Data Governance and Policy Support for Secure AI-Driven Corporate Digital Transformation
Article Information
Abstract
Artificial intelligence is becoming a core engine of corporate digital transformation, but its value depends first on secure, reliable, and accountable data and model infrastructures. As firms combine cloud platforms, edge devices, IoT sensors, digital twins, platform data, and algorithmic decision systems, they also expand the attack surface, privacy exposure, model security risk, and compliance burden. This paper develops a security-aware data and AI governance framework for AI-driven corporate digital transformation. It positions the framework as a unified governance model rather than a narrow extension of data management: data governance controls data classification, provenance, access, privacy, and sharing, while AI governance assures model validation, robustness, auditability, and accountability. The paper identifies six dilemmas: data sharing versus protection, weak provenance and pipeline security, adversarial or opaque AI models, vulnerabilities in cloud-edge-IoT and digital-twin ecosystems, unequal compliance capacity between large firms and SMEs, and fragmented coordination across cybersecurity, privacy, competition, and industrial policy. It then proposes an integrated agenda of tiered data governance, zero-trust and encryption-based security, privacy-enhancing collaboration, model validation and adversarial testing, algorithmic audit, incident response, regulatory sandboxes, certification, public secure data spaces, maturity indicators, and SME-oriented compliance services. The study contributes to reliable and secure computing research by showing that technical controls, organizational routines, and policy support must be integrated to enable trustworthy AI-driven transformation across firms of different sizes and sectors.
Graphical Abstract
Keywords
Data Availability Statement
Funding
Conflicts of Interest
AI Use Statement
Ethical Approval and Consent to Participate
References
- Verhoef, P. C., Broekhuizen, T., Bart, Y., Bhattacharya, A., Dong, J. Q., Fabian, N., & Haenlein, M. (2021). Digital transformation: A multidisciplinary reflection and research agenda. Journal of business research, 122, 889-901.
[CrossRef] [Google Scholar] - Bharadwaj, A., El Sawy, O. A., Pavlou, P. A., & Venkatraman, N. V. (2013). Digital business strategy: toward a next generation of insights. MIS quarterly, 37(2), 471-482.
[CrossRef] [Google Scholar] - Fitzgerald, M., Kruschwitz, N., Bonnet, D., & Welch, M. (2013). Embracing digital technology: A new strategic imperative. MIT sloan management review, 55(2), 1. https://sloanreview.mit.edu/projects/scholars/embracing-digital-technology/
[Google Scholar] - European Parliament and Council. (2016). Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
[Google Scholar] - European Parliament and Council. (2022). Regulation (EU) 2022/868 on European data governance and amending Regulation (EU) 2018/1724 (Data Governance Act). Official Journal of the European Union. http://data.europa.eu/eli/reg/2022/868/oj
[Google Scholar] - European Parliament and Council. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. http://data.europa.eu/eli/reg/2024/1689/oj
[Google Scholar] - Tabassi, E. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). National Institute of Standards and Technology.
[CrossRef] [Google Scholar] - ISO/IEC. (2023). ISO/IEC 23894:2023 Information technology - Artificial intelligence - Guidance on risk management. International Organization for Standardization. https://www.iso.org/standard/77304.html
[Google Scholar] - Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture (No. NIST Special Publication (SP) 800-207). National Institute of Standards and Technology.
[CrossRef] [Google Scholar] - Mäntymäki, M., Minkkinen, M., Birkstedt, T., & Viljanen, M. (2022). Defining organizational AI governance. AI and Ethics, 2(4), 603-609.
[CrossRef] [Google Scholar] - Cihon, P., Maas, M. M., & Kemp, L. (2020, February). Should artificial intelligence governance be centralised? Design lessons from history. In Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society (pp. 228-234).
[CrossRef] [Google Scholar] - Wirtz, B. W., Weyerer, J. C., & Geyer, C. (2019). Artificial intelligence and the public sector—applications and challenges. International journal of public administration, 42(7), 596-615.
[CrossRef] [Google Scholar] - Rubinstein, I. S. (2011). Regulating privacy by design. Berkeley Tech. LJ, 26, 1409.
[Google Scholar] - Boyes, H., Hallaq, B., Cunningham, J., & Watson, T. (2018). The industrial internet of things (IIoT): An analysis framework. Computers in industry, 101, 1-12.
[CrossRef] [Google Scholar] - Janssen, M., Brous, P., Estevez, E., Barbosa, L. S., & Janowski, T. (2020). Data governance: Organizing data for trustworthy Artificial Intelligence. Government information quarterly, 37(3), 101493.
[CrossRef] [Google Scholar] - Khatri, V., & Brown, C. V. (2010). Designing data governance. Communications of the ACM, 53(1), 148-152.
[CrossRef] [Google Scholar] - Weber, K., Otto, B., & Österle, H. (2009). One size does not fit all---a contingency approach to data governance. Journal of Data and Information Quality (JDIQ), 1(1), 1-27.
[CrossRef] [Google Scholar] - Abraham, R., Schneider, J., & Vom Brocke, J. (2019). Data governance: A conceptual framework, structured review, and research agenda. International journal of information management, 49, 424-438.
