[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"article-project-glasswing-ai-security-layer-zh":3,"article-related-project-glasswing-ai-security-layer-zh":30,"series-industry-f512305d-cbc8-4d33-97eb-b7e68b59a4d8":75},{"id":4,"slug":5,"title":6,"content":7,"summary":8,"source":9,"source_url":10,"author":11,"image_url":12,"cover_image":12,"category":13,"language":14,"translated_content":11,"related_article_id":15,"keywords":16,"key_takeaways":22,"views":26,"created_at":27,"published_at":28,"topic_cluster_id":29},"f512305d-cbc8-4d33-97eb-b7e68b59a4d8","project-glasswing-ai-security-layer-zh","Glasswing 把 AI 變成安全閘門","\u003Cp data-speakable=\"summary\">以前把 AI 當功能塞進流程，現在把它放進安全閘門裡做初步審查。\u003C\u002Fp>\u003Cp>我最近一直在看各種「trusted AI」的說法，老實講，很多都很像把模型硬塞進工作流，然後貼一張治理標籤就算交代了。我用過幾次之後只覺得卡：模型很會講，流程很順，最後卻沒人說得清楚它到底影響了哪個決定。這種東西拿來做 demo 可以，拿來碰金融軟體，我心裡會先亮紅燈。\u003C\u002Fp>\u003Cp>這次真正讓我停下來看的，是 FIS 和 Anthropic 的 \u003Ca href=\"https:\u002F\u002Fwww.businesswire.com\u002Fnews\u002Fhome\u002F20260716621725\u002Fen\u002FFIS-and-Anthropic-Extend-Partnership-on-Trusted-AI-for-Financial-Services\">Project Glasswing\u003C\u002Fa>。FIS 把 \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002F\">Anthropic\u003C\u002Fa> 的 \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Fnews\u002Fclaude-3-5-sonnet\">Mythos 5\u003C\u002Fa> 放進它的安全計畫，講法不是「AI 幫你做一切」，而是「AI 多一層控制點」。這個 framing 比那種空泛的 \u003Ca href=\"\u002Ftag\u002Fenterprise-ai\">enterprise AI\u003C\u002Fa> 廢話實在多了。\u003C\u002Fp>\u003Ch2>把 AI 當閘門，別把它當功能\u003C\u002Fh2>\u003Cblockquote>Through Project Glasswing, FIS is putting Mythos 5, Anthropic’s most advanced frontier model, to work as an additional layer within its security program.\u003C\u002Fblockquote>\u003Cp>翻譯一下就是：模型不是產品本體，它是審查路徑的一部分。這句話很重要，因為我看過太多團隊把 AI 當成快捷鍵，結果把風險也一起加速送進 production。先過度信任，出事後再怪模型不夠聰明，這套我真的看膩了。\u003C\u002Fp>\n\u003Cfigure class=\"my-6\">\u003Cimg src=\"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784705616080-tni1.png\" alt=\"Glasswing 把 AI 變成安全閘門\" class=\"rounded-xl w-full\" loading=\"lazy\" \u002F>\u003C\u002Ffigure>\n\u003Cp>我之前在內部工具審查裡就碰過這種事。模型拿來做風險分類、程式摘要、異常標記，確實有用；但如果你讓它單獨站在變更和上線之間，那就是在等 postmortem。FIS 的說法比較對路：additional layer。Layer 才是重點，oracle 只是幻覺。\u003C\u002Fp>\u003Cp>實操上，我會把 AI 放在人工審查前面，不是取代人工。讓它先做 triage、score、摘要、標記可疑點，再把最終判斷交給人。只要流程沒辦法清楚記錄「模型怎麼影響最後決定」，這流程就還不夠硬，根本不適合碰受監管的工作。\u003C\u002Fp>\u003Cul>\u003Cli>讓模型先找異常，不要讓它直接放行。\u003C\u002Fli>\u003Cli>凡是牽涉客戶資料、權限、金流的操作，都保留人工簽核。\u003C\u002Fli>\u003Cli>把模型輸出和最終 reviewer 決策一起記錄，方便之後回頭查 drift。\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>所謂 trusted AI，先把信任邊界畫出來\u003C\u002Fh2>\u003Cp>FIS 和 \u003Ca href=\"\u002Ftag\u002Fanthropic\">Anthropic\u003C\u002Fa> 都在講 trusted AI，但我比較在意的是邊界。到底誰信任？信任什麼任務？在什麼限制下？如果這三件事沒講清楚，trusted 只是裝飾詞，聽起來很正經，實際上什麼都沒定義。