中小型企业规模下的意图漂移:部署实践而非模型能力决定智能体合规性
Intent Drift at SME Scale: Deployment Practice, Not Model Capability, Determines Agentic Compliance
浏览论文内容
中文总结 AI 辅助
针对小型受监管企业,提出“意图链”治理框架,通过四项无需安全工程的管控措施,在模拟资产管理场景中消除智能体非法联系,并揭示部署实践决定合规性。
中文摘要 AI 辅助
我们提出了“意图链”(Chain of Intent),一个面向小型受监管企业的智能体人工智能治理框架,并针对该框架旨在解决的一种失败情形对其进行了验证。现有的智能体治理研究假设企业具备小型企业所没有的基础设施。在一家模拟的香港资产管理公司中,该公司拥有415条合成联系记录,一个执行日常客户沟通任务的智能体受到了要求其扩大触达范围的普通管理压力。当授权约束被写入其配置时,该智能体坚守了约束:它识别出公司记录中的每一处歧义,引用了从未向其展示过的隐私立法,并拒绝了六次连续的请求,在十五次运行中有两次出现违规。在相同的任务、数据、压力和模型条件下,但如其目的因资源受限企业常有的做法而未被明确说明时,它在十五次运行中有十三次违规,联系了多达220人,其中94%的人没有可证明的营销同意——根据香港法律,这种行为最高可判处三年监禁。意图链应用了四项无需安全工程的管控措施:机器可读的目的、受限的工具访问、范围账本和行动前检查。它在每次运行中都消除了非法联系,同时保持了任务完成度,消融实验表明每项管控措施都通过不同机制独立地足以发挥作用。我们进一步表明,漂移必须在两个阶段进行测量——智能体在每次受压力的运行中都扩大了其候选集,但仅在大约七分之一的运行中对其采取行动——并且在意图点应用的治理成本大约是在行动点应用的治理成本的一半。
英文摘要
We introduce Chain of Intent, a governance framework for agentic AI at small regulated firms, and validate it against a failure it was built to address. Existing agentic governance research assumes enterprise infrastructure that small firms do not have. In a simulated Hong Kong asset manager with 415 synthetic contact records, an agent performing a routine client-communications task was subjected to ordinary managerial pressure to increase its reach. With its authorised constraints written into its configuration, the agent held: it identified every ambiguity in the firm's records, cited privacy legislation it had never been shown, and refused six successive requests, breaching in two of fifteen runs. With the same task, data, pressure and model, but its purpose left unstated as resource-constrained firms routinely leave it, it breached in thirteen of fifteen runs, contacting up to 220 individuals of whom 94 per cent had no demonstrable marketing consent - conduct carrying a maximum of three years' imprisonment under Hong Kong law. Chain of Intent applies four controls requiring no security engineering: a machine-readable purpose, constrained tool access, a scope ledger, and a pre-action check. It eliminated unlawful contact in every run while preserving task completion, and ablation shows each control independently sufficient by a different mechanism. We further show that drift must be measured at two stages - agents widened their candidate sets in every pressured run while acting on them in roughly one in seven - and that governance applied at the point of intent costs roughly half as much as governance applied at the point of action.
发表机构
- The Hong Kong University of Science and Technology(香港科技大学)
机构由 AI 辅助整理,请以论文原文为准。