arXiv:2607.25368cs.AI2026-07中稿 · Conference ML4CS

剖析政府机构AI部署中网络安全治理失效的根源,提出可评估的分析框架。

AI Deployment and Cyber Governance Failures in Public-Sector Organizations: A Typological Analysis

  • 构建七领域十类型治理失效模型,结合公共部门制度特点。
  • 发现现有五大治理框架均无法应对影子AI、速度不对称等核心问题。
  • 提出速度不对称新概念及适配政府的智能安全成熟度模型设计。

现有研究将人工智能安全风险、公共部门治理与框架有效性分而论之,未系统分析三者交织下的治理失败机制。本文提出一个七领域十类型的分类体系,揭示政府机构在AI应用中导致网络安全治理失效的特定原因。构建了问责、运营韧性、合规三大路径相互强化的失效模型。通过结构化覆盖矩阵评估五项主要治理框架(NIST CSF 2.0、ISO/IEC 27001、COBIT、NIST AI RMF、ISO/IEC 42001),发现它们均未能在操作层面充分应对影子AI(Shadow AI)、速度不对称及治理真空等问题。论文首次将‘速度不对称’确立为结构性概念并明确其作用机制,提出了适用于政府机构的智能化网络安全成熟度模型设计规范。

原文摘要 · Abstract (English)

The intersection of artificial intelligence adoption, cybersecurity governance, and public sector institutional constraints has not been examined as a unified analytical problem in the existing literature. Studies address AI cybersecurity risks generically, public sector governance independently, and framework adequacy separately. Existing studies have not integrated these three streams to explain specifically how AI adoption causes cybersecurity governance failure in government organizations, nor test existing governance instruments against AI-specific public sector failure causes. This paper ad-dresses that gap. It proposes a seven-domain typology identifying ten specific AI-driven cyber governance failure causes grounded in public sector institutional analysis. It presents a three-pathway failure model showing how accountability failure, opera-tional resilience failure, and compliance failure interact and reinforce each other. It de-livers a structured coverage matrix testing five major governance frameworks (NIST CSF 2.0, ISO/IEC 27001, COBIT, NIST AI RMF, and ISO/IEC 42001) against the typology, finding that no instrument addresses Shadow AI, speed asymmetry, or gov-ernance vacuum at the operational specificity required for public sector application. The paper introduces speed asymmetry as a named structural construct with a specified mechanism. The framework provides the design specification for an AI-enabled cyber-security maturity model for government organizations.

AI治理网络安全公共部门框架评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。