Artificial intelligence governance, management and risk management - A look into EU AIA, standards and other frameworks from practical level
Full text
Juho Reivo ARTIFICIAL INTELLIGENCE GOVERNANCE, MANAGEMENT AND RISK MANAGEMENT - A LOOK INTO EU AIA, STANDARDS AND OTHER FRAMEWORKS FROM PRACTICAL LEVEL JYVÄSKYLÄN YLIOPISTO INFORMAATIOTEKNOLOGIAN TIEDEKUNTA 2024
ABSTRACT Reivo, Juho Artificial intelligence governance, management and risk management - A look into EU AIA, standards and other frameworks from practical level Jyväskylä: University of Jyväskylä, 2024, 89 p. Cybersecurity, Master’s Thesis Supervisor(s): Lehto, Martti; Kari, Martti This thesis explores the governance of artificial intelligence (AI) through various frameworks, emphasizing the necessity of comprehensive management beyond technical solutions in order to achieve effective and secure AI in a complex socio-technical world. The research posits that AI risks cannot be mitigated solely through technical means or managed through a singular strategy at a single level. The central hypothesis is that small organizations struggle to meet the demands of prominent AI frameworks, which often overlook the unique situation of these entities and particularly the challenges faced by small public sector organizations. The study highlights how practical level issues within these frameworks may threaten AI adoption. This research examines three key frameworks: the European Union Artificial Intelligence Act (EU AIA), ISO/IEC 42001:2023, and the National Institute of Standards and Technology AI Risk Management Framework (NIST RMF). The primary research question investigates practical risk management issues related to AI governance and human roles within these frameworks. Findings suggest that these frameworks are extensive and challenging for small organizations, particularly in the public sector, which often have limited IT and security resources. The study underscores the importance of selecting and calibrating governance frameworks appropriately, as inadequate frameworks render digital security efforts ineffective. Closer examination is also done in order to clarify structures of frameworks for effective governance and management of AI systems, risks and digital security aspects. Keywords: artificial intelligence, AI governance, risk management, digital security, security governance, frameworks, level structure, public sector, small organizations
TIIVISTELMÄ Reivo, Juho Tekoälyn hallinnointi, hallinta sekä riskienhallinta – Katsanto EU:n AIA:han, standardeihin ja muihin ohjausmalleihin käytännön toteutuksen tasolta Jyväskylä: Jyväskylän yliopisto, 2024, 89 s. Kyberturvallisuus, pro gradu -tutkielma Ohjaaja(t): Lehto, Martti; Kari, Martti Tässä lopputyössä tarkastellaan tekoälyn hallintaa eri viitekehysten avulla ja korostetaan, että teknisiä ratkaisuja laajemman kokonaisvaltaisen hallinnan tarve on tarpeen, jotta tekoäly olisi tehokas ja turvallinen monimutkaisessa sosioteknisessä maailmassa. Tutkimuksessa esitetään, että tekoälyyn liittyviä riskejä ei voida lieventää pelkästään teknisin keinoin eikä niitä voida hallita yksittäisellä strategialla yksittäisellä tasolla. Keskeinen hypoteesi on, että pienillä organisaatioilla on vaikeuksia vastata tunnettujen tekoälykehysten vaatimuksiin, joissa usein jätetään huomiotta näiden toimijoiden erityinen tilanne ja erityisesti julkisen sektorin pienten organisaatioiden kohtaamat haasteet. Tutkimuksessa tuodaan esiin, miten käytännön tason toteutus näissä kehyksissä voivat uhata tekoälyn käyttöönottoa. Tutkimuksessa tarkastellaan kolmea keskeistä kehystä: Euroopan unionin tekoälylaki eli Artificial Intelligence Act (EU AIA), ISO/IEC 42001:2023 ja National Institute of Standards and Technology AI Risk Management Framework (NIST RMF). Ensisijainen tutkimuskysymys tarkastelee käytännön riskinhallinnan kysymyksiä, jotka liittyvät tekoälyn hallintoon ja ihmisten osuuksiin näissä kehyksissä. Tulokset viittaavat siihen, että nämä kehykset ovat laajoja ja haastavia pienille organisaatioille, erityisesti julkisella sektorilla, joilla on usein rajalliset tietojärjestelmähallintoja turvallisuusresurssit. Tutkimuksessa korostetaan, että on tärkeää valita ja kalibroida hallintakehykset asianmukaisesti, sillä soveltumattomat kehykset tekevät digitaalisen turvallisuuden ponnisteluista tehottomia. Tarkempaa tarkastelua tehdään myös tekoälyjärjestelmien, riskien ja digitaalisen turvallisuuden näkökohtien tehokasta hallinnointia ja hallintaa koskevien kehysten rakenteiden selventämiseksi. Asiasanat: tekoäly, tekoälyn hallinto, riskienhallinta, digitaalinen turvallisuus, hallinnollinen turvallisuus, viitekehys, tasorakenne, julkinen sektori, pienet organisaatiot
3 LIST OF FIGURES FIGURE 1 Statistics of search trends from Google Trends from past five years up to May 9th 2024 .……..………………………………………………………….. 18 LIST OF TABLES TABLE 1 Illustrative matrix of the used framework …………………….……… 57 TABLE 2 List of texts selected for closer analysis .……………...……………. 58-59
TABLE OF CONTENTS ABSTRACT TIIVISTELMÄ LIST OF FIGURES LIST OF TABLES 1 INTRODUCTION.................................................................................................6 1.1 General background for this thesis..............................................................6 1.2 Personal notes.................................................................................................8 2 RESEARCH TOPIC AND METHODOLOGY..................................................9 2.1. Context and focus..........................................................................................9 2.2. Central concepts, terminology and phenomena.....................................12 2.1.1 Socio-technical systems....................................................................12 2.2.1 Risk, security and risk management terms...................................14 2.2.1.1 Digital operating environment...........................................14 2.2.1.2 Risk.........................................................................................15 2.2.1.3 Digital activity risk...............................................................15 2.2.1.4 Digital security......................................................................15 2.2.1.5 Cybersecurity........................................................................16 2.2.2 Artificial intelligence definitions....................................................17 2.2.3 Governance, management, controls and levels............................18 2.2.3.1 Governance and management............................................19 2.2.3.2 Controls..................................................................................19 2.2.3.3 Level structures of meaning making.................................20 2.2.4 Roles....................................................................................................21 2.3. Research aim and questions.......................................................................21 2.4. Structure and methodology.......................................................................22 2.5. Selection of sources.....................................................................................24 3 THEORETICAL BACKGROUND....................................................................26 3.1 Complexity and Socio-technical systems..................................................26 3.2 Meaning of AIs in today’s world...............................................................29 3.3 Public sector organizations and AI............................................................33 3.4 Frameworks for governance and management.......................................36 3.4.1 Definitions and essence of frameworks.........................................36 3.4.2 Two types of frameworks to balance and benefit........................38 3.4.3 Levels as disambiguation tool for frameworks............................39
5 3.4.4 Aspects of AI discourses affecting AI frameworks......................42 3.4.5 Controllable aspects of AI frameworks.........................................44 3.5 Risk management.........................................................................................45 3.6 The challenges of humans in AI governance...........................................49 4 ANALYSIS OF THE SELECTED FRAMEWORKS........................................53 4.1 Selection of examined frameworks............................................................53 4.2 Previous research on these frameworks...................................................55 4.3 Framework for analysis...............................................................................56 4.4 Reading of frameworks...............................................................................57 4.5 Analysis of selected frameworks texts......................................................59 5 CONCLUSIONS..................................................................................................63 5.1 Conclusions and remarks on the research................................................63 5.2 Evaluation and notes on work....................................................................65 5.3 Potential further research............................................................................67 SOURCES.......................................................................................................................69
6 1 INTRODUCTION This Master’s level thesis is about artificial intelligence and some of the aspects of governing it via various frameworks. This first section introduces the topic area and some background of the work. There are also some personal notes. Later sections include descriptions of the research topic and methodology, a theoretical section where relevant previous writing in related areas is looked at, a section where selected framework documents are examined, and finally a concluding section. 1.1 General background for this thesis Artificial intelligence (AI) has become an object of interest to the general public within the last two years. This can be seen from search engine trend data1 as well as from the myriad of news articles. Grace et al. (2024) describe 2023 to have been an eventful year of AI progress, including the launches of ChatGPT and GPT-4, Bard, Bing AI chat and Claude 1 & 2 models, as well as a shift in the public awareness of AI issues – of which they name as evidence publicized letters and governmental advocacy on the topic (Grace, Stewart, Sandkühler, Thomas, Weinstein-Raun & Brauner, 2024, p. 2). This newfound interest has sparked a lot of activity and increased all kinds of speculative hype. Professionals and academics have had more stabler interest in this field of research but have nevertheless also increased efforts as there are more financial interests involved as well with the publicity. European Union’s legislation train is one of the more stable entities and had started its trek long before ChatGPT came along. But, even the EU’s Artificial Intelligence Act (AIA) conductors were surprised and the legislation had to 1 For instance, see https://trends.google.com/trends/explore?date=today%205-y&q=ai&hl=enUS
7 go through some changes – some of which are still not all known, as additional documents and policies are not ready. AIA is not yet in full effect as it entered into force August 1st 2024, but has transitional periods (European Commission, 2024a). Some of the required European standards won’t be ready until 2025, or possibly 2026. Nevertheless, AIA has influenced at minimum European AI development already at draft stages, and it will continue to do so from here on out. Even during the transitional period there is formalized voluntary compliance offered via a pact (European Commission, 2024b). Still, governance of AI is in its early stages – and both ”governance” and ”AI” concepts have alternatives, depending on the viewpoint and area of activity. There are already other guiding documents and standards to support AI development and the needs governance of today. What connects them all is that they are in flux – all of them are to be updated as understanding of AI and governance needs progresses. Of all the various changes that are seeping into AI governance and management in all levels, the part of roles that are associated and assumed along with AI adoption is less clear. In most cases it seems that guiding materials require organizations to be entities of shared responsibility, hiding inside it how those responsibilities and roles are actually implemented. Real responsibility should be clear and the person who ultimately bears that weight should be known. This is relevant not only legally, but for so called ethical and trustworthy AI, as part of creating trust and good governance culture that supports AI use. Research into this governance aspect would seem desirable, as many organizations are about to embark on their AI journeys. The governance and management of AI is inherently linked with various security, privacy and safety aspects. All those areas - from cybersecurity to information security, from digital security to consumer safety – get their bearings from how governance and management are structured. These concepts are, much like the AIA has tried to be, risk based and relative. The language of risks and risk management can be seen as a common denominator. Thus, risks and the roles which are needed to manage them have been taken as the focus of study. In general, Reeshad et al. note that in cybersecurity research of the ”human factor” is much less studied than technology (Reeshad et al. 2022, p. 1). This thesis is built on the notion that not all AI risks can be mitigated via technical means and therefore management and governance are needed. To clarify, managing particularly intricate and complex risks cannot be comprehensively accomplished through a singular strategy at a single level. Questions related to trust, ethics and biases should be seen as an extension of AI risk management in the complex socio-technical whole, often dealing with nuances that can develop into more tangible risks in the future. Combination of controls is needed that also utilize different levels to achieve needed comprehensiveness and depth for truly safe, secure and trustworthy AI systems and services.
8 The underlying hypothesis is that small organizations are unable to handle the requirements set by most notable AI frameworks. Those frameworks do not take into account the nature of most organizations. At the same time those frameworks – which are created at the highest levels by large institutions – expect all the development, responsibility and liability to rest on the grassroots level. If only a fraction of organizations are capable of utilizing the frameworks and influencing such things as trustworthiness or ethics, the AI playing-field is in essence only the playing-field of the few larger organizations. Comprehensive participation in AI guidance may in reality not be possible due to lack of organizational resources. This question of size seems particularly relevant with public sector organizations as they have limited budgets and staff resources, particularly in such human resources areas that are very competitive and notably missing experts - like IT and cybersecurity. 1.2 Personal notes This thesis is the culmination of several paths. It is the second university master’s thesis for this writer – this time for a different department and with different tools, and subsequently with different experiences. This is also both, a continuation of previous thoughts as well as clarification of new ones, both academically and professionally. This thesis combines some ideas that have been brewing for a decade, along with some that were possible to frame only mere months ago. For understanding these topics, and their synthesis, this to be a mere waypoint, not an end. It should not be considered likely that AIs, AI governance or AI risks and risk management would be fully developed and understood within our lifetime. During the process of creating this thesis, the topic and interests have shifted several times over the last years. Two primary challenges emerged during the work: an all-encompassing curiosity within the field, which took me to many winding rabbit holes, and secondly, a strong pull toward another topic area, which however in the end did not seem to lead toward a continuation that would be of interest. It took some time and effort to focus and aim toward something potentially useful. This feels important to point out as this is meant as a salutation and thanks to my former teacher and thesis advisor, who passed away during this process. His teachings on the importance of proper processes and frameworks may not be known to most but those are some of the key learnings. His intelligence and tenacity were inspiring.2 2 As a fitting memory to include regarding this point, in the last conversation we had, he urged: ”You really should graduate. The university needs the money”. Yes, sir. And thank you for the encouragement.
