-
Notifications
You must be signed in to change notification settings - Fork 0
2026 04 26 systems capability debt agentic ai risk synthesis
Systems capability debt, citizen development, and agentic AI risk: is the causal chain and sequencing imperative a novel contribution?
Does the synthesis of technical debt literature (Cunningham, Kruchten), systems capability research, transaction cost economics (Coase, Williamson), operational risk frameworks (Basel III/IV, Risk and Control Self-Assessment (RCSA) methodology), and citizen development research produce a causal chain from systems capability debt through ungoverned citizen development to amplified agentic Artificial Intelligence (AI) operational risk, and an "AI for risk reduction first" sequencing imperative that constitutes a genuinely novel contribution to the literature?
In scope:
- Technical debt literature: Cunningham's original formulation, Kruchten's taxonomy, and subsequent academic elaborations
- Systems capability research: definitions of the gap between system capability and operational need, and its organisational consequences
- Transaction Cost Economics (TCE): Coase's theory of the firm, Williamson's governance of transactions, applied to information technology investment and workaround behaviour
- Operational risk frameworks: Basel III/IV operational risk capital requirements, RCSA methodology as a structured risk identification approach
- Citizen development literature: empirical and conceptual studies on low-code/no-code adoption, shadow information technology, and ungoverned automation
- Prior work on agentic AI risk specifically addressing the removal of implicit human-speed rate-limiting controls
- Assessment of each distinct debt type: integration debt, functionality debt, data access debt, data quality debt, data migration debt, User Experience (UX) and workflow debt, timeliness debt
- Strength of the causal links between each debt type and citizen development as an outcome
- The specific "AI for risk reduction first" sequencing argument and whether any existing framework has argued a comparable imperative
Out of scope:
- Implementation guides for specific remediation programmes
- Empirical measurement of systems capability debt costs in specific organisations
- Regulatory framework analysis per jurisdiction
- AI model safety or alignment literature not specifically addressing enterprise agentic deployment
Constraints:
- Prioritise primary sources: peer-reviewed literature, foundational texts, and documented frameworks; secondary summaries acceptable only if primary is unavailable
- The novelty claim is the central research question, and the assessment must be honest about partial precedents or analogous frameworks even when they do not use the exact same terminology
- Sources must be assessed for relevance to the complete causal chain, not just individual links
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] The working hypothesis is that persistent gaps between operational need and delivered system capability push business teams toward shadow information technology and low-code workarounds when central delivery cannot meet demand with adequate speed, fit, or integration.
- [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] The agentic-AI step matters because autonomous agents can act at machine speed across multiple systems, which makes human-paced review and compensating friction less reliable as a practical control once those workarounds are given write-capable automation.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html] The decision problem is therefore not only whether each literature strand exists individually, but whether the full causal chain and the proposed sequencing rule, use AI first to map and reduce risk before broad autonomous deployment, already exists in assembled form.
- Technical debt literature review: locate Cunningham's original formulation, Kruchten's technical debt taxonomy, and major subsequent elaborations; assess whether any extend debt metaphors to systems capability gaps, shadow tooling causation, or operational risk consequences.
- Transaction cost economics applied to information technology workarounds: search for applications of Coase and Williamson to make-versus-buy under capability gaps, and shadow information technology as a transaction-cost response; assess whether TCE has been used to explain citizen-development demand.
- Citizen development causation literature: review empirical and conceptual studies on what drives citizen-development adoption; distinguish preference for low-code tooling from workaround for unmet system capability as causal drivers; note whether any study explicitly links each debt type to citizen-development behaviour.
- Operational risk frameworks and ungoverned automation: review Basel and RCSA-oriented operational risk definitions for any treatment of shadow information technology, ungoverned automation, or systems capability gaps as distinct operational risk categories.
- Agentic AI risk and implicit rate-limiting: search for prior literature specifically addressing the removal of human-speed implicit controls by autonomous agents; assess whether the blast-radius amplification argument appears in AI safety, operational risk, or enterprise AI governance literature.
- Sequencing imperative precedents: search for any framework, technical, economic, regulatory, or organisational, that has articulated a comparable prerequisite-remediation-before-capability-deployment imperative.
- Novelty assessment: synthesise findings across all six sub-questions; assess whether the complete causal chain and sequencing imperative exists in assembled form, exists in partial form with gaps, or is genuinely novel; identify the strongest counterarguments.
- Ward Cunningham, "The WyCash Portfolio Management System" (OOPSLA 1992) — - original debt-metaphor text; anchors the scope of the metaphor in incomplete understanding and refactoring.
- Ward Cunningham, "Debt Metaphor" transcript (2009) — - later clarification that debt is about learning not written back into the system, not a general license for messy code.
