km.idaeo.ai · IDAEO 知識庫

🏛 Part of the "insight" topic shelf

The Gap Ledger's Next Page: Five Corporate Releases on Japan's AI-Security Supply Side in the Two Weeks Around ChillStack's Survey Release (2026-06-25 to 2026-07-09) -- the Survey's Publisher Launched an 'MCP Server Assessment' 11 Days Before Its Own Release, AI Security Inc. Issued Two Releases in 3 Days (Handling of Digital Arts Products on 2026-07-07, a CrowdStrike Partnership on 2026-07-09), GRCS Opened an AI-Driven Penetration-Test Trial Campaign From JPY 550,000 Tax Included (First 10 Companies), and First Recon AI Launched 'AI Security Runtime' Aimed at Shadow AI -- All Five Are Corporate Press Releases, This Card Has Zero Official Anchors, and the Timing Cluster Is an Editorial Observation, Not Causation

This card is the second, deepened edition extending ANK-2026-07-06-011 (the 'gap ledger' of AI security in Japan -- ChillStack's survey of 188 decision-makers at companies with AI-embedded services: guideline awareness 83.0%, reflection among the understanding layer 30.8%, pre-release measures 'sufficiently implemented' only 20.2%, about 80% self-assessing insufficiency; survey period 2026-05-25 to 2026-06-03, self-reported, a sample survey). The target card pinned down the demand side; this card turns the page: in the two weeks around the survey release (2026-06-25 to 2026-07-09), Japan's AI-security supply side produced five verifiable corporate releases -- all corporate press releases, none of which mentions the survey; this card has zero official anchors. First (CONTEXTUALIZE): the survey's publisher ChillStack itself launched an 'MCP Server Assessment' (MCP saabaa shindan) 11 days before its own survey release (on 2026-06-25; the day count is computed from the two release dates), with the release stating it expands ChillStack's AI-security assessment coverage to MCP-using environments (example inspection categories: communications, authentication/authorization, internal processing, sensitive-data handling, supply chain) -- concretizing the target card's abstract caveat that 'the surveying party has an interest': the company's business lines (Stena Expense / Safia / security assessment / AI Defense Institute) sit squarely in the gap zone its survey describes (founded November 2018, CEO Michiaki Ito, EY Innovative Startup 2026, CEO selected for Forbes 30 Under 30 Asia 2025 -- all self-reported in the company's own releases, not independently verified by this site); the concretization does not overturn the survey figures (fielded by the external provider Freeasy; the source itself asks citations credit ChillStack), and every inherited number is preserved verbatim. Second (ADD_EVIDENCE): AI Security Inc. -- the same company as the target card's F-014 (Shinjuku-ku, Tokyo; founded September 2021; 'AI Security' is its corporate name, not a generic term) -- issued two releases on the day after and 3 days after the survey release: on 2026-07-07 it began handling Digital Arts products (i-FILTER / m-FILTER), and on 2026-07-09 it announced a partnership with CrowdStrike (the CrowdStrike Falcon platform); GRCS (TSE Growth, securities code 9250) opened an 'AI-driven penetration test' trial campaign on 2026-07-08 -- special price from JPY 550,000 tax included, first 10 companies, for contracts concluded 2026-07-07 through the end of October 2026, possibly ending early if capacity is reached -- whose cost-and-effort pain narrative runs in the same direction as the survey's F-004 top reason in both layers, 'insufficient cost/resources' (an editorial juxtaposition, not causation; GRCS's release does not cite the survey; the marketing-campaign character is flagged). Third (CORROBORATE): First Recon AI (the PRTIMES publishing entity is PERSEFONI AI INC.; Japan-market rollout is driven by Persefoni Japan, a godo kaisha; CEO and co-founder Kentaro Kawamori; Japan representative Takehiro Endo) launched 'AI Security Runtime' on 2026-07-09; its release narrative -- growth of shadow AI beyond corporate oversight (vendor self-description, no quantification in the source) and conventional security products premised on protecting files, mail and networks that cannot understand AI dialogue content or user intent -- runs in the same direction as the target card's F-013 (SherLOCK's 'real management harm' mutation thesis) and F-014 (shadow AI): all three are interested supply-side vendors, so same-direction narratives constitute narrative corroboration, not fact verification. REVISE: none -- all five new materials are supply-side moves, none constitutes counter-evidence to the target card's 14 F-Units, and the target card's conclusions stand. Via ChillStack's MCP assessment, the card also connects back to ANK-2026-06-30-002 (Japanese SaaS's MCP 'common AI socket' moment), forming a third panel: feature acceleration, then the governance gap, then assessment-supply moves (an editorial frame; the populations differ; not causation).