15 tems, as doing so would have been impractical, since cybersecurity intends to secure the digital environment, and everything related to it. As there are different discourses of cybersecurity, it would be imaginable that certain differences remain. Reeshad et al. have noted that workplace safety and security of digital operating environment, or digital realm, have a lot in common, to the extent that their theories should be applicable across these research fields. This is relevant considering how multidimensionally this thesis approaches the topic. (Digital and Population Data Services Agency of Finland, 2022, p. 9, 13-16; Reeshad et al. 2022, p. 14). 2.2.1.2 Risk Risk has been defined as “effect of uncertainty on objectives”, which follows the higher level ISO31000 series definition instead of using its descriptive attributes, likelihood and impact. This more general definition is more suitable with complex socio-technical systems, as opposed to the more closed systems context appropriate alternative, while still allowing their use as possible assessment tools. The ISO terminology also includes level of risk, which sets it apart from other frameworks. Risks have a negative connotation, at least in Finnish, Swedish and English, but modern risk management recognizes that they also often bring about possibilities for opportunities as a side-effect, which in turn often leads to change. (Digital and Population Data Services Agency of Finland, 2022, p. 25; Schmidt, 2023, p. 12-16; Järvinen, 2018, p. 47-48, 60) Risk is a relatively recent concept in human culture. Before, in the pre-industrial times, there was only good or bad fortune. These were explained by attributing them to gods (external) or personal prudence (internal). This has not changed, as assigning blame to external sources (other people, systems, rules, aliens etc.) is still used as protection from responsibility (Luhmann, 1996b, p. 3). 2.2.1.3 Digital activity risk Digital activity risk is ”a risk active in the digital operating environment, applicable to or resulting from the digital operating environment”. This definition expands risk concept in a way that is in line with socio-technical structuring as risk can com from beyond digital environment to it but also, they can manifest in digital but their direct or indirect effects may escape into the real world. (Digital and Population Data Services Agency of Finland, 2022, p. 16, 29) 2.2.1.4 Digital security Digital security is defined as ”a target state where a digital operating environment can be trusted and operations both there and related to it are secure and managed, even in the event of disruptions”. This definition is based on Organisation for Economic Co-operation and Development’s (OECD) development of this terminology to
16 be more inclusive to other human phenomena and goals in digital, from what cybersecurity had been used, which has discourses more toward state security, criminal activity and technical areas. Digital security can be seen as a management framework title that gathers the various security areas (in case of Finnish public sector: management and risk management, continuity management, cybersecurity, data protection and information security, as well as any other area relevant to organization) or, in a sense, digital security can be seen as a developmental step in framing security in digital (operating) environment as technologies and ways of using them evolve and expand. New terminology does not replace the previous but adds new layers. The now more established information systems security concerns itself with the security of a system (confidentiality, integrity, availability and other such features), cybersecurity discourses expanded that more toward networks and large negative actors, and more recently digital security has been stabilizing its discourses more toward human activity on platforms and services, which is at least partly visible in how European Union has named and aimed its main legislation in this area. As AI technology and systems develop, and are more widely adopted into security, it can be asked, is autonomous security going to become more than a description to one type of security sub-area, and if not, then what terminology is going to be used and what new phenomena will it embrace. (Digital and Population Data Services Agency of Finland, 2022, p. 9-10, 13-17, 68-69; European Parliament, 2024; Organisation for Economic Co-operation and Development, 2015, p. 8, 30; Aitonurmi, Reivo, & Jokela, 2021, p. 48-50) 2.2.1.5 Cybersecurity Cybersecurity is defined as ”a target state in which threats and risks arising from the cyber operating environment to society’s vital functions or other functions dependent on the cyber operating environment are under control, even in the event of disruptions”. This is a public sector and government centric view, which is defined in a manner that fits risk management framework. This type of contextualization and even loose framework of concepts with information security and digital security supports cybersecurity activities by more clearly defining it’s area of interest to be the more critical systems and services of society, so called ”hard” security. The definition could also be expanded with for instance Reeshad et al.’s definition for organizational cybersecurity, which is “the efforts organizations take to protect and defend their information assets, regardless of the form in which those assets exist, from threats internal and external to the organization”. These can be considered applicable beyond the Finnish context, for instance with European Union and AI Act. (Digital and Population Data Services Agency of Finland, 2022, p. 13-14, 17; Reeshad et al. 2022, p. 4-5)
17 2.2.2 Artificial intelligence definitions Viljanen (2023) advocates that the AI definition should be wide and include all socio-technical systems that include non-biological electronic computing elements that handle information (p. 1208-1209). For managing AI risks comprehensively, beyond mere AI system risks, this inclusive definition is preferable and is used in this research if not otherwise stated. For when AI is more specifically discussed as a system, the updated 2024 Organisation for Economic Cooperation and Development (OECD) definition and supporting memorandum is used: “An AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment” (Organisation for Economic Co-operation and Development, 2024. p. 4-9). The European Union’s Artificial Intelligence Act (AIA) in Article 3 (1) definition, that is intended for judicial context, uses very similarly worded version based on OECD’s versions (European Parliament and Council, 2024). Within the previously given definitions there are still a lot of specific ares which may have to be taken into consideration with AI definitions. The current dominant AI technology, generative pre-trained transformers (GPT), which use large language models (LLM), are literally based on previous information and history, and therefore they are limited by it by being only able to offer outputs based on re-using what has been thought of, created and digitally recorded in the past (Runco, 2023, p. 4-5). This still allows for many different applications. In many cases even simplistic repeated statistical mediocre capabilities based on sub-optimal data may be useful and even give above average results – though likely not perfect. Re-mixing all that information can create something a particular observer has not seen or thought of before, but within limits. GPTs, LLMs and other AI techniques have been indeed applied in all kinds of clever manner. When looking at internet search term popularity statistics (figure 1), there seems to be visible correlation between AI and GPT becoming popularized at the end of 2022. The similarities of their trend lines is a visible indicator that general public associates them strongly as interchangeable terms. As AI is currently seen to be almost solely GPT based, this may have led to some expectations, namely that all AIs work with natural language (human-style interaction and even personality), hallucinate (a human mental phenomena used to describe an unexpected but non-flawed technical process), are mostly not up to date (based on old data), and to some extent that AI requires large cloud services (due to how AI is offered as a services). These could affect how AI technology and AI systems are are trusted, which in turn has implications on how
18 AI is and should be governed. These issues are discussed further in later sections. Figure 1. Statistics of search trends from Google Trends from past five years up to May 9th 2024. AI and GPT became popularized at the end of 2022, which can be seen from the data, comparing to previous years. Graph shows a five-year span of worldwide searches. The apparent similarity of graph lines of the search terms “AI” and “GPT” indicates a strong association and interchangeability of these terms in the public discourse. Screenshot from https://trends.google.com/trends/explore?date=today%205-y&q=ai,gpt&hl=en 2.2.3 Governance, management, controls and levels Terminology at times encounters linguistic peculiarities. In Finnish one term can be used for both safety and security but also governance and management. This may be considered to simplify sense making of an issue in these areas as a single term is all inclusive. This may also enable for more nuanced approach as all the connotations built into separated terms – which may be juxtaposed in use – need to be expressly stated separately and more than two levels or categories of variance can be used. This semantic tool may be useful for examination of these topics. These selected terms – namely governance, management, controls and levels – are all related to coordination and regulation of activities, structures and resources. The first two are about how this is done, on higher and more practical levels respectively. For this controls are important tools. Levels refer to frameworks and structures which are one way to create meaning and under-
19 standing needed to identify, classify, plan and effectively execute governance and management. 2.2.3.1 Governance and management For this thesis, governance and management are taken to mean the same thing, unless otherwise indicated. As can be read from their dictionary definitions, the essence of these terms is the same but depending on the source, may include some additional context. This approach is in line with how these terms are used for instance in European Union’s Artificial Intelligence Act, where larger AI governance is left as organization internal process and management of various areas is part of that (European Parliament and Council, 2024). Governance definition 1: ”the act or process of governing or overseeing the control and direction of something (such as a country or an organization)” (Merriam-Webster, n.d.). Governance definition 2: ”the way that organizations or countries are managed at the highest level, and the systems for doing this” (Cambridge University Press, n.d.). Management definition 1: ”the act or art of managing: the conducting or supervising of something (such as a business)” (Merriam-Webster, n.d.). Management definition 2: ”the control and organization of something” (Cambridge University Press, n.d.). In general, governance and management are a multidimensional concept. They can be seen as coordinated interaction, formal or informal regulation and guidance, between different actors toward set goals. In public sector context governance development includes the idea of lessening bureaucracy toward more inclusive, networked and flexible services. Technology governance is different guidance, regulation and coordination mechanisms and tools applied to technology use and development, but it too has no clear definition or use. The subdomain of AI governance is similar but there seems to be emphasis toward controlling societal risks with for instance regulation, ethical principles, data governance, information guidance, resources, standards and technical controls, due to AI discourse being slanted toward those at the moment. (Sigfrids et al. 2023, p. 15-16) 2.2.3.2 Controls Control is defined as ”an action aimed at changing or maintaining a risk”. The VAHTI risk management vocabulary terminology notes add that ”Controls can be processes, operating principles, devices, policies, one-off measures or other types of activities”. Also that, ”the term management method is sometimes used as a synonym for control [method], but often management method refers to an overall solution (e.g.,
20 identification or good governance), which may include several concrete controls”. This is to be interpreted that controls are equally applicable in governance and management or any other level structure. Semantically there is also not difference between technical, administrative or any other type of controls. (Digital and Population Data Services Agency of Finland, 2022, p. 58-59) 2.2.3.3 Level structures of meaning making Concept of levels refers in this thesis to simple hierarchical structure of two or more levels. For instance, socio-technical systems levels, the Open Systems Interconnection (OSI) layer model and similarly structured frameworks. Using two levels allows for comparison of differences, but may also create juxtaposition, even adversarial positioning – as in, ”us-them” or ”us-other”. This can be at least in social context problematic, if only one side is well defined and the other is essentially excluded to including everything else, as such would be akin to a closed system and its environment. In research multilevel models structure hierarchies are used to assign explanatory variables. Increasing to three or more levels of classification enables better identifying of phenomena and more precise coordination and regulation when applying it but need for simplification and usable accuracy set the upper limit in practice. In research data analysis it has however been shown that already more than three levels produce diminishing returns, but more may be needed to accurately depict reality. Neglecting levels (attributes, differences) may be damaging to subjects, weather governance or research. As per socio-technical systems, all levels influence system functioning and thus no single level can replace the other levels, for instance a level may possess an implication of importance, but it alone would not be enough. (Digital and Population Data Services Agency of Finland, 2022, p. 4748; Sommerville, 2015, p. 556-557; Gill & Womack, 2013, p. 3-5) There are various ways to create and interpret levels. For governance and management, for instance in risk management, something can be studied and handled from the same as well as from a different level. These may yield different meanings and effects. In risk management the same risk may be better identifiable at one level, have different relevance in other levels and require partial controls in all levels to sufficiently and with appropriate depth manage the risk to acceptable level. The Finnish VAHTI risk management vocabulary offers definitions for two approaches and three basic levels6 : Processing levels are defined as ”the level at which a risk is addressed” (mostly ontological). 6 Notably, the VAHTI risk management vocabulary intentionally avoids terms “operational” and “tactical” in naming levels, siting avoidance of military terminology in civilian use, confusion in various contexts of their hierarchical order as well as the use of “operational” as a label for risks and other uses (Digital and Population Data Services Agency of Finland, 2022, p. 47).
21 Review levels are defined as ”the level from which a risk is viewed” (mostly epistemological). Strategic level is ”a decision-making level within an organisation at which decisions are made related to the operating environment and the financing of operations, and concerning the operation and development of the entire organisation”. Organizational level is ”a decision-making level within an organisation at which decisions are made regarding the organisation of the operations of individual operational areas and units, taking strategic-level decisions into account”. Functional level is ”an organisation’s decision-making level, at which, taking into account decisions made at the strategic and coordination levels, decisions on implementation and enforcement are made”. As alluded previously, using VAHTI’s vocabulary offers a multi-stakeholder predefined framework that incorporates public-sector nuances and management methodology to risk management standards and ties those to digital security and digital realm in a systematic way. (Digital and Population Data Services Agency of Finland, 2022, p. 6-8, 46-51, 59) 2.2.4 Roles Role in this thesis is limited to human activity, particularly in regard to how these are incorporated to governance and management frameworks to counter AI risks, which is discussed further later in the theoretical section. As Colman and Han put it, ”in its general usage the concept of a role defines the relationships of an individual within a particular social context”. They further note that entities that inhabit these roles have varying degrees of capabilities and autonomy, likely based on their position in hierarchical levels. In an organization-centrist view, identity of roles derives from organization, not the person filling that role. As such, roles are seen more stable entities and are seen to perform a function in an organization. (Colman & Han 2005, p. 2) 2.3. Research aim and questions Research in the area of artificial intelligence is moving fast, in a cycle where on one hand research findings make new AI applications possible and on the other hand new applications open avenues for new research. Several groups have voiced that AI development seems to move faster than understanding and risk mitigation in the field. According to research done to AI experts, they however were divided on would fast or slow process be ultimately better for humanity (Grace et al., 2024, p. 15-16). As this thesis aims to examine, among others,
22 frameworks that are recent and not yet even in effect or applied, it seems safe to assume that any research on this is timely and the questions presented have not been answered. In this thesis the research questions are formulated as: RQ 1: What practical level risk management issues regarding AI governance and human roles can be identified in the selected AI governance and management frameworks? RQ 1.1: Can analysis of roles in frameworks reveal information about how those roles are emphasized and does that reveal information about these frameworks? RQ 1.2: How do the roles in frameworks affect AI risk management and governance? The main question (RQ1) aims to examine if there are identifiable roles assigned in risk management frameworks and how they are distributed in relation to risk management framework areas of interest (or classification scheme). Although norms (laws, standards) are written in a way that aim to be general – as in, being applicable to most organization shapes and sizes – expectations to certain key roles may not be applicable in all cases. Roles may be vague and may not be identifiable as such but possibly arise when frameworks are juxtaposed. The secondary research question (RQ 1.1 and 1.2) aims to deepen the understanding of risk management of AI. This would include any observations that could possibly suggest opportunity for preferable or avoidable practices in this field to advance AI risk management. 2.4. Structure and methodology The structure of this document is introduction, framing of research and methodology, theoretical section, analysis, commentary, and list of cited sources. The research approach in this thesis is qualitative analysis of a phenomena, which is carried out by examining textual source documents. This is a qualitative exploratory study. The research methodology used is integrative literature review where the aim is to synthesize coherent and comprehensive understanding of selected topic. Used sources for this type of qualitative research may be research articles and books but also non-academic gray literature. The approach to search strategy is not to be rigorously systematic but to select sources that enable new perspectives to emerge on a continuously (re-)emerging new topic. Combining perspectives and insights form different fields of research allows using integrative review for preliminary conceptualization of
23 frameworks – as is done in this thesis. (Snyder 2019, p. 334-336, Hirsjärvi, Remes & Sajavaara, 2009, p. 128-130, 152-153) The theoretical section in is used explain and to create the basis for a specific framework matrix to define coding of roles and to use that to analyze the used sources (Juhila, 2021). The sources are surveyed for named, defined or implied roles, though some activities or requirements in the documents may not be considered to have clear roles associated with them and are therefore set aside. Some roles may be more general, but emphasis is put on those, where a role or and activity that implies an associated role are more tangible or specific in nature. A role should have as an intrinsic property its function, such as purpose or goal or process description, among other properties, which is the key identifier (Colman & Han 2005, p. 3). Retrieval of identified roles will be done manually, based on automatic keyword search results of digital documents, AI assisted subject searches of documents but also additional materials about the documents, as well as reading specific identified sections that are most likely to contain relevant information. The roles and any descriptions or qualifiers associated with them are then classified and grouped using a matrix to analyze the activity in an organization. Attention is paid to activities and their intended risk control aims, process and review levels which these roles can be associated with, as well as the type of security they are associated with within the framework of many securities. This classification is aimed to bring out possible allocation of responsibility via roles at hierarchical levels but leaving possibility that other observations may be made as well. The distribution among various areas of security is expected to bring about a view of where these documents may see risks and look counter them. Inversely, this method should also show where there may be lack or imbalance of expected responsibility to deal with the challenges faced regarding various artificial intelligence systems and services. This and further analysis comparing the various representations or roles in sources should enable to form a view on how responsibilities are formed or expected to form in secure and trustworthy AI governance. The aforementioned matrix and included classifications are constructed by using Finnish application of OECD digital security definition and risk management terminology definitions, as explained in the terminological section under framing of research and methodology. Using their structure as base strengthens the possible applicability of these findings in government and public organizations and does not limit their usability for other types of organizations as well.
