<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="review-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">JCS</journal-id>
<journal-id journal-id-type="nlm-ta">JCS</journal-id>
<journal-id journal-id-type="publisher-id">JCS</journal-id>
<journal-title-group>
<journal-title>Journal of Cyber Security</journal-title>
</journal-title-group>
<issn pub-type="epub">2579-0064</issn>
<issn pub-type="ppub">2579-0072</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">66312</article-id>
<article-id pub-id-type="doi">10.32604/jcs.2025.066312</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Review</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Ethical Implications of AI-Driven Ethical Hacking: A Systematic Review and Governance Framework</article-title>
<alt-title alt-title-type="left-running-head">Ethical Implications of AI-Driven Ethical Hacking: A Systematic Review and Governance Framework</alt-title>
<alt-title alt-title-type="right-running-head">Ethical Implications of AI-Driven Ethical Hacking: A Systematic Review and Governance Framework</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Sufficient</surname><given-names>Hossana Maghiri</given-names></name><email>Hossanasufficient@gmail.com</email></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Mohammed</surname><given-names>Abdulazeez Murtala</given-names></name></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Danjuma</surname><given-names>Bashir</given-names></name></contrib>
<aff id="aff-1">
<institution>Department of Cyber Security, Faculty of Computing, Nigerian Army University Biu</institution>, <addr-line>Biu, 603108</addr-line>, <country>Nigeria</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Hossana Maghiri Sufficient. Email: <email>Hossanasufficient@gmail.com</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>14</day><month>07</month><year>2025</year>
</pub-date>
<volume>7</volume>
<issue>1</issue>
<fpage>239</fpage>
<lpage>253</lpage>
<history>
<date date-type="received">
<day>04</day>
<month>4</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>23</day>
<month>6</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_JCS_66312.pdf"></self-uri>
<abstract>
<p>The rapid integration of artificial intelligence (AI) into ethical hacking practices has transformed vulnerability discovery and threat mitigation; however, it raises pressing ethical questions regarding responsibility, justice, and privacy. This paper presents a PRISMA-guided systematic review of twelve peer-reviewed studies published between 2015 and March 2024, supplemented by Braun and Clarke&#x2019;s thematic analysis, to map four core challenges: (1) autonomy and human oversight, (2) algorithmic bias and mitigation strategies, (3) data privacy preservation mechanisms, and (4) limitations of General Data Protection Regulation (GDPR) and the European Union&#x2019;s AI Act in addressing AI-specific risks, alongside the imperative to balance automation with expert judgment. While artificial intelligence has greatly enhanced efficiency and reduced hazard detection, its actual lack of transparency and dependence on past data may exacerbate inequality in its approach, adversely affecting under-resourced sectors such as rural healthcare systems and small enterprises. For example, a 2024 University of Illinois Urbana-Champaign study demonstrated that generative pre-trained transformer 4 (GPT-4) agents could autonomously exploit 87% of one-day vulnerabilities in a small-business web application, illustrating how AI-driven attacks can rapidly overwhelm under-resourced enterprises without dedicated security teams. To promote equity and accountability, we advocate embedding bias-aware data curation toolkits (e.g., IBM AI Fairness 360, Google What-If Tool, Microsoft Fairlearn, Aequitas) at the data-ingestion stage and adopting adaptive governance models with continuous impact assessments and human-in-the-loop checkpoints. Our findings inform a pragmatic framework for harmonizing regulatory, technical, and organizational controls, and we outline a research agenda focused on adaptive oversight, privacy-enhancing policies, and multidisciplinary collaboration to guide responsible deployment of AI in cybersecurity.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>AI in cybersecurity</kwd>
<kwd>ethical hacking</kwd>
<kwd>algorithmic bias</kwd>
<kwd>privacy-preserving AI</kwd>
<kwd>dual-use dilemma</kwd>
<kwd>human-AI collaboration</kwd>
<kwd>regulatory frameworks</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>Artificial intelligence (AI) has revolutionised ethical hacking and cybersecurity testing by enhancing security defense mechanisms through its integration. Ref. [<xref ref-type="bibr" rid="ref-1">1</xref>] defines ethical hacking as the computer and information system vulnerabilities and weaknesses. Although successful, manual vulnerability detection and penetration testing grounded in conventional techniques required great human effort to monitor vast, complicated datasets [<xref ref-type="bibr" rid="ref-2">2</xref>]. The automated abilities of artificial intelligence simultaneously detect network weaknesses, which shorten the duration for extensive threat recognition. Real-time cybersecurity instruments such as IBM Watson for Cybersecurity and Darktrace Antigena work independently to detect attack patterns and defense strategies in operational situations [<xref ref-type="bibr" rid="ref-3">3</xref>]. Because AI detects risks faster in corporate systems while processing more data than human analysis, the present trend in cybersecurity has brought major changes [<xref ref-type="bibr" rid="ref-4">4</xref>].</p>
<p>Ethical questions must receive urgent assessment because artificial intelligence systems have enabled quick responses and automated operations in their ethical hacking tools [<xref ref-type="bibr" rid="ref-5">5</xref>]. The implementation of artificial intelligence in automated ethical hacking operations generates various principal drawbacks, which encompass responsibility issues together with prejudice risks and disagreement about ethical hacking practices [<xref ref-type="bibr" rid="ref-6">6</xref>]. According to the 2023 Deloitte CTI research, 46% of companies worry about AI tools, especially ChatGPT, which could be abused for building covert phishing attacks and polymorphic malware due lack of ethical protection [<xref ref-type="bibr" rid="ref-7">7</xref>]. At the same time, revealing medical patient information, hackers succeeded in reverse-engineering penetration testing AI software to circumvent healthcare firewalls [<xref ref-type="bibr" rid="ref-8">8</xref>].</p>
<p>These instances draw attention to the operational conflict artificial intelligence self-determination faces against human monitoring responsibilities. Article 14 of the Artificial Intelligence Act (AIA), implemented in August 2024, calls for human oversight of important AI systems. According to [<xref ref-type="bibr" rid="ref-9">9</xref>], the AIA has come under fire for inadequate control of dual-use circumstances whereby defensive technology like AI-driven vulnerability scanners becomes an attacking weapon. Regulatory deficiency causes numerous parties to share accountability when artificial intelligence systems make mistakes or misuse takes place. Through its dual-use risk assessment and governance structure construction for AI-driven ethical hacking solutions, which prior works like [<xref ref-type="bibr" rid="ref-6">6</xref>] mostly overlook, this study closes present research gaps.</p>
<p>AI systems provide a serious ethical challenge right now since their algorithms are biased and influence their operation [<xref ref-type="bibr" rid="ref-10">10</xref>]. Field investigation shows that AI systems fed biased knowledge fuel security prejudices. Specifically, because they were taught on enormous volumes of corporate system data while neglecting susceptible minority sectors, the penetration testing tools driven by AI failed to identify 34% of all vulnerabilities within small-business networks [<xref ref-type="bibr" rid="ref-11">11</xref>].</p>
<p>Large amounts of data challenge privacy rules since they call for intensive data processing [<xref ref-type="bibr" rid="ref-12">12</xref>]. Details the 2023 penetration test intrusion of a South African healthcare platform that exposed 50,000 unsecured patient records to an AI ethical hacking tool, violating GDPR in the EU and NDPR in Nigeria. AI systems tend to be opaque and demand vast volumes of data, which violates privacy rules mandating more protection of sensitive data. This way, the way AI enhances security detection methods causes problems with privacy laws.</p>
<p>AI ethics&#x2019; dual-use operational qualities help to explain their highest point. ChatGPT, combined with other tools meant to replicate phishing attacks for defensive training purposes, has been turned into attack-centric tools for creating realistic phishing emails, which, according to [<xref ref-type="bibr" rid="ref-7">7</xref>,<xref ref-type="bibr" rid="ref-13">13</xref>], led to a 27% increase in social engineering incidents executed by AI technology. According to [<xref ref-type="bibr" rid="ref-9">9</xref>], the open-source AI models from OpenAI Codex are being increasingly manipulated by attackers using them to generate automatically scaled zero-day attacks. Emphasising openness above abuse protection, the EU AI Act 2024 contains legislative flaws when attempting to address dual-use possibilities in artificial intelligence. Between earlier studies on technological efficiency models [<xref ref-type="bibr" rid="ref-6">6</xref>], this research investigates both dual-use security issues and governance vulnerabilities with pragmatic methods to reconcile the alignment between AI&#x2019;s protective characteristics with moral norms.</p>