[CrossRef] [Google Scholar] - OECD. (2022). Going Digital to Advance Data Governance for Growth and Well-being. OECD Publishing.
[CrossRef] [Google Scholar] - Tene, O., & Polonetsky, J. (2011). Privacy in the age of big data: a time for big decisions. Stan. L. Rev. Online, 64, 63.
[Google Scholar] - Wieringa, J., Kannan, P. K., Ma, X., Reutterer, T., Risselada, H., & Skiera, B. (2021). Data analytics in a privacy-concerned world. Journal of Business Research, 122, 915-925.
[CrossRef] [Google Scholar] - Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572.
[CrossRef] [Google Scholar] - Papernot, N., McDaniel, P., Sinha, A., & Wellman, M. P. (2018, April). Sok: Security and privacy in machine learning. In 2018 IEEE European symposium on security and privacy (EuroS&P) (pp. 399-414). IEEE.
[CrossRef] [Google Scholar] - Biggio, B., & Roli, F. (2018, October). Wild patterns: Ten years after the rise of adversarial machine learning. In Proceedings of the 2018 ACM SIGSAC conference on computer and communications security (pp. 2154-2156).
[CrossRef] [Google Scholar] - Mitchell, M., Wu, S., Zaldivar, A., Barnes, P., Vasserman, L., Hutchinson, B., ... & Gebru, T. (2019, January). Model cards for model reporting. In Proceedings of the conference on fairness, accountability, and transparency (pp. 220-229).
[CrossRef] [Google Scholar] - Gebru, T., Morgenstern, J., Vecchione, B., Vaughan, J. W., Wallach, H., Iii, H. D., & Crawford, K. (2021). Datasheets for datasets. Communications of the ACM, 64(12), 86-92. https://dx.doi.org/10.1145/3458723
[Google Scholar] - Raji, I. D., Smart, A., White, R. N., Mitchell, M., Gebru, T., Hutchinson, B., ... & Barnes, P. (2020, January). Closing the AI accountability gap: Defining an end-to-end framework for internal algorithmic auditing. In Proceedings of the 2020 conference on fairness, accountability, and transparency (pp. 33-44).
[CrossRef] [Google Scholar] - Raisch, S., & Krakowski, S. (2021). Artificial intelligence and management: The automation–augmentation paradox. Academy of management review, 46(1), 192-210.
[CrossRef] [Google Scholar] - Mittelstadt, B. D., Allo, P., Taddeo, M., Wachter, S., & Floridi, L. (2016). The ethics of algorithms: Mapping the debate. Big data & society, 3(2), 2053951716679679.
[CrossRef] [Google Scholar] - Leslie, D. (2019). Understanding Artificial Intelligence Ethics and Safety: A Guide for the Responsible Design and Implementation of AI Systems in the Public Sector. The Alan Turing Institute.
[CrossRef] [Google Scholar] - Dwivedi, Y. K., Hughes, L., Ismagilova, E., Aarts, G., Coombs, C., Crick, T., ... & Williams, M. D. (2021). Artificial Intelligence (AI): Multidisciplinary perspectives on emerging challenges, opportunities, and agenda for research, practice and policy. International journal of information management, 57, 101994.
[CrossRef] [Google Scholar] - Dwork, C. (2008, April). Differential privacy: A survey of results. In International conference on theory and applications of models of computation (pp. 1-19). Berlin, Heidelberg: Springer Berlin Heidelberg.
[CrossRef] [Google Scholar] - Kairouz, P., & McMahan, H. B. (2021). Advances and open problems in federated learning. Foundations and trends in machine learning, 14(1-2), 1-210.
[CrossRef] [Google Scholar] - Lindell, Y. (2020). Secure multiparty computation. Communications of the ACM, 64(1), 86-96.
[CrossRef] [Google Scholar] - UNESCO. (2021). Recommendation on the Ethics of Artificial Intelligence. United Nations Educational, Scientific and Cultural Organization. https://www.unesco.org/en/articles/recommendation-ethics-artificial-intelligence
[Google Scholar] - OECD. (2024). Recommendation of the Council on Artificial Intelligence. OECD Legal Instruments. https://legalinstruments.oecd.org/en/instruments/oecd-legal-0449
[Google Scholar] - OECD. (2020). Going Digital integrated policy framework. OECD Digital Economy Papers, No. 292. OECD Publishing.
[CrossRef] [Google Scholar] - Brous, P., Janssen, M., & Herder, P. (2020). The dual effects of the Internet of Things (IoT): A systematic review of the benefits and risks of IoT adoption by organizations. International Journal of Information Management, 51, 101952.
[CrossRef] [Google Scholar] - Brynjolfsson, E., Rock, D., & Syverson, C. (2018). Artificial intelligence and the modern productivity paradox: A clash of expectations and statistics. In The economics of artificial intelligence: An agenda (pp. 23-57). University of Chicago Press. https://www.nber.org/system/files/chapters/c14007/c14007.pdf
[Google Scholar] - Floridi, L., Cowls, J., Beltrametti, M., Chatila, R., Chazerand, P., Dignum, V., ... & Vayena, E. (2018). AI4People—An ethical framework for a good AI society: Opportunities, risks, principles, and recommendations. Minds and machines, 28(4), 689-707.
