Submitted:
20 July 2026
Posted:
21 July 2026
You are already at the latest version
Abstract

Keywords:
1. Introduction
1.1. Governance Problem and Research Gap
1.2. Research Question and Principal Claim
1.3. Core Concepts and Scope
1.4. Research Approach
1.5. Contributions and Article Structure
2. Literature Review and Conceptual Foundations
2.1. Enterprise Systems Engineering and Digital Transformation
2.2. Socio-Technical AI Governance
2.3. The Boundary Deficit in Existing AI Governance
2.4. Modularity, Organizational Design, and Legal Personhood
2.5. Design Requirements Derived from the Literature
3. Research Design and Framework Construction
3.1. Design-Theoretic Research Method
3.2. Modular Legal Personhood as the Legal-Organizational Substrate
3.3. Modular Operating-Agreement Architecture
3.4. AI Use-Case Module Architecture
3.5. Analytical Traceability of the Framework
4. Governance Functions
4.1. Boundary Definition and Configurational Governance
4.2. Authority, Interfaces, and Resource-Risk Alignment
4.3. Observability, Accountability, and Corrective Control
4.4. Lifecycle Adaptation and Portfolio Coordination
4.5. Governance Synthesis
5. Implementation and Assessment
5.1. Proportional Implementation through Staged Institutionalization
5.2. Operational Correspondence and Assessment Evidence
5.3. Operationalization Through Assessment Dimensions and Indicators
5.4. Analytical Demonstration Through an Illustrative Application
5.5. Interpretation and Validation Limits
6. Discussion
6.1. Functional Portability and Legal-Form Dependence
6.2. Proportionality and the Risk of Over-Formalization
6.3. Responsibility Fragmentation and Anti-Evasion Safeguards
6.4. Contribution to Enterprise Systems Engineering
6.5. Empirical Research Agenda
7. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| AI | Artificial intelligence |
| AI RMF | Artificial Intelligence Risk Management Framework |
| DLLCA | Delaware Limited Liability Company Act |
| ESE | Enterprise Systems Engineering |
| EU | European Union |
| ISO | International Organization for Standardization |
| IEC | International Electrotechnical Commission |
| LLC | Limited liability company |
| NIST | National Institute of Standards and Technology |
| UPSA | Uniform Protected Series Act |
References
- Vial, G. Understanding Digital Transformation: A Review and a Research Agenda. J. Strateg. Inf. Syst. 2019, 28, 118–144. [Google Scholar] [CrossRef]
- Bharadwaj, A.; El Sawy, O.A.; Pavlou, P.A.; Venkatraman, N. Digital Business Strategy: Toward a Next Generation of Insights. MIS Q. 2013, 37, 471–482. [Google Scholar] [CrossRef]
- SEBoK Editorial Board. Enterprise Systems Engineering. Guide to the Systems Engineering Body of Knowledge; 2024; https://sebokwiki.org/wiki/Enterprise_Systems_Engineering.
- Walden, D.D.; Shortell, T.M.; Roedler, G.J.; Delicado, B.; Mornas, O.; Yip, Y.S.; Endler, D. (Eds.) INCOSE Systems Engineering Handbook: A Guide for System Life Cycle Processes and Activities, 5 ed.; John Wiley & Sons: Hoboken, NJ, 2023. [Google Scholar]
- Selbst, A.D.; Boyd, d.; Friedler, S.A.; Venkatasubramanian, S.; Vertesi, J. Fairness and Abstraction in Sociotechnical Systems. In Proceedings of the Proceedings of the 2019 Conference on Fairness, Accountability, and Transparency (FAT* ’19), New York, NY, USA, 2019; FAT* ’19, pp. 59–68. [Google Scholar] [CrossRef]
- Selbst, A.D. An Institutional View of Algorithmic Impact Assessments. Harv. J. Law. Technol. 2021, 35, 117–191. https://jolt.law.harvard.edu/assets/articlePDFs/v35/Selbst-An-Institutional-View-of-Algorithmic-Impact-Assessments.pdf.
