arXiv:2607.13040cs.CYcs.AI2026-07

AI治理权该归谁?论文主张行动责任方应拥有最终决策权。

Final Authority in AI Governance: Frontier-Provider Sovereignty and Action-Centered Deployer Governance

  • 区分模型提供方与部署方的治理角色,强调行动责任归属。
  • 多国政策分析显示,分布式问责比单一控制更可行。
  • 适合关注AI落地合规与企业治理的管理者阅读。

本文探讨当强大AI系统嵌入组织流程后,最终决策权应归属何方。比较了两种治理模式:一是前沿模型提供方主权,即由最先进模型的提供者掌控权限,体现于前沿模型测试、发布管控、透明度义务和算力控制;二是以行动为中心的部署方主权,将高影响行动的最终决策权赋予执行机构,其需承担法律、运营和商业后果。通过对比欧盟《人工智能法案》指南、NIST AI风险管理框架、新加坡代理型AI治理框架、日本近期AI政策及加拿大自愿性代码与管理指引,发现支持分布式操作问责的证据更强。论文进一步指出,企业快速采纳、提供方透明度下降及控制缺口扩大,使以可移植治理层为核心、聚焦具体行动而非提供方原生会话对象的机制价值更高。结论并非绝对,而是分层的:前沿能力的上游管控仍合理,但具体企业行动的最终决定权应交由部署方与后果承担者。

原文摘要 · Abstract (English)

This paper examines where final authority should sit once capable AI systems are embedded in organizational workflows. It compares two governance models. The first, frontier-provider sovereignty, assigns privileged authority to the provider of the most capable models and is reflected in contemporary arguments for frontier-model testing, release gating, transparency duties, and compute-related controls. The second, action-centered deployer sovereignty, places final authority over high-impact actions with the organization that authorizes the action, embeds it in a business process, and bears the downstream legal, operational, and commercial consequences. The paper combines comparative reading of public governance frameworks with implementation-informed analysis of runtime heterogeneity and enterprise control requirements. It compares EU AI Act guidance, the NIST AI Risk Management Framework, Singapore's Model AI Governance Framework for Agentic AI, recent Japanese AI policy instruments, and Canada's voluntary code and managerial guidance. Across these materials, the paper finds stronger support for distributed operational accountability than for unilateral frontier-provider control. It further argues that rapid enterprise adoption, declining provider transparency, and widening control gaps increase the value of a portable governance layer centered on governed action rather than on provider-native session objects. The conclusion is layered rather than absolutist: strong upstream authority remains justified for frontier capability gating, but final authority over concrete enterprise action is better located with the deployer and consequence-bearer.

AI治理责任归属企业合规政策分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。