24 2.5. Selection of sources The main objects of examination for this type of research are the documents describing the governance, management, risk management and security management frameworks of artificial intelligence. On these subjects there are ready and established frameworks to look into, but most of them are also recently updated, drafted or approved. One example is the European Union’s Artificial Intelligence Act (AIA), which was finalized during the time of this writing (European Commission, 2024a). Research also shows that during the last few years (2019-2022) several AI frameworks have been published or updated, mostly by governments (Xia et al., 2023, p.3). This, together with what was pointed out about in the terminology section, the AI discourse being currently GPT centric, leads to emphasizing use of relatively new research and sources, when they are related to these fast-developing areas. Regarding this, van Noord & Tangi (2023, p. 11) note that when limiting research to more current literature we may be forgetting two decades of research on digitalization and e-governance, which have created the foundations for this next step in digital evolution for public sector. This must be acknowledged and as far as more general views pertaining to administration are concerned, less recent sources have been also used. Nevertheless, as the review specifically is framed around the more recent and upcoming developments on AI, emphasis to more recent sources is seen justified when it comes to AI related matters. As the research methodology calls for selective approach to sources, guided by the needs of the synthesis creation, search strategy can be considered dynamic. In practice, these were made using internet search engine and university library search engine, emphasizing academic open online sources. In some occasions a pre-publishing version of published peer reviewed article may have been used due to access requirements. As for the selection of the objects of examination, the AIA makes mentions requiring standards compliance as part of the regulation. It is expected that the harmonized standards need to be at least ratified in European standards institutions, or that there needs to be separate European standards. At the moment the most relevant standards appear to be the global ISO/IEC standards as those are considered globally accepted standards due to the multi-national structure of their creation process. Other reason supporting their selection is the applicability to public sector and Finnish environment, where ISO standards are known well. International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) standards may later be joined by additional standards from CEN (EN), CENELEC or ETSI, but for this research the
31 fied as scope 3 greenhouse gas emissions. More and better systems are constantly developed to counter the energy and cooling challenges, but their relevance seems lacking at least for the near future. (Gnibga, Blavette & Orgerie, 2024, p. 315-317; Lin & Bunger, 2024, p. 2-3) In a global risk view these have inherent country and environmental risks which also are likely to manifest as social and economic risks. Yet, although AI may create or advance inequality, environmental problems and change most areas of life, from personal and local to national and global levels, the overall impact of AI to sustainability goals is considered positive (Filippucci et al., 2024, p. 37-42; Brollo et al., 2024, p. 6-8; Vinuesa et al., 2020, p. 1-6). For example, methods of working will change – possibly to the point that the meaning of work will change as well. Similarly, such related areas as learning and studying may follow and there may become need to do so. Advancements in efficiency of work with AI has been demonstrated in several fields, although results vary among different tasks, skills, levels and areas, and managing this change isn’t easy (Green, 2024, p. 24-27, 33-40; Dell’Acqua et al., 2023 p. 17; The Upwork Research Institute, 2024). As for the future, in repeated survey (2016, 2022, 2023) to 2778 published AI researchers, it was estimated that ”the chance of unaided machines outperforming humans in every possible task was estimated at 10% by 2027, and 50% by 2047”. The net impact of advanced AI in the future was considered to be more bad than good but the distribution of answers was wide. Although there was concern over several AI scenarios, the most important takeaway may be how expected AI developments have accelerated in the estimations since previous survey. (Grace at al. 2024, p. 1, 4-7) Using AIs to increase efficiency and advance all areas of society and technology is needed in the coming decades as, at least in Finland, economies and environmental living conditions are expected to decline in the long term significantly, forcing population to lose current standard of living (Ministry of finance of Finland, 2022a, p. 39-44; Ministry of finance of Finland, 2022b, s.3-4). This is known as sustainability gap. Beyond Finland, this ties to globally to limits of growth, where AI may be the key in creating large scale solutions to avoid drastic developments to all life on earth but also to increase efficiency and other outcomes at system level (Nebel, Kling, Willamowski & Schnell, 2024, p. 93, 97). Long term relevance of AI to humanity is inevitably linked also to the question of survival as species, although mixing such different timescale and level of risk to practical and near term convolutes any discussion. Like with some other long term impacts AI may have, these kinds of threats aren’t relevant in the foreseen future, although it is always good to anticipate all futures, plan accordingly and have guides like governance frameworks in place for desired paths. In their yearly survey international experts saw a marked difference (for emphasis, comparing two combined severest levels of 7-step Likert
32 scale: 12% in 2 years versus 51% in 10 years) between how much more risk AI poses in a decade than in the next two years (World Economic Forum, 2024, p. 50). In a different study done to published AI experts, existential AI risks to humanity were considered possible but the mean on those question is below 20%. The more relevant question in this area asks about human capability to control future AI systems, which is tied to how they are governed, and that result points toward respondents seeing this a weaker point. It is unclear if this is about the given scenario in the research survey, or possibly lack of trust in humans being able to set proper controls to advanced AIs and how well our governance and management frameworks guide toward this. (Grace et al., 2024, p. 14-15) The general relevance of AI to security and vice versa in the digital operating environment must also be considered in relation to what has been raised here, as they are needed to ensure the safe path of developing futures. Globally in ten years, technical risks (including cyber insecurity, adverse AI outcomes, misinformation and disinformation etc.) are ranked toward the top of the most worrisome risks, second only to environmental risks, to which technology has a connections (World Economic Forum, 2024, p. 11). In a separate global survey (Bueermann & Rohrs, 2024, p. 6) of most concerning impacts of generative AI to cybersecurity, “increased complexity of security governance” was ranked third (9%), after data leaks (20%) and advanced adversarial capabilities (46%), underlining both how attention consuming immediate threats are and how such all encompassing future challenge is already clearly identifiable right after them. All security facets – information security, privacy, cybersecurity and others, even including the physical realm where equipment lie – are seen to become more and more challengingly complex (Mattioli & Malatras, 2024, p. 1417; Cleaveland et al., 2023, p. 7-9, 12). This is compounded with the estimate that ensuring security will have resource shortage of skill and labor to mach this (Bueermann & Rohrs, 2024, p. 7, 18-19, 31; ISC2, 2023, p. 11). More importantly, the challenge – which can be described as increase in all security complexity (of identifying, understanding and managing etc.) – has been noted as one of main future risks by public sector experts at least in Finland (Reivo, 2023, p. 13-14). As threats become more intricate, faster, automated and constantly evolving, mere human capacity to respond is limited. For the foreseeable future, AI may become the viable solution to bridging these gaps (Marchal & Nawrotek, 2024, p. 34-39; Jada & Mayayise, 2024, p. 8-9). These are some of the most central strategic level threats that societies today need to work on and plan for in the mid to long term.
33 3.3 Public sector organizations and AI People do not readily trust in AI. This is particularly true in Finland (Digital and Population Data Services Agency of Finland, 2023a) but in varying degrees in other countries as well. Approximately 73% of global respondents felt concerned about AI risks, including cybersecurity which was in top two mentioned in all countries. More specifically, it is indicated that people are more trusting of outputs of AI systems than they are in trusting their information to an AI system. This further implies that systems that handle personal information are less likely to be trusted and used, compared to more general system that alternatively might use for instance non-personal environment data or general information. It is also suggested that educated and advanced countries have more suspicion toward AI in general. (Gillespie et al., 2023, p. 13, 25, 42, 71) Particularly in regard to public-sector, there are a lot of risks imposed to individual citizens if AI is not governed appropriately and digitalization fails them. Basic rights could be threatened: principles of good government might not be applied, personal data protection could be bungled, inequality and discrimination rear their heads, arbitrariness weaken faith in legality, proportionality and objectivity be missing from administrative processes, and so on. Mere doubt and fear of losing known status may have a chilling effect on considering AI. Poorly implemented AI systems could lower trust to public services and servants, weakening societal cohesion and administrative efficiency and upkeep of values. These are not questions and risks that private sector organizations must consider. This has been noted by public sector, for instance in digital security risk management value model in Finland, and by researchers, that public sector differs from private sector in governance, and by extension security and AI risks – how risk appetite and valuations work for example – as its activities are tied to public interest. These are often codified in laws (expected minimums as per legal minimum standard principle) and, in the other end of spectrum, projected as hopes in public discourses or policies (expectations beyond average and having higher standards). (Digital and Population Data Services Agency of Finland, 2023b, p. 26-29; Autioniemi, 2020, p. 6-7, 9) Trust is an important aspect with public sector AI systems and services since lack of it will likely diminish the efforts to acquire and implement AI, slow public’s adoption of systems that include AI and hamper the potential efficiency gains that these organizations will need. A study suggests that there is a strong correlation between trust in public sector AI and the trust people have to their government officials and institutions. It is further suggested that so called institutional pathway of building trust in AI and its security via good gover-
34 nance with strong frameworks is the best path to do so. (Gillespie et al., 2023, p. 4, 6, 17) In their preliminary review on the potential impacts of AIA, Paasikivi and others remind us that in addition to formal administrative decisions, it has been established that other administrative actions that have substantial impacts also fall under exercising public power and therefore under legality principle, at least in Finland’s legal system. More importantly for this research, seemingly separate activities of supporting systems development, implementation and management of AI may also in some cases fall under this requirement. The roles and responsibilities in these areas then may play a key part in drawing the proverbial lines when it comes to acceptable, safe, secure or trusted AI. Some legal principles are likely to require that certain elements of AI systems are therefore designed, implemented and managed internally in public organizations. (Paasikivi, Tuohino, Mansnérus & Lång, 2022, p. 17, 19, 40; Finland, 2018, sections 21, 118, 124; Finland, 2003, sections 2, 4-7, 9-10) So called black boxes may function in a manner that the creators of the program’s could not anticipate as there’s proverbially no view to see inside how they work. This problem can be classified into weak and strong, where in the weak case it may be possible to reverse engineer an AI afterwards to derive some information on how the result came to be. But even then, it is impossible to determine was the software designed or instructed to behave in such manner. In the strong case, all insights to AIs thought processes are impossible. This goes to the heart of legal argumentation as this makes it practically impossible to establish intent of the AI creators and administrators – as well as objectively of the AI itself, should its agency ever be argued. Intent is important aspect when evaluating outcome. Another central tenet of law is that it must be determinable that harm was the result and connected to the act, which is unlikely to be established in a dynamically changing system. (Bathaee 2028, p. 906-908, 921-924) If the use of AI systems would not be regulated pertaining to public governance and administration, this could lead to a situation whereby having AI involved in such processes, liability could not be established, effectively becoming a curtain or shield against any responsibility for actions. It must be noted that Bathaee is writing about AI, but any large enough system with complex algorithms may be likewise beyond human comprehension to satisfy the aforementioned requirements. These are the basis why humans need to be in the loop and their involvement governed. Autioniemi (2020) points out that public sector has imbalance toward exploitation of AI compared to exploration. For the public sector, technology is means to enhance efficiency, coordination and organization of services, or, to put it in another way, an answer how organizations can have influence, quality, efficiency and be productive. On the one hand, bureaucratic entities are not op-
35 timal for innovation but at the same time they are well suited for being platforms for AI use. (p.5-6, 8, 11, 17) Public sector processes for digitalization and technology acquisition can be described with a train metaphor. It is a train where the challenge to be solved should be the locomotive, followed by several train cars that need to be solved in order, before moving to the next: issues of legality, strategic positioning, acquiring know-how and resources, ensuring financing for the endeavor, and only after those – in the final traincar – the technology and it’s implementation. (Latvanen, 2023)8 AI ethics and security should be in that train, preferably before implementation. Often these seem to be missing or are superficial, both in public sector projects but also in research9. This may be because some aspects are rigorously required only from public sector organizations, setting them apart from other organizations, and because research indicates that AI projects often have small teams of one or two people, who may not even be full-time, and therefore may not have prerequisite skills, resources and time for them (Deloitte, 2020, p. 188; Reivo, 2023, p. 14-15). Study on public sector AI projects points that AI can be acquired into an organization via internal skills and infrastructure or via external, but this division effects the outcome of the capabilities that are created to the organization. Financial resource limitations are a main influence when selecting appropriate balance. Ad hoc and sporadic funding will hinder acquiring, sustaining and developing any capabilities, and often this leads to exceedingly external solutions. This means, many of the roles and skills needed for the organization to excel in AI are not internally handled, affecting quality and economics of governance, management and security alike. This is not to say both internal and external partners are not crucial in developing AI capabilities, but empirical evidence suggests a core team is needed. It is also noted that there is a distinction between having capabilities to develop AI and to implement AI in organizations. 8 AI ethics expert Marko Latvanen, Chief Senior Specialist at the Digital and Population Data Services Agency of Finland (DVV) has given credit for the metaphor origin to late Finnish politician, member of the parliament, and eminent technologist, Jyrki J. J. Kasvi (Ph.D.). Original idea was to depict what barriers come after an idea, before a public sector organization can actually procure and use technology. It can be further expanded to include the mentioned security and ethics preceding the new technology, but also adding following train cars as well, which should be considered beforehand (including budgeting decisions for future years) despite that they appear later in the process – namely deployment and change management, and ”upkeep” (or maintenance and life-cycle management). A good enough locomotive will pull all those train cars. Such considerations are applicable in any digitalization and technology project, not just AI systems. This train model of public sector technology adoption should be dubbed the Wexteen Train, in reference to Kasvi (Wikipedia, n.a.). 9 For instance, in the AIGA model does not mention all of the security areas that a modern organization is expected to implement. Although they can have been written inside “AI development” and “AI operations” governance tasks, most governance components can be seen to need specific security tasks. (Mäntymäki, Minkkinen, Birkstedt & Viljanen, 2023, p. 8-9, 20)
