Source-linked AI summary

Auditing large language models: a three-layered approach

Jakob Mökander, Jonas Schuett, Hannah Rose Kirk, Luciano Floridi

arXiv:2302.08500v2cs.CLcs.AIcs.CY

TL;DR

Existing audits do not adequately address the governance challenges of general-purpose LLMs and their ethical and social risks. The paper proposes a three-layered blueprint linking governance, model, and application audits, and argues that coordinated audits can identify and manage some risks while facing important conceptual and institutional limits.

  • Problem

    Existing application-focused auditing procedures do not adequately address LLMs’ adaptable capabilities, deployment-contextual risks, and unresolved responsibility between providers and downstream developers.

  • Method

    The paper proposes governance audits of providers, model audits before release, and application audits of LLM-based applications that complement and inform one another.

  • Results

    The paper presents coordinated three-level auditing as a feasible and effective mechanism for identifying and managing some ethical and social risks posed by LLMs.

  • Takeaways & Limitations

    The blueprint expands the methodological toolkit for technology providers and policymakers evaluating LLMs from technical, ethical, and legal perspectives.

  • Takeaways & Limitations

    The approach faces construct-validity problems, lacks a settled institutional ecosystem for independent audits, and cannot address all LLM-related risks at the technology level.

Abstract

from arXiv · show

Large language models (LLMs) represent a major advance in artificial intelligence (AI) research. However, the widespread use of LLMs is also coupled with significant ethical and social challenges. Previous research has pointed towards auditing as a promising governance mechanism to help ensure that AI systems are designed and deployed in ways that are ethical, legal, and technically robust. However, existing auditing procedures fail to address the governance challenges posed by LLMs, which display emergent capabilities and are adaptable to a wide range of downstream tasks. In this article, we address that gap by outlining a novel blueprint for how to audit LLMs. Specifically, we propose a three-layered approach, whereby governance audits (of technology providers that design and disseminate LLMs), model audits (of LLMs after pre-training but prior to their release), and application audits (of applications based on LLMs) complement and inform each other. We show how audits, when conducted in a structured and coordinated manner on all three levels, can be a feasible and effective mechanism for identifying and managing some of the ethical and social risks posed by LLMs. However, it is important to remain realistic about what auditing can reasonably be expected to achieve. Therefore, we discuss the limitations not only of our three-layered approach but also of the prospect of auditing LLMs at all. Ultimately, this article seeks to expand the methodological toolkit available to technology providers and policymakers who wish to analyse and evaluate LLMs from technical, ethical, and legal perspectives.

1 Introduction

LLMs’ generality and widespread use create ethical, social, and governance challenges that existing application-focused audits do not fully address. The article proposes a coordinated three-layered auditing blueprint spanning providers, models, and applications, while acknowledging limits on its scope and effectiveness.

  • Motivation: Foundation models can be adapted across downstream tasks, making risks difficult to assess independently of deployment context and leaving responsibility between providers and developers unresolved.Existing application-level auditing therefore requires complementary supervision and control.
  • Motivation: LLMs pose risks involving discrimination, privacy, misinformation, malicious use, human-computer interaction, automation, and environmental harms.Their public visibility and growing user bases have expanded the potential impact of these challenges.
  • Contribution: The article proposes governance, model, and application audits that complement and inform one another.Governance audits cover technology providers, model audits examine pretrained LLMs before release, and application audits assess LLM-based applications.
  • Contribution: A structured and coordinated procedure combines audit outputs across the three levels so that findings at one level inform audits at the others.The blueprint is presented as a way to support assessment of whether LLMs are legal, ethical, and technically robust.
  • Contribution: The article also develops seven design claims for feasible and effective LLM auditing and identifies conceptual, technical, and practical limitations.These contributions are intended to provide groundwork for more refined auditing procedures.
  • Scope: The proposed approach is intentionally limited to what should be audited, when, and according to which criteria, excluding institutional design and post-audit action.The authors frame this boundary as a way to initiate policy formation rather than address the full auditing ecosystem.

