AI安全治理技术白皮书(英文原文)_第1页
AI安全治理技术白皮书(英文原文)_第2页
AI安全治理技术白皮书(英文原文)_第3页
AI安全治理技术白皮书(英文原文)_第4页
AI安全治理技术白皮书(英文原文)_第5页
已阅读5页,还剩34页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

GTI

AISecurityGovernanceTechnologyWhitePaper

-SecurityRootedinNetworks,GoverningAIwithIntelligence,ShiftLeftCo-Governance

GTIAISecurityGovernanceTechnologyWhitePaper

I

GTIAISecurityGovernanceTechnologyWhitePaper

GTI

Version:

V1.0

DeliverableType

□ProceduralDocument☑WorkingDocument

ConfidentialLevel

□OpentoGTIOperatorMembers

□OpentoGTIPartner☑OpentoPublic

Program

5G-A×AIDevelopmentProgram

WorkingGroup

Project

ResearchontheTechnicalFrameworkforAISecurityGovernance

Task

Sourcemembers

ChinaMobile,HKT,YTL,BeijingBaiduNetcom

ScienceTechnologyCo.,Ltd.,BeijingQihooTechnologyCo.,Ltd.,HuaweiTechnologiesCo.,Ltd.,NewH3C

TechnologiesCo.,Ltd.,Novare,iFLYTEKCo.,Ltd.,AnhuiSparkShieldIntelligentTechnologyCo.,Ltd.,

ZTECorporationCo.,Ltd.,BeijingUniversityofPostsandTelecommunications,FudanUniversity,Zhejiang

University,AIEdTechAssociation,HongKongWeb3.0

StandardizationAssociation

Supportmembers

MediaTek,TsinghuaUniversity,TÜVRheinland,YoungAlLeadersCommunity-SanFranciscoHub

Editor

LastEditDate

2026-08-21

ApprovalDate

2026-09-07

GTIAISecurityGovernanceTechnologyWhitePaper

II

GTIAISecurityGovernanceTechnologyWhitePaper

III

Confidentiality:ThisdocumentmaycontaininformationthatisconfidentialandaccesstothisdocumentisrestrictedtothepersonslistedintheConfidentialLevel.Thisdocumentmaynotbeused,disclosedorreproduced,inwholeorinpart,withoutthepriorwrittenauthorizationofGTI,andthosesoauthorizedmayonlyusethisdocumentforthepurposeconsistentwiththeauthorization.GTIdisclaimsanyliabilityfortheaccuracyorcompletenessortimelinessoftheinformationcontainedinthisdocument.Theinformationcontainedinthisdocumentmaybesubjecttochangewithoutpriornotice.

DocumentHistory

Date

Meeting#

Version#

RevisionContents

2026-09-01

1.0

Version1.0

GTIAISecurityGovernanceTechnologyWhitePaper

IV

Foreword

Artificialintelligenceisrapidlyintegratingintoeconomicandsocialoperationsandpoweringdigitaltransformationacrossindustries.AsAIsystemsscale,modernAIapplicationsdependondatapipelines,computinginfrastructure,softwareecosystems,externaltools,digitalidentities,andinterconnectedbusinessprocesses.Securityrisksthereforeextendfarbeyondmodeloutputs.Vulnerabilitiesininfrastructure,misuseofpermissions,maliciousdatamanipulation,autonomousagentbehavior,andsupply-chaindependenciescanallaffectthereliabilityandtrustworthinessofAIsystems.Traditionalgovernancemechanisms,whichwerelargelydesignedforconventionalinformationsystems,areofteninsufficienttoaddresstheseemergingchallenges.

Aroundtheworld,governments,standardsorganizations,enterprises,andresearchinstitutionsareacceleratingthedevelopmentofgovernanceframeworksforAI.Safety,accountability,transparency,robustness,privacyprotection,andvaluealignmentareincreasinglyrecognizedasessentialrequirementsforresponsibleinnovation.EffectivegovernancemustbalanceinnovationwithriskmanagementwhileensuringthatAIremainscontrollable,trustworthy,andbeneficialtosociety.Tothisend,a“1-3-9”AISecurityGovernanceFrameworkisproposedthatintegratessecurityrequirementsthroughouttheentirelife-cycleofAIsystemsbyfocusingon'SecurityrootedinNetworks','GoverningAIwithIntelligence',and'ShiftLeftCo-Governance'tosupportlarge-scaleAIdeployment.Thisproposalsummarizesthemajordevelopmenttrends,governancechallenges,strategicapproaches,implementationpathways,andcollaborativeinitiativesnecessarytoestablishasecure,trustworthy,andsustainableAIecosystem.

