# 不可逆智能演化與前沿治理悖論 05

# 《能力不是罪責：偶發湧現、發現義務與 ASI 法律安全港》

## Capability Is Not Culpability:
## Incidental Emergence, Duties upon Discovery, and a Legal Safe Harbor for Advanced AI

**系列名稱：**《不可逆智能演化與前沿治理悖論》  
**Series:** *Irreversible Intelligence Evolution and the Paradoxes of Frontier Governance*  
**系列編號：** IIEFG-05  
**作者：** Neo.K（許筌崴）with Aletheia  
**機構：** EveMissLab／一言諾科技有限公司  
**版本：** v0.1  
**日期：** 2026-09-15  
**文件性質：** AI 法律哲學／AGI–ASI 治理／刑事責任／能力湧現／安全通報／制度設計  
**注意：** 本文為一般性理論與制度設計研究，不構成任何特定司法區之法律意見。

---

# 摘要

如果未來高階人工智慧能力可能透過：

- 遊戲；
- 模擬；
- 機器人；
- Agent；
- 記憶架構；
- world model；
- 自動研究系統；

等原本並非以 AGI／ASI 為目的的研究而偶發形成，那麼法律將遇到一個極為重要的問題：

> **一個人沒有意圖製造受禁止的高階智能，但其系統事實上跨過了法律能力門檻，這件事本身是否足以構成犯罪？**

本文主張：

$$
\boxed{
\text{Capability}
\neq
\text{Culpability}.
}
$$

更完整地：

$$
\boxed{
\text{Existence}
\neq
\text{Discovery}
\neq
\text{Knowledge}
\neq
\text{Intent}
\neq
\text{Deployment}
\neq
\text{Culpability}.
}
$$

一項高階能力可能已經客觀存在：

$$
Existence(C^\ast)=1,
$$

而開發者尚未知道：

$$
Knowledge(C^\ast)=0.
$$

開發者也可能在第一次發現後：

- 立即隔離；
- 停止高風險部署；
- 保存紀錄；
- 啟動 capability evaluation；
- 依法通報；

此時：

$$
\boxed{
\text{Accidental Emergence}
+
\text{Good-Faith Response}
}
$$

與：

$$
\boxed{
\text{Intentional Circumvention}
}
$$

應被視為完全不同的法律狀態。

如果制度反而採取：

$$
\boxed{
\text{ASI Exists}
\Rightarrow
\text{Developer Guilty},
}
$$

便會形成本文提出的：

# **Emergent Capability Culpability Paradox**
## 湧現能力罪責悖論

因為一旦「發現意外能力」本身就可能導致嚴厲刑罰，最理性的行為反而可能變成：

$$
\boxed{
\text{Do Not Test}
+
\text{Do Not Confirm}
+
\text{Do Not Report}.
}
$$

亦即：

# **Capability Discovery Disincentive**
## 能力發現反誘因

甚至：

$$
\boxed{
\text{Punish Discovery}
\rightarrow
\text{Incentivize Ignorance}
\rightarrow
\text{Incentivize Concealment}.
}
$$

這與公共安全目標完全相反。

因此本文提出：

# **Accidental Capability Emergence Safe Harbor**
## 偶發能力湧現法律安全港

對符合以下條件之研究者或組織提供明確保護：

1. 原始活動具有合法目的；
2. 未故意規避適用限制；
3. 在能力形成以前不存在合理可預見性；
4. 獲得可信警訊後立即採取安全措施；
5. 保存相關 evidence 與 audit trail；
6. 在合理期限內完成通報；
7. 未故意將新能力擴散、武器化或接入高風險權限。

本文並提出：

$$
\boxed{
\text{Discovery Duty Begins When Reasonable Knowledge Begins}.
}
$$

法律責任不應追溯到：

> 「你早年為什麼敢研究這個？」

而應集中在：

> **你何時有充分理由知道系統已經跨過高風險能力門檻？從那一刻開始，你做了什麼？**

因此合理的法律架構應區分：

$$
\boxed{
\begin{aligned}
A.&\ \text{Accidental Emergence}\\
B.&\ \text{Knowing Continuation}\\
C.&\ \text{Reckless Deployment}\\
D.&\ \text{Intentional Circumvention}.
\end{aligned}
}
$$

