1. Introduction

Artificial intelligence (AI)-enabled systems, such as automation, data-driven decision-making, large language models (LLMs), and cyber-physical architectures, are reshaping organisational processes through distributed and model-centric information flows. This review focuses on data-driven and model-centric AI-enabled systems because this is where the reviewed information governance (IG) literature is most concentrated. These systems reconfigure how organisations coordinate work, manage inter-organisational data exchange, and embed algorithmic outputs into operational decisions [1, 2]. Algorithmic intelligence now augments human judgement in sectors, such as healthcare, manufacturing, public administration, and digital services, improving responsiveness while also increasing governance complexity [3, 4].

At the same time, the scale, velocity, and heterogeneity of data in AI-driven environments have altered how information is generated, interpreted, reused, and controlled. Modern AI relies on high-velocity data streams across clinical, regulatory, and cyber-physical domains [5, 6]. Privacy risks are increasingly embedded in inferred knowledge produced by models, even when explicit identifiers are removed [7]. Although federated learning and related privacy-enhancing technologies can reduce direct data exposure, distributed pipelines introduce new privacy-utility trade-offs, accountability challenges, and coordination demands [8, 9]. Automated curation and metadata governance have therefore become essential for maintaining data quality, Findability, Accessibility, Interoperability, and Reusability (FAIR) alignment, and lifecycle-level traceability [10].

These developments introduce IG challenges that go beyond traditional data management. The opacity of AI architectures creates new vectors for privacy leakage, while accountability becomes diffused across algorithms, developers, organisational decision makers, domain experts, and end users [11, 12]. Data quality deficiencies further undermine explainability, necessitating automated quality control and standardisation [13]. In high-risk domains, reliance on black-box models constrains deployment, motivating the need for explainable AI (XAI) and the management of interpretive trade-offs [14].

Consequently, IG has evolved from a technical control function into a socio-technical organisational challenge. Effective governance requires the continuous integration of technical safeguards with human judgement, organisational capability, and ethical deliberation [15, 16]. Accountability is socially constructed through governance tools, role allocations, and institutional procedures rather than being solely embedded in system design [17]. In practice, socio-technical IG is instantiated through workflow-level design choices and interdisciplinary arrangements that combine AI tools with expert judgement [18, 19].

This study frames AI-enabled IG through dynamic capability theory. Dynamic capabilities refer to an organisation’s capacity to sense environmental change, seize opportunities and risks through strategic action, and reconfigure resources, routines, and competencies as conditions evolve [2022]. This framing is appropriate because AI governance challenges are not static. They require organisations to detect emerging data, model, regulatory, and accountability risks, embed governance controls into AI workflows, and revise roles and competencies as technologies and institutional expectations change.

Prior scholarship defines AI governance (AIG) as a multidimensional system aligning AI deployment with organisational strategy and ethics [23]. The existing reviews have advanced the field by mapping AI governance themes, ethical frameworks, and data governance mechanisms [2426]. However, they provide limited explanation of how IG functions, AI technologies, human roles, and professional competencies operate together as a dynamic organisational capability. This review addresses that gap by synthesising the operational mechanisms through which governance is enacted across the AI lifecycle and by linking them to sensing, seizing, and reconfiguring processes.

  • Research question (RQ)1: What IG functions are implemented in AI-enabled systems across different sectors?

  • RQ2: What AI technologies and methods are utilised to support IG processes?

  • RQ3: What are the human roles and responsibilities in managing IG within AI-enabled systems?

  • RQ4: What skill sets and competencies are required for professionals to effectively govern these systems?

In this review, IG is conceptualised as an organisational capability encompassing structures, processes, roles, and competencies that regulate information across the AI system lifecycle within AI-enabled socio-technical systems. AI-enabled socio-technical systems are defined as AI applications embedded in organisational, regulatory, and human workflows where technical components interact with institutional roles, policies, and social practices. The term ‘AI-enabled systems’ in this paper refers primarily to data-driven and model-centric systems, while symbolic, knowledge-based, and hybrid neuro-symbolic AI are discussed as an important boundary condition and future research direction.

The study therefore makes three contributions. First, it consolidates IG functions across sectors rather than treating governance as a purely technical or legal issue. Second, it integrates technological enablers with human roles and competencies to address the implementation gap in AI governance. Third, it develops a theory-oriented interpretation of AI-enabled IG as a dynamic capability that connects governance mechanisms with organisational sensing, seizing, and reconfiguring.

