Abnormal AI 近日揭晓了其 AI 安全套件的最新增补产品,旨在帮助企业安全地采用人工智能技术,同时抵御由人工智能创建或加速的新威胁。
该套件整合了已全面发布的 Abnormal AI Governance 和此前在私有预览阶段宣布的 AI Cloud Security,并新增了三款产品:AI Employee Guardrails(员工 AI 护栏)、AI Agent Security(AI 代理安全)以及 AI Security Workbench(AI 安全工作台)。
企业正在业务的几乎各个层面采用人工智能,员工将生成式 AI 工具和代理作为日常工作流的一部分。与此同时,攻击者也在利用人工智能来提高其行动的速度、规模和复杂程度。
对于安全团队而言,挑战已不再仅仅是“是否在使用 AI”。他们需要弄清楚哪些 AI 工具和代理在其环境中运行,谁或什么实体可以访问敏感系统和数据,这些活动是否符合预期行为,以及在行为异常时该如何应对。Abnormal 的 AI 安全套件旨在通过一个由行为 AI 驱动的统一平台来解决这些挑战。
“人工智能的进步正在改变全球组织的风险状况,”Abnormal AI 的首席执行官兼创始人 Evan Reiser 表示。“这使得理解人类和非人类身份及行为变得更为重要。安全团队需要明确是谁在采取行动、他们拥有何种访问权限、正常行为是什么样的,以及何时发生了有意义的变化。这正是 Abnormal 致力于解决的安全问题,而现在我们将这种方法扩展到了企业 AI 领域。企业需要一个能够观察并理解员工、代理和云基础设施行为的统一平台,因为风险正是通过这些渠道显现的。”
Abnormal 的 AI 安全套件
AI 安全套件围绕企业采用人工智能带来的五大安全需求构建:
AI Governance(AI 治理):帮助组织发现并了解整个企业中的人工智能使用情况,包括获批准和未获批准的应用程序。安全团队可以评估 AI 应用程序,了解采用情况和用法,建立政策,掌握与 AI 相关的支出情况,并保留证据以支持治理、审计和合规计划。
AI Cloud Security(AI 云安全):将行为检测扩展到云环境,以阻止由 AI 驱动的云端入侵。AI Cloud Security 帮助组织识别未管理或潜在恶意的 AI 活动,了解涉及的实体和资源,揭示安全和态势风险,并调查生产云环境中的行为。
AI Employee Guardrails(员工 AI 护栏):使组织能够治理整个企业中生成式 AI 工具和 AI 增强型应用程序的使用。安全团队可以在使用点应用使用策略,并提供实时指导或阻止存在安全或数据风险的活动。
AI Agent Security(AI 代理安全):让安全团队识别和监控第一方和第三方 AI 代理。该产品将代理与其关联的身份、系统、权限和资源连接起来,然后监控其活动以发现意外或潜在危险的行为。这使组织能够不仅基于代理被允许做什么,而是基于其实际行为来治理代理。
AI Security Workbench(AI 安全工作台):为安全团队提供一个专为调查行为安全数据中威胁而设计的专用环境。安全工程师可以利用 AI 辅助的调查和分析,探索跨实体和系统的活动,识别值得深入调查的模式,并开发新的检测和响应工作流,而无需完全依赖手动构建的查询和规则。
该套件解决了企业 AI 安全挑战的两个方面:既使组织能够以更高的可见性和控制力采用人工智能,又帮助防御涉及 AI 代理、身份和云基础设施的威胁。
“安全团队不应在启用人工智能与控制随之而来的风险之间做出选择,”Reiser表示。“我们的目标是为他们提供足够的可见性和上下文信息,使业务能够快速推进,同时能够识别出员工、账户或自主智能体何时开始执行其不应执行的操作。”
Abnormal AI has unveiled the newest additions to its AI Security suite, designed to help enterprises adopt AI securely while protecting against new threats created or accelerated by AI.
The suite brings together Abnormal AI Governance, which is generally available, and AI Cloud Security, previously announced in private preview, with three newly announced products: AI Employee Guardrails, AI Agent Security, and AI Security Workbench.
Enterprises are adopting AI across nearly every part of the business with employees using generative AI tools and agents as part of their daily workflows. At the same time, attackers are using AI to increase the speed, scale, and sophistication of their operations.
For security teams, the challenge is no longer just whether AI is being used. They need to understand which AI tools and agents are operating in their environment, who or what has access to sensitive systems and data, whether that activity is consistent with expected behavior, and how to respond when it is not. Abnormal’s AI Security suite is designed to address those challenges through a unified platform powered by behavioral AI.
“Advances in AI are changing the risk profile for organizations around the world,” said Evan Reiser , CEO and Founder of Abnormal AI. “That makes understanding human and non-human identity and behavior more important. Security teams need to understand who is acting, what access they have, what normal behavior looks like, and when something meaningfully changes. That is the security problem Abnormal was built to solve, and we are now extending that approach to enterprise AI. Enterprises need one platform that sees and understands behavior for employees, agents, and cloud infrastructure, because that’s how these risks actually surface.”
Abnormal’s AI Security suite
The AI Security suite is organized around five security needs created by enterprise AI adoption:
AI Governance: Helps organizations discover and understand AI use across the enterprise, including sanctioned and unsanctioned applications. Security teams can evaluate AI applications, understand adoption and usage, establish policies, gain visibility into AI-related spend, and maintain evidence to support governance, audit, and compliance programs.
AI Cloud Security: Extends behavioral detection to cloud environments to stop AI-driven cloud breaches. AI Cloud Security helps organizations identify unmanaged or potentially malicious AI activity, understand the identities and resources involved, surface security and posture risks, and investigate behavior across production cloud environments.
AI Employee Guardrails: Enables organizations to govern generative AI tool and AI-enabled application use across the enterprise. Security teams can apply usage policies at the point of use and provide real-time guidance or block activity that presents security or data risk.
AI Agent Security: Lets security teams identify and monitor first-party and third-party AI agents. The product connects agents to the identities, systems, permissions, and resources associated with them, then monitors their activity for unexpected or potentially risky behavior. This gives organizations a way to govern agents not simply based on what they are allowed to do, but on how they actually behave.
AI Security Workbench: Gives security teams a purpose-built environment for investigating threats across behavioral security data. Security engineers can use AI-assisted investigation and analysis to explore activity across identities and systems, identify patterns that merit investigation, and develop new detections and response workflows without relying solely on manually constructed queries and rules.
The suite addresses both sides of the enterprise AI security challenge: enabling organizations to adopt AI with greater visibility and control, while helping defend against threats involving AI agents, identities, and cloud infrastructure.
“Security teams should not have to choose between enabling AI and controlling the risk that comes with it,” said Reiser. “The goal is to give them enough visibility and context to let the business move quickly, while recognizing when an employee, an account, or an autonomous agent starts doing something it should not be doing.”
首次收录 · 2026-09-26 · 7.26 分