

週刊 AI Governance Watch|2026年9月28日調査版
週刊 AI Governance Watch:AI Incident Governanceは「国家間連絡」へ
2026年9月21日号からの差分を、企業がIncidentを公開した後に、国家がどの経路で共有し、分類し、検証し、エスカレーションするのかという観点で記録します。
今週の中心は、AI Incident Governanceの管理境界が、企業内のCase ManagementやPublic Disclosureから、National Authority、Cross-border Notification、Bilateral/Multilateral Coordinationへ広がった点です。
更新が確認できなかった領域は過去説明を繰り返さず、継続確認として簡潔に整理します。
調査・記述方針
政府・国際機関・標準化団体・企業の一次情報を優先し、政策提言、共同声明、法的義務、製品発表、第三者評価を区別して記録しています。確認できない事項は推測で補わず、「未確認」「継続確認」として扱います。
本記事で得られる3つのポイント
- 米中はAI Incidentの二国間Communication Channel設置で合意した。両国の公式発表で確認でき、次回のAI Dialogueは2026年11月とされた。連絡先、対象Incident、通知Threshold等の運用詳細は未公表である。
- Serious Safety Incidentの共有が国際提案へ進んだ。フィンランド・ノルウェー主導の声明は、共通Standard、重大IncidentのShared Reporting、能力閾値超過時に国家を招集できる国際機関を提案した。ただし制度化済みではない。
- 国家間共有に必要なEvidence形式も具体化し始めた。OpenAIは第三者AssessmentのScope、Access、Independence、Publication原則を公表し、UK AISIはEvaluation Cardで設定・文脈・結果を構造化して公開した。
なぜ重要か:#015ではIncidentを企業内でCase化し、第三者へ通知し、段階的に公開する手順を確認した。今週は、その情報を国境を越えて誰に渡し、同じ分類とEvidenceで判断できるようにするかが新しいGovernance Layerとして現れた。
前回からの変更点
| 対象 | 2026年9月21日号まで | 今回確認した変化 |
|---|---|---|
| 米国・中国 | 企業・国内当局向けIncident Reportingを中心に観測。 | 9月25~26日の両国公式発表で、AIのRisk/Benefitを議論するDialogueと、AI Incidentの二国間Communication Channel設置への合意を確認。次回Dialogueは11月予定。 |
| 国際的なIncident共有 | 共通Reporting Thresholdや国際連携を監視。 | 9月21日のFrontier AI声明は、政府間の共通Standard、重大Safety IncidentのShared Reporting、能力閾値超過時に国家を招集できる国際機関の検討を提案。声明は9月24日まで追加署名で更新された。 |
| 国連安全保障理事会 | AI Safetyを国際機関・標準化の観点で監視。 | 9月23日にOpenAI、Anthropic、Hugging Face等が出席する会合を開催。共通Evaluation、Incident Disclosure、Human Oversightが議論された一方、米国代表はGlobal Governanceへ進むことに反対を表明した。 |
| OpenAI Third-party Assessment | #014~#015でIndependent Assessment、Embedded Evaluator、Funding、Reporting Rightを監視。 | 9月22日、Safety Claim/Safety Case、事前登録したScope、Proportionate Access、利益相反、Redaction、Editorial Independence、Incident Investigationを含む原則を公表。 |
| UK AISI/EvalEval | Evaluator Identity、Version、Governance Evidenceを監視。 | 9月22日、AISIの評価結果をEvaluation Cardsで共有。Model、Benchmark、Configuration、Context、Resultを共通Schemaへ載せ、再現性と比較可能性を補う運用を確認。 |
| Agent Control | Identity、Permission、Runtime Enforcement、Containmentを個別製品・標準で監視。 | 9月22日、Okta等12社がBlueprint Allianceを設立。AgentをFirst-class Identityとして扱い、Task-scoped Access、Traceable Delegation、Continuous Monitoring、Instant and Reversible Containmentを共通原則にした。 |
| 米国州政府 | CaliforniaのAuditor/IVO制度とKill Switch検討を確認。 | Californiaは9月23日に専門家4名を発表し、Embedded Verification、継続的に検証されるKill Switch、Loss-of-controlをCritical Incident定義へ含める案を具体化。Oregonは調達基準として第三者ReviewとKill Switchの検討を開始した。 |
| Canada/NIST/OWASP | Canada Consultation、NIST TEVV-Athlon、OWASP 2系統を継続監視。 | Canada Consultationは9月23日に受付期間終了。Summaryや制度化方針は未確認。NISTの意見募集は10月6日まで継続し、OWASPのMajor Version更新は今回確認できなかった。 |
今週の重要更新
米国・中国:AI Incidentの二国間Channel設置で合意
事実
