4.35 亿美元的 Agent 安全浪潮:为什么 88% 的 Agent 试点无法投产
2026 年 4 月至 9 月的五个月里,风投向企业级 AI Agent 安全与治理公司投入了 4.35 亿美元,共 12 轮融资,其中 9 轮专注解决一个并不性感的问题:让 AI Agent 安全到可以真正在企业内跑起来。与此同时,另一组数字形成了刺眼的对照:IDC 与 Lenovo 的研究显示,88% 有 Agent 计划的企业从未投产;Gartner 预测到 2027 年底,超过 40% 的 Agentic AI 项目会被取消。
"钱押在安全与治理上"
一、钱为什么流向「安全与治理」
资本不会无缘无故地涌向枯燥的赛道。4.35 亿美元背后是一个被反复验证的结论:Agent 的技术可行性已经不是瓶颈,可治理性才是。企业不缺能演示的 Agent,缺的是敢让它碰生产数据的 Agent。当 88% 的试点卡在「投产」这道墙前,能把 Agent 安全送入生产的公司自然成了被追逐的对象。
// 1) Hard budget enforced before the call, not after the invoice.
const budget = { perTask: 2.0, perDay: 50.0, spentToday: 0 };
function beforeCall(estimateUsd) {
if (spentToday() + estimateUsd > budget.perDay) {
throw new Error("daily budget exceeded: escalate to human");
}
if (estimateUsd > budget.perTask) {
throw new Error("single task would exceed per-task cap");
}
reserve(estimateUsd); // hold it so parallel tasks cannot double-spend
}
beforeCall(0.35);二、Gartner 的两组相反预测并不矛盾
Gartner 一方面预测,到 2026 年底将有 40% 的企业应用部署任务型 AI Agent,而 2025 年这一比例还不到 5%;另一方面又预测超过 40% 的 Agentic AI 项目会在 2027 年底前被取消,原因包括成本攀升、业务价值不清与风险控制不足。两组数字放一起读就明白了:部署会大规模发生,但只有那些把风险控制做在前面的项目能活下来。这是达尔文式的筛选,不是泡沫破裂。
# 2) Permissions as machine-readable policy, not prompt wishful thinking.
POLICY = {
"agent-42": {
"tools": ["read_doc", "write_note"],
"deny": ["send_email", "delete_*"],
"max_rows_per_query": 1000,
},
}
def enforce(agent_id: str, tool: str, args: dict) -> None:
p = POLICY.get(agent_id)
if not p:
raise PermissionError("agent not registered")
if tool not in p["tools"]:
raise PermissionError(f"tool not allowed: {tool}")
for pattern in p["deny"]:
if pattern.endswith("*") and tool.startswith(pattern[:-1]):
raise PermissionError(f"explicitly denied: {tool}")三、卡在投产的真正原因
试点的死因通常是三件事:第一,成本不可预测,Agent 的 token 消耗随任务长度非线性增长,财务不敢批。第二,边界不清,没人能回答「这个 Agent 究竟被允许做什么」,所以风控一票否决。第三,证据不足,出问题时拿不出可审计的轨迹,合规部门无法签字。这三者都不是模型能力问题,而是工程与治理问题。
// 3) Evidence by default: every tool call is auditable.
function withAudit(agentId, tool, fn) {
return async (...args) => {
const started = Date.now();
let outcome = "ok";
try {
return await fn(...args);
} catch (e) {
outcome = "error:" + e.message;
throw e;
} finally {
auditLog.append({
ts: started,
agent: agentId,
tool,
durationMs: Date.now() - started,
outcome,
});
}
};
}四、把「不敢上」变成「敢上」的工程做法
对应上面三个死因,有三个动作。第一,给每个 Agent 硬预算:每任务、每日的花费上限在协议层可强制,而不只是写在应用代码里。第二,把权限写成策略:机器可读的允许清单,而不是散落在提示词里的「请不要」。第三,默认留证:每次工具调用都写审计日志并与触发轨迹绑定。下面的代码给出成本闸门、策略强制与证据留存的骨架,也对应了 Okta 调查揭示的「高管信心与实际使用之间的安全差距」。
