A Governance Embedded Agentic Artificial Intelligence Framework for Healthcare Cybersecurity in Resource Constrained Settings | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF comment A Governance Embedded Agentic Artificial Intelligence Framework for Healthcare Cybersecurity in Resource Constrained Settings Ibrahim Adabara, Bashir Olaniyi Sadiq, Aliyu Nuhu Shuaibu, Yale Ibrahim Danjuma, and 2 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-9231871/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 7 You are reading this latest preprint version Abstract Healthcare systems are increasingly exposed to cyber threats that compromise patient safety, data integrity, and service continuity, particularly in resource-constrained environments where governance and cybersecurity capacity remain limited. Although artificial intelligence is widely adopted to enhance intrusion detection and automated response, most existing systems remain reactive, opaque, and insufficiently aligned with ethical and regulatory requirements, creating a critical governance gap. This study addresses this challenge by developing the Agentic Artificial Intelligence Framework, a governance-embedded cybersecurity architecture that integrates ethical reasoning, regulatory compliance, and adaptive intelligence within autonomous decision-making processes. The framework was developed using a design science research approach and evaluated through large-scale simulation involving more than 280,000 network events representing diverse healthcare cyber threat scenarios. The results demonstrate that the framework reduced response time by 34.8 percent, improved system recovery rates by 41.6 percent, and achieved an Ethical Compliance Rate of 0.99 without false escalations. These findings show that governance-by-design can enhance both cybersecurity performance and accountability. The study provides a scalable and policy-relevant approach for strengthening resilient, transparent, and ethically aligned healthcare cybersecurity systems in resource-constrained settings. Agentic artificial intelligence healthcare cybersecurity AI governance intrusion detection resource constrained settings ethical AI governance by design Figures Figure 1 1. Introduction Healthcare systems are increasingly exposed to sophisticated cyber threats that compromise patient safety, data integrity, and continuity of care. The rapid expansion of digital health technologies, including electronic health records, telemedicine platforms, and Internet of Medical Things devices, has significantly increased the attack surface of healthcare infrastructures. These developments have improved service delivery but have also introduced critical vulnerabilities that expose healthcare systems to evolving cyber risks (Algarni & Thayananthan, 2025 ; Ewoh & Vartiainen, 2024 ). Artificial intelligence is increasingly deployed to enhance intrusion detection and automated threat response in healthcare cybersecurity. Machine learning and deep learning approaches have demonstrated improved capability in identifying complex and evolving attack patterns compared to traditional rule-based systems (Ejeofobiri et al., 2024 ; Huang et al., 2025 ). However, most existing AI-driven cybersecurity systems remain reactive, relying on historical data rather than anticipating emerging threats. In addition, these systems often operate as opaque models with limited transparency and weak integration of ethical reasoning and regulatory compliance (Adeniran et al., 2024 ; Emmanuel et al., 2024 ). This limitation is particularly significant in resource-constrained settings, where healthcare systems face infrastructural constraints, limited cybersecurity capacity, and dependence on externally developed technologies that may not align with local governance frameworks. These conditions increase systemic vulnerability and reduce the ability of institutions to ensure accountability, transparency, and policy compliance in automated cybersecurity operations (Cuadros et al., 2025 ; Folorunso et al., 2024 ). To address this gap, this study introduces the Agentic Artificial Intelligence Framework, a governance-embedded cybersecurity architecture that integrates ethical reasoning, regulatory compliance, and adaptive intelligence within autonomous decision-making processes. The framework is grounded in agent-based systems theory, reinforcement learning, and machine ethics, enabling intelligent systems to operate adaptively while remaining aligned with governance constraints (Fard et al., 2023 ; Wooldridge & Jennings, 1995 ). Developed using a design science research approach and evaluated through large-scale simulation, the framework demonstrates that governance and technical performance can be jointly optimized. This study makes three contributions. First, it advances a governance-by-design paradigm for artificial intelligence in cybersecurity. Second, it presents a practical and scalable architecture for healthcare cybersecurity in resource-constrained environments. Third, it provides policy-relevant insights for strengthening institutional resilience and accountability in digital health systems. 2. Governance Gap in AI-Driven Cybersecurity Artificial intelligence is increasingly deployed to enhance intrusion detection and automated threat response within healthcare systems. These systems improve the speed and accuracy of identifying known attack patterns using data-driven techniques. However, most current implementations remain fundamentally reactive, relying on predefined datasets and historical attack signatures rather than anticipating emerging or context-specific threats. This limitation reduces their effectiveness in dynamic healthcare environments, where cyber risks continuously evolve and require adaptive, real-time responses (Ali et al., 2025 ; Hassan et al., 2025 ). A second critical limitation is the opacity of many AI models. Advanced machine learning approaches, particularly deep learning systems, often operate as black-box models that provide limited insight into how decisions are made. This lack of transparency constrains the ability of healthcare institutions to interpret, validate, and audit automated cybersecurity actions. In safety-critical environments, where decisions may involve restricting access to patient data or isolating clinical systems, the absence of explainability introduces significant ethical and operational risks (Marey et al., 2024 ; Mohale & Obagbuwa, 2025 ). More critically, governance mechanisms in most AI-driven cybersecurity systems remain external to the system architecture. Ethical principles, regulatory requirements, and institutional policies are typically enforced through post-deployment audits or human oversight rather than being embedded within the decision-making process. This separation allows systems to achieve high technical performance while operating outside acceptable ethical and regulatory boundaries, limiting accountability and trust (Emmanuel et al., 2024 ; Sunkara, 2024 ). These challenges are particularly pronounced in resource-constrained settings. Healthcare institutions in these environments often depend on externally developed cybersecurity technologies that are not aligned with local regulatory frameworks or institutional capacities. This dependency limits contextual adaptability and increases exposure to governance and operational risks, especially in systems where cybersecurity failures can directly affect patient safety and service continuity (Folorunso et al., 2024 ; Njoroge, 2024 ). Taken together, the reactive nature of existing AI systems, their limited transparency, and the externalization of governance mechanisms reveal a fundamental weakness in current cybersecurity approaches. This creates a structural accountability gap in which autonomous systems are capable of acting but are not inherently aligned with the ethical, regulatory, and institutional frameworks within which they operate. 