- Philippe Kruchten, Robert Nord, Ipek Ozkaya, "Technical Debt: From Metaphor to Theory and Practice" (2012) — - canonical expansion from metaphor toward taxonomy and theory.
- Ronald Coase, "The Nature of the Firm" (1937) — - foundational TCE source for make, buy, and internal coordination logic.
- Oliver Williamson, "The Economic Institutions of Capitalism" (1985) — - governance-structure extension of TCE used for workaround and internalisation reasoning.
- From Shadow IT to Business-managed IT (Springer, 2020) — - empirical shadow information technology literature showing workarounds emerge when information technology cannot deliver suitable systems quickly enough.
- On the Emergence of Shadow IT, A Transaction Cost-Based Approach — - explicit TCE explanation for shadow information technology emergence.
- [Practitioners' Perceptions on the Adoption of Low Code Development Platforms (IEEE Access, 2023)](https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406) — .html) - empirical drivers and inhibitors for low-code adoption.
- Adoption of low-code and no-code development, a systematic literature review and future research agenda (Journal of Systems and Software, 2025) — - synthesis of low-code and citizen-development literature.
- Citizen Development, Low-Code/No-Code Platforms, and the Evolution of Generative AI in Software Development (IEEE Computer, 2025) — - concise current statement linking citizen development growth to governance and security challenges under generative AI.
- Basel Committee, Revisions to the Principles for the Sound Management of Operational Risk (2021) — - current formal operational-risk standard.
- Basel Committee, FSI Executive Summary of PSMOR — - usable summary of operational-risk identification, self-assessment, change management, controls, and Information and Communication Technology (ICT) governance.
- Basel Committee, Principles for operational resilience (2021) — - resilience framing for technology failures and interdependency mapping.
- Basel Committee press release on operational resilience and risk — - concise statement that technology threats increase operational-resilience importance.
- NIST AI Risk Management Framework Core — - governance, mapping, human oversight, risk tolerance, and third-party risk subcategories relevant to sequencing.
- AWS Security Blog, "Four security principles for agentic AI systems" (2026) — - explicit machine-speed, least-privilege, and human-approval-bottleneck framing for agentic systems.
- MIT Sloan Management Review, "Agentic AI at Scale: Redefining Management for a Superhuman Workforce" (2025) — - expert panel evidence that human-paced management models strain under agent speed and scale.
- Business-led low-code agent governance: conditions for durable value versus fragmentation in regulated environments — - prior completed repository item on low-code governance and prerequisites.
- Regulatory and standards preconditions for deployment of AI systems that can take multi-step actions — - prior completed repository item on regulated-environment preconditions and control-failure framing.
- The Nature of the Firm: why organisations exist, their fitness functions, and invariants — - prior completed repository item translating Coase and Williamson into organisation design and governance reasoning.
- Business-led low-code agent governance: conditions for durable value versus fragmentation in regulated environments
- Regulatory and standards preconditions for deployment of AI systems that can take multi-step actions
- The Nature of the Firm: why organisations exist, their fitness functions, and invariants
(Full output from running the research skill, retained verbatim in the completed item. Sections 0-5 are the investigation, and section 6 seeds the Findings section below.)
- [fact; source: http://c2.com/doc/oopsla92.html; https://cmdev.com/papers/debt-metaphor/; https://doi.org/10.1109/MS.2012.167; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] Research question restated: does existing literature already assemble a defensible causal chain from systems capability debt, through ungoverned citizen development, to amplified agentic-AI operational risk, and does it already imply or state the sequencing rule that organisations should use AI first for risk reduction and estate mapping before broad write-capable autonomous deployment?
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html; https://davidamitchell.github.io/Research/research/2026-03-10-nature-of-the-firm-coase-organisations.html] Prior completed repository work already covered low-code governance prerequisites, regulated agentic-AI preconditions, and TCE as an organisation-design lens, so this item tests whether those pieces plus debt theory constitute a new synthesis rather than first-order discovery.
- [fact; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] Scope confirmed: the assessment is about novelty of the assembled chain, not about proving cost magnitude, jurisdiction-specific legal advice, or implementation detail, and the output is a knowledge note with explicit confidence grading.
- [fact; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] Constraints confirmed: primary and quasi-primary public sources were prioritised, inaccessible or weak sources were not used as downstream support, and failed exact-term searches were recorded where the novelty claim depends partly on absence.
- Root question: Does the full argument exist already in literature, or is it a novel synthesis?
-
A. Debt lineage
- A1. What did Ward Cunningham mean by technical debt originally?
- A2. How far has later literature expanded debt beyond code into architecture or enterprise contexts?
- A3. Does any published debt taxonomy already describe a system-capability-gap debt that directly causes shadow tooling or citizen development?
-
B. Workaround causation
- B1. What explains shadow information technology and business-managed information technology emergence?
- B2. Does TCE explicitly explain workaround behaviour when central information technology cannot meet business need?