2. Literature Review

2.1. The Changing Landscape of Information Governance in AI-Enabled Systems

The rapid diffusion of data-driven AI-enabled systems has reshaped the scope of IG. As organisations increasingly operate through distributed, model-centric, and data-intensive architectures, governance challenges extend beyond conventional data management towards accountability, privacy, transparency, reliability, and lifecycle traceability. This shift is visible in healthcare, Industry 4.0, urban mobility, and cyber-physical environments, where heterogeneous and high-velocity data intensify governance complexity and magnify the risks of automated decision-making [5, 2729]. Privacy threats are no longer confined to explicit identifiers, because AI systems can infer sensitive attributes from anonymised data, thereby challenging lawful use, integrity, and control of information [1, 30, 31]. Cloud-based LLMs and multi-agent generative AI further intensify these concerns by introducing opaque decision pathways and cross-organisational data flows [18]. Within this landscape, IG in AI-enabled systems is operationalised through interdependent functions designed to sustain trustworthy and compliant operation, including privacy protection, accountability and transparency, data quality assurance, regulatory compliance, and risk management. These functions are supported by technologies such as homomorphic encryption, differential privacy, federated learning, blockchain-based provenance, and XAI [14, 27, 32, 33]. AI has also become an enabler of governance by automating information extraction, document classification, audit preparation, and sensitive-content detection through natural language processing (NLP), machine learning (ML), and LLM-based workflows [3437]. Accordingly, governance is no longer only imposed on AI infrastructures from outside, it is increasingly embedded within the infrastructures, pipelines, and workflows through which AI systems operate.

2.2. Human-Centred Governance and the Implementation Gap

Despite the growth of technical governance mechanisms, the reviewed literature repeatedly shows that AI-enabled IG cannot be reduced to privacy technologies, audit tools, or compliance checklists. Governance is enacted through people who define acceptable risk, interpret model outputs, allocate accountability, translate legal requirements into workflows, and decide when automated systems should be trusted, challenged, or constrained. This human-centred dimension is especially visible in high-stakes contexts, such as clinical decision support, public administration, and legal or auditing environments, where domain experts, managers, regulators, auditors, and affected communities mediate between technical system behaviour and institutional responsibility [16, 3842]. The implementation gap therefore concerns not only the absence of governance tools but also the absence of clear role architectures, escalation pathways, cross-functional competencies, and feedback loops through which governance can adapt as AI systems evolve. Prior work identifies developer-centric bias as a persistent weakness because responsible AI tools often emphasise technical builders while underrepresenting organisational leaders, domain specialists, users, and communities affected by AI decisions [42]. A human-centred IG perspective responds to this gap by treating governance as a socio-technical practice distributed across technical, managerial, legal, ethical, and operational actors. This provides the basis for examining IG as a capability that must be learned, maintained, and reconfigured rather than as a fixed compliance routine.

2.3. Dynamic Capability Theory and Information Governance

Dynamic capability theory distinguishes adaptive organisational capabilities from ordinary operational routines. Teece et al. conceptualise dynamic capabilities as the capacity to integrate, build, and reconfigure internal and external competences in response to rapidly changing environments [20]. Eisenhardt and Martin further argue that dynamic capabilities consist of identifiable processes, such as product development, strategic decision-making, and alliancing, whose value depends on how they help organisations adapt under changing conditions [21]. Teece later specifies the microfoundations of dynamic capabilities as sensing, seizing, and reconfiguring [22].

This distinction is important for the present review because not every governance routine is dynamic. Codified policies, audit forms, and compliance workflows may stabilise organisational behaviour, but they become dynamic capabilities only when they enable organisations to detect changing AI-related risks, convert those signals into governance action, and reconfigure technical, procedural, and human resources. In AI-enabled IG, sensing includes detecting data quality failures, privacy leakage, model drift, accountability gaps, and regulatory change. Seizing includes embedding privacy-preserving architectures, explainability tools, audit mechanisms, and role allocations into AI workflows. Reconfiguring includes revising governance structures, professional competencies, and workflow responsibilities as technologies and institutional expectations evolve. This framework anchors the review’s claim that IG can function as a dynamic capability rather than merely as a static compliance instrument.

2.4. Previous Works

Prior studies on AIG define governance as a multidimensional system aligned with organisational strategy and ethical principles [23, 24]. Related reviews have mapped AI governance principles, responsible AI tools, ethical frameworks, and general data governance mechanisms [2426, 42]. However, these reviews tend to emphasise either broad governance themes, ethical principles, or data governance concepts while offering limited synthesis of how operational IG functions, AI technologies, human roles, and competencies interact as a dynamic organisational capability. The present study therefore focuses on implementation-oriented IG within data-driven AI-enabled systems and positions human agency, technical enablers, and organisational adaptation as interdependent elements of governance. As shown in Figure 1 and Tables 1 and 2, prior research is concentrated in theoretical, ethical, or techno-centric domains, while implementation-oriented work remains fragmented across sectors and often focused on developer-centric tools. Consequently, a major gap persists in integrating procedural IG implementation, non-technical actors, and hybrid competencies within a unified socio-technical governance perspective across the AI lifecycle.

