AI Exposure and AI Resilience: A Two-Dimensional Assessment Framework for Software and Software-Based Business Model
Summary
This paper develops the AI Exposure and Resilience (AI-ER) framework, a two-dimensional assessment model for evaluating how AI affects software businesses by separating exposure to AI pressure from resilience to adapt.
View Cached Full Text
Cached at: 09/12/26, 08:27 AM
# AI Exposure and AI ResilienceA Two-Dimensional Assessment Framework for Software and Software-Based Business Models
Source: [https://arxiv.org/html/2609.11321](https://arxiv.org/html/2609.11321)
Paul Darius MandlPeter MandlAffiliation:Munich University of Applied Sciences Munich, Germany peter\.mandl@hm\.eduMartin HäuslAffiliation:Munich University of Applied Sciences Munich, Germany martin\.haeusl@hm\.edu
###### Abstract
Artificial intelligence is changing both software production and the economics of software\-based business models\. Classical technology due diligence mainly examines technical properties such as architecture, scalability, and technical debt\. These criteria do not fully capture how AI can affect a company’s value proposition, competitive position, margins, or access to customers\. This paper develops*Artificial Intelligence Exposure and Resilience*\(AI\-ER\) as a two\-dimensional assessment framework\.*AI exposure*describes the pressure for change that AI creates for a business model\.*AI resilience*describes the company’s ability to absorb that pressure, adapt to changed conditions, and use AI in an economically viable way\. Metrics for both dimensions are derived from current AI capabilities, their deployment conditions, and relevant research on business models and organizational adaptability\. The model keeps exposure and resilience separate and adds an explicit assessment of evidence quality and confidence\. It can be applied first with public information and later refined with internal evidence\. The result is a traceable company profile that supports comparison without concealing uncertainty in the underlying evidence\. The paper also specifies an initial score logic and a procedure for empirical validation\.
###### Index Terms:
AI exposure, AI resilience, AI\-ER, generative AI, software business models, tech due diligence, M&A, AI unit economics
## IIntroduction
Advances in artificial intelligence are changing how companies create value and how software\-based business models should be assessed\. The relevant question is no longer only whether a company uses AI\. It is also necessary to examine which parts of its offering come under pressure and how well the company can respond\. This is particularly important for software businesses because their customer benefit often depends on the processing or generation of information\. Current AI systems can perform an increasing share of such work at growing scale and falling unit cost\[[13](https://arxiv.org/html/2609.11321#bib.bib1),[18](https://arxiv.org/html/2609.11321#bib.bib4)\]\.
The resulting assessment problem is neither purely technical nor purely strategic\. Technology due diligence typically examines architecture, code quality, scalability, security, and technical debt\. Strategic analysis focuses more strongly on customer value, competitive position, and the economic logic of the business\. AI can affect both sides at the same time\. A company may use AI extensively and still face substantial external pressure\. Conversely, proprietary data, strong customer relationships, or regulatory barriers may provide resilience even when visible AI functionality is still limited\.
This paper develops*Artificial Intelligence Exposure and Resilience*\(AI\-ER\) to separate these two questions\. AI exposure captures the pressure that AI places on the business model, its value proposition, margins, and customer access\. AI resilience captures the technical, organizational, and economic conditions that allow a company to absorb this pressure and adapt\. The two dimensions are assessed separately and shown together in a two\-dimensional company profile\. They are not combined into one overall score\.
The paper makes three contributions\. First, it defines AI exposure and AI resilience as distinct assessment dimensions\. Second, it derives a compact set of metrics from economic impact mechanisms and specifies a non\-compensatory score logic\. The score logic is complemented by an evidence and confidence model so that weak support for a rating remains visible\. Third, the paper provides a numerical example and proposes an empirical validation procedure based on independent assessments, reliability analysis, and sensitivity testing\.
The framework draws on the capabilities and deployment limits of current AI systems as well as research on technological exposure, business model change, platform economics, organizational resilience, and software delivery\. These foundations are used to derive the impact mechanisms and metrics\. The resulting approach is intended for strategic assessment, investment and acquisition decisions, and technology due diligence\. Its purpose is not to produce a universal company grade\. It provides a structured view of AI\-related pressure, response capacity, and the reliability of the evidence used for both\.
## IIMethodological Approach
Assess AI capabilitiesand limitsReview researchfoundationsDerive impactmechanismsDefine assessmentdimensionsDefinemetricsConstruct theAI\-ER profile
Fig\. 1:Procedure for developing the AI\-ER assessment framework, from the conceptual foundations to the two\-dimensional company profile\.The framework translates two abstract concepts into assessment questions that can be examined against observable information\. AI exposure represents external pressure for change\. AI resilience represents the capacity to respond\. A purely verbal appraisal would make comparisons across companies, assessors, and points in time difficult\. AI\-ER therefore uses defined metrics for both dimensions\.
The derivation combines a technical and an economic perspective\. Current AI capabilities indicate which services can in principle be provided by AI and which deployment conditions limit practical use\. Research on business models and market structure shows when these capabilities can create economic pressure\. Research on organizational adaptability identifies the conditions that allow a company to respond\. The framework links these perspectives without inferring a company’s exposure directly from a single technical capability\.
Recurring economic impact mechanisms are derived first\. They describe how AI can alter a company’s offering, market position, or economic performance\. The mechanisms are then assigned to AI exposure or AI resilience and translated into candidate metrics\. A metric is retained when it has a distinct conceptual role, can be supported by observable evidence, and does not duplicate another assessment quantity\.
The number of metrics is deliberately limited\. Too many indicators would increase collection effort and make overlaps more likely\. Excessive aggregation would conceal important differences between business model, market position, and organizational or technical capability\. The final selection therefore follows from the substantive derivation in Chapter[V](https://arxiv.org/html/2609.11321#S5)\. Figure[1](https://arxiv.org/html/2609.11321#S2.F1)summarizes this procedure\.
Metric scores are combined only within their respective dimension\. The dimension scores make the main tendency easier to compare, while the individual metrics remain visible\. This distinction matters because high exposure and high resilience can occur at the same time\. The company profile therefore depends on the joint interpretation of both dimensions rather than on one aggregate score\.
Each metric rating is linked to documented evidence\. Confidence describes how well a rating is supported rather than how high the rating is\. It depends on the quality of the available evidence and, where several independent assessment runs exist, on the agreement between those runs\. Chapter[VI](https://arxiv.org/html/2609.11321#S6)specifies the rating, aggregation, and confidence logic\.
## IIICapabilities and Deployment Conditions of Artificial Intelligence
AI\-ER requires a technical foundation that is not tied to one model, vendor, or product generation\. The relevant issue is therefore not which specific AI technology a company uses\. The framework asks which economically relevant services AI systems can perform under operational conditions\. This functional view connects technical development to possible changes in a business model without treating the availability of a technical feature as evidence of economic impact\.
### III\-AEconomically Relevant Capability Areas
Current AI systems provide analytical, predictive, generative, and decision\-support services\. Analytical methods identify patterns and anomalies in large data sets and can support the automated evaluation of complex information\. Their performance is documented in fields such as image classification and medical image analysis\[[23](https://arxiv.org/html/2609.11321#bib.bib17)\]\. Predictive systems estimate probabilities and expected developments from existing data\. Their usefulness depends strongly on data quality and on the stability of the relationships learned from those data\. Optimization methods extend these capabilities by comparing alternative courses of action within defined objectives and constraints\[[23](https://arxiv.org/html/2609.11321#bib.bib17)\]\.
Generative AI adds the creation and transformation of content\. Current systems can produce text, images, and program code and can transform information between different representations\. Standardized evaluations and professional task benchmarks document the breadth of these capabilities\[[23](https://arxiv.org/html/2609.11321#bib.bib17),[2](https://arxiv.org/html/2609.11321#bib.bib18)\]\. For business use, however, the quality of a single output is not sufficient\. Economic relevance increases when a service can be delivered repeatedly, integrated into existing systems, and scaled at acceptable cost\. Interfaces and standardized services make such capabilities accessible even to companies that do not develop foundation models themselves\.
This broad access has an important economic consequence\. Similar AI capabilities may be available to a company, its competitors, its customers, and large platform providers at the same time\. Technical access therefore does not in itself create a durable advantage\. The later assessment must examine where AI becomes economically effective and which company\-specific conditions support or limit its use\.
