arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

欧盟人工智能法案合规检查器的实证研究与评估

An Empirical Study and Assessment of EU AI Act Compliance Checkers

Zhen Tao, Alize Kahraman, Shidong Pan, Zhenchang Xing, Chiara Ullstein, Jens Grossklags, Chunyang Chen

arXiv 2609.36228首次发表:更新:

发表机构

Technical University of Munich; New York University(慕尼黑工业大学; 纽约大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究首次实证评估12个主流欧盟AI法案合规检查器,发现其质量参差、仅适合作早期定位工具,并提出更可靠合规支持工具的设计原则。

AI 中文摘要

欧盟人工智能法案为开发、部署或集成人工智能系统的组织引入了广泛的合规要求。其中许多要求与安全和隐私直接相关,同时也涉及数据治理、透明度、准确性和鲁棒性等密切相关的问题。然而,中小型企业和个人开发者等利益相关者往往缺乏解读这些义务并将其转化为工程和治理实践所需的法律专业知识。这种脱节给实施欧盟人工智能法案带来了挑战,并可能导致安全保障缺失或开发和部署工作方向错误。为了解决这一问题,各种自动化欧盟人工智能法案合规检查器(AIACCs)应运而生,声称能够简化合规评估并提供实用指导。在本文中,我们首次对AIACCs进行了实证研究和评估。我们从多个维度刻画了12个主流AIACCs的特征,评估了它们的法律覆盖范围和一致性,并分析了检查器生成的合规报告在结构、确定性和可操作性方面的表现。我们发现,AIACCs的质量差异显著,目前它们只能作为早期阶段的定位工具。具体而言,我们观察到交互模式和用户友好性不一致,存在过度简化或遗漏关键义务的倾向,以及未能提供确定且可操作的指导。因此,依赖当前一代AIACCs可能会助长虚假的合规感。通过我们的研究,我们为当前AIACC格局提供了一个关键的基线。我们进一步为实施更可靠的合规支持工具提供了设计原则。

英文摘要

The EU AI Act introduces extensive compliance requirements for organizations that develop, deploy, or integrate AI systems. Many of these requirements are directly relevant to security and privacy, while also addressing closely related issues such as data governance, transparency, accuracy, and robustness. However, stakeholders such as small-to-medium businesses and individual developers often lack the legal expertise required to interpret these obligations and translate them into engineering and governance practices. This disconnect creates challenges for implementing the EU AI Act and may lead to missing safeguards or misdirected development and deployment efforts. To address this, various automated EU AI Act compliance checkers (AIACCs) have emerged, claiming to streamline compliance assessments and provide practical guidance. In this paper, we present the first empirical study and assessment of AIACCs. We characterize 12 mainstream AIACCs across multiple dimensions, evaluate their legal coverage and alignment, and analyze checker-generated compliance reports for structure, determinacy, and actionability. We find that the quality of AIACCs varies significantly and that they currently can only serve as early-stage orientation tools. Specifically, we observe inconsistent interaction modes and user-friendliness, a tendency to overly simplify or omit key obligations, and a failure to provide determinate, actionable guidance. As a result, reliance on the current generation of AIACCs may foster a false sense of compliance. With our study, we provide a critical baseline of the current AIACC landscape. We further offer design principles for the implementation of more reliable compliance-support tools.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