arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.08564cs.CY

欧盟人工智能法案下的风险界定与量化

Qualifying and Quantifying Risk Under the EU AI Act

Gustavo Gil Gasiola, Sarah H. Cen, Frederike Zufall

首次发表
浏览论文内容

中文总结 AI 辅助

本文针对欧盟人工智能法案风险界定与量化的张力,提出两步整合框架,采用“严重程度优先”方法协调基本权利保护与风险量化,同时警示风险量化交由AI主体可能引发的风险操纵问题。

中文摘要 AI 辅助

欧盟人工智能法案(EU AI Act)采用基于风险的方法监管人工智能系统,根据系统带来的风险调整监管强度。尽管该法案对“风险”的定义(伤害发生概率与严重程度的结合)暗示了可量化性,但法案聚焦于对基本权利的风险,因此采用了典型的定性视角。本文通过一个两步框架解决这种张力,该框架下欧盟人工智能法案平衡基本权利保护、提供者与部署者的合法目的,以及监管措施对提供者、部署者和监管机构的影响。我们在潜在风险量化方法的背景下讨论该框架,特别聚焦于定义和测量风险概念的核心组成部分:“概率”“严重程度”及其“结合”。我们提出,在该框架内可协调基本权利保护与风险量化。具体而言,该法案隐含一种平衡分析,采用我们所称的“严重程度优先”方法,即先考虑伤害的严重程度,再考虑其发生概率。该整合框架不仅有助于阐明人工智能法案的基于风险的方法,还能为技术和实施选择提供信息。最后,我们讨论了若将风险量化交由人工智能提供者和部署者处理可能出现的“风险操纵”(risk hacking),他们可能会操纵该方法,导致人工智能系统的风险等级被低估,进而出现监管捷径。

英文摘要

The EU AI Act uses a risk-based approach to regulate AI systems, calibrating the intensity of regulation according to the risks they pose. While the term 'risk' implies quantification, resulting from the combination of the probability and severity of harm, the AI Act refers to risks to fundamental rights, thereby engaging a qualitative perspective. In this piece, we address this puzzle using a two-step framework under which the EU AI Act balances risks with the protection of fundamental rights, the legitimate purposes of providers and deployers, and the impacts of regulatory measures on providers, deployers, and regulators. We discuss this framework against the backdrop of potential approaches to quantifying risks, with a specific focus on defining and measuring the main components of the concept of risk: probability, severity, and their combination. We suggest that the protection of fundamental rights and risk quantification can be aligned by incorporating quantification methodologies into the proposed framework. In particular, the AI Act implies a balancing analysis that uses a severity-first approach to classify and quantify the risks posed by AI systems. The integrated framework not only helps to clarify the AI Act's risk-based approach, but can also inform technical and implementation choices. Finally, we conclude that if the risk quantification methodology or its application to the protection of fundamental rights is left to providers and deployers, there is potential for 'risk hacking', which could lead to the underclassification of AI systems and subsequent regulatory shortcuts.

补充信息

↑