impact.
Digital Transformation, Managing, Sustaining, Research Agenda, Socio-technical Factors, Citizen Development
New Critical Success Factors for an Effective Security Risk Management Program: An Exploratory Case Study
(2026) AI Processed Human Reviewed

Critical Success Factors for an Effective Security Risk Management Program:An Exploratory Case Study

Jason A. Williams, Humayun Zafar, Saurabh Gupta
This exploratory case study evaluates the perceived effectiveness of security risk management (SRM) programs within a Fortune 500 company across different organizational levels. Using a mixed-methods approach involving interviews, scenario-based vignettes, and a Q-sort ranking exercise, the research examines key drivers of SRM success. The study revalidates six established critical success factors and identifies three new operational factors that enhance program performance. Problem Organizations struggle with increasing cybersecurity threats and complex compliance regulations, yet low employee security awareness and lack of policy compliance remain persistent challenges. Furthermore, existing research offers limited insight into how perceptions of success factors differ between management and staff, leading to misaligned priorities and reduced program efficacy. Outcome - Confirmed six initial Critical Success Factors (CSFs) from existing literature: Executive Management Support, Organizational Maturity, Open Communication, Risk Management Stakeholders, Team Member Empowerment, and Holistic View of an Organization.
- Identified three newly extracted CSFs from empirical evidence: Security Maintenance, Corporate Security Strategy, and Human Resource Development.
- Discovered key perception differences across organizational levels, with management prioritizing Executive Management Support and staff ranking Open Communication as most essential.
- Emphasized that effective SRM programs require continuous policy updates, joint management-staff governance committees, and alignment between security goals and overall business strategy.
What it means for you
  • CIO / IT Executive: On Monday morning, schedule a 15-minute call with your direct reports, specifically the heads of IT Security and IT Operations, to review the 'Corporate Security Strategy' CSF and discuss how the current IT security roadmap directly supports two specific, measurable business objectives for Q3. Ask them to come prepared with one example for each.
  • IT Manager: On Monday morning, initiate a 'lunch and learn' session invitation for your team scheduled for next week, focusing on a specific, practical aspect of 'Human Resource Development' related to security, such as a short demo on identifying and reporting phishing emails securely. Request that team members bring one question they have about our current security policies.
  • Business Strategist: On Monday morning, identify and document two specific business processes within your department that currently have the weakest security controls, using the 'Holistic View of an Organization' CSF as a lens. Draft a brief, one-paragraph summary of the potential risks associated with these weaknesses to share with the IT Security team by end-of-day.
  • Researcher: On Monday morning, begin a systematic review of the interview transcripts from your case study, specifically tagging every instance where participants mention 'Open Communication' or 'Team Member Empowerment'. Note the organizational level of the speaker for each tag to facilitate your analysis of perception differences.
  • Policymaker: On Monday morning, draft an agenda for a joint management-staff governance committee meeting focused on reviewing and proposing updates to one specific security policy (e.g., password complexity, data handling). Identify two key areas within that policy that have historically seen low compliance and propose specific, actionable changes to address them.
Information Security, Security Risk Management, Critical Success Factors, Case Study, Q-Sort, Security Governance
New Using a Process Philosophy Perspective in Information Systems Research: Principles of Creative Evolution
Journal of the Association for Information Systems (2024) AI Processed Human Reviewed

Using a Process Philosophy Perspective in Information Systems Research:Principles of Creative Evolution

David Kreps, Frantz Rowe
This paper proposes a creative evolution process philosophy perspective for information systems (IS) research, grounded in the philosophical works of Henri Bergson and Alfred North Whitehead. It establishes a set of five core principles to shift the research paradigm from viewing reality as static entities to seeing it as continuous processes and conscious experiences. The authors demonstrate the practical utility of this perspective by re-examining the challenges and failures in large-scale requirements engineering. Problem Traditional information systems development and research predominantly rely on entitative worldviews that treat reality as composed of fixed, static objects and discrete time steps. This static perspective fails to capture the complex, evolving nature of human experience and temporal flow, which frequently leads to project failures in large-scale IT implementations. Furthermore, the IS literature lacks formal principles and criteria for conducting research anchored in process philosophy that accounts for human consciousness and free will. Outcome - Formulated five foundational principles for process philosophy in IS research: heterogeneous multiplicity, immanence in a process, experience over abstraction, consciousness in duration, and relational ontology.
- Identified entitative abstractions in traditional requirements engineering as a major contributor to large-scale IT project failures.
- Emphasized the critical role of human consciousness, inner time, and free will in co-creating technology systems that adapt to evolving organizational contexts.
What it means for you
  • CIO / IT Executive: On Monday morning, schedule a 30-minute "process thinking" brainstorming session with your heads of engineering and product development to discuss a recent project that faced significant challenges, focusing on how evolving user needs and unforeseen contextual shifts, rather than static requirements, might have been the root cause.
  • IT Manager: On Monday morning, initiate a 15-minute stand-up with your development team to specifically ask them to articulate one instance from the past week where a change in the team's understanding or a user's evolving need led to a necessary adaptation of their work, and how they managed that 'flow'.
  • Business Strategist: On Monday morning, review the 'success metrics' for your current key strategic initiatives and identify one metric that relies heavily on a static, predefined outcome. Then, draft a brief proposal to reframe that metric to capture ongoing adaptability and emergent value rather than just initial adherence to a plan.
  • Researcher: On Monday morning, dedicate an hour to re-reading your current research proposal, specifically highlighting any language that treats concepts as fixed entities. Then, rewrite one paragraph to emphasize the dynamic, experiential, and relational aspects of your subject matter, incorporating the principles of creative evolution.
  • Policymaker: On Monday morning, identify one current policy or regulation within your domain that is narrowly defined by static criteria or historical precedents. Then, draft a one-page memo outlining how an update to this policy could incorporate principles of ongoing adaptation and feedback loops to account for emergent technological and societal shifts.
process philosophy, ontology, duration, consciousness, free will, requirements engineering
New Automated Privacy Policy Simplification through a GPT-Powered Chrome Extension
International Conference on Information Systems (ICIS) (2025) AI Processed Human Reviewed

Automated Privacy Policy Simplification through a GPT-Powered Chrome Extension

Al Maha Al Jabor, Shahad Adnan Astaneh, Manoranjan Mohanty, Chadi Aoun
This study explores how Large Language Models like GPT-4 can simplify complex online privacy policies while maintaining their essential legal validity. The authors evaluated multiple prompt strategies across 25 real-world privacy policies using standard readability metrics and ROUGE content preservation scores. Based on these findings, they developed a Chrome extension that provides real-time policy summaries and an interactive Q&A feature directly within the user's browser. Problem Online privacy policies are typically lengthy, complex, and filled with dense legal jargon, leading over 90% of users to accept them without reading. Existing attempts to simplify policies often lack real-time adaptability during active browsing or fail to address individual user questions, resulting in widespread uninformed consent. Outcome - The audience-adjusted rewriting prompt ('rewrite so a 10th-grade student can understand while maintaining legal accuracy') produced the highest readability improvements while preserving core legal content.
- Readability metrics improved substantially after simplification, with Flesch Reading Ease increasing significantly and complexity indices like Flesch-Kincaid Grade Level dropping sharply.
- ROUGE content evaluation metrics (ROUGE-1 Precision = 0.8862, ROUGE-L Precision = 0.6025) confirmed strong textual overlap and high fidelity to original legal terms.
- A prototype Chrome extension was created, enabling real-time policy summarization and context-aware Q&A capabilities grounded in the APCO theoretical framework.
What it means for you
  • CIO / IT Executive: On Monday morning, initiate a pilot program to evaluate the integration of a GPT-powered privacy policy simplification Chrome extension across a select department, focusing on user adoption and feedback regarding usability and perceived value.
  • IT Manager: On Monday morning, prepare a technical feasibility assessment for deploying the developed Chrome extension across the organization's standard user workstations, outlining any necessary infrastructure changes or security considerations.
  • Business Strategist: On Monday morning, analyze how the real-time privacy policy simplification and Q&A features of the Chrome extension can be leveraged to enhance user trust and potentially create a competitive differentiator for our online services.
  • Researcher: On Monday morning, begin designing an experiment to test the effectiveness of the audience-adjusted rewriting prompt ('rewrite so a 10th-grade student can understand while maintaining legal accuracy') with a new set of privacy policies from a different industry sector.
  • Policymaker: On Monday morning, review the research findings on improved readability and content preservation to draft talking points for discussions on enhancing consumer understanding of digital service terms and conditions.
Privacy Policy Simplification, Large Language Models, Informed Consent, GPT-4, Chrome Extension, Readability Metrics
New Yoga Sutra-Based Memory Analysis of Information Systems Implementation
Communications of the Association for Information Systems (2026) AI Processed Human Reviewed

