Systems capability debt, citizen development, and agentic AI risk
Systems capability debt, citizen development, and agentic AI risk: is the causal chain and sequencing imperative a novel contribution?
key claims
- Technical-debt literature begins with incomplete understanding written into software and later expands into broader architectural and enterprise concerns, and the reviewed evidence does not surface a standard debt category that matches the proposed "systems capability debt" constructC2 (n.d.)Cmdev (n.d.)Philippe (2012)
- Shadow information technology literature already provides a direct causal mechanism from unmet capability and business-information-technology misalignment to local workaround systems, and it is the clearest published bridge in the reviewed evidence between capability gaps and ungoverned citizen developmentSpringer (2020)Academia (n.d.)
- Low-code and citizen-development research supports speed, cost, skills shortage, and governance friction as major adoption drivers, but it does not map those drivers through the seven proposed debt types or isolate unmet system capability as the sole causeTu-dresden (n.d.)Adoption (2025)Citizen (2025)
- Basel Committee operational-risk guidance and the NIST AI Risk Management Framework require organisations to identify risks across products, processes, systems, change, oversight, third-party components, and control environments, which supports treating workaround estates and unclear human oversight as materially relevant even without an explicit shadow-information-technology ruleBasel (n.d.)Basel (2021)NIST (n.d.)
- Current agentic-AI governance literature clearly states that autonomous agents operate at machine speed and scale, that excessive privilege becomes more dangerous in that setting, and that human approval can degrade into a bottleneck or reflexive rubber stampAWS (2026)MIT (2025)
- The claim that agentic AI removes an implicit human-speed rate limit on pre-existing workaround behaviour is best treated as a new synthesis statement, because the reviewed literature supplies the ingredients of the argument but not that precise integrated formulationSpringer (2020)Academia (n.d.)AWS (2026)
- The proposed sequencing imperative, use AI first to map debt, access, and control gaps before scaling write-capable autonomous agents, is strongly implied by existing governance and control literature but does not appear as a widely cited named doctrine in the reviewed sourcesNIST (n.d.)AWS (2026)Business (n.d.)Regulatory (n.d.)
- This item's strongest novelty claim is that it contributes a cross-literature explanatory framework joining debt persistence, workaround emergence, formal risk governance, and machine-speed amplification into one decision-useful argumentC2 (n.d.)Academia (n.d.)Basel (n.d.)AWS (2026)
Research Question
Does the synthesis of technical debt literature (Cunningham, Kruchten), systems capability research, transaction cost economics (Coase, Williamson), operational risk frameworks (Basel III/IV, Risk and Control Self-Assessment (RCSA) methodology), and citizen development research produce a causal chain from systems capability debt through ungoverned citizen development to amplified agentic Artificial Intelligence (AI) operational risk, and an "AI for risk reduction first" sequencing imperative that constitutes a genuinely novel contribution to the literature?
Findings
(Populated from §6 Synthesis above.)
Executive Summary
- The complete causal chain and the "AI for risk reduction first" sequencing imperative do not appear in the reviewed literature as a pre-existing named framework, so the best-supported conclusion is that this is a novel synthesis built from established component literatures rather than a wholly unprecedented theory.
- The clearest published link in that synthesis is between unmet system need and workaround behaviour, because shadow information technology research directly shows business units acquiring local systems when central information technology cannot deliver suitable capability quickly enough.
- Operational-risk frameworks do not supply the causal chain, but they do supply control language that supports treating the resulting workaround estate as a legitimate governance and risk issue.
- Current agentic-AI governance literature then adds the amplification step by showing that machine-speed autonomy can outrun human review and make approval-based oversight ineffective at scale.
Key Findings
- Medium confidence: Technical-debt literature begins with incomplete understanding written into software and later expands into broader architectural and enterprise concerns, and the reviewed evidence does not surface a standard debt category that matches the proposed "systems capability debt" construct.
