Source-linked AI summary

AI Exposure and AI Resilience: A Two-Dimensional Assessment Framework for Software and Software-Based Business Model

Paul Darius Mandl, Peter Mandl, Martin Häusl

arXiv:2609.11321v1cs.AI

TL;DR

Software businesses need assessment beyond conventional technical due diligence because AI can pressure value propositions, competition, margins, and customer access. The paper develops AI-ER, a two-dimensional framework that separately measures exposure and resilience with evidence-aware scoring. Its outcome is a traceable company profile that can be refined from public to internal evidence, while empirical validation remains necessary.

  • Problem

    Conventional technical due diligence does not fully assess how AI affects software companies’ value propositions, competitive positions, margins, and customer access.

  • Method

    AI-ER derives separate exposure and resilience metrics, combines them within dimensions, and records evidence quality and confidence.

  • Results

    The framework produces a two-dimensional company profile that keeps exposure, resilience, and evidence reliability distinguishable.

  • Takeaways & Limitations

    AI-ER can support strategic review, technology due diligence, and investment or acquisition analysis using an outside-in assessment refined with internal evidence.

  • Takeaways & Limitations

    The framework remains a proposal requiring empirical validation through comparative cases, independent assessments, longitudinal observation, and sensitivity analysis.

Abstract

from arXiv · show

Artificial intelligence is changing both software production and the economics of software-based business models. Classical technology due diligence mainly examines technical properties such as architecture, scalability, and technical debt. These criteria do not fully capture how AI can affect a company's value proposition, competitive position, margins, or access to customers. This paper develops Artificial Intelligence Exposure and Resilience (AI-ER) as a two-dimensional assessment framework. AI exposure describes the pressure for change that AI creates for a business model. AI resilience describes the company's ability to absorb that pressure, adapt to changed conditions, and use AI in an economically viable way. Metrics for both dimensions are derived from current AI capabilities, their deployment conditions, and relevant research on business models and organizational adaptability. The model keeps exposure and resilience separate and adds an explicit assessment of evidence quality and confidence. It can be applied first with public information and later refined with internal evidence. The result is a traceable company profile that supports comparison without concealing uncertainty in the underlying evidence. The paper also specifies an initial score logic and a procedure for empirical validation.

I. INTRODUCTION

AI-ER addresses the limits of conventional technical due diligence by assessing both AI-driven pressure on software businesses and their capacity to respond. It operationalizes this distinction through separate metrics, evidence-aware scoring, and a traceable two-dimensional profile.

  • I. INTRODUCTION: The framework complements technical due diligence with assessment of customer value, competitive position, and business-model economics.AI can affect technical and strategic dimensions simultaneously.
  • I. INTRODUCTION: AI-ER separates AI exposure—the pressure AI places on value propositions, margins, and customer access—from AI resilience—the capacity to absorb pressure and adapt.The dimensions remain separate rather than being collapsed into one overall score.
  • I. INTRODUCTION: The assessment uses defined metrics and confidence information so comparisons preserve both rating differences and uncertainty in the supporting evidence.Metric ratings remain linked to documented evidence, while confidence reflects evidence quality and agreement rather than rating magnitude.
  • I. INTRODUCTION: AI-ER derives distinct metrics from AI capabilities, deployment conditions, business-model change, market structure, and organizational adaptability.The derivation retains metrics that add distinct assessment questions and can be supported by observable evidence.
  • I. INTRODUCTION: AI capabilities are economically relevant only when they can be repeatedly delivered, integrated, and scaled under acceptable operating conditions.Technical availability alone does not establish durable economic advantage because similar capabilities may be accessible to firms, customers, competitors, and platforms.

B. Deployment Conditions and Limits

AI capabilities become economically relevant only when they can alter services, value creation, market relationships, and organizational operations under the conditions of actual deployment. AI-ER therefore separates exposure from resilience while recognizing technical, economic, legal, and organizational limits.