2 The need to audit LLMs

LLMs offer broad capabilities but create substantial ethical and social risks that existing governance and auditing approaches do not fully address. The paper therefore develops a coordinated auditing blueprint while acknowledging that auditing has important limits.

  • LLMs can recognise, summarise, translate, and generate text, with near human-like performance on some tasks.
  • LLMs pose risks including discrimination, privacy breaches, misinformation, malicious use, plagiarism, and misuse of copyrighted material.
  • LLM performance can be predictable generally but unpredictable on specific tasks or at scale, raising questions about access and permitted uses.
  • The paper proposes governance, model, and application audits that complement and inform one another.
  • Audits cannot identify and mitigate every LLM-related risk because normative values may conflict and auditing procedures face practical and conceptual difficulties.

3 The merits and limits of existing AI auditing procedures

Existing AI auditing is a broad, multidisciplinary governance practice, but procedures designed for specific systems and contexts are insufficient for LLMs. The paper derives design claims supporting coordinated, independent, adaptive audits across governance, model, and application levels.

  • AI auditing encompasses systematic, independent evaluation of an AI system, organisation, process, or combination thereof, with results communicated to stakeholders.
  • Existing procedures vary in purpose and effectiveness, and LLM auditing must account for technical limitations, institutional access, and administrative costs.
  • Compliance audits compare conduct with predefined standards, whereas risk audits ask open-ended questions to identify and control risks.
  • Compliance alone is unlikely to provide adequate assurance for LLMs, so the blueprint combines risk audits at governance and model levels with compliance audits at the application level.
  • External audits are required for ethical, legal, and technical robustness, while effective procedures also require provider collaboration and governance and technology audit elements.
  • Technology audits require significant modification for LLMs, whose generality and downstream applications exceed the scope of traditional function-specific audits.
  • Model audits help identify and communicate limitations, inform redesign, mitigate downstream harm, and complement governance and application audits.
  • Effective LLM auditing must include continuous ex-post auditing and post-market monitoring of application outputs.

4 Auditing LLMs: A three-layered approach

The proposed blueprint combines governance, model, and application audits in a coordinated process designed to identify LLM-related risks across development and deployment. Each layer has a distinct focus, while their boundaries can overlap and their outputs inform audits at other levels.

  • The blueprint combines governance, model, and application audits in a structured process intended to identify LLM-related risks.The proposal selects activities considered jointly sufficient, practically feasible, and cost-beneficial.
  • Governance audits: Governance audits assess providers’ organisational procedures, accountability structures, incentive structures, and management systems.They can produce reports for provider management, law enforcers, and downstream application developers.
  • Model audits: Model audits assess LLM capabilities and limitations after initial training but before adaptation and deployment in specific applications.The model-level scope is limited because some risks, such as unjust discrimination, are context-dependent and difficult to operationalise at the model level.
  • Application audits: Application audits continuously assess downstream applications’ intended functions, legal compliance, and impacts on users, groups, societies, and the natural environment.They include functionality audits and impact audits, which are complementary components.
  • Connecting the layers: Outputs from one audit level become inputs for audits at other levels, linking provider governance, model properties, and application impacts.Model reports should inform application audits, while ex-post application logs should inform continuous model redesign and revision.
  • Application audits: The approach recommends obligatory governance and model audits, while application audits should be employed more selectively and their results made publicly available at least in summary form.The authors distinguish application auditing from certification, which requires predefined standards and institutional arrangements.

5 Limitations and avenues for further research

The proposed auditing blueprint faces conceptual, institutional, and practical limits. Its effectiveness depends on better metrics, credible audit institutions, and realistic expectations about which LLM risks audits can address.

