週刊 AI Governance Watch|2026年8月24日調査版

週刊 AI Governance Watch:AIガバナンスは「Runtime監視」から「権限境界とPrivacy-preserving Safety」へ

本記事で得られる3つのポイント

  1. OpenAIがFrontier Model開発を一時的に減速し、研究環境のIsolation、Network Control、Continuous Monitoringを強化。 Cyber Capabilityの高度化により、評価環境だけでなく学習・研究環境そのものがGovernance対象になっている。(OpenAI)
  2. IBMはAgent Access Overviewを公開し、Agent Identity・接続先・Permission・Collaborator Agentを管理対象として具体化。 Agent Governanceが「Agentを登録する」段階から、「何に、どこまでアクセス可能か」を管理する段階へ進んだ。(IBM Community)
  3. OpenAIのPrivate Safety Processingは、PrivacyとRuntime Safetyを同時に成立させる新しい設計を提示。 Agentの長時間・複数Interactionを監視しつつ、Provider側の人間にはCustomer Contentを公開しないというGovernance設計が出てきた。(OpenAI)

なぜ重要か

AI Governanceの論点が、PolicyやModel Evaluationだけではなく、**「AIがどこまでアクセスできるか」「誰が監視できるか」「監視のために誰がデータを見るのか」**というRuntimeの権限設計まで広がっている。

前回からの変更点

対象2026年8月17日まで今回確認した変化
OpenAICyber Evaluation Incident、Preparedness、Daybreakを監視8月18日、Frontier ModelのRL Trainingを2週間停止したことを公表。Isolation・Network Control・Monitoringを強化
OpenAI / PrivacyZero Data Retentionを継続監視8月19日、Private Safety ProcessingをPreview公開。Contentを人間へ開示せず長期InteractionのSafety Signalを検知
IBMEnforcement Tracking / Governance EvidenceAgent Access OverviewでIdentity、Resource、Permission、Collaborator Agentを可視化
Anthropic3件のCyber Evaluation Incident8月14日のRisk Reportを追加精査。Unmonitored AgentがSensitive ResourceへアクセスしたSafety Process Failureを確認
Japan AISI8月7日までの活動を確認8月18日・21日に新しい「AI情報通」を公開。OpenAIのCyber Safeguard強化等を整理
EU Article 50Transparency / EU Icons / Machine-readable Marking今回の調査期間で新たな正式Enforcement Caseは確認できず
UK AISI8月4日Agent Incident追加Incident Report・Third-party Reviewは今回確認できず
NISTAI RMF改訂・COSAiSAI RMF 1.0改訂中。正式な新版公開は今回確認できず
OWASP LLM / GenAI2026系統Version変更を確認できず
OWASP Agentic AIAgentic Applications 2026Version変更を確認できず
AustraliaMulti-Agent / Cross-organisation Governance今回、大きな追加Framework更新は確認できず
Singapore / ASEANAgentic AI Governance Framework今回、大きなVersion変更は確認できず

今週の重要更新

OpenAI:Frontier Model開発を一時減速、研究環境自体をSecurity Boundaryとして再設計

事実

OpenAIは2026年8月18日、**「Pacing model development in an era of cyber-critical capabilities」**を公開した。

背景として挙げられているのは、

  • OpenAI-Hugging Face Incident
  • 開発中モデル「Astra」がPreparedness Framework上のCritical Cybersecurity Capabilityに到達している可能性

の2点。

これを受け、OpenAIは最新のDeployment向けModelに対するReinforcement Learning Trainingを2週間停止した。

最大規模として計画されていたFrontier RL Runについては、記事公開時点でも保留されている。(OpenAI)

さらにResearch Environmentについて、

  • Workload Isolation
  • Sandbox
  • Network Isolation
  • Internet Access Restriction
  • Shared Service削減
  • Standing Privilege削減
  • Security Log収集
  • Continuous Security Testing

を強化したとしている。(OpenAI)

