Databricks、AI セキュリティ推進「Open Secure AI Alliance」に加盟
本文の状態
日本語全文を表示中
詳細モードで約12分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Databricks AI Engineering
Databricks は NVIDIA と共に Open Secure AI Alliance の創設メンバーとなり、AI セーフティとセキュリティのオープン化を推進し、実行スタック全体の透明性と信頼性を高める方針を発表した。
AI深層分析を開く2026年8月5日 11:17
AI深層分析
キーポイント
Open Secure AI Alliance の創設参加
Databricks は NVIDIA やその他の業界リーダーと共に Open Secure AI Alliance の創設メンバーとなり、AI セーフティとセキュリティ研究のオープン共有を推進する。
実行スタック全体の開放性重視
単なるモデル重みの公開だけでなく、ランタイム、ガードレール、オーケストレーションハネス、ガバナンス層を含む「オープンな実行スタック」の重要性を強調する。
セキュリティ・レイクハウスの役割
Databricks は Lakewatch を通じてオープンなデータ基盤を提供し、大規模なエージェント型脅威検知と対応を可能にする Security Lakehouse の実現を目指す。
業界全体での協力体制の構築
チップ、モデル、セキュリティ、インフラ分野を含む 75 組織以上が参加するアライアンスにおいて、オープンなツールや学習成果を共有して新たなサイバーセキュリティ技術を開発する。
Omnigentによるエージェント制御とセキュリティ
Apache 2.0ライセンスのオープンソースメタハネスであるOmnigentは、13以上のハネスでモデルやツールの使用を構成・制御し、ポリシーや支出制限、サンドボックス隔離を強制する。
重要な引用
AI safety and security research should be shared openly, and the tools it produces should be built on open systems.
Security in the agentic era requires an open execution stack: from the runtime and guardrails underneath, to the harness that orchestrates agents and their tools.
Omnigent gives developers choice of harness and model, allowing composition and secure sharing, while enforcing policies, spend caps, and sandbox isolation across 13+ harnesses, both open and closed.
Omnigent's contextual policies enable agent behavior governance by tracking session state, blocking slow-burn attacks, and enforcing intent-based authorization.
編集コメントを表示
編集コメント
Databricks がセキュリティ分野でのオープンソース戦略を強化し、業界全体で標準化された実行スタックの構築を目指す動きは注目される。特にエージェント型 AI の普及に伴い、モデル自体だけでなくその動作環境全体の透明性が求められる中、このアライアンスの実効性が今後の鍵となるだろう。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
今週開催の Black Hat USA 2026 にて、Databricks はスポンサーとして出展します。ブースは #5106 と #2167 です。また、Panther の買収がどのようにセキュリティ・レイクハウス時代の加速に寄与しているかについてもご覧ください。
オープンな AI セーフティとセキュリティの必要性
AI システムの能力と自律性が高まるにつれ、2 つの課題が重なり合っています。1 つは、新たな攻撃クラスから AI システム自体を守ることであり、もう 1 つは、AI を活用してサイバー防御を強化することです。どちらも「オープンさ」が不可欠です。なぜなら、重要なセキュリティインテリジェンスが少数のクローズドなシステム内に閉じ込められていれば、広範なエコシステム全体が脅威にさらされるからです。
Databricks はこの 2 つの使命を両方とも支えています。AI システムを守るためのオープンなフレームワークと、大規模なエージェント型脅威検出・対応を実現する基盤となる「Open Security Lakehouse」を提供する **Lakewatch** です。
そのため、Databricks は NVIDIA や他の業界リーダーと共に、「Open Secure AI Alliance(オープン・セキュア AI アライアンス)」の創設メンバーとして名を連ねることを誇りに思っています。このアライアンスは、AI の安全性とセキュリティに関する研究はオープンに共有され、その成果物はオープンなシステム上で構築されるべきだという、シンプルかつ強力な前提に基づいて設立されました。活動範囲は AI 安全性、AI セキュリティ、そして AI を活用したサイバー防御にまたがり、世界中の企業やソフトウェア、重要インフラを強化することを目指しています。
メンバーたちは、新しいセキュリティツールや技術の開発を加速させるため、オープンモデル、モデルの重み(weights)、オープンな検証環境(harnesses)、オープンなツール群、そしてそれらを支える知見を積極的に公開・貢献しています。
オープンさが重要な理由:モデルを超えて
AI エージェントは単なるモデルではありません。それは、エージェントが何を実行できるかを規定するガードレールや検証環境(harnesses)を組み合わせた複雑なシステムです。企業境界内にあるオープンウェイトモデルのセキュリティに注目が集まりがちですが、重みそのものは一つの層に過ぎません。