<sec id="s1_1">
<label>1.1</label>
<title>Organization of the Study</title>
<p><xref ref-type="sec" rid="s2">Section 2</xref> reviews existing literature on AI in cybersecurity, highlighting gaps in ethical oversight. <xref ref-type="sec" rid="s3">Section 3</xref> details our systematic review methodology, including PRISMA screening and thematic analysis to extract four core ethical challenges. In <xref ref-type="sec" rid="s4">Section 4</xref>, we present and critically discuss these challenges: accountability gaps, algorithmic bias, privacy risks, and the dual-use dilemma, along with real-world examples. <xref ref-type="sec" rid="s5">Section 5</xref>, The Way Forward, proposes a set of technical controls, policy recommendations, and research agendas. Finally, <xref ref-type="sec" rid="s6">Section 6</xref> concludes by reflecting on limitations and outlining avenues for future work.</p>
</sec>
<sec id="s1_2">
<label>1.2</label>
<title>Key Contributions</title>
<p><list list-type="order">
<list-item><p><bold>Comprehensive ethical map.</bold> We identify and rigorously define four principal ethical challenges introduced by AI in ethical hacking, supported by twelve peer-reviewed case studies.</p></list-item>
<list-item><p><bold>Methodological clarity.</bold> We detail our dual-review PRISMA approach and thematic coding process, ensuring reproducibility.</p></list-item>
<list-item><p><bold>Practical framework.</bold> We integrate insights into a unified set of governance principles spanning adaptive regulation, bias-aware dataset curation, and accountability structures tailored for low-resource environments.</p></list-item>
<list-item><p><bold>Research agenda.</bold> We articulate seven targeted questions to guide future empirical studies on AI ethics in offensive security.</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s2">
<label>2</label>
<title>Methods/Materials</title>
<p>Following all PRISMA (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) guidelines (See Supplementary Materials) helps us to keep methodological clarity and openness. This paper lays out suggestions to use artificial intelligence responsibly in cybersecurity and concentrates on raising knowledge about its ethical features in Ethical hacking.</p>
<sec id="s2_1">
<label>2.1</label>
<title>Search Strategy and Selection Criteria</title>
<p>A comprehensive search was conducted across four academic databases, IEEE Xplore, SpringerLink, ScienceDirect, and Google Scholar, along with eight additional records identified through manual searches of conference proceedings (e.g., Black Hat, DEF CON). The search spanned publications from January 2015 to September 2024, capturing the evolution of AI in cybersecurity post the rise of deep learning. Keywords included combinations of &#x201C;AI&#x201D;, &#x201C;ethical hacking&#x201D;, &#x201C;cybersecurity ethics&#x201D;, &#x201C;AI bias&#x201D;, &#x201C;accountability&#x201D;, and &#x201C;dual-use dilemma&#x201D;. The summary of the studies eventually utilized in this study is shown in <xref ref-type="table" rid="table-1">Table 1</xref> below.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Summary of the studies included in the systematic review</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Year of publication</th>
<th>Number of publications</th>
</tr>
</thead>
<tbody>
<tr>
<td>2020</td>
<td>1</td>
</tr>
<tr>
<td>2023</td>
<td>3</td>
</tr>
<tr>
<td>2024</td>
<td>8</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s2_1_1">
<label>2.1.1</label>
<title>Inclusion Criteria</title>
<p><list list-type="bullet">
<list-item>
<p>Peer-reviewed studies addressing ethical implications (e.g., bias, privacy, accountability, dual-use) of AI in ethical hacking.</p></list-item>
<list-item>
<p>Empirical research, case studies, conceptual frameworks, or literature reviews.</p></list-item>
<list-item>
<p>Studies published in English.</p></list-item>
</list></p>
</sec>
<sec id="s2_1_2">
<label>2.1.2</label>
<title>Exclusion Criteria</title>
<p><list list-type="bullet">
<list-item>
<p>Purely technical papers (e.g., AI algorithm development without ethical analysis).</p></list-item>
<list-item>
<p>Studies outside cybersecurity (e.g., AI ethics in healthcare or finance).</p></list-item>
<list-item>
<p>Non-peer-reviewed articles (e.g., blogs, white papers).</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Data Extraction and Coding</title>
<p>From each included paper, we extracted (a) study context (domain, application), (b) identified ethical issues, (c) proposed mitigations, and (d) any cited governance frameworks. Extraction was performed independently by both reviewers using a standardized data-charting form.</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Thematic Analysis</title>
<p>We applied the six-phase thematic analysis method of Braun and Clarke (2006) to the extracted ethical issues:
<list list-type="order">
<list-item>
<p><bold>Familiarization.</bold> Reviewers immersed themselves in the full texts, noting initial observations about emerging ethical concerns.</p></list-item>
<list-item>
<p><bold>Generating Initial Codes.</bold> Line-by-line coding captured discrete ethical issues (e.g., &#x201C;unclear responsibility for AI misclassification&#x201D;, &#x201C;dataset skew in attack model training&#x201D;).</p></list-item>
<list-item>
<p><bold>Searching for Themes.</bold> Codes were collated into candidate themes through iterative grouping, each theme representing a broader ethical challenge.</p></list-item>
<list-item>
<p><bold>Reviewing Themes.</bold> Themes were refined by cross-checking against the dataset and ensuring internal coherence; unresolved discrepancies were adjudicated by a third expert.</p></list-item>
<list-item>
<p><bold>Defining and Naming Themes.</bold> We finalized four principal themes: (i) accountability gaps, (ii) algorithmic bias, (iii) privacy risks, and (iv) the dual-use dilemma, each with a clear operational definition.</p></list-item>
<list-item>
<p><bold>Reporting.</bold> We mapped each theme back to the literature, selecting illustrative case examples and noting any proposed mitigations.</p></list-item>
</list></p>
</sec>
<sec id="s2_4">
<label>2.4</label>
<title>Screening Process</title>
<p><list list-type="bullet">
<list-item>
<p>The PRISMA flow diagram (<xref ref-type="fig" rid="fig-1">Fig. 1</xref>) summarizes the screening stages:</p>
</list-item>
<list-item>
<p>Identification: 2891 records from databases &#x002B; 7 from manual searches &#x003D; 2898 total.</p></list-item>
<list-item>
<p>Duplicates Removed: 824 excluded, leaving 2074.</p></list-item>
<list-item>
<p>Title/Abstract Screening: 1947 excluded (irrelevant scope), leaving 127 for full-text review.</p></list-item>
</list></p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>SLR flow chart</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="JCS_66312-fig-1.tif"/>
</fig>
<p>Eligibility Assessment: 115 excluded (11 lacked ethical focus, 61 were technical, 43 covered unrelated fields), resulting in 12 studies for synthesis, and this is further shown in <xref ref-type="table" rid="table-2">Table 2</xref> below.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Number of articles excluded</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Reason for exclusion</th>
<th>Number of articles</th>
</tr>
</thead>
<tbody>
<tr>
<td>Lacked ethical focus</td>
<td>11</td>
</tr>
<tr>
<td>Technical</td>
<td>61</td>
</tr>
<tr>
<td>Unrelated fields</td>
<td>43</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s2_5">
<label>2.5</label>
<title>Scope and Limitations</title>
<p>Our review deliberately focused on peer-reviewed, English-language studies published in reputable journals and conferences between 2015 and March 2024 that explicitly address the ethical dimensions of AI in offensive security. While this ensured a high standard of methodological rigor and thematic relevance, only twelve articles ultimately met these strict inclusion criteria. Consequently, our findings may not fully capture nascent tools, non-English scholarship, or practitioner reports emerging outside this window. Sectoral and geographic imbalances in the selected studies, such as a predominance of corporate-network contexts, could also influence the most salient ethical challenges. We therefore urge readers to interpret our themes as grounded in a well-defined but limited corpus, and to support future work that expands beyond these boundaries to validate and enrich the ethical framework we have presented.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Findings and Discussions</title>
<p><bold>Structuring of Thematic Findings:</bold> Based on the six-phase thematic analysis described in <xref ref-type="sec" rid="s2_2">Section 2.2</xref>, we distilled four principal ethical challenges: accountability gaps, algorithmic bias, privacy risks, and the dual-use dilemma, as well as an overarching concern about human&#x2013;AI interplay. Each subsequent subsection (<xref ref-type="sec" rid="s3_1">Sections 3.1</xref>&#x2013;<xref ref-type="sec" rid="s3_5">3.5</xref>) directly corresponds to one of these themes (or their associated mitigation strategies) and reflects both code prevalence and thematic significance in our coded dataset. The order also mirrors the logical progression from identifying core gaps to exploring mitigation and oversight:
