AI 中文总结
针对智能体AI日志证据意义隐含的问题,提出证据主张模型,区分多种证据类型并映射机制与假设,为评估智能体黑箱能力提供概念框架。
AI 中文摘要
智能体人工智能系统日益频繁地交换消息、调用工具、请求审批、举行结构化决策会议并修改共享工件。日志和锚点可以使选定的记录具有防篡改特性,但如果其证据意义是隐含的,它们也可能产生误导:哈希并不确立语义真实性,签名并不确立授权,外部锚点并不确立捕获完整性。本文提出了一种面向智能体过程的证据主张模型。该模型区分了工件完整性、时间存在性、来源、审批证据、声明排序、捕获主张、相关性主张、审议可追溯性、监控主张、锚定授权主张、策略评估主张、风险处理主张、缓解实施主张和管理响应主张。语义有效性被视为一个反复出现的局限性。该模型将这些主张映射到机制、假设、局限性和威胁,并将其置于一个具有功能性CEO智能体、执行、运营、证据和审计角色以及受计划-执行-检查-处理启发的管理响应循环的智能体组织中。其贡献是概念性的:它不验证特定实现、不防止所有故障,也不自动化法律合规。它提供了一种词汇表,用于说明智能体黑箱能够支持哪些主张、无法确立哪些主张,以及需要在其周围实施哪些控制措施。
英文摘要
Agentic AI systems increasingly exchange messages, invoke tools, request approvals, hold structured decision sessions, and modify shared artifacts. Logs and anchors can make selected records tamper-evident, but they can also mislead if their evidentiary meaning is implicit: a hash does not establish semantic truth, a signature does not establish authorization, and an external anchor does not establish capture completeness. This paper proposes an evidence claim model for agentic processes. It distinguishes artifact integrity, temporal existence, provenance, approval evidence, declared ordering, capture claim, relevance claim, deliberation traceability, monitoring claim, anchoring authorization claim, policy assessment claim, risk treatment claim, mitigation implementation claim, and management response claim. Semantic validity is treated as a recurring limitation. The model maps these claims to mechanisms, assumptions, limitations, and threats, and situates them in an agent organization with functional CEO agent, executive, operational, evidence, and audit roles, plus a plan-do-check-act-inspired management response loop. The contribution is conceptual: it does not validate a particular implementation, prevent all failures, or automate legal compliance. It provides a vocabulary for stating which claims an agentic black box can support, which claims it cannot establish, and which controls are required around it.
Comments7 pages, 1 table