为欧盟高风险AI系统提供可审计的身份判定方法
High-Risk AI Systems and the Problem of Identity in the European AI Act
- 用功能+框架定义AI系统身份,结合预期功能与可信度标准
- 指出AIA缺乏同步身份判断标准,依赖外部行业规范
- 提出可审计的决策流程,适用于采购、监管等场景
欧盟人工智能法案(AIA)对高风险AI系统实行全生命周期治理,包括事前合规评估、上市后监控及重大修改后的重新评估。这些义务隐含对AI系统身份的判断:监管机构与开发者需确定更新后的系统是否仍为同一系统。本文借助‘功能+’(function+)的实体身份理论,主张以系统的预期功能及其上下文敏感的适当运行标准(即‘AI可信度’)来界定身份。我们进一步指出,AIA未提供可内部审计的同步身份判定标准——即在某一时刻两个AI系统是否应被视为同一系统——而是将此类判断主要交由特定领域或协调性文件处理。功能+提供了一个基于预期功能和可信度水平的同步身份测试,使身份判断在采购、责任追究和市场监督等治理场景中可审查。我们的贡献在于构建了AIA生命周期义务与功能+身份要素之间的对应关系图,并通过最小化决策流程,使同步身份判断在审计与争议情境中具备操作性。最后提出两项实施建议:(1) 更精确、可测试的预期用途报告;(2) 标准化、可审计的可信度报告,以支持跨时间与跨部署的可比性。
原文摘要 · Abstract (English)
The EU Artificial Intelligence Act (AIA) establishes a lifecycle governance regime for high-risk AI systems built around ex-ante conformity assessment, post-market monitoring, and re-assessment upon "substantial modification." These obligations presuppose AI identity judgments: regulators and providers must decide when an updated system remains the same system over time. In this work, we show how this logic is clarified by the function+ framework of artifact identity, which individuates AI systems by their intended function together with context-sensitive criteria of appropriate functioning, captured as "AI trustworthiness." We further argue that the AIA does not provide an internal, auditable criterion for synchronic identity--when two AI systems at a given time should count as the same for regulatory purposes--and instead largely defers such sameness determinations to sectoral or harmonization instruments. function+ supplies a synchronic identity test anchored in intended function and trustworthiness profiles and levels, making synchronic identity decisions inspectable in governance settings such as procurement, liability, and market surveillance. Our contribution is a conceptual and auditing lens: we provide a correspondence map between AIA lifecycle obligations and function+ identity components, and we make the synchronic case operationally legible via a minimal decision flow for audit and dispute contexts. We conclude with two implementation-facing recommendations: (1) more precise, testable reporting of intended purpose, and (2) standardized, auditable trustworthiness reporting that supports comparability over time and across deployments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。