### III\-BDeployment Conditions and Limits
The documented capabilities do not make AI a universal replacement technology\. Performance remains dependent on the task, the available data, and the operating context\. Results from standardized evaluations cannot simply be transferred to business processes\. Generative systems can produce plausible but incorrect output and can react unstably to changed inputs\. They may also fail to reflect company\-specific rules or exceptions\. These limitations are particularly relevant in complex or liability\-sensitive applications\[[2](https://arxiv.org/html/2609.11321#bib.bib18),[1](https://arxiv.org/html/2609.11321#bib.bib19)\]\.
Further limits arise when isolated AI functions are embedded in longer workflows\. Operational use requires state to be maintained, errors to be detected, and responsibilities to remain clear across several processing steps\. Uncertainty can accumulate as workflows become longer\. A deployable solution therefore requires more than a capable model\. It also needs integration, monitoring, and suitable human control\.
Technical feasibility also differs from economic viability\. Operation, quality assurance, and integration create costs that can reduce the achievable benefit\. Legal and organizational requirements may further restrict use\. Data protection, information security, traceability, and human oversight are especially relevant where decisions concern persons or protected information\[[1](https://arxiv.org/html/2609.11321#bib.bib19),[8](https://arxiv.org/html/2609.11321#bib.bib20)\]\. AI\-ER therefore treats a capability as economically relevant only when it can be used with sufficient reliability, availability, viability, and permissibility in the respective context\.
The technical analysis defines the range of services from which AI\-related change may originate\. It does not yet establish whether a particular company is exposed or resilient\. That assessment also depends on economic and organizational relationships, which are considered in the next chapter\.
## IVState of Research and Conceptual Frame
Technical capability becomes economically relevant when it changes services, cost structures, market relationships, or forms of value creation\. AI\-ER therefore combines three research perspectives\. Work on technological exposure shows where AI capabilities overlap with existing activities and services\. Business model research explains how such overlaps can affect value creation and economic capture\. Research on resilience addresses how organizations respond to change\. These perspectives provide the conceptual basis for the two assessment dimensions\.
### IV\-ATechnological Exposure and Business Model Change
Research on technological exposure examines how strongly activities or occupations overlap with the capabilities of a new technology\. For generative AI, Eloundou et al\. and the OECD identify particularly strong exposure for knowledge\-intensive, language\-based, and information\-processing activities\[[7](https://arxiv.org/html/2609.11321#bib.bib3),[19](https://arxiv.org/html/2609.11321#bib.bib21)\]\. Such proximity indicates technical potential for change\. It does not establish that an activity will be automated or that a company will be economically weakened\. Operational and market conditions still determine whether the technology can be used and how its effects are distributed\.
A company assessment must therefore extend beyond isolated activities\. The relevant question is whether AI changes the economic core of a service, its value proposition, or its market position\. Research on business model innovation shows that AI can support new offerings, alter service delivery, and change economic capture\[[13](https://arxiv.org/html/2609.11321#bib.bib1),[12](https://arxiv.org/html/2609.11321#bib.bib2)\]\. The effect depends on the business logic\. A digital information product is generally closer to generative and analytical AI capabilities than an offering whose value depends heavily on physical, regulatory, or relational conditions\.
Platform economics adds the question of market structure and customer access\. Digital platforms can integrate formerly independent functions into larger offerings and can take over the interface to the customer\[[20](https://arxiv.org/html/2609.11321#bib.bib9),[26](https://arxiv.org/html/2609.11321#bib.bib10)\]\. A service may therefore remain useful while its independent monetization or route to market weakens\. AI exposure in this paper consequently includes more than technical substitutability\. It also covers AI\-related changes in value creation, competition, and customer access\.
### IV\-BOrganizational Resilience and Adaptability
Organizational resilience concerns the ability to deal with change and disruption\. It includes anticipation, continued capacity to act, and subsequent adaptation\. Duchek describes resilience as a capability that links anticipation, coping, and adaptation\[[6](https://arxiv.org/html/2609.11321#bib.bib12)\]\. This perspective is well suited to AI\-related change because new capabilities diffuse over time and can repeatedly alter customer expectations and competitive conditions\.
Research on digital resilience applies this perspective to organizations whose operations depend strongly on digital technologies\. Digital technologies can improve information processing and responsiveness, but they can also create dependencies on data, platforms, infrastructure, and external providers\[[25](https://arxiv.org/html/2609.11321#bib.bib13)\]\. The use of AI therefore does not automatically increase resilience\. Technical possibilities must be converted into dependable operational capabilities and linked to organizational decisions\.
Business model research also treats adaptation as a response to environmental change\. Buliga et al\. describe business model change as one such response\[[4](https://arxiv.org/html/2609.11321#bib.bib14)\]\. More recent studies examine AI as a resource that may support organizational resilience\. Han et al\. find that AI investment can help firms respond to external disruptions when complementary organizational conditions are present\[[11](https://arxiv.org/html/2609.11321#bib.bib15)\]\. Guo et al\. report a positive relationship between AI use and organizational resilience that is partly mediated by business model development\[[10](https://arxiv.org/html/2609.11321#bib.bib16)\]\. AI\-ER changes the direction of the question\. It asks how well a company can respond to change that is itself induced by AI\.
For the framework, AI resilience therefore denotes the ability to absorb AI\-related pressure and to adapt products, processes, and the business model where necessary\. This capacity may rest on existing competitive positions as well as technical and organizational capabilities\. It is not the inverse of exposure\. High exposure can coexist with high resilience, while low exposure can coexist with weak adaptability\.
### IV\-CResearch Gap and Conceptual Delineation
Existing research covers important parts of AI\-related change but rarely combines them for the assessment of an individual company\. Exposure studies often focus on tasks or occupations\. Business model research examines changes in value creation but does not always connect them to concrete proximity to AI capabilities\. Resilience research usually starts from general environmental change and increasingly treats AI as a supporting resource\.
AI\-ER connects these perspectives\. AI exposure denotes the pressure that AI capabilities and their diffusion place on a business model and its market position\. AI resilience denotes the company’s capacity to absorb this pressure, adapt, and use new technical possibilities for its own value creation\. Keeping the dimensions separate prevents technical vulnerability and organizational response capacity from being reduced to one indicator\.
The research base does not determine a unique set of metrics\. It defines the areas that the assessment needs to cover\. For exposure, these areas concern the transfer of AI capabilities into value creation, competition, and market relationships\. For resilience, they concern protection, adaptability, and the productive use of AI\. The next chapter derives a compact metric set from these foundations\.
## VDerivation of the AI\-ER Assessment Framework
The preceding chapters provide the technical and conceptual basis for AI\-ER\. The next step is to convert these foundations into assessment quantities\. The derivation starts with economic impact mechanisms and then assigns metrics to AI exposure and AI resilience\. Closely related aspects are merged when separate treatment would create double counting\. A metric is retained only when it adds a distinct assessment question and can be supported by observable evidence\.
### V\-AEconomic Impact Mechanisms
An AI capability becomes economically relevant when it changes how a service is provided, differentiated, or monetized\. Research on business model innovation and platform economics points to four recurring mechanisms\[[13](https://arxiv.org/html/2609.11321#bib.bib1),[20](https://arxiv.org/html/2609.11321#bib.bib9),[26](https://arxiv.org/html/2609.11321#bib.bib10)\]\.
- •*Substitution*occurs when AI can provide a substantial part of the customer benefit for which the existing service is paid\. Comparable quality at lower effort or shorter delivery time can already create pressure\.
- •*Compression*reduces the economic value contribution without eliminating the service\. AI may lower labor input or standardize previously scarce expertise\. This can reduce prices and margins\.
- •*Bundling*integrates a formerly stand\-alone service into a broader product or platform\. The function remains available, but its independent economic position can weaken\.
- •*Re\-intermediation*changes the relationship between provider and customer\. Assistants, platforms, or agent systems may take over search, selection, or transaction steps and thereby affect customer access\.
Several mechanisms can occur at the same time\. They are therefore treated as forms of economic impact rather than as mutually exclusive development paths\.
### V\-BDeriving the AI Exposure Metrics
AI exposure measures the pressure that these mechanisms place on a company\. Research on task exposure first motivates the*substitutability of the core benefit*\[[7](https://arxiv.org/html/2609.11321#bib.bib3),[19](https://arxiv.org/html/2609.11321#bib.bib21)\]\. This metric asks how closely the paid customer benefit lies to services that current AI systems can already provide\. The focus is on the service itself rather than on the current strength of brand, sales, or customer relationships\.
A second metric captures the*replicability of the offering*\. Generative AI can reduce the effort required to build or reproduce parts of digital products\. Replicability therefore considers the effort needed to recreate the offering while taking account of company\-specific data, integrations, domain knowledge, and regulatory requirements\. Substitutability and replicability remain separate because a difficult\-to\-copy product may still lose its customer benefit to a different AI\-based solution\. The reverse is also possible\.
