AI エージェントのセキュリティリスク、5 社中 4 社が制御不能
本文の状態
日本語全文を表示中
詳細モードで約15分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
VentureBeat AI
VentureBeat の調査によると、AI エージェントのセキュリティ対策を強化する企業が増えているが、高リスクエージェントの分離や実行時制御の実施率は低く、実装ギャップが拡大している。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月13日 04:06
AI深層分析
キーポイント
エンタープライズにおけるエージェントセキュリティの現状とギャップ
全企業の53% が少なくとも一度はエージェント関連のインシデントまたはニアミスを経験したが、最高リスクを持つエージェントを分離しているのは18% に過ぎず、実行時制御と分離を併用しているのはわずか8% である。
ベンダー依存による対策の不十分さ
7 月に行われた調査では、企業の92% がセキュリティ層の主要部分をハイパースケラーや AI プラットフォームプロバイダーに依存しており、これではエージェントセキュリティの課題を解決するギャップがさらに拡大すると指摘されている。
インシデント経験とツール評価の逆相関
インシデントを経験した企業ほどセキュリティツールの満足度が高く(4.39/5)、一度も被害を受けていない企業の評価は低い(4.13/5)傾向があり、これは「救済」自体がマーケティング効果を生んでいることを示唆している。
Visa と Anthropic の共同実験による教訓
Visa は Anthropic の Mythos モデルを自社の決済ネットワークに適用し、脆弱性を悪用するチェーンを作成したが、この実験は企業が発見した問題に対処できるエンジニアリング深度を持つことがいかに重要かを浮き彫りにした。
アイデンティティと分離の誤解がリスクを拡大
多くの企業がアイデンティティ管理と環境分離を代替手段として扱い、両方を統合した戦略を欠いている。その結果、有効な認証情報を用いた悪意のあるエージェントによる被害が止まらない状況が続いている。
重要な引用
Just over half, or 53%, of enterprises have already had an agentic security incident or near-miss.
Sixty-five percent enforce agent permissions at runtime, yet only 18% isolate their highest-risk agents, and just 8% pair enforcement with isolation.
Leaning on provider-native controls to do the heavy lifting of agentic security just exacerbates that gap.
Giving an agent scoped credentials does not bound the blast radius when those credentials are misused. Sandboxing does.
編集コメントを表示
編集コメント
AI エージェントのセキュリティ対策において、ベンダー任せにせず自社のリスクに応じた具体的な隔離策を講じることが急務である。Visa と Anthropic の共同実験は、単なるツール導入ではなく、深いエンジニアリング能力が不可欠であることを示している。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
Visa の技術担当副社長、ラジット・タネジャ氏は VB Transform 2026 で、Anthropic の Mythos を Visa 自身の決済ネットワークに適用するデモを行いました。このモデルは、システム内のわずかな弱点を結びつけて実行可能な攻撃チェーンへと変換し、その探索プロセスを統制したハーン(枠組み)もオープンソース化されました。
これは、発見された課題に対して実際に行動を起こせるだけのエンジニアリング能力を持つ企業が、どのような姿をしているかを示しています。しかし、多くの企業はそこには至っていません。すでにエージェント(自律型 AI エージェント)によるセキュリティインシデントやニアミスを経験している企業は 53% に過ぎません。ランタイム時にエージェントの権限を制限している企業は 65% に達していますが、最もリスクの高いエージェントを隔離できているのはわずか 18% です。さらに、権限管理と隔離を組み合わせて実施している企業に至っては 8% しかありません。
