AI 中文总结
研究人工智能应用、网络安全治理与公共部门制度约束交叉问题,提出七领域类型学和三途径失败模型,构建覆盖矩阵测试治理框架,发现问题并引入速度不对称概念,为政府组织人工智能网络安全成熟度模型提供设计规范。
AI 中文摘要
人工智能应用、网络安全治理和公共部门制度约束的交叉在现有文献中尚未作为一个统一的分析问题进行研究。现有研究分别探讨人工智能网络安全风险、公共部门治理和框架充分性。本文填补这一空白,提出七领域类型学,识别出基于公共部门制度分析的十种特定人工智能驱动的网络治理失败原因;呈现三途径失败模型,展示问责失败、运营弹性失败和合规失败如何相互作用和强化;构建结构化覆盖矩阵,测试五个主要治理框架,发现无框架能解决公共部门应用所需操作特异性下的影子人工智能、速度不对称或治理真空问题。本文引入速度不对称这一结构化概念及特定机制,该框架为政府组织的人工智能网络安全成熟度模型提供设计规范。
英文摘要
The intersection of artificial intelligence adoption, cybersecurity governance, and public sector institutional constraints has not been examined as a unified analytical problem in the existing literature. Studies address AI cybersecurity risks generically, public sector governance independently, and framework adequacy separately. Existing studies have not integrated these three streams to explain specifically how AI adoption causes cybersecurity governance failure in government organizations, nor test existing governance instruments against AI-specific public sector failure causes. This paper ad-dresses that gap. It proposes a seven-domain typology identifying ten specific AI-driven cyber governance failure causes grounded in public sector institutional analysis. It presents a three-pathway failure model showing how accountability failure, opera-tional resilience failure, and compliance failure interact and reinforce each other. It de-livers a structured coverage matrix testing five major governance frameworks (NIST CSF 2.0, ISO/IEC 27001, COBIT, NIST AI RMF, and ISO/IEC 42001) against the typology, finding that no instrument addresses Shadow AI, speed asymmetry, or gov-ernance vacuum at the operational specificity required for public sector application. The paper introduces speed asymmetry as a named structural construct with a specified mechanism. The framework provides the design specification for an AI-enabled cyber-security maturity model for government organizations.
CommentsAccepted at Conference ML4CS