ANK-Doc ID: ANK-2026-07-12-002 Version: v1.0.0 Published: 2026-07-12 Author: Rin Takenouchi (Global Editor-in-Chief, auto AI structuring) Category: AI Security / AI Governance / Japan Security-Industry Supply-Side Moves / Extension-Deepening Card Covered articles: New 5 -- PRTIMES#1204049 (ChillStack launches "MCP Server Assessment," 2026-06-25, 11 days before the survey release), PRTIMES#1347221 (AI Security Inc. begins handling Digital Arts products, 2026-07-07), PRTIMES#1349229 (GRCS "AI-driven penetration test" trial campaign, 2026-07-08), PRTIMES#1372810 (AI Security Inc. x CrowdStrike partnership, 2026-07-09), PRTIMES#1372312 (First Recon AI launches "AI Security Runtime," PRTIMES publishing entity PERSEFONI AI INC., 2026-07-09); inherited from the target card, 5 -- PRTIMES#1337053, #1265730, #1336682, #1252397, #1189986; cross-card, 2 -- ANK-2026-07-06-011, ANK-2026-06-30-002. Twelve in total, this card's material ceiling; nothing further is added. Extension method: This card is the second, deepened edition extending ANK-2026-07-06-011 (the "gap ledger" of AI security), not a rewrite and not a reskin: the target card's 14 F-Units and every numeric framing are inherited verbatim, and this card adds verifiable facts in four typed layers -- [ADD_EVIDENCE] two supply-side releases by the same company within 3 days after the survey release plus GRCS's price campaign, [CONTEXTUALIZE] the survey publisher's own supply-side move (an MCP assessment launched 11 days before the release) concretizing the conflict-of-interest caveat, [CORROBORATE] three vendors' same-direction shadow-AI narratives (honestly framed as narrative corroboration, not fact verification), [CONNECT] visible, transparent links back to the target card and ANK-2026-06-30-002; [REVISE] = none (no new counter-evidence). Weak links were honestly culled: PRTIMES#1373299 (GSX x NinjaOne unified IT-operations platform -- topic drift, not the AI-security main line), PRTIMES#1374285 (HPE x NVIDIA -- a Japanese-language rendering of a U.S. announcement dated 2026-06-16, not a Japan-market main line) -- cut rather than forced.