36 The latter requires more resources, more comprehensive strategic alignment, organizational changes, legal requirements certainty and change management to ensure adoption to wide use. (van Noordt & Tangi 2023, p. 6-8, 10-11) 3.4 Frameworks for governance and management Frameworks are tools of coordination. Their existence is often between the 2022b strategic and the practical, although they may be aimed at various levels in between. Frameworks are a tool that can be used to control AI system aspects and other areas of activity. They formalize and make alike, which allows for efficient coordination at scale. According to study, organizations can directly affect building trust and use of AI by supporting and implementing governance and management frameworks that ensure security and ethics principles are followed (Gillespie et al., 2023, p. 4). There are different frameworks and they are now developed quite quickly as guides to help facilitate faster adoption of new technology and manage the associated risks (Budler & Trkman, 2019, p. 3; Digital and Population Data Services Agency of Finland, 2022, p. 46-51). In the following sub-sections, the definition and features of frameworks are discussed further, in general as well as in governance AI context. 3.4.1 Definitions and essence of frameworks Broadly put, a framework is created to support and coordinate several (somewhat) equal, competing, supporting or symbiotic aspects in a topic. It is a conceptional structure and frame of reference (Merriam-Webster, n.d.). As Budler & Trkman (2019, p. 7) put it: ”almost anything can be divided on two dimensions and shown in a matrix”. Matrices and blocks may be cognitively light and thus psychologically appealing, but also seemingly universally interconnecting as our minds try to find ways to make sense of relations of their concepts (Budler & Trkman, 2019, p. 19-20). Using ”framework” as a general term, we may in this research broadly read within it laws, standards and less formal idea constructs, like principles, as they consist and are part of other frameworks. When processes are described, whether it’s organizations business, IT systems, services, security or general technology, its often done in the larger planned and systematic context of architecture modeling. Levels help to define the scope and detail of those plans by simplifying the real-world phenomena and by hiding what’s unnecessary. They can be done from multiple viewpoints to include all stakeholders. There are several modeling frameworks but as an example, one of the most successful is The Open Group Architecture Framework (TOGAF), which is also used as the base for now deprecated JHS179 and
37 JHS 152 recommendations that can still use in Finnish public sector. Architectures use stricter definitions to better bind together various frameworks by making them compatible. (Luukkonen et al., 2012, p. 21-24, 28; Digital and Population Data Services Agency of Finland, n.d. a; Digital and Population Data Services Agency of Finland, n.d. b) A framework can be created and used for several purposes, one of which is to set limits – minimums and maximums – for guidance. They also intentionally or unintentionally define discourses as the penalties and rewards associated with abiding to frameworks motivate to shape interaction about the topic. This may be useful and required at times but may also limit views beyond the designed uses and contexts. There are also varying approaches to frames of reference. Some may take a stricter approach while for others they may be mere starting point to modify as needed. This is particularly notable in general, when frameworks are to set a minimum – for example for standards compliant sufficient security – which then an organization must adapt to their own operations. What is notable with AI application, due to the technology taking a leap quite recently, is that almost all of these frameworks are mostly untested and researched how they mesh together with the real world. Tappura et al. (2015, p. 2) concur by pointing out that management theories are not always validated. Using these frameworks is not entirely precarious, as they are based on research, historical examples and expert opinions, but they are not proven either. Ones, which have had open participatory processes, are likely to yield better results. Most the formal AI related frameworks will be 2022b updated as experiences accumulate. For instance, EU AIA, which has review process deadlines starting from 2028, and ISO standards, which have their own review cycle (European Parliament and Council, 2024, article 112; International Organization for Standardization, 2015, p. 1-2). But, as Partelow puts it: ”While frameworks can be useful for synthesizing and communicating core concepts in a field, they often lack transparency in how they were developed and how they can be applied”. This alludes also that while frameworks are important for their uses, their application should not be without analysis, assessment and adaption. (Partelow, 2023, p. 510-511) Partelow also notes that frameworks are sometimes ”black boxes” as there may not be robust research or information on why some concepts were chosen and others were not. He argues that their content is often influenced by the positionality of the creator, ”...meaning it is located within a specific context of a scientific field”, or other area. Adding to this are lacking descriptions of how framework is related to other structures and analytical tools, and lack of guidance on how to use them, for instance when collecting data. To assess frameworks and their relative influence in grander systems, this suggests there needs to be at least some description to connect a framework and its use to the larger context
38 and other applied frameworks as any issue or subject may require several frameworks to cover all the needed viewpoints. This is likely to help practical adaptation and operationalization of frameworks to use. To evaluate any framework, it is suggested that it should be known at least who developed the framework, what is its aim, what questions does it try to answer and for what field it is intended for. (Partelow, 2023, p. 511-512, 515) From risk management viewpoint the governance and management frameworks may come with some unknown uncertainties which may become evident only in the long run. As time progresses, only the most relevant frameworks remain and become sustained, although mandatory nature of some frameworks creates obvious bias toward them. It seems to fallow, based on Budler and Trkman, that codifying a framework into law often happens when it has been sufficiently endorsed – by general opinion or consensus, or by more formal and democratic process. An example of this is European Union’s Artificial Intelligence Act, which can also be seen as a framework, with similar intent to influence behavior via communicating shared understanding and setting appropriate standard (Schuett 2023, p.5; Koop & Lodge, 2017, p. 104-106). Continuing on Budler and Trkman, they note that a framework is only considered valuable (and therefore, used) if it facilitates reaching organization's goals. (Budler & Trkman, 2019, p. 3-4, 20) 3.4.2 Two types of frameworks to balance and benefit Frameworks are an important tool in a complex socio-technical world. Partelow identifies two types of frameworks: those that aim to simplify complexity and those that aim to capture it. The former may leave significant details out, making clarity and orientation difficult, while the latter may include too many features or too much data for meaningful application. (Partelow, 2023, p. 513; Järvinen, 2018, p. 61-62; Budler & Trkman, 2019, p. 7) This duality points to the need of finding a balance, and likely the need to re-balance or update framework from time to time, depending on the rate of change. This may be difficult and the value of using of a framework may vary as the context may drift over time. Even a flawed framework still has value as it can be used to spark engagement and they can even become symbols, which may unify a community around a common problem and understanding, but they may also become a barrier or anchor, preventing further development (Partelow, 2023, p. 516). Frameworks as management ideas do not simply appear and get widely adopted or accepted by communities or organizations. Those that gain critical mass to become more permanently used rise in popularity via network effect. The more users there are, the more value the framework is seen to have, which
39 in turn attracts more adopters. This may be temporary and mirror a need for a solution for a time-dependent problem, which may change. For organizations and managers, frameworks in general have become a way to signal their progressiveness, even though there is only partial evidence of their effectiveness. (Budler & Trkman, 2019, p. 3-5, 8-9, 12, 16, 19) 2022b Structured inquiry and concepts of research benefit from frameworks, as they convey information via knowledge synthesis and communication (Partelow 2023, p. 511). Frameworks help select approaches and decrease uncertainties when tackling something new, laying out relevant features to consider, and by using a framework to inform users, adoption of new concepts is faster, requiring less cognitive effort, leading to their true value in overcoming barriers in decision making (Budler & Trkman, 2019, p. 3, 15). Part of manager and security expert role is to further security culture. With identity leadership a shared identity and culture may develop, which become the basis of organization’s existence and inherent way of operating. (Reiman 2015, p. 5-6, 9) This is needed for proper in-depth adoption of frameworks but frameworks may also be the tool to convey security information to an organization to enable shared understanding. It should also be noted that an adopted framework may later become a barrier for change as its popularity rises, seemingly increasing its value. An alternative framework and a new way of thinking may be considered less desirable even if old framework is seen flawed, due to it still providing familiar common ground. (Budler & Trkman, 2019, p. 20) Xia et al. (2023, p. 1) note that due to the number of available different AI governance and management frameworks, organizations will have trouble selecting most suitable for their needs. There may be simultaneously too many and too few. Schuett writes that EU AIA related harmonized standards and common specifications on AI risk management are still in development process, which may take several years. In the meantime, some standards exist, like the ISO standards, which may be used by virtue of being available and often being used as models for other standards and frameworks. (Schuett 2023, p. 5, 9) 3.4.3 Levels as disambiguation tool for frameworks In previous chapters levels of societal strategic and organizational coordination were outlined via their differing views on goals and challenges with AIs. To expand this further, in accordance with what was previously defined in section 2.2.4.3 Level structures of meaning making, an additional third level is recognized for a more realistic way for frameworks to represent how various complex social and technical areas interact, and for subsequent detailed analysis. A more practical AI systems level is also needed for frameworks to keep up, as the more technical elements of AI systems – their features and use cases, and how they
40 are perceived – are the current driving force in this field due to AI popularization, as has been discussed. Adding of levels to a systematic description is a decrease in abstraction, an increase in detail, with the aim of depicting a tad more realistically the structure of a concept or a system. Abstraction and generalization differ in that in the former details area left out when abstraction is increased, but in the latter they are still presented, albeit in a more generalized form that seems appropriate for that level of abstraction. Layers or levels (used interchangeably here) of abstraction are a concept that is used here as an amalgamation of epistemological, ontological and methodological varieties (Floridi, 2008, p. 1, 10, 36-37). Elsewhere they are used in computer systems and programming, but it is also applicable in technical AI specific problems as well as in larger managerial and human comprehension challenges (Konidaris, 2019, p. 2-5; Nagineni, 2021, p. 746-749; Te’eni & Sani-Kuperberg, 2005, p. 817-820, 828-829, Shih, 2020, p. 3-4, 9). Levels are not new, as for instance Minzberg created a model of five basic parts of an organization, which includes a variation of three level structure, but separates technostructure and support staff from formal “line” structure of an organization (Mintzberg, 1980, p. 323-324). In systems architecture modeling, level divisions should be based on the purpose that they are created for. For instance, business architecture modeling emphasizes management and governance views and organizational hierarchy levels structure is used, which could be three, four or six levels. One notable difference is however that, architecture models seem to be usually organized by who (or what role) is making the decision, not what level issue is addressed, which may differ from some other level models. (Luukkonen et al., 2012, p. 2829) The level models are vertically hierarchical models, corresponding to general structures of organizations and other formal and informal entities. These models are also compatible with most socio-technical system models, despite some them having varying number of levels due to level of chosen abstraction (Sommerville, 2015, p. 292; Whitworth & Zaic, 2003, p. 261; (Digital and Population Data Services Agency of Finland, 2022, p. 47-51) In practice, the various levels are not clearly delimited, nor do they have straight forward interfaces that convert information and meanings between contexts. Translation or transforming is needed. Mäntymäki & Minkkinen (2023, p. 11) have identified that particularly the organization level management roles have a challenge in translating conflicting governance influences in AI governance, requiring continuous balancing between levels. Luukkonen et al. (2012, p. 28) concur that border between two adjacent levels is often open for interpretation and for instance same roles can be looked at from different simultaneous viewpoints. According to Tappura et al. (2015, p. 13-15), in a three man-
47 risks as an alternative. (Mäntymäki et al., 2022, p.606; Digital and Population Data Services Agency of Finland, 2023b, p. 26-27). Preparing to react on cybersecurity incidents is important but managing those risks in advance is more cost efficient. Proper risk management system is forward looking, and it is quite likely that AI is, or soon will be, utilized in those as well in organizations. The challenge with those systems and tools is that they may be fragmented across different levels of organization structure and technological architecture, which increases complexity and hinders governability. (Vähäkainu & Lehto 2019, p. 86-87) Looked at in another way, AI risk management should be done at various stages of AI system lifecycle, for example as in frameworks of Mäntymäki et al. (2023, p. 10-11) or Yampolskiy (2015, p. 143-148) where stages of preand postdeployment are separated. It is to be noted that these models do not still cover the whole life cycle of an information system, which goes beyond the development and deployment (Kozma, Varga & Larrinaga, 2021, p. 11-15). If the controls for risks cannot be applied effectively in other parts of the lifecycle and process cycle – namely, when the AI system is designed, deployed, when data are gathered and entered, or when data processing happens inside the blackbox – the only viable option seems to be managing risks by controlling output and performance (Viljanen 2023, p. 1218-1219). Järvinen classifies risks in general theoretical terms to internal and external, known and unknown (Järvinen 2018, p.49-51)10. Using these general divisions in a four field matrix, organization’s AI risks can be divided to internal knowns and unknowns as well as external knowns and unknowns. This opens up the AI risk field already significantly but not completely. To also anticipate future uncertainties, which are expected to develop in the coming years, decades and centuries with impacts to individuals as well as societies, risk identification methodologies should also take into account more immediate risks but also indirect and delayed risks (Järvinen 2018, p. 52). Another way to look at risks is to consider them by processing or review levels (as defined earlier), where for instance strategic level risks should be based on the defined strategic level goals or needs of the entity (society, government, organization, team etc.) and so on (Digital and Population Data Services Agency of Finland, 2022, p. 4748; Sääskilahti & Mustonen, 2023, p. 20-24). One more relevant point to make in distinguishing different types of risks is the “death by thousand cuts”, referring here to decentralized small risks from many sources, which manifest in multitude of ways in complex socio-technical networks like the digital operating environment. These kinds of risks could be 10 For example, while managing AI risks like how it is utilized, the system may be accessible for limited internal or public external use, meaning that in the former risks can be managed effectively with “soft” governance rules and procedures for employees while the latter often needs “hard” technical guard rails and limitations to prevent abuse.
48 described by AI having small or medium effect at its level, but via scaling through virtual mobbing, bots or other means it would gain massive significance systemically, like the many forms of online harassment or fraud (Albanese, 2005, p. 10-14; Storry, & Poppleton, 2022, p. 13-16, 27-29; Henares-Montiel et al., 2022, p. 6-9; Interpol, 2023, p. 11). Beyond general risk classifications, just like there are frameworks for AI governance and frameworks to manage AI risks, there are many AI risk taxonomy frameworks for classifying AI related risks. Some stand on their own, some extend previous management frameworks, and some are built-in, like in the AIA. How ever, it should be noted, as Schuett (2023, p. 17) and Paasikivi et al., (2022, p. 16) point out, AIA does not replace risk management or other governance frameworks, it is intended to complement them. Schuett also advocates that even if AI system is below AIA high-risk threshold, it is prudent for organizations to include all potential risk areas, even those that go beyond AIA’s AI system definition in identification and assessment, especially since the additional costs would be relatively small (Schuett 2023, p. 7). Frameworks for AI risk taxonomy approach AI risks from different angles. They have varying comprehensiveness (for instance, more general AI view as opposed to AI system definition) and varying emphasis, due to different levels of view and layers of abstraction. Their different use cases, as well as the general risk classifications, suggest that in practice an organization needs to be able to use several classification taxonomies in their risk analysis for effective management. There are several examples of AI risk taxonomies from global entities, low level organizations, public institutions, private companies and researchers. (Abercrombie et al., 2024; Atkinson & Morrison, 2024; Arda, 2024; European Parliament and Council, 2024, recital 116, articles 6, 51, 80, annex III; IBM, 2024; MITRE, 2024; Sherman & Eisenberg, 2024; Vassilev, Oprea, Fordyce & Anderson, 2024; Critch & Russell, 2023; Newman, 2023; Puscas, 2023; Golpayegani & Pandit, 2022a; Golpayegani et al., 2022b; Weidinger et al., 2022) While developing an overview of the AI risk management efforts and tools, there rises an underlying implication of risks being externalized or transferred to society11, especially if they are non-technical in nature or if there is a larger, messier and complex ethical and societal motivation involved. Organizations do not seem to be able to develop their risk management and limit their view about AI related risks according to experts and research (Renieris et al., 2024; Stahl et al., 2022, p. 34). A practical notion by Hardy & Maguire (2020, p. 685, 688, 709) is that risks, such that AI poses, are novel risks, “characterized by uncertainty and unfamiliarity”, which need to be translated to familiar terms and concepts, but this seems to help with symptoms. The problem is not easy to 11 Making the distinction here that this is not about commodification of security by outsourcing it to cybersecurity companies, although that may be part of the manifestation of it.
