OpenHands、AI セキュリティ構築へ Open Secure AI Alliance に参加
本文の状態
日本語全文を表示中
詳細モードで約13分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
OpenHands Engineering
OpenHands は、AI エージェントのセキュリティをモデル単体ではなくシステム全体として捉える必要性を強調し、NVIDIA が主導する Open Secure AI Alliance に参加した。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月11日 14:28
AI深層分析
キーポイント
エージェントセキュリティの定義拡大
AI セキュリティはモデルの保護だけでなく、ハッシュ、実行環境、アイデンティティ、権限、ポリシーなどを含む完全なシステム全体の保護を意味する。
Open Secure AI Alliance の参加表明
OpenHands は NVIDIA とパートナー企業によって立ち上げられた同アライアンスに参加し、オープンな技術やツールの共有を通じてセキュリティ基盤の構築に貢献する。
オープンシステムアプローチの必要性
防御側がインフラを検査・テスト・適応・改善できるためには、エージェントの振る舞いをブラックボックス化せず、オープンなハッシュとセキュリティツールが必要である。
オープンソースによるセキュリティモデルの転換
オープンソースは自動的にシステムを安全にするわけではないが、ベンダーへの依存を減らし、実行経路の検証や独自の脅威モデルへの対応を可能にする異なるセキュリティモデルを実現する。
組織による完全な制御と環境の確保
OpenHands は「あなたの環境、あなたのモデル、あなたの制御」という原則に基づき、機密データや重要インフラにおいて外部サービスに依存しないローカル実行やカスタマイズを可能にする。
重要な引用
Securing an AI agent is not only about securing the model. An agent is a complete system made up of models, harnesses, execution environments, identities, permissions, integrations, policies, and logs.
Defenders need access to security infrastructure they can inspect, test, adapt, and improve for the environments they are responsible for protecting.
When agent infrastructure is open, defenders can examine the execution path instead of relying entirely on vendor assurances.
Your environment. Your models. Your control.
編集コメントを表示
編集コメント
AI エージェントが組織のインフラに深く統合される中で、セキュリティ対策もモデル単体からシステム全体へ視座を移す必要性が高まっている。OpenHands のこの動きは、防御側が自らの環境に合わせてセキュリティ基盤を検証・改善できるオープンな生態系の構築に向けた重要な一歩である。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
AI エージェントは、個々の開発者向けツールから、リポジトリやインフラストラクチャ、さらには組織全体にわたって動作するシステムへと急速に進化しています。
この変化はセキュリティの議論そのものを変えます。AI エージェントを保護することは、単にモデルを守るだけではありません。エージェントとは、モデル、ハネス、実行環境、アイデンティティ、権限、統合機能、ポリシー、ログなどから構成される完全なシステムです。各レイヤーが、エージェントが何を実行できるか、何にアクセスできるか、そしてその行動を監視・管理できるかどうかを決定します。
そのため OpenHands は、AI、サイバーセキュリティ、エンタープライズソフトウェア、クラウドインフラ、オープンソース分野のパートナーらによって立ち上げられた新しい業界イニシアチブである「Open Secure AI Alliance」に参加しました。
このアライアンスは、ソフトウェア、AI エージェント、およびそれを取り巻くインフラストラクチャを防御するためのオープンな技術、手法、ツールを開発・共有することに注力しています。その設立理念は、私たちが強く共感するものです。「防御側には、保護すべき環境に合わせて検査し、テストし、適応させ、改善できるセキュリティインフラへのアクセスが必要である」という前提です。
エージェントのセキュリティにはオープンなシステムアプローチが不可欠
AI セキュリティに関する議論は往々にして、「モデルがオープンかクローズドか」という点に単純化されがちです。しかし、モデルはエージェントスタックにおける一つのレイヤーに過ぎません。
モデルがハーンネスに接続され、ツールを与えられ、実際の環境内で操作を許可されると、セキュリティの境界は大幅に広がります。チームは以下の点を明確にする必要があります。
- どのユーザーやエージェントが作業を開始できるか
