越强的AI越难部署,因为权限太大反而更危险。
The Security Cost of Intelligence: AI Capability, Cyber Risk, and Deployment Paradox

- 在治理能力不足时,越强的AI需更大权限,风险更高。
- 高损失环境下,更强的AI反而导致企业减少部署。
- 提升治理能力可缓解风险,让好AI真正用起来。
企业正在部署更强大的AI系统,但组织控制措施往往未能同步跟进。这些系统虽能带来更高生产效率,但高价值应用需要更大的权限暴露——包括数据访问、流程集成和授权委托——而治理控制尚未实现能力与权限的解耦。我们构建了一个分析模型,研究企业在治理-能力差距下如何权衡AI部署与网络安全投资。核心发现为‘部署悖论’:在高损失环境中,能力更强的AI可能促使企业减少部署,因能力依赖更广泛的权限暴露且治理薄弱。最优部署低于无风险基准,且该差距随损失规模及高能力系统所附权限增加而扩大。治理投入降低漏洞损失可缩小悖论区域;而漏洞外部性则扩大了社会受限的部署范围。因此,治理成熟度不仅是对AI采用的约束,更是决定能力提升能否转化为有效部署的关键条件。
原文摘要 · Abstract (English)
Firms are deploying more capable AI systems, but organizational controls often have not kept pace. These systems can generate greater productivity gains, but high-value uses require broader authority exposure -- data access, workflow integration, and delegated authority -- when governance controls have not yet decoupled capability from authority exposure. We develop an analytical model in which a firm jointly chooses AI deployment and cybersecurity investment under this governance-capability gap. The central result shows a deployment paradox: in high-loss environments, better AI can lead a firm to deploy less when capability is deployed through broader authority exposure under weak governance. Optimal deployment also falls below the no-risk benchmark, and this shortfall widens with breach-loss magnitude and with the authority exposure attached to more capable systems. Governance investment that reduces breach-loss magnitude shrinks the paradox region itself, while breach externalities expand the range of environments in which deployment is socially constrained. Governance maturity is therefore not merely a constraint on AI adoption. It is a condition that shapes whether capability improvements translate into productive deployment.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。