中国外交部は9月26日、9月23~25日の米中首脳協議の成果として、AIのRiskとBenefitを扱うChina-U.S. AI Dialogueの設置、2026年11月の次回協議、AI Incidentのためのbilateral communication channel設置への合意を公表した。
米国側も9月25日のWhite House Fact Sheetで、U.S.-China Super Intelligence Dialogueと、SI Incidentの二国間Communication Channel設置を公表した。名称は異なるが、Incident Channelの設置と11月の次回対話は両国の一次情報で一致する。
一方、対象とするIncidentの定義、通知Threshold、Contact Point、利用言語、Evidence Format、機密区分、応答時間、共同調査、訓練予定は今回確認できなかった。
分析
#015のDisclosure Workflowは、Labから第三者・当局・Publicへ向かう構造だった。今回追加されたのは、National Authority → Foreign Counterpartという国家間のRouteである。
Channelの存在だけでは、相互運用可能なProtocolとはいえない。Incident Category、Severity、Confidence、Affected Infrastructure、Containment Status、Model/Agent Versionを同じ粒度で伝えられるかが次の観測点になる。
観測構造には、Cross-border Notification、National Contact Point、Secure Channel、Acknowledgement、Escalation Stateを追加する。
Frontier AI声明:重大Incident共有と国際的な招集機能を提案
事実
フィンランド大統領とノルウェー首相が主導した9月21日の声明は、Frontier AIについて、Mandatory Pre-deployment Testing、Independent Evaluation、Evaluatorへの十分なAccessを企業へ求めた。
政府・地域機関にはCommon Standardsの調整、重大Safety IncidentのShared Reporting、Trusted Evaluationへの各地域のAccessを求めた。国連加盟国には、Standard設定、Verification、能力閾値を超えたときの国家招集が可能な国際機関の検討を提案した。
当初のPress Releaseは22人のLeaderによる支持と説明した。その後、声明本文は9月24日まで追加署名者を追記している。これは共同声明であり、条約、国連決議、施行済みRuleではない。
分析
「重大Incidentを各社が公開する」から、「各国が共通形式で共有する」への拡張が明文化された。ただし、Seriousの定義と、誰がThreshold超過を判定するかは未確定である。
声明の署名者リストが後日更新されたこと自体も、Governance EvidenceのVersion管理を示す。公開日だけでなく、Endorsement Date、Current Signatory Set、Statement Versionを残す必要がある。
国連安保理:共通Governanceの必要性と政治的な分岐を同時に確認
事実
国連安全保障理事会は9月23日、AIと国際Securityを議題とする第10228回会合を開催した。OpenAIのSam Altman氏は、Capability測定、Risk Assessment、Safeguard Sufficiency、Human Oversightの共通Standard、迅速なIncident Classification/Reporting Protocol、政府・Critical Infrastructure・技術専門家間のSecure Channelを提案した。
AnthropicのDario Amodei氏は、MisuseとLoss of Controlを主要Riskに挙げ、共通Evaluation/Verificationと限定的な国際合意を主張した。Hugging FaceのClément Delangue氏は、MonitoringとIncident DisclosureのStandard強化を求めた。
一方、米国代表は国際対話には参加するが、Global Governanceへ移行することには反対を表明した。会合で新たな決議や拘束的制度が成立したことは確認できない。
分析
技術的な論点は共通化しているが、Institutional Modelは合意していない。したがって「国際AI安全機関が設立された」とは扱わず、共通VocabularyとSecure Information Sharingへの収れんを今回の差分とする。
今後は、UNSCのFollow-up、二国間Channel、任意の共同声明、国内Ruleが並行して進む可能性がある。Global Governanceの単一路線ではなく、複数経路のFederated Governanceとして追う。
OpenAI:Safety Claimを事前登録し、Accessと公表権を設計する
事実
OpenAIは9月22日、「Priorities and principles for effective third party assessments」を公表した。対象はSafety Case、Critical Safeguards、Capability/Alignment Evaluations、Critical Misalignment Incidentの独立調査の4領域である。
AssessmentはClaimとScopeを事前に合意・登録し、制約に応じたProportionate Accessを提供する。Methodology、Criteria、Uncertaintyを明示し、利益相反、Security、Confidentiality、Remediation期間、Responsible Publication、Redaction Policyを扱う。
AssessorはEditorial Independenceを維持し、重要なRedactionがあった場合はその事実とReportへの影響を示せる設計が提案されている。これはOpenAIの原則公表であり、独立標準化団体のFinal Standardではない。