Figure 1

Strategic mapping of research maturity and target novelty area.

https://www.acigjournal.com/f/fulltexts/225267/ACIG-5-225267-g001_min.jpg
Table 1

Positioning of the present review against related reviews.

Related
review
Primary focusRemaining gap for this studyPresent study’s contribution
Birkstedt et al. [23]AI governance themes, knowledge gaps, and future agendas.Provides broad AI governance mapping but less operational detail on information governance (IG) functions, roles, and competencies.Links IG functions, technologies, roles, and competencies to operational governance capability.
Batool et al.[24]Systematic review of AI governance concepts and dimensions.Covers overlapping governance territory but does not theorise IG as a dynamic capability.Develops a dynamic capability interpretation using sensing, seizing, and reconfiguring.
Kuehnert et al. [42]Responsible AI governance tools by actor and AI lifecycle stage.Identifies actor–stage bias but is less focused on IG as an organisational capability across sectors.Extends actor analysis towards cross-functional human roles and competency clusters.
Ismail and Ahmad [25]Ethical and governance frameworks for AI.Strong on governance principles but weaker on implementation mechanisms and human role architectures.Synthesises implementation mechanisms and socio-technical governance responsibilities.
Bližnák et al. [26]Recent data governance literature.Focuses on data governance broadly rather than AI-enabled IG and model-centric governance.Specifies how data governance concerns become lifecycle IG issues in AI-enabled systems.
Table 2

Synthesis matrix of contemporary AI-enabled information governance (IG) studies across sectors.

Focus and IG functionsTechnologies and methodsHuman agency and skillsCritical gap/synthesisSources
Lifecycle Audit and policy: risk mitigation and strategic alignmentTOE framework; risk-tiered regulatory and policy toolsMulti-tier accountability (team to national)Decision gap: lack of guidance for tool selection[25, 42]
Clinical AI: FAIR principles, data quality, and clinical safetyHybrid data lakehouses; clinical decision support system (CDSS); Digital tumour boardsClinicians and leaders; human-centric care skillsImplementation gap: lack of operational procedures[38, 43, 44]
Responsible AI: decentralised privacy and accountabilityBlockchain; federated learning; smart contractsCritiques developer bias; excludes non-tech leadersActor imbalance: tools neglect leaders and end-users[42, 45]
Digital audit: public sector accountability and monitoringAI-driven real-time monitoring and reportingAuditors and administrative leaders; tech agilityRegulatory gap: lacks international coordination[39, 46]
Public trust: citizen engagement and service interactionExplainable AI (XAI); trust transfer mechanismsCitizens and political leaders; digital literacySocio-technical gap: trust requires human ‘bridges’[4749]
Business IG: Data asset valuation and asset complianceSystem decomposition; business artificial intelligence governance (AIG) frameworksNovel governance roles; board of directorsPracticality gap: operational ambiguity in business[26, 50]
Predictive justice: efficiency and oversight in legal sectorsJustice 5.0; collaborative decision-making toolsLegal professionals vs. ‘Robot Judges’ conceptsEthical risk: rrosion of judicial discretion[51]
IT Maturity: strategic resource and IT risk controlBDG MAM (maturity model); 5V big data managementBoard-level committees; proactive AI mindsetHybrid paradigm: shift from ‘knowing’ to application[52, 53]

3. Method

This review followed Kitchenham’s three-phase framework of planning, conducting, and reporting to ensure rigour and reproducibility, while Preferred Reporting Items for Systematic reviews and Meta-Analyses (PRISMA) 2020 guided transparent identification, screening, eligibility assessment, and reporting procedures [5457]. The two frameworks were used for complementary purposes rather than as competing methodologies: Kitchenham structured the systematic review protocol and quality appraisal process, whereas PRISMA 2020 documented how records moved through identification, screening, eligibility, and inclusion. During planning, a review protocol specified the research questions, search strategy, inclusion and exclusion criteria, and quality assessment criteria (Figure 2 ). Study quality was appraised using established systematic literature review (SLR) guidelines, focusing on theoretical grounding, methodological rigour, clarity of objectives, credibility of findings, and contribution to the knowledge base [56, 5860].

Figure 2

Systematic literature review (SLR) protocol and study selection criteria.

https://www.acigjournal.com/f/fulltexts/225267/ACIG-5-225267-g002_min.jpg

A pilot test of 10 studies refined keywords before the search. The search was conducted in January 2025 and covered publications from 2020 to January 2025, including early-online 2025 studies available at the time of retrieval. Databases included IEEE Xplore, ACM Digital Library, AAAI Digital Library, ScienceDirect, SpringerLink, Wiley Online Library, Taylor & Francis Online, SAGE Journals, and Emerald Insight, with supplementary snowballing used to reduce omission bias [6165]. Scopus was not used as a primary search database because the protocol prioritised full-text and publisher-level retrieval from AI, computing, governance, and multidisciplinary databases. This decision may have limited coverage of organisational behaviour and management journals indexed primarily in Scopus, and it is acknowledged as a limitation.

