Empirically validate the AI-ER aggregation rules across industries and business models
Determine empirically whether the maximum rule for AI exposure and the minimum rule for AI resilience are suitable across different industries and software-based business models.
References
The current scale anchors, thresholds, combination rules, evidence weights, and modulators have not been calibrated on a large sample. The maximum rule for exposure and the minimum rule for resilience are conceptual choices. They assume that one pronounced attack path can determine exposure and that one weak core condition can limit resilience. Their suitability across industries and business models remains an empirical question.
The proposed rating logic makes AI-ER operational, but the framework has not yet been validated empirically.
Conformal validity is verified marginally and by rolling origins, but not conditionally on regime: a band can be narrow and correct on average while failing in the regime that matters. Every threshold above is calibrated against the generator and none against a commercial category. And promotional incrementality is outside the system's scope: promotion is treated as a confounder to be removed, never as a lever to be optimized.