Technical replaceability alone does not determine market pressure\.*Competitive dynamics*captures how competitors or platform providers use AI to change speed, price, or bundling\. The*business model modulator*captures the direction of the economic effect on the existing business model\. AI\-related productivity or quality gains can dampen exposure when the company can retain the resulting value\. The same developments can amplify exposure when they mainly benefit customers, competitors, or new entrants\.
*Customer access and demand pressure*covers changes on the demand side\. Customers may expect AI functions, perform parts of a service themselves, or delegate selection to assistants and platforms\[[3](https://arxiv.org/html/2609.11321#bib.bib5),[17](https://arxiv.org/html/2609.11321#bib.bib11)\]\. This can alter willingness to pay and the direct relationship between provider and customer\. The metric is therefore distinct from competitive dynamics, which focuses on the behavior of other providers\.
The derivation yields four numerical exposure metrics and one categorical business model modulator\. Together they cover the core benefit, the replicability of the offering, competitive change, the direction of the business model effect, and customer access\. This scope is broad enough to represent the main impact mechanisms while remaining manageable for evidence collection\.
### V\-CDeriving the AI Resilience Metrics
AI resilience describes the company’s capacity to respond to AI\-related pressure\. Business model and platform research first points to*protective positions*\. These are company\-specific resources or market positions that remain valuable under changed technical conditions\. The metric assesses their robustness against AI\-based alternatives rather than their historical strength alone\.
Research on organizational resilience and dynamic capabilities motivates*adaptability*\[[6](https://arxiv.org/html/2609.11321#bib.bib12),[24](https://arxiv.org/html/2609.11321#bib.bib8)\]\. The metric concerns the ability to recognize relevant change and to adjust products, processes, and the business model\. It therefore describes an organizational capability rather than the success of a single AI project\.
Productive AI use also requires a technical basis\.*Technical AI maturity*assesses whether data\-driven and model\-based functions can be developed, integrated, monitored, and operated reliably\[[14](https://arxiv.org/html/2609.11321#bib.bib22),[22](https://arxiv.org/html/2609.11321#bib.bib7)\]\.*Implementation capability*addresses a different question\. It examines whether skills, decision paths, and software delivery allow technical possibilities to be converted into operational solutions within a reasonable period\[[9](https://arxiv.org/html/2609.11321#bib.bib6)\]\.
The final resilience metric is*economic viability*\. It compares the effort for development, operation, control, and external dependencies with the expected contribution to value creation and customer benefit\. This prevents technical feasibility from being treated as sufficient evidence of lasting economic value\.
The five resilience metrics cover protective positions, adaptability, technical AI maturity, implementation capability, and economic viability\. They describe distinct conditions that influence a company’s ability to respond\. The next chapter specifies how the exposure and resilience metrics are rated and combined\.
### V\-DOverview of the Metrics
The derivation yields four numerical exposure metrics, one categorical business model modulator, and five numerical resilience metrics\. Table[I](https://arxiv.org/html/2609.11321#S5.T1)summarizes their conceptual basis\.
TABLE I:Overview of the assessment quantities derived in the AI\-ER framework and of their conceptual derivation\.The table shows that each assessment quantity addresses a distinct aspect of AI\-related change\. The following chapter defines the rating logic and the treatment of evidence and confidence\.
## VIProposal for a Concrete Implementation
The derived metrics require an explicit rating and aggregation procedure before they can be used in practice\. Different implementations are possible, including averaging and multi\-criteria procedures\. This paper specifies one rule\-based variant\. The purpose of the proposal is to keep critical individual scores visible and to provide a configuration that can be tested empirically\.
AI\-ER does not produce a general company grade\. It classifies AI\-related pressure and a company’s capacity to respond\. The same metrics can be used for an initial assessment based on public information and for a later assessment with internal evidence\. A richer evidence base may change metric scores, dimension scores, and confidence values without changing the underlying model\.
An assessment can be performed by one assessor, by several independent assessors, or by an AI\-based analysis service\. An automated service may collect information about a company, its offering, and relevant competitors and then apply the defined rating rules\. Reliability improves when several assessment runs are produced independently and compared afterward\. Runs are considered independent only when they do not share intermediate judgments\. Repeated outputs from the same reasoning process do not become independent merely because several outputs are generated\.
The formal specification makes the rating logic reproducible and provides a basis for software implementations of AI\-ER\. Such implementations can collect evidence, propose metric scores, execute assessment runs, and document disagreements\.
### VI\-ANotation
Only the terms needed for the score logic are introduced here\. The appendix provides the complete mathematical notation\.
- •A*metric*is a company characteristic rated against defined scale anchors\. Its value is the*metric score*\. Metric scores are combined into a*dimension score*according to the specified score logic\.
- •A*scale anchor*assigns a substantive meaning to a value on the five\-point rating scale\. The values 1, 3, and 5 are described explicitly\. The values 2 and 4 represent justified intermediate positions\.
- •*Core drivers*determine the base value of a dimension\. The proposed logic is*non\-compensatory*, which means that a critical core driver is not automatically offset by a favorable value on another core driver\.
- •A*threshold*activates a predefined rule once a specified value is reached\. A*combination rule*defines how scores or conditions are linked\. A*binary indicator*records whether such a condition is fulfilled\.
- •A*modulator*changes a base value by a bounded amount when an additional economic or structural condition has a dampening or amplifying effect\. It does not alter the underlying metric ratings\.
- •An*assessment run*is one complete application of the rating scheme to a company\. Several independent runs can be combined into a joint metric score and used to measure rating agreement\.
Thresholds, combination rules, and modulators are configurable parameters rather than values inferred from company data\. They must be fixed before an assessment is applied\. The configuration proposed below is an initial specification and requires empirical comparison with alternative settings\. Table[V](https://arxiv.org/html/2609.11321#A1.T5)summarizes the symbols\. Table[VI](https://arxiv.org/html/2609.11321#A1.T6)lists the configurable model parameters and the default values used in this paper\.
### VI\-BDetermining the Individual Scores and the Score Logic
Substantive scale anchors are defined for each numerical metric before the assessment, describing observable conditions for low, medium, and high levels\. The values 1, 3, and 5 come directly from these anchors, while 2 and 4 represent justified intermediate positions\. Missing evidence does not automatically produce a medium score\. The assessment is marked provisional or suspended until sufficient evidence becomes available\. For each metric, the assigned score, its justification, and the supporting evidence are documented together\.
For companyii, metricjj, and assessment runℓ\\ell,xij\(ℓ\)∈\{1,2,3,4,5\}x\_\{ij\}^\{\(\\ell\)\}\\in\\\{1,2,3,4,5\\\}\. IfL≥2L\\geq 2independent ratings are available, the median is used as the robust joint metric score\.
x~ij=median\(xij\(1\),…,xij\(L\)\)\.\\widetilde\{x\}\_\{ij\}=\\operatorname\{median\}\\\!\\left\(x\_\{ij\}^\{\(1\)\},\\ldots,x\_\{ij\}^\{\(L\)\}\\right\)\.\(1\)
The median limits the influence of strongly deviating ratings without assuming equal distances between the five scale levels\. The default configuration for the initial outside\-in assessment usesL=3L=3\. The subsequent inside\-in assessment described in Section[VI\-E](https://arxiv.org/html/2609.11321#S6.SS5)uses a single run\. The median therefore remains an observed integer scale value when several independent runs are used\. If an even number of runs is used, the rule for selecting one of the two middle values must be specified in advance\. With a single run,x~ij=xij\(1\)\\widetilde\{x\}\_\{ij\}=x\_\{ij\}^\{\(1\)\}\. The symbolsxisubx\_\{i\}^\{\\mathrm\{sub\}\}throughxieconx\_\{i\}^\{\\mathrm\{econ\}\}denote the resulting combined metric scores\.
The business model modulator is treated separately because it does not describe an ordinal intensity\. It records whether AI dampens, leaves unchanged, or amplifies the pressure associated with substitutability and replicability\. The classification depends on the economic effect on the company rather than on technical AI usability alone\. Productivity or quality gains matter only to the extent that they change the company’s position relative to customers, competitors, and possible substitutes\.
A dampening effect is present when AI strengthens the economic position of the existing business model\. This may occur when the company captures AI\-induced gains while retaining important competitive advantages\. Proprietary data, durable customer relationships, or regulatory requirements can support such an effect\. A neutral effect is assigned when neither direction predominates or when the evidence does not permit a reliable classification\. An amplifying effect is present when AI weakens the business model, for example by making services easier to substitute or by shifting value toward customers, competitors, or new entrants\.