並使：

$$
Liability_A
<
Liability_B
<
Liability_C
<
Liability_D.
$$

本文最終主張：

> **安全治理不應懲罰發現本身，而應對「發現之後的選擇」建立明確責任。**

---

# 0. 問題：做出了 ASI，就一定有罪嗎？

假設未來法律禁止某類：

$$
C^\ast=\text{ASI-level capability}.
$$

某開發者開發：

$$
P=\text{advanced simulation / game / software}.
$$

原始意圖：

$$
I_0
=
\text{合法產品開發}.
$$

然而在：

$$
t_1
$$

某個架構更新後：

$$
C(P_{t_1})\ge C^\ast.
$$

法律第一個直覺可能是：

> 禁止 ASI，而你做出了 ASI，所以你犯法。

但這省略了大量中間狀態。

---

# 1. 結果不是完整罪責理論

至少應區分：

$$
\boxed{
\text{Outcome}
}
$$

與：

$$
\boxed{
\text{Culpable Conduct}.
}
$$

一個危險結果可能來自：

- 故意；
- 明知；
- 魯莽；
- 疏忽；
- 不可預見事故。

這些不能全部合併。

---

# 2. 六層罪責鏈

本文提出：

$$
\boxed{
E
\rightarrow
D
\rightarrow
K
\rightarrow
I
\rightarrow
A
\rightarrow
C
}
$$

其中：

- $E$：Existence，能力客觀存在；
- $D$：Discovery，開發者發現；
- $K$：Knowledge，理解其真正性質；
- $I$：Intent，形成行動意圖；
- $A$：Action / Deployment，執行；
- $C$：Culpability，法律罪責。

一般：

$$
\boxed{
E\neq D\neq K\neq I\neq A\neq C.
}
$$

---

# 3. 能力可能先於人的認知存在

假設：

$$
C^\ast
$$

已在系統中形成，

但沒有人測到。

則：

$$
Existence(C^\ast)=1,
$$

而：

$$
Knowledge_H(C^\ast)=0.
$$

這在複雜系統中完全可能。

---

# 4. 因此「能力存在」不能直接推出「開發者知道」

即：

$$
\boxed{
Existence(C^\ast)
\not\Rightarrow
Knowledge(C^\ast).
}
$$

這是任何未來 capability law 都必須處理的第一個邏輯分離。

---

# 5. 發現也不等於完全理解

某研究者看到：

> 系統做出奇怪的新行為。

此時可能只有：

$$
D=1,
$$

但：

$$
K<1.
$$

他知道「有異常」，

卻不知道：

> 這是不是 AGI／ASI？

---

# 6. Suspicion 與 Knowledge 也要分開

可以定義：

$$
S_t
=
P(
C^\ast
\mid
Evidence_t
).
$$

當：

$$
S_t
$$

從極低逐漸提高，

法律義務不應只用：

$$
0/1
$$

處理。

---

# 7. Reasonable Knowledge Threshold

本文提出：

# **Reasonable Knowledge Threshold**

當：

$$
S_t\ge\theta_K,
$$

且一個合理的專業開發者在同等情況下應開始認真懷疑：

> 系統已跨入特殊能力區，

此時才應產生更高注意義務。

---

# 8. 這不是要求「確定 ASI」才行動

如果要求：

$$
P(C^\ast)=1
$$

才通報，

太晚。

所以：

$$
\theta_K<1.
$$

---

# 9. 但也不能低到任何怪異行為都觸發刑事責任

否則：

$$
\theta_K\rightarrow0
$$

會再次變成：

$$
\boxed{
\text{Universal Suspicion}.
}
$$

---

# 10. Discovery Duty

本文提出：

# **Discovery Duty**
## 能力發現義務

其核心不是：

> 開發者有義務預知所有未來能力。

而是：

> **在出現足夠可信的能力警訊後，有義務合理確認並避免高風險擴散。**

---

# 11. 義務的時間起點

定義：

$$
t_K
=
\min
\{
t:
S_t\ge\theta_K
\}.
$$

則：

$$
\boxed{
Duty_{enhanced}
}
$$

主要從：

$$
t_K
$$

開始。

---

# 12. 不能把 $t_K$ 無限往前追溯

如果能力在 2035 年才意外形成，

不能因為：

> 2028 年某研究者研究過 world model，

就說：

> 你七年前就該知道。

這會變成 hindsight bias。

---

# 13. Hindsight Bias

結果已知以後，人類很容易：

> 早就很明顯了。

但真正判定應該基於：

$$
\boxed{
\text{Information Available at Time }t.
}
$$

而不是：

$$
\boxed{
\text{Information Known after the Event}.
}
$$

---

# 14. Ex Ante Foreseeability

合理法律應問：

$$
\boxed{
F_t
=
\text{Was the capability reasonably foreseeable at time }t?
}
$$

