arXiv:2510.24383cs.AIcs.CY2025-10被引 5

用可机器读取的规则卡实现自主AI Agent的实时合规管控

Policy Cards: Machine-Readable Runtime Governance for Autonomous AI Agents

  • 通过政策卡在运行时动态约束AI代理行为
  • 支持自动验证、版本控制及与监管框架对接
  • 适合需规模化可控的自治系统开发者

Policy Cards作为一种可机器读取的部署层标准,用于表达自主AI代理的操作、监管和伦理约束。政策卡随代理部署,使其在运行时能遵循既定规则,明确告知代理必须或禁止的行为。它扩展了模型卡、数据卡和系统卡等透明性工具,定义了编码允许/禁止规则、义务、证据要求及与NIST AI RMF、ISO/IEC 42001、欧盟人工智能法案等保障框架的映射关系。每张政策卡可自动验证、版本化,并链接至运行时执行或持续审计流程。该框架为自治代理提供可验证合规性,构建多智能体生态中分布式保证的基础。政策卡将高层治理与工程实践结合,实现大规模可问责自主。

原文摘要 · Abstract (English)

Policy Cards are introduced as a machine-readable, deployment-layer standard for expressing operational, regulatory, and ethical constraints for AI agents. The Policy Card sits with the agent and enables it to follow required constraints at runtime. It tells the agent what it must and must not do. As such, it becomes an integral part of the deployed agent. Policy Cards extend existing transparency artifacts such as Model, Data, and System Cards by defining a normative layer that encodes allow/deny rules, obligations, evidentiary requirements, and crosswalk mappings to assurance frameworks including NIST AI RMF, ISO/IEC 42001, and the EU AI Act. Each Policy Card can be validated automatically, version-controlled, and linked to runtime enforcement or continuous-audit pipelines. The framework enables verifiable compliance for autonomous agents, forming a foundation for distributed assurance in multi-agent ecosystems. Policy Cards provide a practical mechanism for integrating high-level governance with hands-on engineering practice and enabling accountable autonomy at scale.

AI治理运行时约束可验证合规

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。