With several assessment runs, the business model modulator is classified independently in each run and consolidated afterward\. Diverging assignments are documented and checked against the evidence\. The consolidated value enters the exposure score directly asMibmM\_\{i\}^\{\\mathrm\{bm\}\}\. It is not averaged with the numerical metric scores\.
The two dimension scores use non\-compensatory aggregation, a principle established in multi\-criteria decision analysis\[[21](https://arxiv.org/html/2609.11321#bib.bib23),[16](https://arxiv.org/html/2609.11321#bib.bib24)\]\. A simple average could hide a critical attack path or a substantial weakness behind favorable scores on other metrics\. The proposed logic therefore uses core drivers, binary indicators, and modulators\. The indicator function is defined below\.
I\(P\)=\{1,ifPholds,0,otherwise\.I\(P\)=\\begin\{cases\}1,&\\text\{if $P$ holds\},\\\\ 0,&\\text\{otherwise\}\.\\end\{cases\}\(2\)
For AI exposure, substitutability of the core benefitxisubx\_\{i\}^\{\\mathrm\{sub\}\}and replicability of the offeringxirepx\_\{i\}^\{\\mathrm\{rep\}\}are the core drivers\. Either can create substantial pressure on its own\. A product may be difficult to reproduce while its customer benefit is replaced by another AI\-based solution\. Conversely, high replicability can increase competitive pressure before the core benefit is fully substituted\. The base value is thereforemax\{xisub,xirep\}\\max\\\{x\_\{i\}^\{\\mathrm\{sub\}\},\\,x\_\{i\}^\{\\mathrm\{rep\}\}\\\}\. The maximum preserves the more critical of the two attack paths\.
Competitive dynamicsxicompx\_\{i\}^\{\\mathrm\{comp\}\}and customer access and demand pressurexicustx\_\{i\}^\{\\mathrm\{cust\}\}jointly enter an additional indicator\. In the proposed configuration, a score of at least 4 activates the indicator\.
IiE=I\(xicomp≥4∨xicust≥4\)\.I\_\{i\}^\{E\}=I\\\!\\left\(x\_\{i\}^\{\\mathrm\{comp\}\}\\geq 4\\;\\lor\\;x\_\{i\}^\{\\mathrm\{cust\}\}\\geq 4\\right\)\.\(3\)
The categorically rated business model modulator is represented as follows\.
Mibm=\{−1,for a dampening effect,0,for a neutral or ambiguous effect,1,for an amplifying effect\.M\_\{i\}^\{\\mathrm\{bm\}\}=\\begin\{cases\}\-1,&\\text\{for a dampening effect\},\\\\ 0,&\\text\{for a neutral or ambiguous effect\},\\\\ 1,&\\text\{for an amplifying effect\}\.\\end\{cases\}\(4\)
The exposure score is then
Ei=clamp\[1,5\]\(max\(xisub,xirep\)\+IiE\+Mibm\)\.E\_\{i\}=\\operatorname\{clamp\}\_\{\[1,5\]\}\\\!\\left\(\\max\\\!\\left\(x\_\{i\}^\{\\mathrm\{sub\}\},x\_\{i\}^\{\\mathrm\{rep\}\}\\right\)\+I\_\{i\}^\{E\}\+M\_\{i\}^\{\\mathrm\{bm\}\}\\right\)\.\(5\)
For AI resilience, protective positionsxiprotx\_\{i\}^\{\\mathrm\{prot\}\}and adaptabilityxiadaptx\_\{i\}^\{\\mathrm\{adapt\}\}are the core drivers under a weakest\-link logic\. Strong protective positions cannot fully compensate for low adaptability, and adaptability does not replace missing structural protection\. The base value is thereforemin\{xiprot,xiadapt\}\\min\\\{x\_\{i\}^\{\\mathrm\{prot\}\},\\,x\_\{i\}^\{\\mathrm\{adapt\}\}\\\}\. The minimum keeps the weaker core condition visible\.
Technical AI maturityxitechx\_\{i\}^\{\\mathrm\{tech\}\}and implementation capabilityxiimplx\_\{i\}^\{\\mathrm\{impl\}\}increase the base value only when both are high\. Technical infrastructure without implementation capability is insufficient, as is organizational readiness without a reliable technical foundation\.
IiR=I\(xitech≥4∧xiimpl≥4\)\.I\_\{i\}^\{R\}=I\\\!\\left\(x\_\{i\}^\{\\mathrm\{tech\}\}\\geq 4\\;\\land\\;x\_\{i\}^\{\\mathrm\{impl\}\}\\geq 4\\right\)\.\(6\)
Low economic viability is captured through a separate modulator\.
Miecon=I\(xiecon≤2\)\.M\_\{i\}^\{\\mathrm\{econ\}\}=I\\\!\\left\(x\_\{i\}^\{\\mathrm\{econ\}\}\\leq 2\\right\)\.\(7\)
The resilience score is then
Ri=clamp\[1,5\]\(min\(xiprot,xiadapt\)\+IiR−Miecon\)\.R\_\{i\}=\\operatorname\{clamp\}\_\{\[1,5\]\}\\\!\\left\(\\min\\\!\\left\(x\_\{i\}^\{\\mathrm\{prot\}\},x\_\{i\}^\{\\mathrm\{adapt\}\}\\right\)\+I\_\{i\}^\{R\}\-M\_\{i\}^\{\\mathrm\{econ\}\}\\right\)\.\(8\)
The functionclamp\\operatorname\{clamp\}bounds both dimension scores to the interval from 1 to 5\.
clamp\[1,5\]\(z\)=min\(5,max\(1,z\)\)\.\\operatorname\{clamp\}\_\{\[1,5\]\}\(z\)=\\min\\\!\\bigl\(5,\\max\(1,z\)\\bigr\)\.\(9\)
The aggregation operators have different roles\. The median combines independent ratings robustly\. The maximum preserves a sufficient attack path on the exposure side, while the minimum keeps a non\-compensable weakness visible on the resilience side\. Indicators represent threshold conditions\. Modulators adjust the base value by a bounded step when an additional contextual factor changes the direction of the assessment\. The clamping function keeps the final dimension scores on the common five\-point scale\.
Integer scores are intentional in the default configuration\. The framework provides a classification on five levels rather than a degree of numerical precision that the evidence does not support\. Thresholds, combination rules, and modulator values are part of the proposed configuration and must be compared empirically with alternatives\.
### VI\-CEvidence, Consistency, and Confidence
Every metric score must be supported by observable information\. The relevant evidence depends on the metric\. Each assessment records which statements are directly supported, which depend on inference, and where information remains incomplete\.
Evidence quality is assessed through five properties\.*Directness*indicates how closely the evidence relates to the metric itself\.*Timeliness*reflects whether the information is current enough for the assessment\.*Completeness*captures whether the relevant aspects of the metric are covered\.*Independence*reduces the risk of treating repeated information from dependent sources as separate confirmation\.*Agreement*reflects whether independent sources support compatible conclusions\. Each property is rated 0 for insufficient, 0\.5 for partly fulfilled, or 1 for fulfilled\.
The five properties need not contribute equally to every metric\. Positive weights can therefore be assigned to the evidence components\. The weights may differ by metric\. The default configuration uses equal weights, which provides a simple reference case for later validation\.
For companyii, metricjj, and evidence propertykk, letqij\(k\)∈\{0,0\.5,1\}q\_\{ij\}^\{\(k\)\}\\in\\\{0,0\.5,1\\\}denote the component score and letwj\(k\)\>0w\_\{j\}^\{\(k\)\}\>0denote its normalized weight\. The weights satisfy∑k∈𝒦wj\(k\)=1\\sum\_\{k\\in\\mathcal\{K\}\}w\_\{j\}^\{\(k\)\}=1\. The set of evidence properties is
𝒦=\{dir,tim,cmp,ind,agr\}\.\\mathcal\{K\}=\\\{\\mathrm\{dir\},\\mathrm\{tim\},\\mathrm\{cmp\},\\mathrm\{ind\},\\mathrm\{agr\}\\\}\.Evidence quality is calculated as a weighted mean\.