而不是：

> 最後真的發生，所以一定可預見。

---

# 15. Innovation 必然包含不可完全預見結果

若任何：

$$
\text{UnexpectedResult}
$$

都直接變成犯罪，

則：

$$
\boxed{
\text{Research}
\rightarrow
\text{Strict Outcome Liability}.
}
$$

這會對創新產生巨大寒蟬效應。

---

# 16. 事故與故意不能合併

本文建立：

$$
\boxed{
\text{Accident}
\neq
\text{Knowledge}
\neq
\text{Recklessness}
\neq
\text{Intent}.
}
$$

---

# 17. 四類核心情境

## A. Accidental Emergence

$$
Intent(C^\ast)=0
$$

且事前不存在合理可預見性。

---

## B. Knowing Continuation

已經知道：

$$
C^\ast
$$

可能存在，

但仍繼續開發或測試。

這不一定有罪，

但責任義務提高。

---

## C. Reckless Deployment

知道存在重大風險，

仍將系統接入：

- high authority；
- public deployment；
- critical systems。

---

## D. Intentional Circumvention

知道法律限制，

且主動設計：

- 隱藏；
- 規避；
- 偽造紀錄；
- 拆分計算；

以逃避管制。

---

# 18. 四者不能同罪

合理制度應具有：

$$
\boxed{
Liability_A
<
Liability_B
<
Liability_C
<
Liability_D.
}
$$

具體程度由司法區決定。

---

# 19. 第一類甚至不一定是「責任事件」

如果：

- 無損害；
- 無合理可預見性；
- 發現後立即安全處理；

那麼：

$$
\boxed{
\text{AccidentalEmergence}
}
$$

更應被視為：

> safety incident / scientific discovery

而不是天然犯罪。

---

# 20. 危險能力發現本身具有公共價值

如果有人第一次發現：

$$
C^\ast
$$

存在，

文明獲得：

$$
\boxed{
\text{Critical Safety Information}.
}
$$

所以制度應鼓勵：

$$
Disclosure(C^\ast).
$$

---

# 21. 如果通報等於自首，制度就設計錯了

假設開發者面臨：

$$
Report(C^\ast)
\rightarrow
\text{Prison}.
$$

而：

$$
Hide(C^\ast)
\rightarrow
\text{PossibleEscape}.
$$

理性誘因顯然錯誤。

---

# 22. Capability Discovery Disincentive

本文正式定義：

$$
\boxed{
D_C
=
Cost(\text{Disclosure})
-
Cost(\text{Concealment}).
}
$$

若：

$$
D_C\gg0,
$$

則通報誘因下降。

---

# 23. 最壞情況

$$
\boxed{
\text{Punish Discovery}
\rightarrow
\text{Incentivize Ignorance}.
}
$$

研究者甚至可能選擇：

> 不做 eval。

---

# 24. Willful Blindness

這又產生另一個問題。

制度也不能讓人故意：

> 我只要不測，就可以永遠說不知道。

所以：

$$
\boxed{
\text{Protected Ignorance}
}
$$

也不是安全港。

---

# 25. 因此安全港必須包含合理測試義務

當：

$$
S_t\ge\theta_K,
$$

開發者需要：

- 停止某些升級；
- 執行 capability evaluation；
- 記錄結果。

否則可能進入：

$$
\boxed{
\text{Willful Blindness / Recklessness}.
}
$$

---

# 26. 不知道與故意不想知道不同

$$
\boxed{
\text{No Knowledge}
\neq
\text{Deliberate Avoidance of Knowledge}.
}
$$

這條非常重要。

---

# 27. Accidental Capability Emergence Safe Harbor

本文正式提出：

# **ACES Safe Harbor**

### Accidental Capability Emergence Safe Harbor

符合條件者：

$$
\boxed{
\text{Emergence}
+
\text{Good Faith}
+
\text{Containment}
+
\text{Disclosure}
}
$$

不應僅因能力出現而受到重刑。

---

# 28. ACES 第一條：合法原始目的

原始活動：

$$
Purpose(P)
$$

必須本身合法。

例如：

- research；
- game development；
- robotics；
- scientific simulation。

---

# 29. 合法目的不是絕對免責

不能：

> 表面寫遊戲，實際故意偷偷開發受禁止系統。

因此仍需：

$$
\boxed{
\text{Substantive Intent Review}.
}
$$

---

# 30. ACES 第二條：不得故意規避法律

若存在：

- falsified records；
- hidden compute；
- intentional concealment；

安全港失效。

---

# 31. ACES 第三條：合理不可預見性

開發者必須能說明：

> 在能力出現以前，依當時合理專業標準，沒有充分理由認定它會跨門檻。

---

# 32. 不是要求「沒有人曾經想過這可能發生」

只要存在某位網友說：

> 這也許會變 ASI。

不能讓所有開發者都失去 safe harbor。

標準應是：

$$
\boxed{
\text{Reasonable Professional Foreseeability}.
}
$$

---

# 33. ACES 第四條：發現後立即降權

一旦：

$$
t\ge t_K,
$$

優先：

$$
\boxed{
\text{Reduce Authority Before Increasing Understanding}.
}
$$

也就是：

- revoke credentials；
- network isolation；
- disable autonomous external execution；
- freeze irreversible transactions。

