Skip to content
Review

On AI Safety and Security Technical Debt in Engineering AI-Enabled Systems

Jul 2026 · arXiv.org · Vol abs/2607.23365 · 1 citation
Computer Science

TL;DR

AITD-MAP is introduced, an integrated framework that connects the AITD taxonomy, quality and risk impacts, and mitigation strategies into a unified structure for risk-aware AI engineering, and aims to assist AI software engineers in making AI safety and security technical debts visible, understanding their root causes, and mitigating their presence.

Abstract

Artificial intelligence (AI) systems are increasingly deployed in high-stakes domains such as healthcare, autonomous driving, finance, and education. While these systems offer powerful data-driven and adaptive capabilities, their complexity, rapid evolution, and dependence on dynamic data pipelines introduce new forms of engineering liability collectively referred to as AI Technical Debts (AITDs). AITDs arise from root causes spanning data governance, model implementation, algorithm design, architectural decisions, operational processes, documentation practices, and testing adequacy. Unlike conventional technical debt, many AITDs are latent and propagate across tightly coupled AI pipelines, leading to maintenance challenges, reliability degradation, and heightened safety or security risks. Guided by the principles of AI Trust, Risk, and Security Management (AI TRiSM), this study reinterprets technical debt through the interconnected dimensions of trustworthiness, focusing on AI safety and security technical debts. We conduct a systematic review of 60 primary studies and identify 31 distinct types of AITD, which are organized into a root-cause-oriented taxonomy comprising seven classes. The analysis examines how these debts map to 18 trust-related concerns, including 6 safety hazards and 12 security vulnerabilities. To support mitigation, the review synthesizes 34 actionable guidelines (8 safety and 26 security) targeting the prevention, detection, and reduction of AITDs across the AI lifecycle. Building on these findings, we introduce AITD-MAP, an integrated framework that connects the AITD taxonomy, quality and risk impacts, and mitigation strategies into a unified structure for risk-aware AI engineering. The framework aims to assist AI software engineers in making AI safety and security technical debts visible, understanding their root causes, and mitigating their presence.

View source

Similar papers

Sep 2026

Governing data risks in the age of AI

This paper proposes a practical, audit-ready approach to governing data risks in the AI era, and introduces the concept of critical data elements (CDEs): data elements whose inaccuracy, unavailability, or misuse can produce material regulatory, financial, or customer-facing impact.

Xin-Fa Tu · 0 citations
#explainable ai Open access Sep 2026

Enterprise AI Architecture Governance and Risk Framework

A comprehensive governance framework built upon SAP Enterprise Architecture Framework is proposed that enables organizations to build secure, scalable, transparent, explainable, compliant, resilient, and trustworthy AI ecosystems that accelerate innovation while minimizing enterprise risk and supporting long-term digit...

Sanjeeve Kumar Gajadi · 0 citations
Preprint Aug 2026

Insurance as AI Risk Infrastructure: A Generative-Agent Simulation of AI Adoption

The rapid evolution of artificial intelligence (AI) tools has demonstrated immense potential to enhance societal well-being and operational efficiency. However, the inherent unreliability and uncertain operational consequences of modern AI systems, typified by large language models (LLMs), have created a significant ba...

Yi-Xuan Yuan, Dedai Wei, Chudong Qian et al. · 0 citations
Review Open access Aug 2026

AI-Assisted Test Execution as an Augmentation Layer in Enterprise Quality Engineering

The Probabilistic Augmentation and Governance Model (PAGM), a three-tier framework that formally allocates responsibility between AI agents and human testers across autonomous execution, confidence-gated escalation, and human-led verification, provides a governance-ready foundation for organizations seeking to deploy A...

Rejenish Kiran · 0 citations
Open access Aug 2026

AI-Augmented DevSecOps for Protecting U.S. Enterprise Software Supply Chains and Critical Digital Services

Modern enterprise applications rely on extensive third-party code, automated build systems, cloud-native infrastructure and rapidly changing vulnerability intelligence. Security controls are then spread out across the development, the software supply-chain assurance and production operations making it hard to relate so...

Mir Fawad, Mir Jawad Yaqoob, Khawar Muhammad Saad · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.