Automated Lemons: AI, Compliance Regulation and Adverse Selection in the Market for Penetration Testing
Companies that buy a penetration test cannot easily judge its quality, even after the work is delivered. This creates adverse selection: when thorough and superficial tests look alike, buyers choose on price and careful providers are undercut. This paper asks to what extent AI-driven automation worsens that problem, and whether compliance regulation in the UAE and Saudi Arabia can offset it. It applies the economics of asymmetric information and credence goods to the market for security testing, then classifies UAE and Saudi compliance frameworks by the quality signals they require, from rules that only mandate a test to rules that demand accredited providers and independent review. Classifying four rules, the paper finds that each country has one weak and one strong rule, and that the rules with the broadest reach carry the weakest signals. It concludes that regulation offsets the effect of automation in only part of the market, and offers recommendations for regulators and buyers.
Authors
- Arjun Sajiv
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-09
- DOI
- https://doi.org/10.5281/zenodo.23270160
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00