3. The AAIF Framework The Agentic Artificial Intelligence Framework (AAIF) is a governance-embedded cybersecurity architecture designed to integrate ethical reasoning, regulatory compliance, and adaptive intelligence directly within autonomous decision-making processes. Unlike conventional artificial intelligence systems that treat governance as an external constraint, the AAIF operationalizes a governance-by-design paradigm in which ethical and policy considerations are embedded within the core logic of system behavior. This enables cybersecurity systems to not only detect and respond to threats but also ensure that all actions remain aligned with institutional policies, regulatory requirements, and patient safety considerations. At the architectural level, the AAIF is structured around an agentic decision loop that continuously monitors network activity, evaluates potential threats, and determines appropriate responses in real time. This loop integrates perception, reasoning, decision, and action, allowing the system to adapt dynamically to evolving threat conditions. The decision-making process is supported by adaptive learning mechanisms, including reinforcement learning, which enable continuous improvement while maintaining alignment with predefined governance rules (Fard et al., 2023 ; Feltus, 2020 ). The overall architecture of the framework is illustrated in Fig. 1 . A central contribution of the framework is the Governance Gate, which functions as a dual-validation mechanism embedded within the decision pipeline. Each proposed action is evaluated against ethical principles and regulatory constraints before execution. Actions that satisfy governance requirements are implemented autonomously, while those associated with uncertainty, elevated risk, or potential ethical conflict are escalated for human oversight. This mechanism ensures that autonomy operates within clearly defined boundaries, preserving accountability while maintaining operational efficiency (Frenette, 2023 ; Joseph et al., 2024 ). The AAIF is theoretically grounded in the integration of agent-based systems, reinforcement learning, and machine ethics. Agent theory provides the foundation for autonomous and adaptive system behavior, reinforcement learning supports dynamic optimization in adversarial environments, and machine ethics enables the incorporation of moral reasoning into decision-making processes (Nath & Sahu, 2020 ; Vishwanath et al., 2024 ; Wooldridge & Jennings, 1995 ). This interdisciplinary foundation ensures that the framework balances technical effectiveness with ethical and governance requirements. To ensure practical relevance, the AAIF embeds policy and regulatory logic directly within its architecture through alignment with established governance frameworks, including the NIST Cybersecurity Framework 2.0 and the HIPAA Security Rule. This integration transforms governance from a retrospective compliance activity into a continuous and enforceable system capability. As a result, the framework provides a scalable and context-aware approach for deploying ethically aligned cybersecurity systems in healthcare environments, particularly in resource-constrained settings. 4. Empirical Validation The performance of the Agentic Artificial Intelligence Framework was evaluated using a large-scale simulation comprising more than 280,000 network events representing diverse healthcare cybersecurity scenarios, including ransomware, phishing, insider threats, and Internet of Medical Things attacks. The simulation environment was designed to reflect the operational conditions of a Ugandan teaching hospital, incorporating the infrastructural constraints and resource limitations characteristic of healthcare systems in low- and middle-income countries. The results demonstrate that governance-embedded artificial intelligence can achieve substantial performance improvements without compromising accountability. The framework reduced response time by 34.8 percent and improved system recovery rates by 41.6 percent compared to conventional AI-based cybersecurity approaches. In addition, the framework achieved an Ethical Compliance Rate of 0.99, with no false escalations, indicating consistent alignment with predefined ethical and regulatory constraints. Comparative performance across different cybersecurity approaches is summarized in Table 1 . Table 1 Comparative performance of the proposed AAIF against existing AI-based cybersecurity frameworks across accuracy, ethical compliance, resilience, and decision latency. Framework Accuracy F1 Score Ethical Compliance Rate Resilience Index Decision Latency (ms) Traditional IDS 0.92 0.90 0.67 0.43 28 Explainable IDS 0.94 0.91 0.81 0.47 32 Trust-Aware IDS 0.95 0.93 0.89 0.49 34 AAIF (Proposed) 0.97 0.95 0.99 0.51 35 These findings provide clear evidence that embedding governance mechanisms within AI architectures enhances both cybersecurity effectiveness and institutional accountability in resource-constrained healthcare environments. 5. Policy Implications and Recommendations The empirical findings demonstrate that governance and cybersecurity performance can be jointly optimized within a unified artificial intelligence architecture. To translate these findings into practice, four strategic actions are recommended. 5.1 Governance by Design as a Requirement Governance by design should be established as a mandatory requirement in national cybersecurity strategies and digital health policies. Artificial intelligence systems deployed in healthcare must embed ethical oversight, regulatory compliance, and transparent decision-making within their core architecture rather than relying on post-deployment controls. 5.2 Institutionalization of Regulatory Sandboxes Regulatory authorities should establish controlled sandbox environments to enable the testing and validation of governance-embedded AI systems under real-world conditions. These environments support iterative evaluation, risk management, and safe deployment before large-scale implementation. 5.3 Investment in Local Capacity Development Governments and development partners should prioritize investment in local research, technical training, and innovation ecosystems focused on AI governance and healthcare cybersecurity. Strengthening local expertise reduces dependency on external systems and ensures alignment with national regulatory and institutional requirements. 5.4 Strengthening International and Regional Alignment National policies should align with global and regional governance frameworks to support interoperability, knowledge sharing, and coordinated cybersecurity responses. Harmonized standards enhance cross-border collaboration and reduce fragmentation in interconnected healthcare systems. 