49 delve into, nor is it in the scope of this research, but it does lead to the opinion that this kind of tendency is mirrored in how governance, management and risk management are constructed and utilized. It seems elective, how comprehensively AI risks and ethics are thought of, even though there is evidence how the more larger challenging questions are connected to – or even directly causing – the multitude of the explicit security problems and other concerning phenomena. To this point, one analogous explanation suggests that the root cause may be a slow risk that lies in the academics and teachings, as Ghoshal wrote regarding ethics, management and business – something which are entangled with modern AI development (Ghoshal, 2005, p. 75-87; Pfeffer, 2005, p. 99). Research community does warn about lack of comprehensive AI risks, recently by Bengio et al. (2024, p. 2-5). Fortunately, there has already been done work to create models for creating more comprehensive and integrated governance and management, for example Sigfrids et al. (2023, p. 34-49) and Mäntymäki et al. (2023, p. 5-12). Such work still needs to continue as there can be seen areas to develop further, particularly most security aspects and integration to already existing frameworks. 3.6 The challenges of humans in AI governance The meaning and implications of AI are often questioned in relation to us, humans, but conversely it could also be asked, what are humans in relation to AI and what roles do we have. Many, if not most, of these that readily come to mind are in essence roles that humans have in overseeing and guiding AI and AI use. While limiting this examination to roles and tasks associated with governing and managing of AI, it is clear from the previous sections that humans have a large part in AI relationship. For instance, the NIST AI Risk Management Framework Appendix A lists (not counting user) 39 different internal and external roles and 40 tasks as examples of how many different experts and stakeholders may take part in AI creation, implementation and management at different levels (National Institute of Standards and Technology, 2023). Likewise, Mäntymäki et al. (2023, p. 8-9) list as many as 67 tasks needed for development, use, and management of AI systems at various levels during their lifecycle, but notably, their hourglass model has only 13 governance areas, which could be interpreted as roles – although a couple of those may belong to a same person. Paasikivi et al. (2022, p. 22) suggest that in public sector the roles and responsibilities should be defined based on how AI system would be implemented in an organization’s formal decision-making structure, including how external providers and consultant connect to it. As practical as that is, it may not be enough. Since the processes of AI systems can not directly be controlled
50 via code nor by human involvement, legal safeguards need to be constructed elsewhere. A service process that utilizes an AI system does not have to be very large to have several different individuals making various interlinked decisions. A broad range of expertise is needed to create such a complex system, making responsible overall comprehension of the effects and risks a challenges. On the administrative side and good governance, this can be supplemented with setting requirements for work process quality and risk management systems, in order to manage some of the legal risks and harms. (Viljanen, 2023, p. 12141215, 1219, 1229) Conversely, a large organization may not be the only scenario where administrative controls on AI governance may be needed. As many of the frameworks may be applied as checklist, without organization specific application, this may lead an organization to care more about checklist compliance than actual risks or harm mitigation (Reeshad et al. 2022, p. 15). Since in small and mid-sized organizations this may be carried out by a few or even single individuals, it is likely that a checklist is the extent of their capability, resources or allotted time. Indeed, from some public sector reports we see that IT and related security are understaffed in most small and medium organizations, from which we can infer that organizations have very few available specialist resources to share for a new system, such as AI. For instance, 2024 in Finland 66% of public sector organizations (N=178) say that they have 0 to 2 person-years allocated to all digital security related tasks (Rinne, 2024). In general, there are labor and skills shortages in relevant fields (European Employment Services, 2024; Bueermann & Rohrs, 2024, p. 18-19). People who have the role, or at least the responsibilities by default, of securing digital services may have varied titles, backgrounds and positions in an organization. This is not unlike the security and safety professionals working with conventional security and safety areas (Reiman, 2015, p. 4). According to Tappura et al. (2015, p. 2-5), leadership role in security management is not often employed toward operational management and supervisory positions. Leadership is seen as important part of connecting organizational activities and strategy, also in security. Particularly upper management’s role is central as they have decision making power, resources and position to influence organization on all levels. Unfortunately, commitment is an issue. The general essence of security expertise is co-operation and understanding the whole, as the person in that role is likely to be the nexus for related information. Although the expert may have some opportunities to have immediate effects, mostly influencing, developing and managing security is done via line managers or other leaders with requisite power, since security issues are mostly integrated to organizational functions and processes. These can be divided into staff skills, knowledge and capabilities; organizational structures and
51 processes; technology; and organizational culture. Expertise is simultaneously both having a good command of best practices and capability to adapt and create new when balancing and optimizing the aforementioned four. The work is often social due to need for co-operation but the context largely determines how work is conducted. In general, the ability to influence organization’s cybersecurity, data privacy, resilience and contingency planning, risk management or information security, for example, requires basic skills, general knowledge, specific security know-how and understanding of the target area or subject. This general view seems applicable also to roles in AI security and its various subsections as naturally the needed capabilities vary according to specific role, tasks and operating field. This makes defining the work or roles challenging as various security specialty areas, which may be overlapping, are defined by how their risks are formed and articulated. (Reiman 2015, p. 5-6, 9) It should not be forgotten that governance in general is tied to power imbalances between individuals and larger entities, which is part of the larger conversation behind AI ethics. AI and AI security governances have several larger questions that it inherits from previous digitalization venues, as can be interpreted for instance from Salminen. In the context of this research, it has to be noted that this avenue is not explored further, only that, individuals are seen to make the organizations, and indeed it seems that only a handful of them are truly involved with guiding AI – not the whole organization as such. AI governance however should be such that, due to call for wide reading of stakeholders, it should be open and transparent, which ties to ethics and management of risks. It is through AI governance and the fielded AI systems that larger governance issues of public sector, governments, digital environment and cybersecurity are affected. (Salminen, 2022, 81-82, 96-98, 140) Human interaction with AIs is part of larger discourse of human relationship with (AI) technology. There is no one right opinion and they are all in constant change. Gillespie et al. (2023, p. 5, 71) survey shows that most prefer a ”25%-75% or 50%-50%” balance in favor of human control in a system that uses AI, while at the same time still also preferring AI to be involved in decision making. This indicates that although AI is seen threatening, there is hope for its potential benefits. A point regarding the future of AI governance, particularly in the public sector, is that having humans involved in the AI processes in any capacity or balance will change. At the moment, AIs and particularly the GPT based manifestations can more or less be equated with children by their capabilities, selfpreservation and self-limitation or understanding consequences of one’s actions. Likewise, the role of the responsible parent like trainer and overseer is created to meet governance and management requirements. But what will happen, when the AI models advance in their powers but do not grow up – to con-
52 tinue the metaphor, they become teenagers with some superhuman capabilities. The ”responsible parent”, who likely is a public servant without expert level knowledge of AIs, may be ill-equipped to recognize, understand and steer the AI system’s unwanted behavior. The expectation that civil servants across different public organizations and their services would be able to fully act as a plausible balancing entity for advanced AI system seems dubious. In practice this may be able to be supported with adequate governance offering support, as well as other AI tools but research on that has only begun. (Burns et al., 2023, p. 1-2, 16-19)
53 4 ANALYSIS OF THE SELECTED FRAMEWORKS The following sections are used to describe and examine examples of AI governance frameworks. First, the frameworks and their selection criteria are presented. Second, the framework used for analysis and its intended use is described. Third, the selected frameworks are examined. Lastly, an analysis and findings are presented, drawing on the analysis framework and previous theoretical sections. 4.1 Selection of examined frameworks For this research, three targets for inquiry are selected: European Union Artificial Intelligence Act (EU AIA) ISO/IEC 42001:2023 “Information technology — Artificial intelligence — Management system” (ISO 42001) National Institute of Standards and Technology AI Risk Management Framework (NIST RMF) Of these, the first two represent the more currently influential governance frameworks in Europe and are largely followed in public sector. The EU AIA (European Parliament and Council, 2024) and it’s central ideas, like the system risk level classification structure, often presented as a pyramid (European Commission, 2024c), has been noted already in the draft phase and while it is entering into force. Currently, during the writing of this thesis, the AIA was officially published (European Commission, 2024a). Earlier drafts were partly based on the final AIA drafts but eventually all work here is based on the final version of the text.
54 As Schuett describes AIA succinctly: ”The AI Act famously takes a risk-based approach. It prohibits AI systems with unacceptable risks and imposes specific requirements on high-risk AI systems, while leaving AI systems that pose low or minimal risks largely unencumbered. To reduce the risks from high-risk AI systems, providers of such systems must comply with the requirements set out in Chapter 2, but the AI Act assumes that this will not be enough to reduce all risks to an acceptable level: even if providers of high-risk AI systems comply with the requirements, some risks will remain”. He goes on to add, that harmonized standards will play an important role in directing AI systems via compliance requirements. (Schuett 2023, p.4-5) The relevance of the ISO 42001 (International Organization for Standardization, 2023b) is somewhat complicated. The ISO standards are expected to be a large influence for the eventual harmonized EU wide standards mentioned in the AIA. They may act as guidance for many multinational entities. However, the harmonized standards are still a work in progress. The structure of all the participants is somewhat challenging and it would seem there are principled issues for instance in reconciling global and local (EU wide) standards at high level, to such practicalities as the copyrights and availability of these standards. It has been specifically noted that technically inclined standards may not be the best solution to manage governance issues of which many may ultimately be ethical considerations. (Gornet & Maxwell, 2024, p. 6-21) The NIST RMF (National Institute of Standards and Technology, 2023) is also influential in EU due to its adoption via the cybersecurity community, which has many direct communicative ties to to the United States of America’s counterparts and indirect ties through cybersecurity products and services that have been aligned with NIST frameworks when they were initially developed. An example of this is the NSCS-FI evaluation tool (National Cyber Security Centre Finland, 2021). The NIST RMF may thus become partly applied by public sector in some capacity for systems and communications compatibility reasons. Still, despite these connections, for this research, as its origin is removed from the EU regulation and influence, the RMF is used for comparison and contrast. In this sense, it serves in a dual role. Although NIST and ISO standards (for instance for cyber context the ISO 2700x series, which is built on the same principles as ISO 42001), as well as others, differ, they all can be used for AI risk management (European Union Agency for Cybersecurity, 2023, p. 9, 17-20). The selection of these three frameworks is due to their expected influence to AI governance in European public sector organizations. As was stated in a previous section, there are number of varying governance frameworks, but the practical limitations of this thesis limited the number of included frameworks. Due to presented reasoning and backgrounds for the selection of these frameworks, which are unattached to their potential compatibility, specific anomalies or large deviations are not expected, and thus it is acknowledged that compar-
55 isons may not provide the most visibly differing observations. A different combination of frameworks might highlight better some aspects. 4.2 Previous research on these frameworks There has been some previous limited comparative research including these frameworks. In OECD’s comparison, the general compatibility was examined of eight frameworks, emphasizing them as risk management frameworks with distinguishable common repeated background process of “define, assess, treat, govern”. In lieu of AI governance specific ISO 42001, which wasn’t ready at the time, this comparison looked at the general risk management framework ISO 31000:2018 and AI specific ISO 23894:2023. Likewise, in leu of final EU AIA, a draft version of the time was used and the analysis is not fully current. In this research a high-level mapping was made to compare framework interoperability. The findings and notes of the report are likewise high level. The AIA “govern” process was seen to be relatively unclear and missing consultation requirements. The latter statement was confirmed from final AIA text by searching “consult”, which showed no requirements for consultation with internal or external parties, and although recital 92 does remark on this (concerning employer’s requirements to consult workers), article 26 obligations of high risk AI system deployers only requires them to inform (although other work legislation may create consultation needs). From structural point of view, the NIST RMF doesn’t have “govern” process defined separately but its functions are more integrated into other process steps, which may serve practical level needs but raises question how governance functions may be examined and improved efficiently over time. The ISO frameworks merely contrast that although general abstract standard may be usable to some extent, practical applications (like AI and AI systems) need specific standards to bring out actual needs for governance, risk management, cybersecurity and other areas. This previous research did not approach the selected research questions but did validate that further examination of these frameworks is needed and that they are comparable as frameworks despite having different origins and institutional requirements behind them. (Organisation for Economic Co-operation and Development, 2023, p. 16-28; European Parliament and Council, 2024)
56 4.3 Framework for analysis The research questions ask about the roles in the selected frameworks and does closer examination of the frameworks reveal anything about the roles, governance or risk management. The research questions (listed in section 2.4) are: RQ 1: What practical level risk management issues regarding AI governance and human roles can be identified in the selected AI governance and management frameworks? RQ 1.1: Can analysis of roles in frameworks reveal information about how those roles are emphasized and does that reveal information about these frameworks? RQ 1.2: How do the roles in frameworks affect AI risk management and governance? To examine these questions, a framework to help categorize parts of the frameworks is used to code the text (Juhila, 2021). This is based on the concepts introduced in the terminology and theoretical sections of this thesis. It is based on OECD definition of digital security, which has been interpreted as a many securities models and thus is used as the base to consider how various security areas are implemented, as opened in the terminology section. Here, the base breakdown is based on the Finnish public sector guidance model but, as the model implies, that can and should be extended to include any area of security relevant to organization’s activities and systems. The second part of the analysis framework are the organizational levels, used here to allow to consider if and how activity is intended to be carried out, which should lead to identifying roles in the lowest, functional level (”practical level”) by separating higher level requirements. A three level framework is used, where lowest level is equated to individuals with tasks and roles, and for research purposes the middle level is organizational level (”coordination level”) activities while everything higher and external is regarded to belong to the third level (”strategic level”). Using these levels is important part in disambiguation and reducing complexity around the topic. The analysis framework matrix as such may be too superficial and scarce for the research questions to yield detailed analysis. This does not however render it pointless, as it in this case also clarifies the boundaries of inquiry around roles and tasks in organization. It is important to specify which specific area is relevant to guide other analytical questions as well.
63 5 CONCLUSIONS This research has dealt with artificial intelligence governance challenges and risks in public sector, in European context. These issues were looked at through a comprehensive selection of sources. A particular examination was directed at specific low level of governance and persons that have roles in that. This was further examined by reviewing three selected influential AI governance frameworks and analyzing them. The following sections consider these from larger perspectives. 5.1 Conclusions and remarks on the research The research questions asked about AI governance, risk management and human roles. The main question was, ”what practical level risk management issues regarding AI governance and human roles can be identified in the selected AI governance and management frameworks?”. To this, the simplified answer is, based on this research, that the frameworks that guide in this are extensive, requiring quite a lot from any organization but particularly from small organizations with small IT and security teams – as is often in the public sector. The secondary questions supported this view. The results should be considered only indicative, however, as the scope of the study is limited. In digital security in general as well as in cybersecurity, more attention should be given to frameworks. They are are powerful tool but need to be selected and calibrated right. If the base governing framework of an organization and its IT is not sufficient, implementing security is akin as pointless as carrying water to a well. When AI comes to an organization – if it hasn’t already – an organization needs to make sure relevant changes are planned and managed extensively, beyond technical aspect.
