← Latest papers
🤖 AI

Update Opacity: Epistemic Accessibility and Governance Under AI System Change

This paper addresses the governance challenge of "update opacity" in AI systems by proposing a framework that combines the EU AI Act and Machine Learning Operations to implement threshold-based disclosure of materially relevant changes, thereby ensuring epistemic accessibility for users without causing information overload.

Original authors: Andrea Ferrario, Joshua Hatherley

Published 2026-06-02
📖 6 min read🧠 Deep dive

Original authors: Andrea Ferrario, Joshua Hatherley

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Core Problem: The "Silent Shift"

Imagine you have a very smart, helpful GPS app. You've used it for years. You know exactly how it behaves: if you type in "Coffee Shop," it usually shows you the one on Main Street because that's where the traffic is lightest. You have built up a "gut feeling" or a calibration about how the app works.

Now, imagine the app developers quietly update the code overnight to make it faster. They don't tell you. The next morning, you type in "Coffee Shop," and suddenly, it sends you to a different shop on a different street. It's still a valid coffee shop, and the app is still working "correctly" by its own internal standards. But you are confused. You don't know why the answer changed. You don't know if you should trust the new route.

The paper calls this Update Opacity. It's not that the AI is broken; it's that the AI changed in a way that you, the user, can't see or understand. This is dangerous in high-stakes situations (like a doctor using AI to diagnose a patient or a bank using it to approve loans) because users rely on their "gut feeling" about how the system behaves. If the system changes silently, that gut feeling becomes wrong, leading to bad decisions.

The Two Current Solutions (and why they aren't enough)

The authors look at two existing ways we try to manage AI changes, but they say neither works alone:

  1. The "Rulebook" Approach (The EU AI Act):

    • The Analogy: Think of this like a strict building code. If you want to build a house, you must follow specific rules. If you decide to knock down a load-bearing wall or add a whole new floor, you must get a new permit and an inspector to check it.
    • The Problem: This rulebook is great for big, dangerous changes. But what if the builder just swapped the paint color or moved a light switch? The rulebook doesn't care. But for the people living in the house, those small changes might still be annoying or confusing. The rulebook is too "coarse" (too big) to catch the small, confusing shifts that happen inside the system.
  2. The "Engineer's Dashboard" Approach (MLOps):

    • The Analogy: This is like the dashboard in a race car. It tracks every tiny vibration, temperature change, and fuel fluctuation. The engineers can see everything happening inside the engine.
    • The Problem: If you showed that dashboard to the driver (the user), they would be overwhelmed. They don't need to know that "Fuel Injector #3 shifted by 0.04%." They just need to know if the car is safe to drive. MLOps tracks the changes, but it doesn't tell us which changes actually matter to the person using the system.

The Authors' Solution: The "Trustworthiness Plateau"

The authors propose a new way to manage this by combining the Rulebook and the Dashboard. They suggest we stop looking at the AI as a single "model" and start looking at it as a Trustworthy System that has different "levels" of safety.

Here is their three-step plan:

Step 1: The "Safe Zone" (The Plateau)

Imagine the AI's performance is a flat plateau. As long as the AI stays on this plateau, it is considered "safe" and "compliant."

  • Big Changes: If the AI falls off the cliff (e.g., it stops working or breaks the law), that's a crisis. You stop everything and get a new permit (like the EU AI Act requires).
  • Small Changes: Most updates happen on the plateau. The AI gets slightly better or slightly different, but it's still safe.

Step 2: The "Trustworthiness Profile"

Instead of just checking if the AI is "right," we track a specific list of things that matter to the user. Let's call this the Trustworthiness Profile.

  • For a medical AI, this might include: "How accurate is it for elderly patients?" "How fast is it?" "Does it confuse similar-looking diseases?"
  • We turn these into a score. As long as the score stays within a certain range, the AI is on the "Safe Plateau."

Step 3: The "Materiality Threshold" (The Alarm Bell)

This is the most important part. Even if the AI stays on the "Safe Plateau," it can still drift far away from where it started.

  • The Analogy: Imagine you are walking on a flat field. You start at point A. If you walk 5 feet to the right, you are still on the field. If you walk 500 feet to the right, you are still on the field, but you are now in a completely different part of the field.
  • The authors say: We need a Threshold. If the AI changes so much that it crosses a certain distance from where it started (even if it's still "safe"), we must ring a bell.
  • This bell tells the user: "Hey, the system has changed enough that your old 'gut feeling' might not work anymore. Here is what changed."

How This Works in Real Life (The Medical Example)

The paper uses a Stroke Triage AI (a system that helps doctors decide if a patient needs to go to a big hospital or a local one) to show how this works.

  • The Situation: The AI is updated to handle new types of CT scanners. The update is "safe" (it doesn't break the rules). The overall accuracy actually gets slightly better.
  • The Hidden Change: However, the update makes the AI slightly more likely to send elderly patients to the big hospital, even if their symptoms are borderline.
  • The Old Way: The doctor keeps using the AI, trusting their old habits. They might miss the subtle shift, leading to a patient being sent to the wrong place.
  • The New Way (The Authors' Framework):
    1. The system tracks the change.
    2. It sees that the change for "elderly patients" has crossed the Threshold.
    3. The Disclosure: Instead of a boring technical report, a small, clear message pops up on the doctor's screen: "Model Updated: Recommendations for patients over 75 may now differ. Tap for details."
    4. The doctor sees the warning, adjusts their thinking, and makes a safe decision.

The Bottom Line

The paper argues that we don't need to tell users everything about every update (that would be too much information). We also can't tell them nothing (that would be dangerous).

We need a smart filter. We need to measure the AI's "Trustworthiness," watch how much it drifts from its starting point, and only ring the alarm when the change is big enough to confuse the user. This keeps the AI safe, legal, and understandable, even as it constantly evolves.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →