Toward Identifying Role-Aligned AI Governance Needs in Mixed-Trust Environments
DOI:
https://doi.org/10.34190/eccws.25.1.4710Keywords:
AI governance, Audit frameworks, Trust, Risk-management, Mixed-trust environmentsAbstract
The rapid emergence of AI is driving governance challenges in security-sensitive organizational settings. For example, deploying AI in these contexts typically requires embedding automated or semi-automated decision-making into mixed-trust environments characterized by legacy systems, uneven access to and visibility into governance-relevant artifacts, and strict operational, security, and compliance constraints. In such environments, governance decisions, system design, and day-to-day operations are often handled by distinct organizational roles, leading to different expectations and dependencies among stakeholders. Despite growing work on AI governance, there is limited, role-specific guidance that clarifies what governance leaders and oversight bodies should require, what engineers and implementers must ensure, and what operators and system administrators can rely on when deploying and operating AI in mixed-trust environments. This leaves organizations without a shared basis for translating general governance principles into concrete deployment requirements, compliance controls, risk assessments, and ongoing operational accountability. Current and emerging AI governance and risk management frameworks largely provide lifecycle-based approaches to AI risk, establishing a common vocabulary and baseline for AI use within organizations. However, they provide limited guidance on how responsibilities should be interpreted and enacted across organizational roles, particularly in constrained, security-sensitive deployments. In this paper, we analyze widely adopted AI governance and risk-management frameworks and prior synthesis literature through the lens of three stakeholder layers: governance leaders and oversight bodies; engineers and implementers; operators and system administrators. For each layer, we examine what current frameworks explicitly and implicitly address and where role expectations remain underspecified. Building on this analysis, we propose an initial set of role-aligned governance needs and highlight cross-cutting socio-technical factors that shape the enactment of AI governance in practice. The goal is to inform future research, policy work, standards development, and operational planning by moving AI adoption in mixed-trust contexts from aspirational frameworks toward practical, accountable, and auditable implementations.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 European Conference on Cyber Warfare and Security

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.