Yoga Sutra-Based Memory Analysis of Information Systems Implementation

Ranjan Vaidya
This study introduces a memory analysis framework based on Patanjali's Yoga Sutra to evaluate information systems implementation. It incorporates core concepts such as Samskara (subliminal impressions) and Alambana (external triggers) to understand how accumulated stakeholder experiences influence technology engagement. The framework is applied to an existing case study of an agricultural marketing information system in India. Problem Current information systems research predominantly focuses on team memory within Western organizational contexts, overlooking individual cognitive variations and Eastern philosophical perspectives. Additionally, existing studies rarely theorize memory per se, leaving a gap in understanding how subliminal impressions and past negative experiences impact stakeholder trust and behavioral responses. Outcome - The Yoga Sutra framework demonstrates that subliminal impressions (Samskara) formed by past unfair trade practices deeply influence stakeholder behaviors and technology adoption.
- Contextual factors and research interviews function as triggers (Alambana) that evoke unpleasant memories, reinforcing distrust between system users, government boards, and private vendors.
- Information system failures in developing contexts often result from a lack of adherence to core ethical and behavioral values rather than culture acting as a barrier.
What it means for you
  • CIO / IT Executive: On Monday morning, schedule a 30-minute discovery call with your Head of User Experience and your Chief Ethics Officer to brainstorm how to proactively identify and mitigate potential 'Samskara' (subliminal impressions) in upcoming system implementations by focusing on past negative stakeholder experiences.
  • IT Manager: On Monday morning, review the last three system user feedback reports for any recurring themes related to distrust or negative past experiences, and flag the top two recurring issues to investigate further for potential 'Alambana' (external triggers) in your current system.
  • Business Strategist: On Monday morning, draft a brief (one-page) internal memo to your team outlining the concept of 'Samskara' and its potential impact on technology adoption, and request them to identify one instance in recent projects where past negative impressions might have influenced user behavior.
  • Researcher: On Monday morning, begin drafting the introduction to your next research paper by clearly articulating the gap in current information systems research regarding the lack of focus on individual cognitive variations and Eastern philosophical perspectives on memory, using the Yoga Sutra framework as your proposed solution.
  • Policymaker: On Monday morning, initiate a discussion with your advisory board regarding the importance of embedding ethical and behavioral values into the design and implementation guidelines for all new government information systems, referencing the finding that failures often stem from a lack of adherence to these values, not culture.
Yoga, Information Systems, Memory, Behavioural Analysis, Samskara, ICT4D
New Ethics-based ontology in ICT4D
(2025) AI Processed Human Reviewed