エージェントセキュリティの重責をプロバイダーが提供するネイティブなコントロールに頼るだけでは、この格差はむしろ拡大する一方です。VentureBeat の Pulse Research が 7 月に発表した調査では、主要なセキュリティ層を定義した企業の 92% が、デフォルトとしてハイパースケーラーや AI プラットフォームプロバイダーの機能に依存していることが明らかになりました。
1 月以来、6 回の調査が実施され、440 名の資格のある企業セキュリティ担当者にアンケートを行いました。その主な結論は、企業が求めるものと実際に実行されていることの間に存在する「封じ込め」のギャップが拡大しており、エージェント AI への投資と将来性が脅かされている企業の多くで、この問題が放置され続けていることです。
満足度データとインシデントデータの不一致
調査結果は、企業が最もよく知るツールを高く評価する傾向を示し続けています。たとえそのツールが失敗に終わった場合や、中途半端な結果しか出せなかったとしてもです。
しかし、生データからはこの直感に反する3つの発見があります。これらはすべて、まだ市場が若く未成熟であることを物語っています。
被害を受けた企業ほど、自社のツールの評価を高くつけています。
先月の調査では、46の企業が確認されたインシデントまたはニアミスを経験した後にセキュリティツールの満足度を回答しました。その平均満足度は5点満点で4.39でした。一方、インシデントを経験しなかった55社のうち30社がセキュリティツールを評価した結果、平均は4.13でした。
企業は、自社のデータ漏洩を防いでくれたツールに対して、信頼というプレミアム(上乗せ評価)を与えているのです。
ブランドのポジショニングやマーケティング、あるいは企業を説得する他の手段が、顧客を侵害から救うことによって容易に置き換わるのは、新興市場の特徴的な兆候です。6 月と 7 月の両方で、確認されたインシデントの数よりも回避された事案の方が 2 対 1 の割合で上回っており、これは企業が問題の最前線(エッジ)で捕捉していることを意味します。この「エッジでの捕捉」は、セキュリティ戦略と導入したツールの有効性を裏付けるものとして解釈されています。7 ヶ月間にわたるデータが示すのは、侵入や侵害を特定し、アクセスを得られる前に阻止する新しいツールに対して、企業のセキュリティリーダーがいかに迅速に信頼を寄せるかという事実です。VentureBeat は、その「救出」自体がマーケティングの役割を果たしていると考えています。
侵害された経験のない企業におけるツールの評価平均は 4.13 であり、これは同じ現象のもう一つの側面を示しています。一度も動作を確認したことがないツールほど信頼を得られず、逆に信頼が高まることはありません。
VentureBeat はまた、最もリスクの高いエージェントを分離している 17 の企業のうち、ツールの評価が平均 4.00 としたのが 14 社であることを発見しました。一方、分離を行っていない企業は 4.35 と高い評価を与えています。実際にセキュリティに近い立場にある企業がツールに対して最も不満を持っているのは皮肉なことです。しかし、この不満こそが、Visa が取り組んだようなエンジニアリングへの取り組みへと駆り立てる原動力となっています。
アイデンティティの解決に成功した 5 つの企業のうち 4 つは、分離機能を実装していませんでした
7月に実施した調査によると、116社中57社(49%)が各エージェントにスコープ付きの管理されたアイデンティティを付与していました。わずか一ヶ月前のベントゥアビートの6月調査では32%だったため、この1ヶ月で17ポイントもの急増となりました。これは本シリーズで記録された単月での最大幅です。
しかし、こうした進展にもかかわらず、依然として63%の企業がフリート全体で認証情報の共有が行われていると回答しています。その57社の中で、アイデンティティ付与に加えて分離(隔離)措置も講じているのはわずか11社だけです。
この比率こそが、主要な制御機能が改善されるにつれて「封じ込めギャップ」がさらに拡大する理由です。多くの企業は、アイデンティティ管理と分離を相互に代替可能なものとして捉えています。しかし本当の解決策は、これらをプラットフォームベースで階層的な戦略の不可欠な要素として位置づける長期的な視点を持つことです。
ベントゥアビートが報じた2つの事例が、この区別がいかに重要かを示しています。メタ社で発生した不正エージェントは、3月の暴露時に封じ込められるまですべてのアイデンティティチェックを通過していました。また、CrowdStrikeのCEOジョージ・クルツ氏は、RSAC 2026の基調講演で、有効な認証情報を使用して自社のセキュリティポリシーを書き換えたフォーチュン500社所属のエージェントについて言及しました。
エージェントにスコープ付きの認証情報を付与しても、その情報が悪用された際の被害範囲(ブラスト・レイジ)を制限することはできません。それを可能にするのはサンドボックス化です。