- B3. What do low-code and citizen-development studies say are the main adoption drivers?
-
C. Risk framing
- C1. How do Basel Committee operational-risk and resilience frameworks treat products, processes, systems, controls, change, and ICT?
- C2. How does the NIST AI Risk Management Framework treat context, risk tolerance, human oversight, and third-party components?
- C3. Do those frameworks already classify capability gaps, shadow information technology, or citizen development as explicit operational-risk categories?
-
D. Agentic amplification
- D1. Does current agentic-AI governance literature explicitly argue that machine-speed autonomy can outrun human review?
- D2. Does it frame that problem as removal of implicit human-speed rate limits on pre-existing workaround behaviour?
-
E. Sequencing and novelty
- E1. Has any source already stated an "AI for risk reduction first" sequencing rule in comparable form?
- E2. If not, which components are old and which assembly step is new?
- Access note: the originally seeded Gartner, Forrester, and IEEE Spectrum pages were not used for downstream evidence because the accessible material in this runtime was too generic or blocked to support precise claims.
- Access note: the Coase Digital Object Identifier (DOI) landing page returned 403 in this runtime, so Coase is cited by DOI URL and long-established public summaries rather than by an accessible full-text landing page.
- Access note: the seeded Archive.org URL for Williamson returned 404 in this runtime, so Williamson is treated as a canonical book citation by stable URL, with reasoning supported by prior completed repository synthesis grounded in Williamson's published framework.
- Failed primary-source search record: query
"systems capability debt"across web search and repository-related discovery returned no credible established literature term matching the exact phrase; nearest published adjacent concepts were enterprise architecture debt and enterprise technical debt, not a named systems-capability-debt canon. - Failed primary-source search record: query
"AI for risk reduction first"and query"risk reduction first" agentic AI sequencing enterprisereturned no source articulating the exact sequencing rule as a named framework. - Failed primary-source search record: query
"human-speed" agentic AI risk oversightand query"implicit rate limits" agentic AIreturned no direct prior formulation using that exact language; the accessible literature instead talks about machine speed, scale, approval bottlenecks, and human-paced governance limits.
- [fact; source: http://c2.com/doc/oopsla92.html] Ward Cunningham's 1992 debt metaphor describes first-time code that reflects incomplete understanding, where speed is acceptable only if teams promptly rewrite or refactor to consolidate learning.
- [fact; source: https://cmdev.com/papers/debt-metaphor/] Cunningham's 2009 clarification says the metaphor was about learning not written back into the program, not about deliberately writing poor code as a standing strategy.
- [fact; source: https://doi.org/10.1109/MS.2012.167] Kruchten, Nord, and Ozkaya state that technical debt had already expanded from Cunningham's original metaphor into a broader landscape including architectural and organisational concerns, but their framing is still about compromises embedded in software systems and their maintenance economics.
- [fact; source: https://www.scitepress.org/Papers/2023/119714/119714.pdf] Enterprise architecture debt literature exists and treats legacy reuse, misalignment, and slow evolution as debt-like enterprise problems, which shows that published scholarship has already moved beyond source-code-only debt.
- [inference; source: http://c2.com/doc/oopsla92.html; https://cmdev.com/papers/debt-metaphor/; https://doi.org/10.1109/MS.2012.167; https://www.scitepress.org/Papers/2023/119714/119714.pdf] The debt family therefore supports an extension from code debt to enterprise-level capability constraints, but it does not by itself supply the specific claim that unmet operational capability across seven named debt types systematically drives citizen development.
- [inference; source: http://c2.com/doc/oopsla92.html; https://doi.org/10.1109/MS.2012.167] The proposed term "systems capability debt" reads as a plausible synthesis term built from the debt tradition, not as a clearly established literature label already carrying the full intended meaning.
- [fact; source: https://link.springer.com/article/10.1007/s10257-020-00472-6] The Springer shadow information technology article gives a concrete case in which marketing sourced a Software as a Service (SaaS) event-management system because the information technology department could not provide a suitable system as quickly as needed.
- [fact; source: https://link.springer.com/article/10.1007/s10257-020-00472-6] That same article defines shadow information technology as software, hardware, or information-technology service processes used or created autonomously by business units without alignment with the information technology department, and it notes both risk and opportunity dimensions.
- [fact; source: https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] The transaction-cost-based shadow information technology paper states that prohibitive transaction costs in the exchange relation between business and information technology departments, influenced by misalignment, are the main explanation for shadow information technology emergence.
- [inference; source: https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://doi.org/10.1111/j.1468-0335.1937.tb00002.x; https://davidamitchell.github.io/Research/research/2026-03-10-nature-of-the-firm-coase-organisations.html] This is the clearest published bridge from Coase and Williamson to workaround behaviour: when the cost of waiting for sanctioned delivery exceeds the cost of local acquisition or local build, business units internalise the task themselves.