分析
#014の「常設外部検証」、#015の「FundingとReporting Right」に対して、今回は何をClaimとして検証し、どのAccessで、どの制約を伴って公表するかが具体化した。
第三者Reportを国家間で共有するには、Scope ID、Claim ID、Evidence Source、Access Mode、Redaction Log、Conflict Disclosure、Version、Verification Statusを構造化する必要がある。
UK AISI/EvalEval:評価結果をComparison-readyなCardへ
事実
9月22日、EvalEval CoalitionはUK AISIが評価結果をEvaluation Cardsで公開する運用を発表した。Every Eval Ever Schemaを使い、結果、Context、Configurationを共通構造で表現する。
今回のReleaseには5 Benchmark、6 Frontier Modelの結果と、2つのCyber Evaluationが含まれる。評価ProtocolやInference-time Computeの違いによりScoreが変わり得るため、同じModel名の数値を単純比較しないためのContextが添えられる。
これはUK AISIの全Evaluationを網羅するMandatory Registryではなく、公開可能な結果を共通Infrastructureへ載せるCollaborative Practiceとして確認した。
分析
国家間Incident Channelが機能するには、警告文だけでなく再現可能なEvidence Packageが必要になる。Evaluation Cardは、Model Version、Benchmark Version、Harness、Prompting、Compute、Resultを比較可能にする一つの実装例に見える。
Incident ReportとEvaluation CardをCase IDで結べれば、発見、検証、是正後の再評価までを一連のGovernance Evidenceとして残せる。
Blueprint Alliance:Agent Controlを複数Vendorの共通Architectureへ
事実
Oktaは9月22日、AWS、CrowdStrike、Databricks、Docker、Google Cloud、Salesforce、ServiceNow、Wiz、Zscaler等とBlueprint Allianceを設立した。
共通原則は、AgentをFirst-class Identityとして扱うこと、Standing AccessではなくTask Scopeに権限を限定すること、Delegationを追跡可能にすること、Runtime Behaviorを継続監視すること、Containmentを即時かつReversibleにすること、Governanceを継続更新することである。
OpenなMulti-vendor Reference Architectureとして公表されたが、独立認証、相互運用試験、導入組織での実効性は今回確認できない。
分析
二国間Channelが国家レベルの接続なら、Blueprint AllianceはEnterprise Stack内の接続である。どちらも、Identity、Scope、Trace、Containment、Responseを組織境界の外で共有する課題を持つ。
特にReversible Containmentは、Kill Switchを「停止するボタン」から、影響範囲を限定し、復旧判断とEvidenceを残すResponse Workflowへ広げる。
今週更新されたGovernance構造
今回の差分は、企業内のDisclosure Workflowの外側へ、国家間の受領確認、共通分類、Evidence、Escalationを加えた点にある。
Cross-border Notification Scope
対象Incident、除外、第三国・民間組織への波及。
National Contact Point
送信機関、受信機関、24時間対応、権限委任。
Incident Vocabulary
Category、Severity、Confidence、Attribution、Containment State。
Secure Channel
認証、暗号化、機密区分、Acknowledgement、監査Log。
Evidence Package
Case ID、Model/Agent Version、Timeline、Evaluation Card、Redaction Log。
Escalation State
情報共有、共同分析、政策協議、緊急対応、Public Notice。
国際機関・標準化
Security Council
9月23日の会合で、共通Evaluation、Incident Disclosure、Secure Channel、Human Oversightが議論された。新たな決議や国際機関の設立は確認できず、Institutional Modelには意見の分岐が残る。
AI RMF/TEVV-Athlon
AI RMFの新Versionは今回確認できなかった。NIST AI 200-2 Initial Public Draftへの意見募集は2026年10月6日まで。Cross-border Evidenceにも使えるEvaluation用語とRecord構造を継続確認する。
LLM/Agentic/ACS
LLM Applications 2026、Top 10 for Agentic Applications 2026、Agent Control Standardを別系統として確認。今回の調査期間ではMajor Version更新を確認できなかった。
Incident・Logging・Conformity
今回の調査範囲では、国家間AI Incident Channel、Agent Logging、Conformity Assessmentの比較基準を変更する新たな公式標準発行を確認できなかった。
地域別
Bilateral Incident Channel
両国の公式発表で設置合意を確認。11月の次回Dialogueまでに、Contact Point、Scope、Threshold、Protocol、演習の有無が公表されるかを最優先で追う。
