Securing the AI Revolution: A Maturity Framework for Trustworthy and Resilient Software

Authors

DOI:

https://doi.org/10.34190/eccws.25.1.4703

Keywords:

artificial intelligence, capability maturity model, software engineering, zone of proximal development, experiential learning

Abstract

Traditional software-development maturity models—CMMI, Agile, and DevOps—were designed for deterministic, human‑centric processes and struggle to govern the probabilistic, data‑driven nature of AI systems. As organizations embed Artificial Intelligence (AI) across the Software Development Life Cycle (SDLC), these legacy frameworks lack structures to manage AI‑specific risks such as governance, security, data provenance, and model behavior. Accelerated digital transformation and cloud‑native delivery amplify the consequences of unmanaged AI adoption, exposing firms to systemic security and supply‑chain vulnerabilities. This study uses constructivist Glaserian Grounded Theory to synthesize evidence from industry practitioners, academic researchers, FFRDCs, and scholarly literature, thereby creating an AI‑centric software maturity framework. This study develops a five-level AI maturity framework for developing trustworthy and resilient software, grounded in secondary data from industry documents, academic papers, and FFRDC reports using Glaserian Grounded Theory. The framework is empirically derived to identify recurring patterns across sectors, yet it is explicitly presented as a modifiable theory rather than a statistically generalizable model. Future work will validate the framework through primary research – interviews, surveys, and observations to capture informal decision-making practices omitted from the secondary corpus. This five-stage AI adoption model offers a progressive, security-oriented maturation through the stages of 1) Foundational Awareness & Governance—establish AI policies, ethics, and baseline literacy; (2) Experimentation & Initial Integration—enable controlled AI pilots in isolated environments; (3) Integrated Development—embed AI within CI/CD pipelines and business workflows; (4) Proactive Security & Trusted AI—scale AI with threat detection, adversarial testing, and model security; and (5) Adaptive Excellence—achieve continuous, closed‑loop optimization of AI performance, security, and impact. These findings leverage coaching, Vygotsky’s zone of proximal development, and Kolb’s experiential learning to reconcile rapid delivery with trustworthy, resilient software while aligning governance, automation, and security across all stages reduces systemic risk, strengthens supply‑chain resilience, and enables sustainable AI transformation.

Author Biography

Jami Carroll, Unaffiliated

Dr. Jami M. Carroll, a 20‑year Navy veteran, founded Prisidian Security Solutions in 2008. His expertise spans artificial intelligence, offensive cyber operations, threat intelligence, denial/deception, and geopolitics. He holds a BBA (National University), MBA (Southern New Hampshire University), MS/DSc in Cybersecurity (Capitol Technology University), and an MA in International Relations (Harvard Extension School).

Downloads

Published

2026-06-15