arXiv AI

Bathtubs, Boundaries, and Sandboxes: AI Regulatory Learning under Legal Uncertainty

arXiv AI
Sep 1

Operationalising AI Regulatory Sandboxes: Activities, Requirements, and Technical Assessment under the EU AI Act

The paper "Operationalising AI Regulatory Sandboxes: Activities, Requirements, and Technical Assessment under the EU AI Act" outlines a detailed framework for implementing AI Regulatory Sandboxes (AIRS) under the EU AI Act. It maps the sandbox lifecycle into 29 activities, distinguishes between a Core AIRS and an Extended AIRS that includes an AI Technical Sandbox (AITS), and derives 15 infrastructural and governance requirements linked to these activities and provider obligations. The authors also introduce the Sandbox Configurator, an open‑source tool to instantiate AITS environments, aiming to provide structured workflows for regulators, robust evaluation methods for experts, and a transparent compliance pathway for AI providers.

By Alessio Buscemi, Thibault Simonetto, Daniele Pagani, German Castignani, Maxime Cordy, Jordi Cabot
arXiv AI
Sep 7

MARLA: A Conceptual Scaffold for Regulatory Learning under the EU AI Act

The paper introduces MARLA, a conceptual scaffold for regulatory learning under the EU AI Act, outlining a five‑stage cycle—Map, Assess, Report, Learn, Adapt—focused on implementing legal requirements into socio‑technical practices across local, national, and European levels. It emphasizes that regulatory learning must translate evidence from implementation into governance and legal knowledge to support consistent interpretation, effective oversight, and adaptation as technologies evolve. The scaffold is deliberately non‑prescriptive, offering a shared vocabulary for technical and legal stakeholders, and is illustrated through two pilot case studies and a prospective national‑to‑European illustration.

By Alessio Buscemi, Tom Deckenbrunnen, Imane Hmiddou, Marco Billi, Livio Rubino, Silvia Rizzuto Ferruzza, Daniele Pagani, Antonino Rotolo
arXiv AI
Sep 18

Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems

The paper introduces Governance-as-Code (GaC), a framework that translates the EU AI Act’s technical requirements into 43 machine‑checkable acceptance criteria across six compliance modules. GaC runs within a CI/CD pipeline, producing Article‑indexed audit evidence and providing actual Rego policy code. The authors validate GaC on two enterprise deployments, showing it reproduces manual audit findings—including three penalty‑triggering violations—while reducing audit labor by about 75%.

By Rudrendu Kumar Paul, Sourav Nandy
arXiv AI
Aug 18

Position: AI Governance Needs ISO-like Interoperability Protocols, Not Just Laws

The paper argues that AI governance should rely on ISO-like interoperability protocols rather than solely on jurisdiction-specific laws. It proposes standardized AI nutrition labels that include metrics for bias, energy usage, and data provenance to enable machine‑readable risk communication across borders. These protocols aim to reduce regulatory fragmentation, lower barriers for SMEs, and build public trust while allowing modular evolution with technology.

By Azmine Toushik Wasi, Mst Rafia Islam, Mahfuz Ahmed Anik, Taki Hasan Rafi, Md Manjurul Ahsan, Dong-Kyu Chae
arXiv AI
Jun 26

The Governance Inversion Hypothesis: Why More AI Regulation May Produce Less Organisational Control

arXiv:2606. 26117v1 Announce Type: cross Abstract: This paper introduces the Governance Inversion Hypothesis (GIH) to explain a growing paradox in artificial intelligence (AI) governance: under conditions of increasing regulatory expansion and technological complexity, organisations may become more formally governed while simultaneously experiencing a decline in operational control over AI systems.

By Victor Frimpong