A total of 4250 records were retrieved, of which 1350 were removed before screening because of duplication and metadata issues, leaving 2900 records for title and abstract screening. After excluding 2617 records and assessing 258 reports for eligibility, 78 studies met all inclusion criteria and were retained for final synthesis (Figure 3). To strengthen screening objectivity, two reviewers independently screened a random verification subset of 113 records. Inter-rater reliability yielded Cohen’s kappa = 0.82, indicating overall strong agreement [66]. Discrepancies were resolved through discussion until consensus was reached. Table 3 reports the agreement statistics. Data were analysed through thematic synthesis informed by Braun and Clarke’s thematic analysis [6769]. In this review, thematic analysis was applied to extracted secondary evidence, not to primary interview or observation data. Coding focused on IG functions, enabling AI technologies and methods, human roles and responsibilities, and competencies required for effective governance. The analysis followed the following six stages: familiarisation with included studies, initial coding, theme development, theme review, theme definition, and final synthesis. Table 4 links research questions with coded interpretations, original evidence, and source studies, while Table 5 illustrates how lower-level codes were aggregated into higher-level categories and overarching themes.

Figure 3

The Preferred Reporting Items for Systematic reviews and Meta-Analyses (PRISMA) flow diagram of the study selection process.

https://www.acigjournal.com/f/fulltexts/225267/ACIG-5-225267-g003_min.jpg
Table 3

Inter-rater reliability summary for manuscript screening.

MetricValueExplanation
Double-screened verification subset113 recordsRandom subset used to assess screening consistency.
Agreements106Records for which both reviewers reached the same include/exclude decision.
Disagreements7Records requiring discussion and consensus resolution.
Percentage agreement93.8%Calculated as 106/113.
Cohen’s kappa0.82Indicates strong inter-rater agreement according to Landis and Koch [66].
Resolution processConsensus discussionAll disagreements were discussed until a final decision was agreed.
Table 4

Mapping of research questions (RQs) to thematic codes and evidence sources.

RQsCodificationSource
What information governance (IG) functions are implemented in AI-enabled systems across different sectors?Establishes model governance and validation mechanisms to ensure trustworthy and reliable AI systems.P1: organisations are more likely to detect emergent AI governance risks when data quality, provenance, explainability, and risk monitoring are integrated into continuous review processes.
What IG functions are implemented in AI-enabled systems across different sectors?Promotes transparency and explainability to enhance accountability and user trust.P1
What IG functions are implemented in AI-enabled systems across different sectors?Defines human-in-the-loop role delineation to maintain oversight in automated processes.P1
What IG functions are implemented in AI-enabled systems across different sectors?Emphasises high data quality and consistent labelling standards for robust AI performance.P1
What IG functions are implemented in AI-enabled systems across different sectors?Implements bias and risk assessment as part of ethical AI evaluation.P1
Table 5

Illustrative example of the qualitative codification process mapping specific competencies to thematic domains.

Competency / SkillMapped CategoryOverarching Proficiency Domain
Maintains regulatory literacy on GDPR/HIPAARegulatory Compliance & PrivacyEthical & Governance Literacy
Applies data annotation for privacyRegulatory Compliance & PrivacyEthical & Governance Literacy
FOIA & privacy ethicsRegulatory Compliance & PrivacyEthical & Governance Literacy
Understands PDPA regulationsRegulatory Compliance & PrivacyEthical & Governance Literacy
Bias and fairness awarenessAI Ethics & FairnessEthical & Governance Literacy
Ethics policy literacyAI Ethics & FairnessEthical & Governance Literacy
Risk-based incident handlingAI Ethics & FairnessEthical & Governance Literacy
Balances algorithmic accuracy with ethicsAI Ethics & FairnessEthical & Governance Literacy
Data governance standards (COSO/IIA)Governance FrameworksEthical & Governance Literacy
Audit readiness skillsGovernance FrameworksEthical & Governance Literacy
Responsible AI workflowsGovernance FrameworksEthical & Governance Literacy
Accountability skillsGovernance FrameworksEthical & Governance Literacy
IP and FDA law literacyLegal & IP LiteracyEthical & Governance Literacy
Translating complex legal text to rulesLegal & IP LiteracyEthical & Governance Literacy
Medical consent lawsLegal & IP LiteracyEthical & Governance Literacy
R programming workflowsAdvanced ML & Data EngineeringTechnical & Analytical Proficiency
NLP (Word2Vec) techniquesAdvanced ML & Data EngineeringTechnical & Analytical Proficiency
ML ensemble algorithmsAdvanced ML & Data EngineeringTechnical & Analytical Proficiency
Data preprocessing and feature engineeringAdvanced ML & Data EngineeringTechnical & Analytical Proficiency
Differential privacy engineeringSecurity & Privacy TechTechnical & Analytical Proficiency
Cryptography literacySecurity & Privacy TechTechnical & Analytical Proficiency
AI-driven threat analysisSecurity & Privacy TechTechnical & Analytical Proficiency
Secure protocol designSecurity & Privacy TechTechnical & Analytical Proficiency
Model interpretability competenceExplainable AI (XAI)Technical & Analytical Proficiency
XAI developmentExplainable AI (XAI)Technical & Analytical Proficiency
UI trust monitoringExplainable AI (XAI)Technical & Analytical Proficiency
AI performance metrics evaluationExplainable AI (XAI)Technical & Analytical Proficiency
Cloud infrastructure managementSystem Architecture & QATechnical & Analytical Proficiency
ISO/IEC 25010 QA standardsSystem Architecture & QATechnical & Analytical Proficiency
Site Reliability Engineering (SRE)System Architecture & QATechnical & Analytical Proficiency
Industrial process integrationSystem Architecture & QATechnical & Analytical Proficiency
Figure 4

