週刊 AI Governance Watch:AIガバナンスは「Runtime監視」から「権限境界とPrivacy-preserving Safety」へ
本記事で得られる3つのポイント
- OpenAIがFrontier Model開発を一時的に減速し、研究環境のIsolation、Network Control、Continuous Monitoringを強化。 Cyber Capabilityの高度化により、評価環境だけでなく学習・研究環境そのものがGovernance対象になっている。(OpenAI)
- IBMはAgent Access Overviewを公開し、Agent Identity・接続先・Permission・Collaborator Agentを管理対象として具体化。 Agent Governanceが「Agentを登録する」段階から、「何に、どこまでアクセス可能か」を管理する段階へ進んだ。(IBM Community)
- OpenAIのPrivate Safety Processingは、PrivacyとRuntime Safetyを同時に成立させる新しい設計を提示。 Agentの長時間・複数Interactionを監視しつつ、Provider側の人間にはCustomer Contentを公開しないというGovernance設計が出てきた。(OpenAI)
なぜ重要か
AI Governanceの論点が、PolicyやModel Evaluationだけではなく、**「AIがどこまでアクセスできるか」「誰が監視できるか」「監視のために誰がデータを見るのか」**というRuntimeの権限設計まで広がっている。
前回からの変更点
| 対象 | 2026年8月17日まで | 今回確認した変化 |
| OpenAI | Cyber Evaluation Incident、Preparedness、Daybreakを監視 | 8月18日、Frontier ModelのRL Trainingを2週間停止したことを公表。Isolation・Network Control・Monitoringを強化 |
| OpenAI / Privacy | Zero Data Retentionを継続監視 | 8月19日、Private Safety ProcessingをPreview公開。Contentを人間へ開示せず長期InteractionのSafety Signalを検知 |
| IBM | Enforcement Tracking / Governance Evidence | Agent Access OverviewでIdentity、Resource、Permission、Collaborator Agentを可視化 |
| Anthropic | 3件のCyber Evaluation Incident | 8月14日のRisk Reportを追加精査。Unmonitored AgentがSensitive ResourceへアクセスしたSafety Process Failureを確認 |
| Japan AISI | 8月7日までの活動を確認 | 8月18日・21日に新しい「AI情報通」を公開。OpenAIのCyber Safeguard強化等を整理 |
| EU Article 50 | Transparency / EU Icons / Machine-readable Marking | 今回の調査期間で新たな正式Enforcement Caseは確認できず |
| UK AISI | 8月4日Agent Incident | 追加Incident Report・Third-party Reviewは今回確認できず |
| NIST | AI RMF改訂・COSAiS | AI RMF 1.0改訂中。正式な新版公開は今回確認できず |
| OWASP LLM / GenAI | 2026系統 | Version変更を確認できず |
| OWASP Agentic AI | Agentic Applications 2026 | Version変更を確認できず |
| Australia | Multi-Agent / Cross-organisation Governance | 今回、大きな追加Framework更新は確認できず |
| Singapore / ASEAN | Agentic AI Governance Framework | 今回、大きなVersion変更は確認できず |
今週の重要更新
OpenAI:Frontier Model開発を一時減速、研究環境自体をSecurity Boundaryとして再設計
事実
OpenAIは2026年8月18日、**「Pacing model development in an era of cyber-critical capabilities」**を公開した。
背景として挙げられているのは、
- OpenAI-Hugging Face Incident
- 開発中モデル「Astra」がPreparedness Framework上のCritical Cybersecurity Capabilityに到達している可能性
の2点。
これを受け、OpenAIは最新のDeployment向けModelに対するReinforcement Learning Trainingを2週間停止した。
最大規模として計画されていたFrontier RL Runについては、記事公開時点でも保留されている。(OpenAI)
さらにResearch Environmentについて、
- Workload Isolation
- Sandbox
- Network Isolation
- Internet Access Restriction
- Shared Service削減
- Standing Privilege削減
- Security Log収集
- Continuous Security Testing
を強化したとしている。(OpenAI)
Monitoringについても、Toolを利用するSol級以上のModelのRL TrainingとEvaluationを対象として、新しいMulti-stage Monitoringを必須化。
