Risk Architecture for AI-Native Engineering Teams: An Organizational Framework for Agentic System Governance

📅 2026-07-01
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Traditional software risk management struggles to address the unique challenges posed by AI-native teams, particularly probabilistic outputs, autonomous multi-step actions, and silent evolution risks—especially high-consequence failures arising from mismatches between deterministic dependencies and probabilistic outputs at organizational boundaries. This work proposes a risk governance framework tailored for AI-native engineering teams, introducing an innovative seven-dimensional team profiling schema and six failure modes, including a newly identified “determinism-probabilism mismatch at dependency boundaries.” A contextualized synthetic assessment method is developed to align with standards such as NIST AI RMF and ISO/IEC 42001. The study reveals a significant decline in risk coverage when transitioning from conventional software to AI-native teams, with uncovered high-consequence failures predominantly occurring in AI-specific phases, rooted in the misuse of probabilistic outputs at system boundaries.
📝 Abstract
Engineering management research has produced mature frameworks for software risk: ownership by feature, escalation by severity, and assurance by test coverage. These frameworks implicitly assume deterministic behavior, discrete and auditable change events, and clear component-to-owner mappings. Teams that build and operate agentic AI systems violate all three assumptions at once: outputs are probabilistic, systems take autonomous multi-step actions, and the risk surface mutates silently between deployments. Existing AI risk literature addresses this from above (policy frameworks such as the NIST AI RMF and ISO/IEC 42001) or below (threat taxonomies such as OWASP's agentic AI guidance), but not at the layer where an engineering manager (EM) operates: roles, decision rights, and escalation structures. This paper contributes (i) a seven-dimension profile distinguishing pure software-engineering, hybrid, and AI-native teams; (ii) a six-cluster failure-mode taxonomy including a previously unarticulated cluster, dependency-boundary determinism mismatch; and (iii) a synthetic framework-adequacy methodology scoring how well each profile's risk architecture detects, contains, and escalates a defined scenario set. Because the object of study is framework adequacy rather than human behavior, the evaluation yields derived rather than observed coverage claims. Coverage degrades as teams move from pure software engineering to AI-native operation, monotonically in the median and abruptly in the count of uncovered, high-consequence failures appearing only at the AI-native step. The degradation concentrates in specific failure-mode categories, and the most severe, least-covered failures arise not inside AI-native teams but at the organizational boundary where their probabilistic outputs are consumed by determinism-assuming dependencies.
Problem

Research questions and friction points this paper is trying to address.

AI-native systems
risk governance
engineering management
failure modes
organizational boundaries
Innovation

Methods, ideas, or system contributions that make the work stand out.

AI-native teams
agentic AI governance
risk architecture
failure-mode taxonomy
framework adequacy
💼 Related Jobs
No related jobs found.
L
Laxmipriya Ganesh Iyer
Independent Researcher