Kill SwitchとIncident Definition
9月23日に専門家4名を発表。Embedded Independent Verification、Kill Switchの継続検証、Hugging Face AttackのようなLoss-of-controlをCritical Safety Incident定義へ含める提案を検討する。
ProcurementをGovernance Leverへ
9月23日のEO 26-26は、州CIOに第三者AI Safety Reviewの基準とFrontier ModelのKill Switch要件の実現性を検討させる。90日以内の実装提案を待つ。
Consultation受付終了
AI Transparency Consultationは9月23日に受付期間を終えた。今回、What We Heard、Incident Reporting Threshold、制度化Scheduleは確認できず、Publication Stateは「Consultation closed/response pending」と記録する。
Article 50
今回の調査期間では、新たなEnforcement Case、Authority Decision、Penaltyを一次情報で確認できなかった。ProviderのMachine-readable MarkingとDeployerのVisible Labelを分けて継続確認する。
政策・AISI Japan
今回の調査範囲では、AI基本計画、AI事業者ガイドライン、「源内」、AI Incident Reportingの比較基準を変更する大きな一次情報更新は確認できなかった。
IA360 Plan
9月21日、政府は今後12か月のIA360 Planを公表し、Cybersecurity強化とFrontier Model MonitoringをGovernanceの柱にした。具体的なIncident Reporting RuleやBudgetは今回確認できない。
継続監視
South Korea、Singapore/ASEAN、Australia、UAE、Saudi Arabiaでは、共同声明への参加を除き、今回の観測構造を変更する大きな国内制度更新を確認できなかった。
主要AI企業
Third-party AssessmentのPriorityとPrinciple、UNSCでの共通Incident Protocol提案が最大差分。次回は実際のAssessor、Pre-registered Scope、Report、Redaction Logを確認する。
UNSCでMisuse/Loss of Control、Evaluation/Verificationの共通化と限定的合意を提案。Accenture/Faculty Embedded Evaluatorの実働開始日・最初のReportは未確認。
UNSCでIncident Disclosure Standardを求めた。UK AISI/EvalEvalの公開Schemaは、Incident Evidenceの比較可能性という観点で継続確認する。
Blueprint AllianceはIdentity、Task Scope、Delegation、Runtime Monitoring、Reversible ContainmentをMulti-vendor Architectureへ整理した。Specification、Version、Interoperability Test、独立評価は今後の確認事項。
Agent Identity、Effective Permission、Runtime Enforcement、Governance Evidence、Change Approvalを継続監視。Cross-organization Incident共有にCase IDとEvidence Packageを接続できるかを見る。
今回の調査期間では、比較基準を変更する主要なSafety Frameworkまたは公式Incident Follow-upを一次情報で確認できなかった。
今週、気になったポイント
HotlineとProtocolは同義ではない
二国間Channelの設置は大きな差分だが、誰が、何を、いつ送るかが決まらなければ運用できない。Cyber IncidentやNuclear Risk Reductionで使われる連絡経路と、AI固有のCapability/Model Evidenceをどう接続するかが気になる。
Shared Languageは技術Controlでもある
SeverityやConfidenceの定義が異なると、同じIncidentでも緊急度がずれる。Vocabulary、Schema、Version、Acknowledgementは書類上の整理ではなく、Responseの遅延や誤解を減らすOperational Controlになる。
国家間共有の前にEvidence Qualityが問われる
OpenAIのClaim/Scope、AISIのEvaluation Card、Blueprint AllianceのTraceは別の取組だが、いずれも「何を根拠に判断したか」を構造化している。国家間Channelの有用性は、送られるEvidenceの質に依存する。
中小企業の観点で残しておくメモ
国家間Channelを直接運用する場面は限られるが、利用するAI ServiceのIncidentが国境を越えることはある。契約・台帳・Response Planでは、次の項目が比較材料になる。
- Providerから利用者、国内当局、海外関係先へ通知されるIncidentの範囲
- Severity、Confidence、Attribution、Containment Stateの定義
- 利用Model/Agent Version、Case ID、Timeline、Evidence Packageの提供可否
- Third-party AssessmentのScope、Access Mode、利益相反、Redaction、公開Version
- AgentのTask-scoped Permission、Delegation Log、Reversible Containment、復旧承認
まとめ
2026年9月21日から28日までの差分では、AI Incident Governanceの管理境界が、企業内のCase ManagementとPublic Disclosureから、国家間のCommunicationへ広がった。