GTIAISecurityGovernanceTechnologyWhitePaper

V

TableofContents

DocumentHistory III

Foreword IV

TableofContents V

1TrendsinArtificialIntelligenceDevelopmentandtheGlobalGovernanceLandscape 1

1.1DevelopmentTrends:AcceleratingTechnologicalEvolutionTowardSystemicand

AgenticAI

1

1.2GlobalPerspective:GovernanceRulesAreTakingShape 1

1.3IndustryPerspective:CollaborativeExplorationbyDiverseStakeholders 2

2RisksandChallenges:AISecurityGovernanceFacesFiveMajorShifts 3

2.1TheUnknownOutweighstheKnown 3

2.2AttacksOutpaceDefenses 4

2.3EvolutionOutpacesGovernance 4

2.4DivergenceOutweighsConsensus 5

2.5BehaviorOverContent 5

3OverallApproachtoAISecurityGovernance 7

3.1Vision:BecomingFoundationBuilders,Guardians,andEnablersforAIforGreater

Good

8

3.2StrategicApproach 9

3.2.1SecurityrootedinNetworks 9

3.2.2GoverningAIwithintelligence 9

3.2.3ShiftLeftCo-Governance 10

3.3DevelopmentPath:ThreeDirectionsandNinePathways 10

3.3.1InfrastructureSecurityDirection 11

3.3.2Intelligence-DrivenGovernanceDirection 11

3.3.3Full-ScopeCollaborativeGovernanceDirection 12

3.4GovernanceAssessment:SixCapabilityDimensions 13

4AISecurityGovernanceInitiative 16

4.1BalanceHigh-QualityDevelopmentwithHigh-LevelSecurity 16

4.2BuildRobustandReliableOperationalFoundations 16

4.3EmbedEndogenousGovernanceThroughoutLifecycles 16

4.4FosterOpenandCollaborativeSecurityEcosystems 17

AcronymsandAbbreviations 18

References 19

GTIAISecurityGovernanceTechnologyWhitePaper

1

1TrendsinArtificialIntelligenceDevelopmentandtheGlobalGovernanceLandscape

Artificialintelligenceisbecomingacoredriverofeconomicandsocialtransformation.Technologicalprogress,industrialadoption,andgovernancedevelopmentareoccurringsimultaneously,creatingbothopportunitiesandchallengesforstakeholdersacrossindustries.

1.1DevelopmentTrends:AcceleratingTechnologicalEvolution

TowardSystemicandAgenticAI

AIdevelopmentisshiftingfromsingle-modelperformancetosystemiccapabilitiesthatcombinealgorithms,computingpower,data,toolchains,agents,andengineeringplatforms.LLM,multi-modalinteraction,longcontext,andtoolusemoveAItowardplanning,coordination,andcomplexexecution.Agentsareevolvingintosystemsthatunderstandgoals,decomposetasks,invoketools,interactwithenvironments,andlearnfromfeedback.AsAIentersR&D,finance,publicservices,andnetworkoperations,deploymentrequiresprocessadaptation,datagovernance,integration,accesscontrol,andsecureoperations.

1.2GlobalPerspective:GovernanceRulesAreTakingShape

Fromtheperspectiveofglobalgovernance,majorcountries,internationalorganizations,standardsbodies,andindustrystakeholdersareacceleratingthedevelopmentofAIgovernancerulesandpracticalapproaches.Currenteffortsfocusonareassuchasriskclassification,trustworthinessassessment,datagovernance,

modeltransparency,accountabilityboundaries,contentprovenanceandlabeling,

technicalstandards,andinternationalcoordination.

AIsecuritygovernanceisalsodevelopingalongtwocloselyrelatedfronts.ThefirstisAIforSecurity.AIisbecominganimportantenablerforstrengtheningsecuritycapabilities,supportingvulnerabilitydiscovery,threatanalysis,securityoperations,andriskassessmentthroughintelligentanalysis,automateddetection,anddecisionsupport.ThesecondisSecurityofAI.AsthecapabilitiesanddeploymentboundariesofAIsystemscontinuetoexpand,thesecurityofAIitselfisreceivinggrowingattention.Risksrelatedtomodelsecurity,datasecurity,agentbehavior,inter-agentcommunicationleakage,andsupply-chaindependenciesarebecomingkey

GTIAISecurityGovernanceTechnologyWhitePaper

2

governancepriorities.Addressingtheserisksrequiresriskassessment,life-cyclemanagement,andruntimecontrolmechanismsthatimprovethesecurityandtrustworthinessofAIsystems.