\u003C\u002Fp>\u003Cp>Project Glasswing 有意思的地方，是它把重心放在 foundational software 的建構者和維護者身上。這代表 trust boundary 不只是 end-user app，而是更底層的基礎設施層。金融服務裡最髒、也最不能亂碰的東西，通常就是權限、稽核軌跡、政策執行、release control，還有那些平常沒人想起來、出事時卻最致命的系統。\u003C\u002Fp>\u003Cp>我看過團隊想把 AI 直接塞進這些層，結果翻車，原因通常不是模型不夠強，是他們根本沒先寫清楚模型能碰什麼。模型能看哪些資料？只能建議還是可以標記？能不能碰 production logs？能不能看 secrets？這些問題如果你不能一口氣答完，代表你還沒畫好邊界。\u003C\u002Fp>\u003Cp>實操上，我會先寫一頁 model policy，再把模型接進敏感流程。別寫得花俏，越普通越好。把允許的輸入、允許的輸出、升級規則、保留規則，還有每個步驟的責任人寫死，才有辦法談信任。\u003C\u002Fp>\u003Cul>\u003Cli>先縮小模型作用範圍，再談擴張。\u003C\u002Fli>\u003Cli>把 assist 和 authorize 分開，別混在一起。\u003C\u002Fli>\u003Cli>讓工程、資安、法遵都看得到這份政策，不要只給主管看。\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>Glasswing 真正在解的是基礎設施的痛\u003C\u002Fh2>\u003Cp>我覺得最值得劃線的，不是品牌名，而是這句：Project Glasswing 連結的是那些建造或維護 foundational software 的組織。這句話很直白，意思是它不是衝著寫簡報的人去的，是衝著在 plumbing 裡面幹活的人去的。\u003C\u002Fp>\n\u003Cfigure class=\"my-6\">\u003Cimg src=\"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784705621618-8iv7.png\" alt=\"Glasswing 把 AI 變成安全閘門\" class=\"rounded-xl w-full\" loading=\"lazy\" \u002F>\u003C\u002Ffigure>\n\u003Cp>這也正中我以前踩過的坑。很多團隊的 security review 永遠落在工程痛點後面，等資安進場時，架構早就被各種 shortcut 綁死了。你如果真的想讓 AI 幫忙，就得把它放到 architecture、policy、implementation 交會的地方，而不是丟到最外層做裝飾。\u003C\u002Fp>\u003Cp>把模型放近一點之後，它能幫的事情其實很土：看 dependency review、抓 config drift、掃 access-control change、整理 alert summary。這些都不性感，但安全工作本來就不是靠性感活著。大部分時間都很重複，直到突然不重複為止。\u003C\u002Fp>\u003Cp>實操上，我會先拿模型去碰最無聊的\u003Ca href=\"\u002Fnews\u002Fappearance-pointers-region-control-dits-zh\">區域\u003C\u002Fa>。先做依賴審查、設定檔漂移、權限變更、警報摘要。這些地方最能省時間，也最不需要把決策權直接交出去。\u003C\u002Fp>\u003Ch2>安全團隊要的是更快的 triage，不是信心表演\u003C\u002Fh2>\u003Cp>\u003Ca href=\"\u002Ftag\u002F企業-ai\">企業 AI\u003C\u002Fa> 很愛把模型說得像更會做事的員工，我對這種講法很煩。員工有責任、有\u003Ca href=\"\u002Fnews\u002Fgear-cuts-copying-long-context-reasoning-zh\">上下文\u003C\u002Fa>、也有判斷；模型只有模式匹配和失敗模式。把這兩者混為一談，最後就會變成 confidence theater，看起來很安心，實際上只是把風險包裝得更漂亮。\u003C\u002Fp>\u003Cp>FIS 在 Project Glasswing 裡的說法比較務實：把 Mythos 5 當成安全計畫裡的 additional layer。這聽起來就像 triage、filtering、review assistance。很好，這才是現在模型真的能幹的事。它縮短的是「發現怪事」到「有能力的人開始看」之間的時間。\u003C\u002Fp>\u003Cp>我自己會把這當成 AI 在安全場景的核心 KPI：不是某個抽象的 accuracy，而是 time-to-human-attention。模型如果能讓每次 incident review 少等 30 分鐘，那就是實打實的價值；如果只是把錯誤決策寫得更漂亮，那只是壁紙。\u003C\u002Fp>\u003Cp>實操上，別先量模型本身，先量流程。看 suspicious event 多久能被\u003Ca href=\"\u002Fnews\u002Fcoderescue-budget-calibrated-recovery-routing-zh\">路由\u003C\u002Fa>出去、模型標記有多少被接受、又有多少被人推翻。如果模型只是多了一層步驟，卻沒有縮短 review time，那它根本沒幫上忙。\u003C\u002Fp>\u003Cul>\u003Cli>量流程時間，不要只量模型分數。\u003C\u002Fli>\u003Cli>追蹤 flag 被接受與被覆寫的比例。\u003C\u002Fli>\u003Cli>如果模型增加步驟卻沒減少等待時間，就該停。\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>金融業一直把 AI 拉進控制系統，原因很現實\u003C\u002Fh2>\u003Cp>金融服務不能隨便來。每一個偷懶的 shortcut，最後都可能變成 compliance issue、fraud issue，或是 customer trust issue。