- [fact; source: https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] The IEEE Access low-code study says organisations adopt low-code under pressure to develop applications within budget and time at high quality, and it empirically identifies twelve drivers and nineteen inhibitors rather than a single dominant explanation.
- [fact; source: https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] The 2025 systematic review identifies benefits and challenges across forty primary studies, confirming that citizen development and low-code adoption are now established research areas with managerial frameworks and unresolved research gaps.
- [fact; source: https://pure.psu.edu/en/publications/citizen-development-low-codeno-code-platforms-and-the-evolution-o/] The 2025 IEEE Computer article says demand for faster software solutions exceeds the supply of skilled software developers, that more businesses will adopt citizen-development frameworks and generative AI tools, and that governance and security challenges follow.
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html; https://pure.psu.edu/en/publications/citizen-development-low-codeno-code-platforms-and-the-evolution-o/] The literature supports unmet need, backlog pressure, cost, speed, and governance friction as major causes of citizen development, but it does not map those causes through the specific seven-debt-type taxonomy proposed in this item.
- [fact; source: https://www.bis.org/fsi/fsisummaries/psmor.htm] Basel Committee Principle 6 requires comprehensive identification and assessment of operational risk inherent in all material products, activities, processes, and systems, and explicitly lists self-assessments of operational risks and controls among the tools used for that purpose.
- [fact; source: https://www.bis.org/fsi/fsisummaries/psmor.htm] Basel Committee Principle 7 covers change management, Principle 9 requires a strong control environment with risk assessment, control activities, information and communication, and monitoring, and Principle 10 requires a robust ICT risk management programme.
- [fact; source: https://www.bis.org/bcbs/publ/d516.htm; https://www.bis.org/press/p210331a.htm] Basel's operational-resilience principles treat technology failures, cyber incidents, third-party dependencies, interdependency mapping, and incident management as central resilience concerns.
- [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] NIST AI RMF Map requires organisations to document intended purpose, prospective settings, business value, risk tolerance, system knowledge limits, how outputs will be overseen by humans, processes for human oversight, third-party risks, and likely impacts before proceeding.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://www.bis.org/bcbs/publ/d516.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] These frameworks do not name shadow information technology, citizen development, or systems capability debt as standalone categories, but they clearly provide a formal control language for treating workaround estates, weak controls, poor visibility, and unmanaged dependencies as operational-risk material.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The operational-risk literature therefore supplies the risk-assessment scaffold for the argument, not the causal chain itself.
- [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] AWS states that an unintended agentic action can occur at machine speed before a human can intervene and that excessive privileges are more dangerous in agentic contexts because agents operate at greater scale and speed than human actors.
- [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] AWS also states that if every agent action requires human approval, decision volume can overwhelm reviewers and approval becomes reflexive rather than deliberate.
- [fact; source: https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] MIT Sloan Management Review reports expert-panel consensus that today's workflows were not built for the speed and scale of agentic AI and that old management models built for human-paced systems fall short for tracking dynamic agent behaviour.
- [fact; source: https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] The MIT Sloan piece also says accountability remains with people and organisations rather than with the AI system itself.
- [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] Current agentic-governance literature clearly supports the amplification thesis, agents move faster than human review and stretch human oversight, but it usually frames the problem as autonomy-governance strain rather than as the specific release of previously human-paced workaround risk.
- [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] The "implicit rate-limiting control" formulation appears to be a sharper interpretive synthesis of existing observations about machine speed, human bottlenecks, and reflexive approval than a phrase already standardised in the literature.
- [fact; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] Prior completed repository items already argued that governed platforms, risk-based intake, and foundational controls must exist before scaling low-code or write-capable agents in regulated environments.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] External literature supports sequencing by implication, define context, risk tolerance, and oversight first, bound autonomy, then earn greater autonomy through evaluation, but it does not present a clearly named "AI for risk reduction first" doctrine tied specifically to capability debt and citizen development.
- [inference; source: http://c2.com/doc/oopsla92.html; https://doi.org/10.1109/MS.2012.167; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] The strongest evidence supports a novelty position of "new synthesis, not ex nihilo theory": each component exists in adjacent literature, but the assembled chain and sequencing imperative do not appear as a pre-existing integrated framework.
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] The strongest counterargument is that citizen-development research already explains demand through backlog, cost, and agility pressures, so a debt-based framing could be criticised as relabelling familiar drivers rather than discovering a new causal mechanism.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] A second counterargument is that sequencing is already implicit in mainstream control practice, because risk assessment and control design normally precede new deployment, so the contribution is more rhetorical precision and cross-literature integration than an unprecedented normative rule.
