arXiv:2608.27102cs.AIcs.CR2026-08

为大模型应用构建可追溯的责任框架,解决错误输出致损时追责难题。

LAAF: A Layered Accountability Architecture Framework for LLM Applications

论文配图:LAAF: A Layered Accountability Architecture Framework for LLM Applications
图 1 · 摘自论文原文
  • 提出分层责任架构LAAF,覆盖来源、逻辑、人工监督与治理四层
  • 整合技术控制、人工监管等四类机制,评估成熟度并映射至欧盟AI法案
  • 揭示责任机制缺失、指标不统一等四大短板,适合政策制定者参考

大型语言模型在医院、法院、银行和公共服务中广泛应用,其流畅自信的输出常被视为权威,即使无依据或错误。当此类输出导致损害时,谁应负责?通过遵循PRISMA指南,从2022年1月至2026年3月检索五个数据库,共识别4512条记录,纳入122项原始研究及12份法规标准文件。研究将问责制定义为社会技术性关系,分解为五个维度,并整合四类机制:技术控制、人工监督、组织治理与文档可追溯性,每类均具成熟度评估。提出四层分类框架,涵盖来源、应用逻辑、人工监督与治理及补救,贯穿可追溯性、角色清晰与持续监控。该框架映射至欧盟AI法案(2026年8月2日起适用)、NIST AI RMF生成式AI指南、ISO/IEC 42001及医疗、金融、教育与公共部门的领域指引。发现四大持续缺口:人工监督定义不足、共享问责指标缺失、学科间脱节、实证评估有限;同时存在五项结构性矛盾未被任何现有工具解决。最终将分类框架整合为一体化责任架构LAAF,网络安全部分对标OWASP LLM Top 10(2025),系对已有证据的综合,非经验证成果。

原文摘要 · Abstract (English)

Large Language Models (LLMs) operate in hospitals, courtrooms, banks, and public service desks, where fluent, confident outputs are treated as authoritative even when ungrounded or incorrect. When such an output contributes to harm, who is answerable, and through what mechanisms can responsibility be traced, explained, and acted upon? Following PRISMA guidance, five databases were searched from January 2022 to March 2026 against four review questions; of 4,512 records identified, 122 primary studies were included, together with 12 regulatory and standards documents analysed as primary sources. The review consolidates a sociotechnical account of accountability as an actor-forum relation resolved into five dimensions, and synthesises mechanisms across four families: technical controls, human oversight, organisational governance, and documentation and traceability, each with a maturity assessment. The corpus is read through a four-layer classification device spanning provenance, application logic, human oversight, and governance and redress, cross-cut by traceability, role clarity, and continuous monitoring. Both are mapped onto the EU AI Act, whose high-risk obligations have applied since 2 August 2026, the NIST AI RMF with its Generative AI Profile, ISO/IEC 42001, and sectoral guidance in healthcare, consumer finance, education, and the public sector. Four persistent gaps emerge: under-specification of human oversight, absence of shared accountability metrics, disciplinary disconnection, and limited empirical evaluation, alongside five structural tensions that no surveyed instrument resolves. The review closes by consolidating the classification device into an integrated accountability architecture, LAAF, with cybersecurity aligned to the OWASP LLM Top 10 (2025); it is a synthesis of the surveyed evidence rather than a validated artefact.

大模型责任合规框架人工智能治理欧盟AI法案

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。