Score
Designs, drafts, and implements formal policies and governance frameworks that specify rules, objectives, scope, roles, responsibilities, compliance requirements, and processes for decision‑making and operational behavior. Builds and applies analyses, impact assessments, monitoring metrics, enforcement and compliance mechanisms, and evaluations of trade‑offs, incentives, legal/regulatory alignment, and equity to assess, monitor, and refine those policies.
Enterprise-scale general-purpose agents lack built-in, reusable governance mechanisms for autonomous cross-tool operation, making it difficult to satisfy requirements for compliance, auditability, and behavioral controllability. This work proposes the CUGA policy system, which embeds runtime governance capabilities into five critical checkpoints of the agent execution pipeline—intent protection, playbook guidance, tool invocation control, human approval gating, and output formatting—through a modular “policy-as-code” architecture. Without requiring model fine-tuning, CUGA enables proactive, continuous, and structured behavior control. By integrating typed governance primitives, dynamic playbook injection, and human-in-the-loop approval, the system effectively blocks malicious requests, enforces structured tool sequences, and triggers manual review for high-risk operations in healthcare scenarios, significantly enhancing policy adherence, execution consistency, and deployment safety.
Current evaluations of AI governance proposals often fall into binary oppositions, overlooking implicit value trade-offs and lacking transparent analytical tools. This work proposes a multidimensional policy analysis framework that integrates expert interviews with computational text analysis to construct an interpretable scoring system across policy attributes, enabling cross-proposal comparison through visualization. Its novelty lies in three aspects: first, a multidimensional evaluation approach that avoids predetermined conclusions and explicitly reveals inherent trade-offs; second, a transparent hybrid methodology combining qualitative expert insights with quantitative computational validation; and third, the introduction of a domain-calibrated model as a benchmark against general-purpose large language models. The framework enables comparable, interpretable assessments of AI governance proposals across multiple attributes, allowing stakeholders to evaluate proposal relevance and coherence according to their own normative priorities.
Current AI governance suffers from a structural gap between high-level regulatory principles and operational implementation, resulting in weak compliance and ineffective risk management. This paper proposes a five-layer, progressive AI governance framework that systematically bridges macro-level regulatory requirements, meso-level standardization, and micro-level certification—thereby closing the chasm between legislation, standards, and practice. The framework integrates compliance mapping, standardized assessment methodologies, and actionable certification mechanisms. Its efficacy is empirically validated through two representative use cases: AI fairness assurance and incident reporting. As the first model to enable end-to-end, structured alignment from principle to practice, it offers policymakers and industry stakeholders a governance pathway that balances global interoperability with regional adaptability. The framework significantly enhances AI system explainability, controllability, and societal trust. (149 words)
Current AI governance research lacks systematic integration of diverse frameworks and practices, with notable gaps in the operationalizability of key mechanisms and the implementation of inclusive, stakeholder-centered approaches. To address this, we conduct a rapid three-tier literature review, systematically synthesizing nine authoritative IEEE/ACM reviews published between 2020 and 2024. We introduce the novel “thematic semantic synthesis” analytical paradigm to identify high-frequency governance frameworks (e.g., the EU AI Act, NIST AI Risk Management Framework), core principles (e.g., transparency, accountability), and stakeholder role distributions. Our analysis reveals four critical knowledge gaps in AI governance scholarship and practice. Based on these findings, we propose a rigorously grounded, organizationally feasible governance roadmap—bridging theoretical advancement and real-world implementation. This work contributes both empirical evidence and methodological innovation to advance AI governance research and practice.
Existing AI governance research predominantly addresses macro-level regulatory principles, leaving a critical gap in enterprise-level implementation frameworks. This paper proposes a three-layer conceptual framework for organizational AI governance—spanning data, models, and systems—structured around the triad of “actor–artifact–mechanism.” It introduces two novel elements: (1) a data-value quantification methodology and (2) formally defined, role-specific AI governance positions. Leveraging literature-driven modeling, multi-dimensional structural decomposition, and cross-layer alignment techniques, the framework is designed for seamless integration into existing corporate governance infrastructures. The resulting implementation pathway bridges the translational gap between high-level regulatory guidance and operational AI governance practice. By unifying theoretical rigor with practical feasibility, this work establishes a new paradigm for institutionalized AI governance, directly addressing the longstanding challenge of converting abstract governance principles into actionable, organizationally embedded practices. (149 words)
This study addresses the sequential decision-making challenge firms face under stringent regulatory regimes when balancing compliance costs against data value in cross-border data flows. The authors propose a regime-anchored decision support system that translates regulatory requirements into computable minimal compliance mappings and models weekly corporate decisions via a finite-horizon Markov decision process, treating compliance as a hard constraint rather than a penalty term. Innovatively integrating masked deep reinforcement learning with counterfactual path advantage analysis, the framework enables efficient optimization and interpretable decision-making while supporting transferability across jurisdictions. Experimental results demonstrate that the learned policies outperform baseline approaches, exhibit high interpretability and auditability, and uncover key behavioral patterns such as an “absorb–adjust” effect and dynamic shifts in localization boundaries.
This study addresses the limitations of prevailing AI compliance approaches, which often rely on one-time audits and fail to meet the European Union AI Act’s demands for continuous oversight and behavioral drift detection. To bridge this gap, the authors propose a metrics-based governance framework (govllm) that leverages runtime observability to generate ongoing compliance signals. The framework employs an ensemble of small language models (1.7B–7B parameters), each trained on distinct regulatory criteria, to dynamically evaluate system outputs against multidimensional requirements such as GDPR and the EU AI Act within local environments. Disagreements among reviewers are modeled as indicators of regulatory uncertainty, prompting human intervention. Evaluation on 49 annotated samples reveals a maximum inter-model agreement of 69.1% (phi4-mini), underscoring that no single model generalizes across all compliance criteria, while also uncovering three distinct failure modes and significant positional bias in assessments.
This study addresses the challenge of tracing causes and processes when automated decision systems fail, a task inadequately handled by existing compliance governance mechanisms. The authors propose an operational governance evidence framework that integrates structural accountability diagnostics, decision trajectory tracing, sufficiency metrics for evidentiary support, and label-free monitoring. The framework’s applicability is validated across four canonical system architectures. The research uncovers a “governance coverage gradient” phenomenon and introduces an uncertainty cascade model to identify three types of structural discontinuities in agent-based AI systems, along with methods for their analytical extension. By formalizing four propositions that delineate the framework’s boundaries, the work demonstrates full fillability in rule-based engines while simultaneously revealing inherent structural governance gaps in agent-centric AI systems.
This study addresses the challenges of collaboration and quality control in open-source deep learning projects stemming from inadequate governance mechanisms. Drawing on the Institutional Analysis and Development (IAD) framework, it employs a mixed-methods empirical approach combining document content analysis and code commit tracking across PyTorch, TensorFlow, and PaddlePaddle. The analysis encompasses 109 governance documents and over 1,700 code commits, systematically uncovering the structure, temporal evolution, and functional dimensions of governance rules. The research identifies 17 rule themes and 7 rule types, revealing a distinct evolutionary pattern wherein operational rules emerge early and undergo frequent revisions, while structural rules appear later and evolve more steadily. Four core governance functions are distilled, culminating in 33 actionable recommendations for effective open-source AI project governance.