🤖 AI Summary
This work addresses the regulatory challenges posed by continuously adaptive generative AI systems, whose autonomous weight updates can render traditional model risk management ineffective and enable providers to conceal changes to evade oversight. To counter this, the paper proposes a dual-track monitoring architecture that integrates discrete and continuous-time telemetry, combining KL divergence–driven event logging with Itô calculus–derived continuous generalization. It formally frames “model hiding” as an adversarial problem, defining six attack classes and corresponding defenses. The approach innovatively introduces model-agnostic components: minimal sufficient auditing statistics tailored for adaptive generative models, tamper-resistant Merkle chains, and a unified telemetry framework. The resulting system satisfies three core regulatory pillars—auditability, tamper resistance, and anti-concealment—and demonstrates that while continuous telemetry is necessary, it must be complemented by periodic intrusive audits, thereby establishing both theoretical and practical foundations for regulating dynamic AI systems.
📝 Abstract
Model risk management (MRM) guidance assumes a static model lifecycle, in which models are developed, independently validated, and implemented without further autonomous modification. Continually self-adapting generative AI systems --- models that update their own weights during production deployment --- fundamentally violate this assumption and render point-in-time validation inadequate. This paper addresses the resulting governance problem in two parts. Part I develops a rigorous telemetry architecture for such models, operating simultaneously in discrete and continuous time. We establish a Minimal Sufficient Statistic for audit purposes, construct a tamper-evident Merkle chain for discrete weight sequences, derive the appropriate continuous-time generalization via the Ito formula, and propose event-driven logging via KL divergence stopping times that is both computationally tractable and meaningful for validation. Part II asks what happens when the model provider is adversarial. A firm deploying such a model has strong incentives to conceal learning updates that would trigger mandatory validation review. We formalize this as the Model Hiding Problem and provide a systematic taxonomy of six distinct attack strategies against the Part I architecture, spanning discrete and continuous time, with a formal countermeasure for each. Together the two parts establish a dual-regime architecture in which continuous telemetry is necessary but not sufficient, narrowing---but never replacing---periodic invasive audit. The framework is model-architecture-agnostic and is designed to satisfy the three pillars of traditional MRM.