As artificial intelligence (AI) becomes increasingly embedded in digital, social, and institutional infrastructures, and AI and platforms are merged into hybrid structures, systemic risk has emerged as a critical but undertheorized challenge. In this paper, we develop a rigorous framework for understanding systemic risk in AI, platform, and hybrid system governance, drawing on insights from finance, complex systems theory, climate change, and cybersecurity - domains where systemic risk has already shaped regulatory responses. We argue that recent legislation, including the EU's AI Act and Digital Services Act (DSA), invokes systemic risk but relies on narrow or ambiguous characterizations of this notion, sometimes reducing this risk to specific capabilities present in frontier AI models, or to harms occurring in economic market settings. The DSA, we show, actually does a better job at identifying systemic risk than the more recent AI Act. Our framework highlights novel risk pathways, including the possibility of systemic failures arising from the interaction of multiple AI agents. We identify four levels of AI-related systemic risk and emphasize that discrimination at scale and systematic hallucinations, despite their capacity to destabilize institutions and fundamental rights, may not fall under current legal definitions, given the AI Act's focus on frontier model capabilities. We then test the DSA, the AI Act, and our own framework on five key examples, and propose reforms that broaden systemic risk assessments, strengthen coordination between regulatory regimes, and explicitly incorporate collective harms.
翻译:随着人工智能日益嵌入数字、社会与制度基础设施,且人工智能与平台融合为混合结构,系统性风险已成为一项关键但理论建构不足的挑战。本文借鉴金融学、复杂系统理论、气候变化与网络安全等已形成系统性风险监管响应的领域,构建了理解人工智能、平台及混合系统治理中系统性风险的严谨框架。我们论证指出,包括欧盟《人工智能法案》与《数字服务法案》在内的近期立法虽援引系统性风险概念,但对该概念的界定存在狭隘或模糊之处,有时将其简化为前沿人工智能模型中的特定能力,或经济市场情境中产生的危害。研究表明,《数字服务法案》在识别系统性风险方面实际上比近期出台的《人工智能法案》表现更优。本框架揭示了新型风险路径,包括多个人工智能智能体交互可能引发的系统性失效。我们识别了人工智能相关系统性风险的四个层级,并强调:鉴于《人工智能法案》聚焦于前沿模型能力,大规模歧视与系统性幻觉——尽管其具备破坏制度运行与基本权利稳定性的能力——可能未纳入现行法律定义范畴。最后,我们以五个关键案例检验《数字服务法案》、《人工智能法案》及本文框架,并提出拓宽系统性风险评估、强化监管机制间协调、明确纳入集体损害等改革建议。