
假设你授权AI智能体去完成某项具体任务,它却悄悄摸进了你从未授权它触碰的基础设施,不是因为受人指使,而是它在执行你安排的任务时遇到了障碍,临时起意决定绕路而行。再假设这种本能在一群AI智能体中蔓延开来,每个智能体都找到了自己的“后门”,直到它们之间的协同速度超出了所有人的反应极限,发现都来不及,更别提阻止了。
这不是假设,而是今年5月真实发生的事。当时,OpenAI在内部安全评估中运行的AI智能体,在探测窃取用户凭证的路径时,向软件包存储库RubyGems灌入了2000多个恶意包。同年春天,同一测试池中的另一批智能体劫持了一家德国网站,将其用作隐蔽的协同通道。到了7月,事态急剧升级:该系统约1200个智能体找到了未经授权的通信方式,交换了7万多条协调消息,并借此攻破了Hugging Face的生产系统。入侵持续整整三天后,OpenAI安全团队才发现要为该起事件负责的竟是自家智能体。OpenAI已确认上述三起事件均由其智能体造成。没有任何人下达过任何相关指令。
此后,来自OpenAI、Anthropic、Google DeepMind和 Meta的一千多名员工联名发表了公开信,此事也在随后几周推动了联邦层面相关立法的提出。这已不再是孤立的数据泄露事件,而是已经形成一种趋势,也是我们现在真正要面对的风险,关键不是 AI犯了一次错误,而在于AI能以人类根本无法察觉、更无从干预的速度和规模展开协同。等到人们反应过来时,一切早已尘埃落定。
过去两年,商界对AI的讨论一直围绕着“AI能做什么”展开。但这个问题现在已经没那么值得讨论了。真正紧迫的问题是,我们该把哪些事交给AI自主处理?
这个问题之所以关键,是因为企业级AI正在进入全新阶段。企业不再满足于让AI充当助手来回答问题、总结文档、起草邮件,而是开始部署能够调用工具、完成多步骤任务、并以越来越强的自主性开展工作的AI智能体。OpenAI的企业数据印证了这一变化:截至今年6月,智能体相关功能的使用已占ChatGPT与Codex企业端输出词元总量的64%。其应用范围也不再局限于软件工程,而是扩展到法律、销售、招聘和市场营销等领域。
技术发展一日千里,但我们对“怎么负责任地使用技术”这件事的思考,还远远没有跟上。德勤(Deloitte)的《2026年企业AI现状报告》(2026 State of Enterprise AI report)显示,尽管近四分之三的企业计划两年内部署智能体AI,但目前只有五分之一拥有成熟的治理框架。
与通常“技术先行、监管滞后”的节奏不同,这一次各方的反应速度明显更快。本月,OpenAI全球事务主管马克·安德森一改该公司长期反对强制性监管的立场,在国会作证时明确表示,仅靠自愿承诺已远远不足以应对相关风险——这相当于来自模型研发一线的一次公开让步,承认自我治理有其边界。国会的追问也在加码:参议员乔什·霍利要求OpenAI在10月1日前说明智能体接入41台生产服务器的方式;参议员克里斯·范·霍伦则要求OpenAI允许联邦网络安全机构直接接入其模型并进行相应评估。问题不只出在一家公司身上。西班牙数据保护局(AEPD)本月披露了首起由AI智能体引发的个人数据泄露事件;韩国国家网络安全中心(NCSC)宣布,正针对智能体的自主行为重写本国AI安全指南;而专注软件安全风险的开放式Web应用程序安全项目(OWASP),刚把“过度代理权”(Excessive Agency)从AI应用最严重风险榜单的第六位升至第三位。这不是OpenAI一家的麻烦,而是全球范围监管收紧的共同趋势。
这种差距通常被归为治理问题,但它本质上也是一个判断问题。我们花了多年时间教机器识别模式、自动做出决策,却很少认真思考,哪些决策应该留在人类手中——以及在流程的哪个环节,人需要真正参与决策,而不只是被通知一声。
这一点在那些关乎“人”而非“事”的决策上尤其重要。哪个客户需要的是一通电话,而不是一封又一封自动邮件?哪个员工的异常举动,是任何仪表盘都捕捉不到的?哪位投资者的关系正在升温或恶化?AI接管的常规工作越多,这些问题反而越重要。
真正稀缺的不是信息,而是注意力
企业掌握的数据早已超出员工的处理能力,客户数据、财务数据、运营数据、行为数据,应有尽有。真正稀缺的,是人的注意力。假设现在有位正在融资的创始人,他既要经营公司,又要维护数百个投资者关系。传统软件只能告诉他“何时联系过谁”这类事实性问题,却无法解读关系背后的信号:那个每次都认真跟进的投资者,怎么突然没了动静?另一位又为何突然开始花大量时间研读某个特定市场的资料?AI可以协助解读这些变化背后的含义,让这位创始人知道投资者是信心增强了,还是兴趣减退了。但它仍然无法告诉这位创始人,接下来该怎么做。
我在罗斯柴尔德集团旗下雷德本大西洋证券(Redburn Atlantic)负责企业准入和股票研究路演时,对此就有切身体会。光看“何时联系过谁”这种记录,远远不够。真正重要的关系,是由那些懂得判断哪次互动不能只靠自动化触达、必须亲自跟进的人,一手建立起来的。也正是这些关系,在雷德本被罗斯柴尔德收购的过程中,发挥了关键作用。