- エージェントがアクセスできるリポジトリ、サービス、データは何らか
- 実行可能なコマンドとツールは何か
- 実行が行われる場所はどこか
- クレデンシャルと権限の範囲をどう設定するか
- すべてのアクションを追跡・監査可能にするか
- 不審な動作や意図しない挙動をどう検知するか
- 脆弱性の報告と修正プロセスはどうなるか
NVIDIA のアライアンス発表も同様の区別を示しています。真の意味での AI セーフティは、アイデンティティ、権限、ハーンネス、ガードレール、ログ、評価を含む完全なエージェント・スタックに依存します。オープンなハーンネスとセキュリティツールを活用することで、より多くの関係者がこれらの制御を検査・テスト・改善できるようになり、エージェントの挙動をブラックボックスとして扱う必要がなくなります。
これは OpenHands を構築する際の基盤となる考え方です。OpenHands は、ソフトウェアエンジニアリング・エージェントの構築と実行のためのオープンソースプラットフォームであり、単一のローカルエージェントから組織全体で動作するシステムへと移行するために必要なインターフェース、自動化、実行、制御の各レイヤーを提供します。開発者はオープンなフレームワークを検査・拡張でき、要件に合致するモデルを選択し、サポートされるツールや実行アクティビティを確認した上で、自社のインフラストラクチャ上にプラットフォームをデプロイできます。
オープン性はセキュリティ機能である
オープンソースであることが自動的にシステムを安全にするわけではありません。しかし、異なるセキュリティモデルを実現する可能性は開かれます。
エージェントのインフラストラクチャがオープンであれば、防御側はベンダーの保証に完全に依存するのではなく、実行パスを検査できます。また、障害発生時のシステムの挙動をテストしたり、自らの脅威モデルに合わせて制御を追加したり、環境から流出する情報を検証したり、広範なエコシステム全体に利益をもたらす修正を加えたりすることが可能になります。
オープンなシステムは、特定のベンダーへの依存度を下げます。組織は異なるタスクに適したモデルを選択し、エージェントを管理された環境内で稼働させ、外部サービスが利用できない場合や機密性の高いワークロードには不適切な場合に備えて対応能力を維持できます。
これは特に脆弱性対策、インシデント対応、セキュアなソフトウェア開発、重要インフラの分野で重要です。防御側は、有能なモデルをローカルで実行したり、ツールをカスタマイズしたり、承認された環境内で機密データを分析したり、緊急調査をサポートするためにハーン(枠組み)を変更したりする必要があるかもしれません。その境界を実現するには、モデルのエンドポイント、統合、ログ、テレメトリなどを含む完全な設定が不可欠です。
このアライアンスは、防御側がタスクに適した技術を柔軟に選択・制御できるよう、有能なオープンモデルやハーン、ツールをクローズドシステムと併せて利用できるようにする原則に基づいて設立されました。
OpenHands では、基盤となる設計原則として「環境はあなた自身が」「モデルはあなたが選び」「制御もあなたが持つ」というシンプルな考え方を採用しています。この原則は、オープンソースエコシステム全体で OpenHands がどのように構築され、利用されているかにもすでに反映されています。
OpenHands がオープンなセキュリティ生態系に貢献する点
OpenHands は、単なる理論に基づいてこの取り組みを進めているわけではありません。同プロジェクトは、能力あるソフトウェアエージェントの構築・実行・評価・研究のために既にオープンなインフラを提供しています。
MIT ライセンスで公開されている OpenHands エージェントハネスは、エージェントの実行をより監査可能かつ設定しやすくするために設計されています。チームは、自己デプロイされた Docker 環境内でエージェントを実行でき、実行場所を制御できます。また、エージェントの指示やランタイム設定、組織ポリシーを通じて、セキュリティ構成を自社の要件に合わせて柔軟に調整可能です。
これにより、セキュリティ研究と本番環境への展開の両方に対して、実用的な基盤が整います。研究者は、エージェントの全ループを検査し、実験を再現し、モデルを差し替え、ツールや安全装置を修正し、実際のシステムとの相互作用におけるエージェントの振る舞いを評価することが可能になります。
このオープンなアプローチは、OpenHands を本番環境での利用を超えて有用なものにしています。研究者たちは、エージェントがテキスト生成だけでなく、実際にブラウジングやコマンド実行、ファイル操作、ソフトウェア環境との対行が可能になった際の振る舞いを研究するために、このハネスを利用しています。また、OpenHands の研究者らは、350 以上の benign(悪意のない)および adversarial(敵対的)タスクにわたってエージェントの行動を評価する拡張可能なベンチマーク「OpenAgentSafety」にも貢献しました。
他の最近の研究では、OpenHands を用いて、コーディングエージェントが脆弱性を生じさせるかどうかや、ツールを使用するエージェントがより長く多段階のインタラクションにおいてどのように振る舞うかを調査しています。これらの研究は重要な点を裏付けています。つまり、エージェントのセキュリティを単一のシステムプロンプトやモデルレベルの保護機能だけで解決することはできないのです。必要なのは、評価、隔離、ポリシー、観測性、そしてエージェントが実際に行動する環境にまで及ぶ制御です。