- High confidence: Shadow information technology literature already provides a direct causal mechanism from unmet capability and business-information-technology misalignment to local workaround systems, and it is the clearest published bridge in the reviewed evidence between capability gaps and ungoverned citizen development.
- Medium confidence: Low-code and citizen-development research supports speed, cost, skills shortage, and governance friction as major adoption drivers, but it does not map those drivers through the seven proposed debt types or isolate unmet system capability as the sole cause.
- High confidence: Basel Committee operational-risk guidance and the NIST AI Risk Management Framework require organisations to identify risks across products, processes, systems, change, oversight, third-party components, and control environments, which supports treating workaround estates and unclear human oversight as materially relevant even without an explicit shadow-information-technology rule.
- High confidence: Current agentic-AI governance literature clearly states that autonomous agents operate at machine speed and scale, that excessive privilege becomes more dangerous in that setting, and that human approval can degrade into a bottleneck or reflexive rubber stamp.
- Medium confidence: The claim that agentic AI removes an implicit human-speed rate limit on pre-existing workaround behaviour is best treated as a new synthesis statement, because the reviewed literature supplies the ingredients of the argument but not that precise integrated formulation.
- Medium confidence: The proposed sequencing imperative, use AI first to map debt, access, and control gaps before scaling write-capable autonomous agents, is strongly implied by existing governance and control literature but does not appear as a widely cited named doctrine in the reviewed sources.
- High confidence: This item's strongest novelty claim is that it contributes a cross-literature explanatory framework joining debt persistence, workaround emergence, formal risk governance, and machine-speed amplification into one decision-useful argument.
Assumptions
- Assumption: The shadow information technology literature is treated as the closest behavioural analogue for citizen development when direct low-code studies do not explicitly describe the full workaround chain. Justification: both involve business-led creation or sourcing of local digital capability outside full central engineering control.
- Assumption: The move from human-paced workarounds to write-capable agentic automation materially changes risk severity rather than merely increasing volume. Justification: the reviewed agentic-AI sources consistently stress speed, scale, privilege, and reviewer-overload effects.
- Assumption: Coase and Williamson remain valid explanatory lenses for internal workaround behaviour in contemporary digital organisations. Justification: the transaction-cost shadow-information-technology paper applies that logic directly to the phenomenon under study.
Analysis
- The most important discovery in the evidence set is that the middle of the chain is already published. Unmet need and business-information-technology friction do produce local workaround systems through a transaction-cost mechanism.
- The debt literature then gives a vocabulary for persistence and accumulation, but it does not remove the need to show why people route around the sanctioned estate.
- Risk frameworks matter because they convert what could look like an architectural complaint into a governance obligation. Once the estate is risk-bearing and poorly mapped, the problem is not stylistic.
- Agentic-AI literature does not need to mention shadow information technology explicitly for the amplification argument to hold. It is enough that it shows speed, delegated authority, and approval overload change control feasibility.
- The main weakness in the synthesis is that low-code adoption research is multi-causal. A claim that every citizen-development instance is caused by systems capability debt would overstate the evidence.
- That weakness is manageable if the argument is framed carefully: systems capability debt is a major and under-theorised driver of workaround demand, and agentic AI makes the unresolved estate more dangerous, which creates a sequencing imperative grounded in risk management rather than in aesthetic preference.
Risks, Gaps, and Uncertainties
- Full primary-text access for Coase and Williamson was limited in this runtime, so the TCE step relies partly on stable canonical citations and prior completed repository synthesis.
- The low-code literature is still young and methodologically mixed, so the causal hierarchy among adoption drivers is not mature enough to support strong single-cause claims.
- The amplification step is supported mainly by current governance and security commentary rather than by a long peer-reviewed tradition specific to agentic enterprise deployment.
- Exact-phrase absence is always a weaker novelty signal than direct proof of non-existence, so the novelty claim should be framed as "not found in reviewed literature" rather than as an absolute universal statement.