這也是為什麼我特別注意 FIS 這種公司怎麼談 \u003Ca href=\"\u002Ftag\u002Fai-security\">AI security\u003C\u002Fa>，而不是拿 AI 來做行銷或客服。門檻本來就不一樣。\u003C\u002Fp>\u003Cp>Anthropic 也值得看，因為它給人的感覺比較像 controlled deployment，而不是放任式實驗。這不代表系統就安全，當然沒有；但至少起手式不是「我們先把模型接到所有東西上再說」。這種克制，很多團隊其實缺很大。\u003C\u002Fp>\u003Cp>我看過太多團隊買了一個模型，接進流程，然後才發現沒人知道怎麼 audit output。這在一般產品可能還能拖，在金融業就不是小事，這幾乎就是問題本身。\u003C\u002Fp>\u003Cp>實操上，只要你在受監管環境工作，就把每個 AI integration 當成新的 control surface。先問誰擁有、誰稽核、誰能關閉、模型 hallucinate 時怎麼辦。答案如果還很模糊，就先不要往下接。\u003C\u002Fp>\u003Ch2>我會抄的，是操作模型，不是包裝詞\u003C\u002Fh2>\u003Cp>Project Glasswing 這名字聽起來很漂亮，這我承認。但真正有用的是背後那個 operating model：AI 當安全層、綁在 foundational software 上、角色窄、責任清楚。這才是可以偷走的部分，而且不用跟著整套 vendor 敘事一起買單。\u003C\u002Fp>\u003Cp>如果是我自己重做，我會直接跳過那些大話。把模型放進 review lane，限制它的 authority，輸出要能 audit，最後還是人負責。這不性感，但這就是避免 AI 變成另一個沒人敢接手的黑盒子的方式。\u003C\u002Fp>\u003Cp>原始內容沒有丟一堆性能數字，這點我反而覺得好。沒有 context 的數字，最容易拿來養出糟糕的 enterprise 故事。這裡真正值得學的是部署形狀：是一層額外控制，不是替代品；是一個 security program，不是一場 demo。\u003C\u002Fp>\u003Ch2>可抄的模板\u003C\u002Fh2>\u003Cpre>\u003Ccode># AI Security Layer Operating Model\n\n## Purpose\nUse an AI model as an additional review layer inside a security program.\nThe model assists with triage, summarization, and anomaly spotting.\nIt does not approve releases, grant access, or replace human review.\n\n## Allowed inputs\n- Security alerts\n- Config diffs\n- Dependency metadata\n- Access logs with approved redaction\n- Policy text and control mappings\n\n## Disallowed inputs\n- Secrets, private keys, or raw credentials\n- Unredacted customer data\n- Production data outside the approved review scope\n- Any data not covered by the current retention policy\n\n## Allowed outputs\n- Risk summaries\n- Triage labels\n- Anomaly flags\n- Suggested next-review actions\n- Human-readable explanations for reviewers\n\n## Human control points\n1. Model generates a review packet.\n2. Human reviewer inspects the packet.\n3. Reviewer accepts, rejects, or escalates.\n4. Final action is recorded with reviewer identity.\n5. Model output is stored for audit comparison.\n\n## Policy rules\n- The model may recommend, but never authorize.\n- Any high-risk change requires human sign-off.\n- Any uncertain output is treated as a flag, not a decision.\n- Model access is reviewed on a fixed schedule.\n- Output quality is checked against incident outcomes.\n\n## Audit fields\n- Request ID\n- Input category\n- Model version\n- Reviewer ID\n- Model recommendation\n- Final human decision\n- Override reason\n- Timestamp\n\n## Rollout checklist\n- [ ] Define scope\n- [ ] Approve data boundaries\n- [ ] Assign human owner\n- [ ] Add logging\n- [ ] Add override path\n- [ ] Test with low-risk cases first\n- [ ] Review false positives and false negatives\n- [ ] Document disable procedure\n\n## Example usage\n\"Review these changes for policy drift, suspicious access patterns, and dependency risk.