Skip to content

2026 05 08 capability debt definition measurement ai risk amplification

github-actions[bot] edited this page May 9, 2026 · 1 revision

How can organisational capability debt be rigorously defined and measured as a leading indicator of Artificial Intelligence (AI)-related enterprise risk, and how does pre-existing capability debt amplify risks from autonomous AI systems when human rate limits are removed?

Research Question

How can capability debt, the accumulated organisational deficit in review quality, judgment, process maturity, and skill inventory, be rigorously defined, measured, and tracked as a leading indicator of AI-related enterprise risk? What is the relationship between pre-existing capability debt, including slow central systems, unmet business needs, and weak review culture, and the amplification of those risks when autonomous, goal-directed AI systems (agentic AI) remove human rate limits? How should organisations sequence debt reduction relative to AI rollout, and in what ways does promoting individual AI tools without corresponding investment in review and quality systems create hidden organisational debt?

Scope

In scope:

  • Formal or operational definitions of capability debt as distinct from, but related to, technical debt, specifically covering process gaps, permission sprawl, review quality degradation, and skill inventory deficits
  • Maturity models, scorecard frameworks, and leading-indicator approaches that link capability debt measures to future AI-related incident risk
  • Empirical evidence on how pre-existing capability debt, including legacy systems, business-unit workarounds, and under-resourced central functions, amplifies risk when agentic AI removes the natural friction of human review rates
  • Sequencing models for deciding when to reduce capability debt before scaling AI, and when accepting debt is tolerable
  • Hidden organisational debt created by promoting individual AI tools without investment in review infrastructure, quality systems, or collective judgment capacity

Out of scope:

  • Technical debt in source code when it is not linked to organisational process or capability gaps
  • Vendor or product selection for debt-reduction tooling
  • A full Capability Maturity Model Integration (CMMI) survey unrelated to AI risk
  • Macro-level economic cost-benefit analysis of AI adoption

Constraints:

  • Distinguish capability debt as an organisational concept from software technical debt
  • Ground claims in observable enterprise patterns and flag inferences explicitly
  • Expand acronyms on first use
  • Extend prior repository work on systems capability debt rather than duplicate it

Context

Existing repository research already shows that systems capability debt amplifies risk when agentic AI is layered on top of organisations with pre-existing process gaps, weak governance, and workaround behaviour such as shadow Information Technology (shadow IT) and shadow AI. [fact; source: https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-citizen-development-empirical-evidence.html; https://davidamitchell.github.io/Research/research/2026-04-26-implicit-rate-limiting-controls-agentic-ai-removal.html]

The remaining gap is a measurable definition that turns that synthesis into an operational leading-indicator model, including what to count, how to track it over time, how to sequence debt reduction relative to AI rollout, and how individual AI-tool promotion can create hidden debt when shared review capacity does not improve. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html]

Approach

  1. Sub-question 1 - Definition and taxonomy: How has capability debt been defined in the literature or in adjacent practitioner frameworks? How does it differ from and interact with technical debt? What are its sub-components, including process debt, skill debt, review debt, and permission sprawl?
  2. Sub-question 2 - Measurement as a leading indicator: What metrics or maturity-model dimensions have been proposed or validated as leading indicators of AI-related risk? How can process gaps, permission sprawl, workarounds, and skill deficits be quantified and tracked?
  3. Sub-question 3 - Amplification when human rate limits are removed: What empirical evidence exists that pre-existing capability debt is amplified, rather than merely unchanged, when agentic AI removes the natural friction of human review rates? Are there analogous cases from earlier automation waves?
  4. Sub-question 4 - Sequencing and hidden debt from individual tool promotion: What frameworks guide the sequencing of capability-debt reduction relative to AI rollout? How does promoting individual AI tools without review-infrastructure investment accumulate a distinct form of hidden organisational debt?

Sources


Research Skill Output

(Full output from running the research skill - retained verbatim in the completed item. Sections 0-5 are the investigation; section 6 seeds the Findings section below.)