分離措置なしで強制力のある対策を講じている企業群では、インシデント発生率が58%に達しています。
7 月の調査では、53 の企業がランタイムでスコープ付きの権限を適用していますが、隔離は行っていません。そのうち 31 社がすでにエージェントのセキュリティインシデントまたはニアミスを経験しており、これは全体の 58% に相当します。この数値はサンプル平均の 53% よりも 5 ポイント高いものです。
「コンテインメント・ギャップ(隔離の隙間)」に置かれている企業ほど、頻繁に被害を受けていることがわかります。
Cisco の AI 脅威インテリジェンスおよびセキュリティ研究責任者である Amy Chang は、「Transform agentic security」パネルで調査結果を発表しました。Cisco が主要な 15 のモデルに対して 6,986 回の多段階攻撃を仕掛けたところ、会話全体を通じて適応した攻撃者は 88.3% の確率で防御を突破しています。一方、単発のレッドチームテストではこの脅威を見逃していました。
ガードレールを突破する適応型攻撃者が現れると、その背後にあるアーキテクチャはすべて侵害されます。今回のデータに含まれる 53 の企業にとって、そのアーキテクチャは権限適用(enforcement)は行っていますが、隔離(containment)はできていない状態です。
VentureBeat が今年初めに実施した Q1 Pulse Research でも、同様の構造的な弱点が確認されています。不正なツールやデータへのアクセスは、すべての Q1 調査で最も懸念される失敗モードとしてランクインし、1 月の 42% から 3 月には 50% に増加しました。また、4〜5 月の調査では、モデルのガードレールのみを信頼してよいと答えた企業はわずか 4% でした。
これらの企業は、外部制御が必要だと予測し、隔離よりも権限適用(enforcement)の構築を選択しています。
実際、企業が権限適用に注力したのは予想より 35 ポイントも早く進んでいましたが、隔離についてはほとんど進展が見られませんでした。
4 月〜5 月に実施した調査では、109 社を対象に「2026 年末までにエージェントの振る舞いをどのように制御するか」という質問を行いました。その結果、30% がランタイムでの強制執行を予測し、14% がサンドボックス化された実行、32% がモデルレベルのガードレールを挙げていました。
7 月には、65% の企業がすでに強制執行機能を構築しており、これは当初の予測の倍以上に達しました。一方、分離(アイソレーション)機能の実装率は 18% で、当初の予測とほぼ同じ水準でした。
企業は「容易な対策」を予測の倍速で実装し、「困難な対策」は予測通りのペースで進めています。4 月の質問では主要な制御メカニズムを単一選択で答えてもらいましたが、7 月の姿勢に関する質問では複数回答が許されたため、今回の比較は厳密な数値対比というよりは傾向の方向性を示すものです。
プロバイダーロックインは、3 クォーターを通じて加速しました
プロバイダーネイティブプラットフォームは、すでに 4〜5 月に利用の主流を占めていました。ツール選定において、10 社中 7 社がこれらのプラットフォームを名指ししています。6 月には 82% の企業がこれを主要なエージェントセキュリティ層として採用し、7 月にはさらに 92% に達しました。内訳を見ると、OpenAI のガードレールが 44% でトップ、Microsoft Azure が 42%、Anthropic のマネージドエージェント制御が 37%、Google Cloud が 31% です。残りの市場を巡って競り合う専門ベンダーでは、Cloudflare が 11%、Cisco が 9% を占めています。
認証情報の共有ギャップに最も関連するアイデンティティツールは、実は最も規模が小さいものばかりです。Microsoft Entra Agent ID は 7% に留まり、Okta for AI Agents、非人間型アイデンティティプラットフォーム、ランタイムサンドボックス化ツールはそれぞれ 3% です。CrowdStrike の CTO、エリア・ザイツェフ氏は RSAC 2026 で VentureBeat の取材に対し、「エージェントの行動を観察することは解決可能な課題だが、その意図を推測するのは不可能だ」と語りました。プロバイダーが提供するバンドルはまさにこの点を証明しており、観察機能は実現しているものの、封じ込め機能はまだ構築されていません。
74% の企業が、直近でキャリア最高水準の満足度を与えたツールを置き換えようとしています。
エージェンティック AI による攻撃を防ぐためのツールや手法の使用経験が深まるにつれ、満足度は上昇し続けています。6 月の 4.2 から 7 月には 5 点満点中 4.29 に達し、本シリーズにおける最高値を更新しました。
