发表机构
Lehigh University(理海大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究揭示智能体AI中监督减少导致责任倒置的悖论,通过63个工件审计发现行动可观测性远超问责机制,并提出行动路径诊断以强化问责基础设施。
AI 中文摘要
智能体AI的卖点是一个简单的承诺:当用户停止观看时,系统继续行动。这一承诺造成了责任倒置。随着逐步监督的退却,验证并未消失;它转移到了运行时基础设施中,该基础设施定义权威、记录行动、中断执行、检查结果并支持修复。我们将此称为监督减少悖论。通过一项包含63个工件的审计,我们考察了其在46篇研究论文和17个工程、文档、安全及治理来源中的公开可见性。我们发现,智能体的行动表面远比回答其行动所需的机制更容易重建。工具中介和监控痕迹在40和37个工件中清晰可见,而检查点设置在6个中清晰可见,验证器独立性在4个中清晰可见,恢复在2个中清晰可见,可争议性在1个中清晰可见。三条行动路径说明了这种不平衡为何重要。仓库路径可以在重大变更后保留丰富的差异。浏览器路径可以比权限传播更快地跨越组织边界。服务路径可以遵循政策,同时让受影响的人没有追索权。我们认为,当可观测性将验证转移到用户身上,而有意义的干预已不再可能时,可观测性可以成为问责制的替代品。我们的行动路径诊断反而询问委派的行动是否仍与权威、证据、中断、独立判断、恢复和挑战相连。这一主张刻意限定于公开可见性;它并未确立未披露控制措施的普遍性或有效性。我们贡献了一个行动层面的描述,将框架从技术包装重新塑造为问责基础设施。
英文摘要
Agentic AI is sold on a simple promise: the system keeps acting when the user stops watching. That promise creates an accountability inversion. As stepwise supervision recedes, verification does not disappear; it moves into the runtime infrastructure that defines authority, records action, interrupts execution, checks outcomes, and supports repair. We call this the reduced-supervision paradox. Using a 63-artifact audit, we examine its public visibility across 46 research papers and 17 engineering, documentation, security, and governance sources. We find that agents' action surfaces are far easier to reconstruct than the mechanisms needed to answer for their actions. Tool mediation and monitoring traces were clearly visible in 40 and 37 artifacts, whereas checkpoint placement was clearly visible in 6, validator independence in 4, recovery in 2, and contestability in 1. Three action paths show why this imbalance matters. A repository path can preserve rich diffs after a consequential change. A browser path can cross organizational boundaries faster than permissions travel. A service path can follow policy while leaving affected people without recourse. We argue that observability can become a substitute for accountability when it shifts verification onto users after meaningful intervention is no longer possible. Our action-path diagnostic instead asks whether a delegated action remains connected to authority, evidence, interruption, independent judgment, recovery, and challenge. The claim is deliberately bounded to public visibility; it does not establish the prevalence or effectiveness of undisclosed controls. We contribute an action-level account that recasts the harness from a technical wrapper into accountability infrastructure.
Comments24 pages, 4 tables. Expanded preprint with a structured public-artifact audit and three worked action paths