Ethics-based ontology in ICT4D

Devinder Thapa
This study proposes an ethics-based ontology for Information and Communication Technology for Development (ICT4D) research by combining Heidegger's existential phenomenology with Hans Jonas's ethics of responsibility. The paper examines how technology impacts lived experiences, human identity, and moral agency, applying this theoretical framework to re-analyze two One Laptop per Child (OLPC) case studies in Nepal and Peru. Problem Current ICT4D research predominantly relies on realist and idealist ontologies that view technology primarily as functional tools for systemic or economic growth. This narrow focus creates an ethical gap, neglecting how technological interventions affect human dignity, local agency, cultural integrity, and long-term intergenerational justice. Outcome - Establishes an ethics-based ontology in ICT4D that shifts focus from instrumental views of technology to lived human experience and moral responsibility.
- Demonstrates through the OLE Nepal case study how embedding technology into local educational ecosystems, national curricula, and teacher practices leads to sustainable success.
- Reveals through the OLPC Peru case study how top-down, context-unaware technological implementations erode local agency and lead to project failure.
- Highlights key implementation challenges, including translating abstract philosophical concepts into practical design metrics and addressing Eurocentric biases in technology evaluation.
What it means for you
  • CIO / IT Executive: On Monday morning, schedule a 30-minute meeting with your ICT4D project leads to introduce the concept of an 'ethics-based ontology' and ask them to identify one project where technology is deeply integrated into user workflows and cultural practices. Assign them to bring initial thoughts on how the project's impact on lived experience and moral agency could be assessed in the next project review.
  • IT Manager: On Monday morning, review the support tickets and user feedback logs from the last quarter for your current ICT4D deployment. Specifically, look for recurring issues that are not purely technical but seem to relate to user frustration, resistance to adoption, or a perception of technology not fitting their daily routines. Flag these for further investigation with your team.
  • Business Strategist: On Monday morning, identify your organization's most critical ICT4D initiative. Draft a brief memo outlining how you plan to evaluate its success not just on efficiency metrics but also on its impact on the dignity, agency, and cultural integrity of the end-users. Prepare to discuss this revised evaluation framework with your team by the end of the week.
  • Researcher: On Monday morning, revisit the 'implementation challenges' section of the research paper and select ONE challenge (e.g., translating abstract concepts into practical design metrics). Begin drafting a short (1-page) proposal for how you might operationalize this concept for a future ICT4D project you are involved in, focusing on a tangible measurement.
  • Policymaker: On Monday morning, review existing national or organizational guidelines for technology procurement and deployment in development contexts. Identify sections that address user impact, cultural sensitivity, or long-term sustainability. Draft a short list of questions to investigate how these existing guidelines could be strengthened to incorporate considerations of lived experience and moral responsibility for technology's impact.
ICT4D, being-in-the-World, ethics of responsibility, ontology, development, philosophy
New Gamification for Community Building: Click to Shake Hands
Pacific Asia Conference on Information Systems (PACIS) (2025) AI Processed Human Reviewed

Gamification for Community Building:Click to Shake Hands

Faisal Al Thani, Chadi Aoun, Savanid Vatanasakdakul
This short paper proposes a conceptual research model to investigate the factors influencing the adoption and sustained usage of gamified location-based applications for community building. The framework integrates ten core factors across technology characteristics, gamification elements, and social dimensions to explain user engagement. The authors present a quantitative research methodology involving a survey of active Pokémon GO players to empirically test and validate eleven proposed hypotheses. Problem While gamification and location-based games like Pokémon GO have achieved widespread popularity, existing research primarily focuses on short-term individual user behavior or educational outcomes. Little is understood about the long-term sociopsychological mechanisms and 'stickiness' factors that enable location-based games to foster sustainable, real-world community engagement and social bonds. Outcome - Formulates a novel theoretical framework connecting technology adoption, gamification mechanics, external social influences, and intrinsic motivations to app stickiness and community engagement.
- Identifies key drivers such as location incentives, perceived ease of use, reward value, achievement, network influence, herd behavior, social motive, and sense of belonging.
- Establishes an empirical research design targeting over 1,000 active Pokémon GO players using Partial Least Squares Structural Equation Modeling (PLS-SEM).
- Provides preliminary theoretical grounding for designing mobile gamified systems that promote social sustainability and persistent physical-world social interactions.
What it means for you
  • CIO / IT Executive: On Monday morning, allocate budget to pilot a location-based gamified application in one of our company's facilities, specifically focusing on fostering cross-departmental collaboration by integrating 'location incentives' for shared project spaces.
  • IT Manager: On Monday morning, schedule a meeting with your development team to discuss how to integrate elements like 'reward value' and 'achievement' into our existing internal communication platform to encourage more active participation and knowledge sharing.
  • Business Strategist: On Monday morning, initiate a brainstorming session with your marketing and product teams to identify opportunities to leverage 'network influence' and 'herd behavior' in upcoming product launches or community outreach initiatives, perhaps by creating exclusive early-access groups.
  • Researcher: On Monday morning, refine the survey instrument to include questions specifically measuring 'sense of belonging' and 'social motive' as distinct constructs, and prepare to recruit participants from diverse community groups for your next study.
  • Policymaker: On Monday morning, direct your staff to research successful public policy initiatives that have used location-based incentives or gamification to encourage citizen engagement with local services or community events, and identify potential applications for our jurisdiction.
Community Engagement, Gamification, Location-based games, Stickiness, Technology Adoption, Social Interaction
New Social Commerce in Qatar: Consumer Characteristics and Emergent Engagement
Americas Conference on Information Systems (AMCIS) (2025) AI Processed Human Reviewed

