arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.08806q-fin.RM

智能体AI系统与金融稳定性:从模型风险到系统性风险

Agentic AI Systems and Financial Stability, From Model Risk to Systemic Risk

  • Federal Reserve Bank of Cleveland(克利夫兰联邦储备银行)
  • Board of Governors of the Federal Reserve System(联邦储备系统理事会)

机构由 AI 辅助整理,请以论文原文为准。

Sriram Nagaraj, Seung Jung Lee

中文总结 AI 辅助

本文通过六个数学模型论证,智能体AI系统因共享基础设施而产生不可分散的系统性风险,仅靠事后审查或检测无法化解,唯有事前结构性预防才能应对。

中文摘要 AI 辅助

金融稳定建立在这样一个前提之上:困境在很大程度上是特质性的,因此是可分散的——当一个机构出错时,系统的其余部分会吸收冲击。然而,当许多决策者依赖于同一基础设施时,这一前提便不再成立。智能体AI系统(能够采取有后果的行动而不仅仅是输出预测的系统)正成为这样一种基础设施,其核心关切从单一部署的模型风险转变为整个群体的系统性风险。我们在六个数学框架中阐述这一观点。第1章将预期损失的PD/LGD/EAD分解重新表述为预期危害恒等式,并引入集值包含风险度量;在杠杆分配公理下,审查无法拦截不可逆行动,任何非预防性控制都无法满足一致性的尾部约束。第2章将此提升至共享基础模型的舰队层面:共享模型是一种不可分散的共同敞口,其预期缺口下限无论舰队规模如何增长都成立,且渗流阈值控制着传染。第3章将这些动态重新表述为带标记的霍克斯激发跳跃扩散过程,将稳健压力问题与时间一致的熵风险度量联系起来。第4章将运行时防护栏视为部分可观测的随机控制,给出可观测性三分类、检测下限,并在承诺外生性下得出运行时不可能性推论。第5章将对手视为参与者,产生与系统性影响范围成比例的投资不足楔子。第6章将能力作为军备竞赛中的状态变量。一个论断贯穿全部六章:智能体风险的系统性成分既不能分散、不能通过检测消除,也不能逆转,只有事前的结构性预防才能改变它。

英文摘要

Financial stability rests on the premise that distress is largely idiosyncratic and therefore diversifiable: when one institution errs, the rest of the system absorbs the shock. That premise fails when many decision-makers depend on the same infrastructure. Agentic AI systems, which take consequential actions rather than only emitting predictions, are becoming such a substrate, and the binding concern shifts from the model risk of a single deployment to the systemic risk of the population. We develop this account in six mathematical settings. Chapter 1 recasts the PD/LGD/EAD decomposition of expected loss as an expected-harm identity and introduces a set-valued containment-risk measure; under a lever-assignment axiom that review cannot intercept an irreversible action, no non-preventive control satisfies a coherent tail constraint. Chapter 2 lifts this to a fleet sharing a foundation model: the shared model is a non-diversifiable common exposure whose expected-shortfall floor holds however large the fleet grows, and a percolation threshold governs contagion. Chapter 3 recasts these dynamics as a marked, Hawkes-excited jump diffusion, identifying the robust stress problem with a time-consistent entropic risk measure. Chapter 4 treats runtime guardrails as partially observed stochastic control, giving an observability trichotomy, a detection floor, and, under commit exogeneity, a runtime-impossibility corollary. Chapter 5 makes the adversary a player, yielding an underinvestment wedge proportional to systemic reach. Chapter 6 makes capability a state variable in an arms race. One claim runs through all six: the systematic component of agentic risk cannot be diversified, detected away, or reversed, and only ex-ante structural prevention moves it.

↑