AIgovernanceismovingfromhigh-levelprinciplesandvoluntaryinitiativestowardamorematurestagethatcombinesinstitutionalarrangements,standardsdevelopment,technicalevaluation,andregulatoryimplementation.Althoughgovernanceapproachesdifferacrosscountriesandregions,abroadconsensusisemergingaroundsafetyandtrustworthiness,riskcontrol,clearaccountability,human-centereddevelopment,andopencollaboration.

1.3IndustryPerspective:CollaborativeExplorationbyDiverseStakeholders

AIgovernancerequirescollaborationamonggovernments,infrastructureproviders,technologycompanies,securityvendors,standardsorganizations,researchinstitutions,andendusers.NosinglestakeholderpossessessufficientvisibilityorauthoritytomanageallaspectsofAIrisk.

DigitalinfrastructureprovidersplayaparticularlyimportantrolebecauseAIsystemsrelyheavilyonconnectivity,computingpower,identitymanagement,andoperationalmonitoring.TrustedinfrastructureprovidesthefoundationforsecureAIdeployment.Atthesametime,collaborationacrossindustriespromotesknowledgesharing,standardization,interoperability,andcoordinatedriskmanagement.

Thelong-termsuccessofAIgovernancedependsonestablishingmechanismsthatencouragecooperationwhilemaintainingflexibilityforinnovation.

GTIAISecurityGovernanceTechnologyWhitePaper

3

2RisksandChallenges:AISecurityGovernanceFacesFiveMajorShifts

Thelarge-scaledeploymentofAIisfundamentallychangingthenatureofsecurityrisks.Governancechallengesincreasinglyemergefrominteractionsamongmodels,data,infrastructure,permissions,andoperationalprocesses.Asaresult,governanceapproachesmustevolvebeyondstaticcontrolsandcompliance-basedsupervision.

Fivegovernanceshiftsataglance

01TheUnknownOutweighstheKnown

Emergentbehaviorandcomplexinteractionsmakerisks

difficulttopredictbeforedeployment.

02AttacksOutpaceDefense

AIlowersthecostofvulnerabilitydiscovery,socialengineering,andcoordinatedattackcampaigns.

03EvolutionOutpacesGovernance

Newarchitecturesandscenariosevolvefasterthanstandards,rules,andgovernancemechanisms.

04DivergenceOutweighsConsensus

Sharedprinciplesexist,butregulatorytools,riskboundaries,andstandardsremainfragmented.

05BehaviorOverContent

Riskmovesfromcompliantoutputstocontrollableactions,permissions,andexecutionchains.

2.1TheUnknownOutweighstheKnown

ModernAIsystemsexhibitemergentbehaviorsthatareoftendifficulttopredict.Capabilitiessuchaslong-contextreasoning,memorymanagement,externaltool

invocation,andmulti-agentcollaborationintroduceuncertaintyintooperationalenvironments.Risksmayemergethroughcomplexinteractionsratherthanisolatedfailures.

Examplesincludehallucinations,promptinjectionattacks,objectivemisalignment,andunexpectedbehavioraloutcomes.Becausetheseriskscannotalwaysbeidentifiedduringdevelopment,governanceframeworksmustsupportcontinuousmonitoring,runtimeassessment,andadaptivemitigationstrategies.

Governancemustthereforeevolvebeyondstaticrulematchingtowardpre-deploymentriskassessment,continuousruntimemonitoring,dynamicriskevaluation,andruntimecalibration.Reassessmentshouldbetriggeredwhenkey

GTIAISecurityGovernanceTechnologyWhitePaper

4

elementssuchasmodels,data,toolpermissions,orapplicationscenarioschange,ensuringthatgovernancemeasuresremainalignedwiththeevolutionofAIsystems.

2.2AttacksOutpaceDefenses

AIisbecomingdeeplyembeddedinsoftwaredevelopment,securitytesting,andcyberoperations.Vulnerabilitydiscoveryisshiftingfromexpert-drivenanalysistowardintelligentworkflowsthatsupportlarge-scalescreening,automatedvalidation,andcontinuousoperation.MaliciousactorsmayuseAItoacceleratevulnerabilitydiscovery,exploitvalidation,andattack-chainorchestration,loweringpreparationcostsandexecutionbarriers.Defenders,bycontrast,mustbalancebusinesscontinuity,systemcompatibility,andoperationalstability,whichlengthensresponsechainsandwidensthetempogapbetweenattackanddefense.

