Martin McHugh · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.22802709
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
A maturity model where the organization grades its own evidence cannot measure what it claims to measure. This paper names that condition the Governor Problem: the scorer and the scored are the same party. It shows why self-scoring collapses the trust the score is supposed to create, catalogs nine attack classes that self-scored AI governance assessments are structurally exposed to, and works through the recursion problem of who grades the grader. It then states seven testable conditions for honest governance and defines an Adversarial Verification Protocol, a concrete procedure any organization can run against any maturity claim. Applied to the SANS AI Security Maturity Model, the framework separates the claims that survive adversarial testing from the ones that do not.
No comments yet — start the discussion below.