<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.0 20120330//EN" "http://jats.nlm.nih.gov/publishing/1.0/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" article-type="research-article" xml:lang="en">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">IR</journal-id>
<journal-title-group>
<journal-title>Information Research</journal-title>
</journal-title-group>
<issn pub-type="epub">1368-1613</issn>
<publisher>
<publisher-name>University of Bor&#x00E5;s</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">ir31262219</article-id>
<article-id pub-id-type="doi">10.47989/ir31262219</article-id>
<article-categories>
<subj-group xml:lang="en">
<subject>Research article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Artificial intelligence in information security: impact on organisational decision-making</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author"><name><surname>Silva</surname><given-names>Sergio</given-names></name><xref ref-type="aff" rid="aff1"/></contrib>
<aff id="aff1"><bold>Sergio Silva</bold>, works in the Department of Communication Sciences and Information Technologies, at the University of Maia, 4475-690 Maia, Portugal. They can be contacted at <email xlink:href="D012196@umaia.pt">D012196@umaia.pt</email></aff>
</contrib-group>
<pub-date pub-type="epub"><day>25</day><month>05</month><year>2026</year></pub-date>
<pub-date pub-type="collection"><year>2026</year></pub-date>
<volume>31</volume>
<issue>2</issue>
<fpage>391</fpage>
<lpage>404</lpage>
<permissions>
<copyright-year>2026</copyright-year>
<copyright-holder>&#x00A9; 2026 The Author(s).</copyright-holder>
<license license-type="open-access" xlink:href="http://creativecommons.org/licenses/by-nc/4.0/">
<license-p>This is an Open Access article distributed under the terms of the Creative Commons Attribution-NonCommercial 4.0 International License (<ext-link ext-link-type="uri" xlink:href="http://creativecommons.org/licenses/by-nc/4.0/">http://creativecommons.org/licenses/by-nc/4.0/</ext-link>), permitting all non-commercial use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<abstract xml:lang="en">
<title>Abstract</title>
<p><bold>Introduction.</bold> This study investigates the impact of Artificial Intelligence (AI) on information security and organisational decision-making processes. In the face of the growth of cyber threats and the complexity of digital ecosystems, AI emerges as a resource to strengthen the resilience and effectiveness of defence mechanisms.</p>
<p><bold>Method.</bold> Integrative literature review (Scopus, IEEE Xplore, ScienceDirect and SpringerLink) were complemented by technical reports and case studies on the application of AI in Cybersecurity.</p>
<p><bold>Analysis.</bold> It focused on three dimensions: operational efficiency, strategic decision support, and human and ethical factors. Benefits, limitations, algorithmic risks, and adoption challenges were examined.</p>
<p><bold>Results.</bold> AI improves anomaly detection, reduces response time, decreases false positives, and supports risk-based strategic decisions. However, challenges, , such as explainability, trust, accountability, and governance, remain.</p>
<p><bold>Discussion.</bold> AI reconfigures decision-making architecture, requiring symbiotic integration between technology, human oversight, and ethical policies.</p>
<p><bold>Conclusion.</bold> AI strengthens information security and improves organisational decision-making. However, the optimization of its impact is conditional on the implementation of ethical governance, transparency, and continuous training.</p>
</abstract>
</article-meta>
</front>
<body>
<sec id="sec1">
<title>Introduction</title>
<p>The accelerating digital transformation of organisations has expanded the cyber threat landscape, increasing exposure to sophisticated and fast-evolving attacks. Traditional rule-based security mechanisms struggle to cope with the volume and complexity of modern threats, prompting organisations to adopt Artificial Intelligence (AI) techniques for threat detection, prevention, and response (<xref ref-type="bibr" rid="R3">Batool et al., 2025</xref>; <xref ref-type="bibr" rid="R26">Sarker, 2024</xref>). Machine learning and data-driven approaches enable the automated analysis of large-scale data streams and the identification of anomalous behaviour in near real time.</p>
<p>While existing research has extensively documented the technical benefits of AI in cybersecurity, its influence extends beyond operational performance. AI-based systems increasingly shape how security information is filtered, interpreted, and acted upon, thereby influencing organisational decision-making. From alert prioritization to automated response recommendations, AI becomes an active participant in decision processes, aligning with Human-in-the-Loop (HITL) and bounded rationality perspectives (<xref ref-type="bibr" rid="R10">Khan, 2025</xref>; <xref ref-type="bibr" rid="R13">Sushant Kumar et al., 2024</xref>).</p>
<p>Despite this potential, organisations face persistent challenges when integrating AI into security decision-making. Limited explainability, concerns about algorithmic bias, and insufficient governance structures can undermine trust and restrict effective use (<xref ref-type="bibr" rid="R20">M&#x00F6;kander et al., 2021</xref>). Much of the existing literature remains focused on technical performance, leaving a gap in understanding how AI reshapes organisational decision architectures and governance practices.</p>
<p>This study makes two interrelated contributions. First, it provides an integrative synthesis of recent literature on AI in information security, structuring fragmented research across operational, strategic, and human-ethical dimensions. Second, building upon this synthesis, it develops a conceptual framework for the ethical integration of AI into cybersecurity decisionmaking. The framework translates dispersed findings into a socio-technical model that connects technical efficiency, decision processes, and governance responsibilities.</p>
</sec>
<sec id="sec2">
<title>Literature review</title>
<p>The application of AI in information security has gained prominence in contemporary literature, driven by the exponential growth of cyber threats, the increasing complexity of digital ecosystems, and the need for faster and more informed organisational decisions. Recent research shows that machine learning (ML) and deep learning (DL) techniques reshape not only threat detection systems, but also strategic decision-making processes in organisational environments (<xref ref-type="bibr" rid="R19">Mohamed, 2023</xref>; <xref ref-type="bibr" rid="R30">Ugochukwu Ikechukwu Okoli et al., 2024</xref>). Thus, AI is no longer seen only as a technical mechanism for operational support but takes on a broader role in building organisational resilience, risk governance, and defining strategic priorities. This review is structured in three axes: (i) AI-based threat detection, (ii) decision support and risk management, and (iii) trust, explainability, and human factors in decision-making.</p>
<sec id="sec2_1">
<title>AI-based threat detection</title>
<p>The literature presents a robust consensus on the increasing effectiveness of ML models in intrusion detection, malware analysis, and network traffic monitoring. Approaches based on convolutional neural networks (CNNs) and recurrent networks (RNNs) have demonstrated high accuracy in identifying anomalous patterns and suspicious behaviour, allowing near-real-time responses, and reducing exposure to complex attacks (<xref ref-type="bibr" rid="R3">Batool et al., 2025</xref>). At the same time, unsupervised learning and reinforcement learning techniques have been investigated to identify zero-day attacks, mitigating the dependence on static signatures and increasing the adaptability of systems in the face of volatile environments (<xref ref-type="bibr" rid="R34">Zoppi et al., 2021</xref>).</p>