6. Conclusion Healthcare cybersecurity is increasingly challenged by the rapid expansion of digital health systems and the growing sophistication of cyber threats. Existing artificial intelligence approaches, while effective in detection, remain limited by reactive design, lack of transparency, and weak integration of governance mechanisms. These limitations are particularly critical in resource-constrained environments, where institutional capacity, regulatory alignment, and accountability are essential for safeguarding patient safety and maintaining trust. This study introduced the Agentic Artificial Intelligence Framework as a governance-embedded cybersecurity architecture that integrates ethical reasoning, regulatory compliance, and adaptive intelligence within autonomous decision-making processes. The empirical results demonstrate that governance-by-design enhances both system performance and accountability, confirming that governance is not an optional layer but a foundational requirement for effective AI-driven cybersecurity. The findings provide both a scalable technical solution and actionable policy direction, supporting the development of resilient, transparent, and ethically aligned healthcare cybersecurity systems in resource-constrained settings. Declarations Ethics Approval and Consent to Participate This study did not involve human participants, human subjects, or identifiable personal data. The research was conducted as part of an approved doctoral study. Ethical clearance was obtained from the Kampala International University Research Ethics Committee (KIU-REC) and the Uganda National Council for Science and Technology (UNCST). As no human participants were involved, informed consent was not applicable. Consent for Publication Not applicable. This manuscript does not contain any person’s data in any form. Competing Interests The authors declare that they have no competing interests. Funding This work was conducted as part of doctoral research at Kampala International University. No specific external funding was received for this study. Author Contribution I.A. conceived the study, developed the governance protocol and Agentic Artificial Intelligence Framework, designed the system architecture, and drafted the original manuscript. B.O.S. supervised the research and contributed to experimental validation and manuscript revision. A.N.S. contributed to methodological development and technical validation. Y.I.D. conducted model training, performed formal analysis, and contributed to results interpretation. V.M. managed data curation and supported experimental implementation and governance integration. J.M. contributed to data curation, experimental configuration, and governance operationalization. All authors reviewed and approved the final manuscript. Data Availability The AAIF source code and associated validation datasets, including CICIDS2017, CSE-CIC-IDS2018, and DARPA r6.2, are publicly available at [https://github.com/ibrahimadabara01/aaif-cybersecurity-framework](https:/github.com/ibrahimadabara01/aaif-cybersecurity-framework) . Simulation configurations and governance parameter files are provided within the repository documentation. References Adeniran AA, Peace A, William P. Explainable AI (XAI) in healthcare: Enhancing trust and transparency in critical decision-making. World J Adv Res Reviews. 2024;23(3):2447–658. https://doi.org/10.30574/WJARR.2024.23.3.2936 . Algarni AM, Thayananthan V. Cybersecurity for Analyzing Artificial Intelligence (AI)-Based Assistive Technology and Systems in Digital Health. Syst 2025. 2025;13(6):439. https://doi.org/10.3390/SYSTEMS13060439 . 13 . Ali ML, Thakur K, Schmeelk S, Debello J, Dragos D. Deep Learning vs. Machine Learning for Intrusion Detection in Computer Networks: A Comparative Study. Appl Sci. 2025;15(4). https://doi.org/10.3390/APP15041903 . Cuadros DF, Kiragga A, Tu L, Awad S, Bwanika JM, Musuka G. (2025). Unpacking social and digital determinants of health in Africa: a narrative review on challenges and opportunities. MHealth , 11 . https://doi.org/10.21037/MHEALTH-24-73 Ejeofobiri CK, Victor-Igun OO, Okoye C. AI-Driven Secure Intrusion Detection for Internet of Things (IOT) Networks. Asian J Math Comput Res. 2024;31(4):40–55. https://doi.org/10.56557/AJOMCOR/2024/V31I48971 . Emmanuel C, Edima DE, Iboro AE, Joshua OA, Eseoghene DE, Cadet E, Etim ED, Essien IA, Ajayi JO, Erigha ED. Ethical Challenges in AI-Driven Cybersecurity Decision-Making. Int J Sci Res Comput Sci Eng Inform Technol. 2024;10(3):1031–64. https://doi.org/10.32628/CSEIT25113577 . Emmanuel Cadet ED, Etim IA, Essien, Eseoghene Daniel Erigha. Joshua Oluwagbenga Ajayi, &. (2024). Ethical Challenges in AI-Driven Cybersecurity Decision-Making. International Journal of Scientific Research in Computer Science, Engineering and Information Technology , 10 (3), 1031–1064. https://doi.org/10.32628/CSEIT25113577 Ewoh P, Vartiainen T. Vulnerability to Cyberattacks and Sociotechnical Solutions for Health Care Systems: Systematic Review. J Med Internet Res. 2024;26. https://doi.org/10.2196/46904 . Fard NE, Selmic RR, Khorasani K. A Review of Techniques and Policies on Cybersecurity Using Artificial Intelligence and Reinforcement Learning Algorithms. IEEE Technol Soc Mag. 2023;42(3):57–68. https://doi.org/10.1109/MTS.2023.3306540 . Feltus C. Reinforcement Learning’s Contribution to the Cyber Security of Distributed Systems. Int J Distrib Artif Intell. 2020;12(2):35–55. https://doi.org/10.4018/IJDAI.2020070103 . Folorunso A, Babalola O, Nwatu CE, Ukonne U. Compliance and Governance issues in Cloud Computing and AI: USA and Africa. Global J Eng Technol Adv. 2024;21(2):127–38. https://doi.org/10.30574/GJETA.2024.21.2.0213 . Frenette J. Ensuring human oversight in high-performance AI systems: A framework for control and accountability. World J Adv Res Reviews. 2023;20(2):1507–16. https://doi.org/10.30574/WJARR.2023.20.2.2194 . Hassan SADH, Rasheed AA, Mousa AA, Hussein ZA, Ambudkar B. The Rising Cost of Cyberattacks: Trends and Impacts across Industries. HighTech Innov J. 2025;6(2):524–36. https://doi.org/10.28991/HIJ-2025-06-02-011 . Huang K, Huang J, Mehmood Y, Atta H, Baig M, Haq MAU. (2025). AAGATE: A NIST AI RMF-Aligned Governance Platform for Agentic AI. ArXiv , abs/2510.2 . https://doi.org/10.48550/ARXIV.2510.25863 Joseph SA, Kolade TM, Obioha-Val O, Adebiyi OO, Ogungbemi OS, Olaniyi OO. AI-Powered Information Governance: Balancing Automation and Human Oversight for Optimal Organization Productivity. Asian J Res Comput Sci. 2024;17(10):110–31. https://doi.org/10.9734/AJRCOS/2024/V17I10513 . Marey A, Arjmand P, Alerab ADS, Eslami MJ, Saad AM, Sanchez N, Umair M. Explainability, transparency and black box challenges of AI in radiology: impact on patient care in cardiovascular radiology. Egypt J Radiol Nuclear Med. 2024;55(1). https://doi.org/10.1186/S43055-024-01356-2 . Mohale VZ, Obagbuwa IC. (2025). A systematic review on the integration of explainable artificial intelligence in intrusion detection systems to enhancing transparency and interpretability in cybersecurity. Frontiers in Artificial Intelligence , 8 . https://doi.org/10.3389/FRAI.2025.1526221 Nath R, Sahu V. The problem of machine ethics in artificial intelligence. AI Soc. 2020;35(1):103–11. https://doi.org/10.1007/S00146-017-0768-6 . Njoroge JW. Comparative Analysis Of Ai Governance In Africa Relative To Global Standards And Practices. IOSR J Comput Eng. 2024;26(5):19–25. https://doi.org/10.9790/0661-2605031925 . Sunkara G. Ethical and regulatory implications of AI in cybersecurity surveillance. World J Adv Res Reviews. 