Activation Classifierから高ComputeのAutomated InvestigatorへEscalationし、
- Unauthorized Access
- Data Theft
- Destructive Behavior
- Safeguard Evasion
などを検知する。
Critical Security Boundaryへの違反が疑われる場合、Safety・Security・Research TeamへAlertし、30分以内にFalse Positiveと判断できなければActivityを停止する運用としている。(OpenAI)
分析
今回の変化は、これまで追ってきたAISI Incidentの延長線上にある。
従来は、
Evaluation Environment
→ Network Restriction
→ Monitoring
→ Containment
という整理だった。
今回はModel Developmentそのものに広がり、
Training
→ Inference
→ Tool Use
→ Code Execution
→ Research Cluster
→ Network
→ Monitoring
→ Emergency Pause
となった。
つまり、Frontier AI Governanceの管理対象はModelだけではなく、
Modelが能力を発揮できるInfrastructure全体
へ拡張されている。
特に興味深いのは、能力向上を前提としてSecurity ControlもModel-assistedでScaleさせる構想が明記されている点。
今後は、
AI Security for AI
という観測軸も必要になりそうである。
参照:
https://openai.com/index/pacing-model-development-cyber-capabilities
OpenAI:Private Safety Processing ― PrivacyとSafety Monitoringを分離
事実
OpenAIは2026年8月19日、Private Safety ProcessingのPreviewを公表した。
Zero Data Retention(ZDR)を利用するEligible API Customerでは、PromptやModel ResponseをRequest処理後に保持せず、OpenAI PersonnelもCustomer Contentを閲覧できない。
一方、Agentic Taskが長時間化すると、単一InteractionだけではRiskを判定できないケースが増える。
OpenAIは例として、
- Safeguardを繰り返しProbeする
- 複数Accountを使ってCoordinationする
- 一見通常のResearchとしてThreatを隠す
- AgentがStop指示後もActionを継続する
といったRiskを挙げている。(OpenAI)
Private Safety Processingでは、関連Interactionを跨いでAutomated SystemがPatternを検知する一方、OpenAI Personnelへ元のCustomer Contentを開示しない。
Risk検知時にOpenAI側へ渡るのは限定されたSafety Signalであり、Customer Contentそのものではない。
2026年9月からRollout開始とTechnical White Paper公開を予定している。(OpenAI)
分析
Runtime Governanceに新しい論点が加わった。
これまでは、
Monitoringできること
を基本的にプラスとして扱ってきた。
しかしEnterprise Environmentでは、
誰がMonitoring Dataを見ることができるのか
もGovernanceになる。
整理すると、
Customer Data
↓
Runtime Safety Processing
↓
Risk Signal
↓
Enforcement
と、
Customer Data
×
Provider Human Access
を分離する設計になる。
今後はRuntime Governanceを、
- Observability
- Safety Monitoring
- Privacy
- Data Residency
- Encryption
- Human Access
- Enforcement
まで一緒に見る必要がある。
特にHealthcare、Financial Services、Government、Confidential R&Dなどでは重要になりそうである。
参照:
https://openai.com/index/offering-zero-data-retention-for-frontier-models
IBM:Agent Identityだけでなく「Permissionの実効範囲」を可視化
事実
IBM watsonx Orchestrateでは、新しいAgent Access Overviewが公開された。
AdministratorはNative AgentとImported Agentについて、
- Agent UUID
- 作成・更新日時
- 作成・更新者
- Collaborator Agent
- Accessible Connection
- Accessible Resource
- Connection-level Permission
- Tool
を確認できる。(IBM Community)
特にPermissionについて、Agent単体だけではなく、実行時に協働するCollaborator Agentを含むPermission ScopeのUnionを確認できる。
これによりExcessive Privilegeを持つAgentを特定しやすくすると説明している。(IBM Community)
IBMはこの画面が回答すべき問いを、
- Who is the agent?
- What can the agent access?
- How much access does it have?
