为电信AI事故建立专门报告机制,填补印度监管空白
Incorporating AI incident reporting into telecommunications law and policy: Insights from India
- 提出电信AI事故分类体系,区分于传统网络安全事件
- 发现现有法律对算法偏差等事故无强制报告要求
- 建议在现有框架内设立报告义务与专职管理机构
人工智能融入电信基础设施带来算法偏见和系统行为不可预测等新风险,超出传统网络安全与数据保护框架。本文为电信领域AI事故定义并构建分类体系,将其确立为独立风险类别。以缺乏横向AI立法的印度为例,分析《2023年电信法》《CERT-In规则》及《2023年数字个人数据保护法》等核心法规,发现其聚焦网络安全与数据泄露,未覆盖算法偏差、性能下降等AI特有事故,存在显著监管缺口。研究还揭示披露障碍与现有AI事故库的局限性。据此提出针对性建议:对高风险AI失效实施强制报告,指定现有政府机构为统筹管理单位,并建立标准化报告框架。旨在提升监管清晰度与长期韧性,为其他国家在既有行业框架下治理AI风险提供可复制方案。
原文摘要 · Abstract (English)
The integration of artificial intelligence (AI) into telecommunications infrastructure introduces novel risks, such as algorithmic bias and unpredictable system behavior, that fall outside the scope of traditional cybersecurity and data protection frameworks. This paper introduces a precise definition and a detailed typology of telecommunications AI incidents, establishing them as a distinct category of risk that extends beyond conventional cybersecurity and data protection breaches. It argues for their recognition as a distinct regulatory concern. Using India as a case study for jurisdictions that lack a horizontal AI law, the paper analyzes the country's key digital regulations. The analysis reveals that India's existing legal instruments, including the Telecommunications Act, 2023, the CERT-In Rules, and the Digital Personal Data Protection Act, 2023, focus on cybersecurity and data breaches, creating a significant regulatory gap for AI-specific operational incidents, such as performance degradation and algorithmic bias. The paper also examines structural barriers to disclosure and the limitations of existing AI incident repositories. Based on these findings, the paper proposes targeted policy recommendations centered on integrating AI incident reporting into India's existing telecom governance. Key proposals include mandating reporting for high-risk AI failures, designating an existing government body as a nodal agency to manage incident data, and developing standardized reporting frameworks. These recommendations aim to enhance regulatory clarity and strengthen long-term resilience, offering a pragmatic and replicable blueprint for other nations seeking to govern AI risks within their existing sectoral frameworks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。