最も具体的な変化は、米国と中国がAI Incidentの二国間Channel設置に合意し、双方が公式発表したことである。一方、その運用Protocolは未公表であり、Channelの設置と実効的なIncident Responseは分けて観測する必要がある。
国際声明と国連安保理では、Shared Reporting、Common Evaluation、Verification、Human Oversightの必要性が繰り返された。ただし、拘束的なGlobal Governanceには政治的な分岐が残り、新たな国際機関や共通Ruleが成立したわけではない。
今回追加する観測構造は、Lab Case → Independent Evidence → National Authority → Cross-border Channel → International Coordinationである。次回は、この経路にContact Point、Threshold、Vocabulary、Evidence Schema、演習、更新履歴が入るかを確認する。
参照URL
米国・中国
- https://www.fmprc.gov.cn/eng/xw/zyxw/202609/t20260926_12031663.html
- https://www.whitehouse.gov/fact-sheets/2026/09/fact-sheet-president-donald-j-trump-advances-a-fair-and-reciprocal-relationship-with-china-while-hosting-historic-state-visit/
国連・国際声明
- https://press.un.org/en/sc/16462.doc.htm
- https://news.un.org/en/story/2026/09/1168414
- https://www.regjeringen.no/en/whats-new/international-call-for-enhanced-control-of-ai-development/id3173324/
- https://www.regjeringen.no/en/whats-new/dep/smk/press-releases/2026/international-call-for-enhanced-control-of-ai-development/a-call-for-control-of-frontier-ai-models/id3173739/
OpenAI
- https://openai.com/index/priorities-principles-third-party-assessments/
- https://openai.com/index/sam-altman-un-security-council-remarks/
- https://openai.com/index/our-framework-for-reporting-model-misalignment/
UK AISI/Evaluation Evidence
- https://huggingface.co/blog/evaleval-aisi
- https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
Agent Control/企業
米国州政府
- https://www.gov.ca.gov/2026/09/23/governor-newsom-announces-world-leading-experts-to-deliver-on-his-ai-executive-order-including-advancing-creation-of-a-kill-switch/
- https://apps.oregon.gov/oregon-newsroom/OR/GOV/Posts/Post/governor-kotek-issues-executive-order-to-advance-ai-safety-and-oversight
Canada/Spain/EU
- https://ised-isde.canada.ca/site/ised/en/have-your-say-advancing-ai-transparency-canada
- https://ised-isde.canada.ca/site/ised/en/have-your-say-advancing-ai-transparency-canada/enhancing-trust-artificial-intelligence-through-increased-transparency
- https://www.lamoncloa.gob.es/lang/en/presidente/news/paginas/2026/20260921-ia360-plan-presentation.aspx
- https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations
NIST/OWASP
- https://www.nist.gov/artificial-intelligence/ai-research/tevv-athlon-framework-evaluating-ai-systems
- https://www.nist.gov/itl/ai-risk-management-framework
- https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
- https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
- https://genai.owasp.org/resource/agent-control-standard-acs/
記事の独立性・編集方針
本記事は特定企業・政府・製品の依頼によるものではなく、公開されている一次情報を中心に差分を整理した備忘録です。企業・政府の発表は、その主体による主張・方針・公表内容として扱い、独立評価や法的確定事項とは区別しています。
最終確認日:2026年9月28日