- Raji, I.D.; Smart, A.; White, R.N.; Mitchell, M.; Gebru, T.; Hutchinson, B.; Smith-Loud, J.; Theron, D.; Barnes, P. Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing. In Proceedings of the Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency (FAT* ’20), New York, NY, USA, 2020; FAT* ’20, pp. 33–44. [Google Scholar] [CrossRef]
- Okuno, M.J.; Okuno, H.G. Legal frameworks for AI service business participants: A comparative analysis of liability protection across jurisdictions. AI Soc. 2025, 40, 5667–5683. [Google Scholar] [CrossRef]
- Okuno, M.J.; Okuno, H.G. Modular Legal Personhood for AI Use Cases. In Proceedings of the Proc. Intern’l Sympo. on Technology & Society (ISTAS-25), New York, N.Y., 2025; pp. 1–8. [Google Scholar] [CrossRef]
- Yoo, Y.; Boland, R.J., Jr.; Lyytinen, K.; Majchrzak, A. Organizing for Innovation in the Digitized World. Organ. Sci. 2012, 23, 1398–1408. [Google Scholar] [CrossRef]
- Rouse, W.B. Enterprises as Systems: Essential Challenges and Approaches to Transformation. Syst. Eng. 2005, 8, 138–150. [Google Scholar] [CrossRef]
- Maier, M.W. Architecting Principles for Systems-of-Systems. Syst. Eng. 1998, 1, 267–284. [Google Scholar] [CrossRef]
- Jamshidi, M. (Ed.) System of Systems Engineering: Innovations for the 21st Century; John Wiley & Sons: Hoboken, NJ, 2009. [Google Scholar] [CrossRef]
- Trist, E.L. The Evolution of Socio-Technical Systems: A Conceptual Framework and an Action Research Program. Occasional Paper 2, Ontario Quality of Working Life Centre, Toronto, ON. 1981. https://www.lmmiller.com/blog/wp-content/uploads/2013/06/The-Evolution-of-Socio-Technical-Systems-Trist.pdf.
- Suchman, L.A. Plans and Situated Actions: The Problem of Human-Machine Communication; Cambridge University Press: Cambridge, 1987; also available as Xerox PARC ISL-6; https://bitsavers.trailing-edge.com/pdf/xerox/parc/techReports/ISL-6_Plans_and_Situated_Actions.pdf.
- Orlikowski, W.J. The Duality of Technology: Rethinking the Concept of Technology in Organizations. Organ. Sci. 1992, 3, 398–427. [Google Scholar] [CrossRef]
- Baxter, G.; Sommerville, I. Socio-Technical Systems: From Design Methods to Systems Engineering. Interact. With Comput. 2011, 23, 4–17. [Google Scholar] [CrossRef]
- Carayon, P. Human Factors of Complex Sociotechnical Systems. Appl. Ergon. 2006, 37, 525–535. [Google Scholar] [CrossRef] [PubMed]
- Passi, S.; Barocas, S. Problem Formulation and Fairness. In Proceedings of the Proceedings of the Conference on Fairness, Accountability, and Transparency, New York, NY, USA, 2019; FAT* ’19, pp. 39–48. [Google Scholar] [CrossRef]
- Parasuraman, R.; Sheridan, T.B.; Wickens, C.D. A Model for Types and Levels of Human Interaction with Automation. IEEE Trans. Syst. Man. Cybern. – Part A Syst. Hum. 2000, 30, 286–297. [Google Scholar] [CrossRef] [PubMed]
- Sarter, N.B.; Woods, D.D.; Billings, C.E. Automation Surprises. In Handbook of Human Factors and Ergonomics, 2 ed.; Salvendy, G., Ed.; John Wiley & Sons: New York, NY, 1997; pp. 1926–1943. [Google Scholar]