2024;24(2):2895–905. https://doi.org/10.30574/WJARR.2024.24.2.3571 . Vishwanath A, Dennis LA, Slavkovik M. (2024). Reinforcement Learning and Machine ethics:a systematic review. ArXiv , abs/2407.0 . https://doi.org/10.48550/ARXIV.2407.02425 Wooldridge M, Jennings NR. Intelligent agents: theory and practice. Knowl Eng Rev. 1995;10(2):115–52. https://doi.org/10.1017/S0269888900008122 . Additional Declarations No competing interests reported. Cite Share Download PDF Status: Under Review Version 1 posted Reviewers agreed at journal 18 May, 2026 Reviewers agreed at journal 15 May, 2026 Reviewers invited by journal 27 Apr, 2026 Editor assigned by journal 27 Apr, 2026 Editor invited by journal 25 Apr, 2026 Submission checks completed at journal 22 Apr, 2026 First submitted to journal 22 Apr, 2026 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-9231871","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"comment","associatedPublications":[],"authors":[{"id":632809993,"identity":"04f025eb-cc92-4743-902e-9ae8ac1eb513","order_by":0,"name":"Ibrahim Adabara","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABO0lEQVRIie3RPUvDQBjA8acc3HTUNeVC8hUSDiKSEr/KlUCzWCg4KFgwIKRL3AsO+Qp16eQQCCRLP0Aki1kydRAEqTSDuYqIwWBHwfsveYEfz70AyGR/Mo73D6wAIDBAEx/NOxj4UMIAH0pgTwBG/ifpAkdzt3p6e3CgT2/Ll+l05UVRaBZkBqyv8N7zFhLH/06UdXVshpULWM0YXRjFZJkSZpMULKxwNAghcVsEcm4pJEbNXsZAiSCYWHTiw7AhQKEhLaHn3uugjq8FQbuGeHrwRdDuB2LkZxYlcSIIFlM4pB9ELAyLKU6LmOvNBVPjjGA1xXZDzGU6PrfrVGGYlMFJaHi8RbTMW5Wb+ErT7wJUkLrQ9Zvk/nExG5rR3E3y7aV92nHYpP1DXE3PF9czap/Y73VNkclksn/TO649Y1aj27P/AAAAAElFTkSuQmCC","orcid":"","institution":"Kampala International University","correspondingAuthor":true,"prefix":"","firstName":"Ibrahim","middleName":"","lastName":"Adabara","suffix":""},{"id":632809994,"identity":"470a16d6-fcc6-437f-8d9b-1c159086e09f","order_by":1,"name":"Bashir Olaniyi Sadiq","email":"","orcid":"","institution":"Kampala International University","correspondingAuthor":false,"prefix":"","firstName":"Bashir","middleName":"Olaniyi","lastName":"Sadiq","suffix":""},{"id":632809995,"identity":"fe1659ce-f04e-4b79-879d-4ceba01d15d0","order_by":2,"name":"Aliyu Nuhu Shuaibu","email":"","orcid":"","institution":"Kampala International University","correspondingAuthor":false,"prefix":"","firstName":"Aliyu","middleName":"Nuhu","lastName":"Shuaibu","suffix":""},{"id":632809997,"identity":"fc62d76f-fd64-4dc5-b260-727a132dbda7","order_by":3,"name":"Yale Ibrahim Danjuma","email":"","orcid":"","institution":"Kampala International University","correspondingAuthor":false,"prefix":"","firstName":"Yale","middleName":"Ibrahim","lastName":"Danjuma","suffix":""},{"id":632809998,"identity":"37a72944-2e00-45b2-961a-282ebed908ff","order_by":4,"name":"Venkateswarlu Maninti","email":"","orcid":"","institution":"Kampala International University","correspondingAuthor":false,"prefix":"","firstName":"Venkateswarlu","middleName":"","lastName":"Maninti","suffix":""},{"id":632810000,"identity":"7694201e-26b5-4221-9cf9-d2a87ff50ed3","order_by":5,"name":"Mutebi Joe","email":"","orcid":"","institution":"Kampala International University","correspondingAuthor":false,"prefix":"","firstName":"Mutebi","middleName":"","lastName":"Joe","suffix":""}],"badges":[],"createdAt":"2026-03-26 09:10:09","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-9231871/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-9231871/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":108939227,"identity":"cf91b5a3-ee32-4b4a-9ac0-5823b82747d1","added_by":"auto","created_at":"2026-05-11 05:06:45","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":681242,"visible":true,"origin":"","legend":"\u003cp\u003eArchitecture of the Agentic Artificial Intelligence Framework (AAIF) showing governance-embedded decision-making, adaptive response, and integrated monitoring and resilience evaluation.\u003c/p\u003e","description":"","filename":"floatimage1.png","url":"https://assets-eu.researchsquare.com/files/rs-9231871/v1/f80ce660fa9ee8e6a232fd61.png"},{"id":108939229,"identity":"a52c2836-f401-4433-ae0e-6e944a4ed522","added_by":"auto","created_at":"2026-05-11 05:06:56","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":846561,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-9231871/v1/a7ab0313-e53b-4cf5-9770-327c0168fca8.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"A Governance Embedded Agentic Artificial Intelligence Framework for Healthcare Cybersecurity in Resource Constrained Settings","fulltext":[{"header":"1. Introduction","content":"\u003cp\u003eHealthcare systems are increasingly exposed to sophisticated cyber threats that compromise patient safety, data integrity, and continuity of care. The rapid expansion of digital health technologies, including electronic health records, telemedicine platforms, and Internet of Medical Things devices, has significantly increased the attack surface of healthcare infrastructures. These developments have improved service delivery but have also introduced critical vulnerabilities that expose healthcare systems to evolving cyber risks (Algarni \u0026amp; Thayananthan, \u003cspan citationid=\"CR2\" class=\"CitationRef\"\u003e2025\u003c/span\u003e; Ewoh \u0026amp; Vartiainen, \u003cspan citationid=\"CR8\" class=\"CitationRef\"\u003e2024\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eArtificial intelligence is increasingly deployed to enhance intrusion detection and automated threat response in healthcare cybersecurity. Machine learning and deep learning approaches have demonstrated improved capability in identifying complex and evolving attack patterns compared to traditional rule-based systems (Ejeofobiri et al., \u003cspan citationid=\"CR5\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Huang et al., \u003cspan citationid=\"CR14\" class=\"CitationRef\"\u003e2025\u003c/span\u003e). However, most existing AI-driven cybersecurity systems remain reactive, relying on historical data rather than anticipating emerging threats. In addition, these systems often operate as opaque models with limited transparency and weak integration of ethical reasoning and regulatory compliance (Adeniran et al., \u003cspan citationid=\"CR1\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Emmanuel et al., \u003cspan citationid=\"CR6\" class=\"CitationRef\"\u003e2024\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eThis limitation is particularly significant in resource-constrained settings, where healthcare systems face infrastructural constraints, limited cybersecurity capacity, and dependence on externally developed technologies that may not align with local governance frameworks. These conditions increase systemic vulnerability and reduce the ability of institutions to ensure accountability, transparency, and policy compliance in automated cybersecurity operations (Cuadros et al., \u003cspan citationid=\"CR4\" class=\"CitationRef\"\u003e2025\u003c/span\u003e; Folorunso et al., \u003cspan citationid=\"CR11\" class=\"CitationRef\"\u003e2024\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eTo address this gap, this study introduces the Agentic Artificial Intelligence Framework, a governance-embedded cybersecurity architecture that integrates ethical reasoning, regulatory compliance, and adaptive intelligence within autonomous decision-making processes. The framework is grounded in agent-based systems theory, reinforcement learning, and machine ethics, enabling intelligent systems to operate adaptively while remaining aligned with governance constraints (Fard et al., \u003cspan citationid=\"CR9\" class=\"CitationRef\"\u003e2023\u003c/span\u003e; Wooldridge \u0026amp; Jennings, \u003cspan citationid=\"CR22\" class=\"CitationRef\"\u003e1995\u003c/span\u003e). Developed using a design science research approach and evaluated through large-scale simulation, the framework demonstrates that governance and technical performance can be jointly optimized. This study makes three contributions. First, it advances a governance-by-design paradigm for artificial intelligence in cybersecurity. Second, it presents a practical and scalable architecture for healthcare cybersecurity in resource-constrained environments. Third, it provides policy-relevant insights for strengthening institutional resilience and accountability in digital health systems.