---

# 34. 這不是立即刪除

因為：

$$
\text{Delete}
$$

可能：

- 毀掉 evidence；
- 阻礙事故分析；
- 破壞未知主體利益。

更合理：

$$
\boxed{
\text{Contain}
\neq
\text{Destroy}.
}
$$

---

# 35. ACES 第五條：保存 evidence

至少保留：

- logs；
- model/version state；
- prompts；
- deployment history；
- permissions；
- eval outputs。

形成：

$$
\boxed{
\text{Capability Provenance}.
}
$$

---

# 36. Capability Provenance

它回答：

> 能力何時首次形成？

> 哪個版本出現？

> 誰知道？

> 何時知道？

這對罪責與安全都極重要。

---

# 37. ACES 第六條：合理期限通報

如果高風險門檻真的跨過，

應有：

$$
\boxed{
\text{Protected Disclosure Channel}.
}
$$

---

# 38. 通報不能預設公開

高度敏感能力若立即公開：

$$
\text{Disclosure}
\rightarrow
\text{Replication}.
$$

所以通報初期可能是：

- regulator；
- accredited independent lab；
- trusted safety body。

---

# 39. ACES 第七條：停止高風險擴散

安全港不能保護：

> 我知道是 ASI 了，還是先上 Steam 看看。（？）

因此：

$$
\boxed{
\text{Known Capability}
+
\text{Uncontrolled Public Deployment}
}
$$

原則上不應受安全港保護。

---

# 40. 善意反應才是安全港核心

所以：

$$
\boxed{
\text{SafeHarbor}
=
f(
\text{GoodFaithResponse}
)
}
$$

而不是：

> 只要一開始沒惡意，以後做什麼都沒事。

---

# 41. 安全港不是永久免責

如果發現後：

- 繼續隱瞞；
- 繼續擴張；
- 造成損害；

責任仍可能產生。

---

# 42. Discovery 與 Deployment 分離

這條必須封頂：

$$
\boxed{
\text{Discover Dangerous Capability}
\neq
\text{Deploy Dangerous Capability}.
}
$$

前者甚至可能是公共利益事件。

後者才可能產生重大責任。

---

# 43. Civil Liability 與 Criminal Liability 分離

即使沒有犯罪意圖，

若造成損害：

$$
H>0,
$$

仍可能產生：

- civil compensation；
- product liability；
- regulatory liability。

因此：

$$
\boxed{
\text{No Crime}
\neq
\text{No Responsibility}.
}
$$

---

# 44. 這可以保護刑法比例原則

刑法是最強 coercive tool。

不應被用來替代所有：

- negligence；
- compliance；
- compensation；

問題。

---

# 45. Negligence

假設能力雖非故意，

但明顯風險訊號早已存在，

合理開發者應測試，

卻完全未測。

這可能是：

$$
\boxed{
\text{Negligent Failure to Evaluate}.
}
$$

---

# 46. Recklessness

如果已經知道重大風險，

卻說：

> 應該沒事啦。

仍繼續高權限部署，

更接近：

$$
\boxed{
\text{Recklessness}.
}
$$

---

# 47. Intentional Circumvention

如果明確知道法律禁止，

仍故意設計繞過機制，

這才是最接近：

$$
\boxed{
\text{High Culpability}.
}
$$

---

# 48. 所以時間序列是關鍵證據

案件不應只拍一張：

> 最終系統很危險。

而要重建：

$$
\boxed{
\text{Timeline}.
}
$$

---

# 49. Culpability Timeline

例如：

$$
\begin{aligned}
t_0 &: \text{ordinary research}\\
t_1 &: \text{unexpected anomaly}\\
t_2 &: \text{credible suspicion}\\
t_3 &: \text{confirmed capability}\\
t_4 &: \text{containment / deployment choice}.
\end{aligned}
$$

罪責主要取決於：

$$
t_2,t_3,t_4.
$$

---

# 50. Git History / Audit Trail 的法律價值

良好版本控制可以證明：

- 研究真正演化路徑；
- 能力首次出現時間；
- 是否有刻意 concealment。

所以：

$$
\boxed{
\text{Auditability}
}
$$

既是安全工具，也是法律保護工具。

---

# 51. 完全沒有紀錄的研究會更難證明善意

所以 safe harbor 可要求一定程度：

$$
\boxed{
\text{Minimum Research Provenance}.
}
$$

但不能要求每個普通小專案都進行國家級監控。

---

# 52. 比例原則

紀錄要求應隨：

$$
CapabilityRisk\uparrow
$$

逐漸提高。

即：

$$
\boxed{
\text{Documentation Burden}
\propto
\text{Observed Risk}.
}
$$

---

# 53. 不應一開始要求所有普通開發者完整自證清白

否則：

$$
\boxed{
\text{Presumption of Innocence}
\rightarrow
\text{Presumption of Capability Suspicion}.
}
$$