  • Deployment conditions and limits: Deployable AI requires more than model capability because workflows must maintain state, detect errors, preserve responsibility, and provide integration, monitoring, and human control.Uncertainty can accumulate across longer workflows, especially when outputs affect complex or liability-sensitive processes.
  • Deployment conditions and limits: Economic viability remains distinct from technical feasibility because operating, assurance, integration, legal, security, traceability, and oversight requirements can reduce or restrict benefits.AI-ER treats capabilities as economically relevant only when they are sufficiently reliable, available, viable, and permissible in context.
  • Conceptual foundation: AI-ER combines technological exposure, business model, platform economics, and organizational resilience perspectives to assess individual companies.The framework connects technical overlap with value creation, economic capture, competition, customer access, and organizational response.
  • Conceptual foundation: Technical proximity to AI capabilities indicates potential for change but does not establish automation, economic weakening, or company-level exposure.Operational conditions, business logic, market structure, and customer access determine how technical overlap affects a company.
  • Conceptual foundation: AI-ER distinguishes AI exposure as pressure on a business model from AI resilience as the capacity to absorb pressure, adapt, and use AI for value creation.The dimensions are deliberately not combined: high exposure can coexist with high resilience, and low exposure with weak adaptability.

V. DERIVATION OF THE AI-ER ASSESSMENT FRAMEWORK

The AI-ER metric set translates economic impact mechanisms into distinct, observable measures of AI exposure and resilience. It covers how AI can affect a service, its reproduction, competition, customer access, organizational adaptation, technical operation, implementation, and economic viability.

  • Exposure metrics: Exposure begins with substitutability of the paid customer benefit and replicability of the offering, which remain separate because customer displacement and technical copying need not coincide.Replicability accounts for company-specific data, integrations, domain knowledge, and regulatory requirements.
  • Exposure metrics: Competitive dynamics, the business model modulator, and customer access capture changes in provider behavior, value capture, willingness to pay, intermediation, and the provider-customer relationship.Productivity or quality gains can dampen exposure when value is retained by the company, but amplify it when benefits mainly accrue to customers, competitors, or new entrants.
  • Exposure metrics: The framework defines four numerical exposure metrics and one categorical business model modulator covering core benefit, offering replicability, competition, economic direction, and customer access.The metrics are retained when they ask distinct assessment questions and can be supported by observable evidence.
  • Resilience metrics: Economic viability compares development, operation, control, and external-dependency effort with expected value creation and customer benefit.This prevents technical feasibility from being treated as sufficient evidence of lasting economic value.
  • Resilience metrics: Resilience comprises five distinct metrics: protective positions, adaptability, technical AI maturity, implementation capability, and economic viability.Together they assess both the ability to respond and the conditions for converting technical possibilities into operational and economically lasting solutions.

D. Overview of the Metrics

AI-ER derives distinct metrics for AI exposure and AI resilience, then applies a rule-based, non-compensatory aggregation procedure that preserves critical conditions and evidence status.

  • AI-ER derives four numerical exposure metrics, one categorical business-model modulator, and five numerical resilience metrics.
  • The non-compensatory score logic keeps critical individual scores visible instead of allowing favorable values on other drivers to hide major weaknesses.
  • AI-ER supports public-information assessments that can later be refined with internal evidence, changing scores or confidence without changing the underlying model.
  • Metrics are rated against substantive scale anchors, while thresholds, combination rules, and modulators are fixed configuration parameters requiring empirical comparison.
  • Exposure uses substitutability and replicability as core drivers, with competitive dynamics and customer-access pressure entering through an additional indicator.
  • Resilience uses protective positions and adaptability under weakest-link logic, while technical maturity and implementation capability provide additional assessment dimensions.

C. Evidence, Consistency, and Confidence

The framework separates evidence quality from agreement across assessment runs and uses the weaker basis to limit confidence in metrics and dimensions.

  • Evidence quality evaluates directness, timeliness, completeness, independence, and agreement, with configurable positive weights and equal weighting as the default.
  • Independent-run agreement measures deviation from the joint median, with identical ratings producing Aij = 1 and larger deviations lowering agreement.
  • Evidence-source agreement and independent-run agreement remain distinct because they assess the evidence base and rating stability, respectively.
  • With multiple runs, confidence is limited by the weaker of evidence quality and rating agreement; with one run, it relies on evidence quality alone.
  • Dimension confidence uses only decision-relevant metrics, including selected core drivers, activated indicators, and modulator-determining metrics.
  • A high dimension score with low confidence requires further evidence, and near-threshold scores may change quadrant assignments after reassessment.