<p>A recent evolution refers to the incorporation of AI in zero trust architectures, in which continuous validation and adaptive segmentation are reinforced by intelligent algorithms, expanding the ability to detect suspicious behaviour that escapes traditional mechanisms (<xref ref-type="bibr" rid="R17">Li et al., 2025</xref>). In addition, frameworks based on intelligent agents have been proposed for Security Operations Centres (SOCs), allowing automated prioritization of alerts and human decision support, reducing operational overhead, and balancing algorithmic autonomy with human oversight (<xref ref-type="bibr" rid="R7">Ismail et al., 2025</xref>; <xref ref-type="bibr" rid="R28">Srinivas et al., 2025</xref>).</p>
<p>Despite the advances, the literature identifies significant limitations. Reliance on large volumes of labelled data, which is essential for training trusted models, remains one of the biggest challenges, especially in environments where data privacy is critical (<xref ref-type="bibr" rid="R18">Liang et al., 2022</xref>). Another obstacle lies in the interpretability of complex models: deep networks behave like opaque systems, making it difficult to audit and justify automated decisions (<xref ref-type="bibr" rid="R22">Mulita, 2025</xref>; <xref ref-type="bibr" rid="R29">Tyagi et al., 2025</xref>). In response to these limitations, hybrid proposals emerge that combine AI with traditional threat intelligence, creating systems that are more robust, contextualised, and capable of operating in scenarios of uncertainty (<xref ref-type="bibr" rid="R26">Sarker, 2024</xref>; <xref ref-type="bibr" rid="R27">Spyros et al., 2025</xref>).</p>
</sec>
<sec id="sec2_2">
<title>Decision support and risk management</title>
<p>Contemporary literature indicates a progressive transition of AI from a predominantly reactive role to a predictive and strategic role in risk management (<xref ref-type="bibr" rid="R16">Li et al., 2024</xref>). AI-based decision support systems can analyse massive streams of data in real-time, correlate dispersed events, and prioritize vulnerabilities based on impact on critical assets. Technologies, such as Security Orchestration, Automation and Response (SOAR) integrate advanced algorithms that automate responses and consolidate alerts, significantly reducing incident response time and improving the allocation of human and technological resources (<xref ref-type="bibr" rid="R7">Ismail et al., 2025</xref>). In a complementary way, User and Entity Behaviour Analytics (UEBA) solutions use machine learning to build behavioural profiles and detect deviations that may signal internal or external threats, reinforcing the ability of organisations to anticipate and mitigate risks (<xref ref-type="bibr" rid="R6">Gupta et al., 2024</xref>).</p>
<p>The literature also emphasises that the strategic potential of AI depends on organisational factors, including digital maturity, governance infrastructure, and alignment between technology and internal processes. Other studies demonstrate that effective adoption of AI is intrinsically linked to the ability of organisations to integrate new systems into their decision architecture, adjusting policies, workflows, and compliance practices (<xref ref-type="bibr" rid="R1">Aakula &#x0026; Saini, 2024</xref>). At the same time, several authors warn of the risk of over-reliance on automatisms, especially in contexts of high institutional sensitivity, where automated decisions can generate ethical, legal, or reputational implications (<xref ref-type="bibr" rid="R20">M&#x00F6;kander et al., 2021</xref>). In this sense, AI should be understood as a support for human intelligence, and not as a substitute, preserving the critical role of decision-makers in the interpretation, validation, and contextualization of algorithmic recommendations (<xref ref-type="bibr" rid="R25">Rodgers et al., 2023</xref>).</p>
<p>The literature indicates that AI integration affects cybersecurity decision processes through several interrelated functional mechanisms. First, intelligent automation of alerts and incident handling reduces cognitive load in operational decision-making environments, enabling security analysts to focus on higher-level analytical and strategic tasks rather than routine triage (<xref ref-type="bibr" rid="R3">Batool et al., 2025</xref>; <xref ref-type="bibr" rid="R7">Ismail et al., 2025</xref>; <xref ref-type="bibr" rid="R28">Srinivas et al., 2025</xref>). Second, AI-driven predictive analytics support risk-based prioritization, by structuring the evaluation of threats and vulnerabilities, which improves the allocation of security resources and strengthens mitigation planning (<xref ref-type="bibr" rid="R16">Li et al., 2024</xref>; <xref ref-type="bibr" rid="R6">Gupta et al., 2024</xref>). Third, anomaly detection models based on machine learning and deep learning enhance early identification of abnormal system behaviours, shortening response cycles and reducing exposure to rapidly evolving threats (<xref ref-type="bibr" rid="R12">Kumar &#x0026; Gutierrez, 2025</xref>; <xref ref-type="bibr" rid="R23">Muneer et al., 2024</xref>; <xref ref-type="bibr" rid="R34">Zoppi et al., 2021</xref>). In addition, behavioural profiling approaches, such as User and Entity Behaviour Analytics (UEBA) enable context-sensitive interpretation of user actions, reinforcing insider threat detection and adaptive monitoring capabilities (<xref ref-type="bibr" rid="R6">Gupta et al., 2024</xref>; <xref ref-type="bibr" rid="R27">Spyros et al., 2025</xref>). Finally, AI-supported recommendation systems in Security Operations Centres introduce machine-generated options into decision workflows, shifting cybersecurity management from reactive response toward a more anticipatory and preventive posture (<xref ref-type="bibr" rid="R7">Ismail et al., 2025</xref>; <xref ref-type="bibr" rid="R28">Srinivas et al., 2025</xref>). These functional effects illustrate how AI reshapes not only technical operations but also the structure and tempo of organisational security decision-making.</p>
<p>Studies also show that the impact of AI on strategic decision-making depends on organisational maturity, robust governance, and integration with existing practices (Neiroukh et al., 2024).</p>
</sec>
<sec id="sec2_3">
<title>Theoretical frameworks for human-AI decision-making</title>
<p>To analytically anchor the discussion on the interaction between AI and organisational decisionmaking, it is useful to resort to established theoretical frameworks. Two are particularly relevant: the Human-in-the-Loop (HITL) model and the theories of organisational decision making.</p>
<p>The Human-in-the-Loop paradigm, applied to cybersecurity, postulates that the most effective systems are those that combine the speed and processing power of AI with contextual judgment, creativity, and the ethical responsibility of human beings (<xref ref-type="bibr" rid="R13">Sushant Kumar et al., 2024</xref>). This model does not see automation as a replacement, but as a symbiosis. AI acts as a cognitive amplifier, filtering out noise, identifying patterns, and suggesting actions, while the human analyst provides the domain <italic>expertise</italic>, understands organisational nuances, and takes ultimate accountability for the decision. This theoretical perspective helps explain why technical AI solutions, even the most precise ones, fail when they are not designed for smooth integration with existing human workflows and capabilities. In addition, organisational decision-making theories offer a lens to understand how AI challenges and transforms decision-making processes (<xref ref-type="bibr" rid="R9">Kaggwa et al., 2023</xref>). The classic rational model, which assumes complete information and a single objective of maximization, is insufficient to characterize cybersecurity environments, marked by uncertainty and multiple, sometimes conflicting objectives (<xref ref-type="bibr" rid="R4">Bokhari et al., 2022</xref>). AI aligns more closely with the model of Herbert Simon of bounded rationality, where decision-makers <italic>satisfy</italic> rather than optimize. Algorithms can expand these limits by processing more variables than a human could, thus providing a richer informational basis for more effective <italic>satisfaction</italic> (<xref ref-type="bibr" rid="R10">Khan, 2025</xref>). However, AI can also be framed in intuitive models, where <italic>machine learning</italic> systems identify subtle patterns and provide <italic>sensitivities</italic> or <italic>alerts</italic> that are not easily justifiable by linear logic, resembling an algorithmic intuition that must nevertheless be validated by human experience (<xref ref-type="bibr" rid="R32">Vouros, 2023</xref>).</p>