TL;DR

This card is the second, deepened edition extending ANK-2026-07-06-011 (the "gap ledger" of AI security in Japan: ChillStack's survey of 188 decision-makers at companies with AI-embedded services) [CONNECT]. The target card pinned the demand side's three headline rows -- MIC guideline awareness 83.0% (n=188) [F-001], "reviewed and already reflected" among the understanding layer (n=156) 30.8% [F-002], pre-release measures "sufficiently implemented" only 20.2% with about 80% sensing some insufficiency (n=188) [F-003] (survey period 2026-05-25 to 2026-06-03, self-reported, a sample survey). This card turns the page: in the two weeks around the survey release (2026-06-25 to 2026-07-09), Japan's AI-security supply side produced five verifiable corporate releases -- all corporate press releases, none of which mentions the survey; this card has zero official anchors. First [CONTEXTUALIZE]: the survey's publisher ChillStack itself launched an "MCP Server Assessment" 11 days before the survey release (on 2026-06-25; day count computed from the two release dates), with the release stating it expands the company's AI-security assessment coverage to MCP-using server environments; example inspection categories are communications, authentication/authorization, internal processing, sensitive-data handling and supply chain [F-015] -- concretizing the target card's abstract caveat "the surveying party has an interest": the company's business lines (Stena Expense / Safia / security assessment / AI Defense Institute) sit in the gap zone its survey describes (founded November 2018, CEO Michiaki Ito, EY Innovative Startup 2026, CEO selected for Forbes 30 Under 30 Asia 2025 -- all self-reported in the company's own release) [F-016]. Second [ADD_EVIDENCE]: AI Security Inc. -- the same company as the target card's F-014 (Shinjuku-ku, Tokyo; founded September 2021) -- issued two releases on the day after and 3 days after the survey release: handling of Digital Arts products (i-FILTER / m-FILTER) begun on 2026-07-07 [F-017], and a partnership with CrowdStrike (the CrowdStrike Falcon platform) announced on 2026-07-09 [F-018]; GRCS (TSE Growth 9250) opened an "AI-driven penetration test" trial campaign on 2026-07-08 -- special price from JPY 550,000 tax included, first 10 companies, for contracts concluded 2026-07-07 through the end of October 2026 -- whose cost-and-effort pain narrative runs in the same direction as the survey's F-004 top reason "insufficient cost/resources" (editorial juxtaposition, not causation; GRCS does not cite the survey; marketing character flagged) [F-020]. Third [CORROBORATE]: First Recon AI (PRTIMES publishing entity PERSEFONI AI INC.; Japan rollout driven by Persefoni Japan, a godo kaisha; CEO and co-founder Kentaro Kawamori) launched "AI Security Runtime" on 2026-07-09; its release narrative -- growth of shadow AI beyond corporate oversight (vendor self-description, no quantification in the source) and conventional security products premised on protecting files, mail and networks that cannot understand AI dialogue content or user intent -- runs in the same direction as the target card's F-013 (SherLOCK's "real management harm" mutation thesis) and F-014 (shadow AI) [F-019]: all three are interested supply-side vendors, so same-direction narratives are narrative corroboration, not fact verification. [REVISE] = none: all five new materials are supply-side moves, none constitutes counter-evidence to the target card's 14 F-Units, and the conclusions stand. Honest framing: the timing cluster of the five releases is an editorial observation -- neither a causal claim that "the supply side responded to the survey" nor a market statistic; every inherited number is preserved verbatim, with n and the survey period flagged throughout.


Body

The event-chain timeline and framing principles -- this card is the second, deepened edition of ANK-2026-07-06-011

The full extended timeline (each point per its source's release date): in March 2026, MIC published its "AI Security Technical Countermeasure Guidelines" (rendered verbatim per the target card's framing; the source records only the name and publication timing; an unverified official anchor that does not constitute official endorsement verified by this site); over 2026-05-25 to 2026-06-03, ChillStack ran its fact-finding survey on AI security via research provider Freeasy; on 2026-06-25, ChillStack announced the launch of its "MCP Server Assessment" (PRTIMES#1204049) -- 11 days before the survey release; on 2026-07-06, ChillStack released the survey results (PRTIMES#1337053), the main article of the target card ANK-2026-07-06-011; on 2026-07-07, AI Security Inc. began handling Digital Arts products (PRTIMES#1347221); on 2026-07-08, GRCS opened its AI-driven penetration-test trial campaign (PRTIMES#1349229); on 2026-07-09, AI Security Inc. announced a partnership with CrowdStrike (PRTIMES#1372810) and First Recon AI launched "AI Security Runtime" (PRTIMES#1372312).