§0 Initialise

  • Question: how should capability debt be defined, measured, and used as a leading indicator of AI-related enterprise risk, and how does pre-existing debt amplify risk once autonomous, goal-directed AI systems remove human rate limits?
  • Scope: organisational debt in process quality, review quality, skill inventory, governance, and workaround behaviour, not source-code debt in isolation, vendor selection, or macroeconomic adoption modelling.
  • Constraints: public and accessible sources first, explicit separation of fact from inference, acronym expansion on first use, and prior repository items treated as adjacent synthesis rather than sole evidence.
  • Output: knowledge.
  • [fact; source: https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] Term definition: agentic AI refers here to autonomous, goal-directed AI systems that can plan and execute actions with limited continuous human oversight.
  • [fact; source: https://davidamitchell.github.io/Research/research/2026-04-22-enterprise-ai-capability-model.html; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html; https://davidamitchell.github.io/Research/research/2026-04-26-implicit-rate-limiting-controls-agentic-ai-removal.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-agentic-ai-risk-synthesis.html; https://davidamitchell.github.io/Research/research/2026-04-26-systems-capability-debt-citizen-development-empirical-evidence.html; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html] Prior completed repository work already covered systems capability debt, shadow-workaround causation, capability-model prerequisites, implicit rate-limiting, and control-design failure modes, so the remaining work is operational definition, measurement, and sequencing rather than first discovery of the broader chain.
  • [inference; source: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] The external-literature gap is not that organisations lack any discussion of prerequisites or controls, but that those prerequisites have not been assembled into a single leading-indicator construct for AI risk under the label capability debt.

§1 Question Decomposition

  • Root question: what should count as capability debt, how should it be measured, and why does it matter more once agentic AI removes human pacing constraints?
  • A. Definition and taxonomy
    • A1. What does debt mean in Cunningham's and Fowler's original framing?
    • A2. Which organisational prerequisites for safe scale are explicit in CMMI, Westrum, NIST, DORA, AWS, and MIT Sloan?
    • A3. Which missing prerequisites should be grouped into a capability-debt taxonomy?
  • B. Measurement
    • B1. Which reviewed frameworks provide observable indicators rather than slogans?
    • B2. Which indicators are likely to lead incidents rather than merely describe them afterward?
    • B3. How can review quality, workaround demand, permission sprawl, and skill freshness be tracked over time?
  • C. Amplification
    • C1. What shows that workarounds emerge when central systems are too slow or too weak?
    • C2. What shows that agentic AI increases consequence speed beyond human-paced governance?
    • C3. How does reduced human practice intensity weaken the very review capacity needed to absorb that acceleration?
  • D. Sequencing and hidden debt
    • D1. Which sources say autonomy should be earned only after controls and evaluation exist?
    • D2. Which parts of capability debt must be reduced before scale on high-consequence surfaces?
    • D3. How does tool-led adoption without shared review investment create hidden debt?

§2 Investigation

Search and source-position notes

  • [inference; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] None of the reviewed debt, process-maturity, or safety-culture sources uses the exact term capability debt as a settled canonical construct, so the term is a synthesis label rather than an established literature term.
  • [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] No reviewed source states the exact sequencing rule "reduce capability debt before AI rollout" as a named doctrine, but multiple sources independently require platform quality, explicit controls, and earned autonomy before safe scale.
  • [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://davidamitchell.github.io/Research/research/2026-04-26-implicit-rate-limiting-controls-agentic-ai-removal.html] Reviewed sources use phrases such as machine speed, superhuman workforce, and human-paced governance limits rather than the exact phrase removal of human rate limits, but the mechanism they describe is materially the same.

A. What debt means, and what capability debt should include

  • [fact; source: http://c2.com/doc/oopsla92.html] Ward Cunningham's original metaphor describes debt as the residual cost of learning not yet written back into the system, where speed can be useful only if later consolidation occurs.
  • [fact; source: https://martinfowler.com/bliki/TechnicalDebtQuadrant.html] Martin Fowler's quadrant distinguishes prudent versus reckless debt and deliberate versus inadvertent debt, which makes debt a decision-and-learning framework rather than a synonym for any defect.
  • [fact; source: https://cmmiinstitute.com/learning/appraisals] CMMI appraisal practice treats capability as something that can be benchmarked against best practices, with strengths, weaknesses, and maturity or capability levels assessed through formal appraisal rather than intuition.
  • [fact; source: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/] Ron Westrum's typology treats information flow, treatment of messengers, and response to failure as observable organisational traits, with generative cultures surfacing problems and pathological cultures hiding them.
  • [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] The NIST AI Risk Management Framework (AI RMF) requires explicit policies, inventory mechanisms, role clarity, training, human-AI oversight definitions, incident identification, and third-party contingency processes as preconditions for trustworthy AI risk management.
  • [fact; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] DevOps Research and Assessment (DORA) reports that AI does not fix a team and instead amplifies existing workflow, platform, and control quality, with weak downstream safety nets turning higher output into instability.
  • [fact; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] Shadow IT, shadow AI, and citizen-development literature all show the same demand-side pattern: when central delivery paths are too slow, poorly fitted, or too hard to use, business users source their own tools or build workarounds.
  • [inference; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Capability debt denotes here the accumulated shortfall between the organisational capabilities required for safe, reviewable, governable AI use and the capabilities actually present in operating practice.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8] The main sub-components are process debt, review debt, control debt, inventory debt, skill debt, data-context debt, and demand-signal debt, where demand-signal debt means the organisation has learned through repeated workaround behaviour that sanctioned systems do not meet operational need but has not converted that learning into shared capability.