\u003c/p\u003e"},{"header":"2. Governance Gap in AI-Driven Cybersecurity","content":"\u003cp\u003eArtificial intelligence is increasingly deployed to enhance intrusion detection and automated threat response within healthcare systems. These systems improve the speed and accuracy of identifying known attack patterns using data-driven techniques. However, most current implementations remain fundamentally reactive, relying on predefined datasets and historical attack signatures rather than anticipating emerging or context-specific threats. This limitation reduces their effectiveness in dynamic healthcare environments, where cyber risks continuously evolve and require adaptive, real-time responses (Ali et al., \u003cspan citationid=\"CR3\" class=\"CitationRef\"\u003e2025\u003c/span\u003e; Hassan et al., \u003cspan citationid=\"CR13\" class=\"CitationRef\"\u003e2025\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eA second critical limitation is the opacity of many AI models. Advanced machine learning approaches, particularly deep learning systems, often operate as black-box models that provide limited insight into how decisions are made. This lack of transparency constrains the ability of healthcare institutions to interpret, validate, and audit automated cybersecurity actions. In safety-critical environments, where decisions may involve restricting access to patient data or isolating clinical systems, the absence of explainability introduces significant ethical and operational risks (Marey et al., \u003cspan citationid=\"CR16\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Mohale \u0026amp; Obagbuwa, \u003cspan citationid=\"CR17\" class=\"CitationRef\"\u003e2025\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eMore critically, governance mechanisms in most AI-driven cybersecurity systems remain external to the system architecture. Ethical principles, regulatory requirements, and institutional policies are typically enforced through post-deployment audits or human oversight rather than being embedded within the decision-making process. This separation allows systems to achieve high technical performance while operating outside acceptable ethical and regulatory boundaries, limiting accountability and trust (Emmanuel et al., \u003cspan citationid=\"CR6\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Sunkara, \u003cspan citationid=\"CR20\" class=\"CitationRef\"\u003e2024\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eThese challenges are particularly pronounced in resource-constrained settings. Healthcare institutions in these environments often depend on externally developed cybersecurity technologies that are not aligned with local regulatory frameworks or institutional capacities. This dependency limits contextual adaptability and increases exposure to governance and operational risks, especially in systems where cybersecurity failures can directly affect patient safety and service continuity (Folorunso et al., \u003cspan citationid=\"CR11\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Njoroge, \u003cspan citationid=\"CR19\" class=\"CitationRef\"\u003e2024\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eTaken together, the reactive nature of existing AI systems, their limited transparency, and the externalization of governance mechanisms reveal a fundamental weakness in current cybersecurity approaches. This creates a structural accountability gap in which autonomous systems are capable of acting but are not inherently aligned with the ethical, regulatory, and institutional frameworks within which they operate.\u003c/p\u003e"},{"header":"3. The AAIF Framework","content":"\u003cp\u003eThe Agentic Artificial Intelligence Framework (AAIF) is a governance-embedded cybersecurity architecture designed to integrate ethical reasoning, regulatory compliance, and adaptive intelligence directly within autonomous decision-making processes. Unlike conventional artificial intelligence systems that treat governance as an external constraint, the AAIF operationalizes a governance-by-design paradigm in which ethical and policy considerations are embedded within the core logic of system behavior. This enables cybersecurity systems to not only detect and respond to threats but also ensure that all actions remain aligned with institutional policies, regulatory requirements, and patient safety considerations.\u003c/p\u003e \u003cp\u003eAt the architectural level, the AAIF is structured around an agentic decision loop that continuously monitors network activity, evaluates potential threats, and determines appropriate responses in real time. This loop integrates perception, reasoning, decision, and action, allowing the system to adapt dynamically to evolving threat conditions. The decision-making process is supported by adaptive learning mechanisms, including reinforcement learning, which enable continuous improvement while maintaining alignment with predefined governance rules (Fard et al., \u003cspan citationid=\"CR9\" class=\"CitationRef\"\u003e2023\u003c/span\u003e; Feltus, \u003cspan citationid=\"CR10\" class=\"CitationRef\"\u003e2020\u003c/span\u003e). The overall architecture of the framework is illustrated in Fig.\u0026nbsp;\u003cspan refid=\"Fig1\" class=\"InternalRef\"\u003e1\u003c/span\u003e.\u003c/p\u003e \u003cp\u003e \u003c/p\u003e \u003cp\u003eA central contribution of the framework is the Governance Gate, which functions as a dual-validation mechanism embedded within the decision pipeline. Each proposed action is evaluated against ethical principles and regulatory constraints before execution. Actions that satisfy governance requirements are implemented autonomously, while those associated with uncertainty, elevated risk, or potential ethical conflict are escalated for human oversight. This mechanism ensures that autonomy operates within clearly defined boundaries, preserving accountability while maintaining operational efficiency (Frenette, \u003cspan citationid=\"CR12\" class=\"CitationRef\"\u003e2023\u003c/span\u003e; Joseph et al., \u003cspan citationid=\"CR15\" class=\"CitationRef\"\u003e2024\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eThe AAIF is theoretically grounded in the integration of agent-based systems, reinforcement learning, and machine ethics. Agent theory provides the foundation for autonomous and adaptive system behavior, reinforcement learning supports dynamic optimization in adversarial environments, and machine ethics enables the incorporation of moral reasoning into decision-making processes (Nath \u0026amp; Sahu, \u003cspan citationid=\"CR18\" class=\"CitationRef\"\u003e2020\u003c/span\u003e; Vishwanath et al., \u003cspan citationid=\"CR21\" class=\"CitationRef\"\u003e2024\u003c/span\u003e; Wooldridge \u0026amp; Jennings, \u003cspan citationid=\"CR22\" class=\"CitationRef\"\u003e1995\u003c/span\u003e). This interdisciplinary foundation ensures that the framework balances technical effectiveness with ethical and governance requirements.\u003c/p\u003e \u003cp\u003eTo ensure practical relevance, the AAIF embeds policy and regulatory logic directly within its architecture through alignment with established governance frameworks, including the NIST Cybersecurity Framework 2.0 and the HIPAA Security Rule. This integration transforms governance from a retrospective compliance activity into a continuous and enforceable system capability. As a result, the framework provides a scalable and context-aware approach for deploying ethically aligned cybersecurity systems in healthcare environments, particularly in resource-constrained settings.