OpenHands は、オープンなモデルの開発と評価のためのオープンハネスも提供しています。これにより、特定のプロバイダーに依存することなく、広範なモデルをサポートすることが可能になります。
GitHub でのスター数が 8 万を超えた OpenHands の大規模なオープンソースコミュニティは、これらのアイデアを公開環境で検証し、失敗のモードを迅速に表面化させ、研究者や実務家からの教訓を、他者が検査・再利用できるインフラへと転換する機会を生み出しています。
オープンなエージェントから制御されたインフラへ
開発者たちはすでに、コーディングエージェントが実用的なエンジニアリング作業を遂行できることを証明しています。具体的には、障害の調査やコード修正、プルリクエストのレビュー、依存関係の更新、そして多段階ワークフローの実行などが可能です。
次に直面する課題は、これらの能力を特定の開発者のノートパソコンに限定せず、安全かつ再現性のあるものにしていくことです。エージェントがチーム全体に広がっていく中で、組織には実行範囲の定義やアクセス権限の管理、利用状況の監視、そして関連するエージェントやワークフローの活動記録を永続的に保存できるインフラが必要です。重要なのは、どのモデルが回答を生成したかだけでなく、エージェントが実際に何を行ったかを把握することです。
OpenHands はこうした進化に合わせて設計されています。開発者はまず、オープンでモデルに依存しないエージェント環境からローカルで始められます。チームは有用なワークフローを共有自動化ツールへと昇華させ、GitHub や Slack、CI システム、その他のエンジニアリングツールに対して実行できるようになります。採用が進むにつれ、OpenHands の「Agent Control Plane(エージェント制御基盤)」が、組織レベルでのガバナンス、可視性、アクセス制御、そしてチーム間でのワークフロー運用に必要なデプロイオプションを提供します。
目指しているのは、ガバナンスのためにエージェントの能力を弱めることではありません。明確に定義され、監視可能な範囲内で、エージェントが有意義な作業を行う自由を与えることです。
エージェントのためのオープンな防御スタック構築
Open Secure AI Alliance は、アイデンティティと分離、安全なモデル形式、脆弱性スキャン、セキュアなコーディングワークフロー、エージェント評価、そしてエージェントの動作をテスト・追跡・ガバナンスするためのインフラストラクチャなど、多岐にわたる領域で活動する組織を集めています。
OpenHands は、そのスタックの中でエージェントがソースコードやエンジニアリングツール、実行環境と相互作用する部分を担っています。私たちは、これらの相互作用をより観測可能で制御可能、かつ安全なものにするためのオープンな基盤開発を支援するために、このアライアンスに参加します。
単一の企業がエージェントエコシステム全体を独自に守ることはできません。モデル、ランタイム、アイデンティティシステム、サンドボックス、セキュリティツール、そして制御層には、各レイヤーを独立して評価し、集団的に改善できるための共有インターフェースと標準が必要です。
ソフトウェアの構築・運用においてエージェントが占める割合が大きくなるにつれ、OpenHands は NVIDIA やアライアンスコミュニティ全体と共に、これらの基盤づくりに取り組むことを楽しみにしています。
OpenHands について
OpenHands は、ソフトウェアエンジニアリングエージェントを構築・実行するためのオープンソースプラットフォームです。単一のエージェントから組織全体で稼働するシステムへと拡張するために必要なインターフェース、自動化機能、制御層を提供します。ミッションは、エージェントベースのソフトウェア開発が、デフォルトでアクセスしやすく、透明性があり、かつ制御可能になるようにすることです。その第一歩として、私たちはオープンな取り組みを推進しています。
開発者は、まずローカル環境で Agent Canvas を使って、すでに利用しているモデルやツールを接続し、実際のリポジトリに対してエージェントを実行できます。ワークフローが成熟すれば、チームは単発的なエージェントの成功事例を、ラップトップを閉じた後も動作し続ける反復可能な自動化へと転換できます。
エージェントの利用規模を拡大する組織には、OpenHands Enterprise が、チームやリポジトリ、環境を超えて安全にエージェントを実行するために必要な制御層を提供します。
OpenHands コミュニティ に参加し、オープンな形でアジェンシー SDLC の構築を支援しましょう。プロジェクトへの貢献や、現在取り組んでいることの共有を通じて、より高度なエージェントを可視性と制御性を高めて運用するために開発者や組織が必要とするオープンインフラの形成に参画してください。
OpenHands をダウンロード して、ローカルでエージェントの実行を開始し、実際のエンジニアリングワークフローを自動化しましょう。必要に応じて、その規模を拡大することも可能です。
原文を表示
AI agents are quickly moving from individual developer tools to systems that operate across repositories, infrastructure, and entire organizations.