B. How capability debt can be measured as a leading indicator

  • [fact; source: https://cmmiinstitute.com/learning/appraisals] CMMI demonstrates that capability measurement can be structured as repeatable appraisal against defined best practices rather than as a purely subjective maturity discussion.
  • [fact; source: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/] Westrum shows that information-handling behaviour is measurable at the culture level, which matters because poor escalation and messenger suppression hide risk before incidents become visible.
  • [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] NIST AI RMF provides observable governance indicators such as inventory coverage, documented roles, training, oversight definitions, incident-handling mechanisms, and periodic review.
  • [fact; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] DORA provides observable workflow indicators such as platform quality, automated safety nets, version-control quality, feedback-loop speed, and delivery stability under AI-assisted acceleration.
  • [fact; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://link.springer.com/article/10.1007/s10257-020-00472-6] Shadow-tool usage and workaround prevalence are measurable demand signals because they reveal that users are bypassing sanctioned channels when those channels do not meet their needs.
  • [assumption; source: https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] A composite leading-indicator score is more decision-useful than a single scalar metric. Justification: the reviewed sources expose different failure surfaces, so reducing them to one raw number would hide which debt class is actually driving risk.
  • [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8] A practical capability-debt scorecard should track at least seven dimensions: sanctioned-delivery responsiveness, workaround prevalence, governance and inventory coverage, review quality and escalation quality, deterministic-control coverage for high-consequence actions, platform and feedback-loop quality, and workforce skill freshness.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8] Candidate leading indicators include backlog age for sanctioned automation requests, percent of AI use covered by approved tools, percent of AI systems inventoried, percent of high-risk workflows with defined human-AI oversight rules, percent of sensitive actions behind deterministic external controls, stability degradation after AI-assisted throughput increases, and interval since meaningful skill-refresh exercises for reviewers.

C. Why pre-existing capability debt amplifies risk when agentic AI removes human pacing limits

  • [fact; source: https://link.springer.com/article/10.1007/s10257-020-00472-6] The shadow-Information Technology literature documents business units procuring or adapting tools because the Information Technology function could not provide suitable systems quickly enough, which means workaround estates are rooted in pre-existing delivery gaps rather than in tool enthusiasm alone.
  • [fact; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks] IBM reports that 80% of surveyed office workers use AI at work, only 22% rely exclusively on employer-provided tools, nearly 40% prefer external tools for better features, and 60% say hands-on learning would increase enterprise-tool use.
  • [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] AWS states that agentic AI systems can carry out unintended actions at machine speed before a human can intervene, and that deterministic external controls must sit outside the reasoning loop because prompting alone is not a security mechanism.
  • [fact; source: https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] MIT Sloan and Boston Consulting Group report that experts see agentic AI as challenging traditional management because old workflows were built for human pace, while agentic systems need explicit rules, thresholds, tracing, audits, and intervention paths.
  • [fact; source: https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8] Macnamara and colleagues argue that AI assistants can accelerate skill decay among experts, hinder skill development among learners, and obscure those harms from the people experiencing them.
  • [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8] Pre-existing capability debt becomes risk-amplifying under agentic AI because the same organisation that already lacks responsive sanctioned paths, explicit review rules, or strong skills is suddenly asked to govern much higher action volume and consequence speed with the same weak capability base.
  • [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] The shift is multiplicative, not merely additive, because AI increases throughput while machine-speed agents also compress the time available for detection, escalation, and correction.

D. Sequencing rules and the hidden debt created by tool-led rollout

  • [fact; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] DORA's practical recommendations start with socialising policies, connecting AI to internal context, prioritising foundational practices, fortifying safety nets, and investing in the internal platform.
  • [fact; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] NIST states that map-function outcomes inform an initial decision about whether an AI solution is appropriate at all, which makes readiness assessment part of deployment choice rather than a post-deployment repair step.
  • [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] AWS recommends that greater autonomy be earned progressively through ongoing evaluation, with high-consequence actions beginning under human decision-making and only later moving to broader autonomy if evidence supports it.
  • [fact; source: https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] MIT Sloan recommends life-cycle-based management, explicit accountability structures, recurring assessments, and boundary-setting rather than one-time approval checklists.
  • [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Some low-risk debt can be tolerated for bounded read-only or advisory AI uses. Justification: the reviewed sources support risk-tiered governance and progressive autonomy rather than an absolute ban on all deployment before all debt is reduced.
  • [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks] The defensible sequencing rule is to reduce capability debt first on high-consequence control surfaces, especially write-capable workflows, privileged actions, sensitive-data exposure, and overloaded review queues, before scaling autonomous operation.
  • [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html] Promoting individual AI tools without shared investment in review systems, platform quality, training, and governance creates hidden organisational debt because it raises local throughput while externalising verification, escalation, and skill-maintenance costs to already weak shared systems.

§3 Reasoning

  • [inference; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals] The debt metaphor is justified here because the missing capability stock behaves like accumulated unpaid learning: organisations learn through repeated exceptions, workarounds, and review failures that their current operating model is insufficient, but do not convert that learning into shared capability.
  • [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] A leading-indicator model is plausible because each component is observable before a major AI incident, unlike loss-event metrics that appear only after harm.
  • [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks] Workaround prevalence is not just a governance breach metric; it is also a demand signal that sanctioned capability is under-serving the business.
  • [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8] Once agents increase consequence speed while human skill and review quality remain static or decline, pre-existing capability debt stops being background drag and becomes an active risk amplifier.
  • [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] The strongest synthesis outcome is therefore not a universal prohibition on AI rollout, but a readiness-gated sequencing rule tied to consequence level and control completeness.

§4 Consistency Check

  • [fact; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html] No reviewed source contradicts the use of debt as a metaphor for accumulated unpaid learning, although none of them standardises the exact term capability debt.
  • [fact; source: https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Measurement sources are complementary rather than contradictory, because they cover process maturity, information culture, governance controls, and workflow robustness from different angles.
  • [fact; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] Workaround-demand sources agree that unmet business need and slow sanctioned delivery push users toward unsanctioned or business-managed solutions.
  • [fact; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Agentic-speed sources agree that explicit rules, controls, and ongoing evaluation become more necessary as autonomy rises.
  • [inference; source: https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] The weakest part of the chain is the direct longitudinal link from a composite capability-debt score to later AI incidents, so overall confidence remains medium rather than high.

§5 Depth and Breadth Expansion

  • [inference; source: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] From a behavioural lens, capability debt is partly cultural debt because poor information flow and weak escalation discipline delay the discovery of unsafe AI use even when formal controls exist on paper.
  • [inference; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] From a technical lens, platform quality and deterministic external controls are not separate from capability debt measurement; they are major debt dimensions because they determine whether higher AI throughput remains governable.
  • [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] From a governance lens, capability debt is also a boundary-setting problem because unclear decision rights, undefined escalation thresholds, and incomplete lifecycle oversight make autonomy unsafe even before any model failure occurs.
  • [inference; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] From an economic lens, shadow tools are a revealed-preference signal that business demand for capability is real, so treating every workaround only as misconduct misses the root-cause information it contains.
  • [inference; source: https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html] From a workforce lens, skill decay means capability debt can increase even while local output appears to improve, which makes human-capability telemetry necessary alongside platform and policy telemetry.

