Governed Deployment of Enterprise Artificial Intelligence Control Planes for AI-Assisted Modernization Services: A Systematic Review

Authors

  • Nithesh Gudipuri

Keywords:

artificial intelligence governance, control plane, MLOps, zero trust architecture, algorithmic accountability, cloud computing, AI risk management, legacy modernization, explainability, DevOps

Abstract

We have seen the growth of artificial intelligence (AI) assisted modernization services such as automated code modernization, legacy migration tooling and generative coding assistants, but the governance processes to put such services into practice safely and at scale have not kept up. The systematic review collates nineteen resources relating to cloud computing standards, zero trust security architecture, machine learning operations (MLOps), algorithmic accountability and AI risk management, to define the architecture and governance of an enterprise “AI control plane” – a single layer for policy enforcement, access control, and auditing, located between AI-assisted tooling and production systems. To uncover common constructs and tensions, thematic synthesis analysis was performed in four domains of infrastructure and access-control architecture, deployment automation, accountability and explainability, and risk-management frameworks. The results suggest that there is common consensus on the need for three elements: continuous verification, least-privilege access, and reproducible deployment pipelines, but no single element is enough to enable governed AI deployment. A composite governance-risk formulation is suggested to demonstrate how different risk signals found in the literature could be combined in a control-plane gating mechanism. There is also evidence that tools used for coding with AI have measurable productivity impacts, highlighting the operational implications of governance design. The review finds that none of the reviewed frameworks consider infrastructure, deployment and accountability issues simultaneously, creating an opportunity for an integrated control-plane architecture to fill this gap.

Downloads

Download data is not yet available.

References

Busuioc, M. (2021). Accountable artificial intelligence: Holding algorithms to account. Public Administration Review, 81(5), 825–836. https://doi.org/10.1111/puar.13293

Chandramouli, R., & Butcher, Z. (2023). A zero-trust architecture model for access control in cloud-native applications in multi-location environments (NIST Special Publication 800-207A). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207A

Chen, M., Tworek, J., Jun, H., Yuan, Q., Pinto, H. P. de O., Kaplan, J., Edwards, H., Burda, Y., Joseph, N., Brockman, G., Ray, A., Puri, R., Krueger, G., Petrov, M., Khlaaf, H., Sastry, G., Mishkin, P., Chan, B., Gray, S., . . . Zaremba, W. (2021). Evaluating large language models trained on code. arXiv. https://doi.org/10.48550/arXiv.2107.03374

Cobbe, J., Lee, M. S. A., & Singh, J. (2021). Reviewable automated decision-making: A framework for accountable algorithmic systems. In Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency (pp. 598–609). Association for Computing Machinery. https://doi.org/10.1145/3442188.3445921

Costanza-Chock, S., Raji, I. D., & Buolamwini, J. (2022). Who audits the auditors? Recommendations from a field scan of the algorithmic auditing ecosystem. In 2022 ACM Conference on Fairness, Accountability, and Transparency (pp. 1571–1583). Association for Computing Machinery. https://doi.org/10.1145/3531146.3533213

Di Francesco, P., Lago, P., & Malavolta, I. (2018). Migrating towards microservice architectures: An industrial survey. In 2018 IEEE International Conference on Software Architecture (ICSA) (pp. 29–38). IEEE. https://doi.org/10.1109/ICSA.2018.00012

Doshi-Velez, F., & Kim, B. (2017). Towards a rigorous science of interpretable machine learning. arXiv. https://doi.org/10.48550/arXiv.1702.08608

Garg, S., Pundir, P., Rathee, G., Gupta, P. K., Garg, S., & Ahlawat, S. (2021). On continuous integration/continuous delivery for automated deployment of machine learning models using MLOps. In 2021 IEEE Fourth International Conference on Artificial Intelligence and Knowledge Engineering (AIKE) (pp. 25–28). IEEE. https://doi.org/10.1109/AIKE52691.2021.00010

Gholami, M. F., Daneshgar, F., Beydoun, G., & Rabhi, F. (2017). Challenges in migrating legacy software systems to the cloud—an empirical study. Information Systems, 67, 100–113. https://doi.org/10.1016/j.is.2017.03.008

Kordzadeh, N., & Ghasemaghaei, M. (2022). Algorithmic bias: Review, synthesis, and future research directions. European Journal of Information Systems, 31(3), 388–409. https://doi.org/10.1080/0960085X.2021.1927212

Königstorfer, F., & Thalmann, S. (2022). AI documentation: A path to accountability. Journal of Responsible Technology, 11, Article 100043. https://doi.org/10.1016/j.jrt.2022.100043

Kreuzberger, D., Kühl, N., & Hirschl, S. (2023). Machine learning operations (MLOps): Overview, definition, and architecture. IEEE Access, 11, 31866–31879. https://doi.org/10.1109/ACCESS.2023.3262138

Leite, L., Rocha, C., Kon, F., Milojicic, D., & Meirelles, P. (2019). A survey of DevOps concepts and challenges. ACM Computing Surveys, 52(6), Article 127. https://doi.org/10.1145/3359981

Lwakatare, L. E., Raj, A., Crnkovic, I., Bosch, J., & Olsson, H. H. (2020). Large-scale machine learning systems in real-world industrial settings: A review of challenges and solutions. Information and Software Technology, 127, Article 106368. https://doi.org/10.1016/j.infsof.2020.106368

Mell, P., & Grance, T. (2011). The NIST definition of cloud computing (NIST Special Publication 800-145). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-145

Peng, S., Kalliamvakou, E., Cihon, P., & Demirer, M. (2023). The impact of AI on developer productivity: Evidence from GitHub Copilot. arXiv. https://doi.org/10.48550/arXiv.2302.06590

Ribeiro, M. T., Singh, S., & Guestrin, C. (2016). “Why should I trust you?”: Explaining the predictions of any classifier. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 1135–1144). Association for Computing Machinery. https://doi.org/10.1145/2939672.2939778

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207

Sculley, D., Holt, G., Golovin, D., Davydov, E., Phillips, T., Ebner, D., Chaudhary, V., Young, M., Crespo, J.-F., & Dennison, D. (2015). Hidden technical debt in machine learning systems. In Advances in Neural Information Processing Systems 28 (NIPS 2015) (pp. 2503–2511). Curran Associates. https://doi.org/10.5555/2969442.2969519

Tabassi, E. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.100-1

Downloads

Published

25.11.2024

How to Cite

Nithesh Gudipuri. (2024). Governed Deployment of Enterprise Artificial Intelligence Control Planes for AI-Assisted Modernization Services: A Systematic Review. International Journal of Intelligent Systems and Applications in Engineering, 12(4), 6083 –. Retrieved from https://mail.ijisae.org/index.php/IJISAE/article/view/8565

Issue

Section

Research Article