为医疗智能代理建立全生命周期管理框架,解决多系统重复部署与权限失控问题。
Agentic AI Governance and Lifecycle Management in Healthcare
- 构建五层控制架构,涵盖身份注册到权限撤销的完整流程
- 实现医疗数据边界管控与运行时紧急停止机制,保障安全合规
- 提供分阶段实施模型,适合医院CIO/CISO及临床管理者落地使用
医疗机构正将智能代理集成至日常流程,如临床文档支持和早期预警监测。随着能力在各部门和供应商间扩散,出现代理泛滥问题:重复部署、责任不清、控制不一、权限长期留存。现有AI治理框架侧重生命周期风险管理,但缺乏对代理集群日常运营的指导。本文提出统一代理生命周期管理(UALM)蓝图,基于治理标准、代理安全文献与医疗合规要求快速整合而成。UALM将常见缺口映射至五层控制平面:(1) 身份与角色注册,(2) 协调与跨域中介,(3) 受限于患者隐私信息(PHI)的上下文与记忆,(4) 运行时策略执行与关机触发器,(5) 生命周期管理与凭证撤销、审计日志联动的退役机制。配套成熟度模型支持分阶段采纳。UALM为医疗系统首席信息官、首席安全官及临床负责人提供可操作的审计就绪监督模式,既保留本地创新,又支持在临床与行政领域安全扩展。
原文摘要 · Abstract (English)
Healthcare organizations are beginning to embed agentic AI into routine workflows, including clinical documentation support and early-warning monitoring. As these capabilities diffuse across departments and vendors, health systems face agent sprawl, causing duplicated agents, unclear accountability, inconsistent controls, and tool permissions that persist beyond the original use case. Existing AI governance frameworks emphasize lifecycle risk management but provide limited guidance for the day-to-day operations of agent fleets. We propose a Unified Agent Lifecycle Management (UALM) blueprint derived from a rapid, practice-oriented synthesis of governance standards, agent security literature, and healthcare compliance requirements. UALM maps recurring gaps onto five control-plane layers: (1) an identity and persona registry, (2) orchestration and cross-domain mediation, (3) PHI-bounded context and memory, (4) runtime policy enforcement with kill-switch triggers, and (5) lifecycle management and decommissioning linked to credential revocation and audit logging. A companion maturity model supports staged adoption. UALM offers healthcare CIOs, CISOs, and clinical leaders an implementable pattern for audit-ready oversight that preserves local innovation and enables safer scaling across clinical and administrative domains.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。