D. The Two-Dimensional AI-ER Profile

The AI-ER profile displays exposure and resilience jointly in four quadrants, preserving cases where high pressure and strong response capacity coexist.

  • The Defended Niche combines low exposure with high resilience, making the core benefit comparatively difficult to attack while retaining adaptation capacity.
  • The AI-Ready Compounder combines high exposure with high resilience, indicating strong environmental change alongside conditions for active adaptation and AI use.
  • Rebuilding Required combines low exposure with limited resilience, placing the primary action need on protective, adaptive, and implementation capability.
  • Acute Threat combines high exposure with low resilience, creating an immediate need for review and action around vulnerable services and insufficient capability.

E. Analysis Layers and Presentation of Results

AI-ER uses an outside-in assessment from public information followed by an inside-in run that adds internal evidence and can revise ratings or confidence. The resulting profile reports dimension scores, quadrant position, metric-level justifications, evidence quality, agreement, confidence, assumptions, and information gaps.

  • Outside-in analysis: Public information produces an initial rating for the nine metrics and business model modulator, while also identifying weak support and information gaps.This makes a provisional AI-ER profile available before internal data collection is complete.
  • Inside-in analysis: The subsequent inside-in run adds internal technical, organizational, process, and economic information and can change metric scores and confidence.It tests assumptions formed from public evidence using the same metrics and score logic.
  • Inside-in analysis: A nonzero Δxij revises the preliminary rating, while unchanged scores can still receive different confidence when added evidence changes Qij.With one inside-in run, L = 1 and confidence reduces to Cij = Qij.
  • Presentation of results: The profile combines two dimension scores, a quadrant position, and a complete metric profile rather than relying on one aggregate score.Exposure and resilience remain jointly interpretable because both dimensions can be high at the same time.
  • Presentation of results: Each metric remains traceable through its justification, evidence quality, rating agreement, confidence, assumptions, and recorded information gaps.Tables III and IV provide the illustrative exposure and resilience ratings for Company A.

F. Illustrative Numerical Example

A hypothetical Company A illustrates the AI-ER scoring and confidence logic using three assessment runs per metric. The example yields high exposure alongside high resilience, showing why the dimensions should remain separate.

  • Exposure calculation: Company A reaches the highest exposure level because substitutable core benefits, threshold-level competitive dynamics, and an amplifying business model effect raise its score.The core exposure drivers have values of 3, with a base value of 4 before the additional steps.
  • Resilience calculation: Resilience is limited more strongly by adaptability than by technical AI maturity, although economic viability remains above the penalty threshold.The resilience core drivers have value 3, while technical AI maturity and implementation capability reach 4.
  • Confidence calculation: With ratings 4, 4, and 5, evidence quality 0.8, and agreement ≈0.83, metric confidence equals the lower value, 0.8.Dimension confidence is then calculated from the decision-relevant metrics.
  • Overall profile: Company A combines exposure E_A = 5 with resilience R_A = 4 and falls in the AI-Ready Compounder quadrant.The example is hypothetical and has no empirical meaning.
  • Overall profile: The example shows why AI exposure and AI resilience should not be collapsed into one score.High exposure and substantial response capacity coexist in the same company profile.

VII. VALIDATION AND LIMITS

AI-ER is operational as a proposed rating logic, but it has not yet been validated empirically. Validation must test the framework’s metrics, reliability, score stability, predictive relationships, and confidence model.

  • Limits: The framework has not yet been empirically validated, so its metrics, application reliability, score stability, and relationship to later company developments remain open questions.The confidence model also requires separate examination because it is intended to distinguish well-supported ratings from provisional ones.

A. Approach to Empirical Validation

The proposed validation program combines comparative case studies, independent reliability assessments, longitudinal testing, and sensitivity analysis. It is designed to test whether AI-ER metrics are distinguishable, ratings are reliable, scores are stable, and confidence tracks later evidence.