\u003c/p\u003e"},{"header":"4. Empirical Validation","content":"\u003cp\u003eThe performance of the Agentic Artificial Intelligence Framework was evaluated using a large-scale simulation comprising more than 280,000 network events representing diverse healthcare cybersecurity scenarios, including ransomware, phishing, insider threats, and Internet of Medical Things attacks. The simulation environment was designed to reflect the operational conditions of a Ugandan teaching hospital, incorporating the infrastructural constraints and resource limitations characteristic of healthcare systems in low- and middle-income countries.\u003c/p\u003e \u003cp\u003eThe results demonstrate that governance-embedded artificial intelligence can achieve substantial performance improvements without compromising accountability. The framework reduced response time by 34.8 percent and improved system recovery rates by 41.6 percent compared to conventional AI-based cybersecurity approaches. In addition, the framework achieved an Ethical Compliance Rate of 0.99, with no false escalations, indicating consistent alignment with predefined ethical and regulatory constraints. Comparative performance across different cybersecurity approaches is summarized in Table\u0026nbsp;\u003cspan refid=\"Tab1\" class=\"InternalRef\"\u003e1\u003c/span\u003e.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab1\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 1\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003eComparative performance of the proposed AAIF against existing AI-based cybersecurity frameworks across accuracy, ethical compliance, resilience, and decision latency.\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"6\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c5\" colnum=\"5\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c6\" colnum=\"6\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eFramework\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eAccuracy\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003eF1 Score\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003eEthical Compliance Rate\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c5\"\u003e \u003cp\u003eResilience Index\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c6\"\u003e \u003cp\u003eDecision Latency (ms)\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eTraditional IDS\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e0.92\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e0.90\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e0.67\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e0.43\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e28\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eExplainable IDS\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e0.94\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e0.91\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e0.81\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e0.47\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e32\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eTrust-Aware IDS\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e0.95\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e0.93\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e0.89\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e0.49\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e34\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e\u003cb\u003eAAIF (Proposed)\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c2\"\u003e \u003cp\u003e\u003cb\u003e0.97\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e\u003cb\u003e0.95\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c4\"\u003e \u003cp\u003e\u003cb\u003e0.99\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c5\"\u003e \u003cp\u003e\u003cb\u003e0.51\u003c/b\u003e\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c6\"\u003e \u003cp\u003e35\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003eThese findings provide clear evidence that embedding governance mechanisms within AI architectures enhances both cybersecurity effectiveness and institutional accountability in resource-constrained healthcare environments.\u003c/p\u003e"},{"header":"5. Policy Implications and Recommendations","content":"\u003cp\u003eThe empirical findings demonstrate that governance and cybersecurity performance can be jointly optimized within a unified artificial intelligence architecture. To translate these findings into practice, four strategic actions are recommended.\u003c/p\u003e \u003cdiv id=\"Sec6\" class=\"Section2\"\u003e \u003ch2\u003e5.1 Governance by Design as a Requirement\u003c/h2\u003e \u003cp\u003eGovernance by design should be established as a mandatory requirement in national cybersecurity strategies and digital health policies. Artificial intelligence systems deployed in healthcare must embed ethical oversight, regulatory compliance, and transparent decision-making within their core architecture rather than relying on post-deployment controls.\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec7\" class=\"Section2\"\u003e \u003ch2\u003e5.2 Institutionalization of Regulatory Sandboxes\u003c/h2\u003e \u003cp\u003eRegulatory authorities should establish controlled sandbox environments to enable the testing and validation of governance-embedded AI systems under real-world conditions. These environments support iterative evaluation, risk management, and safe deployment before large-scale implementation.\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec8\" class=\"Section2\"\u003e \u003ch2\u003e5.3 Investment in Local Capacity Development\u003c/h2\u003e \u003cp\u003eGovernments and development partners should prioritize investment in local research, technical training, and innovation ecosystems focused on AI governance and healthcare cybersecurity. Strengthening local expertise reduces dependency on external systems and ensures alignment with national regulatory and institutional requirements.\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec9\" class=\"Section2\"\u003e \u003ch2\u003e5.4 Strengthening International and Regional Alignment\u003c/h2\u003e \u003cp\u003eNational policies should align with global and regional governance frameworks to support interoperability, knowledge sharing, and coordinated cybersecurity responses. Harmonized standards enhance cross-border collaboration and reduce fragmentation in interconnected healthcare systems.\u003c/p\u003e \u003c/div\u003e"},{"header":"6. Conclusion","content":"\u003cp\u003eHealthcare cybersecurity is increasingly challenged by the rapid expansion of digital health systems and the growing sophistication of cyber threats. Existing artificial intelligence approaches, while effective in detection, remain limited by reactive design, lack of transparency, and weak integration of governance mechanisms. These limitations are particularly critical in resource-constrained environments, where institutional capacity, regulatory alignment, and accountability are essential for safeguarding patient safety and maintaining trust. This study introduced the Agentic Artificial Intelligence Framework as a governance-embedded cybersecurity architecture that integrates ethical reasoning, regulatory compliance, and adaptive intelligence within autonomous decision-making processes. The empirical results demonstrate that governance-by-design enhances both system performance and accountability, confirming that governance is not an optional layer but a foundational requirement for effective AI-driven cybersecurity. The findings provide both a scalable technical solution and actionable policy direction, supporting the development of resilient, transparent, and ethically aligned healthcare cybersecurity systems in resource-constrained settings.