The rapid development of artificial intelligence (AI) has led to increasing concerns about the capability of AI systems to make decisions and behave responsibly. Responsible AI (RAI) refers to the development and use of AI systems that benefit humans, society, and the environment while minimising the risk of negative consequences. To ensure responsible AI, the risks associated with AI systems' development and use must be identified, assessed and mitigated. Various AI risk assessment frameworks have been released recently by governments, organisations, and companies. However, it can be challenging for AI stakeholders to have a clear picture of the available frameworks and determine the most suitable ones for a specific context. Additionally, there is a need to identify areas that require further research or development of new frameworks, as well as updating and maintaining existing ones. To fill the gap, we present a mapping study of 16 existing AI risk assessment frameworks from the industry, governments, and non-government organizations (NGOs). We identify key characteristics of each framework and analyse them in terms of RAI principles, stakeholders, system lifecycle stages, geographical locations, targeted domains, and assessment methods. Our study provides a comprehensive analysis of the current state of the frameworks and highlights areas of convergence and divergence among them. We also identify the deficiencies in existing frameworks and outlines the essential characteristics of a concrete and connected framework AI risk assessment (C$^2$AIRA) framework. Our findings and insights can help relevant stakeholders choose suitable AI risk assessment frameworks and guide the design of future frameworks towards concreteness and connectedness.
翻译:人工智能的快速发展引发了对AI系统决策与负责任行为能力的日益关注。负责任人工智能(RAI)旨在开发和使用能够造福人类、社会与环境,同时最小化负面后果风险的AI系统。为确保负责任的AI,必须识别、评估并缓解与AI系统开发和应用相关的风险。近期,政府、组织和企业发布了多种AI风险评估框架。然而,AI利益相关方难以全面了解现有框架并确定特定场景下的最适选择。此外,亟需识别需要进一步研究或开发新框架的领域,并更新和维护现有框架。为填补这一空白,我们对来自行业、政府及非政府组织(NGO)的16个现有AI风险评估框架进行了映射研究。我们识别了每个框架的关键特征,并从RAI原则、利益相关方、系统生命周期阶段、地理区域、目标领域及评估方法等方面进行分析。本研究提供了对框架现状的全面分析,揭示了框架间的趋同与分歧领域。我们还指出了现有框架的不足,并勾勒了具体与互联的AI风险评估(C$^2$AIRA)框架的核心特征。我们的发现与见解可帮助相关利益方选择合适的AI风险评估框架,并指导未来框架设计向具体性与互联性方向发展。