AsAIisfurtherintegratedintocloudcomputing,mobilenetworks,andedgecomputing,defensemodelsthatrelyonfixedperimetersandlocaldetectionareincreasinglychallenged.Edgeintelligence,distributedinference,andautonomousagentinteractionareweakeningtraditionalnetworkboundaries.Securitygovernanceisthereforeevolvingfromperimeter-basedprotectiontowarddynamictrustenabledbydistributedtelemetry.Inthefuture,securitycapabilitieswillbefurtherembeddedintocommunicationnetworksandcomputinginfrastructure,formingadaptiveruntimeguardrailsforAIsystemsthroughoperational-statesensing,entityverification,anddynamicpolicyadjustment.

2.3EvolutionOutpacesGovernance

Technologicalinnovationoftenadvancesfasterthanstandards,regulations,andgovernancemechanisms.AIisevolvingfromsingle-modelinvocationintoanintegratedtechnicalsystemthatcombinesmultiplecapabilities,connectsmultiplesystems,andbecomesembeddedacrossmultipleoperationalstages.Itscapabilitiesareexpandingfromtextgenerationtomulti-modalunderstanding,codegeneration,tooluse,andtaskplanning,whileapplicationsareextendingfromassistant-styleQ&Atoofficecollaboration,softwaredevelopment,customerservice,operationsmanagement,andproductioncontrol.

Astechnicalforms,applicationboundaries,andoperatingmodescontinuetochange,governancerules,evaluationmethods,accountabilityboundaries,andauditmechanismsfacecontinuouspressuretoadapt.Governancethereforeneedstomovebeyondfixedrulematchingtowardamodelthatcombinesrisk-basedmanagement,principle-guidedgovernance,anddynamicadaptation.Governancerequirements

GTIAISecurityGovernanceTechnologyWhitePaper

5

shouldalsoexpandfromcontentcompliancetodataflows,permissionuse,externalconnections,behavioralprocesses,andaccountabilitychains.Fulllife-cycleaccesscontrol,dynamicbehaviorcalibration,real-timeriskcorrection,andcontinuousevaluationandauditingareneededtonarrowgovernancegaps.

2.4DivergenceOutweighsConsensus

Globalactorsbroadlyendorseprinciplessuchascommongood,people-centereddevelopment,safety,reliability,transparency,accountability,fairness,inclusiveness,humanoversight,andriskgovernance.However,differencesindevelopmentstages,industrialfoundations,andregulatorysystemshaveledtodifferentgovernancepathwaysintermsofregulatoryintensity,policytools,riskboundaries,responsibilityallocation,andstandardssystems.TheEUplacesgreateremphasisonriskclassification,complianceobligations,andmandatoryregulation;theUSfocusesmoreonriskmanagementframeworks,technicalguidance,industrypractice,andthebalancebetweeninnovationandgovernance;SingaporeandtheUKareexploringmoreflexibleapproaches.

Representativegovernanceframeworksandinitiativeshavealsotakenshape.TheEUArtificialIntelligenceActfocusesonriskclassificationandcompliancerequirements,NISTAIRMFemphasizesriskmanagementprocesses,andISO/IEC42001addressestheestablishmentofAImanagementsystems.TheBletchleyDeclaration,theUNESCORecommendationontheEthicsofArtificialIntelligence,andITUAIforGoodfurthercontributetoglobalconsensusonsafety,ethics,andsustainabledevelopment.

Lookingahead,greatereffortsareneededtopromoteinteroperablestandardsframeworks,evaluationmethodologies,interfacerules,andcoordinationmechanisms.Thiswillhelpdifferentstakeholdersbuildbaselineconsensusonriskidentification,informationsharing,incidentresponse,andaccountabilitytracing,therebyreducingregulatoryfrictionandcoordinationcosts.

2.5BehaviorOverContent

AsAIentersoperations,manufacturing,autonomousdriving,andinspections,modeljudgmentsandinstructionsincreasinglybecomesystemconfigurations,equipmentactions,andprocessdecisions.Riskthereforeshiftsfromcompliantcontenttocontrollablebehavior.Errorcodes,configurationmistakes,perceptionanomalies,corrupteddata,oradversarialinputscanpropagatethroughbusinessor

GTIAISecurityGovernanceTechnologyWhitePaper

6

perception-decision-executionchains,causingleaks,disruptions,productionfailures,orreal-worldsafetyissues.