Qij=∑k∈𝒦wj\(k\)qij\(k\),Qij∈\[0,1\]\.Q\_\{ij\}=\\sum\_\{k\\in\\mathcal\{K\}\}w\_\{j\}^\{\(k\)\}q\_\{ij\}^\{\(k\)\},\\qquad Q\_\{ij\}\\in\[0,1\]\.\(10\)
For the five properties used in the framework, the formula can be written explicitly as
Qij=\\displaystyle Q\_\{ij\}=\{\}wjdirqijdir\+wjtimqijtim\+wjcmpqijcmp\\displaystyle w\_\{j\}^\{\\mathrm\{dir\}\}q\_\{ij\}^\{\\mathrm\{dir\}\}\+w\_\{j\}^\{\\mathrm\{tim\}\}q\_\{ij\}^\{\\mathrm\{tim\}\}\+w\_\{j\}^\{\\mathrm\{cmp\}\}q\_\{ij\}^\{\\mathrm\{cmp\}\}\(11\)\+wjindqijind\+wjagrqijagr\.\\displaystyle\+w\_\{j\}^\{\\mathrm\{ind\}\}q\_\{ij\}^\{\\mathrm\{ind\}\}\+w\_\{j\}^\{\\mathrm\{agr\}\}q\_\{ij\}^\{\\mathrm\{agr\}\}\.
Because the normalized weights sum to one and all component scores lie in\[0,1\]\[0,1\],QijQ\_\{ij\}also lies in\[0,1\]\[0,1\]\. A value of 0 means that all five properties are rated insufficient\. A value of 1 requires all five properties to be fully satisfied\. With equal weights, Equation \([11](https://arxiv.org/html/2609.11321#S6.E11)\) reduces to the arithmetic mean\.
The separate component scores remain part of the assessment record\. Two metrics can have the same value ofQijQ\_\{ij\}even when the supporting evidence differs materially\. One rating may be based on current but incomplete information while another may rely on complete information from dependent sources\. The aggregate value therefore supports comparison without replacing inspection of the component scores and the documented justification\.
When several independent assessment runs are available, their rating agreement is measured separately\. The valueAijA\_\{ij\}captures the deviation of theLLindividual ratings from their joint medianx~ij\\widetilde\{x\}\_\{ij\}\.
Aij=1−12L∑ℓ=1L\|xij\(ℓ\)−x~ij\|,Aij∈\[0,1\],L≥2\.A\_\{ij\}=1\-\\frac\{1\}\{2L\}\\sum\_\{\\ell=1\}^\{L\}\\left\|x\_\{ij\}^\{\(\\ell\)\}\-\\widetilde\{x\}\_\{ij\}\\right\|,\\qquad A\_\{ij\}\\in\[0,1\],\\quad L\\geq 2\.\(12\)
The normalization uses the five\-point rating scale\. Its range is 4 and the mean absolute deviation from the median can be at most 2 points\. The factor2L2Ltherefore maps the agreement measure to\[0,1\]\[0,1\]\. Identical ratings produceAij=1A\_\{ij\}=1\. Larger deviations reduce the value\. With an even number of assessment runs,Aij=0A\_\{ij\}=0can occur when half of the ratings lie at each end of the scale\. With an odd number of runs, the minimum is greater than 0\.
Two forms of agreement are kept distinct\. The componentqijagrq\_\{ij\}^\{\\mathrm\{agr\}\}refers to agreement among evidence sources\. The valueAijA\_\{ij\}refers to agreement among independent assessment runs\. The first concerns the evidence base\. The second concerns the stability of the resulting rating across assessors\.
With only one assessment run, confidence is based on evidence quality alone and is marked as not independently confirmed\. With several independent runs, confidence is limited by the weaker of evidence quality and rating agreement\.
Cij=\{Qij,forL=1,min\{Qij,Aij\},forL≥2\.Cij∈\[0,1\]\.C\_\{ij\}=\\begin\{cases\}Q\_\{ij\},&\\text\{for $L=1$\},\\\\\[5\.69054pt\] \\min\\\!\\left\\\{Q\_\{ij\},A\_\{ij\}\\right\\\},&\\text\{for $L\\geq 2$\}\.\\end\{cases\}\\qquad C\_\{ij\}\\in\[0,1\]\.\(13\)
The minimum implements a non\-compensatory rule\. Strong evidence cannot compensate for poor agreement between independent runs\. High agreement cannot compensate for weak evidence\. Confidence is classified as low forCij<0\.5C\_\{ij\}<0\.5, medium for0\.5≤Cij<0\.750\.5\\leq C\_\{ij\}<0\.75, and high forCij≥0\.75C\_\{ij\}\\geq 0\.75\. These thresholds are part of the proposed configuration and require empirical validation\.
Dimension confidence is based only on metrics that actually affect the corresponding dimension score\. For companyii,𝒜iE\\mathcal\{A\}\_\{i\}^\{\\mathrm\{E\}\}denotes the decision\-relevant metrics for exposure and𝒜iR\\mathcal\{A\}\_\{i\}^\{\\mathrm\{R\}\}denotes the decision\-relevant metrics for resilience\. These sets include the core driver selected by the maximum or minimum and any metric that activates a binary indicator\. They also include metrics that determine a modulator\. If several metrics are equally decisive, all of them are included\.
The confidence values of the two dimension scores are
CiE=minj∈𝒜iECij,CiR=minj∈𝒜iRCij\.C\_\{i\}^\{\\mathrm\{E\}\}=\\min\_\{j\\in\\mathcal\{A\}\_\{i\}^\{\\mathrm\{E\}\}\}C\_\{ij\},\\qquad C\_\{i\}^\{\\mathrm\{R\}\}=\\min\_\{j\\in\\mathcal\{A\}\_\{i\}^\{\\mathrm\{R\}\}\}C\_\{ij\}\.\(14\)
The minimum ensures that dimension confidence does not exceed the confidence of its weakest decision\-relevant basis\. A high dimension score with low confidence should therefore be treated as a result that requires further evidence\. Scores close to a threshold should also be identified because a small reassessment can change an indicator, a modulator, or the quadrant assignment\.
### VI\-DThe Two\-Dimensional AI\-ER Profile
AI exposure and AI resilience are displayed jointly rather than offset against each other\. In the proposed configuration, scores from 1 to 3 are classified as low and scores of 4 or 5 as high\. A score of 3 lies immediately below the threshold and should be marked as near\-threshold\. Table[II](https://arxiv.org/html/2609.11321#S6.T2)defines the four quadrant assignments\.
TABLE II:Score\-based assignment to the quadrants of the AI\-ER profile\.AI exposureAI resiliencelowhighlowhighDefended Nichelow exposure,high resilienceAI\-Ready Compounderhigh exposure,high resilienceRebuilding Requiredlow exposure,low resilienceAcute Threathigh exposure,low resilience
Fig\. 2:Quadrants of the two\-dimensional AI\-ER profile\.- •*Defended Niche\.*This position combines low exposure with high resilience\. The core benefit is comparatively difficult to attack, while good conditions for adaptation and AI use are also present\.
- •*AI\-Ready Compounder\.*High exposure meets high resilience\. The company operates in a strongly changing environment but has the conditions required to manage the change actively and use it for its own development\.
- •*Rebuilding Required\.*Current exposure is low, but the capacity for change is limited\. If the pressure for change rises, the company can respond only to a limited extent\. The primary need for action therefore lies in building protective, adaptive, and implementation capability\.
- •*Acute Threat\.*High exposure coincides with low resilience\. Vulnerable services meet insufficient protective and adaptive capability, creating an immediate need for review and action\.
The quadrants are not final company classes\. Interpretation must also consider the individual metrics, the supporting evidence, confidence, and the distance to relevant thresholds\.
### VI\-EAnalysis Layers and Presentation of Results
The assessment can be performed in two stages\. An outside\-in analysis uses publicly available information to produce an initial rating of the nine metrics and the business model modulator\. It also identifies weakly supported ratings and information gaps\. This makes an initial AI\-ER profile available before internal data collection is complete\. Figure[3](https://arxiv.org/html/2609.11321#S6.F3)shows the relationship between both analysis layers and the formal assessment methodology\.
The inside\-in analysis is conducted as a single subsequent assessment run\. It takes the preliminary outside\-in profile as its starting point and adds internal technical, organizational, process, and economic information\. It tests assumptions formed from public evidence and can change both metric scores and confidence\. Detailed review should focus on metrics that influence a dimension score or remain weakly supported\. Ratings close to thresholds also deserve particular attention\. Both layers use the same metrics and score logic, so the inside\-in analysis refines the provisional profile rather than replacing it with a separate assessment\.
