Score
Designs and implements governance frameworks, processes, roles, policies, metrics, and toolchains that control and oversee the software development lifecycle; this includes mapping SDLC stages, diagnosing process gaps, managing governance operations, and establishing governance bodies and workflows. Builds or configures supporting tooling and dashboards, conducts SDLC analyses and diagnostics to measure compliance and process health, and iterates governance artifacts to mitigate risk and improve delivery quality.
This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.
Enterprise-scale general-purpose agents lack built-in, reusable governance mechanisms for autonomous cross-tool operation, making it difficult to satisfy requirements for compliance, auditability, and behavioral controllability. This work proposes the CUGA policy system, which embeds runtime governance capabilities into five critical checkpoints of the agent execution pipeline—intent protection, playbook guidance, tool invocation control, human approval gating, and output formatting—through a modular “policy-as-code” architecture. Without requiring model fine-tuning, CUGA enables proactive, continuous, and structured behavior control. By integrating typed governance primitives, dynamic playbook injection, and human-in-the-loop approval, the system effectively blocks malicious requests, enforces structured tool sequences, and triggers manual review for high-risk operations in healthcare scenarios, significantly enhancing policy adherence, execution consistency, and deployment safety.
This study addresses the challenges of open-source software governance, where ambiguously defined roles and permissions often lead to unclear accountability and excessive burdens on core maintainers. For the first time, it systematically analyzes governance documents such as GOVERNANCE.md in GitHub projects, applying institutional grammar to structurally dissect roles in terms of their scope, authority, obligations, and lifecycle. The research uncovers a phenomenon termed “role drift” and identifies the “maintainer paradox”: while core contributors foster community engagement, they frequently become bottlenecks in governance. Empirical findings reveal substantial variation in responsibilities among identically named roles across projects and demonstrate that a small number of individuals often concentrate technical, managerial, and community-facing functions. These insights provide critical foundations for improving role design and enhancing the sustainability of open-source communities.
In multi-stakeholder platforms, software architecture decisions often implicitly entrench conflicting requirements without systematic support for mapping governance principles to technical design. This work proposes the first governance-architecture alignment framework, explicitly linking five core governance principles to the space of architectural decisions, thereby rendering implicit governance stances identifiable and contestable. The framework also exposes how default technical choices can obscure underlying value commitments. Feasibility is preliminarily demonstrated through a constructive case study of a pig-farming knowledge platform in Rwanda. Future work will employ pre- and post-intervention user judgment studies to evaluate the framework’s impact on actual governance outcomes.
This study addresses the challenges of collaboration and quality control in open-source deep learning projects stemming from inadequate governance mechanisms. Drawing on the Institutional Analysis and Development (IAD) framework, it employs a mixed-methods empirical approach combining document content analysis and code commit tracking across PyTorch, TensorFlow, and PaddlePaddle. The analysis encompasses 109 governance documents and over 1,700 code commits, systematically uncovering the structure, temporal evolution, and functional dimensions of governance rules. The research identifies 17 rule themes and 7 rule types, revealing a distinct evolutionary pattern wherein operational rules emerge early and undergo frequent revisions, while structural rules appear later and evolve more steadily. Four core governance functions are distilled, culminating in 33 actionable recommendations for effective open-source AI project governance.
This work addresses the security and compliance risks arising when large language model (LLM) agents directly trigger state-changing actions within workflows. To mitigate these risks, the authors propose decoupling action generation from execution and introduce, for the first time, an Organizational Control Layer (OCL) architecture—a model-agnostic, non-intrusive governance infrastructure that enforces policy checks, enables action interception, and supports human escalation prior to execution. The approach requires no modification to the underlying LLM and is compatible with diverse backend systems. Evaluated on an adversarial negotiation task, the method reduces unsafe execution rates from 88% to near zero while increasing effective success rates from 12% to 96%, demonstrating the efficacy and practicality of the proposed governance mechanism.