International Islamic University Chittagong; University of the Cumberlands, Kentucky
Abstract
Enterprise adoption of Generative AI (GenAI) and agentic, tool-using AI systems is accelerating faster than the governance controls designed to contain them. Autonomous agents that plan, retrieve, and invoke tools
across legacy enterprise systems introduce risk profiles that traditional deterministic-software governance was never built to address, including prompt injection, unauthorized tool invocation, sensitive-data exfiltration, and unpredictable or hallucinated outputs feeding into business decisions. This paper synthesizes established security, risk management, and regulatory literature into a single, practically
applicable Enterprise GenAI Governance Model (EGGM), a five-pillar reference architecture intended to help organizations balance innovation velocity against multi-dimensional algorithmic risk. We review the
current standards landscape and recent empirical security research on prompt injection, data exfiltration, and agentic misuse, then derive a governance architecture, a risk taxonomy, and an illustrative maturity
model that maps controls to risk categories. The paper's contribution is architectural and analytical rather than statistically empirical: it does not claim a validated predictive model of enterprise risk, since no public, controlled longitudinal dataset of enterprise agentic-AI incidents currently exists. Instead, it offers structured, citable framework and a maturity-assessment tool that organizations and future empirical studies can build on.
Keywords
Generative AI GovernanceEnterprise Risk ManagementAgentic AI SecurityResponsible AIPrompt Injection
Article Information
- Published
- July 27, 2026
- Journal
- Digital Transformation and Technology Dynamics
- Volume / Issue
- 1 / 1
- Year
- 2021