</sec>
<sec id="sec2_4">
<title>Trust, explainability and human factors</title>
<p>Explainability emerges as one of the central themes in modern literature. Opaque models hinder transparency, auditing, and validation of results, compromising the confidence of analysts and managers (<xref ref-type="bibr" rid="R2">Arunraju Chinnaraju, 2025</xref>). Studies show that the acceptance of intelligent systems depends on the ability of users to understand algorithmic operation, interpret automated decisions, and reconcile technology with existing organisational practices (<xref ref-type="bibr" rid="R31">Vorm &#x0026; Combs, 2022</xref>). The perception of autonomy, the clarity of the results presented, and the adequacy of the interfaces play decisive roles in the adoption of AI (<xref ref-type="bibr" rid="R8">Jocelyn Chew &#x0026; Achananuparp, 2022</xref>).</p>
<p>Ethical and social issues also emerge as crucial elements. The literature highlights concern regarding algorithmic bias, personal data management, and automated decision accountabilities (<xref ref-type="bibr" rid="R11">Kordzadeh et al., 2022</xref>). Algorithmic bias poses a tangible threat to the fairness and effectiveness of safety decisions. For example, an insider threat detection system trained predominantly on user behaviour data from a specific technical department (e.g., IT) can learn to associate <italic>normalcy</italic> with nightly work patterns and access to administrative tools. When applied to the entire organisation, this model could generate false positives for employees in finance or marketing departments whose legitimate work patterns diverge from this learned <italic>normal</italic>, leading to unfair investigations, degradation of the work environment, and potential talent loss (<xref ref-type="bibr" rid="R21">Mubeen, 2024</xref>). This example illustrates how a biased training dataset can not only reduce technical accuracy but also incur ethical and management risks.</p>
<p>Over time and as organisations integrate AI into critical processes, it becomes imperative to establish robust governance policies, ongoing audit mechanisms, and regular training programs. Recent research suggests that the combination of AI-based decision models and human oversight increases organisational resilience, reduces systemic risks, and promotes greater reliability in decision-making (<xref ref-type="bibr" rid="R33">Zeriouh &#x0026; Amara, 2025</xref>).</p>
<p><xref ref-type="table" rid="T1">Table 1</xref> systematises the critical factors identified in the literature, detailing their specific impact and proposing concrete risk mitigation strategies. This analytical structure allows visualisation of not only the challenges, such as the opacity of the models (<italic>black box</italic>) or the risks of algorithmic bias, but also the practical ways to overcome them, namely through the implementation of Explainable AI (XAI) or periodic audits. By organising these elements in a relational way, the table acts as a strategic guide to support the design, implementation, and governance of AI systems that are not only efficient, but also transparent, fair, and, therefore, trustworthy.</p>
<table-wrap id="T1">
<label>Table 1.</label>
<caption><p>Governance and trust risk-mitigation matrix for AI in cybersecurity decision-making. Source: authors&#x2019; elaboration.</p></caption>
<table>
<thead>
<tr>
<th align="center" valign="top">Factor</th>
<th align="center" valign="top">Impact</th>
<th align="center" valign="top">Mitigation strategy</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" valign="top">Explainability</td>
<td align="center" valign="top">Acceptance and auditing</td>
<td align="center" valign="top">Using XAI, clear dashboards</td>
</tr>
<tr>
<td align="left" valign="top">Autonomy</td>
<td align="center" valign="top">User engagement</td>
<td align="center" valign="top">Training and participation in decisions</td>
</tr>
<tr>
<td align="left" valign="top">Algorithmic bias</td>
<td align="center" valign="top">Unfair decisions</td>
<td align="center" valign="top">Periodic audit of datasets</td>
</tr>
<tr>
<td align="left" valign="top">Data privacy</td>
<td align="center" valign="top">Compliance and ethics</td>
<td align="center" valign="top">Anonymization and encryption</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>This table focuses specifically on governance, trust, and accountability mechanisms required to manage AI-related risks.</p>
</sec>
<sec id="sec2_5">
<title>Literature synthesis</title>
<p>In summary, recent scientific production converges on the idea that AI is a transformative element in information security, providing substantial gains in accuracy, automation, and predictive capacity. The theoretical frameworks of HITL and organisational decision-making provide the conceptual lens to understand that its success is intrinsically linked to a symbiotic integration with the human element (<xref ref-type="bibr" rid="R13">Sushant Kumar et al., 2024</xref>). However, the same systems that increase efficiency introduce new challenges related to transparency, trust, governance, and accountability, where algorithmic bias stands out as a practical and ethical threat. The impact of AI on organisational decision-making is therefore conditioned by factors, such as digital maturity, organisational culture, ongoing human oversight, and ethical framework (<xref ref-type="bibr" rid="R1">Aakula &#x0026; Saini, 2024</xref>). Despite this convergence on the benefits and challenges, the literature lacks studies that integrate these three dimensions, technical, decision-making, and human, in a single conceptual model, capable of guiding practical implementation in organisations. The present study aims to contribute to fill this gap, by proposing an <italic>integrated framework</italic> that will be detailed in subsequent sections. These gaps motivate the methodological approach described in the following section.</p>
<p><xref ref-type="fig" rid="F1">Figure 1</xref> presents a conceptual model that illustrates the multidimensional impact of AI on information security and organisational decision-making. This model integrates the three central axes discussed throughout the review, AI-based threat detection, decision support and risk management, and human and trust factors, demonstrating their dynamic interdependence. The figure illustrates the interdependence between operational AI capabilities, decision-support functions, and human&#x2013;governance factors. Rather than operating independently, these components form a feedback system in which technical outputs influence decision processes, which are in turn shaped by trust, oversight, and policy constraints. This visualisation emphasises that cybersecurity effectiveness emerges from alignment among these dimensions rather than from algorithmic performance alone. The gaps and the socio-technical complexity identified in the literature motivate the integrative methodological approach and are presented in the next section.</p>
<fig id="F1">
<label>Figure 1.</label>
<caption><p>Conceptual model illustrating the impact of AI on information security and organisational decision-making. Source: authors&#x2019; elaboration.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="c19-fig1.jpg"><alt-text>none</alt-text></graphic>
</fig>
</sec>
</sec>
<sec id="sec3">
<title>Method</title>
<sec id="sec3_1">
<title>Type of review</title>
<p>This study adopts an integrative literature review methodology. It was selected because the research problem spans technical, organisational, and ethical domains. Unlike systematic reviews focused on homogeneous empirical designs, integrative reviews enable the synthesis of conceptual, technical, and empirical studies, making them particularly suitable for examining socio-technical phenomena, such as AI-enabled cybersecurity decision-making. This approach allows the combination of performance-oriented research with governance and human-factor perspectives that would otherwise remain analytically disconnected.</p>
</sec>
<sec id="sec3_2">
<title>Data sources and search strategy</title>
