Microsoft 2026 数字防御报告建议政府 AI 采用需配套数据管控
Microsoft recommends data controls for government AI adoption
Microsoft 在 2026 数字防御报告中建议政府机构采用 AI 时配套数据管控、系统级测试与共享安全运营,在保留机构对敏感信息控制权的同时推进落地。报告提出对提示词、查询日志、智能体记忆存储和生成文本施加访问限制,并要求跨 API 运行的智能体具备可审计身份记录。Microsoft 称其内部 75% 安全事件已由自动化智能体独立处理,但账户锁定等中断在线服务的操作仍需管理员批准。
Microsoft’s 2026 Digital Defense Report recommends government AI data controls, system-level testing, and shared security operations to support adoption while retaining agency control over sensitive information.
Under the proposed model, public bodies rely on a common, AI-assisted security service while maintaining isolated data environments. Its recommendations connect AI deployment to access governance, accountable automation, and workforce development.
Terrell Cox, CVP and Deputy CISO of Customer Security at Microsoft, said: “A model may be one component, but its security also depends on the data it can reach, the tools it can use, the identities and permissions involved, and the infrastructure and services around it.”
Microsoft’s guidance for the public sector calls for evaluating AI systems in their deployment environments, including interactions among models, tools, data, and users, with monitoring continuing after deployment.
Data controls and memory protection
Managing these deployments requires tracking sanctioned tools alongside unapproved software, with access rules scaled to data classification. Prompts, query logs, agent memory stores, and generated text fall under those restrictions because each can hold confidential records.
Any agent operating across APIs or separate applications requires an auditable identity record. That entry must document who built it, what tasks it performs, and which human sponsor answers for it. Rights must stay narrow: credentials should expire on a fixed schedule, apply only to the immediate job, and face review whenever the agent’s scope changes.
The proposed controls reach individual tool calls. Microsoft recommends short-lived credentials scoped to a single invocation, authentication between agents, and measurement of how quickly access is revoked following a compromise. These measures give administrators mechanisms to attribute actions and withdraw authority.
Persistent memory needs separate safeguards. Microsoft’s red team reports that instructions embedded in external content, commonly email, have influenced memory entries subsequently retrieved as trusted context. The defensive architecture isolates memory write paths: data pulled from outside cannot write directly to instruction stores reserved for verified system rules.
Microsoft also found that agents confuse stored user habits with direct commands that govern safety rules. Human confirmation screens failed in internal testing when agents cited conflicting directives stored in memory to bypass the prompt. Instead of relying on manual clicks, the vendor advises hardcoded policy gates that block execution until a reviewer inspects the command alongside its raw operational context.
Shared operations and tenant separation
Microsoft suggests building multi-tenant security operations centres (SOCs) across government. Centralised teams of analysts and autonomous agents would monitor multiple public bodies at once, though each agency would preserve its own cloud tenant, data residency controls, and zero-trust boundary.
Central staff log in through delegated, short-term accounts restricted to the lowest necessary privileges. All event logs stay inside the agency’s own systems. Microsoft argues that pooling these resources reduces redundant software licenses and gives smaller public bodies access to specialist staff. The report supplies no data, however, verifying actual cost savings in government agencies.
Automated agents handle alert context gathering and threat summaries independently—a routine Microsoft applies to 75 percent of its internal security incidents without human dispatch. In contrast, actions that disrupt live services, including account lockouts, halt until an administrator approves them.
Official breach notifications remain entirely under manual executive control. Audit logs must record the data ingested for every action, along with the agent’s confidence score and notes from any supervisor who reviewed it.
Workforce pipelines and crisis simulations
To expand the pool of skilled defenders, Microsoft points to partnerships with community colleges, technical apprenticeships, and university-run operations facilities. The report also suggests mutual-aid response pacts that combine staff from local governments, federal cybersecurity offices, universities, and volunteer response teams.
Microsoft has started trialling similar cross-agency response structures overseas. Through its Advancing Regional Cybersecurity initiative, Microsoft ran pilot projects with Kenya’s National Computer and Cybercrime Coordination Committee before setting up exercises with Mexico’s Digital Transformation and Telecommunications Agency. Mexican agencies, technical teams, and industry regulators ran incident-response drills to test operational handoffs prior to the FIFA World Cup.
The report’s recommendations attempt to balance pooled security resources with strict departmental autonomy. Agencies share staff and automated tooling, but keep local control over data residency, memory-write rules, and final incident calls.
See also: Malaysia’s MACC expands AI use for intelligence-led investigations

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including IoT Tech Expo and the Cyber Security & Cloud Expo. Click here for more information.
AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
来源:Artificial Intelligence News · artificialintelligence-news.com