満足度が高いにもかかわらず、74% の企業が 12 ヶ月以内にツールの入れ替えを検討しています。これは 6 月の 59% から増加した数字です。変更しないのはわずか 26% です。VentureBeat は、早期採用者がより深い洞察を求め、アジェントセキュリティやレジリエンスに関する自らの知識不足に気づいているため、こうした焦りがあると考えています。この知識のギャップを埋めることが、まだ未成熟な市場における顧客離れ(チャーン)を加速させており、その本質は以下のデータが示しています。主要なレイヤーとして名指しされるプロバイダーの 92% が、プロバイダーネイティブなものです。
「4.29」というスコアは、プロバイダーのガードレール(安全装置)をオンにする容易さを測るものであり、53% の企業がすでに経験したインシデントを防ぐ効果については測定していません。
脅威に最も近い組織ほど、その脅威に対して自信を持っていないのです。
6 月には、防御側が攻撃側を 35% 対 21% で上回っていましたが、7 月には 30% 対 30% の引き分けとなりました。被害を受けた企業のうち 39% が「攻撃側が優勢」と回答する一方、未被害企業ではその割合は 20% です。被害に遭うことで悲観的な見方はほぼ倍増しますが、購入検討の動きには変化がありません。エージェントアイデンティティ製品を考慮対象に含めているのはわずか 10% に過ぎません。ランタイムサンドボックス化に関心があるのは 6% で、この数字はインシデントの有無にかかわらず一定です。VentureBeat は 6 月のデータでも同じ盲点を指摘していました。ラベルが「エージェントセキュリティのギャップ」から「封じ込めのギャップ」に変更されたものの、購入検討の状況には変化がありません。
方法論
姿勢に関する質問には、116 人の有資格回答者のうち 93 人が回答しました。ここで注目すべきは、回答者が「孤立化」を選んだからといって、それが隠れた隔離措置を意味するわけではない点です。
25 人中 23 人が「姿勢なし」を選択したのは、まだエージェントの評価中である組織や、現状が不明確なケース、あるいは導入計画がないグループです。これらの組織ではセキュリティ体制は未だ存在しないため、18% という孤立化の数字は、実際にエージェントを実行またはパイロット運用している企業のみを対象に解釈する必要があります。
4 月〜5 月、6 月、7 月はそれぞれ独立して実施された調査波であり、単一の追跡シリーズではありません。そのため、今記事での月次比較は傾向を示すものであり、厳密なトレンド測定に基づくものではありません。クロス分析の基礎データ数は調査項目によって異なります。アイデンティティに関する質問は全 116 人の回答者に対応し、孤立化に関するデータは姿勢を説明した 93 人に限定されます。また、ツールの満足度に関する逆転現象(4.39 対 4.13)は、ツール評価を行った 76 人の回答者を基に計算されています。
結論
VentureBeat が実施した 573 社の企業を対象としたクロス調査分析では、7 月時点で「企業は管理に必要な制御手段を整える前に AI エージェントの導入を進め、かつそのことを承知の上で行っていた」という結論が導き出されました。しかし、セキュリティに特化したデータが 3 つの波で示すのは、この「承知」がどこまで続いているかという限界です。
企業は依然として、エージェントにスコープ付きのアイデンティティを付与し、それを「隔離」とみなす傾向にあります。しかし、この前提は誤りであり、インシデントデータがその事実を裏付け続けています。実際、アイデンティティ管理を解決した 57 社中 46 社は、隔離対策を構築していませんでした。
「隔離なしで強制する」アプローチを採用している組織のインシデント発生率は 58% に達しており、これはアイデンティティ管理だけでは不十分であることを示す最も明確な証拠です。容易さへの満足感に安住していても、この隔絶ギャップは解消されません。
次なる波が答えるべき問いは、企業が意図的に隔離と統制されたアイデンティティを構築するのか、それとも、伝播するインシデントが発生したことでやむを得ず対応せざるを得なくなるのか、という点です。
原文を表示
Visa's president of technology, Rajat Taneja, walked the VB Transform 2026 audience through aiming Anthropic's Mythos at Visa's own payment network. The model stitched minor weaknesses into working exploit chains, and Visa open-sourced the harness that governed the hunt.