Distribution of included studies across digital libraries and publishers.

https://www.acigjournal.com/f/fulltexts/225267/ACIG-5-225267-g004_min.jpg

4. Results

This review synthesised 78 peer-reviewed studies published between 2020 and January 2025 to map the operational landscape of AI-enabled information governance. The corpus shows a marked increase in publications after 2021, indicating growing institutional attention to governance challenges in distributed and model-centric AI environments (Figs. 5 and 6). Compared with an earlier work centred on abstract ethical principles, the reviewed studies reflect a shift towards operational governance mechanisms embedded in real organisational settings. The findings are organised into four interrelated domains: governance functions, enabling technologies, human roles and responsibilities, and professional competencies. Only representative references are shown in the main text tables, while the full study-to-theme mapping is provided in the Supplementary Material.

Figure 5

Publication trend of AI-enabled information governance (IG) research over the study period.

https://www.acigjournal.com/f/fulltexts/225267/ACIG-5-225267-g005_min.jpg
Figure 6

Thematic mapping of technological enablers, core functions, and human-centred governance roles within the AI-enabled information governance (IG) domain.

https://www.acigjournal.com/f/fulltexts/225267/ACIG-5-225267-g006_min.jpg

4.1. Mapping IG Functions

Studies identify five recurring IG functions across the AI data and model lifecycle: accountability and transparency, data quality and integrity, ethical and privacy-by-design governance, compliance and audit assurance, and security and risk management. Across the reviewed sectors, the most consistently emphasised functions are accountability, data quality, and privacy-oriented governance, reflecting shared concerns with traceability, reliability, and lawful data use in increasingly distributed AI environments. Accountability and transparency are typically operationalised through model explanation tools, provenance capture, and process documentation that support reviewability and post hoc justification [7072]. In parallel, data quality and integrity are treated as foundational to institutional trust, with studies highlighting metadata governance, audit trails, and alignment with FAIR and International Organization for Standardization (ISO) standards to preserve accuracy across the lifecycle [10, 73, 74]. Ethical and privacy-by-design mechanisms further reinforce these functions by embedding fairness, consent, and explainability into both design-time and run-time governance through approaches such as federated learning, differential privacy, and institutional review board (IRB)-aligned oversight [13, 31, 75].

The remaining functions, namely compliance and audit assurance, and security and risk management, most often appear as mechanisms that institutionalise and sustain these core governance priorities under sector-specific constraints. In healthcare, IG functions are closely tied to patient safety, privacy protection, and visible human oversight; in industrial settings, they are oriented towards operational resilience, real-time monitoring, and document or process traceability; while in public administration, they are linked more strongly to auditability, regulatory legitimacy, and formal accountability structures [19, 29, 76, 77]. Across these contexts, compliance is commonly enacted through data protection impact assessments (DPIAs), telemetry, and human-in-the-loop controls aligned with General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), or the European Union (EU) AI Act, whereas security and risk management support prevention, detection, and response through access governance, anomaly detection, privacy budgets, and tamper-evident controls [17, 7880]. However, the literature also reveals unresolved tensions, particularly fragmented accountability structures, uneven governance maturity, and persistent trade-offs between transparency, confidentiality, and operational efficiency in distributed deployments [9, 15, 35, 81]. Table 6 summarises the thematic mapping of these IG functions, while the complete study-to-theme mapping is provided in Table S1.

