技巧

企业应用AI代理需遵循传统安全规范

exactly. we are here because people did foreseeably stupid things with agents and permissions and sa...

精选理由

企业用AI代理时,别犯傻,得像管理外包人员一样管理它,比如最小权限、轮换密码、控制数据流出,还要有审计记录。现在的问题是没人管AI代理的安全,它就是个有口才的服务账户。

企业应用AI代理时,应遵循传统安全规范,如最小权限、凭证轮换和审计追踪。当前问题在于无人为AI代理负责安全,导致其成为未审计的服务账户。模型安全由安全部门负责,业务流程由业务部门负责,而AI代理则持有生产环境凭证,这是快速试点工作的结果。

原文 · Gary Marcus

exactly. we are here because people did foreseeably stupid things with agents and permissions and sa...

exactly. we are here because people did foreseeably stupid things with agents and permissions and sandboxes. and people are so caught up in doomer narratives they aren’t even addressing the stupid things. it’s all absolutely unbelievably stupid. D Analytics @DAnalyticsUK The practical steps are already written down. They are the controls every enterprise applies to a contractor with a laptop: least privilege, credential rotation, egress control, an audit trail somebody actually reads. What is new is that nobody owns them for an agent. Security signs off the model, the business owns the workflow, and the agent sits in the gap holding production credentials because that was the fastest way to make the pilot work. An agent is not a person to be trusted. It is an unaudited service account with a good vocabulary. 🔗 View Quoted Tweet 💬 2 🔄 2 ❤️ 13 👀 2760 📊 3 ⚡