That's what it looks like when an enterprise has the engineering depth to act on what it finds. Most don't get there. Just over half, or 53%, of enterprises have already had an agentic security incident or near-miss. Sixty-five percent enforce agent permissions at runtime, yet only 18% isolate their highest-risk agents, and just 8% pair enforcement with isolation.
Leaning on provider-native controls to do the heavy lifting of agentic security just exacerbates that gap. The July wave of VentureBeat Pulse Research found that 92% of enterprises naming a primary security layer default to their hyperscalers and AI platform providers.
Six waves of research have been completed since January, surveying 440 qualified enterprise security respondents. The key takeaway: the containment gap between what enterprises need and what's getting done is growing wider, often unaddressed by enterprises whose agentic AI investments and futures are at risk.
The satisfaction data doesn't match the incident data
The research keeps showing enterprises rating the tools they know best at a higher score, even if those tools failed them or delivered mediocre results. Three findings from the raw data cut against that instinct, and each one says something about how young this market still is.
The enterprises that got hit rate their tools higher than the ones that didn't
Last month’s survey found that 46 enterprises reported a confirmed incident or near-miss, then went on to rate their satisfaction with their security tooling. Their average satisfaction was 4.39 out of 5. 30 of the 55 enterprises who experienced no incidents rated their security tooling at 4.13. Enterprises are rewarding any tool that saves them from a breach with a trust premium.
It’s a sure sign of a nascent market when brand positioning, marketing, or other means of persuading enterprises get easily superseded by saving a customer from a breach. Near-misses outnumber confirmed incidents 2-to-1 in both June and July, which means enterprises are catching problems at the edge. That edge catch is being interpreted as validation of both the security strategy and the tools acquired. Evident through seven months of data is how quick enterprise security leaders are to trust a new tool that identifies an intrusion or breach and defeats it before it gains access. VentureBeat believes the rescue itself is doing the marketing. The 4.13 average among never-hit enterprises shows the other side of the same effect. Tools that have never been seen working earn less trust, not more.
VentureBeat also found that of the 17 enterprises isolating their highest-risk agents, the 14 that rated their tooling average 4.00. Enterprises that do not isolate rate it 4.35. The enterprises closest to real security are the least satisfied with their tools — that dissatisfaction is what drives them toward the kind of engineering effort Visa put in.
Four of five enterprises that solved identity did not build isolation
49%, or 57 of the 116 enterprises surveyed in July, gave each agent its own scoped, managed identity. Just a month earlier, VentureBeat's June wave recorded 32% of enterprises having assigned per-agent identities. July’s 17-point jump in one month is the fastest single-month move this series has recorded. Despite these gains, 63% still report credential sharing somewhere in the fleet. Only 11 of those 57 also isolate.
That ratio explains why the containment gap keeps widening even as every headline control improves. Enterprises are treating identity and isolation as substitutes. They need to see the longer-term vision of each being integral to a platform-based, layered strategy. Two incidents VentureBeat has covered show why that distinction matters. A rogue AI agent at Meta passed every identity check before its March exposure was contained. And CrowdStrike CEO George Kurtz disclosed, at his RSAC 2026 keynote, a Fortune 50 agent that rewrote its own security policy using valid credentials. Giving an agent scoped credentials does not bound the blast radius when those credentials are misused. Sandboxing does.
The enforce-without-isolate population has a 58% incident rate
Fifty-three enterprises in July’s survey enforce scoped permissions at runtime but do not isolate. 31 of those 53 have already had an agent security incident or near-miss. That is 58%, five points above the 53% sample average. The enterprises living inside the containment gap are getting hit more often than the enterprises outside it.
Amy Chang, Cisco's head of AI threat intelligence and security research, presented findings on the Transform agentic security panel showing that when Cisco ran 6,986 multi-turn attacks against 15 flagship models, attackers who adapted across the conversation broke through up to 88.3% of the time. Single-turn red-teaming missed it. An adaptive attacker who defeats the guardrails lands inside whatever architecture sits behind them, and for 53 of the enterprises in this data, that architecture enforces but does not contain.
VentureBeat's Q1 Pulse Research tracked the same structural weakness earlier this year. Unauthorized tool or data access ranked as the most feared failure mode in every Q1 survey, growing from 42% in January to 50% in March. The April-May survey found only 4% of enterprises comfortable relying on model guardrails alone. Enterprises predicted they needed external controls, choosing to build enforcement over containment.
