字号 ·· | 护眼
thenextweb

端点管理器接下来要管理的是一个AI代理

点「原文对照」整页切到原文,或双击某段只看那段的原文。

Gartner预测,到今年年底,特定任务的AI代理将被集成到40%的企业应用程序中——这一比例从之前的不到5%大幅上升。

Gartner forecasts that task-specific AI agents will be integrated into 40% of enterprise applications by the end of the year. That’s up from less than 5%.

然而,那些用于管理设备上运行软件的系统的发展速度远远落后于AI技术的发展。根据Automox对IT专业人士的调查,目前只有46%的企业实现了端点设备(即计算机终端)的自动化库存管理和监控。这已经超出了传统意义上的“软件库存管理”范畴;因为在这种情况下,软件不再需要等待人工指令来决定自己的行为。

The systems meant to catalog what runs on a managed device haven’t kept pace. 46% of organizations automate endpoint inventorying and monitoring today, per Automox’s survey of IT professionals. That goes beyond a software inventory problem in the traditional sense. It’s the point at which software stopped waiting to be told what to do.

传统的软件库存管理方式主要回答的是“系统中安装了哪些软件”这样的静态问题;在软件技术发展的早期阶段,这种管理方式确实足够用了。但在AI时代,这种管理方式已经不再适用了。因为AI代理能够自主读取本地文件、调用工具、调用API,并在无人监控的情况下执行多步骤操作。

The Inventory Question Just Changed Shape Software inventory answers a static question. For most of the discipline’s history that was enough. Software on an endpoint did nothing until a person or a scheduler told it to. Resident agents break that premise. They read local files, call tools, invoke APIs, and take multi-step action in the gaps between the moments anyone’s looking.

因此,真正有意义的问题不再是“系统中安装了什么软件”,而是“这些软件被允许执行哪些操作,以及它们实际完成了什么”。Cyberhaven Labs发现,过去一年中,企业对基于AI的端点应用程序的采用率增长了509%;BeyondTrust的Phantom Labs则指出,企业环境中AI代理的使用量同比增长了466.7%。虽然这些数据来自特定供应商的统计结果,并不能代表整个行业的趋势,但它们都表明了一个同样的方向:AI技术正在迅速普及。

The Inventory Question Just Changed Shape Software inventory answers a static question. For most of the discipline’s history that was enough. Software on an endpoint did nothing until a person or a scheduler told it to. Resident agents break that premise. They read local files, call tools, invoke APIs, and take multi-step action in the gaps between the moments anyone’s looking. So the useful question shifts to not what’s installed, but what it’s allowed to do and what it did. Cyberhaven Labs found enterprise adoption of endpoint-based AI-native apps grew 509% over the past year. BeyondTrust’s Phantom Labs put the rise in AI agents inside enterprise environments at 466.7% YoY. Both figures are vendor telemetry rather than industry-wide measurement, but they point the same way.

Automox的CEO Justin Talerico表示:“没有人能做到所有事情都完全正确。但‘犯错’和‘同时到处犯错’之间是有区别的:如果只有一台机器出了问题,你可以修复它然后继续正常运行;但如果这种错误被复制到整个系统中,你就不再是在修复一个小错误,而是在应对一场危机了。缺乏规模化的快速响应只会带来更多的学习成本;而具备规模化处理能力的快速响应,则意味着每次决策都必须完全依赖于自己的判断——而这正是人们往往直到为时已晚才意识到的问题。”

“Nobody gets everything right. But there’s a difference between being wrong and being wrong everywhere at once,” says Automox CEO Justin Talerico. “One bad call on one machine, you fix it and move on. That same call pushed across the fleet, suddenly you’re not fixing a mistake, you’re managing a crisis. Speed without scale is a learning curve. Speed at scale is a bet on your own judgment, every time. That’s the part people don’t consider until it’s too late.” The property that makes an agent useful, acting without waiting, is what turns an ungoverned one into a fleet-wide event.

正是AI代理的这种“无需等待、能够自主行动”的特性,使得原本难以管理的系统变成了能够在整个企业范围内产生影响的工具。

“Nobody gets everything right. But there’s a difference between being wrong and being wrong everywhere at once,” says Automox CEO Justin Talerico. “One bad call on one machine, you fix it and move on. That same call pushed across the fleet, suddenly you’re not fixing a mistake, you’re managing a crisis. Speed without scale is a learning curve. Speed at scale is a bet on your own judgment, every time. That’s the part people don’t consider until it’s too late.” The property that makes an agent useful, acting without waiting, is what turns an ungoverned one into a fleet-wide event.

