arXiv:2607.14309cs.AIcs.CY2026-07

Traccia用OpenTelemetry构建AI治理平台,解决智能体失控与合规难题。

Traccia: An OpenTelemetry-Based Governance Platform for AI Systems

论文配图:Traccia: An OpenTelemetry-Based Governance Platform for AI Systems
图 1 · 摘自论文原文
  • 基于OpenTelemetry构建多层级AI治理架构,整合可观测性与安全管控
  • 通过哈希追踪链自动生成符合欧盟AI法案的合规证据包
  • 适合关注AI合规、自主系统监管的企业与技术团队

大型语言模型和人工智能驱动的自主代理快速发展,重塑了软件治理形态。尽管欧盟《人工智能法案》等国际框架要求高度透明与可问责,但当前实践仍存在巨大差距。现有LLM评估、机器学习工作流与应用性能监控平台存在割裂问题,难以防范对无界状态空间智能体架构的严重威胁,如对齐漂移、SaaS安全风险及影子AI系统的未授权部署。本文提出Traccia——一个基于OpenTelemetry的统一治理平台,通过引入遥测数据、被动语义护栏评估与执行溯源,构建哈希追踪账本,实现对齐治理的“最后一公里”。Traccia自动附加防篡改指纹与SHA-256内容哈希,生成映射至欧盟AI法案第12、14、19、26(6)和50条的合规证据包,不侵犯数据隐私。该方法为企业的自主AI系统管理提供了可机器读取的坚实基础。

原文摘要 · Abstract (English)

The rapid development of Large Language Models (LLMs) and Artificial Intelligent (AI) powered autonomous agents has fundamentally changed the existing forms of software governance. In spite of the rigorous standards of transparency and account ability required according to the international frameworks such as the European Union's AI Act, there is a considerable gap between theory and reality. The present study discusses the inherent drawbacks of currently utilized platforms for LLM evaluation, machine learning workflow, and application performance monitoring in general. It has been shown that current disjointed solutions fail to protect unbound state space agentic architecture from serious threats such as alignment drift, SaaS security concerns, and unauthorized deployment of shadow AI systems. Moreover, a solution is proposed for overcoming the discussed challenges in form of a coherent multi-level AI governance stack Traccia built on the top of OpenTelemetry infrastructure platform. Traccia resolves the last mile for AI Alignment by adding the telemetry data, passive semantic guardrail assessment, and execution lineage into a hashed trace ledger. Traccia automatically creates compliance evidence packages by appending tamper-resistant fingerprints and SHA-256 content hash, that map to regulatory requirements (Articles 12, 14, 19, 26(6), and 50 of the EU AI Act) without invading any data privacy. By performing this evaluation in a methodical manner, a solid machine-readable base has been created for enterprise-wide management of autonomous AI systems.

AI治理合规审计OpenTelemetry自主智能体

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。