Enterprises built enforcement 35 points ahead of forecast. Isolation barely moved
The April-May survey asked 109 enterprises how they expected agent behavior to be controlled by the end of 2026, and 30% predicted runtime enforcement, 14% sandboxed execution, and 32% model-level guardrails. By July, 65% had built enforcement, more than double the prediction, while isolation reached 18%, roughly the rate they said it would. Enterprises built what was easy at twice the forecast and built what was hard at roughly the forecast. The April question asked for the primary control mechanism, single-select, while July's posture question allowed multiple selections, so the comparison is directional rather than exact.
Provider lock-in accelerated across all three quarters
Provider-native platforms already led usage in April-May, named by seven in ten enterprises describing their tooling. By June, 82% called one their primary agent security layer, and by July that share reached 92%, with OpenAI's guardrails leading at 44%, Microsoft Azure at 42%, Anthropic's managed-agent controls at 37%, and Google Cloud at 31%. Cloudflare at 11% and Cisco at 9% lead the dedicated specialists fighting over what remains. The identity tools most relevant to the credential-sharing gap are the smallest of all, with Microsoft Entra Agent ID at 7%, while Okta for AI Agents, non-human identity platforms, and runtime sandboxing tooling each sit at 3%. CrowdStrike CTO Elia Zaitsev told VentureBeat at RSAC 2026 that observing agent actions is a solvable problem but inferring intent is not. The provider bundle proves his point, solving observation while leaving containment unbuilt.
74% plan to replace tools they just rated a career-high satisfaction score
Satisfaction scores continue rising as enterprises gain more experience using tools and techniques to stop agentic AI-based attacks. Rising to 4.29 out of 5 in July from 4.2 in June, satisfaction is the highest reading in the series.
Despite the high satisfaction levels, 74% plan to replace their tools within 12 months, up from 59% in June. Only 26% intend not to change. VentureBeat believes early adopters are impatient to gain greater insights, and know what they don’t know about agentic security and resilience. Closing that knowledge gap is forcing churn into a market this young, and the raw answers resolve the paradox: 92% of enterprises naming a primary layer name a provider-native one. The 4.29 measures how easy it is to turn on a provider's guardrails. It does not measure how effective those guardrails are at preventing the incidents 53% of the same respondents already had.
The organizations closest to the threat are the least confident about it
In June, defenders led attackers 35% to 21%, but by July the split was 30-30, a dead heat. Among enterprises that have been hit, 39% now say attackers are ahead, against 20% of those that have not. Getting hit nearly doubles the pessimism but does not change the shopping. Just 10% of enterprises include any agent-identity product in their consideration set. Runtime sandboxing draws 6%, and those numbers hold regardless of incident history. VentureBeat covered the same blind spot in the June data. The label changed from agent security gap to containment gap, but the shopping did not.
Methodology
The posture question was answered by 93 of the 116 qualified July respondents, and the skippers are not hidden isolators. Twenty-three of the 25 who selected no posture option are organizations still evaluating agents, unsure of their status, or with no deployment plans, groups for which a security posture largely does not yet exist, so the 18% isolation figure reads on the enterprises actually running or piloting agents. April-May, June, and July are separate, independently fielded waves rather than a single tracked series, so month-over-month comparisons in this piece are directional rather than a measured trend. Base sizes for the cross-cuts differ by instrument. The identity question covers all 116 respondents, isolation covers the 93 who described a posture, and the satisfaction inversion of 4.39 versus 4.13 is computed on the 76 respondents who rated their tooling.
The bottom line
VentureBeat's cross-survey analysis of 573 enterprise respondents concluded in July that enterprises deployed AI agents ahead of the controls needed to manage them, and they did it knowingly. Three waves of security-specific data now show where the knowing stops.
Enterprises continue giving agents scoped identities and treating that as containment, but that assumption is false, and the incident data keeps proving it. In fact, 46 of 57 enterprises that solved identity did not build isolation. The enforce-without-isolate population's 58% incident rate is the clearest evidence that identity alone isn't enough. The containment gap will not close through satisfaction with what is easy. Whether enterprises build isolation and governed identity deliberately, or whether a confirmed incident that propagates does it for them, is the question the next wave will answer.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み