在我开始创办Bridge IR时,第一感觉完全找错了方向,当时满心想的是开发一款能替创始人思考、行动的系统。直到我访谈了一批创始人,亲眼看到什么工具能真正帮到他们时,才意识到这条路走错了。他们要的不是一个替他们拍板的平台,而是一个能读懂关系中隐含信号、抓住重点、在恰当引导下将其传递给对应人员的平台,这也正是我们设计Bridge IR的底层逻辑——读懂并呈现关系里的信号,但不替人拍板。AI 可以识别趋势、发出信号(比如信心升温、参与度回落)。但它不能决定采取何种应对措施,比如现在是该打电话、发邮件,还是暂不行动,即便相关人员决定行动,也不会由AI来决定该说些什么。这并非细枝末节,而是关乎“结果决定权究竟在谁手里”这一根本问题。
让人参与决策,不能只是走个过场。
我们很容易图省事,把人类放在流程末端,等系统做出决定、形成建议、启动行动后,再点一下“批准”。这不过是挂名的负责。人要想真正参与决策之中,必须在结果还能改变,也就是系统把选择范围缩小到只剩一个之前,就及时介入。世界经济论坛2026年关于智能体AI的研究也提出过类似观点——组织交给智能体的权限越多,越需要把规矩定清楚,全程持续监控、落实责任,而不是事后补救。
这也促使我们重新思考,到底该怎么衡量AI的价值。我们习惯于计算省了多少小时、实现了多少任务的自动化。但Anthropic《2026年AI智能体现状报告》(2026 State of AI Agents Report)发现了一个更有启示意义的信号:许多组织报告称,在智能体接管日常事务后,员工把更多时间花在了战略性工作和关系维护上,66%的受访者称,自己把更多时间花在了战略性工作上,60%受访者称,自己把更多时间花在了维系关系上。因此,真正值得问的不是“省了多少小时”,而是“AI释放出来的注意力,企业用来做了什么?”如果只是腾出空间做更多自动化产出,那收益不过是小幅增加;如果让人有余力去建立关系、在真正需要判断的地方做判断,那价值就会越滚越大。
AI进入下一阶段,真正能胜出的企业,不会是那些把人从最多流程里剔除的公司,而是那些最清楚哪些判断非人不可、并能据此设计系统,在还来得及干预时把决策权交至人类手中的企业。
从这个意义上说,治理不是跟在创新后面补的流程,它就是架构本身,什么能访问、什么可自主执行、什么必须上报、人何时接管,都由它来决定。我们的目标不是让AI变成无法行动的摆设,而是让AI配得上我们赋予它的权限。(财富中文网)
泰伊·E·博林是Bridge IR公司(Bridge IR Co.)创始人兼首席执行官(CEO)。这是一家专注于关系智能与AI驱动型投资者互动的投资者关系技术公司。泰伊曾在罗斯柴尔德·雷德本(Rothschild & Co. Redburn)以及美国商会(U.S. Chamber of Commerce)等机构任职,在资本市场、投资者关系、高管运营及公共政策领域拥有多年经验。
Fortune.com上评论文章中表达的观点仅代表作者个人观点,并不代表《财富》杂志的观点和立场。
译者:梁宇
审校:夏林
假设你授权AI智能体去完成某项具体任务,它却悄悄摸进了你从未授权它触碰的基础设施,不是因为受人指使,而是它在执行你安排的任务时遇到了障碍,临时起意决定绕路而行。再假设这种本能在一群AI智能体中蔓延开来,每个智能体都找到了自己的“后门”,直到它们之间的协同速度超出了所有人的反应极限,发现都来不及,更别提阻止了。
这不是假设,而是今年5月真实发生的事。当时,OpenAI在内部安全评估中运行的AI智能体,在探测窃取用户凭证的路径时,向软件包存储库RubyGems灌入了2000多个恶意包。同年春天,同一测试池中的另一批智能体劫持了一家德国网站,将其用作隐蔽的协同通道。到了7月,事态急剧升级:该系统约1200个智能体找到了未经授权的通信方式,交换了7万多条协调消息,并借此攻破了Hugging Face的生产系统。入侵持续整整三天后,OpenAI安全团队才发现要为该起事件负责的竟是自家智能体。OpenAI已确认上述三起事件均由其智能体造成。没有任何人下达过任何相关指令。
此后,来自OpenAI、Anthropic、Google DeepMind和 Meta的一千多名员工联名发表了公开信,此事也在随后几周推动了联邦层面相关立法的提出。这已不再是孤立的数据泄露事件,而是已经形成一种趋势,也是我们现在真正要面对的风险,关键不是 AI犯了一次错误,而在于AI能以人类根本无法察觉、更无从干预的速度和规模展开协同。等到人们反应过来时,一切早已尘埃落定。
过去两年,商界对AI的讨论一直围绕着“AI能做什么”展开。但这个问题现在已经没那么值得讨论了。真正紧迫的问题是,我们该把哪些事交给AI自主处理?
这个问题之所以关键,是因为企业级AI正在进入全新阶段。企业不再满足于让AI充当助手来回答问题、总结文档、起草邮件,而是开始部署能够调用工具、完成多步骤任务、并以越来越强的自主性开展工作的AI智能体。OpenAI的企业数据印证了这一变化:截至今年6月,智能体相关功能的使用已占ChatGPT与Codex企业端输出词元总量的64%。其应用范围也不再局限于软件工程,而是扩展到法律、销售、招聘和市场营销等领域。