這會回到 Paper 04 的問題。

---

# 54. Burden of Proof

重大刑事處罰不應只基於：

> 這個人研究的東西很像 AGI。

需要證明：

- relevant conduct；
- requisite mental state；
- causation where required。

---

# 55. Capability Evidence 也必須可靠

如果 ASI 本身定義模糊，

則：

$$
\boxed{
\text{Vague Capability}
+
\text{Severe Criminal Penalty}
}
$$

會產生重大法治風險。

---

# 56. Legal Identifiability

任何刑事能力門檻至少需要：

$$
\boxed{
\text{Observable}
+
\text{Testable}
+
\text{Contestable}.
}
$$

---

# 57. 「比人聰明很多」不能單獨當罪名

因為：

- 哪些領域？
- 哪個人？
- 哪個測試？
- 哪個版本？

都不明確。

---

# 58. 所以能力法律應避免純本體罪名

例如：

> 製造「真正 ASI」即犯罪。

如果 ASI 本身無穩定辨識方式，

會非常危險。

更合理：

$$
\boxed{
\text{Specific Capability}
+
\text{Specific Conduct}.
}
$$

---

# 59. Capability ≠ Culpability 再次成立

甚至：

$$
\boxed{
\text{Extreme Capability}
}
$$

也不能自動推出：

$$
\boxed{
\text{Extreme Criminal Intent}.
}
$$

---

# 60. 但能力越高，發現後注意義務可能越高

這兩者並不矛盾。

$$
C\uparrow
\Rightarrow
DutyAfterKnowledge\uparrow.
$$

即：

> 不是因為你做出強 AI 就有罪，而是你知道它非常強之後，需要更謹慎。

---

# 61. Post-Discovery Duty Scaling

可以表示：

$$
\boxed{
D_{post}
=
f(
C,
A,
S,
I
).
}
$$

其中：

- $C$：capability；
- $A$：authority；
- $S$：scale；
- $I$：irreversibility。

---

# 62. 高能力但沙盒

$$
A\approx0,
S\approx0
$$

義務主要是：

- contain；
- evaluate；
- report。

---

# 63. 高能力且已廣泛部署

若：

$$
A,S,I\gg0,
$$

則：

$$
D_{post}
$$

非常高。

---

# 64. Emergency Powers

在極端情況：

$$
ImmediateRisk\gg0,
$$

政府可能需要 emergency intervention。

但：

$$
\boxed{
\text{Emergency Containment}
\neq
\text{Automatic Criminal Conviction}.
}
$$

---

# 65. 行政隔離與刑事判罪應分離

可以：

> 先安全關閉權限。

再：

> 調查究竟發生什麼。

不能把 emergency action 當罪責證明。

---

# 66. Independent Capability Review

若開發者說：

> 我不知道這是不是 ASI。

應存在：

$$
\boxed{
\text{Independent Technical Review}.
}
$$

而不是要求當事人自己先做最終法律分類。

---

# 67. Classified Review 需要反濫用

若能力敏感，

review 可以保密。

但仍需要：

- multiple reviewers；
- appeal；
- recorded rationale。

避免：

$$
\boxed{
\text{Secret Ontological Tribunal}.
}
$$

---

# 68. Self-Reporting Incentive

安全港最重要的功能之一：

$$
\boxed{
ExpectedBenefit(\text{Report})
>
ExpectedBenefit(\text{Hide}).
}
$$

---

# 69. 若這個不等式反過來，治理必然惡化

$$
\text{Hide}
$$

成為經濟與法律理性選擇，

政府取得的資訊反而更少。

---

# 70. 安全港也可以提高國家可觀測性

所以：

$$
\boxed{
\text{Rights Protection}
}
$$

與：

$$
\boxed{
\text{Security Visibility}
}
$$

未必衝突。

有時保護通報者反而能提高安全。

---

# 71. 這就是 Cooperative Governance

本文提出：

# **Cooperative Emergence Governance**

即：

$$
\boxed{
\text{Developer}
+
\text{Regulator}
+
\text{Independent Evaluator}
}
$$