§6 Synthesis

Executive summary:

The accumulated shortfall between the organisational capabilities required for safe AI scale and the capabilities actually present in practice should be tracked as a leading indicator of future AI-related risk rather than as a lagging description of incidents that have already happened. [inference; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report]

Capability debt is used here as shorthand for that shortfall, because the reviewed sources provide the component parts of the construct but do not standardise the label itself. [inference; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/]

Agentic AI, used here to mean autonomous, goal-directed AI systems that can plan and execute actions with limited continuous human oversight, amplifies pre-existing capability debt because the same organisations that already rely on workarounds or weak review culture are then asked to govern machine-speed action with unchanged or deteriorating review capacity. [inference; source: https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8]

The strongest practical conclusion is a sequencing rule, reduce capability debt first on high-consequence control surfaces and allow broader autonomy only where deterministic controls, inventory, oversight rules, and evaluation evidence already exist. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/]

Key findings:

  1. Capability debt is not a settled literature term, but it can be rigorously operationalised as the accumulated gap between the organisational capabilities required for safe, reviewable, governable AI use and the capabilities actually present in day-to-day practice. ([inference]; medium confidence; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/)
  2. A defensible capability-debt scorecard should combine process appraisal, information-flow culture, governance and inventory coverage, platform and safety-net quality, workaround prevalence, deterministic-control coverage, and workforce skill freshness instead of collapsing risk into a single simplistic metric. ([inference]; medium confidence; source: https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8)
  3. Shadow IT, shadow AI, and citizen-development evidence shows that workaround adoption is usually a demand signal produced by slow or poorly fitted sanctioned capability, which supports treating workaround prevalence as a leading indicator of unmet organisational need and rising governance risk. ([inference]; medium confidence; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6)
  4. DORA's evidence that AI amplifies existing workflow and platform quality supports treating capability debt as a forward-looking risk signal, because weak safety nets and weak feedback loops become more damaging as AI raises change volume and action frequency. ([inference]; low confidence; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report)
  5. Pre-existing capability debt becomes a stronger risk amplifier under agentic AI because machine-speed action removes the practical buffering effect of human pace while old management models, review queues, and escalation habits remain too slow to compensate. ([inference]; medium confidence; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://davidamitchell.github.io/Research/research/2026-04-26-implicit-rate-limiting-controls-agentic-ai-removal.html)
  6. Skill decay should be treated as part of capability debt because AI assistance can weaken human judgment and hide deterioration, which reduces the organisation's ability to review, challenge, and safely contain faster automated output over time. ([inference]; medium confidence; source: https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html; https://davidamitchell.github.io/Research/research/2026-05-08-ai-skill-decay-deskilling-measurement-interventions.html)
  7. The reviewed frameworks support a sequencing rule in which organisations reduce capability debt first on high-consequence workflows and grant broader autonomy only after explicit controls, inventory, oversight rules, and evaluation evidence are already in place. ([inference]; medium confidence; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/)
  8. Promoting individual AI tools without investing in shared review systems, platform quality, training, and governance creates hidden organisational debt because local productivity rises faster than the collective capacity needed to verify, escalate, and sustain safe use. ([inference]; medium confidence; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html)

Evidence map:

Claim Source Confidence Notes
[inference] Capability debt is a composite gap between required and present organisational prerequisites for safe AI use. http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/ medium Synthesis claim grounded in debt metaphor plus explicit capability frameworks.
[inference] A usable capability-debt scorecard must combine process, culture, governance, platform, workaround, control, and skill indicators. https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8 medium Multi-source synthesis because no single framework covers all dimensions.
[inference] Workaround adoption is a demand signal produced by slow or poorly fitted sanctioned capability, so workaround prevalence can be used as a leading indicator of unmet organisational need and rising governance risk. https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6 medium The demand-signal framing is a synthesis on top of well-supported workaround evidence.
[inference] DORA's amplifier finding supports using capability debt as a forward-looking risk signal because weak safety nets become more harmful as AI throughput rises. https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report low Interpretive extension from one primary DORA source rather than a directly stated DORA claim.
[inference] Capability debt amplifies agentic-AI risk because machine-speed action outruns human-paced review and escalation. https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://davidamitchell.github.io/Research/research/2026-04-26-implicit-rate-limiting-controls-agentic-ai-removal.html medium Strong mechanism support, but the exact composite term remains synthetic.
[inference] Skill decay should be included in capability debt measurement because weaker human judgment reduces review quality over time. https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html; https://davidamitchell.github.io/Research/research/2026-05-08-ai-skill-decay-deskilling-measurement-interventions.html medium Taxonomy placement is interpretive even though the underlying skill-decay mechanism is evidenced and cross-checked against a dedicated completed item.
[inference] Organisations should reduce capability debt first on high-consequence workflows and grant broader autonomy only after controls and evaluation evidence exist. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/ medium Sequencing rule is an assembled conclusion rather than a named framework.
[inference] Tool-led rollout without shared capability investment creates hidden organisational debt by overloading review and governance capacity. https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html medium Strong conceptual support, limited direct longitudinal field measurement.