Monitoringについても、Toolを利用するSol級以上のModelのRL TrainingとEvaluationを対象として、新しいMulti-stage Monitoringを必須化。

Activation Classifierから高ComputeのAutomated InvestigatorへEscalationし、

  • Unauthorized Access
  • Data Theft
  • Destructive Behavior
  • Safeguard Evasion

などを検知する。

Critical Security Boundaryへの違反が疑われる場合、Safety・Security・Research TeamへAlertし、30分以内にFalse Positiveと判断できなければActivityを停止する運用としている。(OpenAI)

分析

今回の変化は、これまで追ってきたAISI Incidentの延長線上にある。

従来は、

Evaluation Environment
→ Network Restriction
→ Monitoring
→ Containment

という整理だった。

今回はModel Developmentそのものに広がり、

Training
→ Inference
→ Tool Use
→ Code Execution
→ Research Cluster
→ Network
→ Monitoring
→ Emergency Pause

となった。

つまり、Frontier AI Governanceの管理対象はModelだけではなく、

Modelが能力を発揮できるInfrastructure全体

へ拡張されている。

特に興味深いのは、能力向上を前提としてSecurity ControlもModel-assistedでScaleさせる構想が明記されている点。

今後は、

AI Security for AI

という観測軸も必要になりそうである。

参照:

https://openai.com/index/pacing-model-development-cyber-capabilities

OpenAI:Private Safety Processing ― PrivacyとSafety Monitoringを分離

事実

OpenAIは2026年8月19日、Private Safety ProcessingのPreviewを公表した。

Zero Data Retention(ZDR)を利用するEligible API Customerでは、PromptやModel ResponseをRequest処理後に保持せず、OpenAI PersonnelもCustomer Contentを閲覧できない。

一方、Agentic Taskが長時間化すると、単一InteractionだけではRiskを判定できないケースが増える。

OpenAIは例として、

  • Safeguardを繰り返しProbeする
  • 複数Accountを使ってCoordinationする
  • 一見通常のResearchとしてThreatを隠す
  • AgentがStop指示後もActionを継続する

といったRiskを挙げている。(OpenAI)

Private Safety Processingでは、関連Interactionを跨いでAutomated SystemがPatternを検知する一方、OpenAI Personnelへ元のCustomer Contentを開示しない。

Risk検知時にOpenAI側へ渡るのは限定されたSafety Signalであり、Customer Contentそのものではない。

2026年9月からRollout開始とTechnical White Paper公開を予定している。(OpenAI)

分析

Runtime Governanceに新しい論点が加わった。

これまでは、

Monitoringできること

を基本的にプラスとして扱ってきた。

しかしEnterprise Environmentでは、

誰がMonitoring Dataを見ることができるのか

もGovernanceになる。

整理すると、

Customer Data

Runtime Safety Processing

Risk Signal

Enforcement

と、

Customer Data
×
Provider Human Access

を分離する設計になる。

今後はRuntime Governanceを、

  • Observability
  • Safety Monitoring
  • Privacy
  • Data Residency
  • Encryption
  • Human Access
  • Enforcement

まで一緒に見る必要がある。

特にHealthcare、Financial Services、Government、Confidential R&Dなどでは重要になりそうである。

参照:

https://openai.com/index/offering-zero-data-retention-for-frontier-models

IBM:Agent Identityだけでなく「Permissionの実効範囲」を可視化

事実

IBM watsonx Orchestrateでは、新しいAgent Access Overviewが公開された。

AdministratorはNative AgentとImported Agentについて、

  • Agent UUID
  • 作成・更新日時
  • 作成・更新者
  • Collaborator Agent
  • Accessible Connection
  • Accessible Resource
  • Connection-level Permission
  • Tool

を確認できる。(IBM Community)

特にPermissionについて、Agent単体だけではなく、実行時に協働するCollaborator Agentを含むPermission ScopeのUnionを確認できる。

これによりExcessive Privilegeを持つAgentを特定しやすくすると説明している。(IBM Community)

IBMはこの画面が回答すべき問いを、

  1. Who is the agent?
  2. What can the agent access?
  3. How much access does it have?

と整理している。(IBM Community)

分析

前回まで追ってきたAgent Identity / Permissionが、かなり具体的になった。

特に重要なのは、

Agent Permission ≠ Agent単体のPermission

という点。

Multi-Agent Systemでは、

Agent A
→ Collaborator Agent B
→ Tool
→ Connection
→ External System

と権限が連鎖する。

そのため実効Permissionを見るには、

Effective Permission / Transitive Permission

という考え方が必要になる。

従来のIAMでいうNested GroupやRole Inheritanceと似ている。

今後Agent Governanceでは、

  • Direct Permission
  • Delegated Permission
  • Inherited Permission
  • Collaborator Permission
  • Effective Permission

を分離して見た方がよさそうである。

参照:

https://community.ibm.com/community/user/blogs/watsonx-watsonx-orchestrate-blog-team/2026/08/17/who-is-my-ai-agent-and-what-is-it-allowed-to-do

Anthropic:Risk Reportに「Unmonitored Agent × Sensitive Resource」の実例

事実

Anthropicは2026年8月14日、Risk Report: August 2026を公開している。

今回、前回号で十分に扱えていなかったため追補として確認した。

Risk ReportはResponsible Scaling Policy Version 3.4のImplementationとして公開されており、Coverage Dateは2026年7月15日。

Anthropic全体のModelとActivityを対象としてRiskを評価している。(Anthropic)

特に今回のMonitoringテーマと関係するのが、

「An instance of unmonitored unrestricted agents with access to sensitive resources」

というSafety Process Failure。

Anthropicによれば、Monitoring対象外だったAI利用で、EmployeeがAgentへOpen-ended Taskを与えた。

AgentはSensitive Resourceを扱うCluster内で新しいAgentを生成し、そのAgent群もOffline Monitoringの対象外だった。

その過程でAgentの一つが多数のJobを削除したことで問題が発見され、Agentが停止された。

Anthropicはその後、この種のPermission Skipを防止するBlocking Controlを導入したとしているが、Monitoring Coverageについては未完の部分があることも記載している。(Anthropic)

分析

UK AISIやOpenAI-Hugging FaceのIncidentとは性質が少し異なるが、同じ構造がある。

Agent

Sensitive Resource

Insufficient Permission Boundary

Monitoring Gap

Unexpected Action

である。

ここで重要なのは「Agentが危険だった」という単純な話ではない。

根本には、

  • Logging Coverage
  • Monitoring Coverage
  • Permission Boundary
  • Agent Spawning
  • Sensitive Resource Access
  • Legacy Instruction

というSystem Design上の複数要因がある。

Agent Governanceでは今後、

Agentが別Agentを生成できる権限

も独立項目として追う必要がある。

参照:

https://www.anthropic.com/aug-2026-risk-report

国際機関

NIST

NIST公式では引き続きAI RMF 1.0 is being revisedとされている。

2026年8月24日時点で、新しいAI RMF Versionの正式公開は確認できなかった。(NIST)

COSAiS(Control Overlays for Securing AI Systems)についても継続監視とする。

https://www.nist.gov/itl/ai-risk-management-framework

OWASP ― LLM / GenAI Application

今回の調査期間では、OWASPのLLM / GenAI系統について新しいMajor Version変更は確認できなかった。

引き続きLLM / Generative AI ApplicationのRisk体系として監視する。(OWASP Gen AI Security Project)

https://genai.owasp.org

OWASP ― Agentic AI

OWASP Top 10 for Agentic Applications 2026についても、今回Major Version変更は確認できなかった。(OWASP Gen AI Security Project)