  • 5.1 Lack of methods and metrics to operationalise normative concepts: Construct validity limits model audits because metrics may fail to measure normative characteristics such as robustness and truthfulness accurately.These problems also affect operationalisations of performance and information security.
  • 5.2 Lack of an institutional ecosystem: The blueprint does not decisively identify who should conduct the three audits, while institutional ecosystems for AI audits are still emerging.Possible arrangements include private providers, government agencies, industry bodies, non-profits, and international organisations.
  • 5.2 Lack of an institutional ecosystem: Private auditors may face collusion risks, whereas government-led audits may improve independence and uniformity but stifle innovation, lengthen lead times, or lack legitimacy across jurisdictions.These trade-offs make institutional design consequential for audit credibility and feasibility.
  • 5.2 Lack of an institutional ecosystem: Without clear institutional arrangements, claims that an LLM has been audited are difficult to verify and may exacerbate harms.Further research should examine the feasibility and effectiveness of arrangements for conducting and enforcing all three audit types.
  • 5.3 Limits of auditing LLMs: Audits cannot eliminate LLM risks because residual risks remain, deliberate misuse creates an offensive-defensive asymmetry, and some problems require social or political reform.Economic changes linked to automation may therefore be better addressed through broader reform than technology-specific audits.

6 Conclusion

The article concludes that governance, model, and application audits should be coordinated to audit LLMs across providers, models, and downstream uses. The approach can strengthen governance, but its effectiveness is constrained by measurement, institutional, and political limits and must adapt to future technological change.

  • 6 Conclusion: Existing auditing procedures are not well-equipped to assess whether provider and downstream-developer checks and balances ensure good governance of LLMs.LLMs’ adaptability across downstream applications undermines verification procedures built on fixed specifications and predictable environments.
  • 6 Conclusion: Governance audits evaluate providers’ accountability and quality-management systems, model audits assess model characteristics, and application audits examine legal compliance and impacts.Model dimensions include performance, robustness, information security, and truthfulness; applications are evaluated for effects on users, groups, and the environment.
  • 6 Conclusion: The three audit levels are effective only when conducted in a combined and coordinated fashion, using existing tools such as impact assessments, benchmarking, model evaluation, and red teaming.The audits are intended to inform and complement one another rather than replace existing governance mechanisms.
  • 6 Conclusion: The blueprint’s effectiveness is limited by construct-validity problems, unspecified institutional responsibility, and risks that require public deliberation or structural reform rather than auditing.These limitations remain even under ideal implementation conditions.
  • 6 Conclusion: Future research should develop verifiable, construct-valid metrics and further disentangle the sources of different LLM risks.Policymakers can support an audit ecosystem through metric standardisation, regulatory harmonisation, knowledge sharing, and incentives.
  • 6 Conclusion: The blueprint may inform audits of other generative machine-learning technologies, but future democratisation, fragmentation, and personalisation may require continual revision.Open-source development could challenge governance audits, while user-specific model branches could complicate standardised model audits.

A Methodology

The authors use a pragmatist, applied approach to design an actionable LLM-auditing blueprint. They review existing procedures, build a typology and gap analysis, select a minimal blueprint, and refine it through stakeholder triangulation.

  • A Methodology: The methodology adopts a pragmatist stance grounded in real-world governance problems and actionable policy questions.The authors treat designing LLM-auditing procedures as an art requiring systematic engagement with prior research and stakeholders.
  • A Methodology: The research process was iterative rather than strictly sequential, despite being presented as five steps.The authors note that the steps overlapped thematically and chronologically.
  • A Methodology: A systematised literature review mapped existing auditing procedures across five databases and risk-related search terms.The databases were Google Scholar, Scopus, SSRN, Web of Science, and arXiv.
  • A Methodology: The authors constructed a typology distinguishing audit dimensions including risk, compliance, internal, external, ex-ante, ex-post, functionality, code, and impact audits.Possible auditing procedures are combinations of these elements.
  • A Methodology: A gap analysis compared LLM governance challenges with the theoretical affordances of existing auditing procedures to generate six design claims.The claims were intended to capture the full range of risks posed by LLMs.
  • A Methodology: The draft blueprint selected the smallest set of auditing procedures satisfying the six claims, while limiting counterproductive overlap between regimes.Some redundancy can support safety engineering, but excessive overlap can blur roles and responsibilities.
  • A Methodology: The authors refined and validated the blueprint by triangulating sources and consulting more than 20 researchers, auditors, developers, and policymakers.The final blueprint resulted from semi-structured interviews and stakeholder feedback across jurisdictions.
Loading 2302.08500v2…