<list list-type="bullet">
<list-item>
<p><xref ref-type="sec" rid="s3_1">Section 3.1</xref> Autonomy and Human Oversight</p></list-item>
<list-item>
<p><xref ref-type="sec" rid="s3_2">Section 3.2</xref> Bias Mitigation Strategies</p></list-item>
<list-item>
<p><xref ref-type="sec" rid="s3_3">Section 3.3</xref> Privacy Preservation Mechanisms</p></list-item>
<list-item>
<p><xref ref-type="sec" rid="s3_4">Section 3.4</xref> GDPR and AIA: Limitations in Addressing AI-Specific Challenges</p></list-item>
<list-item>
<p><xref ref-type="sec" rid="s3_5">Section 3.5</xref> Balancing Automation with Human Expertise</p></list-item>
</list></p>
<sec id="s3_1">
<label>3.1</label>
<title>Autonomy and Human Oversight</title>
<p>The integration of AI into ethical hacking has revolutionized cybersecurity by enabling unprecedented speed and scalability in threat detection. For instance, AI systems like Pentoma achieve 98% accuracy in automated network mapping, outperforming manual methods in processing vast datasets to identify attack patterns [<xref ref-type="bibr" rid="ref-2">2</xref>,<xref ref-type="bibr" rid="ref-3">3</xref>]. However, this autonomy introduces critical accountability gaps. A stark example occurred at Deutsche Bank in 2023, where an AI penetration testing tool misclassified 12% of legitimate transactions as malicious, triggering a 14-h system lockdown [<xref ref-type="bibr" rid="ref-8">8</xref>]. Post-incident analysis revealed fragmented accountability: developers attributed the error to biased training data, while operators blamed inadequate validation protocols. This incident underscores the ethical dilemma posed by AI&#x2019;s &#x201C;black-box&#x201D; decision-making, as highlighted by [<xref ref-type="bibr" rid="ref-14">14</xref>], who question &#x201C;who bears responsibility when AI fails during ethical hacking?&#x201D;</p>
<p>Moreover, the challenge is exacerbated by tools like Darktrace&#x2019;s Antigena, which autonomously neutralize threats in milliseconds, far exceeding human reaction times [<xref ref-type="bibr" rid="ref-15">15</xref>]. While this speed is advantageous, it creates a governance vacuum. For example, during a 2024 NHS audit, Antigena blocked a suspected ransomware attack but inadvertently disrupted critical patient data workflows, as human operators lacked real-time visibility into its decision logic [<xref ref-type="bibr" rid="ref-16">16</xref>]. Such cases align with [<xref ref-type="bibr" rid="ref-17">17</xref>] warning that AI autonomy without explainability risks opaque decision-making with irreversible consequences. The 2023 Texas power grid attack further illustrates these risks. Adversaries hijacked an AI penetration testing tool designed to map grid vulnerabilities, exploiting its autonomous command execution to trigger a 36-h blackout [<xref ref-type="bibr" rid="ref-18">18</xref>]. Forensic reviews revealed the AI lacked safeguards to flag anomalous command sequences, exposing systemic flaws in oversight frameworks. This incident mirrors findings in the original study&#x2019;s systematic review, where 10 of 12 analyzed papers identified dual-use risks as inadequately regulated (<xref ref-type="table" rid="table-3">Table 3</xref>).</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>The results of the review</title>
</caption>
<table>
<colgroup>
<col/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>S/No.</th>
<th align="center">Study author and year</th>
<th align="center">Type of study</th>
<th align="center">Research focus</th>
<th align="center">Ethical challenges</th>
<th align="center">Recommendations</th>
</tr>
</thead>
<tbody>
<tr>
<td>1</td>
<td>Al-Sinani and Mitchell (2024) [<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
<td>Experimental and conceptual study</td>
<td>Use of generative AI (e.g., ChatGPT) in ethical hacking</td>
<td>Misuse by adversaries, bias in AI algorithms, and over-dependence on AI</td>
<td>Balanced AI-human collaboration, ethical frameworks for AI in ethical hacking</td>
</tr>
<tr>
<td>2</td>
<td>He et al. (2023) [<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
<td>Simulation study</td>
<td>AI-based ethical hacking for Health Information Systems (HIS)</td>
<td>AI misuse for malicious purposes</td>
<td>Research into AI-based optimization algorithms for ethical hacking</td>
</tr>
<tr>
<td>3</td>
<td>Kaushik et al. (2024) [<xref ref-type="bibr" rid="ref-20">20</xref>]</td>
<td>Conceptual study</td>
<td>Ethical implications of AI in cybersecurity</td>
<td>Privacy concerns from data collection</td>
<td>Prioritize privacy protection and accountability when integrating AI</td>
</tr>
<tr>
<td>4</td>
<td>Gupta et al. (2023) [<xref ref-type="bibr" rid="ref-13">13</xref>]</td>
<td>Conceptual and experimental study</td>
<td>Impact of generative AI (e.g., ChatGPT) in cybersecurity</td>
<td>Exploitation by cybercriminals, privacy concerns</td>
<td>Stricter ethical guidelines, enhanced security measures to prevent misuse</td>
</tr>
<tr>
<td>5</td>
<td>Raza (2024) [<xref ref-type="bibr" rid="ref-6">6</xref>]</td>
<td>Systematic literature review</td>
<td>AI contributions to penetration testing</td>
<td>Ethical issues in AI-driven penetration testing</td>
<td>Careful integration of AI, development of risk management plans</td>
</tr>
<tr>
<td>6</td>
<td>Gonz&#x00E1;lez et al. (2024) [<xref ref-type="bibr" rid="ref-21">21</xref>]</td>
<td>Conceptual study</td>
<td>Ethics of AI in cybersecurity</td>
<td>Dual-use of AI, malicious use by adversaries</td>
<td>Infrastructure with ethical standards for responsible AI use in cybersecurity</td>
</tr>
<tr>
<td>7</td>
<td>Agarwal (2023) [<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
<td>Conceptual study</td>
<td>AI&#x2019;s role in ethical hacking for national security</td>
<td>Unbiased practices in integrating AI for cybersecurity</td>
<td>Collaboration between international bodies to regulate AI for ethical hacking</td>
</tr>
<tr>
<td>8</td>
<td>Sambamurthy (2024) [<xref ref-type="bibr" rid="ref-23">23</xref>]</td>
<td>Review and analysis</td>
<td>AI-driven vulnerability scanning and threat detection in ethical hacking</td>
<td>Over-reliance on AI, dual-use of AI</td>
<td>Regular audits, balanced AI-human collaboration, and ethical guidelines</td>
</tr>
<tr>
<td>9</td>
<td>Al-Sinani and Mitchell (2024) [<xref ref-type="bibr" rid="ref-19">19</xref>]</td>
<td>Experimental study and conceptual analysis</td>
<td>AI in Linux-focused ethical hacking</td>
<td>AI misuse, data biases, hallucination risks</td>
<td>Continued innovation, regular human audits, and ethical AI use</td>
</tr>
<tr>
<td>10</td>
<td>Raman et al. (2024) [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td>Comparative analysis</td>
<td>Comparison of AI models (ChatGPT vs. Bard) for ethical hacking</td>
<td>Ethics in AI-generated responses for cybersecurity</td>
<td>Iterative query processes to improve AI accuracy in ethical hacking responses</td>
</tr>
<tr>
<td>11</td>
<td>He et al. (2020) [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td>Experimental study with simulation</td>
<td>AI-driven attack pathways in medical systems (CMDS)</td>
<td>Privacy concerns, AI misuse</td>
<td>Multi-factor authentication and CAPTCHA systems to prevent AI attacks</td>
</tr>
<tr>
<td>12</td>
<td>Omar and Zolkipli (2023) [<xref ref-type="bibr" rid="ref-26">26</xref>]</td>
<td>Fundamental study and review</td>
<td>AI-driven cybersecurity for malware detection, phishing protection</td>
<td>Privacy concerns, adversarial attacks on AI models</td>
<td>Human-AI collaboration, integration of AI with traditional security systems</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Additionally, Current frameworks like the EU AI Act 2024 and GDPR fail to address these operational realities. The AI Act&#x2019;s Article 14 mandates human oversight for &#x201C;high-risk&#x201D; systems but does not define mechanisms for real-time intervention. For instance, tools like Ethiack and Equixly [<xref ref-type="bibr" rid="ref-23">23</xref>] operate at speeds that render retrospective audits ineffective, as shown in the NHS incident. Similarly, GDPR&#x2019;s Article 9 restricts sensitive data access but does not mandate explainability for AI decisions, leaving organizations vulnerable to breaches caused by opaque algorithms [<xref ref-type="bibr" rid="ref-12">12</xref>]. A 2024 ISC2 survey found that 67% of cybersecurity teams lack tools to monitor AI decisions granularly, forcing reactive rather than proactive oversight [<xref ref-type="bibr" rid="ref-10">10</xref>].</p>
<p>Finally, the events surrounding the Texas grid and Deutsche Bank highlight a more general paradox: the autonomy of artificial intelligence improves efficiency while complicating responsibility. Although Pentoma and Antigena show the promise of artificial intelligence, critics criticize them as using &#x201C;security through obscurity&#x201D; [<xref ref-type="bibr" rid="ref-21">21</xref>], and their lack of explainability prevents ethical hackers from fairly auditing decisions. According to [<xref ref-type="bibr" rid="ref-24">24</xref>], AI models as ChatGPT and Bard lack auditable records for vulnerability evaluations, therefore preventing their monitoring of erroneous judgments.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Bias Mitigation Strategies</title>
