MétaCan
Menu
Retour à la cohorte
Enregistrement W6987030444

A Risk-Based Approach to AI Procurement

2022· article· en· W6987030444 sur OpenAlexaboutno aff

Notice bibliographique

RevueeYLS (Yale Law School) · 2022
Typearticle
Langueen
DomaineSocial Sciences
ThématiqueEthics and Social Impacts of AI
Établissements canadiensnon disponible
Organismes subventionnairesnon disponible
Mots-clésProcurementContext (archaeology)VendorWork (physics)Risk managementSupply chain
DOInon disponible

Résumé

récupéré en direct d'OpenAlex

Responsibly procuring and deploying artificial intelligence (AI) systems is a complex endeavor. Through our work at the Responsible AI Institute, we have helped the Joint Artificial Intelligence Center (JAIC) at the U.S. Department of Defense develop foundational procurement protocols that embody the agency’s AI Ethics Principles. We have also supported companies in the financial services and health care industries as they develop their responsible AI procurement processes. Although each context poses different and important issues, our experiences suggest that tailoring contract requirements for procured AI systems to the level of risk created by each system is an effective way to grapple with three major challenges that organizations face in responsibly procuring and deploying AI systems. These challenges include developing organizational responsible AI capacity, navigating legal uncertainty and addressing general information technology procurement issues. To use this risk-based approach, an organization should assign a risk level to an AI system—such as high, medium or low—based on the results of an organization’s AI impact assessment during an early phase of the procurement process. If an organization is procuring an already developed system, AI impact assessment results may be provided as part of the bid. If an organization is creating an AI system with vendor help, it should conduct an AI impact assessment once the details of the system are known. An AI system’s risk level should reflect risks to the people impacted by the system as well as risks to the organization. Although the contents of an organization’s AI impact assessment will vary by organization and context, they should always include considerations related to accountability; robustness, safety, and security; bias and fairness; system operations; explainability and interpretability; and consumer protection. These foundational categories form the basis of our Responsible AI Implementation Framework. Once assigned, an AI system’s risk level should guide the remainder of the procurement and deployment process (see figure). For example, while all AI systems should undergo testing before and during deployment, the extent of the testing, the approval authority that greenlights deployment, the frequency of testing during deployment and documentation requirements—such as responsible AI management plan details and frequency of updates—should all be determined by the risk level of the AI system. Responsible AI programs at most organizations are in an early stage of maturity. Since the functioning of AI systems can be unpredictable and difficult to understand, responsibly deploying AI requires an organization to develop capacity in the form of new contract requirements. These requirements can take a variety of shapes and include assessments such as an AI impact assessment, documentation requirements like the responsible AI management plan, governance processes, policy frameworks and training programs. As an organization develops responsible AI capacity, adopting a risk-based approach to AI procurement can promote a thoughtful and measured understanding of AI within different parts of an organization, overstating neither the benefits nor the risks of AI systems. Since AI systems are generally not subject to blanket regulation and industry-specific AI laws are often short on details, legal requirements for AI systems can be difficult to determine. For example, legislation in New York City requiring that any automated hiring system used on or after January 1, 2023 undergo a bias audit consisting of an “impartial evaluation by an independent auditor,” including testing to assess potential disparate impact to certain groups, does not further specify what kinds of discrimination to test for, what criteria to test for and how often to test. By incorporating regulatory risk considerations into the initial AI impact assessment, organizations can consider the legal and compliance implications of deploying an AI system early in the procurement process, reducing the need for expensive and time-consuming interventions later in the system’s life cycle. In addition to regulatory risks to an organization, carefully reviewing proposed and enacted AI-specific laws and regulations also gives insight into the potential harms to people that regulators are seeking to address. The risks of these potential harms, too, should be thoughtfully incorporated into the AI impact assessment. For instance, an organization’s AI impact assessment for an AI system related to hiring should gauge its compliance with Equal Employment Opportunity Commission guidance on how such systems may violate the Americans with Disabilities Act, Illinois’ notification and consent requirement for AI video interviews, Maryland’s notification and consent requirement for the use of facial recognition in video interviews and New York City’s aforementioned bias audit requirement for automated hiring systems. More generally, it should address the potential fairness, notification, transparency, recourse and effectiveness issues that are driving these regulations. Adopting a risk-based approach to procurement also allows an organization to incorporate contracting language that aligns with emerging laws, best practices and certification standards. For example, the European Union’s proposed Artificial Intelligence Act, the National Institute of Standards and Technology’s draft AI Risk Management Framework, Canada’s proposed Artificial Intelligence and Data Act and our Responsible AI Institute Certification Program—which is currently under review by national accreditation bodies—all reflect increasingly sophisticated understandings of responsible AI implementation. Efforts to responsibly procure and deploy AI systems often bring into sharper focus well-known IT procurement issues, including building the organizational expertise to manage external teams, preventing vendor lock-in and providing an even playing field for suppliers of different sizes. For example, while startups that provide AI solutions are sometimes more current in their understanding of responsible AI considerations and can be faster to adapt to new types of contract requirements, established technology companies can often use existing inroads with organizations to outmaneuver new entrants. Adopting a risk-based approach to procurement and clearly communicating it to vendors can help address such issues by giving the procuring organization advance notice of the specific oversight capabilities it will need in future stages of the system lifecycle, preventing vendors from presenting intellectual property arguments against required testing, monitoring and auditing of their AI systems going forward and rewarding vendors—of all sizes—that are more advanced and responsive in their responsible AI efforts.

Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.

Comment cette classification a été obtenuedéplier

Prédiction machine sur la base complète

Imitation des enseignants

Ni prévalence calibrée, ni vérité terrain. Validation humaine à venir. Le volet Gemma est une étiquette directe du modèle pour chaque travail de la base, lue sur la notice réduite au titre. Le volet Codex est un classifieur appris des 10 348 étiquettes directes de Codex et calibré sur les taux pondérés de l'échantillon; les champs sans appui suffisant ne portent aucun appel Codex. Le mode candidate est l'union des deux volets; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont pas des étiquettes humaines.

score de la tête « metaresearch » (Codex)0,034
score de la tête « metaresearch » (Gemma)0,034
Version: metacan-v3-hybrid-931329e0061cStatut de validation: machine_predicted_unvalidated
Catégories candidatesaucune
Catégories consensuellesaucune
DomaineSignal candidat: aucune · Signal consensuel: aucune
Devis d'étudeSignal candidat: Théorique ou conceptuel · Signal consensuel: Théorique ou conceptuel
GenreSignal candidat: Empirique · Signal consensuel: aucune
Score de désaccord entre enseignants0,034
Score d'incertitude au seuil0,180

Scores du classifieur distillé par catégorie (deux têtes)

CatégorieCodexGemma
Métarecherche0,0340,034
Méta-épidémiologie (sens strict)0,0020,001
Méta-épidémiologie (sens large)0,0010,002
Bibliométrie0,0070,003
Études des sciences et des technologies0,0060,018
Communication savante0,0160,016
Science ouverte0,0070,011
Intégrité de la recherche0,0070,010
Charge utile insuffisante (le modèle a refusé de juger)0,0100,002

Scores machine (provisoires)

Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.

Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.

Tête enseignante Opus0,035
Tête enseignante GPT0,323
Écart entre enseignants0,288 · la distance entre les deux têtes enseignantes sur ce seul travail
Statut de validationscore_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découle

Classification

machine, non validée

Prédiction automatique; un appel candidat d’une seule source (Gemma direct ou Codex distillé), pas un consensus.

Les modèles n’ont appliqué aucune catégorie : rien dans la taxonomie ne correspondait à ce travail.
Devis d'étudeThéorique ou conceptuel
Domainenon disponible
GenreEmpirique

Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».

En bref

Citations0
Publié2022
Routes d'admission1
Résumé présentoui

Explorer davantage

Même revueeYLS (Yale Law School)Même sujetEthics and Social Impacts of AITravaux en français237 207