Score
Designs and documents liability assignments and supervision rules for validated data assets, specifying who is legally and operationally accountable, what supervisory actions are required under which conditions, and what remedies apply when validation failures or misuse occur. Produces governance artifacts—such as accountability matrices, escalation and audit procedures, evidence and reporting requirements, and criteria for automated versus human oversight—to enforce, monitor, and update those policies.
This paper identifies a core dilemma in organizational responsible AI governance: ambiguous responsibility boundaries across AI lifecycle stages and a lack of role- and stage-appropriate operational tools. Methodologically, the study systematically reviews over 220 responsible AI tools and proposes a novel two-dimensional (Actor, Stage) classification framework, integrating systematic review, meta-analysis, and qualitative coding. It identifies three critical governance gaps: (1) unclear accountability attribution, (2) absence of empirical validation for most tools, and (3) severe coverage imbalance across actors and stages. Results show that >80% of tools target developers during data and modeling phases; tools for leadership, deployers, end users, and stages such as value proposition definition and deployment are virtually absent. Moreover, >90% of tools lack empirical evidence. The study establishes a theoretically grounded, empirically benchmarked framework to advance actor–stage–aligned AI governance tool ecosystems.
Current global AI training data governance—across the EU, U.S., and Asia-Pacific—relies predominantly on reactive enforcement, lacking proactive copyright filtering during pretraining, thereby undermining creator rights and threatening AI’s long-term sustainability. Addressing two core challenges—difficult license acquisition and unverifiable filter efficacy—the paper proposes a multi-tiered *pre-ingestion* filtering framework integrating access control, perceptual hashing, ML-based classifiers, and real-time cross-referencing against dynamic copyright databases to identify and block high-risk content prior to training. Unlike existing approaches relying solely on transparency tools or post-hoc detection, this framework shifts copyright protection to the earliest data intake stage, ensuring scalability and auditability. Empirical analysis demonstrates its capacity to systematically close regulatory gaps, offering a practical, globally applicable governance paradigm that balances AI innovation with creator rights protection.
This study addresses the pervasive lack of structural integrity in current AI governance documents, which often fail to meet critical requirements such as traceability, dynamic re-verification, and objective evidence. To bridge this gap, the work systematically adapts structural governance principles from aviation software certification standards (DO-178C/DO-330) and proposes a novel integrity framework tailored for static AI governance artifacts. The framework introduces three key concepts—“epoch constraints,” “proof surfaces,” and “structural gaps”—and establishes the seven-principle PromptQ system. Structural analysis of mainstream governance documents reveals that 37% fall below a basic quality threshold, thereby demonstrating the framework’s effectiveness and practicality in enhancing the rigor and verifiability of AI governance documentation.
Current AI systems rely heavily on manual auditing and documentation, which hinders scalable governance for automated services. This work proposes Ontological Knowledge Blocks (OKBs), a novel framework that formalizes regulatory obligations as quintuples comprising ontologies, SHACL rules, evidence requirements, and provenance links. By leveraging RDF/OWL modeling, PROV-O for provenance tracking, and an intermediate representation–driven deterministic compiler, the approach enables dynamic switching of governance configurations without modifying service code. Evaluation in an AI-assisted HPC scheduling scenario demonstrates that compliance checks are configuration-sensitive, violations accumulate strictly additively, SHACL validation incurs only 12.6–100.3 milliseconds of latency, and the Combined configuration provides the most comprehensive coverage.
This work addresses the fragmentation of governance evidence in automated decision systems caused by heterogeneous log formats by proposing the Decision Event Schema (DES)—a unified tracing specification based on JSON Schema. DES uniquely integrates four infrastructure layers: machine learning inference, rule evaluation, cross-system coupling, and governance metadata. It introduces degradation-resistant field design and a three-tier evidence strategy—lightweight, sampled, and complete—to accommodate varying risk profiles and throughput requirements. Among over 25 existing logging formats, DES is the only one that comprehensively covers all four layers. Empirical validation demonstrates its compatibility with high-throughput production environments, offering practitioners a readily adoptable or extensible reference standard and enabling regulators to map compliance requirements to minimal evidence levels.
Ensuring compliance of AI systems in the legal domain with the EU’s Artificial Intelligence Act (AI Act) poses significant verification challenges due to the gap between legal requirements and technical implementation. Method: This paper proposes the first verifiable governance framework integrating legal norms and technical controls. It introduces a regulation–technical-control mapping model, designs a forensically aware logging architecture and observability mechanism tailored for RAG/LLM systems, and establishes a multidimensional evaluation metric system weighted by legal risk. We publicly release the open-source auditing tool *rag-forense* and a standardized experimental protocol. Contribution/Results: The framework enables end-to-end compliance audit trails, automated verification, and evidence generation. Empirical evaluation demonstrates its effectiveness in identifying high-risk non-compliance scenarios and producing auditable, traceable compliance proofs—advancing RegTech for legal AI through a reusable methodology and engineering infrastructure.
Ensuring dynamic regulatory compliance in cross-organizational, multi-domain data processing—particularly in healthcare—is challenging due to heterogeneous legal constraints, contractual obligations, and evolving individual consents, requiring simultaneous privacy preservation, accountability distribution, and policy adaptability. Method: We propose a decentralized policy fragmentation framework enabling autonomous agents to generate, propagate, and dynamically compose local policy fragments to justify data operations—without requiring a global policy view. We introduce the first logic-programming–based justifiable action model, integrated with a distributed gossip protocol and externally synchronized configuration. Contribution/Results: The framework achieves reproducible authorization, auditable accountability, and verifiable governance under weak centralization. Evaluated in the Brane healthcare system, it demonstrates robust compliance assurance, seamless cross-domain interoperability, and audit traceability with full reproducibility.
In institutional settings, agent workflows may lose credibility even when producing correct outputs if they rely on faulty authorities, lack evidence of completion, or fail to respond to changes. This work proposes a “governed execution” framework that innovatively introduces a Matrix causal state layer, integrating for the first time authority dependency tracking, factual provenance, and selective invalidation mechanisms within agent workflows. By leveraging deterministic causal modeling, dependency tracing, completion verification, and precise invalidation of affected tasks, the approach ensures auditability and independent verifiability. Experiments demonstrate that governed workflows maintain result consistency while persistently preserving governance evidence, rejecting unjustified closed-loop reasoning, and constraining recovery scope; however, strict integrity constraints can lead to excessive blocking in role-separation transfer tasks.