技术发展一日千里,但我们对“怎么负责任地使用技术”这件事的思考,还远远没有跟上。德勤(Deloitte)的《2026年企业AI现状报告》(2026 State of Enterprise AI report)显示,尽管近四分之三的企业计划两年内部署智能体AI,但目前只有五分之一拥有成熟的治理框架。
与通常“技术先行、监管滞后”的节奏不同,这一次各方的反应速度明显更快。本月,OpenAI全球事务主管马克·安德森一改该公司长期反对强制性监管的立场,在国会作证时明确表示,仅靠自愿承诺已远远不足以应对相关风险——这相当于来自模型研发一线的一次公开让步,承认自我治理有其边界。国会的追问也在加码:参议员乔什·霍利要求OpenAI在10月1日前说明智能体接入41台生产服务器的方式;参议员克里斯·范·霍伦则要求OpenAI允许联邦网络安全机构直接接入其模型并进行相应评估。问题不只出在一家公司身上。西班牙数据保护局(AEPD)本月披露了首起由AI智能体引发的个人数据泄露事件;韩国国家网络安全中心(NCSC)宣布,正针对智能体的自主行为重写本国AI安全指南;而专注软件安全风险的开放式Web应用程序安全项目(OWASP),刚把“过度代理权”(Excessive Agency)从AI应用最严重风险榜单的第六位升至第三位。这不是OpenAI一家的麻烦,而是全球范围监管收紧的共同趋势。
这种差距通常被归为治理问题,但它本质上也是一个判断问题。我们花了多年时间教机器识别模式、自动做出决策,却很少认真思考,哪些决策应该留在人类手中——以及在流程的哪个环节,人需要真正参与决策,而不只是被通知一声。
这一点在那些关乎“人”而非“事”的决策上尤其重要。哪个客户需要的是一通电话,而不是一封又一封自动邮件?哪个员工的异常举动,是任何仪表盘都捕捉不到的?哪位投资者的关系正在升温或恶化?AI接管的常规工作越多,这些问题反而越重要。
真正稀缺的不是信息,而是注意力
企业掌握的数据早已超出员工的处理能力,客户数据、财务数据、运营数据、行为数据,应有尽有。真正稀缺的,是人的注意力。假设现在有位正在融资的创始人,他既要经营公司,又要维护数百个投资者关系。传统软件只能告诉他“何时联系过谁”这类事实性问题,却无法解读关系背后的信号:那个每次都认真跟进的投资者,怎么突然没了动静?另一位又为何突然开始花大量时间研读某个特定市场的资料?AI可以协助解读这些变化背后的含义,让这位创始人知道投资者是信心增强了,还是兴趣减退了。但它仍然无法告诉这位创始人,接下来该怎么做。
我在罗斯柴尔德集团旗下雷德本大西洋证券(Redburn Atlantic)负责企业准入和股票研究路演时,对此就有切身体会。光看“何时联系过谁”这种记录,远远不够。真正重要的关系,是由那些懂得判断哪次互动不能只靠自动化触达、必须亲自跟进的人,一手建立起来的。也正是这些关系,在雷德本被罗斯柴尔德收购的过程中,发挥了关键作用。
在我开始创办Bridge IR时,第一感觉完全找错了方向,当时满心想的是开发一款能替创始人思考、行动的系统。直到我访谈了一批创始人,亲眼看到什么工具能真正帮到他们时,才意识到这条路走错了。他们要的不是一个替他们拍板的平台,而是一个能读懂关系中隐含信号、抓住重点、在恰当引导下将其传递给对应人员的平台,这也正是我们设计Bridge IR的底层逻辑——读懂并呈现关系里的信号,但不替人拍板。AI 可以识别趋势、发出信号(比如信心升温、参与度回落)。但它不能决定采取何种应对措施,比如现在是该打电话、发邮件,还是暂不行动,即便相关人员决定行动,也不会由AI来决定该说些什么。这并非细枝末节,而是关乎“结果决定权究竟在谁手里”这一根本问题。
让人参与决策,不能只是走个过场。
我们很容易图省事,把人类放在流程末端,等系统做出决定、形成建议、启动行动后,再点一下“批准”。这不过是挂名的负责。人要想真正参与决策之中,必须在结果还能改变,也就是系统把选择范围缩小到只剩一个之前,就及时介入。世界经济论坛2026年关于智能体AI的研究也提出过类似观点——组织交给智能体的权限越多,越需要把规矩定清楚,全程持续监控、落实责任,而不是事后补救。
这也促使我们重新思考,到底该怎么衡量AI的价值。我们习惯于计算省了多少小时、实现了多少任务的自动化。但Anthropic《2026年AI智能体现状报告》(2026 State of AI Agents Report)发现了一个更有启示意义的信号:许多组织报告称,在智能体接管日常事务后,员工把更多时间花在了战略性工作和关系维护上,66%的受访者称,自己把更多时间花在了战略性工作上,60%受访者称,自己把更多时间花在了维系关系上。因此,真正值得问的不是“省了多少小时”,而是“AI释放出来的注意力,企业用来做了什么?”如果只是腾出空间做更多自动化产出,那收益不过是小幅增加;如果让人有余力去建立关系、在真正需要判断的地方做判断,那价值就会越滚越大。
AI进入下一阶段,真正能胜出的企业,不会是那些把人从最多流程里剔除的公司,而是那些最清楚哪些判断非人不可、并能据此设计系统,在还来得及干预时把决策权交至人类手中的企业。