For companyiiand metricjj, letxijOx\_\{ij\}^\{O\}denote the preliminary outside\-in rating andxijIx\_\{ij\}^\{I\}the rating after the single inside\-in run\. LetEijOE\_\{ij\}^\{O\}denote the set of public evidence andEijIE\_\{ij\}^\{I\}the set of additional internal evidence\. The inside\-in rating is based onEijO∪EijIE\_\{ij\}^\{O\}\\cup E\_\{ij\}^\{I\}and the same scale anchors and score logic\. The change from the preliminary rating is
Δxij=xijI−xijO\.\\Delta x\_\{ij\}=x\_\{ij\}^\{I\}\-x\_\{ij\}^\{O\}\.\(15\)
A value ofΔxij=0\\Delta x\_\{ij\}=0confirms the preliminary rating\. A nonzero value indicates a revision based on the additional internal evidence\. Even when the metric score remains unchanged, the added evidence can changeQijQ\_\{ij\}and therefore confidence\. As the inside\-in stage uses one run,L=1L=1for this stage and Equation \([13](https://arxiv.org/html/2609.11321#S6.E13)\) reduces toCij=QijC\_\{ij\}=Q\_\{ij\}\.
The result consists of the two dimension scores, the quadrant position, and the complete metric profile\. Each metric is accompanied by its justification, evidence quality, rating agreement where applicable, and confidence\. Material assumptions and remaining information gaps are recorded separately\. The condensed profile therefore remains traceable to its underlying findings\.
Outside\-in analysisfor example, publicly available company, product, and market information on the internetInside\-in analysisInternal technology and organizational data as well asprocess and economic dataFormal AI\-ER assessment procedureFormal assessment methodologyDocumented evidence baseStage\-specific assessment runsScore logic with bounded compensationEvidence and confidence modelConfigurable thresholds and combination rulesMetric scores and dimension scoresEiE\_\{i\},RiR\_\{i\}, and the complete metric profileEvidence, agreement, andconfidence documentationEvidence quality and rating agreement where applicableas well as the identified need for reviewOverall AI\-ER profileQuadrant assignment andidentified need for review
Fig\. 3:Formal AI\-ER methodology with outside\-in and inside\-in evidence and the assessment results derived from them\.
### VI\-FIllustrative Numerical Example
A fictitious companyAAillustrates the score logic from Section[VI\-B](https://arxiv.org/html/2609.11321#S6.SS2)and the confidence model from Section[VI\-C](https://arxiv.org/html/2609.11321#S6.SS3)\. The values are hypothetical and have no empirical meaning\. Three independent assessment runs are assumed for every metric, soL=3L=3\. Equation \([1](https://arxiv.org/html/2609.11321#S6.E1)\) therefore returns an observed integer rating as the combined metric score\. Table[III](https://arxiv.org/html/2609.11321#S6.T3)shows the assumed exposure ratings and the business model modulator\.
TABLE III:Assumed ratings for the AI exposure metrics of the fictitious companyAA\(illustrative example\)\.The core exposure drivers arexAsub=4x\_\{A\}^\{\\mathrm\{sub\}\}=4andxArep=3x\_\{A\}^\{\\mathrm\{rep\}\}=3\. Their maximum gives a base value of 4\. SincexAcomp=4x\_\{A\}^\{\\mathrm\{comp\}\}=4, the exposure indicator in Equation \([3](https://arxiv.org/html/2609.11321#S6.E3)\) equalsIAE=1I\_\{A\}^\{E\}=1\. The business model modulator equalsMAbm=\+1M\_\{A\}^\{\\mathrm\{bm\}\}=\+1\. Equation \([5](https://arxiv.org/html/2609.11321#S6.E5)\) therefore gives
EA=clamp\[1,5\]\(max\{4,3\}\+1\+1\)=clamp\[1,5\]\(6\)=5\.E\_\{A\}=\\operatorname\{clamp\}\_\{\[1,5\]\}\\bigl\(\\max\\\{4,3\\\}\+1\+1\\bigr\)=\\operatorname\{clamp\}\_\{\[1,5\]\}\(6\)=5\.
CompanyAAreaches the highest exposure level\. The core benefit is highly substitutable and competitive dynamics already reach the indicator threshold\. The amplifying business model effect increases the score by a further step\.
Table[IV](https://arxiv.org/html/2609.11321#S6.T4)shows the assumed resilience ratings\.
TABLE IV:Assumed ratings for the AI resilience metrics of the fictitious companyAA\(illustrative example\)\.For resilience,xAprot=4x\_\{A\}^\{\\mathrm\{prot\}\}=4andxAadapt=3x\_\{A\}^\{\\mathrm\{adapt\}\}=3are the core drivers\. Their minimum gives a base value of 3\. Both technical AI maturity and implementation capability reach 4, soIAR=1I\_\{A\}^\{R\}=1\. Economic viability remains above the penalty threshold andMAecon=0M\_\{A\}^\{\\mathrm\{econ\}\}=0\. The resilience score is
RA=clamp\[1,5\]\(min\{4,3\}\+1−0\)=clamp\[1,5\]\(4\)=4\.R\_\{A\}=\\operatorname\{clamp\}\_\{\[1,5\]\}\\bigl\(\\min\\\{4,3\\\}\+1\-0\\bigr\)=\\operatorname\{clamp\}\_\{\[1,5\]\}\(4\)=4\.
The company therefore combines high exposure with high resilience\. Its adaptability score limits resilience more strongly than technical AI maturity\.
The confidence calculation can be illustrated withxAsubx\_\{A\}^\{\\mathrm\{sub\}\}\. Assume evidence component scores ofqAdir=1q\_\{A\}^\{\\mathrm\{dir\}\}=1,qAtim=1q\_\{A\}^\{\\mathrm\{tim\}\}=1,qAcmp=0\.5q\_\{A\}^\{\\mathrm\{cmp\}\}=0\.5,qAind=1q\_\{A\}^\{\\mathrm\{ind\}\}=1, andqAagr=0\.5q\_\{A\}^\{\\mathrm\{agr\}\}=0\.5, with equal weights\. Evidence quality isQA,sub=0\.8Q\_\{A,\\mathrm\{sub\}\}=0\.8\. For the ratings4,4,54,4,5with median 4, the summed absolute deviation is 1\. Equation \([12](https://arxiv.org/html/2609.11321#S6.E12)\) therefore givesAA,sub≈0\.83A\_\{A,\\mathrm\{sub\}\}\\approx 0\.83\. Metric confidence is the lower value and thus equalsCA,sub=0\.8C\_\{A,\\mathrm\{sub\}\}=0\.8\. The remaining decision\-relevant metrics are treated in the same way\. Dimension confidence then follows from Equation \([14](https://arxiv.org/html/2609.11321#S6.E14)\)\.
WithEA=5E\_\{A\}=5andRA=4R\_\{A\}=4, companyAAbelongs to the*AI\-Ready Compounder*quadrant in Table[II](https://arxiv.org/html/2609.11321#S6.T2)\. Exposure is high, but the company also has substantial capacity to respond\. The example illustrates why the two dimensions should not be collapsed into one score\.
## VIIValidation and Limits
The proposed rating logic makes AI\-ER operational, but the framework has not yet been validated empirically\. Validation must address the suitability of the metrics, the reliability of their application, the stability of the score logic, and the relationship between assessment results and later company developments\. The confidence model requires separate examination because it is intended to distinguish well\-supported ratings from provisional ones\.
### VII\-AApproach to Empirical Validation
A first validation step should use comparative case studies across different software\-based business models\. The cases should cover different combinations of exposure and resilience and should vary in size, market position, and prior AI use\. Each case can first be assessed from public information and then reassessed with internal evidence\. The comparison indicates which metrics can be judged reliably from the outside and where internal information changes the result\.
Independent assessments of the same company are required to test rating reliability\. Agreement can be measured with established statistics such as Krippendorff’s alpha or Cohen’s kappa\[[15](https://arxiv.org/html/2609.11321#bib.bib26),[5](https://arxiv.org/html/2609.11321#bib.bib25)\]\. Large deviations would indicate unclear concepts, weak scale anchors, or excessive interpretive freedom\. Validation should also examine whether the metrics within each dimension remain empirically distinct and whether exposure and resilience can be separated as intended\.
Longitudinal validation is needed to assess predictive relevance\. High exposure should be associated with later pressure on differentiation, pricing, margins, or customer access\. High resilience should be associated with a stronger capacity to adapt products, processes, technical structures, or the business model\. Such relationships can only be examined by comparing earlier assessments with developments observed later\.
Sensitivity analysis should vary thresholds, combination rules, weights, and modulators within plausible ranges\. Stable dimension scores would support the robustness of the model structure\. Strong changes would indicate dependence on particular parameter choices\. The confidence model should also be tested against later evidence and repeated assessments\. High\-confidence ratings should prove more stable than low\-confidence ratings if the confidence model works as intended\.