<p>The literature search was conducted across Scopus, IEEE Xplore, ScienceDirect, and SpringerLink. Searches used combinations of the keywords &#x201C;artificial intelligence,&#x201D; &#x201C;cybersecurity,&#x201D; &#x201C;information security,&#x201D; and &#x201C;decision-making.&#x201D; The review focused on studies published between 2021 and 2025 to capture recent developments in AI-enabled security.</p>
</sec>
<sec id="sec3_3">
<title>Inclusion and exclusion criteria</title>
<p>Inclusion criteria:</p>
<list list-type="bullet">
<list-item><p>Peer-reviewed journal articles and authoritative technical reports</p></list-item>
<list-item><p>Published between 2021 and 2025</p></list-item>
<list-item><p>Focus on AI applications in information security</p></list-item>
<list-item><p>Explicit discussion of organisational decision-making, governance, or human factors</p></list-item>
</list>
<p>Exclusion criteria:</p>
<list list-type="bullet">
<list-item><p>Publications prior to 2021</p></list-item>
<list-item><p>Purely technical studies without organisational implications</p></list-item>
<list-item><p>Non-peer-reviewed opinion or commentary articles</p></list-item>
</list>
<p><xref ref-type="fig" rid="F2">Figure 2</xref> summarizes the literature identification and selection process.</p>
<fig id="F2">
<label>Figure 2.</label>
<caption><p>Literature identification and selection process for the integrative review. Source: authors&#x2019; elaboration.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="c19-fig2.jpg"><alt-text>none</alt-text></graphic>
</fig>
<p>This figure demonstrates the progressive narrowing of the literature corpus, ensuring that the final sample reflects studies aligned with both technical and organisational dimensions of AI-enabled cybersecurity. The results of the analytical process are presented in the next section.</p>
</sec>
</sec>
<sec id="sec4">
<title>Analysis</title>
<p>This section synthesises evidence from the reviewed literature, describing the main patterns identified across studies without extending into theoretical or normative interpretation.</p>
<p>Selected studies were analysed using thematic coding. Initial codes were grouped into higher-level themes, resulting in three analytical dimensions: operational efficiency, decision support, and human and ethical factors. Given the heterogeneity of study designs, no formal quality scoring was applied; this limitation is acknowledged in Limitations and future research section.</p>
<sec id="sec4_1">
<title>Operational efficiency</title>
<p>The results show that solutions based on <italic>machine learning</italic> and <italic>deep learning</italic> substantially improve the ability to detect threats and anomalies in corporate networks. Some empirical studies report reductions in response time of up to 40%; however, these findings are context-dependent and derived from heterogeneous operational environments. In addition, the use of supervised algorithms, such as <italic>Random Forest</italic> and <italic>Support Vector Machines</italic>, has been shown to be effective in analysing traffic and preventing intrusions (<xref ref-type="bibr" rid="R12">Kumar &#x0026; Gutierrez, 2025</xref>; <xref ref-type="bibr" rid="R23">Muneer et al., 2024</xref>).</p>
<p><xref ref-type="fig" rid="F3">Figure 3</xref> presents an analysis of the percentage distribution of the main application areas, based on the literature published between 2021 and 2025. This visualisation enables identification of dominant research priorities of the sector and the scientific community, revealing which areas have attracted the most attention and intellectual investment. The same figure also serves as a dynamic snapshot of the state of the art, offering an essential macro perspective to guide future technological developments and R&#x0026;D resource allocation decisions.</p>
<fig id="F3">
<label>Figure 3.</label>
<caption><p>Principal areas of application of AI in Cybersecurity (2021-2025). Source: authors&#x2019; elaboration.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="c19-fig3.jpg"><alt-text>none</alt-text></graphic>
</fig>
<p>The predominance observed in the domain of intrusion detection (34%), followed by malware and traffic analysis (22%) and risk management (18%), confirms the focus of the scientific community on operational applications that aim to increase the accuracy and efficiency of cyber defence mechanisms.</p>
</sec>
<sec id="sec4_2">
<title>Decision support and strategic management</title>
<p>The second dimension is related to the role of AI in decision support and initiative-taking risk management. Tools, such as SOAR and UEBA, are being widely used to correlate alerts and prioritize vulnerabilities (<xref ref-type="bibr" rid="R6">Gupta et al., 2024</xref>; <xref ref-type="bibr" rid="R7">Ismail et al., 2025</xref>).</p>
<p>The automation of these processes has allowed security managers to shift the focus from reactive response to a preventive and strategic posture. However, some studies warn that blind trust in algorithmic recommendations can lead to biased or non-transparent decisions if the models are not auditable (<xref ref-type="bibr" rid="R15">Landers &#x0026; Behrend, 2022</xref>).</p>
<p>Automated incident management tools, such as SOAR and UEBA, are demonstrating a measurable impact on prioritizing alerts and reducing false positives (<xref ref-type="bibr" rid="R5">ENISA, 2023</xref>). Reported improvements (30&#x2013;40%) reflect specific case settings and should not be interpreted as generalisable performance benchmarks (<xref ref-type="bibr" rid="R3">Batool et al., 2025</xref>).</p>
</sec>
<sec id="sec4_3">
<title>Human and ethical dimensions</title>
<p>The third dimension highlights the role of human factors, trust, and explainability. The acceptance of AI systems by security professionals relies heavily on the ability to understand the reasons behind system decisions (<xref ref-type="bibr" rid="R31">Vorm &#x0026; Combs, 2022</xref>). The literature emphasises the need for <italic>XAI</italic> to ensure that decision-makers maintain control and confidence over recommended actions (<xref ref-type="bibr" rid="R2">Arunraju Chinnaraju, 2025</xref>).</p>
<p>From an ethical point of view, the collection and processing of sensitive data to train AI models raises privacy concerns and algorithmic bias. The absence of transparency can compromise organisational accountability and generate significant reputational risks (<xref ref-type="bibr" rid="R20">M&#x00F6;kander et al., 2021</xref>). The analysis reveals that human and ethical factors are not a separate barrier, but rather the <italic>ground</italic> on which efficiency and decision support are built. As illustrated in <xref ref-type="table" rid="T1">Table 1</xref>, the mitigation strategy for explainability is the use of XAI. However, the technical implementation of XAI runs into a <italic>trade-off</italic> between precision and explainability: the most complex and accurate models, such as <italic>deep learning</italic>, are often the opaquest, while the most interpretable models, such as decision trees, can underperform. Thus, the choice of an AI model becomes a strategic decision that weighs the marginal gain in accuracy against the loss of transparency and the consequent erosion of team trust.</p>
</sec>
<sec id="sec4_4">
<title>Synthesis of findings</title>
<p>In an integrated way, the analysis confirms that AI plays a decisive role in the modernisation of organisational cybersecurity. Its effectiveness, however, depends on the balanced combination of technology and human oversight. The results indicate that success does not lie in unilaterally maximising one of the dimensions (e.g., efficiency), but in actively managing the inherent tensions between them. The organisations that gain the most operational resilience are those that recognise these <italic>trade-offs</italic> and integrate <italic>AI-driven cybersecurity</italic> with ethical governance, algorithmic auditing, and ongoing training, thus giving rise to a decision-making ecosystem, where the speed of AI is tempered by human judgment, its autonomy is counterbalanced by human control, and its complexity is made useful through explainability.</p>