Social Commerce in Qatar:Consumer Characteristics and Emergent Engagement

Savanid Vatanasakdakul, Chadi Aoun, Faiq Defiandry
This study investigates social commerce (s-commerce) adoption, consumer characteristics, and platform preferences in Qatar. Utilizing a quantitative survey of 441 Qatari residents, the research analyzes demographical trends, internet usage habits, and online shopping frequencies within the country's unique socio-cultural context. Problem Despite rapid growth in social media usage and e-commerce across the GCC region, research on social commerce adoption specifically in Qatar remains very limited. Furthermore, there is a lack of empirical understanding regarding how local socio-cultural factors and demographic profiles shape consumer engagement and purchase behaviors in Qatar's digital landscape. Outcome - Most social commerce users in Qatar engage in s-commerce purchases 1-3 times per month (82%), with an additional 18% purchasing 4-7 times monthly.
- Instagram emerged as the leading platform for s-commerce in Qatar (46%), followed by WhatsApp (20%), TikTok (14%), and Facebook (9%).
- Female consumers (56%) and younger demographics aged 20-24 (48%) constitute the largest user segments engaging in social commerce.
- The findings highlight the significant impact of local culture, digital infrastructure, and localized content preferences in driving social commerce diffusion.
What it means for you
  • CIO / IT Executive: On Monday morning, initiate a strategic review of existing IT infrastructure and security protocols to ensure they can adequately support and protect the growing volume of social commerce transactions, with a specific focus on enhancing mobile payment gateway integrations and data privacy measures for platforms like Instagram and WhatsApp.
  • IT Manager: On Monday morning, task your team to audit the current analytics tracking for social media platforms, particularly Instagram and WhatsApp, to ensure accurate capture of user engagement and conversion data related to social commerce activities, and set up dashboards to monitor these metrics.
  • Business Strategist: On Monday morning, draft a proposal to develop targeted social commerce campaigns on Instagram, prioritizing visually appealing content and influencer collaborations, specifically aimed at the 20-24 female demographic, mirroring their current high engagement in this space.
  • Researcher: On Monday morning, begin outlining a follow-up research proposal focusing on qualitative insights into *why* Qatari consumers, particularly younger females, prefer Instagram for social commerce, exploring themes like trust, authenticity, and localized content.
  • Policymaker: On Monday morning, request a briefing from relevant ministries to understand current regulations regarding digital marketing and e-commerce on social media platforms in Qatar, and identify any gaps that might need to be addressed to foster responsible growth of social commerce.
Social Commerce, Social Media, Consumer Behavior, Technology Adoption, Qatar
New Social mobile analytics and cloud computing: a big data analytical approach
(2026) AI Processed Human Reviewed