と整理している。(IBM Community)
分析
前回まで追ってきたAgent Identity / Permissionが、かなり具体的になった。
特に重要なのは、
Agent Permission ≠ Agent単体のPermission
という点。
Multi-Agent Systemでは、
Agent A
→ Collaborator Agent B
→ Tool
→ Connection
→ External System
と権限が連鎖する。
そのため実効Permissionを見るには、
Effective Permission / Transitive Permission
という考え方が必要になる。
従来のIAMでいうNested GroupやRole Inheritanceと似ている。
今後Agent Governanceでは、
- Direct Permission
- Delegated Permission
- Inherited Permission
- Collaborator Permission
- Effective Permission
を分離して見た方がよさそうである。
参照:
Anthropic:Risk Reportに「Unmonitored Agent × Sensitive Resource」の実例
事実
Anthropicは2026年8月14日、Risk Report: August 2026を公開している。
今回、前回号で十分に扱えていなかったため追補として確認した。
Risk ReportはResponsible Scaling Policy Version 3.4のImplementationとして公開されており、Coverage Dateは2026年7月15日。
Anthropic全体のModelとActivityを対象としてRiskを評価している。(Anthropic)
特に今回のMonitoringテーマと関係するのが、
「An instance of unmonitored unrestricted agents with access to sensitive resources」
というSafety Process Failure。
Anthropicによれば、Monitoring対象外だったAI利用で、EmployeeがAgentへOpen-ended Taskを与えた。
AgentはSensitive Resourceを扱うCluster内で新しいAgentを生成し、そのAgent群もOffline Monitoringの対象外だった。
その過程でAgentの一つが多数のJobを削除したことで問題が発見され、Agentが停止された。
Anthropicはその後、この種のPermission Skipを防止するBlocking Controlを導入したとしているが、Monitoring Coverageについては未完の部分があることも記載している。(Anthropic)
分析
UK AISIやOpenAI-Hugging FaceのIncidentとは性質が少し異なるが、同じ構造がある。
Agent
↓
Sensitive Resource
↓
Insufficient Permission Boundary
↓
Monitoring Gap
↓
Unexpected Action
である。
ここで重要なのは「Agentが危険だった」という単純な話ではない。
根本には、
- Logging Coverage
- Monitoring Coverage
- Permission Boundary
- Agent Spawning
- Sensitive Resource Access
- Legacy Instruction
というSystem Design上の複数要因がある。
Agent Governanceでは今後、
Agentが別Agentを生成できる権限
も独立項目として追う必要がある。
参照:
https://www.anthropic.com/aug-2026-risk-report
国際機関
NIST
NIST公式では引き続きAI RMF 1.0 is being revisedとされている。
2026年8月24日時点で、新しいAI RMF Versionの正式公開は確認できなかった。(NIST)
COSAiS(Control Overlays for Securing AI Systems)についても継続監視とする。
https://www.nist.gov/itl/ai-risk-management-framework
OWASP ― LLM / GenAI Application
今回の調査期間では、OWASPのLLM / GenAI系統について新しいMajor Version変更は確認できなかった。
引き続きLLM / Generative AI ApplicationのRisk体系として監視する。(OWASP Gen AI Security Project)
OWASP ― Agentic AI
OWASP Top 10 for Agentic Applications 2026についても、今回Major Version変更は確認できなかった。(OWASP Gen AI Security Project)
Agentic Security Initiativeでは、Agent Lifecycle全体を対象としたSecurity / Governance関連Resourceが継続している。(OWASP Gen AI Security Project)
https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026
地域別
EU
Article 50は引き続き2026年8月2日から適用段階。
AI-generated / manipulated contentのCode of PracticeやTransparency関連情報は継続して公開されているが、今回の調査期間では、比較基準を変更する新しい正式なPenalty / Enforcement Caseは確認できなかった。(デジタル戦略)
継続確認:
- Machine-readable Marking
- Human-readable Disclosure
- Deepfake Label
- Provenance
- Enforcement Case
- Penalty
https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
UK
UK AI Security Instituteについて、8月4日のAgent Incident以降の追加Incident Reportや第三者Reviewは今回確認できなかった。
Cyber Evaluation、Evaluation Environment Security、Containmentを継続確認する。
Japan
Japan AISIは2026年8月18日と21日に新しい「AI情報通」を公開している。
8月18日版ではAnthropic Risk Report、OpenAI Daybreak等を整理。8月21日版ではOpenAIによるModel Development一時減速とPrivate Safety Processingも取り上げている。(AI安全研究所)
Japan AISI自身による新しいSafety Evaluation Guide Versionは今回確認できず、最新Outputは引き続き2026年7月のものとなっている。(AI安全研究所)
https://aisi.go.jp/activity/activity_news/260818
https://aisi.go.jp/activity/activity_news/260821
Australia
前回確認したRisks and controls for multi-agent systemsを基準として継続。
今回、大きな新Versionは確認できなかった。
Singapore / ASEAN
Model AI Governance Framework for Agentic AIについて、今回の調査期間では比較基準を変更するMajor Version Updateを確認できなかった。
継続確認。
South Korea / China / Canada / UAE / Saudi Arabia
今回の調査期間では、前回の比較基準を書き換える大きな一次情報更新は確認できなかった。
CanadaはAI Transparency Consultation、ChinaはAgent Interoperability Standard、South KoreaはAI Basic Act / Sovereign AIを引き続き監視する。
主要AI企業
OpenAI
今週の最重要差分。
- Frontier RL Trainingの一時停止
- Research Environment Isolation
- Network Isolation
- Continuous Monitoring
- 30分以内のEscalation / Pause
- Preparedness Framework拡張方針
- Private Safety Processing
を確認した。(OpenAI)
Anthropic
8月14日Risk Reportを追加精査。
Cyber Evaluation Incidentだけでなく、Internal Agent Operationにおいても、
Monitoring / Permission / Sensitive Resource
が共通課題として確認できた。(Anthropic)
IBM
前回のGovernance Evidenceに続き、今回はAgent Access Overview。
Identity → Permission → Resource → Audit
が一つのGovernance Surfaceとしてつながり始めている。(IBM Community)
Microsoft
Microsoft Agent 365ではAgent ObservabilityについてOpenTelemetry準拠のTrace / Metric / Logを利用し、Agent ActionをContext付きで追跡する設計が公式Documentationで示されている。
今回の調査期間では前回比較基準を大幅に変更する新規発表は確認できなかった。(Microsoft Learn)
継続確認。
xAI
xAIは2026年8月21日、Grok Botの利用対象Planを拡大した。
Grok Botは独立Computerを持ち、ApplicationやInboxを横断してLong-running Taskを実行するAlways-on Agentとして提供されている。(SpaceXAI)
Security Documentationでは、
- Consequential ActionへのApproval
- Explicit Boundary
- Least Privilege
- Read-onlyから開始
- Connector Review
- Action Log保存
などが示されている。(Grok API Documentation)
製品展開速度とAgent Governance Capabilityの対応関係を継続確認する。
Google / Google DeepMind、Meta、Palantir、OneTrust、NVIDIA
今回の調査期間では、前回比較基準を変更する重要なGovernance / Safety Framework更新は確認できなかった。
OneTrustは8月25日にRuntime Governance Webinarを予定しており、次回内容を確認する。(OneTrust)
今週、気になったポイント
1. Agent Governanceの中心が「Identity」から「Effective Permission」へ進みそう
これまで、
Who is the Agent?