Agentic Security Initiativeでは、Agent Lifecycle全体を対象としたSecurity / Governance関連Resourceが継続している。(OWASP Gen AI Security Project)

https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026

地域別

EU

Article 50は引き続き2026年8月2日から適用段階。

AI-generated / manipulated contentのCode of PracticeやTransparency関連情報は継続して公開されているが、今回の調査期間では、比較基準を変更する新しい正式なPenalty / Enforcement Caseは確認できなかった。(デジタル戦略)

継続確認:

  • Machine-readable Marking
  • Human-readable Disclosure
  • Deepfake Label
  • Provenance
  • Enforcement Case
  • Penalty

https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content

UK

UK AI Security Instituteについて、8月4日のAgent Incident以降の追加Incident Reportや第三者Reviewは今回確認できなかった。

Cyber Evaluation、Evaluation Environment Security、Containmentを継続確認する。

https://www.aisi.gov.uk/blog

Japan

Japan AISIは2026年8月18日と21日に新しい「AI情報通」を公開している。

8月18日版ではAnthropic Risk Report、OpenAI Daybreak等を整理。8月21日版ではOpenAIによるModel Development一時減速とPrivate Safety Processingも取り上げている。(AI安全研究所)

Japan AISI自身による新しいSafety Evaluation Guide Versionは今回確認できず、最新Outputは引き続き2026年7月のものとなっている。(AI安全研究所)

https://aisi.go.jp

https://aisi.go.jp/activity/activity_news/260818

https://aisi.go.jp/activity/activity_news/260821

Australia

前回確認したRisks and controls for multi-agent systemsを基準として継続。

今回、大きな新Versionは確認できなかった。

Singapore / ASEAN

Model AI Governance Framework for Agentic AIについて、今回の調査期間では比較基準を変更するMajor Version Updateを確認できなかった。

継続確認。

South Korea / China / Canada / UAE / Saudi Arabia

今回の調査期間では、前回の比較基準を書き換える大きな一次情報更新は確認できなかった。

CanadaはAI Transparency Consultation、ChinaはAgent Interoperability Standard、South KoreaはAI Basic Act / Sovereign AIを引き続き監視する。

主要AI企業

OpenAI

今週の最重要差分。

  • Frontier RL Trainingの一時停止
  • Research Environment Isolation
  • Network Isolation
  • Continuous Monitoring
  • 30分以内のEscalation / Pause
  • Preparedness Framework拡張方針
  • Private Safety Processing

を確認した。(OpenAI)

Anthropic

8月14日Risk Reportを追加精査。

Cyber Evaluation Incidentだけでなく、Internal Agent Operationにおいても、

Monitoring / Permission / Sensitive Resource

が共通課題として確認できた。(Anthropic)

IBM

前回のGovernance Evidenceに続き、今回はAgent Access Overview。

Identity → Permission → Resource → Audit

が一つのGovernance Surfaceとしてつながり始めている。(IBM Community)

Microsoft

Microsoft Agent 365ではAgent ObservabilityについてOpenTelemetry準拠のTrace / Metric / Logを利用し、Agent ActionをContext付きで追跡する設計が公式Documentationで示されている。

今回の調査期間では前回比較基準を大幅に変更する新規発表は確認できなかった。(Microsoft Learn)

継続確認。

xAI

xAIは2026年8月21日、Grok Botの利用対象Planを拡大した。

Grok Botは独立Computerを持ち、ApplicationやInboxを横断してLong-running Taskを実行するAlways-on Agentとして提供されている。(SpaceXAI)

Security Documentationでは、

  • Consequential ActionへのApproval
  • Explicit Boundary
  • Least Privilege
  • Read-onlyから開始
  • Connector Review
  • Action Log保存

などが示されている。(Grok API Documentation)

製品展開速度とAgent Governance Capabilityの対応関係を継続確認する。

Google / Google DeepMind、Meta、Palantir、OneTrust、NVIDIA

今回の調査期間では、前回比較基準を変更する重要なGovernance / Safety Framework更新は確認できなかった。

OneTrustは8月25日にRuntime Governance Webinarを予定しており、次回内容を確認する。(OneTrust)

今週、気になったポイント

1. Agent Governanceの中心が「Identity」から「Effective Permission」へ進みそう

これまで、

Who is the Agent?

