AI监管忽视内部部署,导致高风险系统逃避监督。
Internal Deployment Gaps in AI Regulation
- 分析美欧2025年前沿AI法规对内部部署的覆盖盲区
- 发现三类漏洞:范围模糊、静态审查、信息不对称
- 适合政策制定者与企业合规团队参考
前沿AI监管主要针对向外部用户部署的系统,因其可见性高且易受外部监督。然而,企业在内部部署高度能力的AI系统(如自动化研发、加速关键业务流程、处理敏感专有数据)时同样存在高风险。本文考察2025年美国与欧盟的前沿AI法规如何应对内部部署问题,识别出三类可能导致内部系统规避监管的漏洞:(1)范围定义模糊,使内部系统可规避监管义务;(2)仅进行时点合规评估,无法捕捉内部系统持续演进;(3)信息不对称,削弱监管机构的知情与监督能力。进一步分析这些漏洞存在的原因,涉及可衡量性、激励机制与信息获取之间的张力。最后,梳理潜在解决方案及其权衡。通过理解这些模式,期望政策制定能更主动、而非被动地应对内部部署的监管挑战。
原文摘要 · Abstract (English)
Frontier AI regulations primarily focus on systems deployed to external users, where deployment is more visible and subject to outside scrutiny. However, high-stakes applications can occur internally when companies deploy highly capable systems within their own organizations, such as for automating R&D, accelerating critical business processes, and handling sensitive proprietary data. This paper examines how frontier AI regulations in the United States and European Union in 2025 handle internal deployment. We identify three gaps that could cause internally-deployed systems to evade intended oversight: (1) scope ambiguity that allows internal systems to evade regulatory obligations, (2) point-in-time compliance assessments that fail to capture the continuous evolution of internal systems, and (3) information asymmetries that subvert regulatory awareness and oversight. We then analyze why these gaps persist, examining tensions around measurability, incentives, and information access. Finally, we map potential approaches to address them and their associated tradeoffs. By understanding these patterns, we hope that policy choices around internally deployed AI systems can be made deliberately rather than incidentally.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。