コンテンツにスキップ

NIST CAISI AI Agent Security RFI ― Agent Securityを「Model+Software System」の問題として定義

Executive Summary

NISTのCenter for AI Standards and Innovation(CAISI)は2026年1月12日、AI Agent Systemの安全な開発・導入に関するRequest for Information(RFI)を公開しました。1

RFIが重要なのは、Agent SecurityをModel単体の問題として扱っていない点です。AI ModelのOutputがSoftware SystemのTool、Data、Credential、APIと結び付くことで、Indirect Prompt Injection、Poisoned Model、Specification Gaming、過剰なAgent AccessといったAgent固有のSystem Riskが生まれると整理しています。

この時点でNISTは、Agent Securityを独立したCybersecurity論点として扱い、Development、Deployment、Measurement、Access Constraint、Monitoringまでを今後のGuidance対象として明示しました。

なぜ今なのか

AI Agentは回答を生成するだけでなく、外部SystemへActionできます。そのため「Modelが安全か」だけでなく、Model Outputがどの権限でどのToolを動かすかがRiskを決めます。

RFIが提示した主要論点

  • Agent固有のSecurity Threat
  • Indirect Prompt Injection
  • Poisoned / Insecure Model
  • Misaligned Action / Specification Gaming
  • Development段階でのSecurity Assessment
  • Deployment EnvironmentでのAccess Constraint
  • Runtime Monitoring
  • Agent SecurityのMeasurement
  • 従来Cybersecurity Practiceの適用可能性とGap

経営インパクト

観点 影響
Architecture AI Agentを通常Appと同じTrust Modelで扱えない
IAM Agent Access Scopeを独立して制御する必要
Governance Model Reviewだけでは導入審査が不十分
Assurance Agent Securityを測るMetric / Testが必要

日本企業への示唆

Agent導入申請では、Model名や利用目的だけでなく、Agentが接続するData、Tool、Credential、Action、Network、Approval Pointを必須項目にした方が安全です。

推奨アクション

  1. Agent InventoryとOwnerを作成する
  2. AgentごとにTool / Data / Action Scopeを記録する
  3. High-impact ActionへHuman Approvalを設定する
  4. External ContentをUntrusted Inputとして扱う
  5. Agent AccessをLeast Privilegeで制約する
  6. Runtime LoggingとSecurity Testを導入条件にする

用語解説

AI Agent System
AI Modelの推論をSoftware、Tool、Data Source、Credential、Workflow等と組み合わせ、計画・判断・Actionを実行するSystem。

関連記事

参考情報