July 19, 2026
企業資訊安全部門是最適合的 AI 管理單位
由於 AI 的自主性,以及眾人對於它的高度期待,AI 深入企業是遲早的事情,現在的問題不是那道界線在那邊,而是企業內現有資訊系統還要花多少時間來接納/串接它,這才是真正的門檻。

By Will 的資安觀測筆記
3 min read
對於企業的資訊安全決策者來說,面對一個不確定性 (Non-deterministic) 的 AI 來說,這個問題不是一個簡單要或不要的問題,也不是簡單劃下一道界線就可以明哲保身,那種過輕鬆日子的想法已經過去了。反而是我們還有多少時間可以準備?有多少時間可以跟高層或是使用者說不?甚至是說這個是可以準備的題目嗎?
經歷過這兩年來的 AI 洗禮,從一開始單純對話式的可控的使用模式,到今年自主 Agentic AI 運行方式,資訊安全管理的界線已經是不斷地被逼到懸崖邊。最強最好用的 AI 模型在雲端,大型企業窮極力氣也難以複製,中型企業更不可能,最後可能拖慢企業進步效能,或是引來更多使用者的抱怨,甚至資安成為使用者躺平的理由。
以目前 AI 服務迭代極為快速的現在,同一家服務幾乎是每週都會有新的功能更新,Claude 就是如此,更別說幾個主要的 AI 服務商,只能說新服務推出已是應接不暇。如果還是抱持著事不關己,IT 或是使用單位有需求再來評估的想法,基本上現在已經是跟不上時代。
Agentic AI 服務還有一個與以往資訊系統或是雲端服務不同的是,它對於企業安全管理最大的風險與挑戰來自於它的自主性、不確定性 (Non-deterministic),以及分不出 Data 與 Command 的本質,這三項合併在一起就會造就各項潛在的未爆彈。
以我認識的幾家高科技公司資安單位的朋友來說,大家的同感是追得很辛苦,有餘裕的會設法自己先研究,跑在使用者與需求單位之前弄清楚各項功能是什麼。更進一步的會強化 AI 服務監控,最好的是直接介入AI 系統管理,讓每一項功能的啟用與否都經過仔細的評估與研究之後,平衡使用端的需求與企業資訊安全防護後才開放。最適合的管理單位應該是企業資安單位,同時跟其他單位合作,而非傳統由 IT 獨撐大樑,更非只考量最大使用效益卻不懂資安風險的使用單位來左右方向。
以 Claude Enterprise 來舉例,"User Created Skills" 選項或是 Claude for Chrome 的黑白名單模式就足以讓資安決策單位面臨非常困難決定的情境,但使用者只會感受到無法使用,卻不理解這背後是有相當風險的存在。如果此時資安單位還躲在後面,任由各項功能與設定隨波逐流,或是煞車踩到底通通不能用,就不是一個勇於承擔的做法,可能會將企業可能因為應用 AI 所帶來的競爭優勢死死地往水裡拖。
因此企業資訊安全管理部門應該更有遠見地往前走,擺脫傳統監管單位形象,主動踏入 AI 管理,深入掌控各項功能的開啟或關閉,才有可能帶著企業往新時代走去。
Due to the autonomy of AI and everyone's high expectations for it, AI deeply penetrating enterprises is only a matter of time. The current question is not where that boundary lies, but rather how much time existing information systems within enterprises will still need to spend to accept/integrate it — this is the real hurdle.
For enterprise information security decision-makers, when facing a non-deterministic AI, this issue is not a simple question of "yes" or "no," nor can one protect oneself simply by drawing a boundary. That kind of thinking of living an easy life is gone. Instead, the questions are: How much time do we still have to prepare? How much time do we have to say no to executives or users? Or is this even a topic that can be prepared for?
Having experience of AI over these past two years — moving from the simple, conversational, and controllable usage models at the beginning to the autonomous, Agentic AI operational methods this year — the boundaries of information security management have been continuously pushed to the edge of the cliff. The strongest and most useful AI models are in the cloud; large enterprises exhaust their efforts and still find them difficult to replicate, while medium-sized enterprises find it even more impossible. Ultimately, this may slow down the efficiency of enterprise progress, trigger more user complaints, or even lead to information security becoming an excuse for users to "lie flat" (give up).
With the current extremely rapid iteration of AI services, where the same service has new feature updates almost every week — Claude is a case in point, not to mention several major AI service providers — one can only say that the launch of new services is already overwhelming. If one still holds onto the mindset that "it's none of my business" and "we will only evaluate it when IT or user departments have a need," basically, they are already failing to keep up with the times.
Another difference between Agentic AI services and past information systems or cloud services is that its greatest risks and challenges to enterprise security management stem from its autonomy, its non-deterministic nature, and its essence of not distinguishing between Data and Command. Combining these three together creates various potential unexploded bombs.
Based on some friends I know in the information security departments of several high-tech companies, everyone's common feeling is that keeping up is very exhausting. Those with extra capacity will try to research it themselves first, figuring out what each feature is before users and requesting departments do. Going a step further, they will strengthen AI service monitoring. The best approach is to directly intervene in AI system management, allowing the enabling or disabling of each feature to undergo careful evaluation and research, opening them up only after balancing user-side demands with enterprise information security protection. The most suitable management unit should be the enterprise information security department, cooperating with other departments simultaneously, rather than the traditional way of IT bearing the brunt alone, and certainly not the user departments — who only consider maximum utilization benefits but do not understand information security risks — steering the direction.
Taking Claude Enterprise as an example, options like "User Created Skills" or the allowlist/blocklist mode of Claude for Chrome are enough to place information security decision-making units into situations of very difficult choices. However, users will only feel that they cannot use it, without understanding that there are considerable risks behind it. At this time, if the information security unit still hides in the back, letting various features and settings drift with the tide, or slamming on the brakes so that absolutely nothing can be used, it is not a courageous and responsible approach. It might drag the competitive advantages that the enterprise could gain from applying AI dead down into the water.
Therefore, enterprise information security management departments should step forward with more foresight, shake off the traditional image of a regulatory unit, actively step into AI management, and deeply control the turning on or off of each feature. Only then is it possible to lead the enterprise into the new era.
(English translation by Gemini)