在敏捷软件开发中实施欧盟AI法案:一种基于指南的方法
Operationalizing the EU AI Act in Agile Software Development: A Guideline-Based Approach
浏览论文内容
中文总结 AI 辅助
该研究针对敏捷团队无法适配欧盟AI法案合规要求的痛点,基于设计科学研究开发出含12项内容的合规指南,经验证可帮助敏捷团队在保留敏捷实践的同时满足欧盟AI法案合规需求。
中文摘要 AI 辅助
背景:欧盟AI法案要求人工智能(AI)系统的提供者和部署者实施文档、风险管理和人工监督。在短迭代中交付AI功能的敏捷团队缺乏履行这些职责的特定工件,因为该法规的抽象条款无法映射到“完成的定义”、Sprint评审或工作协议中。目标:我们为敏捷团队提供一种可操作的合规工具:一份经评估的指南,该指南将欧盟AI法案义务转化为可集成到现有敏捷实践中的活动。我们还记录了其背后的转化方法,以便该方法可用于相邻法规。方法:遵循设计科学研究,我们从三个维度评估了欧盟AI法案的每一条款。随后,我们用交通信号灯方案对条款进行分类,并将被认为高度相关的条款映射到之前记录的敏捷团队使用AI时的痛点。我们通过一项调查和11次额外的半结构化专家访谈,让从业者验证最终的目录,并通过定性内容分析对结果进行分析。结果:该指南包含12个条目,涵盖角色与职责、风险与质量管理、透明度与可追溯性、监控以及监管沙盒。从业者对该目录的可理解性和相关性评价良好;可行性因组织成熟度而异。要有效采用以实现欧盟AI法案合规,需要跨角色的集体所有权,并集成到现有敏捷事件中,而非并行的合规流程。结论:该目录为敏捷团队提供了一个起点,使其能够在不拆解敏捷实践的情况下,将其交付实践转变为符合欧盟AI法案要求的实践。
英文摘要
Context: The EU AI Act requires providers and deployers of Artificial Intelligence (AI) systems to implement documentation, risk management, and human oversight. Agile teams that ship AI features in short iterations lack specific artifacts to discharge these duties, since the regulation's abstract provisions do not map onto the Definition of Done, Sprint Reviews, or working agreements. Objective: We provide agile teams with an actionable compliance instrument: an evaluated guideline that operationalizes EU AI Act obligations as activities integrable into existing agile practice. We further document the translation method behind it so that the approach can be reused for adjacent regulations. Method: Following Design Science Research, we assessed each EU AI Act article along three dimensions. We subsequently classified the articles using a traffic-light scheme and mapped those deemed highly relevant to previously documented pain points of agile teams working with AI. We validated the resulting catalog with practitioners through a survey and 11 additional semi-structured expert interviews, analyzed via qualitative content analysis. Results: The guideline comprises 12 items covering roles and responsibilities, risk and quality management, transparency and traceability, monitoring, and regulatory sandboxes. Practitioners rated the catalog as understandable and relevant; feasibility varied with organizational maturity. Effective adoption towards EU AI Act compliance requires collective ownership across roles and integration into existing agile events rather than parallel compliance processes. Conclusions: The catalog gives agile teams a starting point to transform their delivery practices towards an EU AI Act compliance without dismantling agile practices.