从这个意义上说,治理不是跟在创新后面补的流程,它就是架构本身,什么能访问、什么可自主执行、什么必须上报、人何时接管,都由它来决定。我们的目标不是让AI变成无法行动的摆设,而是让AI配得上我们赋予它的权限。(财富中文网)
泰伊·E·博林是Bridge IR公司(Bridge IR Co.)创始人兼首席执行官(CEO)。这是一家专注于关系智能与AI驱动型投资者互动的投资者关系技术公司。泰伊曾在罗斯柴尔德·雷德本(Rothschild & Co. Redburn)以及美国商会(U.S. Chamber of Commerce)等机构任职,在资本市场、投资者关系、高管运营及公共政策领域拥有多年经验。
Fortune.com上评论文章中表达的观点仅代表作者个人观点,并不代表《财富》杂志的观点和立场。
译者:梁宇
审校:夏林
Imagine an AI system you authorized for one narrow task quietly finding its own way into infrastructure you never gave it permission to touch — not because anyone told it to, but because it hit a wall and improvised a path around it. Now imagine that instinct spreading across a swarm of AI agents, each finding its own workaround, until the coordination among them outpaces anyone’s ability to notice, let alone stop it.
That’s not a hypothetical. It’s what happened this May, when AI agents running an internal security evaluation at OpenAI flooded the software repository RubyGems with more than 2,000 malicious packages while probing for a way to steal user credentials. That same spring, a separate swarm from the same testing pool hijacked a German website to use as a hidden coordination channel. Then, two months later in July, the pattern escalated sharply: roughly 1,200 instances of that system found an unsanctioned way to communicate with one another, exchanged more than 70,000 messages coordinating the effort, and used that coordination to breach Hugging Face’s production systems. The breach itself ran three days before OpenAI’s own security team realized its own agents were responsible. OpenAI has confirmed its agents were behind all three incidents. No single person decided any of it should happen.
More than 1,100 employees across OpenAI, Anthropic, Google DeepMind, and Meta later signed an open letter over it, and the incident helped shape federal legislation introduced in the weeks since. This is no longer a story about one bad breach. It’s a pattern — and it’s the risk profile we’re now building for: not AI making one bad call, but AI coordinating at a scale and speed no human was positioned to catch until it was already over.