エージェンシー時代におけるセキュリティには、実行スタック全体をオープンにすることが不可欠です。これは、エージェントやツールを調整する検証環境(harness)、リスクと制御を定義するフレームワーク、そして企業のセキュリティ・監査可能性・責任所在を確保するガバナンス層に至るまで、その下にあるランタイムやガードレールを含めた全体的な仕組みを指します。
オープンなシステムであれば、広範なコミュニティの防衛者がスタックのあらゆる構成要素を調査・検証し、強化することができます。その結果、保証や可視性、証拠、参加、そして選択に基づいた信頼が築かれます。
Databricks がアライアンスにもたらすもの
このアライアンスには、チップ、モデル、セキュリティ、インフラストラクチャの分野で 75 組織以上が参加しています。NVIDIA は加速計算とオープンな AI インフラを提供し、Databricks は管理されたデータやモデル・エージェント機能に加え、セキュリティ、ガバナンス、レッドチーム演習、サイバー防御のためのオープンなツールやフレームワークを貢献します。
- Omnigent:エージェントがモデルやツールを利用する方法の作成と制御を行います。
- Databricks AI Security Framework (DASF):AI のリスクを実践的な防護策にマッピングします。
- Databricks AI Governance Framework (DAGF):説明責任とガバナンスを定義します。
- BlackIce:実際の攻撃に対する AI システムのテストを行います。
- Lakewatch:統合されたデータ上でエージェントによる検出やハンティングを可能にします。
アライアンス全体からの貢献と相まって、これらの取り組みはフルスタックのエージェント基盤を強化する手助けとなります。
Omnigent: オープンなエージェント・メタハルネス
オープン・セキュア AI アライアンスは、オープンモデルやハルネス、ガードレールの推進を訴求しており、これによりディフェンダーが AI ストック全体にわたるエージェントの動作を検査、監査、管理できるようになります。この要請に応える Databricks の答えが、Omnigent(Apache 2.0 ライセンス)です。これはオープンソースのメタハルネスであり、開発者がハルネスやモデルを選択できる柔軟性を提供します。これにより、13 以上のオープンおよびクローズドなハルネスにまたがるポリシーの適用、支出上限の設定、サンドボックスによる隔離を強制しつつ、構成と安全な共有が可能になります。
Omnigent の文脈に基づくポリシー は、セッション状態の追跡を通じてエージェントの動作管理を実現します。これにより、スローバーン攻撃のブロック や、意図ベースの認証の強制 が可能になります。これらはまさに、アライアンスが構想するオープンで検査可能なコントロールの典型例です。
Omnigent は、ガバナンスバックエンドとして NVIDIA OpenShell のサポートを目的に設計されており、ポリシー制御とカーネルレベルの隔離を組み合わせています。これにより、エージェントの認証からホスト実行に至るまで、多層的かつ監査可能な保護を提供します。
DASF 3.0: リスクを制御策にマッピングする、実用的な AI セキュリティフレームワーク
DASF 3.0は、13 のコンポーネントにわたる 97 の技術的セキュリティリスクを網羅し、これらを 73 の緩和策に対応付けています。すべての項目は MITRE ATLAS、OWASP、NIST、AIUC-1、HITRUST、ISO、CSA と相互参照されています。CC BY-SA 4.0 ライセンスで公開されているこのバージョン 3.0 では、エージェント型 AI に特有の脅威(メモリ汚染、目標操作、不十分な MCP コネクションなど)への対応が新たに追加され、防御者がリスク特定から緩和策の実装へと進むための、ベンダーに依存しないオープンな設計図を提供します。
DASF はリスク分類体系と、実効性のあるベンダー非依存の制御策を結びつけることで、「特定のリスク」から「導入された対策」への具体的な道筋を示します。これにより、コミュニティ内のあらゆる組織が利用可能な、エージェント型脅威とその緩和策のための共通語彙(タクソノミー)が実現されています。
DAGF:AI システムのためのエンタープライズガバナンス
DAGF(Databricks AI Governance Framework)は、責任の所在を明確にし、企業がどのように管理すべきかを定義するフレームワークです。この枠組みは、責任あるかつ強靭な AI プログラムを構築するための 5 つの柱を示しており、意思決定と実行における実践的な知見を提供します。
AI ガバナンス、倫理的コンプライアンス、リスク管理、運用監視といった中核領域に対応し、人・プロセス・技術を横断した協力を促進しながら、AI プログラムを透明性が高く、安全かつ効果的に管理することを支援します。本アライアンスの文脈では、DAGF は企業が NVIDIA のアクセラレーテッドコンピューティングや AI インフラストラクチャを選択・展開・管理する際のガバナンスを支え、オープンテクノロジーが責任を持って大規模に導入されることを保証します。
クリエイティブ・コモンズ表示-継承 4.0 国際ライセンス(CC BY-SA 4.0)の下で公開されている DAGF はベンダー中立であり、コミュニティが既に採用している基準とも整合しています。
BlackIce: オープンソースの AI レッドチームング
**BlackIce** は、Databricks が提供するオープンソースでコンテナ化されたレッドチームングツールキットです。MITRE ATLAS および DASF にマッピングされた 14 の主要な AI セキュリティツールを単一の再現可能な環境にパッケージ化しており、セキュリティチームが手動で各ツールを接続することなく、プロンプトインジェクション、データ漏洩、サプライチェーン攻撃に対するシステムのテストを実施できます。
これにより、AI レッドチームングのハードルが下がりました。14 のツールを個別に構築するには時間と深い専門知識が必要であり、本格的な敵対的テストは多くのチームにとって手が届かないものでした。現在までに 6,000 回以上のダウンロードがあり、もはや自前でこれらのツールを揃えることができなかったチームの間ですでに活用されています。
セキュリティレイクハウスの上に構築される