<p>Although ethical hacking technologies driven by artificial intelligence show great promise, they could also reinforce ingrained attitudes supporting cybersecurity injustice. While underrepresented sectors, including small enterprises, public infrastructure, and locations with low technology investment, the training data is skewed toward high-resource environments such as corporate networks and rich industries [<xref ref-type="bibr" rid="ref-11">11</xref>]. This mismatch shows a clear predisposition in artificial intelligence cybersecurity solutions to underline common attack routes, such as SQL injections in company databases, rather than region-specific concerns like SIM-swapping in mobile-centric economies [<xref ref-type="bibr" rid="ref-13">13</xref>].</p>
<p>Furthermore, the data pipelines supporting artificial intelligence models are ultimately the basic source of this disparity. Designed for automating vulnerability screening, solutions like Ethiack and Equixly show a clear preference for Linux-based systems and cloud architectures, therefore discarding antiquated technology used in areas including education and municipal services [<xref ref-type="bibr" rid="ref-20">20</xref>]. In 2023, an audit of African fintech platforms showed that AI programs that had been trained on Western banking systems got transaction patterns for mobile money ecosystems wrong. This led to a $2.8 million breach in Kenya [<xref ref-type="bibr" rid="ref-12">12</xref>,<xref ref-type="bibr" rid="ref-15">15</xref>]. These kinds of events show a major weakness in ethical hacking in artificial intelligence: the weakness is not just technical, but also systemic, showing differences in how resilient cyberspace is around the world.</p>
<p>Additionally, it is essentially false to assume that artificial intelligence systems act as objective arbiters of security. When asked to replicate phishing attempts, for instance, generative models such as ChatGPT default to templates replicating corporate email protocols, therefore neglecting culturally complex strategies common in non-Western environments [<xref ref-type="bibr" rid="ref-24">24</xref>]. This &#x201C;bias-by-design&#x201D; spans geographic prioritising: AI threat-hunting algorithms indicate vulnerabilities in English-language systems at twice the rate of those employing non-Latin scripts, therefore underprotecting Asia&#x2019;s and the Middle East&#x2019;s vital infrastructure [<xref ref-type="bibr" rid="ref-21">21</xref>]. These results are not aberrations but rather artefacts of training data that mix &#x201C;common&#x201D; with &#x201C;universal&#x201D;, hence favouring dominant systems while marginalising others.</p>
<p>Moreover, Regulatory systems aggravate this problem by giving compliance top priority over fairness. While requiring openness for high-risk systems, the EU AI Act 2024 does not call for assessments of algorithmic bias in cybersecurity technologies. Likewise, GDPR&#x2019;s emphasis on data protection ignores the ethical consequences of artificial intelligence models that undervalue weaknesses in low-resource industries [<xref ref-type="bibr" rid="ref-23">23</xref>]. This regulatory hole allows technologies like Darktrace&#x2019;s Antigena to operate under the cover of neutrality despite data revealing their algorithms disproportionately target urbanised network infrastructures [<xref ref-type="bibr" rid="ref-10">10</xref>].</p>
<p>Finally, in AI ethical hacking tools, bias unintentionally provides attackers with knowledge of systematic flaws. Reverse-engineering models allow adversarial actors to find weaknesses in underprotected industries, therefore exploiting these loopholes. Ref. [<xref ref-type="bibr" rid="ref-13">13</xref>], for instance, showed how AI systems taught to prioritise corporate networks might be controlled to expose attack surfaces in small-business IoT devices, which lack the protective protections of bigger corporations. Deloitte&#x2019;s 2024 analysis shows that 46% of companies worry that biased AI tools may expose underprivileged systems to targeted attacks, therefore transforming bias from an ethical concern into a strategic risk [<xref ref-type="bibr" rid="ref-7">7</xref>].</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Privacy Preservation Mechanisms</title>
<p>Since AI systems for ethical hacking require access to all kinds of sensitive data ranging from personal medical records to secret company files, their use generates significant privacy concerns [<xref ref-type="bibr" rid="ref-25">25</xref>]. Darktrace&#x2019;s Antigena tools&#x2019; real-time threat detection features depend on processing vast data collections, which might unintentionally lead to privacy violations. For instance, after gaining access to 50,000 unencrypted patient records within a 2023 South African healthcare platform penetration test, an artificial intelligence tool broke the GDPR and NDPR laws [<xref ref-type="bibr" rid="ref-8">8</xref>]. The ability of artificial intelligence to improve security works against its inclination to violate personal privacy.</p>
<p>Moreover, Ethical hacking AI systems must have exact computer data to identify security flaws in platforms like Ethiack and Equixly. These systems fail to observe privacy rules, so they often find difficulties running. Although the GDPR Article 9 expressly forbids handling health data, NHS audit findings reveal that tested artificial intelligence technologies usually lack default encryption measures for healthcare data. According to [<xref ref-type="bibr" rid="ref-7">7</xref>], a vulnerability scanner using artificial intelligence revealed compromised financial records during a bank audit in 2024, which set off a $4.2 million phishing campaign. These events make clear the insufficient systems between the data needs of artificial intelligence and the privacy needs.</p>
<p>However, although the present limitations under GDPR and the EU AI Act 2024 mostly protect data and transparency in systems, they overlook the exclusive privacy hazards generated by AI in cybersecurity. Articles 5 and 17 of GDPR on data minimisation and right to erasure have poor application in artificial intelligence settings since data intake for precision is still vital for models. Ref. [<xref ref-type="bibr" rid="ref-12">12</xref>] had unencrypted transaction records stored, according to the audit of Kenyan fintech companies using AI tools, even following an operation that broke KBPR&#x2019;s storage policies. The AI Act distinguishes several types of penetration testing tools into &#x201C;high-risk&#x201D; or &#x201C;non-high-risk&#x201D; categories, therefore allowing companies to avoid doing privacy impact studies [<xref ref-type="bibr" rid="ref-23">23</xref>].</p>
<p>Additionally, reducing hazards has been possible with technical solutions, including homomorphic encryption and differential privacy. Homomorphic encryption allowed artificial intelligence tools to examine encrypted patient data without decryption, therefore lowering exposure risk [<xref ref-type="bibr" rid="ref-27">27</xref>]. Analogous to this, anonymising methods frequently fail in cybersecurity settings: a 2023 study revealed that 78% of &#x201C;anonymised&#x201D; network traffic logs could be re-identified using metadata patterns, therefore negating privacy guarantees [<xref ref-type="bibr" rid="ref-21">21</xref>].</p>
<p>In conclusion, most of the privacy concerns created by technology operations fall on underfunded economic sectors. While developing areas utilise tools with limited encryption capability due to financial constraints, European business network audit tools rely mostly on modern encryption standards as their security mechanism. The 2024 [<xref ref-type="bibr" rid="ref-10">10</xref>] poll indicates that whereas North American teams reported such limits only at 34%, African cybersecurity personnel faced access issues to privacy-protecting AI solutions at a rate of 72%. The disparities shown in this mismatch guarantee that underprivileged systems all around constantly suffer privacy violations as well as cyberattacks.</p>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>GDPR and AIA: Limitations in Addressing AI-Specific Challenges</title>
<p>Together with the EU Artificial Intelligence Act (AIA), the General Data Protection Regulation (GDPR) sets fundamental rules for data security and artificial intelligence ethics. The two models show significant flaws in their applications to ethical hacking driven by artificial intelligence since they do not sufficiently manage the technological accompanying ethical issues of autonomous cybersecurity solutions.</p>
<p>However, GDPR aims to protect personal privacy, which shows up in Article 5 data minimising rules and Article 17 right to erasure policies, but does not control the AI-based systematic dangers in ethical hacking operations. During a 2023 penetration test on a German hospital, investigators insecure patient records, therefore violating GDPR Article 9 regulations of health data processing [<xref ref-type="bibr" rid="ref-8">8</xref>]. Data breach investigations revealed that GDPR&#x2019;s focus on post-leak fines does not create protection mechanisms before their occurrence for real-time artificial intelligence systems. Under GDPR, the right to explanation under Article 22 only affects automated judgements made for individual instances, not the organisational security risks produced by AI faults affecting decision-making systems, such as biased vulnerability prioritising [<xref ref-type="bibr" rid="ref-12">12</xref>].</p>