64 Why is governance, and management of AI risks with it so important? Because AI is flawed and unfinished as a technology and as products. It has a lot of risks that are not expected to be sorted out reliably. In effect, these risks are pushed to the user side, transferred. Not only the expected practical level cyber crime risks but also risks that have the potential to significantly affect societies and human existence. As AI has been popularized and a marketable “need” has been created, AI has been taken out of research labs where it was acceptable to test half-baked variations. Now those are out and about, which may not amount to much more than inconveniences and financial losses to organizations but simultaneously they create AI culture and discourse. The capabilities of AI systems are still fairly limited and their alignment failures to do only acceptable things has not been solved. Good governance frameworks and people in those roles to apply them are the makeshift solution to counter our own irresponsibility. In the short term and practical level, these same frameworks and good governance benefit also AI cybersecurity and other digital security areas. As was discussed earlier, there are a lot of strategic level hopes placed on AIs and their transformative influences to make the world more efficient and better place. This may not happen if small organizations are either hampered in being able to utilize AI systems. Small organizations may be facing challenges in adopting AI as they may not have adequate resources for AI development, management and governance12. This may be doubly unfortunate as small and medium organizations especially in the public sector with their shortages could ideally benefit from AI. The requirements set in regulation and standards may be too high, or drive organizations into cutting corners in governance efforts. As long as policies, strategies, regulations, frameworks and plans do not recognize the different sizes and resources involved at practical level, the driving forces and reached goals pile to the corner of the few and large – the many small organizations will not be able to benefit fully. Serious shared responsible AI has a threshold of at least a few humans. EU AIA risk categories may steer AI system development toward aiming to go below risk category threshold. The positive side would be that some risky features get omitted, potentially requiring also less cybersecurity measures. But the negative side may be that appropriate risk control measures may not be applied if they are deliberately chosen according to the lowest example of the category. Simplifying the AI system could become necessary if organization identifies that it doesn’t have the capacity and resources to govern and manage its AI 12 This is also true on national level, as is evidenced by publication of AI Playbook for Small States by The Forum of Small States (FOSS) and Digital FOSS, just before this thesis was returned for review. It outlines issues and considerations for policymakers in the development, use and governance of AI, from the perspective of small states, which are an informal grouping of 108 small countries. (Forum of Small States, 2024)
65 service properly. This option may be a blessing, but it also means some advanced aspects may be beyond some smaller organization’s reach. ISO42001 governance standard is a glimpse to what kind the future harmonized standards could be. There is some room to apply and scale standards relative to organization’s activities but the basic requirements may already be prohibitive to smaller entities. At the same time, the ISO42001, and to some extent NIST RMF, show just how extensive the governance structure needs to be, for it to be believable. At the same time all the frameworks remind us that they are expected to evolve and expand. It is also noted in previous research how similar these frameworks are. Noticeably, all three mention ethical and trustworthy AI but those areas were not included in the base governance models. Much like security through out digital technological history, they can be described as separate later additions, which is not a preferable modern structure. In this research I have also aimed to create sufficient argument that governance and management in general, as well in particular fields, such as cybersecurity, should be viewed using a layered model. Minimum of three, which can be applied to many other frameworks, creating more coherent and complexity reducing complete constructs – although socio-technical aspects and specificity may require more layers in frameworks. A larger question of AI discourse is not about how efficient AI is, how beneficial it may be, or, how secure and trustworthy, but, what will become “accepted AI” in our culture. How efficient, beneficial, secure and trustworthy does an AI system need to be, to be accepted? That bar often is revealed to be much lower than intended, if adoption of any previous systems are to be taken as example. This is a matter of public discourse, to which public organization experts of AI systems can only participate if they have time and authorization. To sum this up, in regard to AIs, frameworks and other systems, as stated in computer scientist and AI expert John F. Sowa’s Law of Standards: “Whenever a major organization develops a new system as an official standard for X, the primary result is the widespread adoption of some simpler system as a de facto standard for X” (Sowa, 2004). 5.2 Evaluation and notes on work This research has notable limits. First and foremost, it is limited to a master’s level thesis in depth, length as well as in available allotted time. This is apparent in the limited context and extent to which the frameworks have been analyzed. This limitation was intended to be turned as a strength, by concentrating on specific issues within the area and questions.
66 Ultimately during the course of the research, it became evident that original assumptions needed to be slightly altered to both focus the inquiry but also keep it within the assigned limits. This lead to research questions being slightly revised during the writing process. The main research question was expanded while the sub-questions were simplified. These changes were ultimately more in line with the overall research and fit better with the subject matter. This research achieved its intention and has answered to the research questions it set out to clarify. Its results should support further both academic endeavors as well as help the topic experts develop their areas of interest with artificial intelligence governance and management, risk management and all digital security areas. Due to its limitations this work does not answer all possible questions in these areas. The comprehensive approach of the research and the complex area, which combines several academic fields, was intended to create an encompassing view. At the same time the weakness of this is limited depth. However, an adequate balance was found. Another weakness of this research is the limited examination of the selected frameworks, due to previously mentioned reasons, which affects the standing of the analysis. Although the results are not likely to be erroneous, more nuanced and in-depth findings could have been possible with more rigorous and extensive methods. This could have included having additional frameworks for comparison. It is the view of the writer that source materials were used to convey relevant and appropriate view of the subject matter. The sources were used in appropriate academic manner, they are of good quality and where there are sources beyond rigorous peer review process, multiple supporting sources have been provided as possible. It is also noted that as the subject matter is evolving rapidly, and indeed one of the examined frameworks was only recently published officially during the writing process, availability of up-to-date peer reviewed sources was limited in parts. In many cases a pre-print version of a source was used, and also cited in order to support open access science. Additionally it is to be noted, as it was referenced as one of the sources, that the writer was part of the expert group whose partial task was to define and adapt to guidance some of the concepts used in this thesis (notably VAHTI risk terminology), but all materials used are available publicly and all materials from those tasks were put through internal and external public review processes, and approved by various higher instances. This research was conducted in accordance with university of Jyväskylä guidelines for responsible science and research ethics and followed the current instructions and guidelines of using AI-based applications in studies13. Al13 Approved AI guidelines by the Education Council of the University of Jyväskylä on 5th May 2023, published at https://www.jyu.fi/en/for-students/instructions-for-bachelors-and-mas-
67 though AI is the topic of this research, it became evident during this work that the available AI systems were not able to assist meaningfully with research. AI assistant was used for minor stylistic tasks. 5.3 Potential further research This research has pointed toward some mostly unexplored avenues for further research and study. Some are more tangential and some more direct continuation. These are in addition to the possibility of re-examining and expanding the inquiry in this thesis. The most important further examination is on governance frameworks and their implementation minimums. The minimums in having a sufficient and acceptable AI governance may potentially guide AI adoption and tell what is needed for a comprehensive, ethics including, organizational process. Hopefully such research would help to further develop frameworks that scale better, taking into account both the AI system risks as well as the organizations. How many different persons are needed and how many person-years does AI governance require? As the results indicate that there are limitations to small organizations and particularly in public service organizations, it should be further investigated how much resources they have available for AI adoption and governance. It should be noted that AI transformation throughout an organization will require resources beyond IT and security functions and some of the new AI related tasks will be mere extensions of current tasks. This topic is possibly further challenged with taking into account what efficiency increases there may be at various levels. There is also some potential research in human AI interaction in the governance and management area. This is not an angle that has been researched much, although there were mentions of using AI to supervise AI. It is quite likely that some work will be eventually done to evaluate suitability of using AIs to govern and mange some parts of AIs. How many equivalent personyears of human resources could AI add to a small IT team? In various previous research the requirements of security have been largely ignored or minimized in AI governance. In modern and future systems and services – particularly in the public sector that is more strictly legally bound – this is part of needed compliance, but also needed actual comprehenters-students/regulations-and-directives-guiding-studies/using-ai-based-applications-in-studies-jyus-instructions-and-guidelines. University of Jyväskylä research guidelines listed at https://www.jyu.fi/en/research/responsible-science/guidelines-for-responsible-science-andresearch-ethics-and-contact-details-for-advice
68 sive security, safety and privacy for individuals, organizations and society. Governance and management models that lack these aspects need to be rethought, and research should be conducted to optimize and update such models as mere “dropping in” a new facet like security to a framework is likely to be unhelpful. Further research should also be conducted regarding interoperability of various frameworks. There are several of them with different points of interest and strengths. Organizational structure and activities require several different frameworks for effective co-operation, so that organization does not become managementally disconnected and lose shared understanding. One important facet of this would be to delve into the effective use and interplay of different levels. In security research this would most likely manifest via addressing differences of risks, how they manifest and how they are handled, and how risks and their control efforts of different levels, from different contexts, can and should be communicated between all other levels. Artificial intelligence provides an actively developing area for all of this research, benefiting global future.
69 SOURCES Abbas, R., & Michael, K. (2023). Socio-Technical Theory: A review. In S. Papagiannidis (Ed.), TheoryHub Book. Retrieved May 20th, 2024, from https://open.ncl.ac.uk/ ISBN: 9781739604400 Abercrombie, G., Benbouzid, D., Giudici, P., Golpayegani, D., Hernandez, J., Noro, P., Pandit, H., Paraschou, E., Pownall, C., Prajapati, J., Sayre, M. A., Sengupta, U., Suriyawongkul, A., Thelot, R., Vei, S., & Waltersdorfer, L. (2024). A collaborative, human-centred taxonomy of AI, algorithmic, and automation harms. Retrieved August 18th, 2024, from https://arxiv.org/abs/2407.01294 Acemoglu, D. (2024). The Simple Macroeconomics of AI. Review version, 79th Economic Policy Panel Meeting, 4-5 April 2024. Retrieved August 5th, 2024, from https://www.economic-policy.org/wp-content/uploads/2024/04/EcPol2024-016_Proof_hi_Acemoglu.pdf Aitonurmi, J., Reivo, J., & Jokela, E. (2021). Ennakoiva digitaalisen ympäristön riskienhallinta. Futura, 4. Albanese, J. (2005). Fraud: The characteristic crime of the twenty-first century. Trends in Organized Crime, 8(4), 6-14. Retrieved August 18th, 2024, from https://doi.org/10.1007/s12117-005-1011-2 Alegre, S. (2024). Regulators are finally catching up with big tech. WIRED. Retrieved July 19th, 2024, from https://www.wired.com/story/regulators-are-finally-catching-up-withbig-tech/ Amankwah-Amoah, J., Khan, Z., Wood, G., & Knight, G. (2021). COVID-19 and digitalization: The great acceleration. Journal of Business Research, 136, 602611. Retrieved May 18th, 2024, from https://doi.org/10.1016/j.jbusres.2021.08.011 Arda, S. (2024). Taxonomy to Regulation: A (Geo)Political Taxonomy for AI Risks and Regulatory Measures in the EU AI Act. Retrieved August 18th, 2024, from https://arxiv.org/pdf/2404.11476 Atkinson, D., & Morrison, J. (2024). A legal risk taxonomy for generative artificial intelligence. Retrieved August 18th, 2024, from https://doi.org/10.48550/arXiv.2404.0947 Autioniemi, J. (2020). Tekoälyn yhteiskehittäminen julkisella sektorilla. Hallinnon Tutkimus, 39(1), 5–20. Retrieved June 21st, 2024
