[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83225-en":3,"doc-seo-83225-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83225,962075114765,"Quinn","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","The AI Resilience Gap: Bringing Artificial Intelligence Inside the Operational Resilience Perimeter","Rapid adoption of artificial intelligence in regulated firms has triggered extensive governance focused on trustworthiness, including the EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework, and the UK’s principles-based approach. That response addresses safety and model risk but remains incomplete because it does not cover operational resilience: continuity of important services under severe disruptions, dependency substitutability, and provider concentration. The paper presents an AI Resilience obligation distinct from trustworthy-AI governance, maps regulatory logics, identifies a structural gap, and proposes an AI Resilience Framework to bring AI dependencies inside the operational resilience perimeter.","arXiv :2607 .07359v 1 [ cs .CR] 8 Jul 2026  \nThe AI Resilience Gap: Bringing Artificial Intelligence Inside the Operational Resilience Perimeter  \nJonathan Shelby  \nDepartment of Computer Science, University of Oxford  \nHertford College, Oxford, United Kingdom  \nJuly 2026  \nAbstract  \nThe rapid adoption of artificial intelligence across regulated firms has produced an extensive governance response oriented around trustworthiness: the EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework, and the United Kingdom’s principles-based approach all address safety, fairness, transparency, and model risk. That response is necessary but incomplete. It does not, on its own, address operational resilience: the continuity of important business services under severe but plausible disruption, the substitutability of AI components, and the concentration of dependency on the small number of firms that supply frontier models. This paper argues that AI adoption creates a resilience obligation that is distinct from, and inadequately covered by, the trustworthy-AI stack, and that United Kingdom financial authorities are already closing this gap through the Financial Policy Committee’s systemic analysis, the Critical Third Parties regime, and the May 2026 joint statement on frontier AI and cyber resilience. We map the two regulatory logics, identify the structural gap between them, and propose the AI Resilience Framework: a regime-agnostic method for bringing AI dependencies inside the operational resilience perimeter through dependency mapping, a criticality-substitutability tiering, the extension of impact tolerances to AI-specific failure modes, an explicit fallback doctrine, and provider-level concentration management. The framework gives chief information security officers, security architects, and boards an actionable route from AI governance policy to demonstrable resilience. This work extends a companion analysis of the United Kingdom cyber resilience regulatory stack [1] into the artificial intelligence dimension.  \nKeywords: artificial intelligence, operational resilience, EU AI Act, DORA, Critical Third Parties, concentration risk, impact tolerance, model risk, financial services  \n1. Introduction  \nArtificial intelligence has moved from pilot to production across United Kingdom financial services. The third Bank of England and Financial Conduct Authority survey of AI in the sector, published in November 2024, reported that around three quarters of firms were already using AI, with a further tenth planning adoption within three years, and that foundation models, including large language models, already accounted for roughly a sixth of use cases [2] . A majority of use cases involved some degree of autonomous decision-making, even though only a small fraction were described as fully autonomous. The direction of travel is unambiguous. AI is no longer confined to marketing analytics and back-office productivity; it is entering credit decisioning, transaction monitoring, trading, and the operation of customer-facing services that firms are obliged to keep running.  \nThe regulatory and standards response to this shift has been substantial. At the European level, the AI Act establishes a horizontal, risk-tiered regime for AI systems and general-purpose models [3] . Internationally, ISO/IEC 42001 provides a certifiable managementsystem standard for AI [4], and the NIST AI Risk Management Framework offers a voluntary structure for identifying and managing AI risks, extended in 2024 by a profile for generative AI [5, 6] . In the United Kingdom, financial regulators have chosen a principles-  \nbased, technology-neutral path, declining to introduce AI-specific rules and instead relying on existing frameworks such as the Consumer Duty, the Senior Managersand Certification Regime, model risk management expectations, and operational resilience requirements [7, 8] .  \nThese instruments share an orientation. They are concerned, first and forem","cbCaifm30nCa3Qwo","https://ap.wps.com/l/cbCaifm30nCa3Qwo","pdf",326398,3,1,11,"English","en",105,"# Introduction\n## Trustworthiness vs operational resilience\n## Central argument and UK efforts","[{\"question\":\"What gap does the paper identify between AI governance and operational resilience?\",\"answer\":\"Trustworthiness-focused governance does not address whether important business services survive severe but plausible disruptions, including AI dependency concentration and lack of substitutability. The paper argues this creates a distinct resilience obligation not covered by the trustworthy-AI stack.\"},{\"question\":\"How does the paper characterize a severe resilience liability created by AI adoption?\",\"answer\":\"It describes a scenario where an AI system can be trustworthy while still creating a severe resilience liability through a single, unsubstitutable dependency on an external frontier model provider embedded in an important service.\"},{\"question\":\"What does the proposed AI Resilience Framework aim to do?\",\"answer\":\"It provides a regime-agnostic method to bring AI dependencies inside the operational resilience perimeter using dependency mapping, criticality–substitutability tiering, AI-specific impact tolerance extensions, an explicit fallback doctrine, and provider-level concentration management.\"}]",1784186064,28,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"the-ai-resilience-gap-bringing-artificial-intelligence-inside-the-operational-resilience-perimeter","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/the-ai-resilience-gap-bringing-artificial-intelligence-inside-the-operational-resilience-perimeter/83225/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What gap does the paper identify between AI governance and operational resilience?","Question",{"text":75,"@type":76},"Trustworthiness-focused governance does not address whether important business services survive severe but plausible disruptions, including AI dependency concentration and lack of substitutability. The paper argues this creates a distinct resilience obligation not covered by the trustworthy-AI stack.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the paper characterize a severe resilience liability created by AI adoption?",{"text":80,"@type":76},"It describes a scenario where an AI system can be trustworthy while still creating a severe resilience liability through a single, unsubstitutable dependency on an external frontier model provider embedded in an important service.",{"name":82,"@type":73,"acceptedAnswer":83},"What does the proposed AI Resilience Framework aim to do?",{"text":84,"@type":76},"It provides a regime-agnostic method to bring AI dependencies inside the operational resilience perimeter using dependency mapping, criticality–substitutability tiering, AI-specific impact tolerance extensions, an explicit fallback doctrine, and provider-level concentration management.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]