<p>Beyond identifying thematic categories, the analysis revealed that most studies emphasise operational performance, while governance and human oversight dimensions remain comparatively underrepresented. This imbalance suggests that the technical maturity of AI applications is advancing faster than organisational and ethical integration frameworks, reinforcing the need for interdisciplinary approaches.</p>
</sec>
</sec>
<sec id="sec5">
<title>Results</title>
<p>The thematic coding of the reviewed studies revealed three interdependent dimensions that structure the impact of AI on cybersecurity decision-making.</p>
<sec id="sec5_1">
<title>Operational efficiency</title>
<p>The reviewed literature consistently reports that AI improves intrusion detection accuracy, reduces false positives, and accelerates incident response. Machine learning and deep learning models enable faster identification of anomalous patterns, contributing to measurable efficiency gains (<xref ref-type="bibr" rid="R12">Kumar &#x0026; Gutierrez, 2025</xref>).</p>
<p>Quantitative performance improvements reported in the literature vary substantially across contexts, datasets, and implementation conditions, and, therefore, indicate potential rather than standardized outcomes.</p>
</sec>
<sec id="sec5_2">
<title>Strategic decision support</title>
<p>AI-based tools, such as Security Orchestration, Automation and Response (SOAR) and User and Entity Behaviour Analytics (UEBA) support decision-making by correlating alerts and prioritizing risks. These systems enable a shift from reactive responses to predictive and risk-based security strategies.</p>
</sec>
<sec id="sec5_3">
<title>Human and ethical factors</title>
<p>Trust and explainability emerge as critical factors for AI adoption. Blackbox models hinder accountability and user confidence, whereas explainable AI (XAI) techniques improve transparency and acceptance (<xref ref-type="bibr" rid="R2">Arunraju Chinnaraju, 2025</xref>). Ethical concerns include data privacy, algorithmic bias, and responsibility for automated decisions.</p>
</sec>
<sec id="sec5_4">
<title>Framework for ethical AI integration</title>
<p>The proposed framework constitutes the conceptual outcome of the integrative synthesis, translating empirical and theoretical findings into an applied socio-technical model. Based on the synthesis, this study proposes a framework comprising three interdependent pillars: (1) technical efficiency, (2) trust and explainability, and (3) governance and accountability. At the centre lies contextualised human judgment, supported by continuous feedback between operational outcomes and governance mechanisms. <xref ref-type="fig" rid="F4">Figure 4</xref> shows a conceptual <italic>framework</italic> for this. The framework operationalises the study&#x2019;s integrative contribution by translating literature synthesis into an implementable decision-governance structure. The findings are interpreted and contextualised in the Discussion section.</p>
<fig id="F4">
<label>Figure 4.</label>
<caption><p>Framework for the ethical integration of AI in cybersecurity decision-making. Source: authors&#x2019; elaboration.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="c19-fig4.jpg"><alt-text>none</alt-text></graphic>
</fig>
</sec>
</sec>
<sec id="sec6">
<title>Discussion</title>
<p>This section interprets the synthesised findings considering organisational decision-making theory, highlighting conceptual implications, trade-offs, and governance challenges. The findings indicate that AI adoption in cybersecurity is not merely a technological transition, but a transformation of decision authority structures. Organisations must, therefore, redesign accountability chains, audit practices, and human oversight mechanisms alongside technical deployment. The discussion highlights that effectiveness depends less on algorithmic sophistication alone and more on alignment between AI systems, decision processes, and governance structures.</p>
<p>A second fundamental trade-off arises here between <italic>autonomy</italic> and <italic>control</italic>. Intelligent automation frees up human resources for strategic tasks, but excessive delegation of authority to systems can have unintended consequences. For example, automating incident responses can contain a threat quickly, but it can also lead to <italic>alert fatigue,</italic> if false positives are not minimised. It can lead to inappropriate automated responses that disrupt legitimate services, causing operational and reputational damage. The ideal balance is not full automation, but rather supervised autonomy, where AI proposes actions, but the execution of high-impact measures requires human validation.</p>
<p>From a theoretical perspective, cybersecurity decision-making can be understood as an extended, bounded rationality process, in which AI expands informational capacity while humans retain interpretive and ethical responsibility. This perspective aligns with HITL principles and emphasises augmentation rather than replacement of human judgment.</p>
</sec>
<sec id="sec7">
<title>Limitations and future research</title>
<p>This review is limited by reliance on published literature, which may underrepresent failed implementations or emerging practices. No formal quality assessment was conducted due to the heterogeneity of study designs. Quantitative findings synthesised from diverse contexts should, therefore, be interpreted cautiously. Future research should employ empirical case studies and longitudinal analyses to validate and refine the proposed framework.</p>
<p>Furthermore, the reliance on published studies may introduce publication bias, as unsuccessful or incomplete AI implementations are less likely to be documented. The rapid evolution of AI technologies means that some findings may become outdated as governance practices mature.</p>
</sec>
<sec id="sec8">
<title>Conclusion</title>
<p>AI significantly enhances information security capabilities and supports organisational decisionmaking. However, its value depends on transparent, human-centred, and ethically governed integration. AI should be viewed as an enabler of informed judgment, rather than a substitute for human responsibility. The study underscores that sustainable AI adoption in cybersecurity requires simultaneous progress in technical performance, organisational adaptation, and ethical governance. Organisations that address only the technical dimension risk efficiency gains without institutional resilience. When responsibly implemented, AI strengthens both cyber resilience and organisational trust.</p>
</sec>
</body>
<back>
<ref-list>
<title>References</title>
<ref id="R1"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Aakula</surname><given-names>A.</given-names></name><name><surname>Saini</surname><given-names>V.</given-names></name></person-group><year>2024</year><article-title>The impact of AI on organisational change in digital transformation</article-title><source>Internet of Things and Edge Computing Journal</source><volume>4</volume><issue>1</issue><fpage>75</fpage><lpage>115</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://thesciencebrigade.com/iotecj/article/view/465">https://thesciencebrigade.com/iotecj/article/view/465</ext-link></comment></element-citation></ref>
<ref id="R2"><element-citation publication-type="journal"><person-group person-group-type="author"><collab>Arunraju Chinnaraju</collab></person-group><year>2025</year><article-title>Explainable AI (XAI) for trustworthy and transparent decisionmaking: A theoretical framework for AI interpretability</article-title><source>World Journal of Advanced Engineering Technology and Sciences</source><volume>14</volume><issue>3</issue><fpage>170</fpage><lpage>207</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.30574/wjaets.2025.14.3.0106">https://doi.org/10.30574/wjaets.2025.14.3.0106</ext-link></comment></element-citation></ref>
<ref id="R3"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Batool</surname><given-names>F.</given-names></name><name><surname>Hassnain</surname><given-names>S. I.</given-names></name></person-group><year>2025</year><source>Neural network-enhanced machine learning applications in cybersecurity for real-time detection of anomalous activities and prevention of unauthorized access in large-scale networks</source><volume>1</volume><issue>1</issue><comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.62762/TNC.2025.920886">https://doi.org/10.62762/TNC.2025.920886</ext-link></comment></element-citation></ref>