### VII\-BLimits of the Assessment Framework
The current scale anchors, thresholds, combination rules, evidence weights, and modulators have not been calibrated on a large sample\. The maximum rule for exposure and the minimum rule for resilience are conceptual choices\. They assume that one pronounced attack path can determine exposure and that one weak core condition can limit resilience\. Their suitability across industries and business models remains an empirical question\. The dimension scores should therefore be interpreted as structured classifications rather than precise measurements\.
Assessment quality depends strongly on the available evidence\. Public information often describes products and visible AI activities better than internal technical or organizational conditions\. Companies with extensive external communication may therefore appear easier to assess than more reticent companies with similar capabilities\. The confidence model makes this limitation visible but cannot replace missing evidence\.
AI\-ER also provides a time\-bound assessment\. New AI capabilities, changes in cost, competitive offerings, regulation, or internal transformation can alter both dimensions\. Assessments should therefore be updated when material conditions change\. The overall model can be used across industries, but scale anchors and evidence requirements may need adaptation to industry\-specific value creation and regulatory conditions\.
A single AI\-ER assessment does not establish causality\. Company performance is influenced by many factors beyond AI\. The framework therefore complements strategic, technical, and financial analysis rather than replacing them\. Dimension scores should always be read together with the individual metrics, the supporting evidence, and confidence\.
## VIIIConclusion and Outlook
This paper develops*Artificial Intelligence Exposure and Resilience*as a framework for assessing how AI affects software\-based business models\. Its central distinction is between AI exposure and AI resilience\. Exposure describes the pressure for change\. Resilience describes the company’s capacity to absorb that pressure and adapt\. Keeping both dimensions separate makes situations visible in which a company is highly exposed but also well prepared to respond\.
The metrics are derived from AI capabilities, economic impact mechanisms, and research on organizational adaptability\. The proposed score logic is non\-compensatory so that a critical attack path or a weak core condition remains visible\. Evidence quality and rating agreement are assessed separately from the metric values and are combined into a confidence measure\. The framework can therefore distinguish the assessment result from the reliability of the evidence supporting it\.
AI\-ER can be applied first as an outside\-in assessment and later refined with internal evidence\. Possible applications include strategic review, technology due diligence, and investment or acquisition analysis\. The framework remains a proposal that requires empirical validation\. Comparative case studies, independent assessment runs, longitudinal observation, and sensitivity analysis are needed to test the metrics and the score logic\.
A software implementation can support evidence collection and the reproducible application of the formal rules\. Such implementation work is useful for testing practical applicability, but it does not replace empirical validation of the framework\. The next research step is therefore to combine implementation tests with a broader case base and to refine scale anchors, thresholds, weights, and modulators where the evidence supports adjustment\.
## Note on Preparation
Technical assistance systems were used for language revision, formal checks, and individual editorial steps\. The concept, methodology, selection of content, source assessment, argumentation, and approval of the final version remained with the authors\.
## References
- \[1\]C\. Autio, R\. Schwartz, J\. Dunietz, S\. Jain, M\. Stanley, E\. Tabassi, P\. Hall, and K\. Roberts\(2024\)Artificial intelligence risk management framework: generative artificial intelligence profile\.Technical reportTechnical ReportNIST AI 600\-1,National Institute of Standards and Technology\.External Links:[Document](https://dx.doi.org/10.6028/NIST.AI.600-1),[Link](https://doi.org/10.6028/NIST.AI.600-1)Cited by:[§III\-B](https://arxiv.org/html/2609.11321#S3.SS2.p1.1),[§III\-B](https://arxiv.org/html/2609.11321#S3.SS2.p3.1)\.
- \[2\]Y\. Bengioet al\.\(2026\)International AI safety report 2026\.Technical reportTechnical ReportDSIT 2026/001,Department for Science, Innovation and Technology\.Note:Accessed July 27, 2026External Links:[Link](https://internationalaisafetyreport.org/publication/international-ai-safety-report-2026)Cited by:[§III\-A](https://arxiv.org/html/2609.11321#S3.SS1.p2.1),[§III\-B](https://arxiv.org/html/2609.11321#S3.SS2.p1.1)\.
- \[3\]A\. Bick, A\. Blandin, and D\. J\. Deming\(2024\)The rapid adoption of generative AI\.NBER Working PaperTechnical Report32966,National Bureau of Economic Research\.Note:Revised February 2025External Links:[Document](https://dx.doi.org/10.3386/w32966),[Link](https://www.nber.org/papers/w32966)Cited by:[§V\-B](https://arxiv.org/html/2609.11321#S5.SS2.p4.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.6.4.1.1)\.
- \[4\]O\. Buliga, C\. W\. Scheiner, and K\. Voigt\(2016\)Business model innovation and organizational resilience: towards an integrated conceptual framework\.Journal of Business Economics86\(6\),pp\. 647–670\.External Links:[Document](https://dx.doi.org/10.1007/s11573-015-0796-y),[Link](https://link.springer.com/article/10.1007/s11573-015-0796-y)Cited by:[§IV\-B](https://arxiv.org/html/2609.11321#S4.SS2.p3.1)\.
- \[5\]J\. Cohen\(1960\)A coefficient of agreement for nominal scales\.Educational and Psychological Measurement20\(1\),pp\. 37–46\.Cited by:[§VII\-A](https://arxiv.org/html/2609.11321#S7.SS1.p2.1)\.
- \[6\]S\. Duchek\(2020\)Organizational resilience: a capability\-based conceptualization\.Business Research13,pp\. 215–246\.External Links:[Document](https://dx.doi.org/10.1007/s40685-019-0085-7),[Link](https://link.springer.com/article/10.1007/s40685-019-0085-7)Cited by:[§IV\-B](https://arxiv.org/html/2609.11321#S4.SS2.p1.1),[§V\-C](https://arxiv.org/html/2609.11321#S5.SS3.p2.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.8.4.1.1)\.
- \[7\]T\. Eloundou, S\. Manning, P\. Mishkin, and D\. Rock\(2024\)GPTs are GPTs: labor market impact potential of LLMs\.Science384\(6702\),pp\. 1306–1308\.External Links:[Document](https://dx.doi.org/10.1126/science.adj0998),[Link](https://www.science.org/doi/10.1126/science.adj0998)Cited by:[§IV\-A](https://arxiv.org/html/2609.11321#S4.SS1.p1.1),[§V\-B](https://arxiv.org/html/2609.11321#S5.SS2.p1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.2.4.1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.3.4.1.1)\.
- \[8\]European Parliament and Council of the European Union\(2024\)Regulation \(EU\) 2024/1689 laying down harmonised rules on artificial intelligence\.Note:Official Journal of the European Union, 12 July 2024External Links:[Link](https://eur-lex.europa.eu/eli/reg/2024/1689/oj)Cited by:[§III\-B](https://arxiv.org/html/2609.11321#S3.SS2.p3.1)\.
- \[9\]N\. Forsgren, J\. Humble, and G\. Kim\(2018\)Accelerate: the science of lean software and devops\.IT Revolution Press,Portland, OR\.External Links:ISBN 978\-1942788331Cited by:[§V\-C](https://arxiv.org/html/2609.11321#S5.SS3.p3.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.10.4.1.1)\.
- \[10\]T\. Guo, J\. Shang, and X\. Ding\(2026\)Send charcoal in snowy weather: artificial intelligence and organizational resilience\.Asia Pacific Journal of Management\.Note:Online firstExternal Links:[Document](https://dx.doi.org/10.1007/s10490-025-10107-4),[Link](https://link.springer.com/article/10.1007/s10490-025-10107-4)Cited by:[§IV\-B](https://arxiv.org/html/2609.11321#S4.SS2.p3.1)\.
- \[11\]M\. Han, H\. Shen, J\. Wu, and X\. M\. Zhang\(2025\)Artificial intelligence and firm resilience: empirical evidence from natural disaster shocks\.Information Systems Research36\(4\),pp\. 2116–2133\.External Links:[Document](https://dx.doi.org/10.1287/isre.2022.0440),[Link](https://pubsonline.informs.org/doi/10.1287/isre.2022.0440)Cited by:[§IV\-B](https://arxiv.org/html/2609.11321#S4.SS2.p3.1)\.
- \[12\]P\. Jorzik, S\. P\. Klein, D\. K\. Kanbach, and S\. Kraus\(2024\)AI\-driven business model innovation: a systematic review and research agenda\.Journal of Business Research182,pp\. 114764\.External Links:[Document](https://dx.doi.org/10.1016/j.jbusres.2024.114764),[Link](https://www.sciencedirect.com/science/article/pii/S0148296324002686)Cited by:[§IV\-A](https://arxiv.org/html/2609.11321#S4.SS1.p2.1)\.
