arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.12352cs.CYcs.AIcs.HC

为何AI治理框架难以被采用:对NIST AI RMF的基于角色的压力测试

Why AI Governance Frameworks Are Hard to Adopt: A Role-Based Stress Test of the NIST AI RMF

Joseph R. Simons, David A. Broniatowski

首次发表
浏览论文内容

中文总结 AI 辅助

本文通过对NIST AI RMF的基于角色的压力测试,发现AI治理框架的核心问题在于活动能否产生治理价值,角色、部署类型对治理价值有显著影响,仅当治理价值与结构适配性同时满足时才易实现风险降低。

中文摘要 AI 辅助

AI治理框架可能在形式上被知晓、使用和实施,却无法在实践中成为治理。本文通过对消费者贷款场景下NIST人工智能风险管理框架(AI RMF)的基于角色的压力测试来研究这一问题。我们将框架采用视为一种治理转化问题:即RMF语言能否转化为对在用AI系统的、可被角色使用、跨层级、与权威关联的治理,而非仅产生看似治理的制品。该研究采用基于大语言模型(LLM)的角色模拟作为结构化分析探针,应用4×2×3的设计,涵盖4种组织角色、2种AI部署、3种治理难题,生成120份评分响应。结果显示,局部转化并非主要问题:模拟角色通常理解自身分配的角色,并将RMF转化为局部活动;更难的问题在于该活动能否产生治理价值。角色与跨层级治理价值、权威关联、治理可转化性及治理价值强相关;部署与结构适配性强相关:RMF与有界的ML核保模型的适配性,比与嵌入工作流的LLM核保助手的适配性更清晰。风险降低则更为困难,仅在治理价值存在且结构适配性完全时出现,且两个条件单独均不充分。本文对基于框架的AI治理提供了诊断性说明:框架的价值在于帮助组织观察、解读、升级、授权和纠正在用AI系统中的风险,也在于揭示现有证据路径、权威结构和系统边界下的可治理性局限。

英文摘要

AI governance frameworks can be known, used, and implemented in form without becoming governance in practice. This paper examines that problem through a role-based stress test of the NIST Artificial Intelligence Risk Management Framework (AI RMF) in consumer lending. We treat framework adoption as a governance translation problem: whether RMF language can become role-usable, cross-level, authority-connected governance over the AI system-in-use, rather than producing governance-looking artifacts. The study uses LLM-based role simulation as a structured analytic probe. We apply a 4 $\times$ 2 $\times$ 3 design across four organizational roles, two AI deployments, and three governance hard cases, producing 120 scored responses. Results show that local translation was not the main problem. Simulated actors generally understood their assigned roles and translated the RMF into local activity. The harder problem was whether that activity became governance value. Actor role was strongly associated with Cross-Level Governance Value, Authority Connection, Governance Translatability, and governance value. Deployment was strongly associated with Structural Fit: the RMF fit a bounded ML underwriting model more cleanly than a workflow-embedded LLM underwriting copilot. Risk reduction was harder still. It appeared only when governance value was present and Structural Fit was full, but neither condition was sufficient by itself. The paper contributes a diagnostic account of framework-based AI governance. Frameworks create value when they help organizations see, interpret, escalate, authorize, and correct risk in the AI system-in-use. They also create value when they reveal limits of governability under existing evidence paths, authority structures, and system boundaries.

发表机构

  • The George Washington University(乔治·华盛顿大学)

机构由 AI 辅助整理,请以论文原文为准。

↑