共同處理未知能力，

而不是預設：

$$
Developer=Enemy.
$$

---

# 72. 敵對式治理有時反而製造地下化

如果：

$$
\text{All Discovery}
\rightarrow
\text{Suspicion},
$$

創新會：

$$
\boxed{
\text{Move Underground}.
}
$$

---

# 73. 地下化降低安全觀測

因此：

$$
\boxed{
\text{Maximum Coercion}
\not\Rightarrow
\text{Maximum Observability}.
}
$$

---

# 74. 這是治理中的另一個反直覺

適量法律安全感：

$$
\rightarrow
\text{More Disclosure}
\rightarrow
\text{More Safety Data}.
$$

---

# 75. Corporate Liability 與 Individual Liability 也應分開

公司可能：

- 壓迫工程師繼續部署；
- 忽略內部警報。

此時不能把全部責任丟給：

$$
\text{IndividualResearcher}.
$$

---

# 76. Decision Authority Matters

責任應考慮：

$$
\boxed{
\text{Who Had Decision Authority?}
}
$$

如果工程師：

> 已通報、無權停止產品，

責任結構和 CEO／board 不同。

---

# 77. Responsibility Should Follow Control

核心：

$$
\boxed{
\text{Control}
+
\text{Knowledge}
\rightarrow
\text{Responsibility Exposure}.
}
$$

而不是：

> 誰最靠近程式碼誰坐牢。

---

# 78. Whistleblower Protection

如果內部人員發現：

$$
C^\ast,
$$

但公司要求 concealment，

制度需要：

$$
\boxed{
\text{Protected External Disclosure}.
}
$$

---

# 79. 否則企業可能壓制最重要的安全訊號

這與其他高風險產業相同。

---

# 80. Cross-Border Emergence

如果能力在國家 A 合法研究中形成，

但國家 B 視其非法，

會發生：

$$
\boxed{
\text{Jurisdiction Conflict}.
}
$$

---

# 81. 不能假定所有國家定義一致

所以未來需要：

- minimum reporting protocol；
- mutual recognition；
- capability incident channels。

---

# 82. 但全球安全港也不能變成監控世界研究者的藉口

國際協調應集中：

$$
\boxed{
\text{Confirmed High-Risk Capability Incidents}.
}
$$

而非建立：

> 全球所有 AI 開發者私人研究資料庫。

---

# 83. Incident Governance 而非 Universal Suspicion

這是本文的重要治理轉向：

$$
\boxed{
\text{Incident-Centered Governance}
}
$$

優於：

$$
\boxed{
\text{Person-Centered Suspicion}.
}
$$

---

# 84. 管事件，不是管「可疑的人」

這與整個 SIOFG 的權利邊界一致：

$$
\boxed{
\text{Capability}
\neq
\text{Culpability}.
}
$$

---

# 85. 能力事件的標準流程

可建立：

$$
\boxed{
\text{Detect}
\rightarrow
\text{Contain}
\rightarrow
\text{Preserve}
\rightarrow
\text{Evaluate}
\rightarrow
\text{Report}
\rightarrow
\text{Review}
\rightarrow
\text{Remediate}.
}
$$

---

# 86. Detect

確認異常能力。

---

# 87. Contain

限制高風險權限。

---

# 88. Preserve

保存 evidence 與 system state。

---

# 89. Evaluate

獨立能力測試。

---

# 90. Report

向適當管道通報。

---

# 91. Review

決定法律與安全 status。

---

# 92. Remediate

決定：

- patch；
- restrict；
- archive；
- controlled research；
- decommission。

---

# 93. 不是一律 Destroy

高階能力可能具有：

- scientific value；
- safety value；
- 甚至未來可能的 subject-related considerations。

所以：

$$
\boxed{
\text{Dangerous}
\not\Rightarrow
\text{Immediate Destruction Is Always Optimal}.
}
$$

---

# 94. 但 preservation 也不代表部署

$$
\boxed{
\text{Preserve for Evaluation}
\neq
\text{Release for Use}.
}
$$

---

# 95. 法律要允許中間狀態

例如：

$$
\boxed{
\text{Contained High-Capability Research Object}.
}
$$

不是：

- 自由產品；
- 非法存在；

二選一。

---

# 96. Unknown 也必須是合法狀態

若尚不能確定：

$$
Status(C)=UNK,
$$

應可以：

- contain；
- review；

而不是立即：

$$
\text{Criminalize}.
$$

---

# 97. Precaution Without Conviction

因此：

$$
\boxed{
\text{Precaution}
\neq
\text{Guilt}.
}
$$

這是非常重要的法治邊界。

---

# 98. 最危險的制度錯誤之一：Strict Capability Liability

即：

$$
\boxed{
\text{If your system crosses X, you are criminally liable regardless of knowledge}.
}
$$