That shift changes the security conversation. Securing an AI agent is not only about securing the model. An agent is a complete system made up of models, harnesses, execution environments, identities, permissions, integrations, policies, and logs. Every layer affects what the agent can do, what it can access, and whether its actions can be observed and governed.
That is why OpenHands has joined the Open Secure AI Alliance, a new industry initiative launched by NVIDIA and partners across AI, cybersecurity, enterprise software, cloud infrastructure, and open source.
The Alliance is focused on developing and sharing open technologies, techniques, and tools that help defenders secure software, AI agents, and the infrastructure around them. Its founding premise is one we strongly share: defenders need access to security infrastructure they can inspect, test, adapt, and improve for the environments they are responsible for protecting.
Agent security requires an open systems approach
The AI security debate is often reduced to whether a model is open or closed. But models are only one layer of the agent stack.
Once a model is connected to a harness, given tools, and allowed to operate inside a real environment, the security boundaries expand considerably. Teams must determine:
- Which users and agents are allowed to initiate work
- What repositories, services, and data an agent can access
- Which commands and tools it can execute
- Where the execution takes place
- How credentials and permissions are scoped
- Whether every action can be traced and audited
- How suspicious or unintended behavior is detected
- How vulnerabilities are reported and remediated
NVIDIA’s Alliance announcement makes the same distinction: meaningful AI safety depends on the full agent stack, including identity, permissions, harnesses, guardrails, logs, and evaluation. Open harnesses and security tools give more defenders the ability to inspect, test, and improve those controls rather than treating agent behavior as a black box.
This is foundational to how we are building OpenHands. OpenHands is the open source platform for building and running software engineering agents, with the interface, automation, execution, and control layers needed to move from a single local agent to a system operating across an organization. Developers can inspect and extend the open framework, choose models that meet their requirements, review supported tool and execution activity, and deploy the platform on infrastructure they control.
Openness is a security capability
Open source does not automatically make a system secure. It does make a different security model possible.
When agent infrastructure is open, defenders can examine the execution path instead of relying entirely on vendor assurances. They can test how the system behaves under failure, add controls for their own threat model, validate what information leaves an environment, and contribute fixes that benefit the broader ecosystem.
Open systems also reduce reliance on a single provider. Organizations can choose different models for different tasks, operate agents inside controlled environments, and maintain the ability to respond when external services are unavailable or inappropriate for a sensitive workload.
This matters especially in areas such as vulnerability remediation, incident response, secure software development, and critical infrastructure. Defenders may need to run capable models locally, customize their tooling, analyze sensitive data within an approved environment, or modify a harness to support an urgent investigation. Achieving that boundary depends on the full configuration, including model endpoints, integrations, logging, and telemetry.
The Alliance was formed around the principle that defenders need access to capable open models, harnesses, and tools, alongside closed systems, so they can select and control the right technology for the job.
At OpenHands, we use a simple design principle for that foundation: Your environment. Your models. Your control. That principle is already reflected in how OpenHands is built and used across the open-source ecosystem.