这些事件按照定义都会被报告给终端管理团队(endpoint management teams)。然而,大多数这些团队对自己系统的安全状况缺乏清晰的了解;只有 36% 的团队向 Automox 表示他们对自身系统的合规性(即是否符合安全标准)非常有信心或极其有信心。

“Nobody gets everything right. But there’s a difference between being wrong and being wrong everywhere at once,” says Automox CEO Justin Talerico. “One bad call on one machine, you fix it and move on. That same call pushed across the fleet, suddenly you’re not fixing a mistake, you’re managing a crisis. Speed without scale is a learning curve. Speed at scale is a bet on your own judgment, every time. That’s the part people don’t consider until it’s too late.” The property that makes an agent useful, acting without waiting, is what turns an ungoverned one into a fleet-wide event.

代理(Agents)的权限机制: AI 代理本身没有独立的权限,它们会使用启动它们的应用程序或系统的身份信息及权限范围来执行操作。这正是 BeyondTrust 在代理身份管理(agent identity governance)方面的核心理念。操作系统无法区分用户手动输入的命令与由 AI 模型生成的命令——这一切都符合系统的设计初衷,无需任何额外的攻击手段。

Those events land on the endpoint team by definition. Most of those teams lack a clear view of their own estate. Only 36% told Automox they were very or extremely confident in their endpoint compliance visibility. Agents Inherit Privilege, They Do Not Request It An AI agent has no privileges of its own. It runs with the identity and permission scope of whatever launched it. That is BeyondTrust’s point on agent identity governance. The operating system can’t tell a command a person typed from one a model generated. None of that requires an exploit; it’s the design working as intended.

权限的撤销与管理:在大多数关于代理管理的讨论中,权限的“撤销”(revocation)这一环节往往被忽略。系统通过清单(inventory)来确认代理的存在,而权限范围(scope of permissions)则决定了代理可以执行哪些操作。作为终端管理工具,这类工具的独特优势在于能够及时发现用户在决定停止某个代理后的 90 秒内发生的所有异常行为。

Revocation is the verb missing from most agent conversations. Inventory confirms an agent exists and scoping decides what it may do. What a fleet tool is uniquely placed to answer is what happens in the ninety seconds after someone decides it should stop.

OWASP 对 LLM 应用的安全建议: OWASP 将这类安全漏洞归类为“代理权限过度(Excessive Agency”问题,认为其根源在于代理功能过于强大、权限设置过于宽松以及代理的自主性过高。其中,权限问题占据了主要原因。缓解这类问题的方法主要包括:限制代理在用户环境中的操作范围,以及对高影响操作进行审批。

The OWASP Top 10 for LLM Applications files this failure mode under Excessive Agency. It traces it to excessive functionality, excessive permissions, and excessive autonomy. Two of those three are permission problems. Its mitigations read like endpoint policy. Minimize what an agent can reach, execute in the user’s context, require approval for high-impact actions.

现实情况:然而,大多数组织并未采取这些措施。IBM 的《2026 年数据泄露成本报告》显示,92% 报告 AI 相关数据泄露事件的组织缺乏有效的 AI 访问控制机制;仅有 40% 的组织对 AI 模型和数据实施了访问控制。Teleport 在 2026 年进行的基础设施身份管理调查中发现:权限过低的 AI 系统发生数据泄露的概率为 17%,而权限过高的系统这一概率则高达 76%。

Most organizations aren’t doing it. IBM’s Cost of a Data Breach Report 2026 found that 92% of organizations reporting an AI-related breach lacked proper AI access controls. Only 40% apply access controls to AI models and data at all. Teleport’s 2026 Infrastructure Identity Survey measured the cost at a 17% incident rate for least-privileged AI access against 76% for over-privileged systems.

关键控制原则:

The controls that make an agent safe to run already make any automated change safe. Automox’s agent-facing Model Context Protocol integration ships with a read-only mode that disables every write operation through a single setting, tool access scoped by role, and correlation IDs written to an audit log on every invocation. That isn’t a new category of control, it’s endpoint governance applied to a caller that reasons.