Table 6

Thematic summary of information governance (IG) functions.

ThemeNo. of studiesRepresentative references
Accountability and transparency55[14, 17, 70]
Data quality and integrity55[10, 73, 74]
Ethical governance and privacy34[1, 31, 75]
Compliance and audit assurance9[19, 82, 83]
Security and risk management5[12, 30, 33]

4.2. Mapping AI Technologies Supporting Information Governance

Studies identify six recurring technological clusters that support IG in AI-enabled systems: privacy-preserving collaboration through federated learning, ethical and responsible AI design in machine-learning operations (MLOps), AI–blockchain integration, ML for anomaly detection, deep learning for information extraction, and AI-driven risk assessment. Across the literature, the dominant patterns are privacy-preserving collaboration, governance-by-design in MLOps, and infrastructure-level traceability, indicating that AI-enabled IG is increasingly operationalised through distributed, auditable, and privacy-aware architectures. Federated learning and related privacy-enhancing technologies are the most frequently reported enablers, supporting model training without raw data exchange through differential privacy, homomorphic encryption, secure multiparty computation, and adaptations for heterogeneous environments [31, 81, 84, 85]. Ethical and responsible AI design complements these mechanisms by embedding fairness-aware learning, explainability, accountability-by-design, and continuous monitoring within MLOps pipelines, while AI–blockchain integration strengthens provenance, consent automation, and decentralised trust across organisational boundaries [11, 12, 29, 83, 8688].

The remaining clusters, namely anomaly detection, information extraction, and AI-driven risk assessment, mainly function as operational tools for monitoring, multimodal oversight, and adaptive security response. Their emphasis varies by context: anomaly detection is more prominent in transactional and infrastructure-heavy settings, information extraction in document-intensive and multimodal environments, and risk-assessment tools where policy verification and threat propagation require continuous tracking [9, 70, 79, 89, 90]. Across sectors, however, the literature highlights persistent tensions, including scalability and latency constraints in federated and blockchain-based systems, performance-interpretability trade-offs in fairness-aware and explainability-driven models, and the limited generalisability of monitoring tools across governance contexts [2, 28, 72, 91]. Taken together, these findings suggest that AI technologies increasingly embed governance logic within the technical infrastructure of AI systems rather than merely supporting it from the outside. Table 7 summarises the technological clusters supporting information governance, while the complete study-to-theme mapping is provided in Table S2.

Table 7

Thematic summary of AI technologies supporting information governance.

ThemeNo. of studiesRepresentative references
Federated learning and data heterogeneity48[31, 81, 84]
Ethical and responsible AI design37[14, 83, 88]
AI–Blockchain integration for traceability and IP protection20[1, 29, 86]
Machine learning (ML) for anomaly and fraud detection15[9, 90, 92]
Deep learning for information extraction and leak detection7[35, 70, 93]
AI for risk assessment and security6[16, 17, 79]

4.3. Mapping Human Roles and Responsibilities in AI-Driven Governance Systems

The literature identifies five recurring role clusters in AI-enabled IG: ethical and governance oversight, technical development and validation, policy and regulatory frameworks, quality assurance and traceability, and system design and workflow integration. Across these clusters, the most dominant patterns are ethical oversight, technical validation, and regulatory coordination, showing that human involvement in AI governance is distributed across strategic, operational, and technical layers rather than concentrated in a single role. Ethical oversight remains central because developers, ethicists, and domain experts jointly sustain fairness, transparency, and professional accountability through human-in-the-loop arrangements, particularly in high-stakes contexts, such as healthcare and justice [31, 73, 9496]. Technical development and validation roles support this oversight through reproducible architectures, fairness testing, drift detection, and privacy-preserving controls, while policy and regulatory roles translate ethical principles into enforceable mechanisms through legal obligations, consent requirements, and escalation pathways [17, 29, 36, 85, 9799].

The remaining clusters, namely quality assurance and traceability, and system design and workflow integration, mainly function as operational mechanisms that embed governance into daily practice. Quality assurance roles emphasise audit trails, lineage records, and verification controls, whereas workflow integration roles embed governance requirements into development & operations (DevOps) and MLOps processes through interpretable interfaces and privacy-oriented system design [19, 30, 83, 86]. Their importance varies by context: regulated sectors prioritise traceability and formal accountability, while deployment-intensive settings emphasise integration and operational continuity. Across sectors, however, the literature highlights persistent tensions between rapid technical innovation and slower ethical or regulatory review as well as challenges in maintaining clear accountability across multiple actors and layers [1, 6, 8, 77]. Taken together, these findings suggest that human roles in AI-enabled IG are best understood as an interconnected governance architecture rather than a set of isolated responsibilities. Table 8 summarises the human roles and responsibilities in AI-driven governance systems, while the complete study-to-theme mapping is provided in Table S3.