- Metcalf, J.; Moss, E.; danah boyd. Owning Ethics: Corporate Logics, Silicon Valley, and the Institutionalization of Ethics. Soc. Res. An. Int. Q. 2019, 86, 449–476. https://muse.jhu.edu/article/732185. [CrossRef]
- Rakova, B.; Yang, J.; Cramer, H.; Chowdhury, R. Where Responsible AI Meets Reality: Practitioner Perspectives on Enablers for Shifting Organizational Practices. Proc. ACM Hum.-Comput. Interact. 2021, 5, 1–23. [Google Scholar] [CrossRef] [PubMed]
- Jobin, A.; Ienca, M.; Vayena, E. The global landscape of AI ethics guidelines. Nat. Mach. Intell. 2019, 1, 389–399. [Google Scholar] [CrossRef]
- Mittelstadt, B. Principles Alone Cannot Guarantee Ethical AI. Nat. Mach. Intell. 2019, 1, 501–507. [Google Scholar] [CrossRef]
- Schiff, D.; Biddle, J.; et al. What’s Next for AI Ethics, Policy, and Governance? A Global Overview. In Proceedings of the Proceedings of the AAAI/ACM Conf. on AI, Ethics, & Society (AIES’20), New York, N.Y., 2020; pp. 153–158. [Google Scholar] [CrossRef]
- Morley, J.; Floridi, L.; Kinsey, L.; Elhalal, A. From What to How: An Initial Review of Publicly Available AI Ethics Tools, Methods and Research to Translate Principles into Practices. Sci. Eng. Ethics 2020, 26, 2141–2168. [Google Scholar] [CrossRef] [PubMed]
- Mitchell, M.; Wu, S.; Zaldivar, A.; Barnes, P.; Vasserman, L.; Hutchinson, B.; Spitzer, E.; Raji, I.D.; Gebru, T. Model Cards for Model Reporting. In Proceedings of the Proceedings of the Conference on Fairness, Accountability, and Transparency, New York, NY, USA, 2019; FAT* ’19, pp. 220–229. [Google Scholar] [CrossRef]
- Gebru, T.; Morgenstern, J.; Vecchione, B.; Vaughan, J.W.; Wallach, H.; Daumé, H., III; Crawford, K. Datasheets for Datasets. Commun. ACM 2021, 64, 86–92. [Google Scholar] [CrossRef]
- Arnold, M.; Bellamy, R.K.E.; Hind, M.; Houde, S.; Mehta, S.; Mojsilović, A.; Nair, R.; Ramamurthy, K.N.; Olteanu, A.; Piorkowski, D.; et al. FactSheets: Increasing Trust in AI Services through Supplier’s Declarations of Conformity. IBM J. Res. Dev. 2019, 63, 6:1–6:13. [Google Scholar] [CrossRef]
- Bovens, M.A.P. Analysing and Assessing Accountability: A Conceptual Framework. Eur. Law. J. 2007, 13, 447–468. [Google Scholar] [CrossRef]
- Kroll, J.A.; Huey, J.; Barocas, S.; Felten, E.W.; Reidenberg, J.R.; Robinson, D.G.; Yu, H. Accountable Algorithms. Univ. Pa. Law. Rev. 2017, 165, 633–705. https://www.jstor.org/stable/26600576.
- Wieringa, M. What to Account for When Accounting for Algorithms: A Systematic Literature Review on Algorithmic Accountability. In Proceedings of the Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency, New York, NY, USA, 2020; FAT* ’20, pp. 1–18. [Google Scholar] [CrossRef]
- National Institute of Standards and Technology (NIST). Artificial Intelligence Risk Management Framework (AI RMF 1.0). 2023. [Google Scholar] [CrossRef]
- International Organization for Standardization. ISO/IEC 23894:2023; Information Technology – Artificial Intelligence – Guidance on Risk Management. International Standard. 2023. https://www.iso.org/standard/77304.html.