Consequently,organizationsmustensurethatAIactionsremainwithinauthorizedboundaries.Governancemechanismsshouldincludeaccesscontrols,approvalworkflows,anomalydetection,rollbackcapabilities,andcomprehensiveauditing.ThegoalistoensurethatAIbehaviorremainspredictable,controllable,andaccountable.

GTIAISecurityGovernanceTechnologyWhitePaper

3OverallApproachtoAISecurityGovernance

ToaddressthefivemajorshiftsinAIsecuritygovernance,weproposea“1-3-9”AISecurityGovernanceFramework.Traditionalpoint-basedapproachescenteredonmodelsecurity,contentsafety,andapplicationprotectionarenolongersufficienttoaddresscross-model,cross-data,cross-tool,cross-computing,andcross-stakeholderrisksarisingfromsystemicandagenticAI.AIsecuritygovernanceisthereforemovingtowardamoreintegratedapproachthatcoversinfrastructuresupport,intelligentgovernance,applicationoperations,andecosystemcollaboration.

BuildingontheevolvingglobalAIgovernancelandscapeandthesecurityneedsoflarge-scaleAIdeployment,theframeworkisguidedbySecurityRootedinNetworks,GoverningAIwithIntelligence,andShift-LeftCollaborativeGovernance.Itconsistsofonesharedvision,threestrategicapproaches,andninedevelopmentpathways.Byembeddingsecurityrequirementsintoinfrastructuresupport,intelligentcapabilitygovernance,andindustryapplicationecosystems,theframeworkworksincoordinationwithinternationalframeworkssuchasNISTAIRMFandISO/IEC42001,providingapracticalreferencefortranslatingAIsecuritygovernanceprinciplesintoimplementation.

SixCapabilityDimensions

TrustworthyEntities

Esdsbishtrustmscbisms

Control

MeasurableRisk

Achieveriskquantificationandpreciseassessment

TraceableProcesses

andfulltraceability

ControllableBehavior

Ensdecotrolaliewareness

AlignedValues

ohadtnabenivelentiacigles

trustworthymanner

EvolvingCapabilities

otinuosritereteard

ConvergedFoundationofThreeNetworks

TellecommunicationComputing

NetworksPowerNetworks

1VisionandPositioning

3MajorStrategicApproaches

9DevelopmentPathways

GovemninCo-Defense

Securecomputing

resources

IntelligenceNetworks

Ilntelisence-

Trust

Chaining

Positioning

Bobavins

connectivity

Figure1:“1-3-9”AISecurityGovernanceFramework

GTIAISecurityGovernanceTechnologyWhitePaper

8

3.1Vision:BecomingFoundationBuilders,Guardians,andEnablersforAIforGreaterGood

AIisrapidlyintegratingintoproduction,dailylife,andsocialgovernance,becomingavitalforcedrivingthedevelopmentofnewproductiveforces,theconstructionofdigitalsocieties,andthemodernizationofgovernancesystems.AIsecuritygovernanceservesasacriticalpillarforensuringthatAIremainssafe,trustworthy,inclusive,beneficial,andhigh-qualityinitsdevelopment.Acrosskeyscenariossuchasdigitalandintelligentproduction,digitalandintelligentliving,anddigitalandintelligentgovernance,allindustrystakeholdersneedtocollectivelyfulfilltheirrolesinprovidingfoundationalsupport,securityassurance,andscenarioempowerment.Together,theyshouldactasfoundationbuilders,guardians,andenablersforthebeneficialdevelopmentofAI.

ForDigitalandIntelligentProduction-ActingasFoundationBuildersforTrustworthyAIDevelopment

AsAIbecomesdeeplyembeddedinkeyareassuchasR&Danddesign,productionandmanufacturing,supplychaincoordination,andoperationsmanagement,securitycapabilitieshavebecomeanessentialfoundationforindustrialintelligenttransformation.Itisnecessarytoleveragenetwork,computing,data,andplatformcapabilitiestopromotethecoordinateddevelopmentofsecuritycapabilitiesalongsideAIinfrastructure,therebyprovidingastable,reliable,safe,andtrustworthyfoundationforindustrialintelligentupgrading.