<p>Furthermore, Article 6 of the AIA labels AI technologies applied in critical infrastructure as &#x201C;high-risk&#x201D;, hence requiring openness and human control. Its standards, meanwhile, lack clarity for uses in cybersecurity. Because they are sold as improvements to human-led processes rather than stand-alone systems, tools like Ethiack and Equixly, which independently run penetration tests, often avoid &#x201C;high-risk&#x201D; designation [<xref ref-type="bibr" rid="ref-23">23</xref>]. As shown in a 2024 event whereby an AI tool corrupted firewall rules during a banking sector audit, exposing transactional data, this gap lets vendors avoid thorough audits [<xref ref-type="bibr" rid="ref-7">7</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>].</p>
<p>However, while both systems stress openness, they ignore the technical facts of artificial intelligence decision-making. Though it does not demand explainability approaches (e.g., LIME, SHAP) to demystify AI logic, the AIA mandates that high-risk systems offer &#x201C;sufficiently detailed&#x201D; documentation (Article 13). For example, Darktrace&#x2019;s Antigena, which independently stops threats, provides no interpretable logs for its activities, therefore depriving auditors of the means to confirm judgements during post-incident assessments [<xref ref-type="bibr" rid="ref-10">10</xref>]. Comparably, GDPR&#x2019;s transparency criteria centre on data subjects rather than cybersecurity experts, therefore separating operational responsibility from compliance.</p>
<p>Moreover, Cross-border settings clearly show the limits of these systems. An artificial intelligence technology based on EU data unintentionally breached Kenya&#x2019;s Data Protection Act by processing consumer information without regional consent safeguards during a 2024 audit of a multinational e-commerce platform [<xref ref-type="bibr" rid="ref-12">12</xref>]. While Article 3 of GDPR imposes rigorous territorial restrictions, it does not mandate that businesses create worldwide AI tool compliance policies. Outside of its borders, the AIA lacks enforcement powers; so, non-EU suppliers can utilise covert artificial intelligence systems left unmonitored in any member state.</p>
<p>These models fail to adequately address the dual-use problem present in ethical hacking instruments using artificial intelligence algorithms. Since they were first developed to fight phishing attempts, unlike GDPR&#x2019;s emphasis on data protection and the AIA&#x2019;s safety protocols, ChatGPT, along with other generative models, poses a threat of undetectable malware generation since they pose a threat of conducting undetectable malware production. While Article 52 of the AIA requires risk assessment of high-risk systems, it does not provide required measures against systematic exploitation, therefore exposing organisations to AI attack threats.</p>
</sec>
<sec id="s3_5">
<label>3.5</label>
<title>Balancing Automation with Human Expertise</title>
<p>By expediting vulnerability discovery and threat response, the incorporation of artificial intelligence into ethical hacking has transformed cybersecurity; nonetheless, its effectiveness depends fundamentally on the complementary function of human knowledge. By automating processes like network mapping and log analysis, AI systems like Pentoma and Equixly show amazing efficiency in lowering detection times by 60% over hand techniques [<xref ref-type="bibr" rid="ref-3">3</xref>]. But often the cost of this efficiency is contextual knowledge.</p>
<p>Additionally, Human knowledge is essential in closing these gaps, especially in ethically and culturally complex settings. Think about the difficulty of protecting mobile money platforms in sub-Saharan Africa, where artificial intelligence tools trained on Western corporate networks missed 34% of SIM-swapping vulnerabilities. By contrast, human-led audits included local transactional behaviours and infrastructural quirks, therefore highlighting dangers that algorithms missed [<xref ref-type="bibr" rid="ref-12">12</xref>]. Likewise, Darktrace&#x2019;s Antigena lacks the sense to assess collateral damage, even if it is successful in autonomously neutralising hazards. Its forceful isolation of a misflagged server upset the telemedicine operations of a hospital in 2023, therefore postponing important patient care until human operators interfered [<xref ref-type="bibr" rid="ref-8">8</xref>]. These illustrations show how human judgment must temper artificial intelligence&#x2019;s operational speed to negotiate ethical and practical trade-offs.</p>
<p>Still, the move toward automation poses the risk of worsening underlying inequalities. A 2024 ISC2 survey shows that, compared to 29% in North America [<xref ref-type="bibr" rid="ref-10">10</xref>], 72% of cybersecurity teams in underdeveloped countries lack access to AI capability. Training data biases, such as giving corporate networks priority over public infrastructure, skew their influence even with the current resources at hand. Artificial intelligence municipal audits, for example, frequently undervaluate vulnerabilities in water treatment plants, which account for 58% of all critical infrastructure breaches in low-income areas [<xref ref-type="bibr" rid="ref-21">21</xref>].</p>
<p>These variations reveal a paradox: even if artificial intelligence democratises access to better risk detection in theory, it reinforces previously existing inequality in reality [<xref ref-type="bibr" rid="ref-19">19</xref>]. Modern judicial systems aggravate these problems by ignoring the necessary human observation. For instance, the EU AI Act 2024 requires &#x201C;human oversight&#x201D; for high-risk systems but does not specify procedures for real-time collaboration.</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Recommendations</title>
<p>The integration of artificial intelligence (AI) into cybersecurity, particularly in ethical hacking, demands urgent regulatory reforms to address gaps in frameworks like the GDPR and EU AI Act. Current systems struggle to balance innovation with accountability, especially as AI tools increasingly grapple with dual-use risks, privacy breaches, and algorithmic bias. Promoting ethical AI integration and reducing systemic risks depend on evidence-based improvements grounded in technical viability and worldwide interoperability.</p>
<p>The solution requires an approach to handle the black-box nature of AI systems because it hinders accountability when using Darktrace&#x2019;s Antigena platforms. Post-incident review auditing becomes impossible because these systems do not provide auditable decision trails according to [<xref ref-type="bibr" rid="ref-28">28</xref>]. The deployment of explainable frameworks such as LIME (Local Interpretable Model-agnostic Explanations) and SHAP (SHapley Additive exPlanations) through government mandate enables the breakdown of AI decisions. Researchers found that the LIME framework incorporation minimized incorrect interpretations of AI alerts when used in healthcare penetration testing [<xref ref-type="bibr" rid="ref-29">29</xref>]. Meaningful explainability-by-design frameworks as prescribed by LIME and SHAP operatively meet GDPR&#x2019;s &#x201C;right to explanation&#x201D; standards while enabling auditors to inspect AI systems while maintaining operational speed.</p>
<p>The EU AI Act&#x2019;s &#x201C;high-risk&#x201D; definition must be clarified because Ethiopian tools circumvent regulation through marketing of their systems as human process improvement modules [<xref ref-type="bibr" rid="ref-23">23</xref>]. AI systems used for threat response and penetration tests alongside vulnerability detection must be grouped as a high-risk category, no matter how they are marketed [<xref ref-type="bibr" rid="ref-5">5</xref>]. Asset owners would need to perform adversarial testing during certification, according to the upcoming measure illustrated by the Texas power grid attack of 2024, where an uncertified AI tool weaponization caused a 36-h blackout. Developers can use the CALDERA framework by MITRE to simulate attacks through the framework during their AI tools&#x2019; development stage [<xref ref-type="bibr" rid="ref-26">26</xref>].</p>
<p>The second foundation of restructuring involves implementing robust privacy-by-design procedures. GDPR&#x2019;s reactive approach to fining breaches was unable to stop the 2023 breach of German hospital patient records through an AI-controlled penetration test, according to [<xref ref-type="bibr" rid="ref-8">8</xref>]. As a parallel solution, we need to combat algorithmic bias so that it stops causing health system inequalities among rural communities [<xref ref-type="bibr" rid="ref-14">14</xref>].</p>
<p>The solution to international complex situations depends on regulatory harmonization. Research by [<xref ref-type="bibr" rid="ref-12">12</xref>] shows that the global e-commerce AI tool violated the Data Protection Act of Kenya, thus demonstrating the necessity for standardized regulations. The implementation of adaptive compliance modules that follow the ISO/IEC 27050 framework enables automatic adaptation of data processing approaches among different jurisdictions. Climate change is a global threat that requires collective national and international solutions. The Wassenaar Arrangement&#x2019;s controls on cyber technologies and collaborative enforcement bodies such as the Global Cybersecurity Alliance would help harmonize regional requirements with standard ethical practices [<xref ref-type="bibr" rid="ref-30">30</xref>].</p>
</sec>
<sec id="s5">
<label>5</label>
<title>The Way Forward</title>