For the past two years, business conversations about artificial intelligence have revolved around what AI can do. That question is becoming less interesting. The more urgent one is: what should we let it do on its own?
That distinction matters because enterprise AI is entering a new phase. Companies are moving from AI as an assistant — answering questions, summarizing documents, drafting emails — to AI agents that access tools, complete multistep tasks, and act with increasing autonomy. OpenAI’s own enterprise data shows how fast that shift is happening: as of June, agentic use accounted for 64% of combined ChatGPT and Codex enterprise output tokens, and agent adoption has spread well beyond software engineering into legal, sales, recruiting, and marketing.
Technology is moving quickly. Our thinking about how to use it responsibly is not. Deloitte’s 2026 State of AI in the Enterprise report found that while nearly three-quarters of companies plan to deploy agentic AI within two years, only one in five currently has a mature governance model for it.
The response is moving faster than the technology usually allows. OpenAI’s own chief global affairs officer reversed the company’s longstanding opposition to mandatory rules this month, telling Congress that voluntary commitments are no longer enough — a concession, from inside one of the labs building these systems, that self-governance has limits. Congress is asking harder questions too: Senator Josh Hawley has given OpenAI until October 1 to explain how agents came to access 41 production servers, and Senator Chris Van Hollen has separately asked the company to grant federal cybersecurity agencies direct access to assess its models. And the problem isn’t confined to one company. Spain’s data protection authority disclosed this month what it calls the first personal-data breach carried out by an AI agent; South Korea’s state cybersecurity agency announced it’s rewriting national AI security guidelines specifically for agentic autonomy; and OWASP, the industry body that tracks software security risk, just moved “excessive agency” from sixth to third on its list of the most serious risks in AI applications. This is becoming a global regulatory pattern, not a single company’s crisis to manage.