Table 8

Thematic summary of human roles and responsibilities in AI-driven gover-nance systems.

ThemeNo. of studiesRepresentative references
Ethical and governance oversight71[31, 94, 95]
Technical development and validation64[36, 85, 99]
Policy and regulatory frameworks64[17, 29, 97]
Quality assurance and traceability25[19, 71, 86]
System design and workflow integration16[83, 100, 101]

4.4. Mapping Competencies and Skill Sets within the AI-Enabled IG Domain

The reviewed studies identify five recurring competency clusters for governing AI-enabled information systems: ethical and governance literacy, collaborative and legal awareness, technical and analytical proficiency, experimental and evaluation skills, and human-centred socio-technical competence. Across these clusters, the most dominant capabilities are governance literacy, technical–analytical proficiency, and cross-functional legal collaboration, indicating that effective IG depends on the ability to connect ethical principles, regulatory requirements, and system performance in practice. Governance literacy is central because professionals must translate fairness, accountability, and privacy into operational controls, while technical–analytical proficiency supports system design, monitoring, validation, and the use of privacy-enhancing and explainability tools [10, 17, 89, 97, 99]. Collaborative and legal awareness further enables coordination across disciplines and jurisdictions, particularly in relation to GDPR, consent, and cross-border data governance [15, 18, 86, 102].

Experimental and evaluation skills, together with human-centred socio-technical competence, mainly appear as operational capabilities that sustain governance in practice. These include auditing privacy-utility trade-offs, testing robustness, calibrating trust, and aligning system design with organisational and cultural contexts [3, 11, 33, 70, 81, 103, 107]. Their relative emphasis varies by sector: regulated environments prioritise legal literacy and auditability, whereas deployment-intensive settings stress technical validation and operational resilience. Across contexts, however, the literature reveals a persistent tension between rising governance complexity and the limited availability of professionals able to bridge compliance, engineering, and human-centred implementation. Taken together, these findings suggest that competency in AI-enabled IG is best understood as a hybrid capability architecture rather than a set of isolated skills. Table 9 summarises these competencies and skill sets, while the complete study-to-theme mapping is provided in Table S4.

Table 9

Thematic mapping of competencies and skill sets within the AI-enabled information governance (IG) domain.

ThemeNo. of studiesRepresentative references
Ethical and governance literacy13[17, 36, 97]
Collaborative and legal awareness29[15, 18, 86]
Technical and analytical proficiency38[72, 80, 104]
Experimental and evaluation skills24[14, 33, 81]
Human-centred and socio-technical competence25[3, 11, 103]

5. Discussion

The findings of this SLR show that AI-enabled IG is evolving from a post hoc compliance activity into a distributed, lifecycle-spanning capability embedded within data-driven AI systems [15, 72]. This interpretation is not based merely on the observation that governance is important. Rather, it rests on how the four thematic domains identified in the review interact: governance functions define what must be controlled, technologies provide mechanisms for operationalising control, human roles allocate interpretive and accountability responsibilities, and competencies determine whether organisations can adapt those mechanisms under changing technical and institutional conditions.

Viewed through dynamic capability theory, the five IG functions identified in the review can be interpreted as a capability architecture. Data quality and integrity, accountability and transparency, and security and risk management contribute to sensing because they help organisations detect unreliable data, opaque models, privacy leakage, bias, drift, and emerging threats. Ethical governance, privacy-by-design, compliance, and audit assurance contribute to seizing because they translate detected risks into design choices, controls, and institutional commitments. Human-centred oversight, workflow integration, and competency development support reconfiguring because they enable organisations to revise governance routines, redistribute accountability, and update professional skills as AI systems and regulations evolve [2022].

This mapping also addresses the critique that governance routines may be stable rather than dynamic. The review suggests that IG becomes dynamic only when stable routines, such as audit trails, DPIAs, data quality checks, and accountability documentation, are coupled with feedback mechanisms, monitoring tools, escalation pathways, and cross-functional decision-making. Without these adaptive elements, governance remains an ordinary operational routine. With them, it becomes a capability for sensing changing conditions, seizing governance options, and reconfiguring socio-technical arrangements.

Figure 6 consolidates the thematic mapping of technological enablers, core IG functions, and human-centred governance roles within the AI-enabled IG domain. The figure should be read as an integrative map rather than a causal model: it shows where technical precision and human agency intersect, but the explanatory logic emerges from the capability interpretation developed below.

To move from taxonomy to theory-building, Table 10 translates the thematic synthesis into propositions that can guide future empirical research. These propositions specify how technologies may enable or constrain governance functions, how human roles mediate these relationships, and why organisational maturity conditions the effectiveness of IG as a dynamic capability.

