NIST CAISI AI Agent Security RFI ― Agent Securityを「Model+Software System」の問題として定義
Executive Summary
NISTのCenter for AI Standards and Innovation(CAISI)は2026年1月12日、AI Agent Systemの安全な開発・導入に関するRequest for Information(RFI)を公開しました。1
RFIが重要なのは、Agent SecurityをModel単体の問題として扱っていない点です。AI ModelのOutputがSoftware SystemのTool、Data、Credential、APIと結び付くことで、Indirect Prompt Injection、Poisoned Model、Specification Gaming、過剰なAgent AccessといったAgent固有のSystem Riskが生まれると整理しています。
この時点でNISTは、Agent Securityを独立したCybersecurity論点として扱い、Development、Deployment、Measurement、Access Constraint、Monitoringまでを今後のGuidance対象として明示しました。
なぜ今なのか
AI Agentは回答を生成するだけでなく、外部SystemへActionできます。そのため「Modelが安全か」だけでなく、Model Outputがどの権限でどのToolを動かすかがRiskを決めます。
RFIが提示した主要論点
- Agent固有のSecurity Threat
- Indirect Prompt Injection
- Poisoned / Insecure Model
- Misaligned Action / Specification Gaming
- Development段階でのSecurity Assessment
- Deployment EnvironmentでのAccess Constraint
- Runtime Monitoring
- Agent SecurityのMeasurement
- 従来Cybersecurity Practiceの適用可能性とGap
経営インパクト
| 観点 | 影響 |
|---|---|
| Architecture | AI Agentを通常Appと同じTrust Modelで扱えない |
| IAM | Agent Access Scopeを独立して制御する必要 |
| Governance | Model Reviewだけでは導入審査が不十分 |
| Assurance | Agent Securityを測るMetric / Testが必要 |
日本企業への示唆
Agent導入申請では、Model名や利用目的だけでなく、Agentが接続するData、Tool、Credential、Action、Network、Approval Pointを必須項目にした方が安全です。
推奨アクション
- Agent InventoryとOwnerを作成する
- AgentごとにTool / Data / Action Scopeを記録する
- High-impact ActionへHuman Approvalを設定する
- External ContentをUntrusted Inputとして扱う
- Agent AccessをLeast Privilegeで制約する
- Runtime LoggingとSecurity Testを導入条件にする
用語解説
AI Agent System
AI Modelの推論をSoftware、Tool、Data Source、Credential、Workflow等と組み合わせ、計画・判断・Actionを実行するSystem。