Jul 2026· 2026 6th International Conference on Electrical, Computer and Energy Technologies (ICECET)· pp. 1-6· 0 citations· 31 references
Abstract
AI-assisted software development approaches, such as vibe coding, enable rapid code generation but lack the governance and reliability required for sustaining engineering in enterprise software. In these environments, traceability, security, technical debt management, and architectural integrity are critical for any software modification. This paper presents ATeam, a framework that facilitates AI-assisted software development through a structured and auditable maintenance process incorporating human oversight. The framework employs a multi-phase pipeline that enforces impact analysis and explicit approval gates. ATeam is evaluated on 24 sustaining engineering tasks spanning four IEEE maintenance categories, utilizing three distinct large language models (LLMs). A set of interdependent microservices is developed to assess the system. ATeam achieves an 82.5 end-to-end score. The results demonstrate that structured decomposition and governance reduce dependence on model scale, with smaller models remaining competitive with larger ones. This finding enables regulated industries to leverage AI-assisted development using on-premises models. Comparative evaluation against AutoGPT-style and unconstrained baselines reveals that ATeam achieves statistically significant improvements (Welch's $p<10^{-6})$ with large effect sizes. The evidence suggests that governance, rather than agentic execution alone, is the primary determinant of reliable enterprise software sustaining engineering.
Enterprise software requires specification governance to transform probabilistic AI generation into deterministic, auditable engineering, and the SGRM framework is introduced, which defines four-component specification contracts, constrains stochastic generation via deterministic validation, and integrates generation, verification, and governance into a closed-loop architecture.
Despite the strategic priority of digital transformation and Artificial Intelligence (AI), many organizational initiatives fail to achieve sustainable outcomes due to insufficient institutional readiness and fragmented governance. To address this gap, this paper introduces the Abuhaimed Digital & AI Excellence Model (ADAIEM), a comprehensive conceptual framework designed to foster institutional readiness and guide enduring transformation. The framework integrates three interdependent pillars: Institutional Foundation: Governance, strategy, organizational structure, processes, knowledge management, and talent development, Digital Enablement: Core digital systems, data infrastructure, automation, analytics, and platforms, and AI Enablement: AI governance, intelligent agents, decision-support mechanisms, and enterprise-wide adoption. Central to the framework is the ADAIEM Conditional Transformation Logic (ACTL), which utilizes capability gates to enforce progression only when prerequisite maturity levels are met. Unlike traditional static maturity models, ACTL actively facilitates continuous capability development, mitigates execution risks, and reinforces operational sustainability. Grounded in Business Engineering and organizational capability theory, ADAIEM advances the literature on digital transformation and AI governance by offering a structured, risk-mitigated pathway toward high-maturity, AI-enabled enterprise operations. Building on the concepts of Business Engineering and based on a variety of organizational and transformation theories, ADAIEM brings together governance, organizational design, knowledge management, talent development, digital capabilities and AI enablement under a single transformation architecture. The proposed framework offers a real-world action plan for sustainable AI transformation and a theoretical understanding of the phenomenon of AI transformation.
M. Abuhaimed· Journal of Intelligent Decis...· 0 citations
A codepath-aware governance framework for AI-assisted engineering in regulated codebases, with emphasis on financial services, payments, healthcare, and other domains where software changes may affect legal, operational, privacy, and audit obligations is developed.
Ashutosh Pal· International journal of com...· 0 citations
Large language models are being integrated into critical infrastructure and enterprise workflows at unprecedented scale,yet the lifecycle frameworks governing their development and operations were designed for operational efficiency rather than security analysis. As a result, security-relevant activities such as data provenance verification, artifact signing, agentic permission control, and decommissioning are often left implicit or assumed to receive due care. Governance frameworks, in turn, organise requirements around risk levels or management processes without clearly linking them to the lifecycle stages where they apply. This paper addresses both deficiencies. We propose a lifecycle model for LLM systems that supports security analysis by structuring it around security-relevant boundaries rather than workflow optimisation. The model comprises 32 stages across four core pipeline layers (Data, Model, Distribution, Application), supported by a 12-stage LLMOps pillar and a 9-category governance pillar. Thirteen stages are introduced here as separate units because they expose distinct security concerns that existing frameworks do not clearly distinguish. A governance mapping synthesising the NIST AI RMF, the EU AI Act, and ISO/IEC 42001 reveals a structural property of the current regulatory landscape: governance evidence concentrates at deployment-facing stages, where systems are visible to regulators, while the most consequential decisions, data selection, alignment strategy, and capability boundaries, are made at development-facing stages, where regulatory visibility is lowest.
Eleftherios Batzolis, George Drosatos, V. Katsouros et al.· 0 citations
Objectives: This paper addresses the persistent conflict between project velocity and regulatory compliance in enterprise software engineering within regulated markets. It aims to demonstrate that treating compliance as a late-stage validation phase leads to significant technical debt and project failure.
Methods: The study introduces the Organizational Readiness Model (ORM), a framework developed through a qualitative analysis of executive-level engineering engagements in the U.S. healthcare sector. The model categorizes readiness into three dimensions: Process, Architectural, and Human Capital.
Results: The application of the ORM was evaluated through a case study of ProScan Imaging, a large-scale teleradiology network. Implementing the ORM allowed for a 50% reduction in delivery timelines compared to historical benchmarks by integrating compliance into the initial architectural design.
Conclusions: Successful delivery in high-stakes environments requires organizations to achieve a regulated operational state before project commencement. Prioritizing maintainability, vendor independence, and observability as core safety properties ensures long-term system integrity and clinical safety.
O. Orlov· International Journal of Mod...· 0 citations