<p>The collaboration between ethical hacking and artificial intelligence represents a big step forward in cybersecurity as it gives professionals the power to discover system flaws and vulnerabilities, along with suggesting possible attacks and reducing exposure points, and ensuring stronger protection elements. The study demonstrates how autonomous systems created by artificial intelligence systems that increase operational efficiency have the potential to cause system failures at all organizational levels. Systems that favor well-funded educational initiatives over underfunded ones contribute to the systemic promotion of inequality. The dual-use challenge that results from this identification process expanding attack surfaces can make defensive technology a potential weapon.</p>
<p>Moreover, the ethical application of AI in cybersecurity requires a careful strategy to use automation to improve human insight while maintaining crucial ethical judgment, cultural awareness, and context sensitivity. The case studies that are being discussed, which start with the 2023 Deutsche Bank Crisis and end with the 2024 Texas power infrastructure attack, show the serious repercussions that arise when a proper balance is not maintained. In this particular case, artificial intelligence functions beyond accepted ethical bounds, designed to optimize its efficiency. Analysis of the impending repercussions is presented in the paper. The EU AI Act of 2024 offers a higher level of analysis of unique AI-related issues beyond its limited potential.</p>
<p>To operationalize bias-aware data curation in practice, organizations should integrate open-source fairness toolkits directly into their AI pipelines at the data-ingestion stage. For example, IBM AI Fairness 360 offers over seventy metrics for dataset and model bias detection alongside eleven bias-mitigation algorithms (e.g., reweighting, disparate impact remover), enabling teams to identify and correct skew before training. Complementing this, Google&#x2019;s What-If Tool provides an interactive, no-code interface for slicing datasets, probing &#x201C;what-if&#x201D; counterfactual scenarios, and visualizing fairness metrics across subpopulations. For production workflows, Microsoft Fairlearn delivers dashboards and constraint-based learning algorithms that optimize models for parity across defined groups, while Aequitas (University of Chicago) supplies group-based audit reports and threshold-independent disparity metrics to surface underrepresented segments. By embedding these toolkits into automated data pipelines running batch audits on incoming records, generating fairness reports, and triggering alerts when imbalance thresholds are exceeded, organizations can ensure their ethical-hacking AI models are trained on representative, equitable datasets, thereby reducing the risk of perpetuating systemic vulnerabilities.</p>
<p>Finally, the direction of ethical hacking depends on defining its current meaning rather than halting the integration of AI technology [<xref ref-type="bibr" rid="ref-31">31</xref>]. Those involved in technology-based adaptive governance need to increase communication between developers, policymakers, and practitioners to collaborate; resources should be allocated at equal levels throughout the entire artificial intelligence development process; ethical considerations and cross-field team collaboration must be given priority; and people must be more committed to transforming AI into a safety network that is accessible to all, given the ongoing complexity of cyber threats. Instead of looking for ways to stop the integration of artificial intelligence, ethical hacking stays true to its original purpose definition, which dictates its direction [<xref ref-type="bibr" rid="ref-32">32</xref>]. More cooperation between developers, policymakers, and practitioners is required by those in charge of making governance decisions based on technological advancements. To ensure fair progress, shared resources from several participating teams and ethical knowledge are required at every stage of artificial intelligence development. Because cyber threats are becoming more complex, our increased commitment should support the advancement of artificial intelligence as a global safety measure.</p>
</sec>
<sec id="s6">
<label>6</label>
<title>Conclusion and Future Directions</title>
<p>In this review, we first established four principal ethical challenges: algorithmic bias, privacy-preserving tensions, accountability gaps, and the dual-use dilemma, and demonstrated how AI&#x2019;s efficiency gains can nonetheless amplify inequities in under-resourced settings such as rural clinics and small enterprises. Although the GDPR and the EU AI Act lay a foundation for data protection and transparency, they lack the agility to keep up with rapidly evolving autonomous cybersecurity tools.</p>
<p>To address these shortcomings, we advocate a twofold strategy. First, organizations must adopt adaptive governance frameworks that embed continuous monitoring, algorithmic impact assessments, and human-in-the-loop checkpoints whenever models are retrained, transforming policy from a one-off compliance exercise into a living process. Second, security teams should integrate bias-aware data curation at the earliest stages of their AI pipelines. By employing open-source toolkits, IBM AI Fairness 360 for fairness metrics and mitigation algorithms, Google&#x2019;s What-If Tool for interactive scenario testing, Microsoft Fairlearn for performance parity dashboards, and Aequitas for group-based audit reports, practitioners can systematically detect and correct dataset imbalances before deployment. This combination of adaptive governance and rigorous data curation will help ensure that AI-driven ethical hacking tools serve all contexts equitably, rather than perpetuating existing resource divides.</p>
<p>At the same time, credentialed identities and immutable audit logs must be mandatory for autonomous AI agents, measures underscored by cybersecurity experts at the RSA Conference 2025 to prevent unauthorized actions and enable robust forensics. Implementing tiered monitoring systems will then classify tools by risk level, requiring high-risk deployments to undergo explainability audits and maintain human oversight.</p>
<p>Globally, harmonized standards are essential to prevent regulatory arbitrage. The Bletchley Declaration (November 2023) offers a blueprint for shared commitments to responsible AI, while emerging proposals for a global regime complex align AI governance with international law, ensuring hostile AI uses are universally prohibited.</p>
<p>Finally, future research should probe the socio-technical interplay between AI autonomy and human judgment in diverse cultural and infrastructural settings. Key questions include how to tailor adaptive governance to local legal frameworks, how tamper-resistant architectures can mitigate dual-use risks, and how breakthroughs in quantum computing or generative AI will reshape ethical hacking practices. By grounding these inquiries in the themes identified here, scholars can develop empirically supported models that guide policymakers, technologists, and practitioners toward a cybersecurity future that is equitable, accountable, and transparent.</p>
</sec>
<sec sec-type="supplementary-material" id="s7">
<title>Supplementary Materials</title>
<supplementary-material id="SD1">
<media xlink:href="JCS_66312-s001.docx"/>
</supplementary-material>
<supplementary-material id="SD2">
<media xlink:href="JCS_66312-s002.pdf"/>
</supplementary-material>
</sec>
</body>
<back>
<ack>
<p>Not applicable.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>The authors received no specific funding for this study.</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>The authors confirm contribution to the paper as follows: Conceptualization, Hossana Maghiri Sufficient; methodology, Hossana Maghiri Sufficient; validation, Hossana Maghiri Sufficient, Abdulazeez Murtala Mohammed and Bashir Danjuma; formal analysis, Hossana Maghiri Sufficient; investigation, Bashir Danjuma; resources, Hossana Maghiri Sufficient; data curation, Abdulazeez Murtala Mohammed; writing&#x2014;original draft preparation, Hossana Maghiri Sufficient and Abdulazeez Murtala Mohammed; writing&#x2014;review and editing, Hossana Maghiri Sufficient, Abdulazeez Murtala Mohammed and Bashir Danjuma; project administration, Abdulazeez Murtala Mohammed. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The authors confirm that the data supporting the findings of this study are available within the article.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<sec>
<title>Supplementary Materials</title>