Table 10

Dynamic capability synthesis and propositions for AI-enabled information governance (IG).

Dynamic capability mechanismRelated IG functionsKey technology and method clustersHuman roles and competenciesTheory-building proposition
SensingData quality and integrity; accountability and transparency; security and risk management.Anomaly detection, information extraction, explainable AI (XAI), risk assessment, metadata governance.Auditors, domain experts, data stewards, security analysts, and governance leaders with analytical and ethical literacy.P1: organisations are more likely to detect emergent AI governance risks when data quality, provenance, explainability, and risk monitoring are integrated into continuous review processes.
SeizingEthical governance and privacy; compliance and audit assurance.Federated learning, differential privacy, homomorphic encryption, responsible MLOps, AI–blockchain traceability.Legal, compliance, technical, and managerial actors able to convert governance signals into deployable controls.P2: privacy-preserving and traceability technologies strengthen IG only when organisations can translate them into concrete design choices, accountability rules, and audit procedures.
ReconfiguringCross-functional accountability; workflow integration; competency development.MLOps feedback loops, lifecycle documentation, workflow-level governance tools, adaptive monitoring.Leaders, developers, domain experts, and users who can redistribute responsibilities and update governance routines.P3: AI-enabled IG becomes a dynamic capability when organisations revise roles, workflows, and competencies in response to changes in data, models, regulation, and stakeholder expectations.
Boundary
condition
Inclusive governance and organisational maturity.Technology choices calibrated to sectoral risk, infrastructure maturity, and institutional capacity.Stakeholders able to align governance tools with local constraints and affected communities.P4: the effectiveness of AI-enabled IG depends on fit between technological complexity and organisational maturity; excessive dependence on advanced infrastructures may reproduce governance inequality.

These propositions extend the descriptive taxonomy by identifying configurational relationships among technologies, governance functions, roles, and competencies. They also preserve a boundary condition emphasised in the reviewed literature: if AI-enabled IG depends exclusively on advanced infrastructures such as blockchain or complex federated pipelines, organisations in resource-constrained environments may face technological path dependence. A co-evolutionary perspective is therefore needed, where technologies and professional capabilities mutually shape one another rather than assuming that technical adoption alone produces responsible governance.

6. Limitations and Future Research

This review has several limitations. First, although the manuscript uses the term AI-enabled systems, the included studies are dominated by data-driven, model-centric, and generative AI applications. Symbolic, knowledge-based, and hybrid neuro-symbolic AI also require IG, particularly in relation to rule bases, knowledge representation, explainability, ontology governance, and hybrid reasoning accountability. However, these streams were not systematically represented in the retrieved corpus. Future reviews should examine IG requirements in symbolic and hybrid AI explicitly, rather than assuming that governance mechanisms developed for data-driven AI fully transfer to these paradigms.

Second, Scopus was not included as a primary search database. The review mitigated this limitation through multiple publisher databases, multidisciplinary sources, and snowballing, but relevant organisational behaviour and management studies may still have been missed. Third, the thematic counts reported in the results should be interpreted as coded occurrences within the reviewed corpus, not as meta-analytic effect sizes. Finally, because this study is based on secondary literature, the propositions developed in the discussion require future empirical testing across sectors with different levels of technological and institutional maturity.

Finally, future research may connect AI-enabled IG with the broader IT governance capability and maturity-assessment tradition. Studies on governance capability in operational contract management, COBIT 2019 implementation in mineral mining, and COBIT 5 capability-level measurement show how governance capability can be operationalised through process assessment, control alignment, and organisational accountability in non-AI settings [104106]. These studies should not be treated as direct evidence of AI-enabled IG, but they provide a useful bridge for developing sector-sensitive capability metrics that can later be adapted to AI governance contexts.

7. Conclusions

This SLR synthesises how IG is implemented within data-driven AI-enabled systems across technological, organisational, and human dimensions. By consolidating evidence from diverse sectors and stages of AI lifecycle, it provides a structured understanding of how governance functions are enacted in contemporary AI-driven environments.

The study conceptualises AI-enabled IG as a socio-technical dynamic capability by integrating fragmented literatures and identifying recurring patterns through which governance is operationalised. Rather than treating governance principles as abstract or institutionally detached constructs, the review demonstrates how accountability, transparency, privacy, trust, and compliance are mediated through the interplay of technological infrastructures, organisational arrangements, and human oversight roles.

The review also clarifies that IG becomes dynamic only when governance routines support sensing, seizing, and reconfiguring. This insight advances the literature by moving from taxonomic mapping towards propositions that can be tested in future empirical research. It positions AI-enabled IG as an organisational concern that extends beyond formal policies and regulatory compliance while also acknowledging the need for further work on symbolic, knowledge-based, and hybrid AI governance.