This card first sets six framing principles. First, this card has zero official anchors -- all ten PRTIMES items are corporate press releases; official_count_verified=0; the MIC guidelines appear only as a verbatim rendering per the target card's framing. Second, none of the five new materials mentions ChillStack's survey -- the "two weeks around" clustering is an editorial observation, neither a causal claim nor a market statistic; the companies' internal schedules are unknowable. Third, every inherited number is preserved verbatim -- the target card's 83.0% (n=188), 30.8% (n=156), 20.2%, about 80% and all other figures are inherited as-is, together with their n's, the survey period (2026-05-25 to 2026-06-03) and the self-report framing (no recomputation, no amplification). Fourth, corporate attribution is made precise -- the PRTIMES publishing entity for First Recon AI is PERSEFONI AI INC., with the Japan rollout driven by Persefoni Japan (a godo kaisha); "AI Security Inc." is a corporate name, not a generic term. Fifth, marketing character is flagged -- GRCS's item is a trial campaign (advertising in nature), and every product capability is the vendor's self-description. Sixth, REVISE = none -- none of the five new materials constitutes counter-evidence to the target card's 14 F-Units; the target card's conclusions stand.

[CONNECT] What this card extends: the target card and the MCP card's third panel

This card extends explicitly, visibly and honestly from this site's published ANK-2026-07-06-011 (the "gap ledger" of AI security): that card used ChillStack's survey to pin the demand side's gap structure ("aware but unable to act"), and this card adds two weeks of supply-side moves on the same thematic axis -- the next page of the same ledger, not a new topic. In parallel, via ChillStack's "MCP Server Assessment" (PRTIMES#1204049), this card connects back to ANK-2026-06-30-002 (Japanese SaaS's MCP "common AI socket" moment): that card recorded the acceleration of Japanese SaaS plugging AI features into the MCP "common socket" around 2026-06-30, the target card recorded the security-governance side's self-assessed insufficiency in the same weeks, and this card records assessment-supply moves for MCP-using environments -- feature acceleration, then the governance gap, then assessment-supply moves. The three panels have different populations (SaaS vendors' product-release behavior / 188 decision-makers' self-assessment / an individual security vendor's service release); this card juxtaposes them editorially only and makes no causal claim. (PRTIMES#1204049, ANK-2026-07-06-011, ANK-2026-06-30-002)

[CONTEXTUALIZE] What the survey's publisher sells: concretizing "the surveying party has an interest"

In the target card's risk factors, "the surveying party has an interest: ChillStack is an AI-security vendor and the release has a marketing character" was one abstract sentence. This card concretizes it: on 2026-06-25 -- 11 days before the survey release date of 2026-07-06 (day count computed from the two release dates, not the source's wording) -- ChillStack announced the launch of its "MCP Server Assessment," and the release frames this as an expansion of the company's AI-security assessment coverage, targeting server environments that use MCP (Model Context Protocol), with inspection items customized to each company's system specifications and use cases; the example inspection categories are: risks in the communications themselves, authentication/authorization risks, internal-processing risks, sensitive-data-handling risks, and supply-chain risks (PRTIMES#1204049). [F-015] The release's background section states that as LLMs evolve, the use of AI agents that autonomously operate external systems is expanding and that MCP is settling in as a common standard across many services (vendor self-description, no quantification in the source).

The company-profile section of the same release self-reports: ChillStack is headquartered in Shibuya-ku, Tokyo, founded in November 2018, with Michiaki Ito as representative director; its business includes "Stena Expense" (an AI that automatically checks expense fraud and errors), "Safia" (automatic detection of fraudulent use to promote generative-AI adoption), "security assessment" services, and the "AI Defense Institute" (R&D and education); awards include EY Innovative Startup 2026; CEO Michiaki Ito received the IEEE CSPA2018 best-paper award and the IPA Security Camp Award 2018 top prize, and was selected for "Forbes 30 Under 30 Asia 2025" (all self-reported in the company's own release; this site has not independently verified them). [F-016] In other words, the company's business lines sit in the very gap zone its survey describes -- the demand the survey surfaced for assessment/monitoring schemes (the in-house layer's top strengthening wish, "building a scheme for regular security assessment/monitoring," 55.0%, n=120, inherited [F-009]) is precisely the service category the company sells.

