Generative AI Risk Governance in Organizational Information Systems: A Conceptual Model Integrating Security, Ethics, and Digital Trust
DOI:
https://doi.org/10.56127/ijst.v5i2.2876Keywords:
Generative AI, AI governance, information security, ethical AI, digital trust, information systemsAbstract
The rapid adoption of Generative Artificial Intelligence in organizational information systems has created new opportunities for improving productivity, decision-making, service innovation, and knowledge management. However, its implementation also introduces critical risks related to data privacy, information security, inaccurate outputs, algorithmic bias, ethical misuse, and declining user trust. Objective: This study aims to develop a conceptual model of Generative AI risk governance by integrating AI governance readiness, information security control, ethical AI awareness, user digital trust, and AI adoption effectiveness. The model is proposed to explain how organizations can adopt Generative AI in a secure, ethical, responsible, and trusted manner. Methodology: This study employed a conceptual research design using an integrative literature review approach. Data were collected from secondary academic sources, including peer-reviewed journal articles, reputable conference proceedings, and official technical reports relevant to Generative AI, information systems, cybersecurity, AI ethics, responsible AI governance, and digital trust. The data were analyzed through thematic synthesis to identify conceptual domains, relationships among constructs, and research propositions. Findings: The findings indicate that AI governance readiness serves as a foundational construct that strengthens information security control and ethical AI awareness. These two mechanisms contribute to user digital trust, which subsequently supports the effectiveness of Generative AI adoption in organizational information systems. Implications: This study implies that organizations should not adopt Generative AI solely based on technological benefits. Organizations need to establish governance policies, security controls, ethical guidelines, user education, and trust-building strategies to ensure that Generative AI implementation is safe, accountable, and aligned with organizational objectives. Originality: The originality of this study lies in its integrated conceptual framework, which connects technology adoption, information security, AI ethics, responsible AI governance, and digital trust into a single model for responsible Generative AI implementation in organizational information systems.
References
Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P., & Roberts, K. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1, Issue. https://doi.org/10.6028/NIST.AI.600-1
Bélanger, F., & Crossler, R. E. (2011). Privacy in the Digital Age: A Review of Information Privacy Research in Information Systems. MIS Quarterly, 35(4), 1017-1042. https://doi.org/10.2307/41409971
Bender, E. M., Gebru, T., McMillan-Major, A., & Shmitchell, S. (2021). On the Dangers of Stochastic Parrots: Can Language Models Be Too Big? Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency,
D'Arcy, J., Hovav, A., & Galletta, D. (2009). User Awareness of Security Countermeasures and Its Impact on Information Systems Misuse: A Deterrence Approach. Information Systems Research, 20(1), 79-98. https://doi.org/10.1287/isre.1070.0160
Davis, F. D. (1989). Perceived Usefulness, Perceived Ease of Use, and User Acceptance of Information Technology. MIS Quarterly, 13(3), 319-340. https://doi.org/10.2307/249008
DeLone, W. H., & McLean, E. R. (2003). The DeLone and McLean Model of Information Systems Success: A Ten-Year Update. Journal of Management Information Systems, 19(4), 9-30. https://doi.org/10.1080/07421222.2003.11045748
Dwivedi, Y. K., Hughes, L., Ismagilova, E., Aarts, G., Coombs, C., Crick, T., Duan, Y., Dwivedi, R., Edwards, J. S., Eirug, A., Galanos, V., Ilavarasan, P. V., Janssen, M., Jones, P., Kar, A. K., Kizgin, H., Kronemann, B., Lal, B., Lucini, B.,…Williams, M. D. (2021). Artificial Intelligence (AI): Multidisciplinary Perspectives on Emerging Challenges, Opportunities, and Agenda for Research, Practice and Policy. International Journal of Information Management, 57, 101994. https://doi.org/10.1016/j.ijinfomgt.2019.08.002
Floridi, L., & Cowls, J. (2019). A Unified Framework of Five Principles for AI in Society. Harvard Data Science Review, 1(1). https://doi.org/10.1162/99608f92.8cd550d1
Greshake, K., Abdelnabi, S., Mishra, S., Endres, C., Holz, T., & Fritz, M. (2023). Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection. Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security,
Ifinedo, P. (2012). Understanding Information Systems Security Policy Compliance: An Integration of the Theory of Planned Behavior and the Protection Motivation Theory. Computers & Security, 31(1), 83-95. https://doi.org/10.1016/j.cose.2011.10.007
Jobin, A., Ienca, M., & Vayena, E. (2019). The Global Landscape of AI Ethics Guidelines. Nature Machine Intelligence, 1, 389-399. https://doi.org/10.1038/s42256-019-0088-2
Lee, J. D., & See, K. A. (2004). Trust in Automation: Designing for Appropriate Reliance. Human Factors, 46(1), 50-80. https://doi.org/10.1518/hfes.46.1.50_30392
McKnight, D. H., Choudhury, V., & Kacmar, C. (2002). Developing and Validating Trust Measures for E-Commerce: An Integrative Typology. Information Systems Research, 13(3), 334-359. https://doi.org/10.1287/isre.13.3.334.81
Papagiannidis, E., Mikalef, P., & Conboy, K. (2025). Responsible Artificial Intelligence Governance: A Review and Research Framework. The Journal of Strategic Information Systems, 34(2), 101885. https://doi.org/10.1016/j.jsis.2024.101885
Safa, N. S., von Solms, R., & Furnell, S. (2016). Information Security Policy Compliance Model in Organizations. Computers & Security, 56, 70-82. https://doi.org/10.1016/j.cose.2015.10.006
Shin, D. (2021). The Effects of Explainability and Causability on Perception, Trust, and Acceptance: Implications for Explainable AI. International Journal of Human-Computer Studies, 146, 102551. https://doi.org/10.1016/j.ijhcs.2020.102551
Siponen, M., & Vance, A. (2010). Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations. MIS Quarterly, 34(3), 487-502. https://doi.org/10.2307/25750688
Snyder, H. (2019). Literature Review as a Research Methodology: An Overview and Guidelines. Journal of Business Research, 104, 333-339. https://doi.org/10.1016/j.jbusres.2019.07.039
Tabassi, E. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1, Issue. https://doi.org/10.6028/NIST.AI.100-1
Venkatesh, V., Morris, M. G., Davis, G. B., & Davis, F. D. (2003). User Acceptance of Information Technology: Toward a Unified View. MIS Quarterly, 27(3), 425-478. https://doi.org/10.2307/30036540
Venkatesh, V., Thong, J. Y. L., & Xu, X. (2012). Consumer Acceptance and Use of Information Technology: Extending the Unified Theory of Acceptance and Use of Technology. MIS Quarterly, 36(1), 157-178. https://doi.org/10.2307/41410412
Whetten, D. A. (1989). What Constitutes a Theoretical Contribution? Academy of Management Review, 14(4), 490-495. https://doi.org/10.5465/amr.1989.4308371
Yang, R., & Wibowo, S. (2022). User Trust in Artificial Intelligence: A Comprehensive Conceptual Framework. Electronic Markets, 32, 2053-2077. https://doi.org/10.1007/s12525-022-00592-6
Downloads
Published
How to Cite
Issue
Section
Citation Check
License
Copyright (c) 2026 Nurdiyanto Yusuf

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.













