arXiv:2608.12352cs.CYcs.AI2026-08

测试了美国AI治理框架在信贷场景中的落地难题,发现角色差异比理解障碍更关键。

Why AI Governance Frameworks Are Hard to Adopt: A Role-Based Stress Test of the NIST AI RMF

  • 用大模型模拟四种角色,测试框架在实际工作中的可操作性
  • 框架价值取决于角色权限与系统结构的匹配程度,非仅靠理解就能实现
  • 揭示了现有治理框架在真实场景中难以生效的根本原因

AI治理框架虽可形式化应用,却常未能真正转化为实践中的治理。本文通过角色导向的压力测试,评估美国国家标准与技术研究院(NIST)人工智能风险管理框架(AI RMF)在消费信贷场景的应用。研究将框架采纳视为治理转化问题:RMF语言能否成为跨层级、有权威关联的系统运行治理,而非仅生成表面合规文件。采用基于大模型的角色模拟,设计4×2×3实验,覆盖四个组织角色、两种AI部署方式和三类治理难点,生成120份评分响应。结果显示,本地化理解并非主要障碍,模拟参与者普遍能正确理解自身角色并转化为具体行动;真正困难在于这些行动是否产生治理价值。角色类型显著影响跨层级治理价值、权威连接性、治理可转化性及整体治理效能。部署方式也显著影响结构契合度:对边界明确的机器学习授信模型,框架契合度更高;而嵌入业务流程的LLM协作者则匹配困难。风险降低仅在治理价值充分且结构契合完整时出现,但任一条件均不单独足够。论文提出一种诊断性框架治理观:框架创造价值在于帮助组织识别、解读、上报、授权与纠正系统中的风险;同时也在于揭示现有证据路径、权威结构与系统边界下的治理局限。

原文摘要 · Abstract (English)

AI governance frameworks can be known, used, and implemented in form without becoming governance in practice. This paper examines that problem through a role-based stress test of the NIST Artificial Intelligence Risk Management Framework (AI RMF) in consumer lending. We treat framework adoption as a governance translation problem: whether RMF language can become role-usable, cross-level, authority-connected governance over the AI system-in-use, rather than producing governance-looking artifacts. The study uses LLM-based role simulation as a structured analytic probe. We apply a 4 $\times$ 2 $\times$ 3 design across four organizational roles, two AI deployments, and three governance hard cases, producing 120 scored responses. Results show that local translation was not the main problem. Simulated actors generally understood their assigned roles and translated the RMF into local activity. The harder problem was whether that activity became governance value. Actor role was strongly associated with Cross-Level Governance Value, Authority Connection, Governance Translatability, and governance value. Deployment was strongly associated with Structural Fit: the RMF fit a bounded ML underwriting model more cleanly than a workflow-embedded LLM underwriting copilot. Risk reduction was harder still. It appeared only when governance value was present and Structural Fit was full, but neither condition was sufficient by itself. The paper contributes a diagnostic account of framework-based AI governance. Frameworks create value when they help organizations see, interpret, escalate, authorize, and correct risk in the AI system-in-use. They also create value when they reveal limits of governability under existing evidence paths, authority structures, and system boundaries.

AI治理风险框架角色模拟信贷应用

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。