<ref id="R4"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Bokhari</surname><given-names>S.</given-names></name><name><surname>Hamrioui</surname><given-names>S.</given-names></name><name><surname>Aider</surname><given-names>M.</given-names></name></person-group><year>2022</year><article-title>Cybersecurity strategy under uncertainties for an IoE environment</article-title><source>Journal of Network and Computer Applications</source><volume>205</volume><fpage>103426</fpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1016/JJNCA.2022.103426">https://doi.org/10.1016/JJNCA.2022.103426</ext-link></comment></element-citation></ref>
<ref id="R5"><element-citation publication-type="book"><person-group person-group-type="author"><collab>ENISA</collab></person-group><year>2023</year><source>ENISA threat landscape 2023</source><publisher-name>Publications Office of the EU</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://op.europa.eu/en/publication-detail/-/publication/3bd053c2-9e1e-11ee-b164-01aa75ed71a1/language-en">https://op.europa.eu/en/publication-detail/-/publication/3bd053c2-9e1e-11ee-b164-01aa75ed71a1/language-en</ext-link></comment></element-citation></ref>
<ref id="R6"><element-citation publication-type="web"><person-group person-group-type="author"><name><surname>Gupta</surname><given-names>A.</given-names></name><name><surname>Senior</surname><given-names>D.</given-names></name><name><surname>Engineer</surname><given-names>S.</given-names></name></person-group><year>2024</year><article-title>Unveiling hidden threats with ML-powered user and entity behavior analytics (UEBA)</article-title><source>Turkish Journal of Computer and Mathematics Education 15</source><issue>1</issue><comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.61841/turcomat.v15i1.14394">https://doi.org/10.61841/turcomat.v15i1.14394</ext-link></comment></element-citation></ref>
<ref id="R7"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Ismail, Kurnia</surname><given-names>R.</given-names></name><name><surname>Brata</surname><given-names>Z. A.</given-names></name><name><surname>Nelistiani</surname><given-names>G. A.</given-names></name><name><surname>Heo</surname><given-names>S.</given-names></name><name><surname>Kim</surname><given-names>Hyeongon</given-names></name><name><surname>Kim</surname><given-names>Howon</given-names></name></person-group><year>2025</year><article-title>Toward robust security orchestration and automated response in security operations centers with a hyper-automation approach using agentic artificial intelligence</article-title><source>Information (Switzerland)</source><volume>16</volume><issue>5</issue><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.3390/info16050365">https://doi.org/10.3390/info16050365</ext-link></comment></element-citation></ref>
<ref id="R8"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Jocelyn Chew</surname><given-names>H. S.</given-names></name><name><surname>Achananuparp</surname><given-names>P.</given-names></name></person-group><year>2022</year><article-title>Perceptions and needs of artificial intelligence in health care to increase adoption: Scoping review</article-title><source>Journal of Medical Internet Research</source><volume>24</volume><issue>1</issue><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.2196/32939">https://doi.org/10.2196/32939</ext-link></comment></element-citation></ref>
<ref id="R9"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Kaggwa</surname><given-names>S.</given-names></name><name><surname>Francisa Eleogu</surname><given-names>T.</given-names></name><name><surname>Okonkwo</surname><given-names>F.</given-names></name><name><surname>Farayola</surname><given-names>O. A.</given-names></name><name><surname>Ugomma Uwaoma</surname><given-names>P.</given-names></name><name><surname>Akinoso</surname><given-names>A.</given-names></name></person-group><year>2023</year><article-title>AI in decision making: Transforming business strategies</article-title><source>International Journal of Research and Scientific Innovation (IJRSI)</source><volume>10</volume><issue>12</issue><fpage>423</fpage><lpage>444</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.51244/URSI.2023.1012032">https://doi.org/10.51244/URSI.2023.1012032</ext-link></comment></element-citation></ref>
<ref id="R10"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Khan</surname><given-names>S.</given-names></name></person-group><year>2025</year><article-title>From constraints to cognition: Integrating bounded rationality into AI design for realistic decision-making</article-title><source>The Critical Review of Social Sciences Studies</source><volume>3</volume><issue>3</issue><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.59075/n96xaa33">https://doi.org/10.59075/n96xaa33</ext-link></comment></element-citation></ref>
<ref id="R11"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Kordzadeh</surname><given-names>N.</given-names></name><name><surname>Ghasemaghaei</surname><given-names>M.</given-names></name><name><surname>Mikalef</surname><given-names>P.</given-names></name><name><surname>Popovic</surname><given-names>A.</given-names></name><name><surname>Lundstr&#x00F6;m</surname><given-names>J. E.</given-names></name><name><surname>Conboy</surname><given-names>K.</given-names></name></person-group><year>2022</year><article-title>Algorithmic bias: review, synthesis, and future research directions</article-title><source>European Journal of Information Systems</source><volume>31</volume><issue>3</issue><fpage>388</fpage><lpage>409</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1080/0960085X.2021.1927212">https://doi.org/10.1080/0960085X.2021.1927212</ext-link></comment></element-citation></ref>
<ref id="R12"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Kumar</surname><given-names>A.</given-names></name><name><surname>Gutierrez</surname><given-names>J. A.</given-names></name></person-group><year>2025</year><article-title>Impact of machine learning on intrusion detection systems for the protection of critical infrastructure</article-title><source>Information 2025</source><volume>16</volume><issue>7</issue><fpage>515</fpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.3390/INFO16070515">https://doi.org/10.3390/INFO16070515</ext-link></comment></element-citation></ref>
<ref id="R13"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Kumar</surname><given-names>Sushant</given-names></name><name><surname>Datta</surname><given-names>S.</given-names></name><name><surname>Singh</surname><given-names>V.</given-names></name><name><surname>Datta</surname><given-names>D.</given-names></name><name><surname>Kumar Singh</surname><given-names>S.</given-names></name><name><surname>&amp; Sharma</surname><given-names>R.</given-names></name></person-group><year>2024</year><article-title>Applications, challenges, and future directions of human-in-the-loop learning</article-title><source>IEEE Access</source><volume>12</volume><fpage>7573575760</fpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1109/ACCESS.2024.3401547">https://doi.org/10.1109/ACCESS.2024.3401547</ext-link></comment></element-citation></ref>
<ref id="R14"><element-citation publication-type="book"><person-group person-group-type="author"><name><surname>Kumar</surname><given-names>Santosh</given-names></name><name><surname>Sharma</surname><given-names>N. K.</given-names></name><name><surname>Sharma</surname><given-names>M.</given-names></name><name><surname>&amp; Agrawal</surname><given-names>N.</given-names></name></person-group><year>2024</year><article-title>Text extraction from images using Tesseract.</article-title><source>Deep Learning Techniques for Automation and Industrial Applications</source><fpage>1</fpage><lpage>18</lpage><publisher-name>Wiley</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1002/9781394234271.ch1">https://doi.org/10.1002/9781394234271.ch1</ext-link></comment></element-citation></ref>