  • Comparative case studies: Comparative case studies should span software business models, exposure-resilience combinations, company sizes, market positions, and prior AI use.Each case can be assessed first from public information and then reassessed with internal evidence.
  • Reliability and distinctness: Independent assessments should test rating reliability with statistics such as Krippendorff’s alpha or Cohen’s kappa.Large deviations would indicate unclear concepts, weak scale anchors, or excessive interpretive freedom.
  • Reliability and distinctness: Validation should examine whether metrics within each dimension remain empirically distinct and whether exposure and resilience can be separated as intended.These tests address whether the framework’s dimensions retain distinct constructs in application.
  • Longitudinal validation: Longitudinal validation should compare earlier assessments with later developments in differentiation, pricing, margins, customer access, products, processes, technical structures, or business models.This tests the proposed predictive relevance of high exposure and high resilience.
  • Sensitivity and confidence: Sensitivity analysis should vary thresholds, combination rules, weights, and modulators to determine whether dimension scores remain stable.The confidence model should also be tested against later evidence and repeated assessments, with high-confidence ratings expected to be more stable if it works as intended.

B. Limits of the Assessment Framework

AI-ER is a structured, time-bound assessment rather than a universal grade or causal explanation of company performance. Its scores depend on evidence quality, remain empirically uncalibrated, and should complement—not replace—strategic, technical, and financial analysis.

  • B. Limits of the Assessment Framework: The exposure maximum and resilience minimum rules are conceptual choices whose suitability across industries and business models remains an empirical question.The current scale anchors, thresholds, combination rules, evidence weights, and modulators have not been calibrated on a large sample.
  • B. Limits of the Assessment Framework: Public information often covers products and visible AI activities better than internal technical or organizational conditions, limiting evidence quality.The confidence model makes this asymmetry visible but cannot replace missing evidence.
  • B. Limits of the Assessment Framework: AI-ER assessments are time-bound because changes in AI capabilities, costs, competition, regulation, or internal transformation can alter both dimensions.Assessments should be updated when material conditions change, and scale anchors or evidence requirements may need industry-specific adaptation.
  • B. Limits of the Assessment Framework: A single AI-ER assessment does not establish causality, because company performance is influenced by factors beyond AI.Dimension scores should be read with individual metrics, supporting evidence, and confidence, alongside strategic, technical, and financial analysis.
  • B. Limits of the Assessment Framework: AI-ER keeps exposure and resilience separate, making visible cases where a company is highly exposed but also well prepared to respond.The framework is intended to provide a structured profile rather than a universal company grade.
  • B. Limits of the Assessment Framework: The proposal requires empirical validation through comparative cases, independent assessment runs, longitudinal observation, and sensitivity analysis.Implementation tests can support practical applicability but do not replace broader validation or refinement of anchors, thresholds, weights, and modulators.

APPENDIX A NOTATION AND MODEL PARAMETERS

The appendix defines the notation and configurable parameters used by the formal AI-ER assessment methodology. It covers dimension scores, evidence and confidence measures, resilience metrics, economic modulation, and implementation-specific configuration.

  • APPENDIX A NOTATION AND MODEL PARAMETERS: Resilience notation covers protective positions, organizational and strategic adaptability, technical AI maturity, implementation ability, and economic viability.The corresponding ratings are xprot_i, xadapt_i, xtech_i, ximpl_i, and xecon_i.
  • APPENDIX A NOTATION AND MODEL PARAMETERS: The model includes an economic-viability modulator M_econ_i for low economic viability within the resilience assessment.The parameter is defined as a modulator for company i rather than as another resilience capability rating.
  • APPENDIX A NOTATION AND MODEL PARAMETERS: The formal notation includes company-level exposure and resilience dimension scores, indicator functions, decision-relevant metric sets, and dimension confidence scores.Ei and Ri denote AI exposure and resilience scores, while CEi and CRi denote confidence in those dimension scores.
  • APPENDIX A NOTATION AND MODEL PARAMETERS: Evidence quality Qij aggregates five properties: directness, timeliness, completeness, independence, and substantive agreement.Component scores q(k)ij lie in {0, 0.5, 1}, and weighted evidence components contribute to the quality measure.
  • APPENDIX A NOTATION AND MODEL PARAMETERS: Agreement Aij represents agreement among independent ratings when at least two assessors provide ratings, while Cij denotes confidence in a combined metric score.These quantities separate rating agreement and evidence quality from the metric value itself.
  • APPENDIX A NOTATION AND MODEL PARAMETERS: Table VI lists configurable AI-ER parameters with value ranges and default configuration, and deviations should be documented for validation.The default values reflect the initial configuration used in the paper.
Loading 2609.11321v1…