用CER框架重构AI导致的损失,帮保险公司判断是否理赔。
From Control Boundary to Insurance Claim: Reconstructing AI-Mediated Losses Through the CER Framework
- 提出CER框架,从控制边界、证据还原到保险响应三方面诊断AI风险
- 能还原如提示注入、工具误用等10余种AI故障的因果链和系统状态
- 为保险索赔提供可验证证据,适合保险公司与AI安全团队使用
由被保组织的生成式或自主型AI系统引发的损失,需要状态重建而非仅事件重建,因为系统在推理、检索、调用工具和执行过程中状态持续变化。关键问题不仅是发生了什么损失,更在于系统被允许做什么、实际做了什么,以及重构的损失能否支持保险索赔。本文针对AI系统处于因果链中的损失,包括提示注入、RAG污染、恶意工具输出、凭证滥用、数据投毒等外部触发故障,提出CER框架——一种面向具体使用场景的AI残余风险转移诊断工具。C(控制边界)判断系统是否有可强制执行的操作边界;E(证据重建)判断是否能从留存痕迹还原系统状态与因果链;R(保险响应)判断重构损失是否可保:市场是否存在覆盖、投保是否已落实,以及索赔所需的证明是否具备。论文贡献包括定义AI特有重建难题、通过CER实现操作化、明确索赔级证据标准。公开案例涵盖PocketOS与Replit的自主型数据库删除事件,以及Moffatt v. Air Canada这一经判决的输出依赖案。
原文摘要 · Abstract (English)
AI losses that arise through an insured organization's generative or agentic AI system require state reconstruction, not merely event reconstruction, because the relevant state changes as the system reasons, retrieves, calls tools, and acts. The relevant question is not only what loss occurred, but what the system was allowed to do, what it actually did, and whether that reconstructed loss can support insurance claim recovery. This paper addresses losses in which the insured's AI system is in the causal chain, including externally triggered failures such as prompt injection, retrieval-augmented generation (RAG) poisoning, malicious tool output, credential misuse, and data poisoning. Specifically, this paper introduces CER, a use-case-level diagnostic for AI residual risk transfer. C (control boundary) asks whether the system had an enforceable operating envelope. E (evidence reconstruction) asks whether the system state and causal chain can be reconstructed from retained artifacts. R (insurance response) asks whether the reconstructed loss is insured: whether insurance coverage is available in the market and placed for the insured, together with the proof needed to support insurance claim recovery. The paper makes three contributions: it defines the AI-specific reconstruction problem, operationalizes that problem through CER, and specifies claim-grade evidence for AI reconstruction. Public examples include the reported PocketOS and Replit agentic database-deletion incidents and Moffatt v. Air Canada as an adjudicated output/reliance case. Keywords: AI systems; CER framework; residual risk transfer; agentic AI; generative AI; AI insurance; evidence reconstruction.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。