那些确保代理程序安全运行的控制措施,同时也确保了所有自动化操作的安全性。Automox 的代理程序所使用的“模型上下文协议”(Model Context Protocol)集成了只读模式——通过一个简单的设置即可禁用所有写入操作;工具的使用权限基于用户角色进行限制;每次调用该协议时,相关操作信息都会被记录到审计日志中。这并非一种全新的控制机制,而是将传统的“端点治理”(endpoint governance)原则应用于调用该协议的程序/用户。

The controls that make an agent safe to run already make any automated change safe. Automox’s agent-facing Model Context Protocol integration ships with a read-only mode that disables every write operation through a single setting, tool access scoped by role, and correlation IDs written to an audit log on every invocation. That isn’t a new category of control, it’s endpoint governance applied to a caller that reasons.

现状与挑战:目前所有的治理框架都假设代理程序的数量是已知的,但实际上这一数量并不明确。Verizon 在 2026 年发布的《数据泄露调查报告》中指出:67% 的用户是通过企业设备中的非企业账户来访问人工智能服务的;在这些设备上,45% 的员工属于“常规人工智能用户”(即经常使用人工智能功能的员工),而这一比例较去年同期上升了 15%。

Ungoverned by Default Every governance framework here assumes a known population of agents. The population isn’t known. Verizon’s 2026 Data Breach Investigations Report found 67% of users reaching AI services from non-corporate accounts on corporate devices. 45% of employees now qualify as regular AI users on those devices, up from 15% a year earlier.

在 Verizon 的数据泄露预防数据集中,“影子人工智能”(shadow AI)已成为第三大常见的非恶意内部行为(其发生率增长了四倍)。最常被未经授权的模型访问的数据类型是源代码。IBM 的调查结果也显示类似的趋势:涉及“影子人工智能”的事件从 20% 增加到了 43%;68% 的受攻击组织缺乏相应的管理或检测机制。

Shadow AI is now the third most common non-malicious insider action in Verizon’s data loss prevention dataset, a fourfold increase in percentage terms. The data type most often handed to unauthorized models is source code. IBM’s numbers run parallel: shadow AI incidents more than doubled to 43% from 20%, and 68% of breached organizations had no policy for managing or detecting it.

应对策略:当未经授权的软件数量增长速度超过黑名单的更新速度时,单纯通过阻止特定工具已无法有效解决问题。十年前,端点管理团队就已经意识到这一点,并提出了相应的解决方案:对未经授权的软件进行清单管理、制定相关政策,并提供相应的移除机制。

Blocking named tools doesn’t work when the category grows faster than the blocklist. Endpoint teams reached that conclusion about unsanctioned software a decade ago, and the answer was inventory, policy, and the ability to remove.

技术障碍与用户顾虑:当被问及哪些因素阻碍了自动化端点管理的实施时,Automox 调查中的 46% 的 IT 专业人士提到了数据隐私与安全问题,44% 的人担心操作错误或未经授权的变更可能带来的风险,还有 36% 的人表示对人工智能驱动的建议缺乏信任。他们最迫切需要的功能是:自动回滚机制(43%的人提出这一需求),以及暂停或覆盖现有设置的能力(42%的人提出这一需求)。

The resistance isn’t about value. Asked what holds them back from autonomous endpoint management, 46% of the IT professionals in Automox’s survey named data privacy and security implications, 44% the risk of incorrect or unauthorized changes, and 36% limited trust in AI-driven recommendations. What they want first is brakes: automatic rollback, named by 43%, and the ability to pause or override, named by 42%.

关于“AI代理是否应属于终端管理(endpoint management)的范畴”这一争论,其实早已通过这些AI代理的实际运行环境得到了明确答案。剩下的问题仅仅是所有权方面的问题:究竟是哪个团队负责管理这些AI代理;谁来决定它们的使用权限范围;以及当权限范围被证明是错误的时候,如何迅速收回对这些代理的访问权限。

Scope, Then Trust The argument over whether AI agents belong under endpoint management has been settled by where they run. What’s left is an ownership question before it’s a technical one: which team holds agent inventory, who sets the permission scope, and how fast access can be withdrawn when that scope turns out to be wrong.

本文由第三方作者提供,并非 TNW 新闻编辑部所撰写,因此不代表 TNW 的编辑立场。

Contributed article. Not produced by the TNW newsroom and does not reflect the editorial stance of TNW.