Social mobile analytics and cloud computing:a big data analytical approach

Farhad Ali, Habib Ullah Khan, Shah Nazir
This study presents a systematic literature review examining the integration of Social, Mobile, Analytics, and Cloud (SMAC) technologies and their role in modern big data processing. The authors evaluated 75 selected research papers to classify key participating entities, assess SMAC's organizational and societal impacts, and summarize existing technical solutions. Problem Although SMAC technologies offer transformative potential for decision-making and business efficiency, organizations face significant implementation barriers. Issues surrounding user privacy, cybersecurity, data management, high energy consumption, and access control create critical research and practical gaps that hinder widespread adoption. Outcome - Identified main collaborative entities within SMAC ecosystems, including smartphones, cloud platforms, crowd participants, and environmental sensors.
- Summarized key organizational and societal benefits such as enhanced decision-making, operational cost reduction, improved productivity, and expanded social engagement.
- Classified primary adoption challenges, focusing on data privacy, security vulnerabilities, scalability limits, energy consumption, and system interoperability.
- Compiled existing technical solutions from literature, highlighting techniques such as attribute-based encryption, anonymization methods, and hyper-heuristic frameworks.
What it means for you
  • CIO / IT Executive: On Monday morning, initiate a cross-departmental working group focused on assessing our current SMAC infrastructure against the identified adoption challenges (privacy, security, scalability, energy, interoperability) using the research's findings as a framework, and schedule an initial meeting for next week.
  • IT Manager: On Monday morning, begin a review of our existing data anonymization protocols and encryption techniques, cross-referencing them with the 'existing technical solutions' highlighted in the research to identify immediate gaps or opportunities for enhancement within our current cloud and mobile analytics platforms.
  • Business Strategist: On Monday morning, schedule a 30-minute brainstorming session with your core team to identify one specific business process that could significantly benefit from SMAC integration, and during that session, identify the most critical adoption challenge from the research that needs to be addressed first for this specific process.
  • Researcher: On Monday morning, create a detailed spreadsheet to categorize the 75 papers reviewed in this study by the specific SMAC component (Social, Mobile, Analytics, Cloud), the primary adoption challenge addressed, and the technical solution proposed, to facilitate further meta-analysis.
  • Policymaker: On Monday morning, draft a request for a preliminary impact assessment on user privacy and cybersecurity risks associated with the widespread adoption of SMAC technologies within our jurisdiction, drawing upon the challenges identified in the research as key areas to investigate.
SMAC Framework, Big Data, Cloud Computing, Social Media Analytics, Mobile Computing, Data Security
New Location Analytics in Information Systems: Opportunities for Research and Teaching
Communications of the Association for Information Systems (2024) AI Processed Human Reviewed

Location Analytics in Information Systems:Opportunities for Research and Teaching