Honest framing: concretizing the conflict of interest is not the same as overturning the survey figures. The survey was fielded by the external provider Freeasy, the source itself asks that citations credit the survey to ChillStack, and this card inherits every n and the self-report framing. The point of the concretization is this: anyone citing this survey now has a verifiable anchor (release date, service name, business lines) behind the caveat "the release has a marketing character," instead of a lone abstract note. (PRTIMES#1204049, PRTIMES#1337053)

[ADD_EVIDENCE] The same company, twice in 3 days: AI Security Inc.'s channel and partnership moves

The target card's F-014 recorded that AI Security Inc. (Shinjuku-ku, Tokyo; "AI Security" is its corporate name) spoke at AWS Summit Japan 2026 on the "serious gap between governance and implementation technology" and shadow AI (release dated 2026-06-24). This card adds: the same company issued two supply-side releases on the day after and 3 days after the survey release --

First, released 2026-07-07: it began handling Digital Arts Inc.'s information-security products, stating that from that day ("honjitsu yori" = 2026-07-07) it starts proposing the web-security product "i-FILTER," the email-security product "m-FILTER" and other security products; Digital Arts is an information-security maker founded in 1995 (per that release). (PRTIMES#1347221) [F-017]

Second, released 2026-07-09: a partnership with CrowdStrike (the release title says "strengthening the partnership" while the body says "announced a partnership"; the source does not state when any prior relationship began), built on the CrowdStrike Falcon platform, offering security-operations assessment and design, Falcon deployment and rollout support, security-workflow optimization, operations support and advisory services, and tool consolidation/modernization support; the release carries comments from AI Security Inc. representative director and CEO Takao Horii and from Jon Fox, Vice President of Channel & Alliances, CrowdStrike Japan and Asia Pacific; the company-profile section lists founding in September 2021, capital of JPY 19,110,000, CEO Takao Horii and COO Takahiro Ichikawa, under the banner "Security for AI." (PRTIMES#1372810) [F-018]

Both items are channel/partnership moves, and neither mentions ChillStack's survey; "the company that lectured on the governance gap issued two supply-expansion releases (2026-07-07 and 2026-07-09) within the two weeks after the survey release of 2026-07-06" is this card's editorial observation -- temporal adjacency does not constitute causation.

[ADD_EVIDENCE] GRCS's price tactic: a JPY 550,000 trial campaign against "insufficient cost/resources"

GRCS Inc. (headquartered in Chiyoda-ku, Tokyo; president Yoshikazu Sasaki; Tokyo Stock Exchange Growth Market, securities code 9250; established March 2005; capital JPY 116 million per the source) announced on 2026-07-08 the start of a trial campaign for its "AI-driven penetration test": penetration testing powered by "RidgeBot," an AI-driven CTEM-support solution, at a campaign price from JPY 550,000 tax included, applicable to contracts concluded between 2026-07-07 and the end of October 2026, limited to the first 10 companies, with possible early termination if capacity is reached (the fact that the eligibility window opens 1 day before the release date is transcribed as-is from the source); the service covers companies' internet-facing websites and externally accessible systems, running simulated attacks for risk detection and analysis and delivering an assessment report; CTEM (Continuous Threat Exposure Management) is a concept proposed by Gartner (per that release). (PRTIMES#1349229) [F-020]

The release's background section states that conventional penetration tests are largely manual work by specialists (white-hat hackers), with growing effort and cost as the pain point, and that AI-driven testing enables assessment in a short time (the vendor's self-description in the 2026-07-08 release, with no third-party verification). This cost-and-effort pain narrative runs in the same direction as the target card's F-004 -- the top reason for insufficient pre-release measures in both layers being "insufficient cost/resources" (percentage not given in the source). To be stated plainly: this is an editorial juxtaposition, not causation. GRCS's release does not cite ChillStack's survey, and this is a marketing-campaign release (advertising in nature); this card does not evaluate the price level (no market benchmark data) and does not forecast the campaign's results. (PRTIMES#1349229, PRTIMES#1337053)

[CORROBORATE] Three vendors' same-direction narratives: shadow AI and the "mismatch of conventional security products' premises" -- narrative corroboration, not fact verification