- European Union. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act). Off. J. Eur. Union 2024, L series. [Google Scholar]
- Simon, H.A. The Architecture of Complexity. In Proceedings of the American Philosophical Society; also avialable in; Klaus, P., Muller, S., Eds.; The Roots of Logistics; Springer: Berlin., 1962; Volume 106, pp. 467–482. [Google Scholar] [CrossRef]
- Parnas, D.L. On the Criteria To Be Used in Decomposing Systems into Modules. Commun. ACM 1972, 15, 1053–1058. [Google Scholar] [CrossRef]
- Ulrich, K. The Role of Product Architecture in the Manufacturing Firm. Res. Policy 1995, 24, 419–440. [Google Scholar] [CrossRef]
- Sanchez, R.; Mahoney, J.T. Modularity, Flexibility, and Knowledge Management in Product and Organization Design. Strateg. Manag. J. 1996, 17, 63–76. [Google Scholar] [CrossRef]
- Baldwin, C.Y.; Clark, K.B. Design Rules, Volume 1: The Power of Modularity; The MIT Press: Cambridge, MA, 2000; Volume 1. [Google Scholar]
- Kraakman, R.; Armour, J.; Davies, P.; Enriques, L.; Hansmann, H.; Hertig, G.; Hopt, K.; Kanda, H.; Pargendler, M.; Ringe, W.G.; et al. The Anatomy of Corporate Law: A Comparative and Functional Approach, 3 ed.; Oxford University Press: London, U.K., 2017. [Google Scholar]
- Hansmann, H.; Kraakman, R. The essential role of organizational law. Yale Law. J. 2000, 110, 387–440. https://heinonline.org/HOL/Page?handle=hein.journals/ylr110&id=405. [CrossRef]
- Hansmann, H.; Kraakman, R. Organizational Law as Asset Partitioning. Eur. Econ. Rev. 2000, 44, 807–817. [Google Scholar] [CrossRef]
- Hansmann, H.; Kraakman, R.; Squire, R. Law and the Rise of the Firm. Harv. Law. Rev. 2006, 119, 1335–1403. https://access.heinonline.com/HOL/P?h=hein.journals/hlr119&i=1365.
- Solum, L.B. Legal Personhood for Artificial Intelligences. N. C. Law. Rev. 1992, 70, 1231–1287. https://scholarship.law.unc.edu/nclr/vol70/iss4/4.
- Bryson, J.J.; Diamantis, M.E.; Grant, T.D. Of, for, and by the People: The Legal Lacuna of Synthetic Persons. Artif. Intell. Law. 2017, 25, 273–291. [Google Scholar] [CrossRef]
- Chesterman, S. Artificial Intelligence and the Limits of Legal Personality. Int. Comp. Law. Q. 2020, 69, 819–844. [Google Scholar] [CrossRef]
- Zech, H. Liability for AI: Public policy considerations. ERA Forum 2021, 22, 147–158. [Google Scholar] [CrossRef]
- Bayern, S. The Implications of Modern Business-Entity Law for the Regulation of Autonomous Systems. Stanf. Technol. Law. Rev. 2015, 19, 93–112. https://law.stanford.edu/wp-content/uploads/2017/11/19-1-4-bayern-final_0.pdf.
- LoPucki, L.M. Algorithmic Entities. Wash. Univ. Law. Rev. 2018, 95, 887. https://openscholarship.wustl.edu/law_lawreview/vol95/iss4/7.
- Ribstein, L.E. The Rise of the Uncorporation; Oxford University Press: New York, NY, 2009. [Google Scholar] [CrossRef]
- Molk, P. How Do LLC Owners Contract Around Default Statutory Protections? J. Corp. Law. 2017, 42, 503–557. [Google Scholar]
- Uniform Law Commission. Uniform Protected Series Act (UPSA) with Prefatory key and Comments, 2017. https://www.uniformlaws.org/HigherLogic/System/DownloadDocumentFile.ashx?DocumentFileKey=30c1060c-0ea7-4ed4-9d48-df97c991f4b9.
- DLLCA. Del. Code Ann tit. 6, §18-215 (protected series). 1996. https://delcode.delaware.gov/title6/c018/sc02/index.html#18-215.