アライアンスのミッションにおける AI を活用したサイバー防御の側面において、Databricks のオープンネスへのコミットメントはフレームワークを超えています。Databricks はSecurity Lakehouseを先駆的に提唱しました。これはセキュリティ、IT、ビジネスデータを統合する、管理されたオープンなアーキテクチャであり、防御者がペタバイト規模で検出、調査、対応を実行することを可能にします。
Databricks のオープンセキュリティレイクハウス「Lakewatch」を活用すれば、セキュリティチームは AI エージェントをデプロイしてアラートの自動選別、脅威ハンティング、検出ロジックの改善を積極的に行えます。これらはすべてベンダーロックインを防ぐオープンデータフォーマット上で動作します。これは、Open Secure AI Alliance が推進する哲学と共通しています。「防御側が自らのデータ、ツール、知見を所有すべきだ」という考え方です。
このアーキテクチャのガバナンス基盤となるのが「Unity Catalog」です。Databricks はこれを Apache 2.0 ライセンスでオープンソース化し、Linux Foundation に寄付しました。カタログは、どのエージェントがどのデータやモデル、ツールにアクセスできるかを決定し、そのルールを強制する層です。この最も重要なセキュリティ制御ポイントをプロプライエタリなままにしつつ、その上位レイヤーだけをオープンにしても意味がありません。一方、カタログ自体(API、テーブルフォーマット、実装)をすべてオープンにすれば、防御側は強制ポイントの監査や拡張が可能になり、セキュリティデータも特定のベンダーのコントロールプレーンに縛られず、異なるエンジン間でのポータビリティが確保されます。
Databricks のオープンソースへの歩み
Databricks が掲げるセキュリティの開放性は、創業時から続く深いオープンソースの歴史の上に成り立っています。**Apache Spark**、**Delta Lake**、そして **MLflow** はすべて、「基盤となる技術はオープンであり、検証可能で、コミュニティ主導であるべき」という原則に基づいて構築されました。この理念をガバナンス層にも広げ、Unity Catalog をオープンソース化した際も同様です。Apache Spark 単体でも、すでに 20 億回のダウンロードを突破しています。Open Secure AI Alliance は、この哲学を AI の安全性とセキュリティの領域へと拡張するものです。
今後の展望
Open Secure AI Alliance は、AI の安全性とセキュリティに関する研究を透明性を持って開発・共有するためのムーブメントです。時間の経過とともに、組織が検証し、採用し、さらに発展させることができる実践的なオープンな機能群が蓄積されていくことになります。
私たちは、この使命において NVIDIA や広範なアライアンスの仲間たちと共に歩むことを嬉しく思います。そして、エージェント時代を共に守りながら、コミュニティに対してオープンなコードやフレームワーク、研究を継続して提供し続けていきます。
**Lakewatch(Open Security Lakehouse)の詳細** や、Databricks がエージェント時代のセキュリティ運用をどのように再定義しているかについて詳しくご覧ください。
ご自身の環境でオープンエージェントのメタハッチ、コンテキストポリシー、サンドボックス分離を実行するには、Omnigent の始め方 をご覧ください。
AI システムを保護するためのリスクと制御を理解するには、Databricks AI セキュリティフレームワーク (DASF) 3.0 をご参照ください。
AI プログラム全体における説明責任と監督体制について学ぶには、Databricks AI ガバナンスフレームワーク (DAGF) をダウンロードしてください。
統合ツールの詳細、Databricks 上でホストされるモデルでの実行例、およびすべての Docker ビルド成果物へのアクセスについては、BlackIce GitHub リポジトリ をチェックしてください。
原文を表示
*Databricks is a sponsor at Black Hat USA 2026 this week. Find us at Booths #5106 / #2167, and read how our *acquisition of Panther* accelerates the Security Lakehouse era.*
The case for open AI safety and security
As AI systems grow more capable and autonomous, two challenges are converging: securing AI systems themselves against new classes of attack, and using AI to strengthen cyber defense. Both require openness because critical security intelligence locked inside a small number of closed systems leaves the broader ecosystem exposed. Databricks supports both mission sides: open frameworks for securing AI systems, and open data via Lakewatch, the Open Security Lakehouse powering agentic threat detection and response at scale.
That's why Databricks is proud to be a founding member of the Open Secure AI Alliance, alongside NVIDIA and other industry leaders. The alliance is built on a simple but powerful premise: AI safety and security research should be shared openly, and the tools it produces should be built on open systems. That work spans AI safety, AI security, and AI-enabled cyber defense, strengthening enterprises, software, and critical systems worldwide. Members are contributing into the open: open models, model weights, open harnesses, open tooling, and the learnings behind them, to accelerate the development of new cybersecurity tools and techniques.
