arXiv:2604.04749cs.AI2026-04被引 3

构建持续可观测的AI治理框架,实现企业级零信任合规。

AI Trust OS -- A Continuous Governance Framework for Autonomous AI Observability and Zero-Trust Compliance in Enterprise Environments

  • 通过可观测信号自动发现未登记AI系统
  • 用实时遥测数据替代人工证明,提升合规可信度
  • 适合需要满足欧盟AI法案等严苛监管的企业

大型语言模型、检索增强生成流程及多智能体工作流的快速普及引发结构性治理危机。组织无法治理看不见的系统,现有合规方法针对确定性网络应用,缺乏对无正式监管下跨工程团队涌现的AI系统的发现与持续验证机制。导致监管要求的治理成熟度证明与组织实际能力间存在信任鸿沟。本文提出AI Trust OS,一种连续、自主的AI可观测性与零信任合规治理架构。该框架将合规重构为始终在线、以遥测驱动的运行层:通过可观测信号发现AI系统,自动化探针收集控制断言,持续合成信任凭证。基于四大原则:主动发现、遥测证据优于人工认证、持续态势优于点时审计、架构支撑证明优于政策文档信任。系统在零信任遥测边界内运行,临时只读探针在不接入源码或敏感数据的前提下验证结构元数据。AI可观测性提取代理扫描LangSmith与Datadog LLM遥测,自动注册未登记系统,推动治理从自报转向机器实证。经ISO 42001、EU AI Act、SOC 2、GDPR、HIPAA评估,论证遥测优先的治理代表了企业信任生成与展示的根本性架构跃迁。

原文摘要 · Abstract (English)

The accelerating adoption of large language models, retrieval-augmented generation pipelines, and multi-agent AI workflows has created a structural governance crisis. Organizations cannot govern what they cannot see, and existing compliance methodologies built for deterministic web applications provide no mechanism for discovering or continuously validating AI systems that emerge across engineering teams without formal oversight. The result is a widening trust gap between what regulators demand as proof of AI governance maturity and what organizations can demonstrate. This paper proposes AI Trust OS, a governance architecture for continuous, autonomous AI observability and zero-trust compliance. AI Trust OS reconceptualizes compliance as an always-on, telemetry-driven operating layer in which AI systems are discovered through observability signals, control assertions are collected by automated probes, and trust artifacts are synthesized continuously. The framework rests on four principles: proactive discovery, telemetry evidence over manual attestation, continuous posture over point-in-time audit, and architecture-backed proof over policy-document trust. The framework operates through a zero-trust telemetry boundary in which ephemeral read-only probes validate structural metadata without ingressing source code or payload-level PII. An AI Observability Extractor Agent scans LangSmith and Datadog LLM telemetry, automatically registering undocumented AI systems and shifting governance from organizational self-report to empirical machine observation. Evaluated across ISO 42001, the EU AI Act, SOC 2, GDPR, and HIPAA, the paper argues that telemetry-first AI governance represents a categorical architectural shift in how enterprise trust is produced and demonstrated.

AI治理零信任可观测性合规

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。