<ref id="R15"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Landers</surname><given-names>R. N.</given-names></name><name><surname>Behrend</surname><given-names>T. S.</given-names></name></person-group><year>2022</year><article-title>Auditing the AI auditors: A framework for evaluating fairness and bias in high stakes AI predictive models</article-title><source>American Psychologist</source><volume>78</volume><issue>1</issue><fpage>36</fpage><lpage>49</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1037/AMP0000972">https://doi.org/10.1037/AMP0000972</ext-link></comment></element-citation></ref>
<ref id="R16"><element-citation publication-type="book"><person-group person-group-type="author"><name><surname>Li</surname><given-names>H.</given-names></name><name><surname>Yazdi</surname><given-names>M.</given-names></name><name><surname>Nedjati</surname><given-names>A.</given-names></name><name><surname>Moradi</surname><given-names>R.</given-names></name><name><surname>Adumene</surname><given-names>S.</given-names></name><name><surname>Dao</surname><given-names>U.</given-names></name><name><surname>Moradi</surname><given-names>A.</given-names></name><name><surname>Haghighi</surname><given-names>A.</given-names></name><name><surname>Obeng</surname><given-names>F. E.</given-names></name><name><surname>Huang</surname><given-names>C.-G.</given-names></name><name><surname>Kang</surname><given-names>H. S.</given-names></name><name><surname>Pirbalouti</surname><given-names>R. G.</given-names></name><name><surname>Zarei</surname><given-names>E.</given-names></name><name><surname>Dehghan</surname><given-names>M.</given-names></name><name><surname>Darvishmotevali</surname><given-names>M.</given-names></name><name><surname>Ghasemi</surname><given-names>P.</given-names></name><name><surname>Fard</surname><given-names>P. S.</given-names></name><name><surname>Garg</surname><given-names>H.</given-names></name></person-group><year>2024</year><article-title>Harnessing AI for project risk management: A paradigm shift</article-title><person-group person-group-type="editor"><name><surname>Yazdi</surname><given-names>M.</given-names></name></person-group><source>Progressive decision-making tools and applications in project and operation management: Approaches, case studies, multi-criteria decision-making, multi-objective decision-making, decision under uncertainty</source><fpage>253</fpage><lpage>272</lpage><publisher-name>Springer Nature Switzerland</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/978-3-031-51719-816">https://doi.org/10.1007/978-3-031-51719-816</ext-link></comment></element-citation></ref>
<ref id="R17"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Li</surname><given-names>K.</given-names></name><name><surname>Li</surname><given-names>C.</given-names></name><name><surname>Yuan</surname><given-names>X.</given-names></name><name><surname>Li</surname><given-names>S.</given-names></name><name><surname>Zou</surname><given-names>S.</given-names></name><name><surname>Ahmed</surname><given-names>S. S.</given-names></name><name><surname>Ni</surname><given-names>W.</given-names></name><name><surname>Niyato</surname><given-names>D.</given-names></name><name><surname>Jamalipour</surname><given-names>A.</given-names></name><name><surname>Dressler</surname><given-names>F.</given-names></name><name><surname>Akan</surname><given-names>O. B.</given-names></name></person-group><year>2025</year><article-title>Zero-trust foundation models: A new paradigm for secure and collaborative artificial intelligence for Internet of Things</article-title><source>IEEE Internet of Things Journal</source><volume>12</volume><issue>2</issue><fpage>46269</fpage><lpage>46293</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1109/JIOT.2025.3603957">https://doi.org/10.1109/JIOT.2025.3603957</ext-link></comment></element-citation></ref>
<ref id="R18"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Liang</surname><given-names>W.</given-names></name><name><surname>Tadesse</surname><given-names>G. A.</given-names></name><name><surname>Ho</surname><given-names>D.</given-names></name><name><surname>Fei-Fei</surname><given-names>L.</given-names></name><name><surname>Zaharia</surname><given-names>M.</given-names></name><name><surname>Zhang</surname><given-names>C.</given-names></name><name><surname>Zou</surname><given-names>J.</given-names></name></person-group><year>2022</year><article-title>Advances, challenges and opportunities in creating data for trustworthy AI</article-title><source>Nature Machine Intelligence</source><volume>4</volume><issue>8</issue><fpage>669</fpage><lpage>677</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1038/s42256-022-00516-1">https://doi.org/10.1038/s42256-022-00516-1</ext-link></comment></element-citation></ref>
<ref id="R19"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Mohamed</surname><given-names>M.</given-names></name></person-group><year>2023</year><article-title>Empowering deep learning based organisational decision making: A survey 2</article-title><source>Sustainable Machine Intelligence Journal</source><volume>3</volume><issue>5</issue><fpage>1</fpage><lpage>13</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.61185/SMIJ.2023.33105">https://doi.org/10.61185/SMIJ.2023.33105</ext-link></comment></element-citation></ref>
<ref id="R20"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>M&#x00F6;kander</surname><given-names>J.</given-names></name><name><surname>Morley</surname><given-names>J.</given-names></name><name><surname>Taddeo</surname><given-names>M.</given-names></name><name><surname>Floridi</surname><given-names>L.</given-names></name></person-group><year>2021</year><article-title>Ethics-based auditing of automated decision-making systems: Nature, scope, and limitations</article-title><source>Science and Engineering Ethics</source><volume>27</volume><issue>4</issue><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1007/s11948-021-00319-4">https://doi.org/10.1007/s11948-021-00319-4</ext-link></comment></element-citation></ref>
<ref id="R21"><element-citation publication-type="book"><person-group person-group-type="author"><name><surname>Mubeen</surname><given-names>M.</given-names></name></person-group><year>2024</year><source>Zero-trust architecture for cloud-based AI chat applications: Encryption, access control and continuous AI-driven verification</source><publisher-name>Master&#x2019;s thesis, Jamk University of Applied Sciences</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="http://www.theseus.fi/handle/10024/876662">http://www.theseus.fi/handle/10024/876662</ext-link></comment></element-citation></ref>
<ref id="R22"><element-citation publication-type="book"><person-group person-group-type="author"><name><surname>Mulita</surname><given-names>R.</given-names></name></person-group><year>2025</year><article-title>Challenging the cybersecurity threats through education programs</article-title><person-group person-group-type="editor"><name><surname>Dhoska</surname><given-names>K.</given-names></name><name><surname>Spaho</surname><given-names>E.</given-names></name></person-group><source>Bridging horizons in artificial intelligence, robotics, cybersecurity, smart cities, and digital economy</source><fpage>271</fpage><lpage>283</lpage><publisher-name>Springer Nature Switzerland</publisher-name></element-citation></ref>
<ref id="R23"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Muneer</surname><given-names>S.</given-names></name><name><surname>Farooq</surname><given-names>U.</given-names></name><name><surname>Athar</surname><given-names>A.</given-names></name><name><surname>Raza</surname><given-names>M. A.</given-names></name><name><surname>Ghazal</surname><given-names>T. M.</given-names></name><name><surname>Sakib</surname><given-names>S.</given-names></name></person-group><year>2024</year><article-title>A critical review of artificial intelligence based approaches in intrusion detection: A comprehensive analysis</article-title><source>Journal of Engineering</source><volume>2024</volume><issue>1</issue><fpage>3909173</fpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1155/2024/3909173">https://doi.org/10.1155/2024/3909173</ext-link></comment></element-citation></ref>
