{"id":"https://openalex.org/W7152064359","doi":"https://doi.org/10.48550/arxiv.2604.06148","title":"Who Governs the Machine? A Machine Identity Governance Taxonomy (MIGT) for AI Systems Operating Across Enterprise and Geopolitical Boundaries","display_name":"Who Governs the Machine? A Machine Identity Governance Taxonomy (MIGT) for AI Systems Operating Across Enterprise and Geopolitical Boundaries","publication_year":2026,"publication_date":"2026-04-07","ids":{"openalex":"https://openalex.org/W7152064359","doi":"https://doi.org/10.48550/arxiv.2604.06148"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.06148","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.06148","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.06148","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5010760858","display_name":"Andrew Kurtz","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kurtz, Andrew","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5000864191","display_name":"Klaudia Krawiecka","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Krawiecka, Klaudia","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.2093999981880188,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.2093999981880188,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.059700001031160355,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10270","display_name":"Blockchain Technology Applications and Security","score":0.047200001776218414,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/operationalization","display_name":"Operationalization","score":0.6589999794960022},{"id":"https://openalex.org/keywords/corporate-governance","display_name":"Corporate governance","score":0.6432999968528748},{"id":"https://openalex.org/keywords/taxonomy","display_name":"Taxonomy (biology)","score":0.5078999996185303},{"id":"https://openalex.org/keywords/identity","display_name":"Identity (music)","score":0.4156000018119812},{"id":"https://openalex.org/keywords/industrial-espionage","display_name":"Industrial espionage","score":0.36309999227523804},{"id":"https://openalex.org/keywords/information-governance","display_name":"Information governance","score":0.3337000012397766}],"concepts":[{"id":"https://openalex.org/C9354725","wikidata":"https://www.wikidata.org/wiki/Q286017","display_name":"Operationalization","level":2,"score":0.6589999794960022},{"id":"https://openalex.org/C39389867","wikidata":"https://www.wikidata.org/wiki/Q380767","display_name":"Corporate governance","level":2,"score":0.6432999968528748},{"id":"https://openalex.org/C58642233","wikidata":"https://www.wikidata.org/wiki/Q8269924","display_name":"Taxonomy (biology)","level":2,"score":0.5078999996185303},{"id":"https://openalex.org/C2778355321","wikidata":"https://www.wikidata.org/wiki/Q17079427","display_name":"Identity (music)","level":2,"score":0.4156000018119812},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.3668000102043152},{"id":"https://openalex.org/C99712631","wikidata":"https://www.wikidata.org/wiki/Q1160650","display_name":"Industrial espionage","level":2,"score":0.36309999227523804},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3517000079154968},{"id":"https://openalex.org/C189922023","wikidata":"https://www.wikidata.org/wiki/Q17056348","display_name":"Information governance","level":4,"score":0.3337000012397766},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.3239000141620636},{"id":"https://openalex.org/C177212765","wikidata":"https://www.wikidata.org/wiki/Q627335","display_name":"Workflow","level":2,"score":0.320499986410141},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.31130000948905945},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.3050000071525574},{"id":"https://openalex.org/C195094911","wikidata":"https://www.wikidata.org/wiki/Q14167904","display_name":"Process management","level":1,"score":0.30219998955726624},{"id":"https://openalex.org/C39549134","wikidata":"https://www.wikidata.org/wiki/Q133080","display_name":"Public relations","level":1,"score":0.301800012588501},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.29120001196861267},{"id":"https://openalex.org/C201960208","wikidata":"https://www.wikidata.org/wiki/Q159385","display_name":"Geopolitics","level":3,"score":0.28839999437332153},{"id":"https://openalex.org/C140423589","wikidata":"https://www.wikidata.org/wiki/Q7249406","display_name":"Project governance","level":3,"score":0.2856000065803528},{"id":"https://openalex.org/C72648740","wikidata":"https://www.wikidata.org/wiki/Q658476","display_name":"Public key infrastructure","level":4,"score":0.26669999957084656}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.06148","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.06148","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.06148","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.06148","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"governance":[1,128,134,198,213],"of":[2,98],"artificial":[3],"intelligence":[4],"has":[5],"a":[6,95,153,189,212],"blind":[7],"spot:":[8],"the":[9,59,90,119,132,136,141,223],"machine":[10,74],"identities":[11,30],"that":[12,145,164],"AI":[13,18,181,196],"systems":[14],"use":[15],"to":[16,38,45],"act.":[17],"agents,":[19],"service":[20],"accounts,":[21],"API":[22],"tokens,":[23],"and":[24,68,115,140,171,203,210],"automated":[25,51],"workflows":[26],"now":[27],"outnumber":[28],"human":[29],"in":[31,56,58,107,150],"enterprise":[32,160,195,227],"environments":[33],"by":[34],"ratios":[35],"exceeding":[36],"80":[37],"1,":[39],"yet":[40],"no":[41],"integrated":[42,126],"framework":[43,129],"exists":[44],"govern":[46],"them.":[47,217],"A":[48,218],"single":[49],"ungoverned":[50,73],"agent":[52],"produced":[53],"$5.4-10":[54],"billion":[55],"losses":[57],"2024":[60],"CrowdStrike":[61],"outage;":[62],"nation-state":[63],"actors":[64],"including":[65],"Silk":[66,165],"Typhoon":[67,70],"Salt":[69,167],"have":[71,178],"operationalized":[72,180],"credentials":[75],"as":[76,184],"primary":[77],"espionage":[78],"vectors":[79],"against":[80],"critical":[81],"infrastructure.":[82],"This":[83],"paper":[84],"makes":[85],"four":[86],"original":[87],"contributions.":[88],"First,":[89],"AI-Identity":[91],"Risk":[92],"Taxonomy":[93,123],"(AIRT):":[94],"comprehensive":[96],"enumeration":[97],"37":[99],"risk":[100],"sub-categories":[101],"across":[102],"eight":[103],"domains,":[104],"each":[105],"grounded":[106],"documented":[108],"incidents,":[109],"regulatory":[110,137,191],"recognition,":[111],"practitioner":[112],"prevalence":[113],"data,":[114],"threat":[116,157],"intelligence.":[117],"Second,":[118],"Machine":[120],"Identity":[121],"Governance":[122],"(MIGT):":[124],"an":[125],"six-domain":[127],"simultaneously":[130],"addressing":[131],"technical":[133],"gap,":[135,139],"compliance":[138],"cross-jurisdictional":[142,190],"coordination":[143],"gap":[144],"existing":[146],"frameworks":[147,205],"address":[148],"only":[149],"isolation.":[151],"Third,":[152],"foreign":[154],"state":[155],"actor":[156],"model":[158],"for":[159,215],"identity":[161,175,182,197],"governance,":[162],"establishing":[163],"Typhoon,":[166,168,170],"Volt":[169],"North":[172],"Korean":[173],"AI-enhanced":[174],"fraud":[176],"operations":[177],"already":[179],"vulnerabilities":[183],"active":[185],"attack":[186],"vectors.":[187],"Fourth,":[188],"alignment":[192],"structure":[193],"mapping":[194],"obligations":[199],"under":[200],"EU,":[201],"US,":[202],"Chinese":[204],"simultaneously,":[206],"identifying":[207],"irreconcilable":[208],"conflicts":[209],"providing":[211],"mechanism":[214],"managing":[216],"four-phase":[219],"implementation":[220],"roadmap":[221],"translates":[222],"MIGT":[224],"into":[225],"actionable":[226],"programs.":[228]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-04-09T00:00:00"}