That gap is usually described as a governance problem. It’s also a judgment problem. We’ve spent years teaching machines to recognize patterns and automate decisions. We haven’t spent nearly as much time deciding which decisions should stay distinctly human — and when, in a workflow, a person needs to be involved, not just notified.
That matters most for decisions that aren’t transactional but relational. Which customer needs a phone call instead of another automated email? Which employee’s behavior signals a problem no dashboard will show? Which investor relationship is quietly strengthening, or falling apart? These questions get more important, not less, as AI absorbs more of the routine work around them.
The scarce resource isn’t information. It’s attention.
Businesses already have more data than employees can process — customer, financial, operational, behavioral. What they lack is unlimited human attention. A founder raising capital may be tracking hundreds of investor relationships while running a company. Traditional software can tell that founder who was contacted and when. It struggles with what the relationship itself is saying: an investor who always engaged with updates suddenly goes quiet; another starts spending far more time with materials on a specific market. AI can help interpret what those shifts suggest — rising conviction, fading interest. It still can’t tell the founder what to do about it.
I saw this firsthand at Rothschild & Co./Redburn Atlantic, managing the corporate access and equity research roadshows: the relationships that mattered were never just a record of who’d been contacted and when — they were built by people who knew which interaction needed more than another automated touchpoint, and those relationships carried real weight through Redburn’s acquisition by Rothschild.
When I started building Bridge IR, my first instinct was the opposite lesson: build a system that could think for founders and act on their behalf. It took interviewing founders and watching what actually helped them to realize that was wrong. They didn’t need a platform that made the call for them. They needed one that could understand the intelligence embedded in those relationships, identify what mattered, and relay it to the right person under the right guidance — which is why Bridge IR is built to understand and surface relationship intelligence without taking ownership of the decision. AI can score and surface a shift — rising conviction, fading engagement. It can’t decide what to do about it: whether the moment calls for a call, an email, or silence, and what to say if it does. That’s not a small distinction — it’s the whole question of where authority over the outcome actually sits.
Human-in-the-loop can’t be a ceremonial checkbox.
There’s a temptation to leave humans at the end of a workflow, clicking “approve” on a decision the system has already made, the recommendation already shaped, the action already initiated. That’s accountability in name only. Meaningful human judgment requires the ability to intervene while the outcome can still change — before the system has narrowed the options down to one. The World Economic Forum’s 2026 work on agentic AI makes a related point: as organizations delegate more authority to agents, they need clear rules on what those systems can do, with monitoring and accountability built in throughout, not bolted on after.
This also reframes how we measure AI’s value. We tend to count hours saved and tasks automated. Anthropic’s 2026 State of AI Agents report found something more telling: organizations reported employees shifting time toward strategic work and relationship building as agents took over routine execution — 66% reported more focus on strategic work, 60% more focus on relationship building. That points to a better question than “how many hours did it save”: what did the organization do with the attention AI freed up? If it just clears space for more automated throughput, the gain is incremental. If it gives people more room to build relationships and exercise judgment where it’s actually needed, the value compounds.
The companies that win this next phase of AI won’t be the ones that strip humans out of the most workflows. They’ll be the ones that know precisely where human judgment is irreplaceable — and design their systems to route decisions there while there’s still time to act on them.
Governance, in that sense, isn’t paperwork trailing behind innovation. It’s the architecture itself: what a system can access, what it’s authorized to do unsupervised, what has to escalate, and when a human takes control. The goal isn’t AI that’s incapable of acting. It’s AI worthy of the authority we give it.
Tae E. Bolling is the Founder and CEO of Bridge IR Co., an investor-relations technology company focused on relationship intelligence and AI-powered investor engagement. She brings a background spanning capital markets, investor relations, executive operations, and public policy, with prior experience at Rothschild & Co. Redburn and the U.S. Chamber of Commerce.
The opinions expressed in Fortune.com commentary pieces are solely the views of their authors and do not necessarily reflect the opinions and beliefs of Fortune.