- Keatinge, R.R.; Conaway, A.E.; Rutledge, T.E.; Ely, B.P. Keatinge and Conaway on Choice of Business Entity; Thomson Reuters: Eagan, MN, 2024. [Google Scholar]
- Sargent, M.A.; Schwudetzky, W.D. Limited Liability Company Handbook; Thomson Reuters: Eagan, MN, 2024. [Google Scholar]
- AlSayyad, A.; Huang, K.Y.; Pal, R. AgentTrace: A Structured Logging Framework for Agent System Observability, 2026. arXiv:cs.SE/2602.10133.
- European Parliament. European Parliament Resolution of 16 February 2017 with Recommendations to the Commission on Civil Law Rules on Robotics, 2017. https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_EN.html.






| Design requirement | Prototype legal-organizational response | Contractual or architectural realization | Expected governance consequence |
|---|---|---|---|
| Determinate boundary identity | Differentiated protected series within an associated LLC, or an equivalent institutionally bounded unit | Authorized purpose, scope, management structure, and enterprise relationship in the common core and constitutional layer | An identifiable system of interest whose correspondence with the operating deployment can be assessed, including use drift and unauthorized expansion |
| Configurable governance | Contractual autonomy within a continuing organizational structure | Common contractual core combined with selected deployment-specific riders | Stable baseline governance with controlled and reviewable deployment-specific variation |
| Authority-interface alignment | Allocation of management rights, reserved powers, and external relationships | Constitutional and operational provisions governing actors, vendors, infrastructure, workflows, and intervention rights | Decision authority corresponds more closely to the interfaces through which the deployment operates |
| Resource-risk capacity | Association of resources and obligations with the module, supported by enterprise escalation | Resource commitments, insurance or financial arrangements, technical access, staffing, and escalation provisions | Responsibility is supported by substantive capacity rather than assigned nominally |
| Reviewable evidence and corrective capacity | Separate but accessible records associated with the use case, together with identifiable review and corrective authority | Accountability-layer duties covering approvals, documentation, incidents, interventions, audits, escalation, remediation, and suspension | Reviewers can reconstruct the relationship between governance commitments, operational decisions, and consequences, and connect substantiated findings to proportionate action |
| Lifecycle adaptation | Continuing institutional identity combined with controlled amendment | Material-change triggers, periodic review, rider amendment, revalidation, suspension, and retirement procedures | The governance configuration can evolve without losing continuity or permitting informal drift |
| Organizational anchoring | Continuing relationship between the protected series and associated LLC | Portfolio oversight, shared-capability rules, reserved enterprise powers, and associated-LLC or enterprise-level escalation | Modularization differentiates governance without displacing broader enterprise responsibility |
| External reference point | Selected governance focus | Use in the present assessment |
|---|---|---|
| NIST AI Risk Management Framework [34] | The Govern, Map, Measure, and Manage functions across the AI lifecycle | Provides a reference point for assessing whether the module addresses organizational governance, deployment context, risk measurement, prioritization, treatment, and response |
| ISO/IEC 23894 [35] | Integration of AI risk identification, analysis, evaluation, treatment, monitoring, and communication into organizational activities and processes | Provides a reference point for assessing whether risk responsibilities, resources, monitoring information, communication, treatment, and lifecycle processes are connected to the governed use case |
| EU AI Act [36] | Selected obligations, where applicable, concerning intended purpose, risk management, technical documentation, logging, human oversight, serious-incident reporting, corrective action, and post-market monitoring | Provides a reference point for assessing whether relevant legal obligations can be associated with an identifiable deployment, responsible actors, accessible records, effective oversight, and corrective powers |
| Dimension | Diagnostic question | Illustrative indicator | Principal evidence |
|---|---|---|---|
| Boundary integrity | Does current operation remain within the authorized purpose and scope? | Sampled operational instances conforming to the authorized purpose, scope, workflow, and decision context divided by total sampled instances; count and severity classification of material boundary deviations | Authorization records, workflow samples, system logs, change records, operating procedures, complaints, and stakeholder reports |
| Configuration adequacy | Does the current governance configuration address the material conditions of the deployment? | Material deployment conditions addressed by a current, applicable, and verified governance control divided by total material conditions requiring control | Applicable agreements, rider register, risk classification, dependency inventory, configuration history, and implementation tests |