<ref id="R24"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Neiroukh</surname><given-names>S.</given-names></name><name><surname>Emeagwali</surname><given-names>O. L.</given-names></name><name><surname>Aljuhmani</surname><given-names>H. Y.</given-names></name></person-group><year>2025</year><article-title>Artificial intelligence capability and organisational performance: Unraveling the mediating mechanisms of decision-making processes</article-title><source>Management Decision</source><volume>63</volume><issue>10</issue><fpage>3501</fpage><lpage>3532</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1108/MD-10-2023-1946">https://doi.org/10.1108/MD-10-2023-1946</ext-link></comment></element-citation></ref>
<ref id="R25"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Rodgers</surname><given-names>W.</given-names></name><name><surname>Murray</surname><given-names>J. M.</given-names></name><name><surname>Stefanidis</surname><given-names>A.</given-names></name><name><surname>Degbey</surname><given-names>W. Y.</given-names></name><name><surname>Tarba</surname><given-names>S. Y.</given-names></name></person-group><year>2023</year><article-title>An artificial intelligence algorithmic approach to ethical decision-making in human resource management processes</article-title><source>Human Resource Management Review</source><volume>33</volume><issue>1</issue><fpage>100925</fpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1016/J.HRMR.2022.100925">https://doi.org/10.1016/J.HRMR.2022.100925</ext-link></comment></element-citation></ref>
<ref id="R26"><element-citation publication-type="book"><person-group person-group-type="author"><name><surname>Sarker</surname><given-names>I. H.</given-names></name></person-group><year>2024</year><article-title>Introduction to AI-driven cybersecurity and threat intelligence</article-title><person-group person-group-type="editor"><name><surname>Sarker</surname><given-names>I. H.</given-names></name></person-group><source>AI-driven cybersecurity and threat intelligence: Cyber automation, intelligent decisionmaking and explainability</source><fpage>3</fpage><lpage>19</lpage><publisher-name>Springer Nature Switzerland</publisher-name><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1007/978-3-031-54497-21">https://doi.org/10.1007/978-3-031-54497-21</ext-link></comment></element-citation></ref>
<ref id="R27"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Spyros</surname><given-names>A.</given-names></name><name><surname>Koritsas</surname><given-names>I.</given-names></name><name><surname>Papoutsis</surname><given-names>A.</given-names></name><name><surname>Panagiotou</surname><given-names>P.</given-names></name><name><surname>Chatzakou</surname><given-names>D.</given-names></name><name><surname>Kavallieros</surname><given-names>D.</given-names></name><name><surname>Tsikrika</surname><given-names>T.</given-names></name><name><surname>Vrochidis</surname><given-names>S.</given-names></name><name><surname>Kompatsiaris</surname><given-names>I.</given-names></name></person-group><year>2025</year><article-title>AI-based holistic framework for cyber threat intelligence management</article-title><source>IEEE Access</source><volume>13</volume><fpage>20820</fpage><lpage>20846</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1109/ACCESS.2025.3533084">https://doi.org/10.1109/ACCESS.2025.3533084</ext-link></comment></element-citation></ref>
<ref id="R28"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Srinivas</surname><given-names>S.</given-names></name><name><surname>Kirk</surname><given-names>B.</given-names></name><name><surname>Zendejas</surname><given-names>J.</given-names></name><name><surname>Espino</surname><given-names>M.</given-names></name><name><surname>Boskovich</surname><given-names>M.</given-names></name><name><surname>Bari</surname><given-names>A.</given-names></name><name><surname>Dajani</surname><given-names>K.</given-names></name><name><surname>Alzahrani</surname><given-names>N.</given-names></name></person-group><year>2025</year><article-title>AI-augmented SOC: A survey of LLMs and gents for security automation</article-title><source>Journal of Cybersecurity and Privacy</source><volume>5</volume><issue>4</issue><fpage>95</fpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.3390/jcp5040095">https://doi.org/10.3390/jcp5040095</ext-link></comment></element-citation></ref>
<ref id="R29"><element-citation publication-type="book"><person-group person-group-type="author"><name><surname>Tyagi</surname><given-names>Himanshu</given-names></name><name><surname>Goel</surname><given-names>P. K.</given-names></name><name><surname>Tyagi</surname><given-names>P.</given-names></name><name><surname>Tyagi</surname><given-names>Himani</given-names></name></person-group><year>2025</year><article-title>AI-driven cybersecurity in industrial automation: Navigating ethical and legal complexities</article-title><source>AI-enhanced cybersecurity for industrial automation</source><fpage>309</fpage><lpage>338</lpage><publisher-name>IGI Global</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4018/979-8-3373-3241-3.ch016">https://doi.org/10.4018/979-8-3373-3241-3.ch016</ext-link></comment></element-citation></ref>
<ref id="R30"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Ugochukwu Ikechukwu</surname><given-names>Okoli</given-names></name><name><surname>Ogugua Chimezie</surname><given-names>Obi</given-names></name><name><surname>Adebunmi Okechukwu</surname><given-names>Adewusi</given-names></name><name><surname>Temitayo Oluwaseun</surname><given-names>Abrahams</given-names></name></person-group><year>2024</year><article-title>Machine learning in cybersecurity: A review of threat detection and defense mechanisms</article-title><source>World Journal of Advanced Research and Reviews</source><volume>21</volume><issue>1</issue><fpage>2286</fpage><lpage>2295</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.30574/wjarr.2024.21.1.0315">https://doi.org/10.30574/wjarr.2024.21.1.0315</ext-link></comment></element-citation></ref>
<ref id="R31"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Vorm</surname><given-names>E. S.</given-names></name><name><surname>Combs</surname><given-names>D. J. Y.</given-names></name></person-group><year>2022</year><article-title>Integrating transparency, trust, and acceptance: The intelligent systems technology acceptance model (ISTAM)</article-title><source>International Journal of Human&#x2013;Computer Interaction</source><volume>38</volume><issue>18-20</issue><fpage>1828</fpage><lpage>1845</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1080/10447318.2022.2070107">https://doi.org/10.1080/10447318.2022.2070107</ext-link></comment></element-citation></ref>
<ref id="R32"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Vouros</surname><given-names>G. A.</given-names></name></person-group><year>2023</year><article-title>Explainable deep reinforcement learning: State of the art and challenges</article-title><source>ACM Computing Surveys</source><volume>55</volume><issue>5</issue><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1145/3527448">https://doi.org/10.1145/3527448</ext-link></comment></element-citation></ref>
<ref id="R33"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Zeriouh</surname><given-names>K.</given-names></name><name><surname>Amara</surname><given-names>M.</given-names></name></person-group><year>2025</year><article-title>AI&#x2013;driven frameworks for strategic risk management: A systematic review and model for organisational resilience and decision support</article-title><source>Journal of Intelligent Management Decision</source><volume>4</volume><issue>3</issue><fpage>224</fpage><lpage>234</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.56578/jimd040304">https://doi.org/10.56578/jimd040304</ext-link></comment></element-citation></ref>
<ref id="R34"><element-citation publication-type="journal"><person-group person-group-type="author"><name><surname>Zoppi</surname><given-names>T.</given-names></name><name><surname>Ceccarelli</surname><given-names>A.</given-names></name><name><surname>Bondavalli</surname><given-names>A.</given-names></name></person-group><year>2021</year><article-title>Unsupervised algorithms to detect zero-day attacks: Strategy and application</article-title><source>IEEE Access</source><volume>9</volume><fpage>90603</fpage><lpage>90615</lpage><comment><ext-link ext-link-type="doi" xlink:href="https://doi.org/10.1109/ACCESS.2021.3090957">https://doi.org/10.1109/ACCESS.2021.3090957</ext-link></comment></element-citation></ref>
</ref-list>
</back>
</article>