Open Questions
- Which of the seven proposed debt types most strongly predicts citizen-development emergence in practice, and which are only background contributors?
- What is the best Risk and Control Self-Assessment design for surfacing workaround estates, excessive permissions, and low-code automations before agent deployment?
- At what action volume or privilege profile does human review become nominal rather than substantive for agentic systems in regulated enterprises?
- Which governance interventions reduce workaround demand most effectively: better sanctioned delivery speed, better platform self-service, tighter controls, or some combination?
sources
- [x] Ward Cunningham, "The WyCash Portfolio Management System" (OOPSLA 1992) — - original debt-metaphor text; anchors the scope of the metaphor in incomplete understanding and refactoring.
- [x] Ward Cunningham, "Debt Metaphor" transcript (2009) — - later clarification that debt is about learning not written back into the system, not a general license for messy code.
- [x] Philippe Kruchten, Robert Nord, Ipek Ozkaya, "Technical Debt: From Metaphor to Theory and Practice" (2012) — - canonical expansion from metaphor toward taxonomy and theory.
- [x] Ronald Coase, "The Nature of the Firm" (1937) — - foundational TCE source for make, buy, and internal coordination logic.
- [x] Oliver Williamson, "The Economic Institutions of Capitalism" (1985) — - governance-structure extension of TCE used for workaround and internalisation reasoning.
- [x] From Shadow IT to Business-managed IT (Springer, 2020) — - empirical shadow information technology literature showing workarounds emerge when information technology cannot deliver suitable systems quickly enough.
- [x] On the Emergence of Shadow IT, A Transaction Cost-Based Approach — - explicit TCE explanation for shadow information technology emergence.
- [x] [Practitioners' Perceptions on the Adoption of Low Code Development Platforms (IEEE Access, 2023)](Practitioners' Perceptions on the Adoption of Low Code Development Platforms (IEEE Access, 2023) — .html) - empirical drivers and inhibitors for low-code adoption.
- [x] Adoption of low-code and no-code development, a systematic literature review and future research agenda (Journal of Systems and Software, 2025) — - synthesis of low-code and citizen-development literature.
- [x] Citizen Development, Low-Code/No-Code Platforms, and the Evolution of Generative AI in Software Development (IEEE Computer, 2025) — - concise current statement linking citizen development growth to governance and security challenges under generative AI.
- [x] Basel Committee, Revisions to the Principles for the Sound Management of Operational Risk (2021) — - current formal operational-risk standard.
- [x] Basel Committee, FSI Executive Summary of PSMOR — - usable summary of operational-risk identification, self-assessment, change management, controls, and Information and Communication Technology (ICT) governance.
- [x] Basel Committee, Principles for operational resilience (2021) — - resilience framing for technology failures and interdependency mapping.
- [x] Basel Committee press release on operational resilience and risk — - concise statement that technology threats increase operational-resilience importance.
- [x] NIST AI Risk Management Framework Core — - governance, mapping, human oversight, risk tolerance, and third-party risk subcategories relevant to sequencing.
- [x] AWS Security Blog, "Four security principles for agentic AI systems" (2026) — - explicit machine-speed, least-privilege, and human-approval-bottleneck framing for agentic systems.
- [x] MIT Sloan Management Review, "Agentic AI at Scale: Redefining Management for a Superhuman Workforce" (2025) — - expert panel evidence that human-paced management models strain under agent speed and scale.
- [x] Business-led low-code agent governance: conditions for durable value versus fragmentation in regulated environments — - prior completed repository item on low-code governance and prerequisites.
- [x] Regulatory and standards preconditions for deployment of AI systems that can take multi-step actions — - prior completed repository item on regulated-environment preconditions and control-failure framing.
- [x] The Nature of the Firm: why organisations exist, their fitness functions, and invariants — - prior completed repository item translating Coase and Williamson into organisation design and governance reasoning.