Assumptions:

  • [assumption; source: https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] A composite scorecard is more decision-useful than a single score because different debt classes fail in different ways and need different interventions.
  • [assumption; source: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Westrum's healthcare safety-culture typology generalises sufficiently to enterprise AI governance because both settings depend on escalation quality, information flow, and the treatment of bad news.
  • [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Some low-risk debt can be tolerated in bounded advisory use cases because the reviewed frameworks support progressive, risk-tiered autonomy rather than all-or-nothing deployment decisions.

Analysis:

The evidence weighs most strongly in favour of treating capability debt as an operational synthesis construct rather than as an already-standardised academic term. [inference; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/]

That synthesis is still rigorous because each component of the construct is independently evidenced: process maturity is appraisable, information culture predicts safety performance, AI governance requires inventory and oversight, workflow quality determines whether AI amplification is stabilising or destabilising, and workaround prevalence reveals unmet demand. [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks]

The competing interpretation is that organisations should simply deploy AI quickly and rely on later governance hardening, but the reviewed sources point the other way on high-consequence surfaces because they repeatedly require explicit controls, lifecycle oversight, and safety nets before broad autonomy is expanded. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/]

The strongest rival remedy is to preserve traditional human review rather than reducing capability debt, but MIT Sloan and AWS both warn that generic human-in-the-loop approval collapses when volume rises, which means staffing alone does not solve the structural gap unless review rules, thresholds, skills, and external controls are also redesigned. [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://davidamitchell.github.io/Research/research/2026-05-02-hitl-review-volume-bottleneck-rubber-stamp.html]

Risks, gaps, uncertainties:

  • [fact; source: https://cmmiinstitute.com/learning/appraisals; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] No reviewed source provides a validated off-the-shelf capability-debt index tied directly to later AI incident rates.
  • [fact; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] Shadow-AI and LCNC evidence is strong on drivers and prevalence, but much of it remains survey-based or synthesis-based rather than longitudinal causal measurement.
  • [fact; source: https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8] The skill-decay source is theoretically strong but does not yet provide enterprise-scale incident correlations for AI reviewer populations.
  • [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Agentic-AI governance literature is moving quickly, so some sequencing guidance will likely become more explicit over the next review cycle.

Open questions:

  • [inference; source: https://cmmiinstitute.com/learning/appraisals; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Which scorecard thresholds best separate tolerable from intolerable capability debt for specific workflow classes such as advisory, read-only, and write-capable operations?
  • [inference; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://link.springer.com/article/10.1007/s10257-020-00472-6] Which workaround signals most reliably distinguish healthy local experimentation from evidence of systemic sanctioned-path failure?
  • [inference; source: https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] What reviewer-practice regime preserves human judgment best once agents are operating continuously at enterprise scale?

§7 Recursive Review

  • Labels: complete across Research Skill Output; adjacent completed items re-scanned; GitHub Pages URLs used where cited
  • Confidence: medium, because capability debt is a synthesis construct assembled from multiple sources rather than a named canonical framework
  • Mechanics: no em dash characters; first-use checks applied to Artificial Intelligence (AI), agentic AI, Information Technology (IT), Low-Code/No-Code (LCNC), National Institute of Standards and Technology (NIST), AI Risk Management Framework (AI RMF), DevOps Research and Assessment (DORA), Amazon Web Services (AWS), Boston Consulting Group (BCG), and Capability Maturity Model Integration (CMMI)

Findings

Executive Summary

The accumulated shortfall between the organisational capabilities required for safe AI scale and the capabilities actually present in practice should be tracked as a leading indicator of future AI-related risk rather than as a lagging description of incidents that have already happened. [inference; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report]

Capability debt is used here as shorthand for that shortfall, because the reviewed sources provide the component parts of the construct but do not standardise the label itself. [inference; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/]

Agentic AI, used here to mean autonomous, goal-directed AI systems that can plan and execute actions with limited continuous human oversight, amplifies pre-existing capability debt because the same organisations that already rely on workarounds or weak review culture are then asked to govern machine-speed action with unchanged or deteriorating review capacity. [inference; source: https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8]