70 https://journal.fi/hallinnontutkimus/article/download/98075/56023/16 7067 Barabási, A.-L. (2002). The new science of networks. Cambridge, MA, USA: Perseus Publishing. Barabási, A.-L. (2014). Linked. USA: Perseus Publishing. Barthes, R. (2002). The death of the author. In D. Finkelstein & A. McCleery (Eds.), The book history reader. London, England: Routledge. Bathaee, Y. (2018). The artificial intelligence black box and the failure of intent and causation. Harvard Journal of Law & Technology, 31(2). Retrieved May 9th, 2024, from https://jolt.law.harvard.edu/assets/articlePDFs/v31/The-ArtificialIntelligence-Black-Box-and-the-Failure-of-Intent-and-Causation-YavarBathaee.pdf Bengio, Y., Hinton, G., Yao, A., Song, D., Abbeel, P., Darrell, T., Harari, Y. N., Zhang, Y. Q., Xue, L., Shalev-Shwartz, S., Hadfield, G., Clune, J., Maharaj, T., Hutter, F., Baydin, A. G., McIlraith, S., Gao, Q., Acharya, A., Krueger, D., Dragan, A., Torr, P., Russell, S., Kahneman, D., Brauner, J., & Mindermann, S. (2024). Managing extreme AI risks amid rapid progress. Science, 384(6698), 842-845. Retrieved August 19th, 2024, from https://arxiv.org/pdf/2310.17688 Bentley, P. J. (2018). The three laws of artificial intelligence: Dispelling common myths. In Scientific Foresight Unit (STOA), Should we fear artificial intelligence? In-depth analysis. Parliamentary Research Services, European Parliament. Retrieved July 28th, 2024, from https://www.europarl.europa.eu/RegData/etudes/IDAN/2018/614547 /EPRS_IDA(2018)614547_EN.pdf Brollo, F., Dabla-Norris, E., de Mooij, R., Garcia-Macia, D., Hanappi, T., Liu, L., & Nguyen, A. D. M. (2024). Broadening the Gains from Generative AI: The Role of Fiscal Policies (SDN/2024/002). International Monetary Fund. Retrieved July 19th, 2024, from https://www.imf.org/en/Publications/Staff-Discussion-Notes/Issues/ 2024/06/11/Broadening-the-Gains-from-Generative-AI-The-Role-ofFiscal-Policies-549639 Budler, M., & Trkman, P. (2019). The nature of management frameworks. Journal of Management & Organization, Volume 29, Issue 2, March 2023 , 173 - 190. Retrieved May 11th, 2024, from https://doi.org/10.1017/jmo.2019.83 Bullock, S., & Cliff, D. (2004). Complexity and emergent behavior in ICT systems. Retrieved May 20th, 2024, from https://www.researchgate.net/publication/235409934_Complexity_and_ Emergent_behavior_in_ICT_systems
71 Burns, C., Izmailov, P., Kirchner, J. H., Baker, B., Gao, L., Aschenbrenner, L., Chen, Y., Ecoffet, A., Joglekar, M., Leike, J., Sutskever, I., & Wu, J. (2023). Weak-to-strong generalization: Eliciting strong capabilities with weak supervision. Retrieved May 19th, 2024, from https://cdn.openai.com/papers/weak-to-strong-generalization.pdf Bueermann, G., & Rohrs, M. (2024). Global Cybersecurity Outlook 2024 (Insight Report). World Economic Forum. Retrieved July 24th, 2024, from https://www.weforum.org/publications/global-cybersecurity-outlook2024/ Burns, C., Izmailov, P., Kirchner, J. H., Baker, B., Gao, L., Aschenbrenner, L., Chen, Y., Ecoffet, A., Joglekar, M., Leike, J., Sutskever, I., & Wu, J. (2024). Weak-to-strong generalization: Eliciting strong capabilities with weak supervision. OpenAI. Retrieved July 15th, 2024, from https://cdn.openai.com/papers/weak-to-strong-generalization.pdf Calvino, F., et al. (2023). What technologies are at the core of AI?: An exploration based on patent data. OECD Artificial Intelligence Papers (No. 6). Retrieved March 26th, 2024, from https://www.oecd-ilibrary.org/science-and-technology/whattechnologies-are-at-the-core-of-ai_32406765-en Çam, E., Hungerford, Z., Schoch, N., Miranda, F. P., & Yáñez de León, C. D. (2024). Electricity 2024 - Analysis and forecast to 2026. International Energy Agency. Retrieved July 19th, 2024, from https://iea.blob.core.windows.net/assets/18f3ed24-4b26-4c83-a3d28a1be51c8cc8/Electricity2024-Analysisandforecastto2026.pdf Cambridge University Press. (n.d.). Governance. In Cambridge Dictionary. Retrieved June 11th, 2024, from https://dictionary.cambridge.org/dictionary/english/governance Cambridge University Press. (n.d.). Management. In Cambridge Dictionary. Retrieved June 11th, 2024, from https://dictionary.cambridge.org/dictionary/english/management CEN-CENELEC. (2021, April 21). European Standards support EU ambitions on Artificial Intelligence. Retrieved June 11th, 2024, from https://www.cencenelec.eu/news-and-events/news/2021/briefnews/20 21-04-21-european-standards-support-eu-ambitions-on-artificialintelligence/ Ciborra, C. (2007). Digital technologies and risk: a critical review. In O. Hanseth & C. Ciborra (Eds.), Risk Complexity and ICT. Cheltenham, England: Edward Elgar Publishing. Cleaveland, A., Cohn, A., Nagamine, M., Thomas, D., Rimsky Vernon, A., Bouckaert, J., & Joshi, A. (2023). Cybersecurity Futures 2030: New
72 Foundations. World Economic Forum. Retrieved July 24th, 2024, from https://www.weforum.org/publications/cybersecurity-futures-2030new-foundations/ Cohen, A. (2024). AI Is Pushing The World Toward An Energy Crisis. Forbes. Retrieved July 17th, 2024, from https://www.forbes.com/sites/arielcohen/2024/05/23/ai-is-pushingthe-world-towards-an-energy-crisis/ Colman, A. W., & Han, J. (2005). Organizational roles and players. Applied Ontology. Retrieved June 11th, 2024, from https://www.researchgate.net/publication/228625251_Organizational_ro les_and_players Committee of Sponsoring Organizations of the Treadway Commission. (2020). Enterprise risk management: Integrating with strategy and performance. Retrieved August 18th, 2024, from https://www.coso.org/_files/ugd/3059fc_5f9c50e005034badb07f94e9712 d9a56.pdf Cotton, P., Patel, M., & Wei, W. (2022). The Foundational Standards for AI. ISO/IEC Workshop 2425. Retrieved May 13th, 2024, from https://jtc1info.org/wp-content/uploads/2022/06/03_08_Paul_Milan_W ei_The-foundational-standards-for-AI-20220525-ww-mp.pdf Critch, A., & Russell, S. (2023). TASRA: A taxonomy and analysis of societal-scale risks from AI. Retrieved August 18th, 2024, from https://arxiv.org/abs/2306.06924v2 Dalal, R. S., Howard, D. J., Bennett, R. J., Posey, C., Zaccaro, S. J., & Brummel, B. J. (2022). Organizational science and cybersecurity: abundant opportunities for research at the interface. Journal of Business and Psychology, 37, 1–29. Retrieved April 11th, 2024, from https://doi.org/10.1007/s10869-021-09732-9 Data Center Map. (2024). Retrieved July 22nd, 2024, from https://www.datacentermap.com/datacenters/ Delipetrev, B., Tsinaraki, C., & Kosti , U. (2020). ćHistorical evolution of artificial intelligence: Analysis of the three main paradigm shifts in AI (EUR 30221EN, JRC Technical Reports). Retrieved April 24th, 2024, from https://doi.org/10.2760/801580 Dell’Acqua, F., McFowland III, E., Mollick, E. R., Lifshitz-Assaf, H., Kellogg, K., Rajendran, S., Krayer, L., Candelon, F., & Lakhani, K. R. (2023). Navigating the Jagged Technological Frontier: Field Experimental Evidence of the Effects of AI on Knowledge Worker Productivity and Quality. Harvard Business School Technology & Operations Mgt. Unit Working Paper No. 24-013, The Wharton School Research Paper. Retrieved July 23rd,
79 Kozma, D., Varga, P., & Larrinaga, F. (2021). System of systems lifecycle management—A new concept based on process engineering methodologies. Applied Sciences, 11(8), 3386. Retrieved August 19th, 2024, from https://doi.org/10.3390/app11083386 Krauskopf, L. (2024). Echoes of dotcom bubble haunt AI-driven US stock market. Reuters. Retrieved July 17th, 2024, from https://www.reuters.com/markets/echoes-dotcom-bubble-haunt-aidriven-us-stock-market-2024-07-02/ Lash, S. (1995). Refleksiivisyys ja sen vastinpari: rakenne, estetiikka yhteisö. In U. Beck, A. Giddens, & S. Lash (Eds.), Nykyajan jäljillä – refleksiivinen modernisaatio. Jyväskylä, Finland: Gummerus Kirjapaino Oy. Latvanen, M. (2023). Pohdintaa tekoälystä ja kestävyydestä - Erikoiskirjastojen ja tietopalveluiden verkoston vuosiseminaari. Helsinki, Finland. Retrieved August 7th, 2024, from https://www.kirjastot.fi/ammattikalenteri/koulutus-ja-seminaarit/pohdi ntaa-tekoalysta-ja-kestavyydesta-erikoiskirjastojen Li, P., Yang, J., Islam, M. A., & Ren, S. (2023). Making AI Less “Thirsty”: Uncovering and Addressing the Secret Water Footprint of AI Models. Retrieved July 17th, 2024, from https://arxiv.org/abs/2304.03271 Limnéll, J. (2014). Tämän päivän ja huomisen kyberturvallisuus [Public lecture]. In Mitä on kyberturvallisuus ja miksi se koskettaa meitä jokaista?. Retrieved August 17th, 2024, from https://youtu.be/qr6ZuuR_rPU? list=PLI_CRjXr4Y2HckgEATEC-NtcKnCuk3Sdi&t=3397 Limnéll, J. (2016). Luottamus digitaalisessa turvallisuudessa [Public lecture]. Retrieved August 17th, 2024, from https://youtu.be/BnajsP-C34Q?t=1455 Lin, P., & Bunger, R. (2024). Recommended Inventory for Data Center Scope 3 GHG Emissions Reporting (White Paper 53 Version 2). Schneider Electric – Energy Management Research Center. Retrieved July 18th, 2024, from https://www.se.com/ww/en/download/document/SPD_WP53_EN Luhmann, N. (1996a). Social Systems. Stanford, CA, USA: Stanford University Press. Luhmann, N. (1996b). Modern society shocked by its risks. In Social Sciences Research Centre occasional paper. Retrieved May 18th, 2024, from http://hub.hku.hk/bitstream/10722/42552/1/17.pdf Lui, K., & Karmiol, J. (2018). AI Infrastructure Reference Architecture (IBM Systems 87016787USEN-00). IBM. Retrieved August 14th, 2024, from https://www.ibm.com/downloads/cas/W1JQBNJV.
80 Lu, Q., Zhu, L., Xu, X., Whittle, J., Zowghi, D., & Jacquet, A. (2023). Responsible AI pattern catalogue: A multivocal literature review. ACM Computing Surveys, 56(7). Retrieved April 26th, 2024, from https://arxiv.org/abs/2209.04963v4 (preprint version, v4) Luukkonen, I., Mykkänen, J., Itälä, T., Savolainen, S., & Tamminen, M. (2012). Toiminnan ja prosessien mallintaminen: Tasot, näkökulmat ja esimerkit. Itä-Suomen yliopisto ja Aalto-yliopisto. Retrieved April 24th, 2024, from https://www.researchgate.net/publication/257528716 Malan, D. (2018). The law can’t keep up with new tech. Here’s how to close the gap. World Economic Forum. Retrieved July 18th, 2024, from https://www.weforum.org/agenda/2018/06/law-too-slow-for-newtech-how-keep-up/ Malik, Y. (2024). AI startup funding more than doubles in Q2, Crunchbase data shows. Reuters. Retrieved August 2nd, 2024, from https://www.reuters.com/technology/artificial-intelligence/ai-startupfunding-more-than-doubles-q2-crunchbase-data-shows-2024-07-09/ Marchal, S., & Nawrotek, B. (2024). Tekoälypohjaiset kyberturvallisuusratkaisut. Traficomin tutkimuksia ja selvityksiä (No. 07/2024). National Cyber Security Centre Finland (NSCS-FI). Retrieved July 24th, 2024, from https://www.kyberturvallisuuskeskus.fi/fi/ajankohtaista/tekoaly-yhakeskeisempi-tekija-tulevaisuuden-tietoturvaratkaisuissa Mattioli, R., & Malatras, A. (2024). Foresight Cybersecurity Threats For 2030 - Update 2024: Extended report. European Union Agency for Cybersecurity (ENISA). Retrieved July 22nd, 2024, from https://www.enisa.europa.eu/publications/foresight-cybersecuritythreats-for-2030-update-2024-extended-report Menaria, N. (2024). Comparative Analysis of VUCA and BANI Frameworks. IJFMR, 6(2). Retrieved June 3rd, 2024, from https://doi.org/10.36948/ijfmr.2024.v06i02.15715 Merriam-Webster. (n.d.). Framework. In Merriam-Webster.com dictionary. Retrieved August 6th, 2024, from https://www.merriam-webster.com/dictionary/framework Merriam-Webster. (n.d.). Management. In Merriam-Webster.com dictionary. Retrieved June 11th, 2024, from https://www.merriam-webster.com/dictionary/management Merriam-Webster. (n.d.). Governance. In Merriam-Webster.com dictionary. Retrieved June 11th, 2024, from https://www.merriam-webster.com/dictionary/governance
81 Microsoft. (2023). Work Trend Index Special Report - What Can Copilot’s Earliest Users Teach Us About Generative AI at Work? Retrieved July 23rd, 2024, from https://www.microsoft.com/en-us/worklab/worktrend-index/copilots-earliest-users-teach-us-about-generative-ai-at-work Ministry of finance of Finland. (2016). Digitaaliseen turvallisuuteen kohdistuvien riskien hallinta. Retrieved April 10th, 2024, from http://urn.fi/URN:ISBN:978-952-251-790-6 Ministry of finance of Finland. (2022a). Uudistuva ja kestävä Suomi: Valtiovarainministeriön virkamiespuheenvuoro 2022. Retrieved April 10th, 2024, from https://julkaisut.valtioneuvosto.fi/bitstream/handle/10024/164480/ VM_2022_77.pdf Ministry of finance of Finland. (2022b). Ekologinen kestävyys, kestävä talouskasvu ja markkinoiden rooli. Valtiovarainministeriön virkamiespuheenvuoron taustamuistio 38. Retrieved April 10th, 2024, from https://vm.fi/documents/10623/142666320/38_Ekologinen+kest %C3%A4vyys,+kest%C3%A4v %C3%A4+talouskasvu+ja+markkinoiden+rooli.pdf/a0da0327-d6d7-0ea78157-b4c91e3af076/38_Ekologinen+kest%C3%A4vyys,+kest%C3%A4v %C3%A4+talouskasvu+ja+markkinoiden+rooli.pdf Minkkinen, M., & Mäntymäki, M. (2023). Institutional logics underpinning AI governance. Fourteenth Scandinavian Conference on Information Systems (SCIS2023). Retrieved April 27th, 2024, from https://www.researchgate.net/publication/373167303_The_institutional_ logics_underpinning_organizational_AI_governance_practices Mintzberg, H. (1980). Structure in 5’s: A synthesis of the research on organization design. Management Science, 26(3), 322-341. Retrieved August 5th, 2024, from https://ics.uci.edu/~corps/phaseii/MintzbergStructureIn5s-MgmtSci.pdf MITRE. (2024). MITRE ATLAS: Adversarial Threat Landscape for ArtificialIntelligence Systems. Retrieved August 18th, 2024, from https://atlas.mitre.org/ Moses, L. B. (2007). Recurring dilemmas: The law’s race to keep up with technological change. UNSW Law Research Paper No. 2007-21. Retrieved July 19th, 2024, from http://dx.doi.org/10.2139/ssrn.979861 Mäntymäki, M., Minkkinen, M., Birkstedt, T., & Viljanen, M. (2022). Defining organizational AI governance. AI and Ethics, 2, 603–609. Retrieved April 27th, 2024, from https://doi.org/10.1007/s43681-022-00143-x Mäntymäki, M., Minkkinen, M., Birkstedt, T., & Viljanen, M. (2023). Putting AI ethics into practice: The hourglass model of organizational AI governance.