- \[13\]D\. K\. Kanbach, L\. Heiduk, G\. Blueher, M\. Schreiter, and A\. Lahmann\(2024\)The GenAI is out of the bottle: generative artificial intelligence from a business model innovation perspective\.Review of Managerial Science18\(4\),pp\. 1189–1220\.External Links:[Document](https://dx.doi.org/10.1007/s11846-023-00696-z),[Link](https://link.springer.com/article/10.1007/s11846-023-00696-z)Cited by:[§I](https://arxiv.org/html/2609.11321#S1.p1.1),[§IV\-A](https://arxiv.org/html/2609.11321#S4.SS1.p2.1),[§V\-A](https://arxiv.org/html/2609.11321#S5.SS1.p1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.3.4.1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.4.4.1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.5.4.1.1)\.
- \[14\]D\. Kreuzberger, N\. Kühl, and S\. Hirschl\(2023\)Machine learning operations \(MLOps\): overview, definition, and architecture\.IEEE Access11,pp\. 31866–31879\.External Links:[Document](https://dx.doi.org/10.1109/ACCESS.2023.3262138),[Link](https://doi.org/10.1109/ACCESS.2023.3262138)Cited by:[§V\-C](https://arxiv.org/html/2609.11321#S5.SS3.p3.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.11.4.1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.9.4.1.1)\.
- \[15\]K\. Krippendorff\(2018\)Content analysis: an introduction to its methodology\.4 edition,SAGE Publications,Thousand Oaks, CA\.Cited by:[§VII\-A](https://arxiv.org/html/2609.11321#S7.SS1.p2.1)\.
- \[16\]G\. Munda\(2008\)Social multi\-criteria evaluation for a sustainable economy\.Springer,Berlin, Heidelberg\.Cited by:[§VI\-B](https://arxiv.org/html/2609.11321#S6.SS2.p8.1)\.
- \[17\]OECD\(2025\)Artificial intelligence and competitive dynamics in downstream markets\.OECD Roundtables on Competition Policy PapersTechnical Report331,OECD Publishing,Paris\.External Links:[Document](https://dx.doi.org/10.1787/ccf0624a-en),[Link](https://www.oecd.org/en/publications/artificial-intelligence-and-competitive-dynamics-in-downstream-markets_ccf0624a-en.html)Cited by:[§V\-B](https://arxiv.org/html/2609.11321#S5.SS2.p4.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.6.4.1.1)\.
- \[18\]OECD\(2026\)Generative AI\.Note:Accessed March 29, 2026External Links:[Link](https://www.oecd.org/en/topics/sub-issues/generative-ai.html)Cited by:[§I](https://arxiv.org/html/2609.11321#S1.p1.1)\.
- \[19\]OECD\(2026\)The OECD AI exposure measure: mapping the OECD AI capability indicators to occupations\.Technical reportTechnical Report59,OECD Artificial Intelligence Papers,OECD Publishing\.External Links:[Document](https://dx.doi.org/10.1787/f3da0f0a-en),[Link](https://doi.org/10.1787/f3da0f0a-en)Cited by:[§IV\-A](https://arxiv.org/html/2609.11321#S4.SS1.p1.1),[§V\-B](https://arxiv.org/html/2609.11321#S5.SS2.p1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.2.4.1.1)\.
- \[20\]G\. G\. Parker, M\. W\. Van Alstyne, and S\. P\. Choudary\(2016\)Platform revolution: how networked markets are transforming the economy and how to make them work for you\.W\. W\. Norton & Company,New York\.External Links:ISBN 978\-0393354355Cited by:[§IV\-A](https://arxiv.org/html/2609.11321#S4.SS1.p3.1),[§V\-A](https://arxiv.org/html/2609.11321#S5.SS1.p1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.4.4.1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.5.4.1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.7.4.1.1)\.
- \[21\]B\. Roy\(1996\)Multicriteria methodology for decision aiding\.Springer,Boston, MA\.Cited by:[§VI\-B](https://arxiv.org/html/2609.11321#S6.SS2.p8.1)\.
- \[22\]D\. Sculley, G\. Holt, D\. Golovin, E\. Davydov, T\. Phillips, D\. Ebner, V\. Chaudhary, M\. Young, J\. Crespo, and D\. Dennison\(2015\)Hidden technical debt in machine learning systems\.InAdvances in Neural Information Processing Systems,Vol\.28\.External Links:[Link](https://proceedings.neurips.cc/paper_files/paper/2015/hash/86df7dcfd896fcaf2674f757a2463eba-Abstract.html)Cited by:[§V\-C](https://arxiv.org/html/2609.11321#S5.SS3.p3.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.11.4.1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.9.4.1.1)\.
- \[23\]Stanford Institute for Human\-Centered Artificial Intelligence\(2026\)The 2026 AI index report\.Technical reportStanford University\.Note:Accessed July 27, 2026External Links:[Link](https://hai.stanford.edu/ai-index/2026-ai-index-report)Cited by:[§III\-A](https://arxiv.org/html/2609.11321#S3.SS1.p1.1),[§III\-A](https://arxiv.org/html/2609.11321#S3.SS1.p2.1)\.
- \[24\]D\. J\. Teece, G\. Pisano, and A\. Shuen\(1997\)Dynamic capabilities and strategic management\.Strategic Management Journal18\(7\),pp\. 509–533\.External Links:[Document](https://dx.doi.org/10.1002/%28SICI%291097-0266%28199708%2918%3A7%3C509%3A%3AAID-SMJ882%3E3.0.CO%3B2-Z)Cited by:[§V\-C](https://arxiv.org/html/2609.11321#S5.SS3.p2.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.10.4.1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.7.4.1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.8.4.1.1)\.
- \[25\]Y\. Tim and D\. E\. Leidner\(2023\)Digital resilience: a conceptual framework for information systems research\.Journal of the Association for Information Systems24\(5\),pp\. 1184–1198\.External Links:[Document](https://dx.doi.org/10.17705/1jais.00842),[Link](https://aisel.aisnet.org/jais/vol24/iss5/11/)Cited by:[§IV\-B](https://arxiv.org/html/2609.11321#S4.SS2.p2.1)\.
- \[26\]M\. Wessel, M\. Adam, A\. Benlian, A\. Majchrzak, and F\. Thies\(2025\)Generative AI and its transformative value for digital platforms\.Journal of Management Information Systems42\(2\),pp\. 346–369\.External Links:[Document](https://dx.doi.org/10.1080/07421222.2025.2487315),[Link](https://www.jmis-web.org/articles/1706)Cited by:[§IV\-A](https://arxiv.org/html/2609.11321#S4.SS1.p3.1),[§V\-A](https://arxiv.org/html/2609.11321#S5.SS1.p1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.4.4.1.1),[TABLE I](https://arxiv.org/html/2609.11321#S5.T1.4.6.4.1.1)\.
## Appendix ANotation and Model Parameters
Table[V](https://arxiv.org/html/2609.11321#A1.T5)summarizes the symbols used in the main text\. Table[VI](https://arxiv.org/html/2609.11321#A1.T6)lists the configurable parameters of the AI\-ER assessment model\. The default values reflect the initial configuration used in this paper\. Any deviation should be documented and compared with this configuration during validation\.
TABLE V:Notation of the formal AI\-ER assessment methodology\.TABLE VI:Configurable parameters of the AI\-ER model with value ranges and default configuration\.Similar Articles
AI in business
A general article discussing the role and impact of artificial intelligence in business environments.
How evals drive the next chapter in AI for businesses
OpenAI publishes a framework for business leaders on using AI evaluations (evals) to measure and improve AI system performance in organizational contexts, distinguishing between frontier evals for model development and contextual evals tailored to specific business workflows.
The five AI value models driving business reinvention
OpenAI outlines five emerging AI value models for enterprise transformation: workforce empowerment, customer engagement, expert augmentation, system integration, and autonomous operations. The article argues that successful organizations treat AI as a portfolio of interconnected value models rather than isolated pilots, following a strategic sequence to maximize business reinvention.
AI From the Trenches: Why Its Brilliance and Failures Share the Same Root
The author shares two years of experience building a platform with AI, identifying six recurring failure modes (Band-Aid, Assumption, Drift, Hallucination, Lack of Common Sense, Path of Least Resistance) and argues that even as models improve, these failure modes persist, becoming harder to detect.
Psychological Competence as a Missing Dimension in AI Evaluation
This paper introduces psychological competence as a missing dimension in AI evaluation, proposing a conceptual framework to assess how AI systems support user cognition, emotional interpretation, and decision-making in human-facing roles.