17 分钟12要素智能体:可靠LLM应用的模式——Dex Horthy,HumanLayer
学会设计能够暂停、恢复、请求人工判断,并将业务状态与模型猜测分离的AI工作流。
IBM Technology. Jeff Crume通过白板讲解了生成式AI引入风险的三个环节——数据、模型和使用方式——以及各环节应采用的良好管控措施。这有助于理解文章的观点:“务必小心”并不足够;作为员工,你需要判断自己实际面对的是哪一类风险。
请将本视频视为概念性指导。在权限、保留政策、日志记录和人工审核边界明确之前,不要使用真实公司数据。
你可以说出生成式AI在工作中增加的三个风险面——数据、模型和使用方式——并说明每个风险面所需的管控措施。
无——面向员工,而非安全工程师。
最后审核:2026年5月18日
通过相同的视频学习路径,继续观看下一个精选配套视频。
精选的外部课程,帮助您更深入地了解该主题。
AWS Training and Certification
A cloud-vendor-specific complement to the Macquarie specialization: AWS's own Generative AI Security Scoping Matrix, OWASP Top 10 for LLMs, and MITRE ATLAS, walked through governance, legal, and compliance controls for five different AI deployment scopes — from consumer apps to self-trained models. Not GDPR-specific, but a genuinely practical advanced pick for teams whose AI workloads actually run on AWS and need concrete data-governance and compliance controls, not just theory.
Macquarie University Cyber Security Hub faculty
The advanced, most explicitly on-target answer to our GDPR × AI gap: a three-course specialization from Macquarie University's Cyber Security Hub that goes from GDPR/CCPA fundamentals and privacy-by-design, through privacy impact assessments, to a dedicated third course on securing AI systems against adversarial attacks and model leakage. Genuinely bridges 'GDPR compliance' and 'AI security' rather than treating them as separate topics.
CyberSuite
少有的真正为法案适用对象编写的《人工智能法案》课程:它面向采用AI的中小企业,而不是开发AI的实验室。课程托管在欧盟委员会自有的技能平台上,将法律层面的角色、义务和风险分类,与大多数合规课程忽略的安全问题(提示词注入、数据泄露、供应商尽职调查)结合起来。对于部署AI的爱沙尼亚中小企业,这是切实可行的起点。