AI governance methods for controlling models during use

Beyond Training: A Feasibility Taxonomy for Inference-Time AI Governance

Computers and SocietyArtificial IntelligenceCryptography and Security

Summary

Current AI rules focus mainly on the training phase where models learn from data. The authors point out that important control can also happen when AI models are being used, not just when they are trained. They studied 20 ways to monitor and control models during use and rated how ready these methods are in real-world settings. Their analysis shows most methods work well for ordinary users but struggle against powerful, potentially malicious actors.

What this means in practice

  • For ai platform operators: Improve monitoring and enforcement strategies for AI models during deployment to ensure safer use and compliance with governance rules.
  • For policy makers: Develop regulations that govern AI use beyond training by applying tested mechanisms that detect and control improper deployment behaviors.

Authors

Samar Ansari

Abstract

Compute governance today is a governance of training: the thresholds, reporting requirements, and frontier-AI regimes now in force attach to training compute and treat the trained model as the regulatory unit. That picture is incomplete: capability increasingly migrates to the deployment stage through inference-time scaling, agentic scaffolding, and compression onto consumer hardware. This paper asks which mechanisms are available once the regulatory object shifts from the training run to the inference call. We develop a feasibility taxonomy of twenty inference-time mechanisms across monitoring, verification, and enforcement, each rated on a four-point readiness scale against a documented four-vendor evidence base. We then stress the taxonomy against a two-dimensional adversary model (three capability tiers crossed with four adversary roles) and map each mechanism to four governance scenarios (domestic regulation, bilateral or multilateral coordination, industry self-regulation, and compute-marketplace governance). Fifteen of the twenty mechanisms have commercial technical substrates in production today, although governance-grade assurance and adversarial robustness vary substantially. The adversary analysis shows that this readiness holds only against a cooperative deployer and a low-to-medium-capability user: no mechanism rates adequate against a high-capability state-level deployer, and fine-tuning removes the model-internal components of the enforcement cluster, although platform-external controls can persist. A substitution analysis connects the taxonomy to a companion hardware paper as a conditional substitution principle describing when inference-stage and hardware-stage mechanisms provide comparable regulatory coverage under stated conditions. A second-rater reliability check on a random subset of the readiness ratings returned a quadratic-weighted Cohen's kappa of 0.74.