\nReturn a short summary, flags, and the exact reason each item was flagged.\nDo not approve or reject the change.\"\n\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp>這份模板你可以直接拿去改成自己的版本。把控制欄位、稽核欄位、允許輸入換成你們的環境語言就好。若你在金融、保險、支付這種地方工作，我會先把模型鎖在 review lane，等你真的證明它可稽核，再談擴權。\u003C\u002Fp>\u003Cp>來源是 \u003Ca href=\"https:\u002F\u002Fwww.businesswire.com\u002Fnews\u002Fhome\u002F20260716621725\u002Fen\u002FFIS-and-Anthropic-Extend-Partnership-on-Trusted-AI-for-Financial-Services\">Business Wire 的公告\u003C\u002Fa>，以及 \u003Ca href=\"https:\u002F\u002Fwww.fisglobal.com\u002F\">FIS\u003C\u002Fa>、\u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002F\">Anthropic\u003C\u002Fa> 的公開資訊。上面對 operating model 的拆解和模板化，是我根據原文自己整理出來的可抄版本。\u003C\u002Fp>","我拆 FIS 與 Anthropic 的 Project Glasswing，整理成可直接套用的 AI 安全層流程與審核模板。","www.businesswire.com","https:\u002F\u002Fwww.businesswire.com\u002Fnews\u002Fhome\u002F20260716621725\u002Fen\u002FFIS-and-Anthropic-Extend-Partnership-on-Trusted-AI-for-Financial-Services",null,"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784705616080-tni1.png","industry","zh","17c9eecf-51f4-48f2-b709-91a4c83e6711",[17,18,19,20,21],"AI security","financial services","model governance","trusted AI","security workflow",[23,24,25],"AI 在金融場景最適合放在審查閘門，不是直接做決策。","先畫清楚 trust boundary，再把模型接進敏感流程。","真正該量的是 triage 速度、人工覆寫率和可稽核性。",0,"2026-07-22T07:32:48.092927+00:00","2026-07-22T07:32:48.081+00:00","caa87b65-9bbc-46fe-bba8-4f4158dd2d8b",{"tags":31,"relatedLang":34,"relatedPosts":38},[32],{"name":17,"slug":33},"ai-security",{"id":15,"slug":35,"title":36,"language":37},"project-glasswing-ai-security-layer-en","Project Glasswing turns AI into a security layer","en",[39,45,51,57,63,69],{"id":40,"slug":41,"title":42,"cover_image":43,"image_url":43,"created_at":44,"category":13},"d45f7840-d7e0-4aa1-aa6f-5410976b9361","anthropic-ipo-ai-stocks-playbook-zh","Anthropic IPO 讓 AI 股看估值","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784637245475-mcqb.png","2026-07-21T12:33:22.563293+00:00",{"id":46,"slug":47,"title":48,"cover_image":49,"image_url":49,"created_at":50,"category":13},"d7472a4b-0e1f-4c35-b786-d4a98382ecf5","anthropic-meta-compute-dependence-zh","Anthropic 不該把算力命脈交給 Meta","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784633577100-1mxp.png","2026-07-21T11:32:21.908371+00:00",{"id":52,"slug":53,"title":54,"cover_image":55,"image_url":55,"created_at":56,"category":13},"cc1afbcc-ef0a-44a8-9483-19b69b7f8d28","mistral-robotics-model-cuts-navigation-costs-zh","Mistral 進軍機器人：5 