[CrossRef] [Google Scholar] - Brundage, M., Avin, S., Wang, J., Belfield, H., Krueger, G., Hadfield, G., ... & Anderljung, M. (2020). Toward trustworthy AI development: mechanisms for supporting verifiable claims. arXiv preprint arXiv:2004.07213.
[CrossRef] [Google Scholar] - Adner, R. (2017). Ecosystem as structure: An actionable construct for strategy. Journal of management, 43(1), 39-58.
[CrossRef] [Google Scholar] - Zuboff, S. (2019). The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. PublicAffairs. https://www.hbs.edu/faculty/Pages/item.aspx?num=56791
[Google Scholar]
Cite This Article
TY - JOUR AU - Sun, Fang PY - 2026 DA - 2026/07/21 TI - Data Governance and Policy Support for Secure AI-Driven Corporate Digital Transformation JO - Journal of Reliable and Secure Computing T2 - Journal of Reliable and Secure Computing JF - Journal of Reliable and Secure Computing VL - 2 IS - 3 SP - 164 EP - 178 DO - 10.62762/JRSC.2026.326448 UR - https://www.icck.org/article/abs/JRSC.2026.326448 KW - secure data governance KW - AI-driven corporate digital transformation KW - trustworthy AI KW - cybersecurity KW - privacy-preserving computation KW - compliance framework KW - model security AB - Artificial intelligence is becoming a core engine of corporate digital transformation, but its value depends first on secure, reliable, and accountable data and model infrastructures. As firms combine cloud platforms, edge devices, IoT sensors, digital twins, platform data, and algorithmic decision systems, they also expand the attack surface, privacy exposure, model security risk, and compliance burden. This paper develops a security-aware data and AI governance framework for AI-driven corporate digital transformation. It positions the framework as a unified governance model rather than a narrow extension of data management: data governance controls data classification, provenance, access, privacy, and sharing, while AI governance assures model validation, robustness, auditability, and accountability. The paper identifies six dilemmas: data sharing versus protection, weak provenance and pipeline security, adversarial or opaque AI models, vulnerabilities in cloud-edge-IoT and digital-twin ecosystems, unequal compliance capacity between large firms and SMEs, and fragmented coordination across cybersecurity, privacy, competition, and industrial policy. It then proposes an integrated agenda of tiered data governance, zero-trust and encryption-based security, privacy-enhancing collaboration, model validation and adversarial testing, algorithmic audit, incident response, regulatory sandboxes, certification, public secure data spaces, maturity indicators, and SME-oriented compliance services. The study contributes to reliable and secure computing research by showing that technical controls, organizational routines, and policy support must be integrated to enable trustworthy AI-driven transformation across firms of different sizes and sectors. SN - 3070-6424 PB - Institute of Central Computation and Knowledge LA - English ER -
@article{Sun2026Data,
author = {Fang Sun},
title = {Data Governance and Policy Support for Secure AI-Driven Corporate Digital Transformation},
journal = {Journal of Reliable and Secure Computing},
year = {2026},
volume = {2},
number = {3},
pages = {164-178},
doi = {10.62762/JRSC.2026.326448},
url = {https://www.icck.org/article/abs/JRSC.2026.326448},
abstract = {Artificial intelligence is becoming a core engine of corporate digital transformation, but its value depends first on secure, reliable, and accountable data and model infrastructures. As firms combine cloud platforms, edge devices, IoT sensors, digital twins, platform data, and algorithmic decision systems, they also expand the attack surface, privacy exposure, model security risk, and compliance burden. This paper develops a security-aware data and AI governance framework for AI-driven corporate digital transformation. It positions the framework as a unified governance model rather than a narrow extension of data management: data governance controls data classification, provenance, access, privacy, and sharing, while AI governance assures model validation, robustness, auditability, and accountability. The paper identifies six dilemmas: data sharing versus protection, weak provenance and pipeline security, adversarial or opaque AI models, vulnerabilities in cloud-edge-IoT and digital-twin ecosystems, unequal compliance capacity between large firms and SMEs, and fragmented coordination across cybersecurity, privacy, competition, and industrial policy. It then proposes an integrated agenda of tiered data governance, zero-trust and encryption-based security, privacy-enhancing collaboration, model validation and adversarial testing, algorithmic audit, incident response, regulatory sandboxes, certification, public secure data spaces, maturity indicators, and SME-oriented compliance services. The study contributes to reliable and secure computing research by showing that technical controls, organizational routines, and policy support must be integrated to enable trustworthy AI-driven transformation across firms of different sizes and sectors.},
keywords = {secure data governance, AI-driven corporate digital transformation, trustworthy AI, cybersecurity, privacy-preserving computation, compliance framework, model security},
issn = {3070-6424},
publisher = {Institute of Central Computation and Knowledge}
}
Article Metrics
Publisher's Note
ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Rights and Permissions
Copyright © 2026 by the Author(s). Published by Institute of Central Computation and Knowledge. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made.
Portico