Securing the AI Revolution: A Maturity Framework for Trustworthy and Resilient Software
DOI:
https://doi.org/10.34190/eccws.25.1.4703Keywords:
artificial intelligence, capability maturity model, software engineering, zone of proximal development, experiential learningAbstract
Traditional software-development maturity models—CMMI, Agile, and DevOps—were designed for deterministic, human‑centric processes and struggle to govern the probabilistic, data‑driven nature of AI systems. As organizations embed Artificial Intelligence (AI) across the Software Development Life Cycle (SDLC), these legacy frameworks lack structures to manage AI‑specific risks such as governance, security, data provenance, and model behavior. Accelerated digital transformation and cloud‑native delivery amplify the consequences of unmanaged AI adoption, exposing firms to systemic security and supply‑chain vulnerabilities. This study uses constructivist Glaserian Grounded Theory to synthesize evidence from industry practitioners, academic researchers, FFRDCs, and scholarly literature, thereby creating an AI‑centric software maturity framework. This study develops a five-level AI maturity framework for developing trustworthy and resilient software, grounded in secondary data from industry documents, academic papers, and FFRDC reports using Glaserian Grounded Theory. The framework is empirically derived to identify recurring patterns across sectors, yet it is explicitly presented as a modifiable theory rather than a statistically generalizable model. Future work will validate the framework through primary research – interviews, surveys, and observations to capture informal decision-making practices omitted from the secondary corpus. This five-stage AI adoption model offers a progressive, security-oriented maturation through the stages of 1) Foundational Awareness & Governance—establish AI policies, ethics, and baseline literacy; (2) Experimentation & Initial Integration—enable controlled AI pilots in isolated environments; (3) Integrated Development—embed AI within CI/CD pipelines and business workflows; (4) Proactive Security & Trusted AI—scale AI with threat detection, adversarial testing, and model security; and (5) Adaptive Excellence—achieve continuous, closed‑loop optimization of AI performance, security, and impact. These findings leverage coaching, Vygotsky’s zone of proximal development, and Kolb’s experiential learning to reconcile rapid delivery with trustworthy, resilient software while aligning governance, automation, and security across all stages reduces systemic risk, strengthens supply‑chain resilience, and enables sustainable AI transformation.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 European Conference on Cyber Warfare and Security

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.