The governance of artificial intelligence has a blind spot: the machine identities that AI systems use to act. AI agents, service accounts, API tokens, and automated workflows now outnumber human identities in enterprise environments by ratios exceeding 80 to 1, yet no integrated framework exists to govern them. A single ungoverned automated agent produced $5.4-10 billion in losses in the 2024 CrowdStrike outage; nation-state actors including Silk Typhoon and Salt Typhoon have operationalized ungoverned machine credentials as primary espionage vectors against critical infrastructure. This paper makes four original contributions. First, the AI-Identity Risk Taxonomy (AIRT): a comprehensive enumeration of 37 risk sub-categories across eight domains, each grounded in documented incidents, regulatory recognition, practitioner prevalence data, and threat intelligence. Second, the Machine Identity Governance Taxonomy (MIGT): an integrated six-domain governance framework simultaneously addressing the technical governance gap, the regulatory compliance gap, and the cross-jurisdictional coordination gap that existing frameworks address only in isolation. Third, a foreign state actor threat model for enterprise identity governance, establishing that Silk Typhoon, Salt Typhoon, Volt Typhoon, and North Korean AI-enhanced identity fraud operations have already operationalized AI identity vulnerabilities as active attack vectors. Fourth, a cross-jurisdictional regulatory alignment structure mapping enterprise AI identity governance obligations under EU, US, and Chinese frameworks simultaneously, identifying irreconcilable conflicts and providing a governance mechanism for managing them. A four-phase implementation roadmap translates the MIGT into actionable enterprise programs.
翻译:人工智能治理存在一个盲区:AI系统用以执行操作的身份凭证。在企业环境中,AI代理、服务账号、API令牌及自动化工作流的数量已超过人类身份的80倍以上,然而目前尚无综合框架对其进行治理。2024年CrowdStrike事件中,一个未受监管的自动化代理造成了54亿至100亿美元的损失;包括"丝绸之路"黑客组织(Silk Typhoon)和"盐台风"(Salt Typhoon)在内的国家级行为体,已将未受监管的机器凭证作为针对关键基础设施的主要间谍攻击载体。本文提出四项原创性贡献。第一,AI-身份风险分类法(AIRT):系统梳理涵盖八个领域的37个风险子类别,每项均基于已记录事件、监管认定、从业者普遍性数据及威胁情报。第二,机器身份治理分类法(MIGT):一个整合六大领域的治理框架,同步解决现有框架各自孤立应对的技术治理缺口、法规合规缺口及跨司法管辖协调缺口。第三,面向企业身份治理的外国国家行为体威胁模型,证实"丝绸之路"、"盐台风"、"伏特台风"(Volt Typhoon)及朝鲜AI增强型身份欺诈行动已将AI身份漏洞转化为活跃攻击向量。第四,跨司法管辖监管对齐架构:同时映射欧盟、美国及中国框架下的企业AI身份治理义务,识别不可调和冲突并提供管理此类冲突的治理机制。一个四阶段实施路线图将MIGT转化为可操作的企业方案。