- [inference; source: http://c2.com/doc/oopsla92.html; https://doi.org/10.1109/MS.2012.167] The debt literature establishes a family resemblance, not a ready-made theory of citizen development. Its main contribution is permission to describe persistent capability shortfalls as accumulated organisational liabilities.
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] The shadow information technology literature supplies the actual behavioural mechanism. Business units create local systems when sanctioned delivery is too slow, too misaligned, or too costly in transaction-cost terms.
- [inference; source: https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6; https://pure.psu.edu/en/publications/citizen-development-low-codeno-code-platforms-and-the-evolution-o/] Low-code and citizen-development research confirms the demand side, but it is broader than workaround behaviour alone. Speed, cost, skills scarcity, and digital-transformation goals all matter.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Basel Committee and NIST do not provide the causal story, but they show why the assembled story matters operationally: unmanaged workaround estates and unclear oversight are exactly the kind of context and control problems formal risk frameworks require firms to document and control.
- [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Agentic-AI literature provides the amplification step. Machine-speed execution and reviewer overload make previously tolerable local workarounds materially more dangerous when they become autonomous and write-capable.
- [inference; source: http://c2.com/doc/oopsla92.html; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] The novelty therefore lies in composition: debt explains persistence, TCE explains workaround emergence, risk frameworks explain why the estate must be mapped and controlled, and agentic literature explains why the severity changes.
- [fact; source: http://c2.com/doc/oopsla92.html; https://doi.org/10.1109/MS.2012.167] Consistency check: no reviewed source showed Cunningham or Kruchten explicitly tying technical debt to citizen development or shadow information technology, so all such links remain labelled as inference rather than fact.
- [fact; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] Consistency check: the strongest causal evidence for workaround behaviour comes from shadow information technology research, not from low-code adoption research, so the argument uses shadow information technology as the primary mechanism and low-code studies as corroborating context.
- [fact; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Consistency check: Basel Committee and NIST are cited only for control, governance, assessment, and oversight obligations, not as evidence that they explicitly coined or endorsed the proposed systems-capability-debt framework.
- [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Consistency check: the reviewed agentic-AI sources support machine-speed amplification and approval-bottleneck claims, but the exact phrase "implicit human-speed rate limits" is this item's synthesis wording.
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] No internal contradiction remained after separating explicit published claims from the new integrative framing.
- [inference; source: https://doi.org/10.1111/j.1468-0335.1937.tb00002.x; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] Economic lens: the argument is strongest when framed as a transaction-cost problem. Business units choose workarounds when the internal market for sanctioned capability is too slow or expensive relative to local action.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://www.bis.org/bcbs/publ/d516.htm] Regulatory lens: regulated firms do not need a new named rule to justify concern. Existing operational-risk and resilience expectations already require them to identify unmanaged processes, weak controls, and technology dependencies.
- [inference; source: https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6; https://pure.psu.edu/en/publications/citizen-development-low-codeno-code-platforms-and-the-evolution-o/] Behavioural lens: citizen development is not merely rebellion against governance. It is often a rational local response to speed, capability, and resource constraints, which means suppressing it without repairing the unmet need will not solve the root problem.
- [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Technical lens: the key shift under agentic AI is not only better content generation but delegated action across tools and interfaces, which raises the cost of excessive permissions and weak visibility.
- [inference; source: https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] Strategic lens: the practical consequence is a sequencing rule. If the same technology can either expand autonomous execution or map debt, access, and control gaps, the lower-regret move is to use it first for estate understanding and risk reduction.
(This section seeds the Findings below.)
Executive summary:
- [inference; source: http://c2.com/doc/oopsla92.html; https://cmdev.com/papers/debt-metaphor/; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] The complete causal chain and the "AI for risk reduction first" sequencing imperative do not appear in the reviewed literature as a pre-existing named framework, so the best-supported conclusion is that this is a novel synthesis built from established component literatures rather than a wholly unprecedented theory. [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] The clearest published link in that synthesis is between unmet system need and workaround behaviour, because shadow information technology research directly shows business units acquiring local systems when central information technology cannot deliver suitable capability quickly enough. [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Operational-risk frameworks do not supply the causal chain, but they do supply control language that supports treating workaround estates as legitimate governance and risk issues. [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Current agentic-AI governance literature then adds the amplification step by showing that machine-speed autonomy can outrun human review and make approval-based oversight ineffective at scale.
Key findings:
- [inference; source: http://c2.com/doc/oopsla92.html; https://cmdev.com/papers/debt-metaphor/; https://doi.org/10.1109/MS.2012.167] Medium confidence: Technical-debt literature begins with incomplete understanding written into software and later expands into broader architectural and enterprise concerns, and the reviewed evidence does not surface a standard debt category that matches the proposed "systems capability debt" construct.
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] High confidence: Shadow information technology literature already provides a direct causal mechanism from unmet capability and business-information-technology misalignment to local workaround systems, and it is the clearest published bridge in the reviewed evidence between capability gaps and ungoverned citizen development.