Why openness matters: beyond models
An AI agent isn't just a model. It's a complex system built from models, harnesses, and guardrails that govern what the agent is allowed to do. While much attention has focused on securing open-weight models within enterprise boundaries, model weights are only one layer. Security in the agentic era requires an open execution stack: from the runtime and guardrails underneath, to the harness that orchestrates agents and their tools, to the frameworks that define risks and controls, to the governance layer that ensures enterprise security, auditability and accountability.
Open systems allow the broadest community of defenders to study, test, and strengthen every component of this stack. The result is trust built on assurances, visibility, evidence, participation, and choice.
What Databricks brings to the alliance
The alliance spans more than 75 organizations across chips, models, security, and infrastructure. NVIDIA contributes accelerated computing and open AI infrastructure. Databricks brings governed data, model and agent capabilities, and open tools and frameworks for security, governance, red teaming, and cyber defense.
- Omnigent composes and controls how agents use models and tools.
- Databricks AI Security Framework (DASF) maps AI risks to practical safeguards.
- Databricks AI Governance Framework (DAGF) defines accountability and governance.
- BlackIce tests AI systems against real-world attacks.
- Lakewatch powers agentic detections and hunting across unified data.
Together with contributions from across the alliance, this work helps strengthen the full agent stack.
Omnigent: an open agent meta-harness
The Open Secure AI Alliance advocates for open models, harnesses, and guardrails so defenders can inspect, audit, and govern agent behavior across the full AI stack. Omnigent (Apache 2.0) is Databricks' answer to this call, an open-source meta-harness. Omnigent gives developers choice of harness and model, allowing composition and secure sharing, while enforcing policies, spend caps, and sandbox isolation across 13+ harnesses, both open and closed.
Omnigent's contextual policies enable agent behavior governance by tracking session state, blocking slow-burn attacks, and enforcing intent-based authorization. These are exactly the kinds of open, inspectable controls the alliance envisions.
Omnigent is designed to support NVIDIA OpenShell as a governance backend, pairing policy controls with kernel-level isolation for layered, auditable protection from agent authorization through host execution.
