Automated Lemons: AI, Compliance Regulation and Adverse Selection in the Market for Penetration Testing

Companies that buy a penetration test cannot easily judge its quality, even after the work is delivered. This creates adverse selection: when thorough and superficial tests look alike, buyers choose on price and careful providers are undercut. This paper asks to what extent AI-driven automation worsens that problem, and whether compliance regulation in the UAE and Saudi Arabia can offset it. It applies the economics of asymmetric information and credence goods to the market for security testing, then classifies UAE and Saudi compliance frameworks by the quality signals they require, from rules that only mandate a test to rules that demand accredited providers and independent review. Classifying four rules, the paper finds that each country has one weak and one strong rule, and that the rules with the broadest reach carry the weakest signals. It concludes that regulation offsets the effect of automation in only part of the market, and offers recommendations for regulators and buyers.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-09
DOI
https://doi.org/10.5281/zenodo.23270160
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Automated Lemons: AI, Compliance Regulation and Adverse Selection in the Market for Penetration Testing

Arjun Sajiv
Zenodo (CERN European Organization for Nuclear Research)
Information and Cyber Security
article

Automated Lemons: AI, Compliance Regulation and Adverse Selection in the Market for Penetration Testing

Arjun Sajiv
article en

Abstract

Companies that buy a penetration test cannot easily judge its quality, even after the work is delivered. This creates adverse selection: when thorough and superficial tests look alike, buyers choose on price and careful providers are undercut. This paper asks to what extent AI-driven automation worsens that problem, and whether compliance regulation in the UAE and Saudi Arabia can offset it. It applies the economics of asymmetric information and credence goods to the market for security testing, then classifies UAE and Saudi compliance frameworks by the quality signals they require, from rules that only mandate a test to rules that demand accredited providers and independent review. Classifying four rules, the paper finds that each country has one weak and one strong rule, and that the rules with the broadest reach carry the weakest signals. It concludes that regulation offsets the effect of automation in only part of the market, and offers recommendations for regulators and buyers.

Zenodo (CERN European Organization for Nuclear Research)
Openalex Percentile: Top 6%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Automated Lemons: AI, Compliance Regulation and Adverse Selection in the Market for Penetration Testing — Arjun Sajiv · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS