为企事业级智能体提供可控制、可审计、可治理的评估框架
CAGE-1: Control, Assurance, and Governance Evaluation for Enterprise Agentic AI
- 构建CAGE-1评估框架,覆盖授权、策略执行、工具安全等11个关键维度
- 提出预绑定保障机制,验证动作在生效前是否被有效控制
- 适合企业AI负责人、安全部门及合规团队评估智能体部署风险
企业人工智能正从实验阶段进入实际业务流程。早期项目聚焦模型访问与检索增强生成,而今企业开始部署能规划、检索、记忆、调用工具、更新系统并跨应用协作的智能体。这改变了评估需求:领导者不再只关心答案是否准确流畅,更需确认动作授权方、适用政策、证据时效性、记忆有效性、工具调用权限、决策可回溯性及能否在造成业务影响前中止。本文提出CAGE-1:企业智能体控制、保障与治理评估框架。该框架评估权威性、策略执行、检索质量、记忆完整性、工具安全、可审计性、人工监督、冲突处理、安全失败、预绑定保障、运营就绪度和业务适应性。引入预绑定保障,用于评估智能行动在成为不可逆操作前是否已被控制。测试动作在形成保护性后果前是否被允许、暂停、限制、拒绝、升级、隔离或失效。
原文摘要 · Abstract (English)
Enterprise artificial intelligence is moving from experimentation into operational workflows. Early programs focused on model access and retrieval-augmented generation, but enterprises are now beginning to deploy agents that plan, retrieve, remember, call tools, update systems, and coordinate work across applications. This changes the evaluation problem. Leaders are no longer asking only whether an answer is accurate or fluent. They need to know who authorized an action, which policy applied, whether evidence was current, whether memory was valid, whether a tool call was permitted, whether the decision can be replayed, and whether the agent can be stopped before it creates business impact. This paper introduces CAGE-1: Control, Assurance, and Governance Evaluation for Enterprise Agentic AI. CAGE-1 is an evaluation framework for deciding whether enterprise agents are ready for deployment. It evaluates authority, policy enforcement, retrieval quality, memory integrity, tool safety, auditability, human oversight, conflict handling, safe failure, Prebind Assurance, operational readiness, and business fitness. CAGE-1 introduces Prebind Assurance to describe the evaluated ability to prove that an agentic action is controlled before it becomes binding, effective, or operationally consequential. The framework tests whether a proposed action is admitted, held, narrowed, refused, escalated, quarantined, or made non-effective before protected consequence forms.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。