Skip to main content
QUICK REVIEW

[论文解读] The risks of risk-based AI regulation: taking liability seriously

Martin Kretschmer, Tobias Kretschmer|arXiv (Cornell University)|Nov 3, 2023
Ethics and Social Impacts of AI被引用 4
一句话总结

本文批判欧盟基于风险的《人工智能法案》过度依赖事前监管指令(如数据质量与人工监督),主张应采用以责任为核心的监管模式,仅在造成损害后追究开发者与部署者的责任。通过区分风险的内生性(系统性)与外生性(外部)来源,并据此分配责任,作者提出,责任追究机制将比指令性监管更有效地激励合规、透明度与系统再训练。

ABSTRACT

The development and regulation of multi-purpose, large "foundation models" of AI seems to have reached a critical stage, with major investments and new applications announced every other day. Some experts are calling for a moratorium on the training of AI systems more powerful than GPT-4. Legislators globally compete to set the blueprint for a new regulatory regime. This paper analyses the most advanced legal proposal, the European Union's AI Act currently in the stage of final "trilogue" negotiations between the EU institutions. This legislation will likely have extra-territorial implications, sometimes called "the Brussels effect". It also constitutes a radical departure from conventional information and communications technology policy by regulating AI ex-ante through a risk-based approach that seeks to prevent certain harmful outcomes based on product safety principles. We offer a review and critique, specifically discussing the AI Act's problematic obligations regarding data quality and human oversight. Our proposal is to take liability seriously as the key regulatory mechanism. This signals to industry that if a breach of law occurs, firms are required to know in particular what their inputs were and how to retrain the system to remedy the breach. Moreover, we suggest differentiating between endogenous and exogenous sources of potential harm, which can be mitigated by carefully allocating liability between developers and deployers of AI technology.

研究动机与目标

  • 挑战欧盟基于风险的AI监管模式,特别是《人工智能法案》对数据质量与人工监督的事前要求。
  • 主张责任机制——而非预先设定的规则——应成为AI系统的核心监管机制。
  • 区分AI损害的内生(系统性)与外生(外部)来源,以实现更精准的监管责任分配。
  • 提出责任追究机制将更有效地激励开发者了解输入数据并在此类事件发生后对系统进行再训练。
  • 倡导从指令性监管转向通过民事责任实现的结果导向型问责机制。

提出的方法

  • 分析欧盟《人工智能法案》基于风险的监管框架及其对数据质量与人工监督的要求。
  • 比较欧盟的事前监管模式与数字技术领域传统的事后责任模式。
  • 提出一种以责任为基础的监管模式,即企业仅在发生违规后才被追究责任。
  • 引入AI损害的内生(与开发相关)与外生(与部署或环境相关)来源之间的区分。
  • 建议根据风险来源分配责任,以确保适当的激励与问责机制。
  • 借鉴现有法律框架,如产品责任与通知-删除程序,以支持所提出的责任机制。
Figure 1: The EU’s risk-based approach to AI regulation
Figure 1: The EU’s risk-based approach to AI regulation

实验结果

研究问题

  • RQ1欧盟《人工智能法案》基于风险的事前监管模式与数字技术领域传统的事后责任模式相比如何?
  • RQ2《人工智能法案》中强制要求数据质量与人工监督,对AI系统可能产生哪些非预期后果?
  • RQ3为何责任机制比指令性规则在AI开发与部署方面更具监管有效性?
  • RQ4如何根据损害源于内生(系统性)还是外生(外部)来源,对责任进行差异化分配?
  • RQ5责任机制在确保开发者能够识别并在此类事件后对系统进行再训练方面应发挥何种作用?

主要发现

  • 欧盟《人工智能法案》基于风险的监管方式,特别是对数据质量与人工监督的强制要求,可能造成过重的合规负担,却未必能有效降低实际风险。
  • 通过产品安全原则对AI进行事前监管,偏离了长期存在的数字政策规范,后者依赖事后责任机制,而该机制历史上一直支持创新。
  • 若结构合理,责任机制能为开发者提供比指令性规则更强的激励,以追踪输入数据并在事件发生后对系统进行再训练。
  • 区分内生与外生损害来源,有助于在开发者与部署者之间实现更精确的责任分配。
  • 现行《人工智能法案》框架可能因优先考虑监管控制而非问责机制,而损害创新与透明度。
  • 以责任为基础的监管模式将更符合现有法律原则,并在不给开发者施加过重事前合规义务的前提下,提升系统层面的问责性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。