- [fact; source: https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6; https://pure.psu.edu/en/publications/citizen-development-low-codeno-code-platforms-and-the-evolution-o/] Medium confidence: Low-code and citizen-development research supports speed, cost, skills shortage, and governance friction as major adoption drivers, but it does not map those drivers through the seven proposed debt types or isolate unmet system capability as the sole cause.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://www.bis.org/bcbs/publ/d516.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] High confidence: Basel Committee operational-risk guidance and the NIST AI Risk Management Framework require organisations to identify risks across products, processes, systems, change, oversight, third-party components, and control environments, which supports treating workaround estates and unclear human oversight as materially relevant even without an explicit shadow-information-technology rule.
- [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] High confidence: Current agentic-AI governance literature clearly states that autonomous agents operate at machine speed and scale, that excessive privilege becomes more dangerous in that setting, and that human approval can degrade into a bottleneck or reflexive rubber stamp.
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] Medium confidence: The claim that agentic AI removes an implicit human-speed rate limit on pre-existing workaround behaviour is best treated as a new synthesis statement, because the reviewed literature supplies the ingredients of the argument but not that precise integrated formulation.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] Medium confidence: The proposed sequencing imperative, use AI first to map debt, access, and control gaps before scaling write-capable autonomous agents, is strongly implied by existing governance and control literature but does not appear as a widely cited named doctrine in the reviewed sources.
- [inference; source: http://c2.com/doc/oopsla92.html; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://www.bis.org/fsi/fsisummaries/psmor.htm; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] High confidence: This item's strongest novelty claim is that it contributes a cross-literature explanatory framework joining debt persistence, workaround emergence, formal risk governance, and machine-speed amplification into one decision-useful argument.
Evidence map:
Assumptions:
- [assumption; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] The shadow information technology literature is treated as the closest behavioural analogue for citizen development when direct low-code studies do not explicitly describe the full workaround chain. Justification: both involve business-led creation or sourcing of local digital capability outside full central engineering control.
- [assumption; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] The move from human-paced workarounds to write-capable agentic automation materially changes risk severity rather than merely increasing volume. Justification: the reviewed agentic-AI sources consistently stress speed, scale, privilege, and reviewer-overload effects.
- [assumption; source: https://doi.org/10.1111/j.1468-0335.1937.tb00002.x; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] Coase and Williamson remain valid explanatory lenses for internal workaround behaviour in contemporary digital organisations. Justification: the transaction-cost shadow-information-technology paper applies that logic directly to the phenomenon under study.
Analysis:
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] The most important discovery in the evidence set is that the middle of the chain is already published. Unmet need and business-information-technology friction do produce local workaround systems through a transaction-cost mechanism.
- [inference; source: http://c2.com/doc/oopsla92.html; https://doi.org/10.1109/MS.2012.167; https://www.scitepress.org/Papers/2023/119714/119714.pdf] The debt literature then gives a vocabulary for persistence and accumulation, but it does not remove the need to show why people route around the sanctioned estate.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Risk frameworks matter because they convert what could look like an architectural complaint into a governance obligation. Once the estate is risk-bearing and poorly mapped, the problem is not stylistic.
- [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Agentic-AI literature does not need to mention shadow information technology explicitly for the amplification argument to hold. It is enough that it shows speed, delegated authority, and approval overload change control feasibility.
- [inference; source: https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] The main weakness in the synthesis is that low-code adoption research is multi-causal. A claim that every citizen-development instance is caused by systems capability debt would overstate the evidence.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] That weakness is manageable if the argument is framed carefully: systems capability debt is a major and under-theorised driver of workaround demand, and agentic AI makes the unresolved estate more dangerous, which creates a sequencing imperative grounded in risk management rather than in aesthetic preference.
Risks, gaps, uncertainties:
- [fact; source: https://doi.org/10.1111/j.1468-0335.1937.tb00002.x; https://archive.org/details/economicinstitut00will] Full primary-text access for Coase and Williamson was limited in this runtime, so the TCE step relies partly on stable canonical citations and prior completed repository synthesis.
- [fact; source: https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] The low-code literature is still young and methodologically mixed, so the causal hierarchy among adoption drivers is not mature enough to support strong single-cause claims.
- [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] The amplification step is supported mainly by current governance and security commentary rather than by a long peer-reviewed tradition specific to agentic enterprise deployment.
- [inference; source: http://c2.com/doc/oopsla92.html; https://doi.org/10.1109/MS.2012.167; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] Exact-phrase absence is always a weaker novelty signal than direct proof of non-existence, so the novelty claim should be framed as "not found in reviewed literature" rather than as an absolute universal statement.