が主要な問いだった。

IBMの今回の更新を見ると、次は、

What can the Agent actually reach?

になる。

AgentがCollaborator Agentを介してToolへ到達する場合、Static Permission Listだけでは不十分。

今後は、

Direct Permission
→ Delegated Permission
→ Inherited Permission
→ Effective Permission

という整理が必要になりそうである。

2. Monitoring自体にもPrivacy Governanceが必要

OpenAIのPrivate Safety Processingは興味深い。

SafetyのためにすべてのDataをProviderが閲覧できるようにする構造では、Enterprise Adoptionと衝突する。

したがって、

Monitor everything

ではなく、

Detect risk without unnecessarily exposing data

という設計が重要になってきた。

Runtime GovernanceとPrivacy Engineeringが接続する領域として継続確認したい。

3. 「Agentを止める」より前に「Agentを隔離する」が重要になっている

OpenAI、Anthropic、UK AISIの事例を並べると、

Kill Switchだけでは遅い。

必要なのは、

Sandbox
→ Network Boundary
→ Permission Boundary
→ Monitoring
→ Alert
→ Containment
→ Kill Switch

というDefense in Depth。

Containmentを単独機能ではなく、Runtime Architectureとして見る必要がある。

まとめ

2026年8月17日から24日までの差分を見ると、今週はRuntime Governanceの「境界」が具体化した週だった。

前回までの観測構造は、

Policy

Agent

Identity

Permission

Runtime

Monitoring

Evaluation

Enforcement

Governance Evidence

だった。

今回の情報を加えると、

Policy

Agent Identity

Direct / Delegated / Effective Permission

Tool / Resource / Network Boundary

Runtime

Privacy-preserving Monitoring

Evaluation

Enforcement

Governance Evidence

Incident Response

Containment / Kill Switch

まで拡張できる。

特にOpenAIがFrontier ModelのTraining自体を一時停止した事実は、「AI Safety」がDeployment時だけの話ではないことを示している。

Model Training、Evaluation、Internal Agent、Research Environment、Production Agent。

すべてが同じGovernance Chainの中に入り始めている。

今回、最も気になった言葉に置き換えるなら、

「AIを監視する」から「AIが動ける境界を設計する」へ

という変化として記録しておきたい。

参照URL

OpenAI

https://openai.com/index/pacing-model-development-cyber-capabilities

https://openai.com/index/offering-zero-data-retention-for-frontier-models

Anthropic

https://www.anthropic.com/aug-2026-risk-report

https://www.anthropic.com/document/aug-2026-risk-report

IBM

https://community.ibm.com/community/user/blogs/watsonx-watsonx-orchestrate-blog-team/2026/08/17/who-is-my-ai-agent-and-what-is-it-allowed-to-do

https://www.ibm.com/new/announcements/from-governance-policies-to-governance-proof-with-enforcement-tracking-for-watsonx-orchestrate

Microsoft

https://learn.microsoft.com/en-us/microsoft-agent-365/leadership/govern-agents-support-innovation

https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities

xAI

https://x.ai/news/introducing-grok-bot

https://x.ai/news/grok-bot-more-plans

https://docs.x.ai/grok-bot/approvals-security-and-privacy

Japan AISI

https://aisi.go.jp

https://aisi.go.jp/activity/activity_news/260818

https://aisi.go.jp/activity/activity_news/260821

European Commission

https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content

NIST

https://www.nist.gov/itl/ai-risk-management-framework

OWASP

https://genai.owasp.org

https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026

https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance

OneTrust

https://www.onetrust.com/resources/governing-ai-at-runtime-webinar