Generative AI Risk Governance in Organizational Information Systems: A Conceptual Model Integrating Security, Ethics, and Digital Trust

Authors

  • Nurdiyanto Yusuf Universitas Gunadarma, Indonesia

DOI:

https://doi.org/10.56127/ijst.v5i2.2876

Keywords:

Generative AI, AI governance, information security, ethical AI, digital trust, information systems

Abstract

The rapid adoption of Generative Artificial Intelligence in organizational information systems has created new opportunities for improving productivity, decision-making, service innovation, and knowledge management. However, its implementation also introduces critical risks related to data privacy, information security, inaccurate outputs, algorithmic bias, ethical misuse, and declining user trust. Objective: This study aims to develop a conceptual model of Generative AI risk governance by integrating AI governance readiness, information security control, ethical AI awareness, user digital trust, and AI adoption effectiveness. The model is proposed to explain how organizations can adopt Generative AI in a secure, ethical, responsible, and trusted manner. Methodology: This study employed a conceptual research design using an integrative literature review approach. Data were collected from secondary academic sources, including peer-reviewed journal articles, reputable conference proceedings, and official technical reports relevant to Generative AI, information systems, cybersecurity, AI ethics, responsible AI governance, and digital trust. The data were analyzed through thematic synthesis to identify conceptual domains, relationships among constructs, and research propositions. Findings: The findings indicate that AI governance readiness serves as a foundational construct that strengthens information security control and ethical AI awareness. These two mechanisms contribute to user digital trust, which subsequently supports the effectiveness of Generative AI adoption in organizational information systems. Implications: This study implies that organizations should not adopt Generative AI solely based on technological benefits. Organizations need to establish governance policies, security controls, ethical guidelines, user education, and trust-building strategies to ensure that Generative AI implementation is safe, accountable, and aligned with organizational objectives. Originality: The originality of this study lies in its integrated conceptual framework, which connects technology adoption, information security, AI ethics, responsible AI governance, and digital trust into a single model for responsible Generative AI implementation in organizational information systems.

References

Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P., & Roberts, K. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1, Issue. https://doi.org/10.6028/NIST.AI.600-1

Bélanger, F., & Crossler, R. E. (2011). Privacy in the Digital Age: A Review of Information Privacy Research in Information Systems. MIS Quarterly, 35(4), 1017-1042. https://doi.org/10.2307/41409971

Bender, E. M., Gebru, T., McMillan-Major, A., & Shmitchell, S. (2021). On the Dangers of Stochastic Parrots: Can Language Models Be Too Big? Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency,

D'Arcy, J., Hovav, A., & Galletta, D. (2009). User Awareness of Security Countermeasures and Its Impact on Information Systems Misuse: A Deterrence Approach. Information Systems Research, 20(1), 79-98. https://doi.org/10.1287/isre.1070.0160

Davis, F. D. (1989). Perceived Usefulness, Perceived Ease of Use, and User Acceptance of Information Technology. MIS Quarterly, 13(3), 319-340. https://doi.org/10.2307/249008

DeLone, W. H., & McLean, E. R. (2003). The DeLone and McLean Model of Information Systems Success: A Ten-Year Update. Journal of Management Information Systems, 19(4), 9-30. https://doi.org/10.1080/07421222.2003.11045748

Dwivedi, Y. K., Hughes, L., Ismagilova, E., Aarts, G., Coombs, C., Crick, T., Duan, Y., Dwivedi, R., Edwards, J. S., Eirug, A., Galanos, V., Ilavarasan, P. V., Janssen, M., Jones, P., Kar, A. K., Kizgin, H., Kronemann, B., Lal, B., Lucini, B.,…Williams, M. D. (2021). Artificial Intelligence (AI): Multidisciplinary Perspectives on Emerging Challenges, Opportunities, and Agenda for Research, Practice and Policy. International Journal of Information Management, 57, 101994. https://doi.org/10.1016/j.ijinfomgt.2019.08.002

