arXiv AI

Inferential Capability Does Not Determine Legal Scope

arXiv:2608. 10601v1 Announce Type: cross Abstract: Two instruments of EU digital law place inference at their centre and mean different things by it.

arXiv AI
Sep 15

From Legal Text to AI-specific Risk Sources: A Systematic Analysis of the EU AI Act's High-Risk Requirements

The paper systematically classifies the EU AI Act’s high‑risk requirements, finding that only a minority directly address AI‑specific risk sources while most impose organizational and documentation obligations. From these risk‑related requirements, the authors derive a consolidated list of distinct AI‑specific risk sources, creating an EU AI Act Risk Source List. This list aims to bridge the gap between legal obligations and AI risk‑management practice by providing a structured reference for comparing the Act’s implicit risk coverage with existing AI risk taxonomies.

By Ronald Schnitzer, Mike Auer, Rumpa Choudhury, Andreas Hapfelmeier, Maximilian Hoeving, Isabelle Painter, Josiane Xavier Parreira, Sonja Zillner
arXiv AI
Sep 10

Causal Attribution for Agentic Decisions: Estimators, Coupling, and a Traceability Specification

The paper presents a framework for causal attribution in agentic AI systems, outlining estimators and conditions where they fail. It distinguishes between marginal total effects and common‑random‑number total effects, introduces a natural direct effect under pinned downstreams, and derives a coupling method to keep direct effects estimable. The authors also propose a traceability specification to meet upcoming regulatory requirements for high‑risk AI systems.

By Ajay Pravin Mahale (Hochschule Trier)
arXiv AI
Aug 18

Generated Context versus Governed State: Functional Conditions for Accountable Longitudinal Clinical Reasoning

arXiv:2608. 14804v1 Announce Type: new Abstract: Large language models (LLMs) have become the dominant interface of clinical artificial intelligence, yet the interface they expose (text in, text out, one context window at a time) maintains no explicit, persistent, governed representation of what is currently true about a patient.

By Augusto Bernardo Pissarra, Victor Lorena de Farias Souza
arXiv AI
Sep 18

Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems

The paper introduces Governance-as-Code (GaC), a framework that translates the EU AI Act’s technical requirements into 43 machine‑checkable acceptance criteria across six compliance modules. GaC runs within a CI/CD pipeline, producing Article‑indexed audit evidence and providing actual Rego policy code. The authors validate GaC on two enterprise deployments, showing it reproduces manual audit findings—including three penalty‑triggering violations—while reducing audit labor by about 75%.

By Rudrendu Kumar Paul, Sourav Nandy