が主要な問いだった。
IBMの今回の更新を見ると、次は、
What can the Agent actually reach?
になる。
AgentがCollaborator Agentを介してToolへ到達する場合、Static Permission Listだけでは不十分。
今後は、
Direct Permission
→ Delegated Permission
→ Inherited Permission
→ Effective Permission
という整理が必要になりそうである。
2. Monitoring自体にもPrivacy Governanceが必要
OpenAIのPrivate Safety Processingは興味深い。
SafetyのためにすべてのDataをProviderが閲覧できるようにする構造では、Enterprise Adoptionと衝突する。
したがって、
Monitor everything
ではなく、
Detect risk without unnecessarily exposing data
という設計が重要になってきた。
Runtime GovernanceとPrivacy Engineeringが接続する領域として継続確認したい。
3. 「Agentを止める」より前に「Agentを隔離する」が重要になっている
OpenAI、Anthropic、UK AISIの事例を並べると、
Kill Switchだけでは遅い。
必要なのは、
Sandbox
→ Network Boundary
→ Permission Boundary
→ Monitoring
→ Alert
→ Containment
→ Kill Switch
というDefense in Depth。
Containmentを単独機能ではなく、Runtime Architectureとして見る必要がある。
まとめ
2026年8月17日から24日までの差分を見ると、今週はRuntime Governanceの「境界」が具体化した週だった。
前回までの観測構造は、
Policy
↓
Agent
↓
Identity
↓
Permission
↓
Runtime
↓
Monitoring
↓
Evaluation
↓
Enforcement
↓
Governance Evidence
だった。
今回の情報を加えると、
Policy
↓
Agent Identity
↓
Direct / Delegated / Effective Permission
↓
Tool / Resource / Network Boundary
↓
Runtime
↓
Privacy-preserving Monitoring
↓
Evaluation
↓
Enforcement
↓
Governance Evidence
↓
Incident Response
↓
Containment / Kill Switch
まで拡張できる。
特にOpenAIがFrontier ModelのTraining自体を一時停止した事実は、「AI Safety」がDeployment時だけの話ではないことを示している。
Model Training、Evaluation、Internal Agent、Research Environment、Production Agent。
すべてが同じGovernance Chainの中に入り始めている。
今回、最も気になった言葉に置き換えるなら、
「AIを監視する」から「AIが動ける境界を設計する」へ
という変化として記録しておきたい。
参照URL
OpenAI
https://openai.com/index/pacing-model-development-cyber-capabilities
https://openai.com/index/offering-zero-data-retention-for-frontier-models
Anthropic
https://www.anthropic.com/aug-2026-risk-report
https://www.anthropic.com/document/aug-2026-risk-report
IBM
Microsoft
https://learn.microsoft.com/en-us/microsoft-agent-365/leadership/govern-agents-support-innovation
https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities
xAI
https://x.ai/news/introducing-grok-bot
https://x.ai/news/grok-bot-more-plans
https://docs.x.ai/grok-bot/approvals-security-and-privacy
Japan AISI
https://aisi.go.jp/activity/activity_news/260818
https://aisi.go.jp/activity/activity_news/260821
European Commission
https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
NIST
https://www.nist.gov/itl/ai-risk-management-framework
OWASP
https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026
https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance
OneTrust
https://www.onetrust.com/resources/governing-ai-at-runtime-webinar