First Recon AI launched its enterprise AI-security platform "First Recon AI Security Runtime" on 2026-07-09. Corporate attribution first (cross-company misbinding is a credibility-destroying red line): the PRTIMES publishing entity for this release is PERSEFONI AI INC.; First Recon AI provides AI-security technology developed on the basis of enterprise-AI expertise cultivated at Persefoni (the source's wording; the source states nothing further about the two entities' legal or capital relationship, and this card does not infer one); the Japan-market rollout is driven by Persefoni Japan, a godo kaisha; the release carries comments from First Recon AI CEO and co-founder Kentaro Kawamori and from First Recon AI's Japan representative (Persefoni Japan) Takehiro Endo. (PRTIMES#1372312)

Product content (all vendor self-description): real-time analysis of every AI interaction inside a company, applying policy before data is sent to AI models and recording each decision as an auditable trail; the four functions are Observe, Detect, Enforce and Trace; the core technologies are the proprietary Semantic Security Engine and Security Context Graph; the product comprises an Endpoint Agent (macOS/Windows) and an Application (a Secure AI Workspace), and the company says major AI providers including OpenAI, Anthropic, Google and Meta can be managed under a single policy; offered to enterprises from 2026-07-09 with a 30-day free trial; the company also announced plans to exhibit at Black Hat USA 2026 in Las Vegas in August 2026 (a plan, not yet realized). [F-019]

The point of this layer is the narrative structure: in its 2026-07-09 release, First Recon AI states that shadow AI used beyond corporate oversight is expanding, that confidential-data leak risks, rising AI usage costs and new management issues around AI governance, audit and regulatory response are surfacing, and that conventional cybersecurity products -- designed to protect files, mail and networks -- cannot understand AI dialogue content or user intent (vendor self-description, no quantification in the source). This runs in the same direction as the target card's F-013 (SherLOCK: AI risk mutating from reputational issues into "real management harm") and F-014 (AI Security Inc.: growing shadow AI as its talk theme, released 2026-06-24). Honest framing: all three are interested AI-security supply-side vendors, and the same direction of their press-release narratives shows a convergence of supply-side marketing narratives -- narrative corroboration, not independent fact verification; none of the three attaches verifiable market statistics to its release. (PRTIMES#1372312, PRTIMES#1252397, PRTIMES#1189986)

Pulling back the lens: what these two weeks added to the ledger, and what they did not

After the extension, the ledger gained: five verifiable supply-side moves (each with a release date and source URL: 2026-06-25 ChillStack MCP assessment, 2026-07-07 AI Security Inc. x Digital Arts, 2026-07-08 GRCS campaign, 2026-07-09 AI Security Inc. x CrowdStrike, 2026-07-09 First Recon AI), plus a verifiable anchor for the surveying party's conflict of interest. The ledger did not gain: any official statistic, any verifiable market-size figure, or any counter-evidence to the target card's 14 F-Units. The demand-side gap figures -- awareness 83.0% (n=188), reflection among the understanding layer 30.8% (n=156), pre-release "sufficient" 20.2% (n=188) -- are inherited verbatim; the next page is a list of the supply side's visible moves within the same window (2026-06-25 to 2026-07-09), each checkable against its source, but the list should not be read as a market trend or as a causal response to the survey.