<p>The supplementary material is available online at <ext-link ext-link-type="uri" xlink:href="https://www.techscience.com/doi/10.32604/jcs.2025.066312/s1">https://www.techscience.com/doi/10.32604/jcs.2025.066312/s1</ext-link>.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Saha</surname> <given-names>S</given-names></string-name>, <string-name><surname>Das</surname> <given-names>A</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Biswas</surname> <given-names>D</given-names></string-name>, <string-name><surname>Saha</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Ethical hacking: redefining security in information system</article-title>. In: <conf-name>Proceedings of the International Ethical Hacking Conference 2019</conf-name>; <year>2019 Aug 22&#x2013;25</year>; <publisher-loc>Kolkata, India</publisher-loc>. doi:<pub-id pub-id-type="doi">10.1007/978-981-15-0361-0_16</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sarker</surname> <given-names>IH</given-names></string-name></person-group>. <article-title>Machine learning for intelligent data analysis and automation in cybersecurity: current and future prospects</article-title>. <source>Ann Data Sci</source>. <year>2023</year>;<volume>10</volume>(<issue>6</issue>):<fpage>1473</fpage>&#x2013;<lpage>98</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s40745-022-00444-2</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Hu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Beuran</surname> <given-names>R</given-names></string-name>, <string-name><surname>Tan</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Automated penetration testing using deep reinforcement learning</article-title>. In: <conf-name>Proceedings of the 2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&#x0026;PW)</conf-name>; <year>2020 Sep 7&#x2013;11</year>; <publisher-loc>Genoa, Italy</publisher-loc>. doi:<pub-id pub-id-type="doi">10.1109/eurospw51379.2020.00010</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jada</surname> <given-names>I</given-names></string-name>, <string-name><surname>Mayayise</surname> <given-names>TO</given-names></string-name></person-group>. <article-title>The impact of artificial intelligence on organisational cyber security: an outcome of a systematic literature review</article-title>. <source>Data Inf Manag</source>. <year>2024</year>;<volume>8</volume>(<issue>2</issue>):<fpage>100063</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.dim.2023.100063</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kaur</surname> <given-names>R</given-names></string-name>, <string-name><surname>Gabrijel&#x010D;i&#x010D;</surname> <given-names>D</given-names></string-name>, <string-name><surname>Klobu&#x010D;ar</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Artificial intelligence for cybersecurity: literature review and future research directions</article-title>. <source>Inf Fusion</source>. <year>2023</year>;<volume>97</volume>(<issue>6</issue>):<fpage>101804</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.inffus.2023.101804</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Raza</surname> <given-names>H</given-names></string-name></person-group>. <source>Systematic literature review of challenges and AI contributions in penetration testing [master&#x2019;s thesis]</source>. <publisher-loc>Lule&#x00E5;, Sweden</publisher-loc>: <publisher-name>Lule&#x00E5; University of Technology</publisher-name>; <year>2024</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Deloitte</surname> <given-names>CTI</given-names></string-name></person-group>. <article-title>Threat assessment: how threat actors are leveraging artificial intelligence (AI) technology to conduct sophisticated attacks [Internet]. [cited 2024 Nov 22]</article-title>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.contentree.com/reports/threat-report-how-threat-actors-are-leveraging-artificial-intelligence-ai-technology-to-conduct-sophisticated-attacks_417160">https://www.contentree.com/reports/threat-report-how-threat-actors-are-leveraging-artificial-intelligence-ai-technology-to-conduct-sophisticated-attacks_417160</ext-link>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>He</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zamani</surname> <given-names>E</given-names></string-name>, <string-name><surname>Yevseyeva</surname> <given-names>I</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Artificial intelligence-based ethical hacking for health information systems: simulation study</article-title>. <source>J Med Internet Res</source>. <year>2023</year>;<volume>25</volume>(<issue>1</issue>):<fpage>e41748</fpage>. doi:<pub-id pub-id-type="doi">10.2196/41748</pub-id>; <pub-id pub-id-type="pmid">37097723</pub-id></mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Ueno</surname> <given-names>H</given-names></string-name></person-group>. <chapter-title>Artificial intelligence as dual-use technology</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Hatzilygeroudis</surname> <given-names>IK</given-names></string-name>, <string-name><surname>Tsihrintzis</surname> <given-names>GA</given-names></string-name>, <string-name><surname>Jain</surname> <given-names>LC</given-names></string-name></person-group>, editors. <source>Fusion of machine learning paradigms: theory and applications</source>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2023</year>. p. <fpage>7</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.1007/978-3-031-22371-6_2</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>ISC2</collab></person-group>. <article-title>The ethical dilemmas of AI in cybersecurity [Internet]. [cited 2024 Nov 18]</article-title>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.isc2.org/Insights/2024/01/The-Ethical-Dilemmas-of-AI-in-Cybersecurity">https://www.isc2.org/Insights/2024/01/The-Ethical-Dilemmas-of-AI-in-Cybersecurity</ext-link>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Schellekens</surname> <given-names>P</given-names></string-name>, <string-name><surname>Skilling</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Three reasons why AI may widen global inequality [Internet]. [cited 2024 Aug 15]</article-title>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.cgdev.org/blog/three-reasons-why-ai-may-widen-global-inequality#:&#x007E;:text=Will%20global%20inequality%20rise%20or,regions%20risk%20being%20left%20behind">https://www.cgdev.org/blog/three-reasons-why-ai-may-widen-global-inequality#:&#x007E;:text=Will%20global%20inequality%20rise%20or,regions%20risk%20being%20left%20behind</ext-link>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Wanyama</surname> <given-names>E</given-names></string-name></person-group>. <article-title>The impact of artificial intelligence on data protection and privacy in Africa: a walk-through rights of a data subject in Africa [Internet]</article-title>. <comment>[cited 2024 Nov 18]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://cipesa.org/wp-content/files/briefs/The_Impact_of_Artificial_Intelligence_on_Data_Protection_and_Privacy_-_Brief.pdf">https://cipesa.org/wp-content/files/briefs/The_Impact_of_Artificial_Intelligence_on_Data_Protection_and_Privacy_-_Brief.pdf</ext-link>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gupta</surname> <given-names>M</given-names></string-name>, <string-name><surname>Akiri</surname> <given-names>C</given-names></string-name>, <string-name><surname>Aryal</surname> <given-names>K</given-names></string-name>, <string-name><surname>Parker</surname> <given-names>E</given-names></string-name>, <string-name><surname>Praharaj</surname> <given-names>L</given-names></string-name></person-group>. <article-title>From ChatGPT to ThreatGPT: impact of generative AI in cybersecurity and privacy</article-title>. <source>IEEE Access</source>. <year>2023</year>;<volume>11</volume>:<fpage>80218</fpage>&#x2013;<lpage>45</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2023.3300381</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Joshi</surname> <given-names>R</given-names></string-name></person-group>. <chapter-title>Ethical challenges and privacy concerns in innovations</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Abouhawwash</surname> <given-names>M</given-names></string-name>, <string-name><surname>Rosak-Szyrocka</surname> <given-names>J</given-names></string-name>, <string-name><surname>Gupta</surname> <given-names>SK</given-names></string-name></person-group>, editors. <source>Aspects of quality management in value creating in the Industry 5.0 way</source>. <publisher-loc>Boca Raton, FL, USA</publisher-loc>: <publisher-name>CRC Press</publisher-name>; <year>2024</year>. p. <fpage>202</fpage>&#x2013;<lpage>23</lpage>. doi:<pub-id pub-id-type="doi">10.1201/9781032677040-12</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Riza</surname> <given-names>AZBM</given-names></string-name>, <string-name><surname>Jennsen</surname> <given-names>L</given-names></string-name>, <string-name><surname>Anggani</surname> <given-names>P</given-names></string-name>, <string-name><surname>Rafeen</surname> <given-names>AI</given-names></string-name>, <string-name><surname>Ruth</surname> <given-names>PNJ</given-names></string-name>, <string-name><surname>Sookun</surname> <given-names>D</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>Leveraging machine learning and AI to combat modern cyber threats</article-title>. <year>2025</year>. doi:<pub-id pub-id-type="doi">10.20944/preprints202501.0360.v1</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Lamche</surname> <given-names>A</given-names></string-name></person-group>. <article-title>NHS software provider fined &#x00A3;3m over data breach [Internet]</article-title>. <comment>[cited 2025 Feb 5]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.bbc.com/news/articles/cp3yv1zxn94o">https://www.bbc.com/news/articles/cp3yv1zxn94o</ext-link>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bengio</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Hinton</surname> <given-names>G</given-names></string-name>, <string-name><surname>Yao</surname> <given-names>A</given-names></string-name>, <string-name><surname>Song</surname> <given-names>D</given-names></string-name>, <string-name><surname>Abbeel</surname> <given-names>P</given-names></string-name>, <string-name><surname>Darrell</surname> <given-names>T</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Managing extreme AI risks amid rapid progress</article-title>. <source>Science</source>. <year>2024</year>;<volume>384</volume>(<issue>6698</issue>):<fpage>842</fpage>&#x2013;<lpage>5</lpage>. doi:<pub-id pub-id-type="doi">10.1126/science.adn0117</pub-id>; <pub-id pub-id-type="pmid">38768279</pub-id></mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Jones</surname> <given-names>D</given-names></string-name></person-group>. <article-title>CISA, FBI confirm critical infrastructure intrusions by China-linked hackers [Internet]. [cited 2025 Feb 5]</article-title>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.utilitydive.com/news/cisa-fbi-critical-infrastructure-china-hacker/706979/">https://www.utilitydive.com/news/cisa-fbi-critical-infrastructure-china-hacker/706979/</ext-link>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Al-Sinani</surname> <given-names>HS</given-names></string-name>, <string-name><surname>Mitchell</surname> <given-names>CJ</given-names></string-name></person-group>. <article-title>AI-enhanced ethical hacking: a Linux-focused experiment</article-title>. <comment>arXiv:2410.05105v1. 