从法律文本到AI特定风险源:欧盟AI法案高风险要求的系统分析
From Legal Text to AI-specific Risk Sources: A Systematic Analysis of the EU AI Act's High-Risk Requirements
浏览论文内容
中文总结 AI 辅助
本文系统分析欧盟AI法案高风险要求,发现多数为组织流程义务,少数直接针对AI风险源,并据此推导出风险源清单,以桥接法律义务与AI风险管理实践。
中文摘要 AI 辅助
欧盟AI法案对高风险AI系统引入了强制性要求,其明确目标是确保可信AI的开发与运行。与此同时,AI风险管理实践依赖于结构化的风险分类法,以系统地识别和处理AI特定风险源。由于AI法案和既有的风险分类法都旨在应对AI引发的风险,一个自然的问题是它们在所涵盖的风险源上是否一致。然而,在法案高风险要求所隐含处理的风险与既有分类法之间,不存在清晰的映射,这使得从业者缺乏结构化的基础来将监管义务与AI风险管理实践对齐。本文对从欧盟AI法案第2节(高风险AI系统的要求)中提取的要求进行了系统分类,揭示出只有少数要求直接针对AI特定风险源,而大多数要求则施加了组织流程和文档义务。从与AI风险相关的要求中,推导出了一份整合的、不同的AI特定风险源清单。由此产生的欧盟AI法案风险源清单在弥合法律义务与AI风险管理实践之间的差距方面迈出了重要一步,为现有AI风险分类法与欧盟AI法案隐含处理的风险源之间的明确比较提供了结构化参考。重要说明:这是作者的预印本。该论文已在第四届人工智能、伦理与多学科应用前沿国际会议上发表。会议官方论文集的链接将在出版后提供。
英文摘要
The EU AI Act introduces mandatory requirements for high-risk AI systems with the explicit goal of ensuring the development and operation of trustworthy AI. At the same time, AI risk management practices rely on structured risk taxonomies to systematically identify and treat AI-specific risk sources. As both the AI Act and established risk taxonomies aim to address AI-induced risks, a natural question is whether they align in the risk sources they cover. However, no clear mapping exists between the risks implicitly addressed by the Act's high-risk requirements and established taxonomies, leaving practitioners without a structured basis for aligning regulatory obligations with AI risk management practice. This paper presents a systematic classification of the requirements extracted from the EU AI Act Section 2 (Requirements for high-risk AI systems), revealing that only a minority directly address AI-specific risk sources, while the majority impose organizational process and documentation obligations. From the AI risk-related requirements, a consolidated list of distinct AI-specific risk sources is derived. The resulting EU AI Act Risk Source List takes an important step towards bridging the gap between legal obligation and AI risk management practice, providing a structured reference for explicit comparison between existing AI risk taxonomies and the risk sources implicitly addressed by the EU AI Act. Important Note: This is the authors' preprint. The paper was presented at the 4th International Conference on Frontiers of Artificial Intelligence, Ethics, and Multidisciplinary Applications. A link to the conference's official proceedings will be provided upon publication.
发表机构
- Technical University of Munich(慕尼黑工业大学)
- Siemens AG(西门子股份公司)
机构由 AI 辅助整理,请以论文原文为准。