82 arXiv. Retrieved April 27th, 2024, from https://doi.org/10.48550/arXiv.2206.00335 Nader, K., Toprac, P., Scott, S., & Baker, S. (2022). Public understanding of artificial intelligence through entertainment media. AI & society Volume 39 (2024), 713–726. Advance online publication. Retrieved August 14th, 2024, from https://doi.org/10.1007/s00146-022-01427-w National Cyber Security Centre. (n.d.). A basic risk assessment and management method. Retrieved August 19th, 2024, from https://www.ncsc.gov.uk/collection/risk-management/a-basic-riskassessment-and-management-method National Cyber Security Centre Finland. (2021). Kybermittari - Cybermeter. National Cyber Security Centre Finland (NSCS-FI). Retrieved August 23rd, 2024, from https://www.kyberturvallisuuskeskus.fi/en/ourservices/situation-awareness-and-network-management/kybermittaricybermeter National Institute of Standards and Technology. (2023). AI Risk Management Framework. Retrieved August 21st, 2024, from https://www.nist.gov/itl/ai-risk-management-framework National Institute of Standards and Technology. (2023). Appendix A: Descriptions of AI Actor Tasks. In AI Risk Management Framework (AI RMF) 1.0. Retrieved August 21st, 2024, from https://airc.nist.gov/AI_RMF_Knowledge_Base/AI_RMF/Appendices/ Appendix_A Nebel, A., Kling, A., Willamowski, R., & Schell, T. (2024). Recalibration of limits to growth: An update of the World3 model. Journal of Industrial Ecology, 28, 87-99. Retrieved May 6th, 2024, from https://doi.org/10.1111/jiec.13442 Newman, J. (2023). A taxonomy of trustworthiness for artificial intelligence: Connecting properties of trustworthiness with risk management and the AI lifecycle. UC Berkeley Center for Long-Term cybersecurity. Retrieved May 11th, 2024, from https://cltc.berkeley.edu/wp-content/uploads/2023/01/Taxonomy_of_ AI_Trustworthiness.pdf NVIDIA. (2024). AI Enterprise reference architecture (Version 0.1.0). Retrieved August 14th, 2024, from https://docs.nvidia.com/ai-enterprise/referencearchitecture/0.1.0/index.html Organisation for Economic Co-operation and Development. (2015). Digital Security Risk Management for Economic and Social Prosperity: OECD Recommendation and Companion Document (Ministry of Finance, Finland, Trans.), OECD Publishing, Paris. https://doi.org/10.1787/9789264245471en. Retrieved May 20th, 2024, from
83 https://julkaisut.valtioneuvosto.fi/bitstream/handle/10024/75412/OEC D_julkaisu_NETTI.pdf Organisation for Economic Co-operation and Development. (2021). Database of national AI policies. EC / OECD.AI. Retrieved August 14th, 2024, from https://oecd.ai/en/dashboards/overview/policy Organisation for Economic Co-operation and Development. (2023). Common guideposts to promote interoperability in AI risk management. OECD Artificial Intelligence Papers (No. 5). Retrieved August 23rd, 2024, from https://doi.org/10.1787/ba602d18-en Organisation for Economic Co-operation and Development. (2024). Explanatory memorandum on the updated OECD definition of an AI system. OECD Artificial Intelligence Papers (No. 8). Retrieved July 11th, 2024, from https://www.oecd.org/en/publications/explanatory-memorandum-onthe-updated-oecd-definition-of-an-ai-system_623da898-en.html Paasikivi, O., Tuohino, J., Mansnérus, J., & Lång, J. (2022). Tekoälyn käyttömahdollisuudet julkisella sektorilla - Oikeudelliset reunaehdot ja kansainvälinen vertailu. Sitran selvityksiä 206. Retrieved May 19th, 2024, from https://www.sitra.fi/app/uploads/2022/03/tekoalynkayttomahdollisuudet-julkisella-sektorilla-sitran-selvityksia-206.pdf Partelow, S. (2023). What is a framework? Understanding their purpose, value, development and use. Journal of Environmental Studies and Sciences, 13, 510– 519. Retrieved May 14th, 2024, from https://doi.org/10.1007/s13412-02300833-w Peltoniemi, M., Isoaho, S., Hämäläinen, T., Nurmi, P., & Nummela, E. (2004). Katsaus systeemiteorioihin - järjestelmäajattelu. Retrieved March 2nd, 2024, from https://www.utu.fi/en/units/ffrc/research/project-archive/environmen t/Documents/etu_7.pdf Perri, L. (2023). What’s New in Artificial Intelligence from the 2023 Gartner Hype Cycle. Retrieved March 6th, 2024, from https://www.gartner.com/en/articles/what-s-new-in-artificialintelligence-from-the-2023-gartner-hype-cycle Pfeffer, J. (2005). Why do bad management theories persist? A comment on Ghoshal. Academy of Management Learning & Education, 4(1). Retrieved August 20th, 2024, from https://doi.org/10.5465/AMLE.2005.16132570 Power, M. (2007). Organized Uncertainty: Designing a World of Risk Management. Norfolk, England: Oxford University Press. Retrieved February 5th, 2024, from http://ebookcentral.proquest.com/lib/jyvaskyla-ebooks/detail.action? docID=415614
84 Puscas, I. (2023). AI risks taxonomy: Paving the path for confidence-building measures. United Nations Institute for Disarmament Research. Retrieved August 18th, 2024, from https://unidir.org/wp-content/uploads/2023/10/UNIDIR_Research_Bri ef_AI_International_Security_Understanding_Risks_Paving_the_Path_for _Confidence_Building_Measures.pdf Reiman, T. (2014). Turvallisuusasiantuntijoiden roolit, toimintatavat ja tarvittavat kyvyt ja taidot. VTT. Retrieved April 5th, 2024, from https://cris.vtt.fi/en/publications/turvallisuusasiantuntijoiden-roolittoimintatavat-ja-tarvittavatReivo, J. (2023). Julkisen hallinnon digitaalisen turvallisuuden strateginen riskienhallinta – Yleinen riskitilannekatsaus, kevät 2023. Digital and Population Data Services Agency of Finland. Retrieved July 24th, 2024, from https://dvv.fi/documents/16079645/110183105/Julkisen+hallinnon+digi turvan+strateginen+riskienhallinta,+raportti+kev%C3%A4t+2023.pdf/ 03139437-5ec3-f556-9f71-865f6e4bd0f2/ Julkisen+hallinnon+digiturvan+strateginen+riskienhallinta,+raportti+kev %C3%A4t+2023.pdf?t=1686111905768 Renieris, E. M., Kiron, D., & Mills, S. (2024, April 23). AI-related risks test the limits of organizational risk management. MIT Sloan Management Review. Retrieved August 21st, 2024, from https://sloanreview.mit.edu/article/ai-related-risks-test-the-limits-oforganizational-risk-management/ Rinne, T. (2024). Julkisen hallinnon digitaalisen turvallisuuden hallinnollinen tilanne [Video]. In VAHTI-kesäseminaari 13.6.2024. Retrieved September 5th, 2024, from https://youtu.be/bgFYFokkLBM?t=7267 Rossi, L., Wens, M., De Moel, H., Cotti, D., Sabino Siemons, A.-S., Toreti, A., Maetens, W., Masante, D., Van Loon, A., Hagenlocher, M., Rudari, R., Meroni, M., Isabellon, M., Avanzi, F., Naumann, G., & Barbosa, P. (2023). European Drought Risk Atlas. Publications Office of the European Union. Retrieved July 22nd, 2024, from https://doi.org/10.2760/608737 Runco, M. A. (2023). AI Can Only Produce Artificial Creativity. Journal of Creativity, 33(72), 100063. Retrieved June 7th, 2024, from https://doi.org/10.1016/j.yjoc.2023.100063 Saariluoma, P., & Karvonen, A. (2023). Recommended Inventory for Theory languages in designing artificial intelligence. AI & Society. Retrieved July 2nd, 2024, from https://doi.org/10.1007/s00146-023-01716-y Salminen, M. (2022). “Et nää on näitä meiän kyberhyökkäyksiä nämä” – The government of one and all in everyday digital security in Finnish Lapland.
85 University of Lapland. Retrieved June 6th, 2024, from https://urn.fi/URN:ISBN:978-952-337-314-3 Santos-Olmo, A., Sánchez, L. E., Rosado, D. G., Serrano, M. A., Blanco, C., Mouratidis, H., & Fernández-Medina, E. (2024). Towards an integrated risk analysis security framework according to a systematic analysis of existing proposals. Frontiers of Computer Science, 18(3), 183808. Retrieved August 19th, 2024, from https://doi.org/10.1007/s11704-023-1582-6 Sartori, L., & Bocca, G. (2023). Minding the gap(s): Public perceptions of AI and socio-technical imaginaries. AI & Society, 38(3), 443-458. Retrieved June 2nd, 2024, from https://doi.org/10.1007/s00146-022-01422-1 Schmidt, M. (2023). Information security risk management terminology and key concepts. Risk Management, 25(2). Retrieved August 1st, 2024, from https://doi.org/10.1057/s41283-022-00108-8 Schuchmann, S. (2019). Analyzing the Prospect of an Approaching AI Winter. Retrieved May 18th, 2024, from https://www.researchgate.net/publication/333039347_Analyzing_the_Pr ospect_of_an_Approaching_AI_Winter Schuett, J. (2023). Risk Management in the Artificial Intelligence Act. European Journal of Risk Regulation, 1–19. Retrieved May 9th, 2024, from https://doi.org/10.1017/err.2023.1 Sheikh, H., Prins, C., & Schrijvers, E. (2023). Artificial Intelligence: Definition and Background. In Mission AI. Research for Policy. Springer, Cham. Retrieved July 17th, 2024, from https://doi.org/10.1007/978-3-031-214486_2 Sherman, E., & Eisenberg, I. (2024). AI risk profiles: A standards proposal for predeployment AI risk disclosures. Proceedings of the AAAI Conference on Artificial Intelligence, 38(21), 23047-23052. Retrieved June 20th, 2024, from https://doi.org/10.1609/aaai.v38i21.30348 Shih, W. C. (2020). Increasing the level of abstraction as a strategy for accelerating the adoption of complex technologies. Strategy Science, 6(1), 54-61. Retrieved August 17th, 2024, from https://www.hbs.edu/ris/Publication%20Files/Increasing%20the %20level%20of%20abstraction_ca0a5b9b-cec7-482c-95ca-b56e5c5a9d67.pdf Sigfrids, A., Nieminen, M., Leikas, J., Karvonen, A., & Pikkuaho, P. (2023). Julkishallinto tukemassa eettisen tekoälyyhteiskunnan rakentamista. Katsaus tekoälyn ohjauskeinoihin ja politiikkatoimenpiteisiin. VTT TECHNOLOGY 421. Retrieved April 25th, 2024, from https://doi.org/10.32040/2242-122X.2023.T421
86 Snyder, H. (2019). Literature review as a research methodology: An overview and guidelines. Journal of Business Research, 104, 333–339. Retrieved March 27th, 2024, from https://doi.org/10.1016/j.jbusres.2019.07.039 Sommerville, I. (2016). Software engineering (Tenth edition, global edition). Pearson. Sowa, J. F. (2004). The law of standards. Retrieved September 7th, 2024, from https://www.jfsowa.com/computer/standard.htm Stahl, B. C., Antoniou, J., Ryan, M., Macnish, K., & Jiya, T. (2022). Organisational responses to the ethical issues of artificial intelligence. AI & SOCIETY, 37, 23–37. Retrieved May 4th, 2024, from https://doi.org/10.1007/s00146-021-01148-6 Stepek, J. (2024). How should you invest around the AI bubble? Bloomberg. Retrieved August 2nd, 2024, from https://www.bloomberg.com/news/newsletters/2024-07-09/howshould-you-invest-around-the-ai-bubble Storry, M., & Poppleton, S. (2022). The impact of online abuse: Hearing the victims’ voice. Victims’ Commissioner for England and Wales. Retrieved July 22nd, 2024, from https://victimscommissioner.org.uk/document/the-impactof-online-abuse-hearing-the-victims-voice/ Sääskilahti, T., & Mustonen, E. (2023). Riskienhallinnan käsikirja valtionhallinnon toimijoille (Valtiovarainministeriön julkaisuja 2023:54). Ministry of finance of Finland. Retrieved August 18th, 2024, from http://urn.fi/URN:ISBN:978-952-367-633-6 Tappura, S., Hyytinen, T., Kivistö-Rahnasto, J., Nenonen, N., & Vasara, J. (2015). Turvallisuuden johtajat - Esimiesten johtajuus, osaaminen ja sitoutuminen. Tampereen teknillinen yliopisto; Tampereen yliopisto. Retrieved May 22nd, 2024, from https://research.tuni.fi/uploads/2019/08/86f4012bloppuraportti_30.12.2015.pdf Te’eni, D., & Sani-Kuperberg, Z. (2005). Levels of abstraction in designs of human–computer interaction: The case of e-mail. Computers in Human Behavior, 21(5), 817-830. Retrieved August 17th, 2024, from https://doi.org/10.1016/j.chb.2004.03.029 The Economist. (2024). What happened to the artificial-intelligence revolution? The Economist. Retrieved August 2nd, 2024, from https://www.economist.com/finance-and-economics/2024/07/02/whathappened-to-the-artificial-intelligence-revolution The European co-operation for Accreditation. (2022). EA Multilateral Agreement: Criteria for signing, policy and procedures for development (Publication Reference EA-1/06 A-AB:2022). Retrieved September 4th,
87 2024, from https://european-accreditation.org/wp-content/uploads/2018/10/ea-106-A-AB.pdf The Upwork Research Institute. (2024). From Burnout to Balance: AI-Enhanced Work Models. Upwork. Retrieved July 29th, 2024, from https://www.upwork.com/research/ai-enhanced-work-models Thompson, N., Svanberg, M. S., Li, W., Fleming, M., & Goehring, B. C. (2024). Beyond AI Exposure: Which Tasks are Cost-Effective to Automate with Computer Vision? FutureTech. Retrieved May 24th, 2024, from https://futuretech-site.s3.us-east-2.amazonaws.com/2024-0118+Beyond_AI_Exposure.pdf Tursunbayeva, A., & Chalutz-Ben Gal, H. (2024). Adoption of artificial intelligence: A TOP framework-based checklist for digital leaders. Business Horizons, 67(4), 357-368. Retrieved July 25th, 2024, from https://doi.org/10.1016/j.bushor.2024.04.006 United Nations. (2023). Advancing rule of law, justice for all through technology must include equal internet access, human rights compliance, sixth committee speakers stress. Retrieved July 18th, 2024, from https://press.un.org/en/2023/gal3694.doc.htm van Noordt, C., & Tangi, L. (2023). The dynamics of AI capability and its influence on public value creation of AI within public administration. Government Information Quarterly, 40. Retrieved May 8th, 2024, from https://doi.org/10.1016/j.giq.2023.101860 Vassilev, A., Oprea, A., Fordyce, A., & Anderson, H. (2024). Adversarial machine learning: A taxonomy and terminology of attacks and mitigations (NIST AI 1002 E2023). National Institute of Standards and Technology (NIST). Retrieved July 12th, 2024, from https://csrc.nist.gov/pubs/ai/100/2/e2023/final Viljanen, M. (2023). Menikö juna jo? Tekoälyn sääntelemisen mahdollisuuksista. Lakimies, 7–8, 1204–1231. Retrieved May 2nd, 2024, from https://journal.fi/lakimies/article/download/136265/89446/316049 Vinuesa, R., Azizpour, H., Leite, I., Balaam, M., Dignum, V., Domisch, S., Felländer, A., Langhans, S. D., Tegmark, M., & Fuso Nerini, F. (2020). The role of artificial intelligence in achieving the Sustainable Development Goals. Nature Communications, 11(1), 233. Retrieved July 12th, 2024, from https://doi.org/10.1038/s41467-019-14108-y Vähäkainu, P., Lehto, M., & Neittaanmäki, P. (2018). Tekoäly ja kyberturvallisuus. In H. Tuominen, & P. Neittaanmäki (Eds.), Tekoälyn perusteita ja sovelluksia. Jyväskylän yliopisto, Informaatioteknologian
88 tiedekunta. Retrieved May 23rd, 2024, from https://jyx.jyu.fi/handle/123456789/64975 Wang, L., Liu, Z., Liu, A., & Tao, F. (2021). Artificial intelligence in product lifecycle management. The International Journal of Advanced Manufacturing Technology, 114, 771-796. Retrieved May 11th, 2024, from https://doi.org/10.1007/s00170-021-06882-1 Weidinger, L., Uesato, J., Rauh, M., Griffin, C., Huang, P.-S., Mellor, J., Glaese, A., Cheng, M., Balle, B., Kasirzadeh, A., Biles, C., Brown, S., Kenton, Z., Hawkins, W., Stepleton, T., Birhane, A., Hendricks, L. A., Rimell, L., Isaac, W., Haas, J., Legassick, S., Irving, G., & Gabriel, I. (2022). Taxonomy of risks posed by language models. In FAccT '22: Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency (214-229). ACM. https://doi.org/10.1145/3531146.3533088 Whitworth, B., & Zaic, M. (2003). The WOSP model: Balanced information system design and evaluation. Communications of the Association for Information Systems, 12, 258-282. Retrieved June 7th, 2024, from https://doi.org/10.17705/1CAIS.01217 Whyman, B. (2023). AI regulation is coming - What is the likely outcome? CSIS Strategic Technologies Blog. Retrieved July 19th, 2024, from https://www.csis.org/blogs/strategic-technologies-blog/ai-regulationcoming-what-likely-outcome Wikipedia. (n.a.). Jyrki Kasvi. In Wikipedia. Retrieved August 7th, 2024, from https://en.wikipedia.org/wiki/Jyrki_Kasvi World Economic Forum. (2024). Global Risks Report 2024. Retrieved July 24th, 2024, from https://www.weforum.org/publications/global-risks-report2024/ Xia, B., Lu, Q., Perera, H., Zhu, L., Xing, Z., Liu, Y., & Whittle, J. (2023). Towards Concrete and Connected AI Risk Assessment (C2AIRA): A Systematic Mapping Study. ArXiv. Retrieved May 17th, 2024, from https://doi.org/10.48550/arXiv.2301.11616v4 Yampolskiy, R. V. (2015). Taxonomy of pathways to dangerous AI. In Proceedings of the 2nd International Workshop on AI, Ethics and Society (AIEthicsSociety2016) (143-148). Retrieved August 17th, 2024, from https://doi.org/10.48550/arXiv.1511.03246