Score
Designs, implements, and evaluates formal structures, policies, roles, and processes that define decision rights, accountability, oversight, and compliance for an organization, program, or system. Builds governance frameworks, controls, reporting and incentive mechanisms, and metrics to ensure transparent, coordinated decision-making and to monitor and enforce adherence to rules and standards.
This study addresses the challenges of open-source software governance, where ambiguously defined roles and permissions often lead to unclear accountability and excessive burdens on core maintainers. For the first time, it systematically analyzes governance documents such as GOVERNANCE.md in GitHub projects, applying institutional grammar to structurally dissect roles in terms of their scope, authority, obligations, and lifecycle. The research uncovers a phenomenon termed “role drift” and identifies the “maintainer paradox”: while core contributors foster community engagement, they frequently become bottlenecks in governance. Empirical findings reveal substantial variation in responsibilities among identically named roles across projects and demonstrate that a small number of individuals often concentrate technical, managerial, and community-facing functions. These insights provide critical foundations for improving role design and enhancing the sustainability of open-source communities.
Enterprise-scale general-purpose agents lack built-in, reusable governance mechanisms for autonomous cross-tool operation, making it difficult to satisfy requirements for compliance, auditability, and behavioral controllability. This work proposes the CUGA policy system, which embeds runtime governance capabilities into five critical checkpoints of the agent execution pipeline—intent protection, playbook guidance, tool invocation control, human approval gating, and output formatting—through a modular “policy-as-code” architecture. Without requiring model fine-tuning, CUGA enables proactive, continuous, and structured behavior control. By integrating typed governance primitives, dynamic playbook injection, and human-in-the-loop approval, the system effectively blocks malicious requests, enforces structured tool sequences, and triggers manual review for high-risk operations in healthcare scenarios, significantly enhancing policy adherence, execution consistency, and deployment safety.
This paper addresses the regulatory failure exacerbated by deploying autonomous AI—particularly embodied agents—in the public sector, where traditional siloed, stage-gated approval mechanisms fail to meet three emerging needs: continuous oversight, deep integration of governance into operational workflows, and cross-agency coordination. Adopting a mixed-methods approach—systematic literature review complemented by in-depth interviews with frontline public officials—the study identifies, for the first time, five core AI governance dimensions tailored to public-sector contexts: cross-agency implementation, holistic assessment, enhanced security, operational transparency, and systemic auditing. Based on these, it proposes a novel “agent-oriented regulatory framework” that is institutionally adaptive and technically interoperable. The framework bridges theory and practice, offering actionable guidance for governing autonomous AI systems under real-world institutional constraints—thereby filling a critical gap in the literature on public-sector AI regulation.
This work addresses the challenge of effectively governing side effects—such as memory accesses, external calls, and large model queries—in AI workflows without compromising their computational expressiveness. The authors propose an Effect-Transparent Governance framework that interposes a governance operator \( G \) to mediate all effectful operations, enforcing constraints at effect boundaries while preserving internal semantics. Leveraging interactive trees formalized in Rocq 8.19, the framework enables fully verified development without additional axiomatic assumptions. The implementation comprises 36 modules, approximately 12,000 lines of code, and 454 formally verified theorems, establishing seven core properties: orthogonality between governance and computational expressiveness, decidability of governance predicates, superiority of structural over content-based filtering, Turing completeness, semantic transparency, and minimal capability expression.
This study addresses the challenge of tracing causes and processes when automated decision systems fail, a task inadequately handled by existing compliance governance mechanisms. The authors propose an operational governance evidence framework that integrates structural accountability diagnostics, decision trajectory tracing, sufficiency metrics for evidentiary support, and label-free monitoring. The framework’s applicability is validated across four canonical system architectures. The research uncovers a “governance coverage gradient” phenomenon and introduces an uncertainty cascade model to identify three types of structural discontinuities in agent-based AI systems, along with methods for their analytical extension. By formalizing four propositions that delineate the framework’s boundaries, the work demonstrates full fillability in rule-based engines while simultaneously revealing inherent structural governance gaps in agent-centric AI systems.
This work addresses the misalignment between capability boundaries and governance boundaries in current AI systems, which engenders uncontrolled risks and renders formal regulatory mechanisms ineffective. To resolve this, the paper introduces a “coterminous governance” framework that mandates strict alignment between these boundaries. Leveraging Rice’s theorem, it proves that behavioral governance is undecidable under Turing-complete architectures, thereby necessitating governance to be intrinsically embedded within system design rather than imposed ex post facto. The authors realize this principle through an architecture that decouples computation from effect, integrating governance checks directly into the execution pipeline instead of relying on a separate oversight layer. Using Coq-based formal verification—encompassing 454 theorems across 36 modules—the study establishes coterminous governance as a necessary criterion for verifiable AI governance systems.
This study addresses the challenges of collaboration and quality control in open-source deep learning projects stemming from inadequate governance mechanisms. Drawing on the Institutional Analysis and Development (IAD) framework, it employs a mixed-methods empirical approach combining document content analysis and code commit tracking across PyTorch, TensorFlow, and PaddlePaddle. The analysis encompasses 109 governance documents and over 1,700 code commits, systematically uncovering the structure, temporal evolution, and functional dimensions of governance rules. The research identifies 17 rule themes and 7 rule types, revealing a distinct evolutionary pattern wherein operational rules emerge early and undergo frequent revisions, while structural rules appear later and evolve more steadily. Four core governance functions are distilled, culminating in 33 actionable recommendations for effective open-source AI project governance.
This study addresses the sequential decision-making challenge firms face under stringent regulatory regimes when balancing compliance costs against data value in cross-border data flows. The authors propose a regime-anchored decision support system that translates regulatory requirements into computable minimal compliance mappings and models weekly corporate decisions via a finite-horizon Markov decision process, treating compliance as a hard constraint rather than a penalty term. Innovatively integrating masked deep reinforcement learning with counterfactual path advantage analysis, the framework enables efficient optimization and interpretable decision-making while supporting transferability across jurisdictions. Experimental results demonstrate that the learned policies outperform baseline approaches, exhibit high interpretability and auditability, and uncover key behavioral patterns such as an “absorb–adjust” effect and dynamic shifts in localization boundaries.
Current approaches to automated program synthesis lack effective governance mechanisms to ensure the compliance of generated code. This work proposes Protocol-Driven Development (PDD), a model that treats machine-executable protocols as primary artifacts and delineates the space of valid implementations through structural, behavioral, and operational invariants. PDD mandates that every implementation be accompanied by a verifiable chain of compliance evidence. By integrating formal methods, property-based testing, policy-as-code, and software provenance techniques, PDD establishes a unified framework for protocol specification and verification. This framework enables trustworthy admission control over automatically synthesized code, guaranteeing that all adopted implementations strictly adhere to protocol constraints and are backed by complete, auditable proofs of compliance.