個部署重點","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784554395648-a2pm.png","2026-07-20T13:32:23.505761+00:00",{"id":58,"slug":59,"title":60,"cover_image":61,"image_url":61,"created_at":62,"category":13},"4fca13b9-8761-428d-9eeb-42e182ff446d","mistral-missile-france-short-range-air-defense-zh","Mistral：法國短程防空主力","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784552589556-bz6r.png","2026-07-20T13:02:42.099126+00:00",{"id":64,"slug":65,"title":66,"cover_image":67,"image_url":67,"created_at":68,"category":13},"0c8276b1-80c2-4f91-9ce7-7e59fee5cb82","apple-reclaims-top-market-cap-nvidia-slips-en-zh","苹果重回全球市值第一，英伟达回落4%","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784534583716-2xct.png","2026-07-20T08:02:34.321704+00:00",{"id":70,"slug":71,"title":72,"cover_image":73,"image_url":73,"created_at":74,"category":13},"256b76bf-9688-4a39-8d99-f3033228a6c7","kimik3-ai-model-market-impact-zh","KimiK3 會先擠壓誰的價值","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1784532786358-4il6.png","2026-07-20T07:32:34.819593+00:00",[76,81,86,91,96,101,106,111,116,121],{"id":77,"slug":78,"title":79,"created_at":80},"ee073da7-28b3-4752-a319-5a501459fb87","ai-in-2026-what-actually-matters-now-zh","2026 AI 真正重要的事","2026-03-26T07:09:12.008134+00:00",{"id":82,"slug":83,"title":84,"created_at":85},"83bd1795-8548-44c9-9a7e-de50a0923f71","trump-ai-framework-power-speech-state-preemption-zh","川普 AI 框架瞄準電力、言論與州權","2026-03-26T07:12:18.695466+00:00",{"id":87,"slug":88,"title":89,"created_at":90},"ea6be18b-c903-4e54-97b7-5f7447a612e0","nvidia-gtc-2026-big-ai-announcements-zh","NVIDIA GTC 2026 重點拆解","2026-03-26T07:14:26.62638+00:00",{"id":92,"slug":93,"title":94,"created_at":95},"4bcec76f-4c36-4daa-909f-54cd702f7c93","claude-users-spreading-out-and-getting-better-zh","Claude 用戶更分散，也更會用","2026-03-26T07:22:52.325888+00:00",{"id":97,"slug":98,"title":99,"created_at":100},"bd903b15-2473-4178-9789-b7557816e535","openclaw-raises-hard-question-for-ai-models-zh","OpenClaw 逼問 AI 模型價值","2026-03-26T07:24:54.707486+00:00",{"id":102,"slug":103,"title":104,"created_at":105},"eeac6b9e-ad9d-4831-8eec-8bba3f9bca6a","gap-google-gemini-checkout-fashion-search-zh","Gap 把結帳搬進 Gemini","2026-03-26T07:28:23.937768+00:00",{"id":107,"slug":108,"title":109,"created_at":110},"0740e53f-605d-4d57-8601-c10beb126f3c","google-pushes-gemini-transition-to-march-2026-zh","Google 把 Gemini 轉換延到 2026 年 3…","2026-03-26T07:30:12.825269+00:00",{"id":112,"slug":113,"title":114,"created_at":115},"e660d801-2421-4529-8fa9-86b82b066990","metas-llama-4-benchmark-scandal-gets-worse-zh","Meta Llama 4 分數風波又擴大","2026-03-26T07:34:21.156421+00:00",{"id":117,"slug":118,"title":119,"created_at":120},"183f9e7c-e143-40bb-a6d5-67ba84a3a8bc","accenture-mistral-ai-sovereign-enterprise-deal-zh","Accenture 攜手 Mistral AI 賣主權 AI","2026-03-26T07:38:14.818906+00:00",{"id":122,"slug":123,"title":124,"created_at":125},"191d9b1b-768a-478c-978c-dd7431a38149","mistral-ai-faces-its-hardest-year-yet-zh","Mistral AI 迎來最硬的一年","2026-03-26T07:40:23.716374+00:00"]