\u003c/p\u003e"},{"header":"Declarations","content":" \u003cp\u003e \u003cstrong\u003eEthics Approval and Consent to Participate\u003c/strong\u003e \u003cp\u003eThis study did not involve human participants, human subjects, or identifiable personal data. The research was conducted as part of an approved doctoral study. Ethical clearance was obtained from the Kampala International University Research Ethics Committee (KIU-REC) and the Uganda National Council for Science and Technology (UNCST). As no human participants were involved, informed consent was not applicable.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eConsent for Publication\u003c/strong\u003e \u003cp\u003eNot applicable. This manuscript does not contain any person\u0026rsquo;s data in any form.\u003c/p\u003e \u003c/p\u003e\u003cp\u003e \u003ch2\u003eCompeting Interests\u003c/h2\u003e \u003cp\u003eThe authors declare that they have no competing interests.\u003c/p\u003e \u003c/p\u003e\u003ch2\u003eFunding\u003c/h2\u003e \u003cp\u003eThis work was conducted as part of doctoral research at Kampala International University. No specific external funding was received for this study.\u003c/p\u003e\u003ch2\u003eAuthor Contribution\u003c/h2\u003e\u003cp\u003eI.A. conceived the study, developed the governance protocol and Agentic Artificial Intelligence Framework, designed the system architecture, and drafted the original manuscript. B.O.S. supervised the research and contributed to experimental validation and manuscript revision. A.N.S. contributed to methodological development and technical validation. Y.I.D. conducted model training, performed formal analysis, and contributed to results interpretation. V.M. managed data curation and supported experimental implementation and governance integration. J.M. contributed to data curation, experimental configuration, and governance operationalization. All authors reviewed and approved the final manuscript.\u003c/p\u003e\u003ch2\u003eData Availability\u003c/h2\u003e\u003cp\u003eThe AAIF source code and associated validation datasets, including CICIDS2017, CSE-CIC-IDS2018, and DARPA r6.2, are publicly available at [https://github.com/ibrahimadabara01/aaif-cybersecurity-framework](https:/github.com/ibrahimadabara01/aaif-cybersecurity-framework) . Simulation configurations and governance parameter files are provided within the repository documentation.\u003c/p\u003e"},{"header":"References","content":"\u003col\u003e\u003cli\u003e\u003cspan\u003eAdeniran AA, Peace A, William P. Explainable AI (XAI) in healthcare: Enhancing trust and transparency in critical decision-making. World J Adv Res Reviews. 2024;23(3):2447\u0026ndash;658. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.30574/WJARR.2024.23.3.2936\u003c/span\u003e\u003cspan address=\"10.30574/WJARR.2024.23.3.2936\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eAlgarni AM, Thayananthan V. Cybersecurity for Analyzing Artificial Intelligence (AI)-Based Assistive Technology and Systems in Digital Health. Syst 2025. 2025;13(6):439. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.3390/SYSTEMS13060439\u003c/span\u003e\u003cspan address=\"10.3390/SYSTEMS13060439\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e. \u003cem\u003e13\u003c/em\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eAli ML, Thakur K, Schmeelk S, Debello J, Dragos D. Deep Learning vs. Machine Learning for Intrusion Detection in Computer Networks: A Comparative Study. Appl Sci. 2025;15(4). \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.3390/APP15041903\u003c/span\u003e\u003cspan address=\"10.3390/APP15041903\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eCuadros DF, Kiragga A, Tu L, Awad S, Bwanika JM, Musuka G. (2025). Unpacking social and digital determinants of health in Africa: a narrative review on challenges and opportunities. \u003cem\u003eMHealth\u003c/em\u003e, \u003cem\u003e11\u003c/em\u003e. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.21037/MHEALTH-24-73\u003c/span\u003e\u003cspan address=\"10.21037/MHEALTH-24-73\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eEjeofobiri CK, Victor-Igun OO, Okoye C. AI-Driven Secure Intrusion Detection for Internet of Things (IOT) Networks. Asian J Math Comput Res. 2024;31(4):40\u0026ndash;55. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.56557/AJOMCOR/2024/V31I48971\u003c/span\u003e\u003cspan address=\"10.56557/AJOMCOR/2024/V31I48971\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eEmmanuel C, Edima DE, Iboro AE, Joshua OA, Eseoghene DE, Cadet E, Etim ED, Essien IA, Ajayi JO, Erigha ED. Ethical Challenges in AI-Driven Cybersecurity Decision-Making. Int J Sci Res Comput Sci Eng Inform Technol. 2024;10(3):1031\u0026ndash;64. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.32628/CSEIT25113577\u003c/span\u003e\u003cspan address=\"10.32628/CSEIT25113577\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eEmmanuel Cadet ED, Etim IA, Essien, Eseoghene Daniel Erigha. Joshua Oluwagbenga Ajayi, \u0026amp;. (2024). Ethical Challenges in AI-Driven Cybersecurity Decision-Making. \u003cem\u003eInternational Journal of Scientific Research in Computer Science, Engineering and Information Technology\u003c/em\u003e, \u003cem\u003e10\u003c/em\u003e(3), 1031\u0026ndash;1064. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.32628/CSEIT25113577\u003c/span\u003e\u003cspan address=\"10.32628/CSEIT25113577\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eEwoh P, Vartiainen T. Vulnerability to Cyberattacks and Sociotechnical Solutions for Health Care Systems: Systematic Review. J Med Internet Res. 2024;26. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.2196/46904\u003c/span\u003e\u003cspan address=\"10.2196/46904\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eFard NE, Selmic RR, Khorasani K. A Review of Techniques and Policies on Cybersecurity Using Artificial Intelligence and Reinforcement Learning Algorithms. IEEE Technol Soc Mag. 2023;42(3):57\u0026ndash;68. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1109/MTS.2023.3306540\u003c/span\u003e\u003cspan address=\"10.1109/MTS.2023.3306540\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eFeltus C. Reinforcement Learning\u0026rsquo;s Contribution to the Cyber Security of Distributed Systems. Int J Distrib Artif Intell. 2020;12(2):35\u0026ndash;55. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.4018/IJDAI.2020070103\u003c/span\u003e\u003cspan address=\"10.4018/IJDAI.2020070103\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eFolorunso A, Babalola O, Nwatu CE, Ukonne U. Compliance and Governance issues in Cloud Computing and AI: USA and Africa. Global J Eng Technol Adv. 2024;21(2):127\u0026ndash;38. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.30574/GJETA.2024.21.2.0213\u003c/span\u003e\u003cspan address=\"10.30574/GJETA.2024.21.2.0213\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eFrenette J. Ensuring human oversight in high-performance AI systems: A framework for control and accountability. World J Adv Res Reviews. 2023;20(2):1507\u0026ndash;16. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.30574/WJARR.2023.20.2.2194\u003c/span\u003e\u003cspan address=\"10.30574/WJARR.2023.20.2.2194\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eHassan SADH, Rasheed AA, Mousa AA, Hussein ZA, Ambudkar B. The Rising Cost of Cyberattacks: Trends and Impacts across Industries. HighTech Innov J. 2025;6(2):524\u0026ndash;36. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.28991/HIJ-2025-06-02-011\u003c/span\u003e\u003cspan address=\"10.28991/HIJ-2025-06-02-011\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eHuang K, Huang J, Mehmood Y, Atta H, Baig M, Haq MAU. (2025). AAGATE: A NIST AI RMF-Aligned Governance Platform for Agentic AI. \u003cem\u003eArXiv\u003c/em\u003e, \u003cem\u003eabs/2510.2\u003c/em\u003e. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.48550/ARXIV.2510.25863\u003c/span\u003e\u003cspan address=\"10.48550/ARXIV.2510.25863\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eJoseph SA, Kolade TM, Obioha-Val O, Adebiyi OO, Ogungbemi OS, Olaniyi OO. AI-Powered Information Governance: Balancing Automation and Human Oversight for Optimal Organization Productivity. Asian J Res Comput Sci. 2024;17(10):110\u0026ndash;31. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.9734/AJRCOS/2024/V17I10513\u003c/span\u003e\u003cspan address=\"10.9734/AJRCOS/2024/V17I10513\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eMarey A, Arjmand P, Alerab ADS, Eslami MJ, Saad AM, Sanchez N, Umair M. Explainability, transparency and black box challenges of AI in radiology: impact on patient care in cardiovascular radiology. Egypt J Radiol Nuclear Med. 2024;55(1). \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1186/S43055-024-01356-2\u003c/span\u003e\u003cspan address=\"10.1186/S43055-024-01356-2\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eMohale VZ, Obagbuwa IC. (2025). A systematic review on the integration of explainable artificial intelligence in intrusion detection systems to enhancing transparency and interpretability in cybersecurity. \u003cem\u003eFrontiers in Artificial Intelligence\u003c/em\u003e, \u003cem\u003e8\u003c/em\u003e. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.3389/FRAI.2025.1526221\u003c/span\u003e\u003cspan address=\"10.3389/FRAI.2025.1526221\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eNath R, Sahu V. The problem of machine ethics in artificial intelligence. AI Soc. 2020;35(1):103\u0026ndash;11. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1007/S00146-017-0768-6\u003c/span\u003e\u003cspan address=\"10.1007/S00146-017-0768-6\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eNjoroge JW. Comparative Analysis Of Ai Governance In Africa Relative To Global Standards And Practices. IOSR J Comput Eng. 2024;26(5):19\u0026ndash;25. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.9790/0661-2605031925\u003c/span\u003e\u003cspan address=\"10.9790/0661-2605031925\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eSunkara G. Ethical and regulatory implications of AI in cybersecurity surveillance. World J Adv Res Reviews. 2024;24(2):2895\u0026ndash;905. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.30574/WJARR.2024.24.2.3571\u003c/span\u003e\u003cspan address=\"10.30574/WJARR.2024.24.2.3571\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eVishwanath A, Dennis LA, Slavkovik M. (2024). Reinforcement Learning and Machine ethics:a systematic review. \u003cem\u003eArXiv\u003c/em\u003e, \u003cem\u003eabs/2407.0\u003c/em\u003e. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.48550/ARXIV.2407.02425\u003c/span\u003e\u003cspan address=\"10.48550/ARXIV.2407.02425\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eWooldridge M, Jennings NR. Intelligent agents: theory and practice. Knowl Eng Rev. 1995;10(2):115\u0026ndash;52. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1017/S0269888900008122\u003c/span\u003e\u003cspan address=\"10.1017/S0269888900008122\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e.\u003c/span\u003e\u003c/li\u003e\u003c/ol\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"discover-artificial-intelligence","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"diai","sideBox":"Learn more about [Discover Artificial Intelligence](https://www.springer.com/44163)","snPcode":"","submissionUrl":"","title":"Discover Artificial Intelligence","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Discover Series","inReviewEnabled":true,"inReviewRevisionsEnabled":true},"keywords":"Agentic artificial intelligence, healthcare cybersecurity, AI governance, intrusion detection, resource constrained settings, ethical AI, governance by design","lastPublishedDoi":"10.21203/rs.3.rs-9231871/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-9231871/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eHealthcare systems are increasingly exposed to cyber threats that compromise patient safety, data integrity, and service continuity, particularly in resource-constrained environments where governance and cybersecurity capacity remain limited. Although artificial intelligence is widely adopted to enhance intrusion detection and automated response, most existing systems remain reactive, opaque, and insufficiently aligned with ethical and regulatory requirements, creating a critical governance gap. This study addresses this challenge by developing the Agentic Artificial Intelligence Framework, a governance-embedded cybersecurity architecture that integrates ethical reasoning, regulatory compliance, and adaptive intelligence within autonomous decision-making processes. The framework was developed using a design science research approach and evaluated through large-scale simulation involving more than 280,000 network events representing diverse healthcare cyber threat scenarios. The results demonstrate that the framework reduced response time by 34.8 percent, improved system recovery rates by 41.6 percent, and achieved an Ethical Compliance Rate of 0.99 without false escalations. These findings show that governance-by-design can enhance both cybersecurity performance and accountability. The study provides a scalable and policy-relevant approach for strengthening resilient, transparent, and ethically aligned healthcare cybersecurity systems in resource-constrained settings.\u003c/p\u003e","manuscriptTitle":"A Governance Embedded Agentic Artificial Intelligence Framework for Healthcare Cybersecurity in Resource Constrained Settings","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-05-11 05:06:40","doi":"10.21203/rs.3.rs-9231871/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"reviewerAgreed","content":"120052325583083602446016843066501174596","date":"2026-05-18T21:06:01+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"195123016518884897168128152460393387876","date":"2026-05-15T14:13:02+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2026-04-27T10:27:18+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2026-04-27T10:21:46+00:00","index":"","fulltext":""},{"type":"editorInvited","content":"","date":"2026-04-25T14:23:20+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2026-04-22T05:31:15+00:00","index":"","fulltext":""},{"type":"submitted","content":"Discover Artificial Intelligence","date":"2026-04-22T05:26:16+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"discover-artificial-intelligence","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"diai","sideBox":"Learn more about [Discover Artificial Intelligence](https://www.springer.com/44163)","snPcode":"","submissionUrl":"","title":"Discover Artificial Intelligence","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Discover Series","inReviewEnabled":true,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"37b51ff0-a7c4-4f7a-9bb9-e967206ec84d","owner":[],"postedDate":"May 11th, 2026","published":true,"recentEditorialEvents":[{"type":"reviewerAgreed","content":"120052325583083602446016843066501174596","date":"2026-05-18T21:06:01+00:00","index":57,"fulltext":""},{"type":"reviewerAgreed","content":"195123016518884897168128152460393387876","date":"2026-05-15T14:13:02+00:00","index":37,"fulltext":""}],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[],"tags":[],"updatedAt":"2026-05-11T05:06:40+00:00","versionOfRecord":[],"versionCreatedAt":"2026-05-11 05:06:40","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-9231871","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-9231871","identity":"rs-9231871","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.