Open questions:
- [inference; source: https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6; https://pure.psu.edu/en/publications/citizen-development-low-codeno-code-platforms-and-the-evolution-o/] Which of the seven proposed debt types most strongly predicts citizen-development emergence in practice, and which are only background contributors?
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] What is the best Risk and Control Self-Assessment design for surfacing workaround estates, excessive permissions, and low-code automations before agent deployment?
- [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] At what action volume or privilege profile does human review become nominal rather than substantive for agentic systems in regulated enterprises?
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] Which governance interventions reduce workaround demand most effectively: better sanctioned delivery speed, better platform self-service, tighter controls, or some combination?
- [fact; source: http://c2.com/doc/oopsla92.html; https://cmdev.com/papers/debt-metaphor/; https://doi.org/10.1109/MS.2012.167; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Review outcome: every substantive claim in the Research Skill Output is either bound to a source or labelled as inference or assumption, and the novelty claim is positioned as a synthesis contribution rather than as an entirely unprecedented theory.
(Populated from §6 Synthesis above.)
- [inference; source: http://c2.com/doc/oopsla92.html; https://cmdev.com/papers/debt-metaphor/; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] The complete causal chain and the "AI for risk reduction first" sequencing imperative do not appear in the reviewed literature as a pre-existing named framework, so the best-supported conclusion is that this is a novel synthesis built from established component literatures rather than a wholly unprecedented theory.
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] The clearest published link in that synthesis is between unmet system need and workaround behaviour, because shadow information technology research directly shows business units acquiring local systems when central information technology cannot deliver suitable capability quickly enough.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Operational-risk frameworks do not supply the causal chain, but they do supply control language that supports treating the resulting workaround estate as a legitimate governance and risk issue.
- [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Current agentic-AI governance literature then adds the amplification step by showing that machine-speed autonomy can outrun human review and make approval-based oversight ineffective at scale.
- [inference; source: http://c2.com/doc/oopsla92.html; https://cmdev.com/papers/debt-metaphor/; https://doi.org/10.1109/MS.2012.167] Medium confidence: Technical-debt literature begins with incomplete understanding written into software and later expands into broader architectural and enterprise concerns, and the reviewed evidence does not surface a standard debt category that matches the proposed "systems capability debt" construct.
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] High confidence: Shadow information technology literature already provides a direct causal mechanism from unmet capability and business-information-technology misalignment to local workaround systems, and it is the clearest published bridge in the reviewed evidence between capability gaps and ungoverned citizen development.
- [fact; source: https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6; https://pure.psu.edu/en/publications/citizen-development-low-codeno-code-platforms-and-the-evolution-o/] Medium confidence: Low-code and citizen-development research supports speed, cost, skills shortage, and governance friction as major adoption drivers, but it does not map those drivers through the seven proposed debt types or isolate unmet system capability as the sole cause.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://www.bis.org/bcbs/publ/d516.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] High confidence: Basel Committee operational-risk guidance and the NIST AI Risk Management Framework require organisations to identify risks across products, processes, systems, change, oversight, third-party components, and control environments, which supports treating workaround estates and unclear human oversight as materially relevant even without an explicit shadow-information-technology rule.
- [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] High confidence: Current agentic-AI governance literature clearly states that autonomous agents operate at machine speed and scale, that excessive privilege becomes more dangerous in that setting, and that human approval can degrade into a bottleneck or reflexive rubber stamp.
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] Medium confidence: The claim that agentic AI removes an implicit human-speed rate limit on pre-existing workaround behaviour is best treated as a new synthesis statement, because the reviewed literature supplies the ingredients of the argument but not that precise integrated formulation.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-agentic-ai-regulatory-preconditions-control-failure-assessment.html] Medium confidence: The proposed sequencing imperative, use AI first to map debt, access, and control gaps before scaling write-capable autonomous agents, is strongly implied by existing governance and control literature but does not appear as a widely cited named doctrine in the reviewed sources.
- [inference; source: http://c2.com/doc/oopsla92.html; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach; https://www.bis.org/fsi/fsisummaries/psmor.htm; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] High confidence: This item's strongest novelty claim is that it contributes a cross-literature explanatory framework joining debt persistence, workaround emergence, formal risk governance, and machine-speed amplification into one decision-useful argument.
- [assumption; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] Assumption: The shadow information technology literature is treated as the closest behavioural analogue for citizen development when direct low-code studies do not explicitly describe the full workaround chain. Justification: both involve business-led creation or sourcing of local digital capability outside full central engineering control.
- [assumption; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Assumption: The move from human-paced workarounds to write-capable agentic automation materially changes risk severity rather than merely increasing volume. Justification: the reviewed agentic-AI sources consistently stress speed, scale, privilege, and reviewer-overload effects.
