发表机构
Aurite AI(奥莱特人工智能公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对企业自主AI智能体管控的适配问题,提出发现、身份等五大运行时管控原语,描述其实现方案、成本及部分原语的开发状态。
AI 中文摘要
企业部署的自主AI智能体继承了为人类用户和长期服务构建的控制模型,该模型在三个方面适配失败:智能体主体是短暂的,其出现和消失速度快于配置速度;它们的动作由模型而非编程选择,因此其可能尝试的动作集合无法预先知晓;智能体群体是被发现而非配置的,因为任何能调用API的人都可以创建一个智能体。我们认为,管控此类智能体是一个运行时问题——既不是模型对齐问题,也不是构建时问题——我们从动作生效前和生效后必须回答的问题中推导出五大原语:发现、身份、管控、证明和供应链。对于每个原语,我们说明了其缺失时会出现什么问题,以及为何其他原语无法在结构上提供该原语的功能。我们描述了一个实现方案:智能体的动作在生效前会根据策略进行调解,针对每个租户的动作词汇表进行授权,并记录在一个哈希链接的分类账中,第三方可在不涉及供应商的情况下进行验证。我们报告了该架构的成本:执行点位于请求的关键路径上,身份需要每个工作负载一个边车,故障关闭式调解会将可用性事件转为拒绝。我们明确说明实现状态:四个原语已构建并在私人试点中运行,第五个原语已作为独立工具构建,尚未集成到请求路径中。我们将其保留在集合中:一个与作者实际构建内容完全匹配的五部分分解不是分类法,而是代码库的描述。
英文摘要
Enterprise deployments of autonomous AI agents inherit a control model built for human users and long-lived services, and the fit fails in three specific ways: agent principals are ephemeral, appearing and vanishing faster than provisioning; their actions are selected by a model rather than programmed, so the set of things they may attempt is not known in advance; and the population is discovered rather than provisioned, because anyone who can call an API can create one. We argue that governing such agents is a runtime problem -- not a model-alignment problem and not a build-time problem -- and we derive five primitives from the questions that must be answered before an action takes effect and after it has: discovery, identity, governance, attestation, and supply chain. For each we state what fails if it is absent and why the others cannot structurally supply it. We describe an implementation in which an agent's action is mediated against policy before it takes effect, authorised against a per-tenant action vocabulary, and recorded in a hash-linked signed ledger a third party can verify with the vendor out of the loop. We report what the architecture costs: the enforcement point sits on the request's critical path, identity requires a sidecar per workload, and fail-closed mediation converts availability incidents into denial. We are explicit about implementation status: four primitives are built and running in private pilots, and the fifth is built as separate tooling and not yet integrated into the request path. We keep it in the set deliberately: a five-part decomposition that exactly matches what its authors happened to build is not a taxonomy but a description of a codebase.
Comments14 pages, 2 figures, 1 table. Describes an implemented system in private pilot deployment; four of five primitives implemented