Floridi, L., & Cowls, J. (2019). A Unified Framework of Five Principles for AI in Society. Harvard Data Science Review, 1(1). https://doi.org/10.1162/99608f92.8cd550d1

Greshake, K., Abdelnabi, S., Mishra, S., Endres, C., Holz, T., & Fritz, M. (2023). Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection. Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security,

Ifinedo, P. (2012). Understanding Information Systems Security Policy Compliance: An Integration of the Theory of Planned Behavior and the Protection Motivation Theory. Computers & Security, 31(1), 83-95. https://doi.org/10.1016/j.cose.2011.10.007

Jobin, A., Ienca, M., & Vayena, E. (2019). The Global Landscape of AI Ethics Guidelines. Nature Machine Intelligence, 1, 389-399. https://doi.org/10.1038/s42256-019-0088-2

Lee, J. D., & See, K. A. (2004). Trust in Automation: Designing for Appropriate Reliance. Human Factors, 46(1), 50-80. https://doi.org/10.1518/hfes.46.1.50_30392

McKnight, D. H., Choudhury, V., & Kacmar, C. (2002). Developing and Validating Trust Measures for E-Commerce: An Integrative Typology. Information Systems Research, 13(3), 334-359. https://doi.org/10.1287/isre.13.3.334.81

Papagiannidis, E., Mikalef, P., & Conboy, K. (2025). Responsible Artificial Intelligence Governance: A Review and Research Framework. The Journal of Strategic Information Systems, 34(2), 101885. https://doi.org/10.1016/j.jsis.2024.101885

Safa, N. S., von Solms, R., & Furnell, S. (2016). Information Security Policy Compliance Model in Organizations. Computers & Security, 56, 70-82. https://doi.org/10.1016/j.cose.2015.10.006

Shin, D. (2021). The Effects of Explainability and Causability on Perception, Trust, and Acceptance: Implications for Explainable AI. International Journal of Human-Computer Studies, 146, 102551. https://doi.org/10.1016/j.ijhcs.2020.102551

Siponen, M., & Vance, A. (2010). Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations. MIS Quarterly, 34(3), 487-502. https://doi.org/10.2307/25750688

Snyder, H. (2019). Literature Review as a Research Methodology: An Overview and Guidelines. Journal of Business Research, 104, 333-339. https://doi.org/10.1016/j.jbusres.2019.07.039

Tabassi, E. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1, Issue. https://doi.org/10.6028/NIST.AI.100-1

Venkatesh, V., Morris, M. G., Davis, G. B., & Davis, F. D. (2003). User Acceptance of Information Technology: Toward a Unified View. MIS Quarterly, 27(3), 425-478. https://doi.org/10.2307/30036540

Venkatesh, V., Thong, J. Y. L., & Xu, X. (2012). Consumer Acceptance and Use of Information Technology: Extending the Unified Theory of Acceptance and Use of Technology. MIS Quarterly, 36(1), 157-178. https://doi.org/10.2307/41410412

Whetten, D. A. (1989). What Constitutes a Theoretical Contribution? Academy of Management Review, 14(4), 490-495. https://doi.org/10.5465/amr.1989.4308371

Yang, R., & Wibowo, S. (2022). User Trust in Artificial Intelligence: A Comprehensive Conceptual Framework. Electronic Markets, 32, 2053-2077. https://doi.org/10.1007/s12525-022-00592-6

Downloads

Published

2026-07-22

How to Cite

Nurdiyanto Yusuf. (2026). Generative AI Risk Governance in Organizational Information Systems: A Conceptual Model Integrating Security, Ethics, and Digital Trust. International Journal Science and Technology, 5(2), 184–202. https://doi.org/10.56127/ijst.v5i2.2876

Citation Check

Similar Articles

<< < 1 2 3 4 5 6 7 > >> 

You may also start an advanced similarity search for this article.