ForDigitalandIntelligentLiving—ActingasGuardiansforSecureAIApplications

Asapplicationssuchassmarthomes,intelligentterminals,andvirtualdigitalavatarsspread,AIservicesrequirestrongersafeguardsforindividualsandfamilies.Thereisanurgentneedtostrengthencomprehensivepublic-facingsecuritysafeguards.Securitygovernancemustbeembeddedthroughouttheentireprocessofintelligentproductdesign,serviceoperation,anduserinteraction,reinforcingprotectionforuserdata,servicecontent,identityauthentication,andterminalaccess.ThisensuresthatsecurityboundariesaremaintainedforAIapplicationsservingthepublic,makingintelligentapplicationsmoretrustworthyandreassuring.

ForDigitalandIntelligentGovernance—ActingasEnablersforIntegratedAIInnovation

GTIAISecurityGovernanceTechnologyWhitePaper

9

Asgovernmentservices,urbanoperations,publicsafety,andemergencymanagementadoptAI,cross-industryandcross-regionalcollaborationbecomesvital.ItisnecessarytopromotedeepintegrationofAIcapabilitiesandsecuritycapabilitieswithindustryscenarios,providingrobustsupportforgovernancemodernizationandintelligentsocialoperations.

Byestablishingsecurefoundationsforconnectivity,computing,andintelligentservices,theframeworkseekstosupportthelong-termdevelopmentofaresilientandtrustworthyAIecosystem.

3.2StrategicApproach

Theframeworkisbuiltuponthreestrategicprinciples:SecurityrootedintoNetworks,GoverningAIwithintelligence,andShiftLeftCo-Governance.Together,theseprinciplesprovideaholisticapproachtomanagingAIrisksthroughoutthelife

cycleofsystemsandservices.

01SecurityRootedinNetworks

02GoverningAIwithintelligence

03ShiftLeftCo-Governance

3.2.1SecurityrootedinNetworks

SecurityRootedinNetworksemphasizesdigitalinfrastructureasthefoundationforAIsecuritygovernance.Fromtheperspectiveoflarge-scaleAIdeployment,AIdependsonthecoordinatedsupportofconnectivity,computingpower,trust,data,models,andapplications.Amongthese,connectivity,computing,andtrustareessentialtosecureandreliableAIoperations,andarekeyareaswherenetworkoperatorscanprovidefoundationalsupport.

Securityrequirementsshouldthereforebeembeddedintoconnectivitylinks,computingenvironments,interactionentrypoints,andbusinessworkflows.Thisenablessecuritycapabilitiestobedeployed,monitored,andenforcedinstepwithAIoperations,forminginfrastructure-levelprotectionacrossrealoperationalchains.

3.2.2GoverningAIwithintelligence

GoverningAIwithIntelligenceemphasizestheuseofAIcapabilitiestostrengthenAIsecuritygovernance.Asmodelcapabilitiescontinuetoemerge,agentsbecomemoreautonomous,attacksbecomeincreasinglyautomated,andriskspropagateacrosschains,governancecapabilitiesmustmatchthespeedandcomplexityofevolvingrisks.

GTIAISecurityGovernanceTechnologyWhitePaper

10

Security-orientedAImodels,intelligentsensing,dynamicassessment,behavioralanalyses,situationalawareness,andpolicyorchestrationcanbeusedtocontinuouslyidentify,assess,andinterveneintheorigins,behaviors,andtrendsofAI-relatedrisks.Combinedwithcontinuousandautomatedsecurityvalidation,includingredteaming,attacksimulation,andriskverification,thesecapabilitieshelpuncoverpotentialrisks,refineprotectionstrategies,andformaclosedloopofriskdiscovery,validation,assessment,andsecurityimprovement.

Thisenablesgovernancetomovefromexperience-basedmanualoversighttowardhuman-AIcollaboration,intelligentjudgment,andproactivedefense.

3.2.3ShiftLeftCo-Governance

Shift-LeftCollaborativeGovernanceemphasizesembeddingsecuritygovernanceearlyintothefullprocessofAIdevelopmentandapplication,reducingriskaccumulationthroughsourcepreventionandprocesscontrol.GiventhesystemicnatureofAIsecuritygovernance,itrequirescoordinatedmanagementofcoreelements,lifecyclestages,anddiversestakeholders,movinggovernancetowardfull-scopecoverage,early-stageprevention,andmulti-partycollaboration.

Responsibilitiesshouldbeclearlydefinedamongdevelopers,deployers,users,andotherrelevantactors.Inhigh-riskscenarios,humanoversight,intervention,andaccountabilitymechanismsshouldbestrengthenedtoensurethatAIapplicationsremaincontrollableandresponsibilitiesremaintraceable.T

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论