arXiv:cs.AI· Seungho Lee, Changbin Lee·· 6 小时前AI 评分48
AI 智能体的作者身份风险:智能体应是治理平面的主体而非作者
Subjects, Not Authors: The Authorship Hazard in Agentic Dataspaces
AI 导读
论文提出"作者身份风险"原则:AI 智能体是治理平面的主体,绝不能成为其作者,其发布授权通道在设计上即关闭。在 90 次预注册编辑(各经 344,512 次请求评估)中,仅重新分类字段的 6 次编辑全部改变授权并收缩义务而不触碰政策文本,政策差异分类器全部通过这 6 项。
正文
Abstract:Dataspace connectors decide whether a transfer may occur, not what the transferred value contains, tolerable for contracted applications, not for LLM agents that compose tool calls. Work on agents that generate governance artifacts evaluates output quality, not who may authorize an artifact for use. A published policy is what the decision point enforces, so publication is a governance event, and agents that are both policy subjects and policy authors write the norms that bind them. We name this the authorship hazard and state one principle: an agent is a subject of the governance plane, never an author of it. Its authorization channel to publication is closed by construction; its influence channel, drafting what humans approve, becomes an enforcement problem. Across 90 preregistered edits to the paper's running agreement, each evaluated on 344,512 requests, the six that only reclassify a field all change authorization and narrow a duty without touching policy text, and a policy-diff classifier passes all six. Read as worded, the privilege-delta conditions also pass 33 of 69 effective policy-text edits; read as covering any relaxation, none. Treating classification as authorship routes all six to review; the registry this requires is not yet built. At the execution boundary, protected fields reach the model in 105 of 105 cases under prompt-stated duties and in 0 of 105 under a compiled tool-call constraint, but values outside named fields are exposed in 7 of 7. At the review share measured, a central approval pool needs one approver per 20 to 138 participants.
| Comments: | 16 pages, 3 figures, 13 tables |
| Subjects: | Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI); Databases (cs.DB); Multiagent Systems (cs.MA) |
| Cite as: | arXiv:2609.30614 [cs.CR] |
| (or arXiv:2609.30614v2 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2609.30614 arXiv-issued DOI via DataCite |
Submission history
From: Seungho Lee [view email]
[v1]
Thu, 24 Sep 2026 22:58:16 UTC (802 KB)
[v2]
Tue, 6 Oct 2026 11:43:54 UTC (774 KB)
来源:arXiv:cs.AI · arxiv.org