我们分享了一套在企业中部署自主 AI 智能体的安全框架,涵盖了新的威胁格局、分层零信任架构,以及为应对 AI 加速攻击而构建的防御运营体系。
- 分类企业 AI智能体
- 产品Claude 安全
- 日期2026 年 5 月 27 日
- 阅读时间5分钟
- https://claude.com/blog/zero-trust-for-ai-agents
前沿 AI 模型正在将漏洞发现到利用的时间窗口从数月压缩至数小时。采用这些工具的防御者能更快地发现并修复漏洞;而采用它们的攻击者,或者仅仅是等待防御者的补丁并将其逆向工程为攻击手段的人,行动速度也同样加快。这并非未来的隐忧:模型如今已能发现传统工具和人工审查多年来都遗漏的严重漏洞。
对于任何部署智能体的组织而言,这种加速具有双重意义。你的智能体所运行的基础设施,与你的其他资产一样,暴露在 AI 加速的攻击之下;而智能体本身则引入了自主性,用于解读目标、选择工具并执行多步骤操作。传统的访问控制无法阻止智能体滥用合法权限,监控也需要考虑到那些旨在通过持久性而非直接利用漏洞来达成成功的攻击。
零信任——不信任任何事物,验证一切,并假设已发生入侵——为安全领导者应对这一问题提供了经过验证的基础。但这些原则需要针对智能体系统进行重塑:基于密码学根植的身份、按任务划分的权限范围、防止中毒的内存保护,以及以自主攻击者速度运行的防御运营。
为了帮助安全和风险领导者应对这一转变,我们整理了一套在企业中部署自主 AI 智能体的实用框架。
- 智能体系统特有的安全考量,包括工具访问、自主决策、上下文持久化以及多智能体协调
- 当前智能体面临的威胁格局,包括提示词注入、工具投毒、身份与权限滥用、内存投毒以及供应链攻击
- 一个三层零信任框架(基础级、进阶级和优化级),与组织成熟度和风险承受能力相对应。
- 一个涵盖身份、访问范围界定、沙箱隔离、输入输出控制以及内存保护措施的八阶段实施工作流。
- 如何快速运行智能体安全运营(智能体 SOAR),以应对 AI 加速的攻击者。
- 针对受监管行业(包括医疗、金融和政府)的合规对齐。
最适合迎接这一转变的组织,将是那些基础足够扎实、以至于 AI 辅助扫描一开始就能发现更少漏洞,并且其智能体部署从第一天起就为应对入侵而设计的组织。
立即开始使用 Claude Security。
用 Claude 改变您组织的运营方式。
We share a security framework for deploying autonomous AI agents in the enterprise, covering the new threat landscape, a tiered Zero Trust architecture, and defensive operations built for AI-accelerated attacks.
- Category
- ProductClaude Security
- DateMay 27, 2026
- Reading time5min
- https://claude.com/blog/zero-trust-for-ai-agents
Frontier AI models are compressing the timeline between vulnerability and exploit from months to hours. Defenders who adopt these tools find and fix bugs faster; attackers who adopt them, or who simply wait for defenders' patches and reverse-engineer them into exploits, move faster too. This is not a future concern: models can already find serious vulnerabilities that traditional tooling and human reviewers have missed for years.
This acceleration matters twice for any organization deploying agents. The infrastructure your agents run on is exposed to AI-accelerated offense like the rest of your estate, and the agents themselves introduce autonomy to interpret goals, select tools, and execute multi-step operations. Traditional access controls won't prevent agents from misusing legitimate permissions, and monitoring needs to account for attacks designed to succeed through persistence rather than exploitation.
Zero Trust—trust nothing, verify everything, and assume breach has already occurred—gives security leaders a proven foundation to address this. But the principles need new shape for agentic systems: identities that are cryptographically rooted, permissions scoped per task, memory protected against poisoning, and defensive operations that run at the speed of autonomous attackers.
To help security and risk leaders build for this shift, we put together a practical framework for deploying autonomous AI agents in the enterprise.
- The security considerations unique to agentic systems, including tool access, autonomous decision-making, context persistence, and multi-agent coordination
- The current threat landscape for agents, including prompt injection, tool poisoning, identity and privilege abuse, memory poisoning, and supply chain attacks
- A three-tier Zero Trust framework (Foundation, Advanced, and Optimized) mapped to organizational maturity and risk tolerance
- An eight-phase implementation workflow covering identity, access scoping, sandboxing, input and output controls, and memory safeguards
- How to run agentic security operations (Agentic SOAR) fast enough to contend with AI-accelerated attackers
- Compliance alignment for regulated industries including healthcare, finance, and government
The organizations best positioned for this shift will be the ones whose fundamentals are strong enough that AI-assisted scanning finds fewer bugs in the first place, and whose agent deployments are architected for breach from day one.
Get started with Claude Security today.