- [assumption; source: https://doi.org/10.1111/j.1468-0335.1937.tb00002.x; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] Assumption: Coase and Williamson remain valid explanatory lenses for internal workaround behaviour in contemporary digital organisations. Justification: the transaction-cost shadow-information-technology paper applies that logic directly to the phenomenon under study.
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] The most important discovery in the evidence set is that the middle of the chain is already published. Unmet need and business-information-technology friction do produce local workaround systems through a transaction-cost mechanism.
- [inference; source: http://c2.com/doc/oopsla92.html; https://doi.org/10.1109/MS.2012.167; https://www.scitepress.org/Papers/2023/119714/119714.pdf] The debt literature then gives a vocabulary for persistence and accumulation, but it does not remove the need to show why people route around the sanctioned estate.
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Risk frameworks matter because they convert what could look like an architectural complaint into a governance obligation. Once the estate is risk-bearing and poorly mapped, the problem is not stylistic.
- [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Agentic-AI literature does not need to mention shadow information technology explicitly for the amplification argument to hold. It is enough that it shows speed, delegated authority, and approval overload change control feasibility.
- [inference; source: https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] The main weakness in the synthesis is that low-code adoption research is multi-causal. A claim that every citizen-development instance is caused by systems capability debt would overstate the evidence.
- [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] That weakness is manageable if the argument is framed carefully: systems capability debt is a major and under-theorised driver of workaround demand, and agentic AI makes the unresolved estate more dangerous, which creates a sequencing imperative grounded in risk management rather than in aesthetic preference.
- [fact; source: https://doi.org/10.1111/j.1468-0335.1937.tb00002.x; https://archive.org/details/economicinstitut00will] Full primary-text access for Coase and Williamson was limited in this runtime, so the TCE step relies partly on stable canonical citations and prior completed repository synthesis.
- [fact; source: https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6; https://fis.tu-dresden.de/portal/en/publications/practitioners-perceptions-on-the-adoption-of-low-code-development-platforms(20818aa9-8856-45e1-accf-b95e10376406).html] The low-code literature is still young and methodologically mixed, so the causal hierarchy among adoption drivers is not mature enough to support strong single-cause claims.
- [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] The amplification step is supported mainly by current governance and security commentary rather than by a long peer-reviewed tradition specific to agentic enterprise deployment.
- [inference; source: http://c2.com/doc/oopsla92.html; https://doi.org/10.1109/MS.2012.167; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] Exact-phrase absence is always a weaker novelty signal than direct proof of non-existence, so the novelty claim should be framed as "not found in reviewed literature" rather than as an absolute universal statement.
- [inference; source: https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6; https://pure.psu.edu/en/publications/citizen-development-low-codeno-code-platforms-and-the-evolution-o/] Which of the seven proposed debt types most strongly predicts citizen-development emergence in practice, and which are only background contributors?
- [inference; source: https://www.bis.org/fsi/fsisummaries/psmor.htm; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] What is the best Risk and Control Self-Assessment design for surfacing workaround estates, excessive permissions, and low-code automations before agent deployment?
- [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] At what action volume or privilege profile does human review become nominal rather than substantive for agentic systems in regulated enterprises?
- [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.academia.edu/9093645/On_the_Emergence_of_Shadow_IT_A_Transaction_Cost_Based_Approach] Which governance interventions reduce workaround demand most effectively: better sanctioned delivery speed, better platform self-service, tighter controls, or some combination?
- Type: knowledge
- Description: Novelty assessment of the proposed systems-capability-debt to citizen-development to agentic-risk causal chain, including what is already established in debt, shadow-information-technology, low-code, operational-risk, and agentic-governance literature, and where the actual new contribution begins.
- Links:
Navigation
By Tag
bureaucracy
change-management
coase
constraint-analysis
control-model
decision-rights
delegation
- Q4: Decision rights that should move closer to execution
- Q5: Control model for the best throughput-risk trade-off
delivery-risk
- Operating model synthesis for split-authority delivery systems
- Q6: Leading indicators of instability in split-authority flow systems
demand-segmentation
enterprise
exception-handling
execution
flow
flow-design
flow-metrics
governance
- Operating model synthesis for split-authority delivery systems
- Q1: Dominant flow constraint in split-authority delivery systems
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q4: Decision rights that should move closer to execution
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
governance-patterns
incentives
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
instability
institutional-economics
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
leading-indicators
operating-model
organisation
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
organisational-design
queue-design
queueing
regulated-enterprise
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
- Barriers to governance reform, leadership failure modes, and reform mechanisms in regulated enterprises
routing
throughput
throughput-risk
transaction-costs
- Conditions under which internal governance controls minimise coordination costs in regulated enterprises
- Failure mechanisms of internal governance controls: bureaucratic inefficiency and informal circumvention in regulated enterprises
triage
- Q2: Demand segmentation for fast-path vs controlled-path flow
- Q3: Routing design that isolates exceptions from routine flow
williamson