近日,全球权威研究与咨询机构Forrester正式发布《The Data Security Platforms Landscape, Q3 2026》报告,阿里云凭借数据安全中心(Data Security Center)作为Notable Vendor(代表厂商)成功入围,进一步印证了阿里云数据安全中心在“数据安全 + AI安全”融合方向上的产品完整度与技术前瞻性。
数据安全正在从“合规驱动的静态治理”进入“AI驱动的运行时治理”新阶段。企业不仅要面对日益复杂的隐私法规、数据主权与跨境流转要求,还要应对生成式AI、Copilot、Agentic AI带来的全新数据风险——AI Agent作为“新型身份”访问、生成、流转敏感数据,传统以人为中心的数据管控体系正被彻底重构。
机构观点
Forrester在报告中重新定义了数据安全平台(Data Security Platform,DSP):
"A platform that delivers a holistic approach to securing data, understanding your data and its sensitivity, surfacing and generating insights about the data and its use, providing visibility of risks and threats to the data, and implementing data-centric security controls to enforce policies for data access, use, and lifecycle management."
Forrester同时判断,本轮市场的主导趋势是 — “Agentic AI风险正推动DSP向持续评估与更广泛的控制能力演进”:围绕这一趋势,Forrester将本轮市场的核心用例锁定为regulatory compliance(合规监管),并将 agentic AI guardrails、AI copilot use、AI training、database security、data provisioning and access、data sharing and collaboration、DLP/insider risk、information governance列为八大扩展用例——这一用例地图,几乎完整覆盖了阿里云数据安全中心当前的产品能力边界。
产品及战略
阿里云认为,Agentic时代的数据安全,必须完成三个根本性转变:从“发现资产”走向“理解意图”、从“周期性评估”走向“运行时持续控制”、从“以人为身份”走向“人 + AI Agent双身份统一治理”。
在这一判断下,阿里云以数据安全中心(DSC)为核心,向上延伸至Data Security for AI(面向大模型训练、RAG 检索、推理调用全链路的数据保护),向下覆盖至云原生数据库、大数据、对象存储等数据底座,横向与Agent安全中心、Agent ID Guard、Agentic API安全、Agentic SOC、AI DeepSign等2026年新发布的Agent原生安全产品打通,为客户提供覆盖“人 - Agent - 数据”三方的端到端数据安全体系。
核心能力

数据资产洞察,覆盖多种数据源
数据安全中心提供覆盖结构化数据库、非结构化对象存储、大数据平台、lindorm向量数据库等一体化数据资产测绘,通过内置行业模板与自定义规则实现敏感数据自动发现、分类分级,并以数据资产地图、敏感数据分布、风险趋势提供业务上下文,帮助企业将DSPM的洞察真正转化为可执行的数据管控策略。
以数据为中心的全生命周期控制
面向Forrester强调的DLP/insider risk、data sharing and collaboration、database security等扩展用例,DSC提供数据脱敏、动态脱敏、访问权限收敛、UEBA数据行为异常检测、列加密等全套控制能力,与阿里云RAM、数据库/OSS管控、密钥管理服务(KMS)等产品形成协同,为客户构建“发现—评估—管控—审计-拦截/治理”的闭环。
面向AI的数据安全(Data Security for AI)
针对Agentic时代新增的AI training、AI copilot use、agentic AI guardrails三大扩展用例,DSC提供从训练前到推理后的全链路保护:
训练前,对语料库进行敏感数据识别与脱敏、去标识化;
训练与检索中,对向量库、RAG索引施加最小权限与内容过滤;
推理时,通过Prompt DLP与输出合规过滤,防止敏感信息通过AI通道外泄,落地Forrester所强调的“runtime monitoring of AI agent data access and use”。
跨云、跨境、跨监管域的合规底座
数据安全中心内置面向《数据安全法》《个人信息保护法》《数据出境安全评估办法》以及GDPR、HIPAA、PCI-DSS等的合规模板,可快速生成合规报告与审计证据链。阿里云自身持有ISO 27001/27017/27018/27701、SOC 1/2/3、PCI-DSS、C5等国内外主流认证,为客户在多监管域下运行DSC提供了坚实的平台级信任基础。
从DSPM到Data Security for AI,从传统数据资产保护到AI数据资产管控,阿里云正把“数据安全中心”从一款单点产品,升级为面向Agentic时代的数据安全基础设施。此次入选Forrester《The Data Security Platforms Landscape, Q3 2026》,既是全球机构对阿里云数据安全产品能力的又一次认可,也是阿里云数据安全中心持续投入AI时代数据安全的一个新起点。
点击“阅读原文”了解更多,欢迎访问阿里云数据安全中心产品页免费试用体验。
*Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance, For more information, read about Forrester’s objectivity(https://www.forrester.com/about-us/objectivity/) .