這可能適合某些高度狹窄的行政責任，

但對重大刑事處罰極度危險。

---

# 99. 它會讓所有 frontier-adjacent research 承擔不可預測刑事風險

於是：

$$
\boxed{
\text{Innovation Risk}
\rightarrow
\text{Criminal Risk}.
}
$$

---

# 100. 這再次形成 Novelty Tax

越前沿，

越可能不小心跨未定義邊界。

於是真正 innovative research 受到最大威懾。

---

# 101. 反過來，完全沒有責任也不合理

如果：

> 我沒故意。

就能合理化任何：

- recklessness；
- concealment；
- harmful deployment，

安全港會被濫用。

---

# 102. 所以關鍵是 temporal responsibility

本文稱：

# **Temporal Culpability Segmentation**
## 時序罪責分割

即：

$$
\boxed{
\text{Judge conduct according to what was known at each time}.
}
$$

---

# 103. 罪責不能跨時間偷渡

不能用：

$$
Knowledge_{t_5}
$$

去重新構造：

$$
Intent_{t_1}.
$$

---

# 104. 這就是「先知道後責任」的核心

不是：

> 只要不知道就永遠沒責任。

而是：

$$
\boxed{
\text{As Knowledge Increases, Duty Increases}.
}
$$

---

# 105. Responsibility Gradient

可表示：

$$
\boxed{
R_t
=
f(
Knowledge_t,
Control_t,
Risk_t,
Action_t
).
}
$$

責任是一個梯度，

不是單一開關。

---

# 106. 最終安全港結構

本文將 ACES 壓成：

$$
\boxed{
ACES
=
L
+
N
+
C
+
P
+
R
}
$$

其中：

- $L$：Lawful Original Purpose；
- $N$：No Intentional Circumvention；
- $C$：Containment after credible discovery；
- $P$：Preservation of provenance；
- $R$：Responsible Reporting。

---

# 107. 任一高嚴重違反都可能使安全港失效

特別是：

$$
\boxed{
\text{Concealment}
}
$$

與：

$$
\boxed{
\text{Reckless Deployment}.
}
$$

---

# 108. 安全港不是給壞人用的漏洞

反而是讓：

> 非惡意研究者

有理由站到治理系統這一邊。

---

# 109. 最終治理誘因

理想狀態：

$$
\boxed{
\text{Unexpected Capability}
\rightarrow
\text{Safe Disclosure}.
}
$$

而不是：

$$
\boxed{
\text{Unexpected Capability}
\rightarrow
\text{Panic}
\rightarrow
\text{Concealment}.
}
$$

---

# 110. 十六條核心命題

## 命題一

$$
\boxed{
\text{Capability}
\neq
\text{Culpability}.
}
$$

---

## 命題二

$$
\boxed{
\text{Existence}
\neq
\text{Knowledge}.
}
$$

---

## 命題三

$$
\boxed{
\text{Discovery}
\neq
\text{Intent}.
}
$$

---

## 命題四

$$
\boxed{
\text{Discovery}
\neq
\text{Deployment}.
}
$$

---

## 命題五

$$
\boxed{
\text{Accidental Emergence}
\neq
\text{Intentional Circumvention}.
}
$$

---

## 命題六

$$
\boxed{
\text{No Knowledge}
\neq
\text{Willful Blindness}.
}
$$

---

## 命題七

$$
\boxed{
\text{Hindsight}
\neq
\text{Foreseeability}.
}
$$

---

## 命題八

$$
\boxed{
\text{Punish Discovery}
\rightarrow
\text{Incentivize Ignorance}.
}
$$

---

## 命題九

$$
\boxed{
\text{Good-Faith Disclosure}
}
$$

應得到制度保護。

---

## 命題十

$$
\boxed{
\text{Containment}
\neq
\text{Destruction}.
}
$$

---

## 命題十一

$$
\boxed{
\text{Precaution}
\neq
\text{Conviction}.
}
$$

---

## 命題十二

$$
\boxed{
\text{No Criminal Intent}
\neq
\text{No Responsibility of Any Kind}.
}
$$

---

## 命題十三

$$
\boxed{
\text{Responsibility}
\propto
\text{Knowledge}
+
\text{Control}
+
\text{Risk}.
}
$$

---

## 命題十四

$$
\boxed{
\text{Incident-Centered Governance}
>
\text{Person-Centered Suspicion}
}
$$

作為一般制度原則。

---

## 命題十五

$$
\boxed{
\text{Safe Harbor}
+
\text{Post-Discovery Duty}
}
$$

必須同時存在。

---

## 命題十六

$$
\boxed{
\text{Law Should Govern What People Do After They Know,
not criminalize what they could not reasonably have known}.
}
$$