# 4) Cost telemetry so finance can forecast, not guess.
def token_cost(usage: dict, price: dict) -> float:
return (usage["input"] * price["input"]
+ usage["output"] * price["output"]) / 1_000_000
def daily_report(events: list, price: dict) -> dict:
total = sum(token_cost(e["usage"], price) for e in events)
by_agent = {}
for e in events:
by_agent[e["agent"]] = by_agent.get(e["agent"], 0) + token_cost(e["usage"], price)
return {"total_usd": round(total, 2), "by_agent": by_agent}五、一个被低估的细节:身份
在融资主题里,「身份」出现的频率极高。原因很直白:Agent 是企业里最新的一类非人类身份,也是最没人管的一类。如果无法回答「这个 Agent 是谁、谁拥有它、它能碰什么、怎么撤销」,那么前面所有的成本闸门与策略都会在某个被泄漏的密钥面前失效。身份是治理的地基,不是可选项。
// 5) Verifiable production gate: a checklist, not a vibe.
const GATES = [
{ name: "hard-budget", check: () => budget.perDay > 0 },
{ name: "policy", check: () => Object.keys(POLICY).length > 0 },
{ name: "audit-log", check: () => auditLog.enabled === true },
{ name: "agent-identity", check: () => registry.allHaveOwners() },
{ name: "revocation", check: () => revokeLatencyMinutes() < 5 },
];
function canShipToProd() {
const failed = GATES.filter((g) => { try { return !g.check(); } catch { return true; } });
return { ok: failed.length === 0, failed: failed.map((f) => f.name) };
}六、给要立项的团队的清单
六条:第一,选一个边界清晰、ROI 可衡量的高价值场景起步,而不是「全公司铺开」。第二,从第一天就设硬预算与用量告警。第三,把权限写成可强制执行的策略,而不是提示词里的礼貌请求。第四,默认记录可审计轨迹。第五,给每个 Agent 独立、可撤销的身份。第六,把「投产」定义成一套可验证的门禁,而不是一次演示成功。4.35 亿美元告诉我们行业的钱押在哪里;88% 这个数字则告诉你,把这份功课提前做完的团队,会站在少数的那 12% 里。
"88% 卡在投产前"
"先有治理,再谈规模"
📌 常见问题 FAQ
这 4.35 亿美元指什么?
2026 年 4 月至 9 月的五个月里,风投投入企业级 AI Agent 安全与治理公司的资金总额,分布于 12 轮融资,其中 9 轮专注于让 Agent 安全进入企业生产。
为什么 88% 的 Agent 试点无法投产?
主要不是模型能力问题,而是成本不可预测、权限边界不清、缺少可审计证据这三件工程与治理问题。
Gartner 的两组预测矛盾吗?
不矛盾。一边预测到 2026 年底 40% 的企业应用会部署任务型 Agent,一边预测超过 40% 的 Agentic AI 项目会在 2027 年底前被取消,因为部署大规模发生但只有把风险控制做在前面的项目能存活。
最重要的三项工程动作是什么?
在协议层强制的硬预算、机器可读的权限策略,以及默认留存的、与触发轨迹绑定的审计日志。
为什么身份治理是地基?
因为 Agent 是最新也最缺治理的一类非人类身份。若无法回答它是谁、谁拥有、能碰什么、怎么撤销,任何成本与策略控制都会在一个泄漏的密钥面前失效。
🔧 推荐工具
📚 参考资料
- Forkast News / Yahoo Finance — Enterprise AI Agent Funding Surges to $435M in Five Months (IDC and Lenovo research; Gartner forecast)
- Okta — AI Agents at Work 2026: Securing the agentic enterprise
- Agentic AI Institute — Agentic AI Enterprise Adoption 2026: governance gap (Gartner 40% projection)
- Beamsec — How Enterprises Are Building AI Agents in 2026: From Pilots to Production