What OpenHands contributes to the open security ecosystem
OpenHands is not approaching this work from theory alone. The project already provides open infrastructure used to build, run, evaluate, and study capable software agents.
The OpenHands agent harness is MIT-licensed and designed to make agent execution more inspectable and configurable. Teams can run agents inside self-deployed Docker environments, control where execution happens, and adapt security configurations to their own requirements through agent instructions, runtime configuration, and organizational policies.
This creates a practical foundation for security research as well as production deployment. Researchers can inspect the full agent loop, reproduce experiments, substitute models, modify tools and safeguards, and evaluate how agents behave when they interact with real systems.
That openness has made OpenHands useful beyond production deployments. Researchers use the harness to study how agents behave when they can actually browse, execute commands, modify files, and interact with software environments rather than only generate text. OpenHands researchers also contributed to OpenAgentSafety, an extensible benchmark that evaluates agent behavior across more than 350 benign and adversarial tasks.
Other recent research has used OpenHands to study whether coding agents introduce vulnerabilities and how tool-using agents behave across longer, multi-turn interactions. That work reinforces an important point: agent security cannot be solved with a single system prompt or model-level safeguard. It requires evaluation, isolation, policies, observability, and controls that extend into the environments where agents actually act. Other recent work has used OpenHands to study whether coding agents introduce vulnerabilities and how tool-using agents behave over longer interactions.
OpenHands also provides an open harness for developing and evaluating open models. It supports a broad range of models without tying the agent system to a single provider.
With more than 80,000 GitHub stars, OpenHands’ large open source community creates an opportunity to test these ideas in public, surface failure modes quickly, and turn lessons from researchers and practitioners into infrastructure others can inspect and reuse.
From open agents to controlled agent infrastructure
Developers are already proving that coding agents can perform meaningful engineering work. They can investigate failures, modify code, review pull requests, update dependencies, and execute multi-step workflows.
The next challenge is making those capabilities safe and repeatable beyond one developer’s laptop. As agents spread across teams, organizations need infrastructure that can define execution boundaries, govern access, monitor usage, and preserve a durable record of relevant agent and workflow activity. They need to know not just which model produced an answer, but what the agent actually did.
OpenHands is designed around that progression. Developers can begin locally with an open, model-agnostic agent environment. Teams can turn useful workflows into shared automations that run against GitHub, Slack, CI systems, and other engineering tools. As adoption grows, the OpenHands Agent Control Plane adds the organization-level governance, visibility, access controls, and deployment options needed to operate those workflows across teams.
The goal is not to weaken agent capability in exchange for governance. It is to give agents the freedom to do meaningful work inside clearly defined and observable boundaries.
Building the open defense stack for agents
The Open Secure AI Alliance brings together organizations working across identity and isolation, safe model formats, vulnerability scanning, secure coding workflows, agent evaluation, and the infrastructure used to test, trace, and govern agent behavior.
OpenHands represents the part of that stack where agents interact with source code, engineering tools, and execution environments. We are joining the Alliance to help develop open foundations for making those interactions more observable, controllable, and secure.
No single company can secure the entire agent ecosystem alone. Models, runtimes, identity systems, sandboxes, security tools, and control layers need shared interfaces and standards that allow each layer to be evaluated independently and improved collectively.
We look forward to collaborating with NVIDIA and the broader Alliance community on those foundations as agents become a larger part of how software is built and operated.
About OpenHands
OpenHands is the open-source platform for building and running software engineering agents, with the interface, automations, and control layer needed to go from a single local agent to a system running across an entire organization. The mission is to make agent-based software development accessible, transparent, and controllable by default. That starts in the open.
Developers can start locally with Agent Canvas, connect the models and tools they already use, and run agents against real repositories. As workflows mature, teams can turn one-off agent wins into repeatable automations that keep working when the laptop is closed. For organizations scaling agent usage, OpenHands Enterprise adds the control layer required to run agents safely across teams, repositories, and environments.
Join the OpenHands community and help us build the agentic SDLC in the open. Contribute to the project, share what you’re building, and help shape the open infrastructure developers and organizations need to run increasingly capable agents with more visibility and control. Download OpenHands to start running agents locally, automate real engineering workflows, and scale them when you’re ready.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み