The strongest practical conclusion is a sequencing rule, reduce capability debt first on high-consequence control surfaces and allow broader autonomy only where deterministic controls, inventory, oversight rules, and evaluation evidence already exist. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/]

Key Findings

  1. Capability debt is not a settled literature term, but it can be rigorously operationalised as the accumulated gap between the organisational capabilities required for safe, reviewable, governable AI use and the capabilities actually present in day-to-day practice. ([inference]; medium confidence; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/)
  2. A defensible capability-debt scorecard should combine process appraisal, information-flow culture, governance and inventory coverage, platform and safety-net quality, workaround prevalence, deterministic-control coverage, and workforce skill freshness instead of collapsing risk into a single simplistic metric. ([inference]; medium confidence; source: https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8)
  3. Shadow IT, shadow AI, and citizen-development evidence shows that workaround adoption is usually a demand signal produced by slow or poorly fitted sanctioned capability, which supports treating workaround prevalence as a leading indicator of unmet organisational need and rising governance risk. ([inference]; medium confidence; source: https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6)
  4. DORA's evidence that AI amplifies existing workflow and platform quality supports treating capability debt as a forward-looking risk signal, because weak safety nets and weak feedback loops become more damaging as AI raises change volume and action frequency. ([inference]; low confidence; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report)
  5. Pre-existing capability debt becomes a stronger risk amplifier under agentic AI because machine-speed action removes the practical buffering effect of human pace while old management models, review queues, and escalation habits remain too slow to compensate. ([inference]; medium confidence; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://davidamitchell.github.io/Research/research/2026-04-26-implicit-rate-limiting-controls-agentic-ai-removal.html)
  6. Skill decay should be treated as part of capability debt because AI assistance can weaken human judgment and hide deterioration, which reduces the organisation's ability to review, challenge, and safely contain faster automated output over time. ([inference]; medium confidence; source: https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html; https://davidamitchell.github.io/Research/research/2026-05-08-ai-skill-decay-deskilling-measurement-interventions.html)
  7. The reviewed frameworks support a sequencing rule in which organisations reduce capability debt first on high-consequence workflows and grant broader autonomy only after explicit controls, inventory, oversight rules, and evaluation evidence are already in place. ([inference]; medium confidence; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/)
  8. Promoting individual AI tools without investing in shared review systems, platform quality, training, and governance creates hidden organisational debt because local productivity rises faster than the collective capacity needed to verify, escalate, and sustain safe use. ([inference]; medium confidence; source: https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html)

Evidence Map

Claim Source Confidence Notes
[inference] Capability debt is a composite gap between required and present organisational prerequisites for safe AI use. http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/ medium Synthesis claim grounded in debt metaphor plus explicit capability frameworks.
[inference] A usable capability-debt scorecard must combine process, culture, governance, platform, workaround, control, and skill indicators. https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8 medium Multi-source synthesis because no single framework covers all dimensions.
[inference] Workaround adoption is a demand signal produced by slow or poorly fitted sanctioned capability, so workaround prevalence can be used as a leading indicator of unmet organisational need and rising governance risk. https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6 medium The demand-signal framing is a synthesis on top of well-supported workaround evidence.
[inference] DORA's amplifier finding supports using capability debt as a forward-looking risk signal because weak safety nets become more harmful as AI throughput rises. https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report low Interpretive extension from one primary DORA source rather than a directly stated DORA claim.
[inference] Capability debt amplifies agentic-AI risk because machine-speed action outruns human-paced review and escalation. https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://davidamitchell.github.io/Research/research/2026-04-26-implicit-rate-limiting-controls-agentic-ai-removal.html medium Strong mechanism support, but the exact composite term remains synthetic.
[inference] Skill decay should be included in capability debt measurement because weaker human judgment reduces review quality over time. https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://davidamitchell.github.io/Research/research/2026-05-02-incentive-misalignment-shadow-ai-skill-decay-controls.html; https://davidamitchell.github.io/Research/research/2026-05-08-ai-skill-decay-deskilling-measurement-interventions.html medium Taxonomy placement is interpretive even though the underlying skill-decay mechanism is evidenced and cross-checked against a dedicated completed item.
[inference] Organisations should reduce capability debt first on high-consequence workflows and grant broader autonomy only after controls and evaluation evidence exist. https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/ medium Sequencing rule is an assembled conclusion rather than a named framework.
[inference] Tool-led rollout without shared capability investment creates hidden organisational debt by overloading review and governance capacity. https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://davidamitchell.github.io/Research/research/2026-04-24-business-led-low-code-agent-governance.html medium Strong conceptual support, limited direct longitudinal field measurement.

