arXiv:2512.22211cs.AI2025-12中稿 · IASEAI 2026被引 4

为自主智能系统设计风险与能力治理框架,助力安全创新。

With Great Capabilities Come Great Responsibilities: Introducing the Agentic Risk & Capability Framework for Governing Agentic AI Systems

  • 以能力为中心分析自主AI系统,识别风险源头。
  • 提炼出组件、设计、能力三类核心风险来源。
  • 提供可落地的技术控制方案,适合企业合规团队使用。

自主智能系统因具备代码执行、网络交互和文件修改等自主行动能力,带来巨大机遇的同时也引发新型风险,对组织治理构成严峻挑战。为此,我们提出面向自主智能系统的风险与能力(ARC)框架,旨在帮助组织全面识别、评估并缓解相关风险。该框架的核心贡献包括:(1) 建立以能力为导向的分析视角,覆盖多种自主智能系统;(2) 提炼出组件、设计与能力三类内在风险源;(3) 明确各风险源与具体风险表现及对应技术控制之间的关联;(4) 提供结构化且实用的实施路径。该框架为组织应对自主智能系统的复杂性提供了稳健且可扩展的方法,支持快速创新的同时保障系统安全、可信与负责任地部署。框架已开源,详见 https://govtech-responsibleai.github.io/agentic-risk-capability-framework/。

原文摘要 · Abstract (English)

Agentic AI systems present both significant opportunities and novel risks due to their capacity for autonomous action, encompassing tasks such as code execution, internet interaction, and file modification. This poses considerable challenges for effective organizational governance, particularly in comprehensively identifying, assessing, and mitigating diverse and evolving risks. To tackle this, we introduce the Agentic Risk \& Capability (ARC) Framework, a technical governance framework designed to help organizations identify, assess, and mitigate risks arising from agentic AI systems. The framework's core contributions are: (1) it develops a novel capability-centric perspective to analyze a wide range of agentic AI systems; (2) it distills three primary sources of risk intrinsic to agentic AI systems - components, design, and capabilities; (3) it establishes a clear nexus between each risk source, specific materialized risks, and corresponding technical controls; and (4) it provides a structured and practical approach to help organizations implement the framework. This framework provides a robust and adaptable methodology for organizations to navigate the complexities of agentic AI, enabling rapid and effective innovation while ensuring the safe, secure, and responsible deployment of agentic AI systems. Our framework is open-sourced \href{https://govtech-responsibleai.github.io/agentic-risk-capability-framework/}{here}.

自主AI风险治理框架设计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。