New Framework Aims to Guide Governance of Agentic AI Systems
Global: New Framework Aims to Guide Governance of Agentic AI Systems
A team of researchers associated with GovTech Responsible AI has introduced the Agentic Risk & Capability (ARC) Framework, a technical governance model intended to help organizations identify, assess, and mitigate risks stemming from agentic artificial intelligence systems. The framework targets AI that can execute code, interact with the internet, and modify files without direct human oversight, addressing both opportunities and emerging threats.
Capability‑Centric Perspective
The ARC Framework adopts a novel capability‑centric lens, allowing analysts to evaluate a broad spectrum of agentic AI systems based on their functional abilities rather than solely on underlying architectures. By focusing on what the systems can do, the approach aims to capture nuanced risk vectors that traditional model‑centric assessments might overlook.
Identified Sources of Risk
According to the authors, three primary sources of risk are intrinsic to agentic AI: components, design, and capabilities. Components refer to hardware and software elements that could be compromised; design encompasses architectural choices that may enable unintended behaviors; and capabilities describe the range of autonomous actions the AI can perform.
Linking Risks to Controls
The paper establishes a clear nexus between each risk source, specific materialized risks, and corresponding technical controls. For example, vulnerabilities in components may lead to unauthorized data access, which can be mitigated through sandboxing and strict permission models. Design‑related risks such as goal misalignment are addressed with robust verification and validation procedures.
Implementation Guidance
To assist organizations in practical adoption, the framework provides a structured methodology that includes risk identification workshops, capability assessments, and the selection of appropriate technical safeguards. The authors emphasize that the process is adaptable, enabling rapid innovation while maintaining safety and security standards.
Open‑Source Access
The ARC Framework is openly available for review and integration at https://govtech-responsibleai.github.io/agentic-risk-capability-framework/, encouraging community contributions and transparency.
This report is based on information from arXiv, licensed under Academic Preprint / Open Access. Based on the abstract of the research paper. Full text available via ArXiv.
Ende der Übertragung