为自主AI系统设计统一治理框架,解决企业级AI的管控难题
A Unified Policy Architecture (UPA): The Governance Kernel for Enterprise AI Operating Systems

- 构建统一策略模型,整合权限、合规、审计等多维度治理
- 支持运行时义务与人工审批,实现全生命周期管控
- 适合需构建可信自治AI系统的大型企业或技术团队
企业AI正演变为可自主规划、推理、调用工具、执行工作流并协同作业的智能操作系统。这一转变带来新的治理挑战:现有授权、安全、防护及合规机制分散且无法统一管理自主AI系统。本文提出统一策略架构(UPA),作为企业AI操作系统的核心治理机制。UPA提供统一策略模型,覆盖AI、代理、工具、工作流、记忆、企业资源、代理间交互及业务规则。其扩展了策略控制范围,涵盖运行时义务、人工审批、合规性、审计证据与治理评估。文中阐述了UPA的治理模型、声明式策略语言基础、策略评估语义、可扩展插件、行业策略包及企业治理评估框架,并提出多代理协调、溯源感知策略与状态化运行时治理等延伸方向。UPA为构建安全、可问责、可治理的企业级自主AI系统提供了坚实基础。
原文摘要 · Abstract (English)
Enterprise AI is evolving into an Enterprise Operating System where autonomous AI agents can plan, reason, use memory, invoke tools, execute workflows, and collaborate with other agents. This shift creates a new governance challenge: existing authorization, security, guardrails, and compliance mechanisms are fragmented and are not designed to govern autonomous AI as a unified system. This paper introduces the Unified Policy Architecture (UPA), a governance architecture for Enterprise AI Operating Systems. UPA provides a unified policy model for governing AI and agents, tools, workflows, memory, enterprise resources, and agent-to-agent interactions and enterprise business rules. It extends policy control beyond authorisation to include runtime obligations, human approvals, compliance, audit evidence, and governance evaluation. We present UPA's governance model, declarative policy language foundations, policy evaluation semantics, extensible plugins, industry policy packs, and an evaluation framework for enterprise governance. We also identify extensions for multi-agent coordination, provenance-aware policies, and stateful runtime governance. UPA provides a foundation for building secure, accountable, and governable Enterprise Operating Systems for autonomous AI.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。