Narnaiezzsshaa Truong · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.23021535
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
AI risk registers commonly record a harmful event, likelihood, severity, owner, and listed controls. This structure supports accountability, but it can leave a critical question unanswered: whether the stated controls actually address the mechanism likely to produce the event. This paper argues that control adequacy is a causal hypothesis requiring evidence, not a label. Using a routing-error case study, it shows that identical harmful events can arise through human-performance or model-behavior mechanisms, requiring different control families and different evidence of effectiveness. The resulting gap is not merely a documentation defect. Because governance operates through the artifacts it requires organizations to create, review, and audit, a register schema that does not require mechanism-control-evidence traceability can permit mitigation claims that cannot be tested for adequacy.
No comments yet — start the discussion below.