AI 中文总结
本文整合ISO/IEC 42001、NIST AI RMF和欧盟AI法案,构建统一AI治理分类体系,提出实施模型与示例,助力组织同时满足三者要求且无需重复付出。
AI 中文摘要
人工智能治理正围绕三个结构异质的工具整合:ISO/IEC 42001:2023是首个可认证的人工智能管理系统(AIMS)标准;美国国家标准与技术研究院(NIST)AI风险管理框架(AI RMF 1.0)是自愿性的社会技术风险模型;欧盟人工智能法案(Regulation (EU) 2024/1689)是具有约束力的风险分级法律。尽管这些工具的共同目标是实现可信赖的人工智能,但它们在法律地位、治理主体和风险概念上存在根本差异,因此实践中常见的控制层对照表既不完整,部分内容还具有误导性。本文通过对官方标准与框架的文件分析及比较治理文献研究,将这三个工具整合为统一AI治理分类体系(UAGT),该体系由五个分析层构成——规范目的、治理主体、风险逻辑、控制架构、证据与保证,以可追溯性核心为纽带,通过八个稳定监管的治理领域体现。该分类体系特意保持时效性,纳入了欧盟AI法案2026年5月的数字 omnibus修正案及2024年NIST生成AI配置文件。四步实施模型和两个已完成的高风险示例——基于AI的临床决策支持系统、AI信用评分系统——展示了组织如何运行单一控制库和证据库,以支持ISO/IEC 42001认证、NIST AI RMF采用及欧盟AI法案合规,且无需重复付出努力。本文明确指出了整合失效之处:法律合规与自愿认证的不可替代性、列表式与情境式风险本体论的不匹配、执法不对称,以及这三个工具与通用人工智能和智能体人工智能之间日益扩大的差距。
英文摘要
Artificial intelligence governance is consolidating around three structurally heterogeneous instruments: ISO/IEC 42001:2023, the first certifiable Artificial Intelligence Management System (AIMS) standard; the United States NIST AI Risk Management Framework (AI RMF 1.0), a voluntary, socio-technical risk model; and the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689), a binding, risk-tiered law. Although these instruments share the goal of trustworthy AI, they differ fundamentally in legal status, governance subject, and conception of risk, so that the control-level crosswalks now common in practice are both incomplete and, in places, misleading. Drawing on document analysis of the official standards and frameworks and on comparative governance literature, this article reconciles the three instruments into a Unified AI Governance Taxonomy (UAGT) organized as five analytical layers -- normative purpose, governance subject, risk logic, control architecture, and evidence and assurance -- bound by a traceability spine and expressed through eight regulation-stable governance domains. The taxonomy is deliberately current, incorporating the May 2026 Digital Omnibus amendments to the AI Act and the 2024 NIST Generative AI Profile. A four-step implementation model and two worked high-risk examples -- an AI-enabled clinical decision-support system and an AI credit-scoring system -- show how organizations can operate a single control library and evidence base that supports ISO/IEC 42001 certification, NIST AI RMF adoption, and EU AI Act compliance without duplicative effort. We are explicit about where unification breaks down: the non-fungibility of legal conformity and voluntary certification, the mismatch between list-based and contextual risk ontologies, enforcement asymmetry, and the widening gap between all three instruments and general-purpose and agentic AI.
Comments17 pages, 5 tables