Michael A. Erskine, James B. Pick, Asish Satpathy, Andrés Díaz López, Avijit Sarkar, Namchul Shin
This study explores the current state, challenges, and opportunities for integrating location analytics into Information Systems (IS) research and education. Drawing on insights from an academic panel, it outlines how spatial methodologies can enrich IS theories, enhance research rigor, and better prepare students for data-driven business roles. Problem Despite the critical role of location analytics in modern industry decision-making and strategic planning, its presence in academic IS research and business school curricula remains remarkably sparse. This gap leaves researchers overlooking spatial dimensions in complex problems and leaves graduates lacking essential geospatial skills required by the modern workforce. Outcome - Demonstrates how incorporating spatial methodologies (such as spatial autocorrelation and geographically weighted regression) can address complex societal 'wicked problems' like climate change, network disruption, and privacy.
- Provides a strategic roadmap for integrating location analytics into undergraduate and graduate IS curricula to prepare students for high-demand business roles.
- Outlines actionable steps to bridge academia and industry, including collaborative case study development, special journal issues, and enhanced faculty training in geospatial tools.
What it means for you
  • CIO / IT Executive: On Monday morning, schedule a 30-minute meeting with your Head of Data Science and Head of Business Intelligence to discuss a pilot project integrating a basic spatial analysis layer (e.g., visualizing customer locations on a map) into one of your existing dashboards for a specific business unit.
  • IT Manager: On Monday morning, identify one internal IT project or operational challenge (e.g., network outage analysis, data center resource allocation) that could potentially benefit from a spatial perspective, and research one readily available open-source geospatial tool (like QGIS) for initial exploration.
  • Business Strategist: On Monday morning, review your current customer segmentation data and identify 2-3 key business questions that might be better answered by understanding the geographical distribution of your customers (e.g., optimal new store locations, targeted marketing campaigns by region).
  • Researcher: On Monday morning, identify one of your current research projects and brainstorm 2-3 ways that incorporating spatial data or analysis (e.g., geographic clustering of events, spatial dependencies) could strengthen your theoretical contributions or add methodological rigor.
  • Policymaker: On Monday morning, contact a representative from a local urban planning or environmental agency to inquire about any existing spatial datasets related to community infrastructure, resource distribution, or environmental impact that might be publicly accessible.
Location Analytics, Spatial Analysis, IS Curriculum, Research Methodologies, Geographic Information Systems, Decision Support Systems
New Securing Generative AI Systems: Threat-Centric Architectures and the Impact of Divergent EU–US Governance Regimes
(2026) AI Processed Human Reviewed

Securing Generative AI Systems:Threat-Centric Architectures and the Impact of Divergent EU–US Governance Regimes

Vijay Kanabar and Kalinka Kaloyanova
This study presents a threat-centric security analysis that maps adversarial techniques across a five-layer reference architecture for generative AI systems. The authors combine architectural decomposition and threat taxonomy mapping with a comparative analysis of EU and US governance frameworks to evaluate security controls. Problem Generative AI systems introduce security risks that fundamentally differ from traditional software due to probabilistic outputs, emergent failure modes, and expanded attack surfaces from tool and retrieval integration. Conventional perimeter-based and policy-only controls are insufficient because many GenAI vulnerabilities are structural rather than configurable. Outcome - High-impact generative AI risks are structural properties inherent to architectural design rather than isolated, patchable bugs.
- Effective risk mitigation requires a layered defense-in-depth model that combines traditional cybersecurity controls with AI-specific mechanisms such as context separation and tool sandboxing.
- Transatlantic regulatory divergence establishes EU frameworks as the de facto technical baseline for multinational deployments, driving global architectural convergence.
What it means for you
  • CIO / IT Executive: On Monday morning, initiate a review of the current generative AI system architecture and identify which of the five layers (e.g., prompt engineering, model, data, tools, infrastructure) represent the highest structural risk based on the research's threat taxonomy. Prioritize a pilot project to implement context separation and tool sandboxing for a critical generative AI application.
  • IT Manager: On Monday morning, schedule a team meeting to map the specific adversarial techniques identified in the research (e.g., prompt injection, data poisoning, model evasion) to the current generative AI tools and integrations in use. Document which of these techniques pose the most significant structural risk to your deployed systems.
  • Business Strategist: On Monday morning, begin researching the EU's AI Act and its implications for generative AI deployments. Identify how the research's findings on divergent EU-US governance regimes suggest that adopting EU-like technical security baselines will be crucial for global market access and competitive advantage.
  • Researcher: On Monday morning, focus on replicating the research's methodology by attempting to map a specific novel adversarial technique against a widely used generative AI reference architecture, documenting any emergent failure modes observed and comparing them to the research's findings.
  • Policymaker: On Monday morning, analyze the comparative governance analysis presented in the research, specifically focusing on how the EU's framework is driving global architectural convergence. Draft a memo outlining potential legislative actions to align US generative AI security regulations with the EU's technical baseline to foster transatlantic interoperability and responsible innovation.
Generative AI Security, Cybersecurity Architecture, AI Governance, EU AI Act, NIST AI RMF, OWASP LLM Risks, MITRE ATLAS
Load More Showing 18 of 58