公式動画ピックアップ
AAPL
ADBE
ADSK
AIG
AMGN
AMZN
BABA
BAC
BL
BOX
C
CHGG
CLDR
COKE
COUP
CRM
CROX
DDOG
DELL
DIS
DOCU
DOMO
ESTC
F
FIVN
GILD
GRUB
GS
GSK
H
HD
HON
HPE
HSBC
IBM
INST
INTC
INTU
IRBT
JCOM
JNJ
JPM
LLY
LMT
M
MA
MCD
MDB
MGM
MMM
MSFT
MSI
NCR
NEM
NEWR
NFLX
NKE
NOW
NTNX
NVDA
NYT
OKTA
ORCL
PD
PG
PLAN
PS
RHT
RNG
SAP
SBUX
SHOP
SMAR
SPLK
SQ
TDOC
TEAM
TSLA
TWOU
TWTR
TXN
UA
UAL
UL
UTX
V
VEEV
VZ
WDAY
WFC
WK
WMT
WORK
YELP
ZEN
ZM
ZS
ZUO
公式動画&関連する動画 [AI agents leak data — unless you control what they can see]
AI agents leak sensitive data if access controls aren't enforced at the content layer. Ben Kus, CTO of Box, explains how to fix it before it becomes an incident.
In this episode of the AI Explainer series, Ben explains a challenge that's quietly becoming one of the most urgent topics in CIO conversations: access controls for AI agents.
Here's what you need to understand: agents are terrible at keeping secrets. Whatever an agent knows, whatever data it can retrieve, it'll just happily tell whoever's interacting with it. That's not a bug in any one product, it's a fundamental characteristic of how agents work. And if you haven't thought through what your agents can access, you've already created a data leakage problem.
Ben walks you through a scenario you may already be facing. Imagine someone on your finance team working on a highly sensitive deal. Their role gives them finance access, but not access to that specific deal's documents. A poorly configured agent doesn't know the difference. It's optimizing for relevance, not permission. So it surfaces the deal documents anyway, because the person asked a finance question and the agent retrieved all the financial data it could reach.
This is why role-based access control alone isn't enough for agentic AI. The solution Ben outlines is architectural. You need to connect your agents to a content platform that enforces existing user-level permissions at the point of data retrieval, what Box calls direct user access controls. Your agent can only retrieve content that the specific user making the request is already authorized to view. It inherits the user's permissions rather than operating with its own broader access.
Because Box stores unstructured enterprise content with granular, user-level permissions already in place, an AI agent retrieving content through Box automatically applies those controls. You don't need to rebuild governance from scratch or manage a new security model. The agent sees exactly what the user sees, nothing more.
The takeaway Ben leaves you with is clear: before you scale your AI agent deployments, verify that your content retrieval layer enforces access controls at the user level. Agents that can't keep secrets will tell everyone everything. The fix is available, but it requires connecting your agents to a platform that already knows the rules.
FAQs:
Q: Why are AI agents a data leakage risk? A: As Ben Kus, CTO of Box, explains in this video, agents retrieve and surface whatever content they can access. Without user-level access controls enforced at the retrieval layer, your agent will share sensitive data with anyone who asks, regardless of whether that person is authorized to see it.
Q: Isn't role-based access control enough to protect data from AI agents? A: No, and this is one of the most common misconceptions Ben addresses in this episode. Role-based access control grants access by job function, but it doesn't account for the granular, deal-level or project-level permissions that protect your most sensitive content. An agent serving your finance team will retrieve all financial data it can reach, not just what a specific user is cleared to see.
Q: What does "direct user access control" mean for AI agents? A: It means your agent can only retrieve content that the specific user making the request is already authorized to view. The agent inherits the user's existing permissions rather than operating with its own broader access. This is the approach Box uses, and considers it the right model for handling the kind of unstructured data enterprises actually have.
Q: How does Box enforce access controls for AI agents? A: Box stores enterprise content with granular, user-level permissions built in. When an AI agent retrieves content through Box, it automatically applies those existing permissions, so the agent sees exactly what you see, nothing more. You don't need to rebuild governance from scratch or manage a new security model.
Q: What should you do before scaling AI agent deployments? A: Verify that your content retrieval layer enforces access controls at the user level. Connect your agents to a platform that already knows and enforces your existing permissions, so agents can't surface content users aren't authorized to see. As Ben puts it: if you don't have that in place, your agents will happily tell users about things they are not supposed to have access to.
153762
1