| Authority-interface coverage | Does each material interface have an actor with effective control, influence, or escalation authority? | Validated material interfaces with a verified control, influence, or escalation path divided by total validated material interfaces | Responsibility matrices, access rights, contracts, service agreements, escalation tests, interviews, and observed exercises |
| Resource-risk capacity | Do responsible actors possess capacity proportionate to assigned risks and duties? | Critical responsibilities for which staffing, expertise, technical access, available time, and response resources meet predefined capacity thresholds divided by total critical responsibilities | Staffing, expertise, budget, technical access, financial or insurance arrangements where relevant, response resources, and workload data |
| Evidentiary continuity | Can material decisions and events be reconstructed across participants and systems? | Sampled material events with a complete and accessible evidence chain from authorization through review and disposition divided by total sampled material events | Logs, approvals, model and data records, intervention records, audit files, incident documentation, and review records |
| Corrective responsiveness | Do substantiated findings produce timely and proportionate organizational action? | Corrective actions completed within the applicable severity-based threshold divided by total actions due; completed actions verified as effective divided by total completed actions; median time from substantiated finding to containment | Finding registers, remediation plans, suspension records, escalation decisions, effectiveness reviews, recurrence data, and closure evidence |
| Lifecycle and portfolio coordination | Are material changes and cross-module effects identified and reviewed within the required period? | Material changes reviewed within the applicable threshold divided by total material changes; findings involving shared dependencies communicated and assessed within the applicable threshold divided by total such findings | Change records, periodic reviews, dependency registers, portfolio reports, shared-service notifications, and cross-module incident analysis |
| Dimension | Scenario observation | Diagnostic implication | Indicated governance response |
|---|---|---|---|
| Boundary integrity | Outputs are used in additional patient-flow and resource-allocation decisions that were not included in the original authorization | The operational use case exceeds its authorized purpose and scope, resulting in a loss of boundary correspondence | Restrict the expanded use pending formal reassessment, or amend the authorization and related controls before the expanded use continues |
| Configuration adequacy | The model update, workflow expansion, and reduced conditions for meaningful clinical review are not reflected in the current governance configuration | The applicable controls correspond to the earlier deployment rather than to current operating conditions | Reassess the material changes, risk classification, and oversight requirements, and amend the applicable configuration and associated controls |
| Authority-interface coverage | Hospital oversight depends on vendor-controlled update information, while the scenario does not establish a verified path for obtaining timely information or requiring vendor action | Formal responsibility is not matched by effective authority over a material external interface | Establish timely information and intervention rights, vendor change-notification duties, and a tested escalation path |
| Resource-risk capacity | The expanded use increases monitoring and review demands while clinical workload reduces the time available for meaningful review | Available governance capacity is not proportionate to the expanded scope and operational consequences | Increase protected review time, staffing, expertise, monitoring, and response resources, or reduce the deployment scope |
| Evidentiary continuity | Hospital records and vendor update records remain divided and cannot be reliably connected with case-level decision histories | Material events cannot be reconstructed through a complete and accessible evidence chain from authorization through review and disposition | Implement shared identifiers, access rights, retention rules, evidence-exchange procedures, and periodic reconstruction tests |
| Corrective responsiveness | Review bodies can identify the concern, although the scenario does not establish who may restrict the expanded workflow, require vendor remediation, or suspend use of the service | Substantiated findings do not connect to a complete and timely corrective decision path | Assign restriction, remediation, suspension, and escalation authority, establish severity-based response thresholds, and verify the effectiveness of completed actions |
| Lifecycle and portfolio coordination | The model update and emerging incident pattern are not assessed for another hospital function using the same service | A module-level change may propagate through a shared dependency without portfolio-level review | Initiate portfolio review, notify affected modules, assess the shared dependency, and coordinate corrective action and revalidation |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).