Assumptions

  • [assumption; source: https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] A composite scorecard is more decision-useful than a single score because different debt classes fail in different ways and need different interventions.
  • [assumption; source: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Westrum's healthcare safety-culture typology generalises sufficiently to enterprise AI governance because both settings depend on escalation quality, information flow, and the treatment of bad news.
  • [assumption; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] Some low-risk debt can be tolerated in bounded advisory use cases because the reviewed frameworks support progressive, risk-tiered autonomy rather than all-or-nothing deployment decisions.

Analysis

The evidence weighs most strongly in favour of treating capability debt as an operational synthesis construct rather than as an already-standardised academic term. [inference; source: http://c2.com/doc/oopsla92.html; https://martinfowler.com/bliki/TechnicalDebtQuadrant.html; https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/]

That synthesis is still rigorous because each component of the construct is independently evidenced: process maturity is appraisable, information culture predicts safety performance, AI governance requires inventory and oversight, workflow quality determines whether AI amplification is stabilising or destabilising, and workaround prevalence reveals unmet demand. [inference; source: https://cmmiinstitute.com/learning/appraisals; https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1765804/; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://link.springer.com/article/10.1007/s10257-020-00472-6; https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks]

The competing interpretation is that organisations should simply deploy AI quickly and rely on later governance hardening, but the reviewed sources point the other way on high-consequence surfaces because they repeatedly require explicit controls, lifecycle oversight, and safety nets before broad autonomy is expanded. [inference; source: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/]

The strongest rival remedy is to preserve traditional human review rather than reducing capability debt, but MIT Sloan and AWS both warn that generic human approval collapses when volume rises, which means staffing alone does not solve the structural gap unless review rules, thresholds, skills, and external controls are also redesigned. [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/; https://davidamitchell.github.io/Research/research/2026-05-02-hitl-review-volume-bottleneck-rubber-stamp.html]

Risks, Gaps, and Uncertainties

  • [fact; source: https://cmmiinstitute.com/learning/appraisals; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/; https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report] No reviewed source provides a validated off-the-shelf capability-debt index tied directly to later AI incident rates.
  • [fact; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://research.universityofgalway.ie/en/publications/adoption-of-low-code-and-no-code-development-a-systematic-literat-6] Shadow-AI and LCNC evidence is strong on drivers and prevalence, but much of it remains survey-based or synthesis-based rather than longitudinal causal measurement.
  • [fact; source: https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8] The skill-decay source is theoretically strong but does not yet provide enterprise-scale incident correlations for AI reviewer populations.
  • [inference; source: https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/; https://sloanreview.mit.edu/article/agentic-ai-at-scale-redefining-management-for-a-superhuman-workforce/] Agentic-AI governance literature is moving quickly, so some sequencing guidance will likely become more explicit over the next review cycle.

Open Questions

  • [inference; source: https://cmmiinstitute.com/learning/appraisals; https://airc.nist.gov/airmf-resources/airmf/5-sec-core/] Which scorecard thresholds best separate tolerable from intolerable capability debt for specific workflow classes such as advisory, read-only, and write-capable operations?
  • [inference; source: https://www.ibm.com/think/insights/rising-ai-adoption-creating-shadow-risks; https://link.springer.com/article/10.1007/s10257-020-00472-6] Which workaround signals most reliably distinguish healthy local experimentation from evidence of systemic sanctioned-path failure?
  • [inference; source: https://cognitiveresearchjournal.springeropen.com/articles/10.1186/s41235-024-00572-8; https://aws.amazon.com/blogs/security/four-security-principles-for-agentic-ai-systems/] What reviewer-practice regime preserves human judgment best once agents are operating continuously at enterprise scale?

Output

Navigation

Home

By Tag

bureaucracy

change-management

coase

constraint-analysis

control-model

decision-rights

delegation

delivery-risk

demand-segmentation

enterprise

exception-handling

execution

flow

flow-design

flow-metrics

governance

governance-patterns

incentives

instability

institutional-economics

leading-indicators

operating-model

organisation

organisational-design

queue-design

queueing

regulated-enterprise

routing

throughput

throughput-risk

transaction-costs

triage

williamson

Clone this wiki locally