2024</comment>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Kaushik</surname> <given-names>K</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>A</given-names></string-name>, <string-name><surname>Kumari</surname> <given-names>A</given-names></string-name>, <string-name><surname>Sharma</surname> <given-names>I</given-names></string-name>, <string-name><surname>Dubey</surname> <given-names>R</given-names></string-name></person-group>. <chapter-title>Ethical considerations in AI-based cybersecurity</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Kaushik</surname> <given-names>K</given-names></string-name>, <string-name><surname>Sharma</surname> <given-names>I</given-names></string-name></person-group>, editors. <source>Next-generation cybersecurity: AI, ML, and blockchain</source>. <publisher-loc>Singapore</publisher-loc>: <publisher-name>Springer Nature Singapore</publisher-name>; <year>2024</year>. p. <fpage>437</fpage>&#x2013;<lpage>70</lpage>. doi:<pub-id pub-id-type="doi">10.1007/978-981-97-1249-6_19</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>L&#x00F3;pez Gonz&#x00E1;lez</surname> <given-names>A</given-names></string-name>, <string-name><surname>Moreno</surname> <given-names>M</given-names></string-name>, <string-name><surname>Moreno Rom&#x00E1;n</surname> <given-names>AC</given-names></string-name>, <string-name><surname>Hadfeg Fern&#x00E1;ndez</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Cepero P&#x00E9;rez</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Ethics in artificial intelligence: an approach to cybersecurity</article-title>. <source>Inteligencia Artific</source>. <year>2024</year>;<volume>27</volume>(<issue>73</issue>):<fpage>38</fpage>&#x2013;<lpage>54</lpage>. doi:<pub-id pub-id-type="doi">10.4114/intartif.vol27iss73pp38-54</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Agarwal</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Unleashing the power: exploring ethical hacking and artificial intelligence for stronger national security</article-title>. <source>Int J Curr Sci</source>. <year>2023</year>;<volume>13</volume>(<issue>3</issue>):<fpage>556</fpage>&#x2013;<lpage>66</lpage>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sambamurthy</surname> <given-names>PK</given-names></string-name></person-group>. <article-title>The integration of artificial intelligence in ethical hacking: revolutionizing cybersecurity predictive analytics</article-title>. <source>Int J Adv Res Emerg Trends</source>. <year>2024</year>;<volume>1</volume>(<issue>2</issue>):<fpage>199</fpage>&#x2013;<lpage>211</lpage>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Raman</surname> <given-names>R</given-names></string-name>, <string-name><surname>Calyam</surname> <given-names>P</given-names></string-name>, <string-name><surname>Achuthan</surname> <given-names>K</given-names></string-name></person-group>. <article-title>ChatGPT or bard: who is a better certified ethical hacker?</article-title> <source>Comput Secur</source>. <year>2024</year>;<volume>140</volume>(<issue>6</issue>):<fpage>103804</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2024.103804</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>He</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>C</given-names></string-name>, <string-name><surname>Suxo Camacho</surname> <given-names>R</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>H</given-names></string-name></person-group>. <article-title>AI-based security attack pathway for medical diagnosis systems (CMDS)</article-title>. In: <conf-name>Proceedings of the 2020 Computing in Cardiology</conf-name>; <year>2020 Sep 13&#x2013;16</year>; <publisher-loc>Rimini, Italy</publisher-loc>. doi:<pub-id pub-id-type="doi">10.22489/cinc.2020.439</pub-id>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Omar</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Zolkipli</surname> <given-names>MF</given-names></string-name></person-group>. <article-title>Fundamental study of hacking attacks protection using artificial intelligence (AI)</article-title>. <source>Int J Adv Eng Manag</source>. <year>2023</year>;<volume>5</volume>(<issue>2</issue>):<fpage>813</fpage>&#x2013;<lpage>21</lpage>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Williamson</surname> <given-names>SM</given-names></string-name>, <string-name><surname>Prybutok</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Balancing privacy and progress: a review of privacy challenges, systemic oversight, and patient perceptions in AI-driven healthcare</article-title>. <source>Appl Sci</source>. <year>2024</year>;<volume>14</volume>(<issue>2</issue>):<fpage>675</fpage>. doi:<pub-id pub-id-type="doi">10.3390/app14020675</pub-id>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Casper</surname> <given-names>S</given-names></string-name>, <string-name><surname>Ezell</surname> <given-names>C</given-names></string-name>, <string-name><surname>Siegmann</surname> <given-names>C</given-names></string-name>, <string-name><surname>Kolt</surname> <given-names>N</given-names></string-name>, <string-name><surname>Curtis</surname> <given-names>TL</given-names></string-name>, <string-name><surname>Bucknall</surname> <given-names>B</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>Black-box access is insufficient for rigorous AI audits</article-title>. In: <conf-name>Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency</conf-name>; <year>2024 Jun 3&#x2013;6</year>; <publisher-loc>Rio de Janeiro, Brazil</publisher-loc>. doi:<pub-id pub-id-type="doi">10.1145/3630106.3659037</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hassan</surname> <given-names>SU</given-names></string-name>, <string-name><surname>Abdulkadir</surname> <given-names>SJ</given-names></string-name>, <string-name><surname>Zahid</surname> <given-names>MSM</given-names></string-name>, <string-name><surname>Al-Selwi</surname> <given-names>SM</given-names></string-name></person-group>. <article-title>Local interpretable model-agnostic explanation approach for medical imaging analysis: a systematic literature review</article-title>. <source>Comput Biol Med</source>. <year>2025</year>;<volume>185</volume>(<issue>1</issue>):<fpage>109569</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.compbiomed.2024.109569</pub-id>; <pub-id pub-id-type="pmid">39705792</pub-id></mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Korzak</surname> <given-names>E</given-names></string-name></person-group>. <chapter-title>Export controls: the Wassenaar experience and its lessons for international regulation of cyber tools</chapter-title>. In: <person-group person-group-type="editor"><string-name><surname>Tikk</surname> <given-names>E</given-names></string-name>, <string-name><surname>Kerttunen</surname> <given-names>M</given-names></string-name></person-group>, editors. <source>Routledge handbook of international cybersecurity</source>. <publisher-loc>Abingdon, UK</publisher-loc>: <publisher-name>Talylor Francis Group</publisher-name>; <year>2020</year>. p. <fpage>297</fpage>&#x2013;<lpage>311</lpage>. doi:<pub-id pub-id-type="doi">10.4324/9781351038904-31</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Saraswathi</surname> <given-names>VR</given-names></string-name>, <string-name><surname>Ahmed</surname> <given-names>IS</given-names></string-name>, <string-name><surname>Reddy</surname> <given-names>SM</given-names></string-name>, <string-name><surname>Akshay</surname> <given-names>S</given-names></string-name>, <string-name><surname>Reddy</surname> <given-names>VM</given-names></string-name>, <string-name><surname>Reddy</surname> <given-names>SM</given-names></string-name></person-group>. <article-title>Automation of recon process for ethical hackers</article-title>. In: <conf-name>Proceedings of the 2022 International Conference for Advancement in Technology (ICONAT)</conf-name>; <year>2022 Jan 21&#x2013;22</year>; <publisher-loc>Goa, India</publisher-loc>. doi:<pub-id pub-id-type="doi">10.1109/iconat53423.2022.9726077</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Mohamed</surname> <given-names>I</given-names></string-name>, <string-name><surname>Hefny</surname> <given-names>HA</given-names></string-name>, <string-name><surname>Darwish</surname> <given-names>NR</given-names></string-name></person-group>. <article-title>Enhancing cybersecurity defenses: a multicriteria decision-making approach to MITRE ATT&#x0026;CK mitigation strategy</article-title>. <comment>arXiv:2407.19222v1. 2024</comment>.</mixed-citation></ref>
</ref-list>
</back></article>