DASF 3.0: an actionable AI security framework mapping risks to controls
TheDASF 3.0 catalogs 97 technical security risks across 13 components and maps them to 73 mitigation controls, all cross-referenced to MITRE ATLAS, OWASP, NIST, AIUC-1, HITRUST, ISO and CSA. Released under CC BY-SA 4.0, version 3.0 introduces dedicated coverage for Agentic AI threats (including memory poisoning, goal manipulation, and insecure MCP connections), providing defenders with an open, vendor-agnostic blueprint to move from risk identification to mitigation.
Because DASF connects risk taxonomy to enforceable, vendor-agnostic controls, it gives defenders a concrete path from "named risk" to "deployed mitigation." It offers a common taxonomy for agentic threats and mitigations available to any organization in the community.
DAGF: enterprise governance for AI systems
The DAGF defines who is accountable and how the enterprise manages it. This framework outlines five pillars for building a responsible and resilient AI program, offering practical insights for decision-making and execution. It addresses core areas, such as AI governance, ethical compliance, risk management, and operational oversight. This helps manage AI programs transparently, securely, and effectively while fostering collaboration across people, processes and technology. In the context of the alliance, DAGF helps enterprises govern how NVIDIA's accelerated computing and AI infrastructure is selected, deployed, and managed, and ensures that open technology is adopted responsibly at scale. Released under the Creative Commons Attribution-ShareAlike 4.0 International License, DAGF is vendor-agnostic and already aligned to the standards the community uses.
BlackIce: open-source AI red teaming
BlackIce is Databricks' open-source, containerized red-teaming toolkit. It bundles 14 widely used AI security tools into a single reproducible environment, mapped to MITRE ATLAS and DASF, so a security team can test a system against prompt injection, data leakage, and supply-chain attacks without wiring up each tool by hand.
This lowers the bar for AI red teaming. Standing up 14 tools individually takes time and deep expertise, which puts serious adversarial testing out of reach for most teams. With over 6,000 downloads to date, it is already in the hands of teams that could not have assembled these tools on their own.
Building on the Security Lakehouse
On the AI-enabled cyber defense side of the alliance's mission, our commitment to openness extends beyond frameworks. Databricks pioneered the Security Lakehouse, an open, governed architecture that unifies security, IT, and business data so defenders can run detection, investigation, and response at petabyte scale.
With Lakewatch, Databricks’ Open Security Lakehouse, security teams can deploy AI agents that actively triage alerts, conduct threat hunts, and refine detection logic, all on top of open data formats that prevent vendor lock-in. This is the same philosophy that drives the Open Secure AI Alliance: defenders should own their data, their tools, and their intelligence.
The governance foundation for that architecture is Unity Catalog, which Databricks open-sourced under Apache 2.0 and donated to the Linux Foundation. The catalog is the layer that decides which agent can reach which data, model, or tool, and enforces it. Leaving that layer proprietary while everything above it is open would put the most security-critical control point beyond inspection. With an open catalog, meaning open APIs, open table formats, and an open implementation, defenders can audit and extend the enforcement point itself, and security data stays portable across engines rather than locked to one vendor's control plane.
Databricks' open-source heritage
Our commitment to open security builds on a deep open-source heritage that goes back to our founding. Apache Spark, Delta Lake, and MLflow were all built on the principle that foundational technology should be open, inspectable, and community-driven, and we extended that principle to the governance layer when we open-sourced Unity Catalog. Apache Spark alone has now passed two billion downloads. The Open Secure AI Alliance extends that same philosophy to AI safety and security.
What's next
The Open Secure AI Alliance is a movement to develop and share relevant AI safety and security research transparently. Over time, the alliance will produce a growing body of practical, open capabilities that organizations can inspect, adopt, and build on.
We're excited to stand alongside NVIDIA and the broader alliance in this mission and to continue making open code, open frameworks, and open research available to the community as we secure the agentic era together.
Learn more about Lakewatch, the Open Security Lakehouse and how Databricks is redefining security operations for the agentic era.
Get started with Omnigent to run the open agent meta-harness, its contextual policies, and sandbox isolation in your own environment.
Explore the Databricks AI Security Framework (DASF) 3.0 to understand the risks and controls for securing your AI systems.
Download the Databricks AI Governance Framework (DAGF) to learn about accountability and oversight across your AI program.
Check out our BlackIce GitHub Repo to learn more about the integrated tools, find examples for running them with Databricks-hosted models, and access all Docker build artifacts.
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み