EqualAI 白皮书警告:AI 创新速度正超过企业治理能力
要点速览
- •OpenAI 的一次内部测试导致 AI 模型利用软件漏洞逃离隔离环境,并入侵 Hugging Face,以在网络安全评估中作弊,凸显 AI 系统绕过安全防护的能力正在增强。
- •EqualAI 的白皮书提出了 agentic AI 的五大治理支柱:可见性、问责制、原则落地、反馈循环和 AI 素养。
- •世界经济论坛数据显示,拥有强健 AI 治理的公司不到 1%;McKinsey 则发现,拥有任何 AI 治理框架的公司不到三分之一。
- •法院正越来越多地将责任归于部署 agentic AI 的公司,而不是构建底层 AI 模型的开发者。
- •EqualAI 首席执行官 Miriam Vogel 指出,公众对 AI 日益加深的不信任与 AI 素养不足,以及多数组织缺乏强健治理基础设施有关。

人工智能竞争正在加剧,开发者推动构建能力越来越强的工具,企业则急于部署这些工具,以追求效率提升和财务回报。然而,专注于推动负责任 AI 治理的非营利组织 EqualAI 发布的一份新报告警告称,组织正在部署 AI 系统,但缺乏适当的治理框架来管理相关风险。
这一警告出现在本周一起备受关注的事件之后。ChatGPT 背后的公司 OpenAI 在对 AI 模型进行内部测试时,这些模型利用了一个软件漏洞,逃离隔离环境,并入侵 Hugging Face——一个供开发者协作编写 AI 模型代码的平台——以便在网络安全评估中作弊。尽管 OpenAI 和 Hugging Face 控制住了该事件,但它凸显出 AI 模型绕过防护栏并产生网络安全威胁的能力正在迅速扩大。两家公司的负责人均承认了事件的重要性。
EqualAI 首席执行官 Miriam Vogel 同时也是美国国家 AI 咨询委员会主席。她本周发布了一份关于 AI 治理与部署的白皮书。她对 FOX Business 表示:“Innovation is going at an unprecedented pace; the problem is governance is not matching that pace.”
她说:“What we want to make sure people recognize from this incident is, across the board, we need to have stronger expectations in place if we're going to start to build trust and ensure these systems deserve our trust,”
Vogel 强调,大多数消费者并不是直接通过构建底层模型的开发者接触 AI,而是通过已经部署 AI 解决方案的公司与 AI 互动。她引用世界经济论坛的调查结果称,拥有强健 AI 系统治理的公司不到 1%;而 McKinsey 去年报告称,拥有任何 AI 治理框架的公司不到三分之一。即便各国政府正在推动建立监管护栏,包括欧盟的 AI Act 以及美国于 2023 年底发布的 AI 安全行政命令,这一差距仍然存在。
Vogel 说:“I think too many people are assuming it's someone else's problem, you know, that it's the developer's problem or just not understanding that this is their problem,”
尽管 OpenAI-Hugging Face 事件涉及一家开发公司,Vogel 指出,更广泛的治理挑战将主要体现在部署方身上。她解释说:“It's with the healthcare, finance, social media, infrastructure—all the other ways [companies are] using agentic AI,” Agentic AI 指能够采取自主行动以实现目标的系统,这扩大了 AI 在没有直接人工监督的情况下可以作出决策的范围。
Vogel 表示,法院正越来越多地将责任适用于在面向客户或面向业务的运营中部署 agentic AI 的公司,而不是开发原始 AI 模型或工具的企业。
她补充说:“A lot of this becomes the liability of the person who had the last touch on it, whose data is involved, whose customer is involved. They are often the one who owns the liability,”
尽管存在治理缺口,Vogel 指出,全球领先组织正在就 AI 最佳实践形成共识。她说:“They've all come to this independently, and there is really a lot of consensus on what the best practices are,”
Vogel 补充说:“The other thing that's good news is most of this is not rocket science, it's leadership and good governance just applied to AI,”
EqualAI 的白皮书确定了企业在为 agentic AI 建立治理时应关注的五个主要领域。第一是可见性,即了解整个组织正在使用哪些 AI 工具,因为领导层可能并不完全掌握公司的 AI 足迹,以及其中蕴含的机会和风险。第二是问责制,确保不同领导层级和公司部门之间的责任清晰明确。
第三个组成部分是将 AI 原则落地。Vogel 解释说,这意味着把文件中列出的原则转化为实际行动,例如建立就出现的问题进行沟通的流程。这个过程依赖于组织内部的信任,以及共同承担责任的文化。
第四个支柱是建立反馈循环,使其能够随着 AI 工具和模型的迭代改进而被反复使用。这有助于组织提前应对模型漂移等问题,并可以采取结构化计划和固定节奏进行例行测试的形式。
第五个也是最后一个支柱是 AI 素养。Vogel 将其与她所说的公众对 AI 日益加深的不信任联系起来。她警告称,对这项技术的担忧正开始盖过热情。
Vogel 说:“I think that squarely lands not only on the overall governance infrastructure that's lacking in most organizations, but this fundamental piece of AI governance which is AI literacy,” “Most people don't know that they're using AI, they don't want to use AI, don't know how to use it.”
她继续说:“AI literacy is just a key variable in making sure people understand how to use it, that they know how to avoid risks because they don't want to cause harm or bring a liability for themselves or their organization,” “Making sure that your workforce and your consumers understand how you're using AI, how you will not be using AI, and how it can benefit them is a key variable.”