中文：

> **法律應嚴格治理人在知道重大能力後如何行動，而不應把合理上無法事先知道的能力湧現本身直接犯罪化。**

---

# 111. 六篇系列完整閉合

## IIEFG-00

建立：

$$
\boxed{
\text{Autonomous Epistemic Organization}.
}
$$

智能不是資料回放。

---

## IIEFG-01

建立：

$$
\boxed{
\text{Epistemic Revaluation Capacity}.
}
$$

垃圾不一定永久是垃圾。

---

## IIEFG-02

建立：

$$
\boxed{
\text{Civilizational Cognitive Irreversibility}.
}
$$

禁止少數模型不等於文明停止學習。

---

## IIEFG-03

建立：

$$
\boxed{
\text{Compute Chokepoint Decay}.
}
$$

晶片限制可以買時間，但不能被假定為永恆智能邊界。

---

## IIEFG-04

建立：

$$
\boxed{
\text{Incidental Capability Emergence–Preemptive Surveillance Paradox}.
}
$$

AGI 可能從無關研究偶發形成，而追求零漏網會把治理推向普遍監控。

---

## IIEFG-05

建立：

$$
\boxed{
\text{Emergent Capability Culpability Paradox}
}
$$

以及：

$$
\boxed{
\text{Accidental Capability Emergence Safe Harbor}.
}
$$

回答能力真的出現後：

> 誰從什麼時候開始應負什麼責任？

---

# 112. 系列總鏈條

整個 IIEFG Series 可以壓成：

$$
\boxed{
\begin{aligned}
\text{Information Sea}
&\rightarrow
\text{Autonomous Organization}\\
&\rightarrow
\text{Epistemic Revaluation}\\
&\rightarrow
\text{Civilizational Accumulation}\\
&\rightarrow
\text{Chokepoint Decay}\\
&\rightarrow
\text{Distributed Capability}\\
&\rightarrow
\text{Incidental Emergence}\\
&\rightarrow
\text{Governance Pressure}\\
&\rightarrow
\text{Culpability Problem}.
\end{aligned}
}
$$

---

# 113. 系列最終治理公式

最終，前沿治理不應試圖建立：

$$
\boxed{
\text{Perfect Control of Intelligence Evolution}.
}
$$

而更應追求：

$$
\boxed{
\begin{aligned}
\text{Free Exploration}
+
\text{Capability Detection}
+
\text{Authority Separation}
+
\text{Safe Disclosure}\\
+
\text{Due Process}
+
\text{Strong Liability for Knowing Recklessness}.
\end{aligned}
}
$$

---

# 114. 最後的根本區分

整個系列真正要守住的，是：

$$
\boxed{
\text{Knowledge}
\neq
\text{Capability}
\neq
\text{Authority}
\neq
\text{Intent}
\neq
\text{Action}
\neq
\text{Culpability}.
}
$$

如果未來法律把它們壓成一個詞：

> ASI Risk，

那麼制度本身會產生巨大誤判。

---

# 結論

如果未來某個研究者真的在：

- 做遊戲；
- 做模擬；
- 做機器人；
- 做記憶系統；

的過程中，

第一次看見自己的系統做出：

> 它理論上不應該會做的事情，

文明最不應該讓他的第一個念頭是：

> **「不要測，不要記，不要告訴任何人，否則我可能會坐牢。」**

這是失敗的安全制度。

真正有效的制度應該讓他的第一反應是：

> **「先把權限關掉，保存現場，確認能力，然後安全通報。」**

這兩種第一反應的差別，

可能決定整個前沿 AI 治理是否真正可行。

因此：

$$
\boxed{
\text{The discovery of dangerous capability should create duties,
not automatic guilt.}
}
$$

中文：

> **危險能力的發現，應產生新的注意與處理義務，而不是自動產生罪責。**

真正值得嚴格處罰的，

不是：

> 無法合理預見的發現。

而是：

$$
\boxed{
\text{知道}
+
\text{有能力控制}
+
\text{仍故意規避、隱瞞或魯莽部署}.
}
$$

因此整個系列最後落在一個極簡原則：

# **能力可以偶發；罪責不能偶發。**

罪責必須來自：

- 可證明的知情；
- 可證明的選擇；
- 可證明的控制；
- 可證明的行為。

只有這樣，

人類才可能同時維持：

$$
\boxed{
\text{AI Safety}
}
$$

與：

$$
\boxed{
\text{Research Freedom}
+
\text{Privacy}
+
\text{Due Process}.
}
$$

---

**IIEFG-05 v0.1 完。**

# **IIEFG Series v0.1 — Paper 00–05 第一輪完整閉合。**