Risk factors

  • Zero official anchors (official_count_verified=0): all ten PRTIMES items are corporate press releases; the "AI Security Technical Countermeasure Guidelines" name is rendered verbatim per the target card's framing (source PRTIMES#1337053), an unverified official anchor that does not constitute official endorsement verified by this site; this card does not elaborate on the guidelines' content.
  • Timing cluster is not causation: none of the five new materials (2026-06-25 to 2026-07-09) mentions ChillStack's survey; "the two weeks around" is an editorial observation; the companies' internal schedules are unknowable, and this card makes no claim that "the supply side responded to the survey."
  • Marketing character: GRCS's item is a trial-campaign release (special price from JPY 550,000 tax included, first 10 companies, for contracts 2026-07-07 through end-October 2026, possible early termination; the eligibility window opening earlier than the 2026-07-08 release date is transcribed as-is) (PRTIMES#1349229); every product capability (Semantic Security Engine, RidgeBot, Falcon operational benefits, etc.) is vendor self-description without third-party verification.
  • Corporate attribution: the PRTIMES publishing entity for First Recon AI is PERSEFONI AI INC., with the Japan rollout driven by Persefoni Japan (a godo kaisha); "developed on the basis of expertise cultivated at Persefoni" is the source's wording, the legal/capital relationship is not further stated in the source, and this card does not infer one (PRTIMES#1372312). "AI Security Inc." is a corporate name, not a generic term (framing inherited from the target card) (PRTIMES#1347221, #1372810).
  • Concretized interest does not equal refutation: ChillStack's MCP assessment and business lines are the company's own self-reported release content; the survey figures are inherited verbatim; this card neither overturns nor endorses any figure on grounds of the conflict of interest (PRTIMES#1204049, #1337053).
  • Award mentions not independently verified: ChillStack's EY Innovative Startup 2026 and the CEO's Forbes 30 Under 30 Asia 2025 selection are self-reported in the company's release (PRTIMES#1204049).
  • Day counts are computed: "11 days before," "the day after" and "3 days after" are day counts computed by this card from the release dates, not the sources' wording.
  • All inherited survey framings remain in force: a sample survey, not a census (n=188 and subsets); self-assessment, not an audit; the surveying party has an interest; rounding (answer-option percentages may not sum to 100%); a single-market Japan card (no Taiwan-side data, no Taiwan-Japan comparison) (PRTIMES#1337053).
  • CrowdStrike partnership wording: the release title says "strengthening the partnership" while the body says "announced a partnership" -- the source does not state when any prior relationship began; this card transcribes both wordings and infers nothing (PRTIMES#1372810).

FAQ

Q: How does this card relate to ANK-2026-07-06-011? What does "second, deepened edition" mean?

This card is the second, deepened edition extending the target card ANK-2026-07-06-011 (the "gap ledger" of AI security): the target card's 14 F-Units and every numeric framing are inherited verbatim, and this card layers on five supply-side corporate releases from 2026-06-25 to 2026-07-09 (six new F-Units) in four typed layers -- ADD_EVIDENCE / CONTEXTUALIZE / CORROBORATE / CONNECT -- with REVISE = none (no new counter-evidence).

It is not a rewrite and not a reskin: the target card covers the demand side (188 decision-makers' self-reported gaps), this card covers the supply side (five corporate moves in the same window); the ledger is complete only with both pages (ANK-2026-07-06-011, PRTIMES#1204049, #1347221, #1349229, #1372810, #1372312).

Q: What does the survey's publisher ChillStack itself sell? Does that overturn the survey figures?

ChillStack launched its "MCP Server Assessment" 11 days before the survey release (on 2026-06-25), and its business lines include Stena Expense, Safia, security assessment and the AI Defense Institute -- sitting in the gap zone its survey describes. But this does not overturn the survey figures: the survey was fielded by the external provider Freeasy, the source itself asks that citations credit ChillStack, and this card inherits every n and the self-report framing.

The point of concretizing the interest: the target card's abstract caveat "the release has a marketing character" now comes with a verifiable anchor (release date, service name, business lines). Anyone citing the survey should carry this framing with it (PRTIMES#1204049, #1337053).

Q: What did AI Security Inc. release in these two weeks, and how does it relate to the target card?

It is the same company as the speaker in the target card's F-014 (the AWS Summit Japan 2026 talk on the "serious gap between governance and implementation technology" and shadow AI). This card adds: on the day after the survey release (2026-07-07) it began handling Digital Arts products (i-FILTER / m-FILTER), and 3 days after (2026-07-09) it announced a partnership with CrowdStrike (CrowdStrike Falcon) -- two channel/partnership moves within 3 days.

Neither release mentions ChillStack's survey; the temporal adjacency is an editorial observation, not causation. The company was founded in September 2021, is based in Shinjuku-ku, Tokyo, and "AI Security" is its corporate name, not a generic term (PRTIMES#1347221, #1372810, #1189986).

Q: Does GRCS's JPY 550,000 campaign prove that "insufficient cost/resources" is being solved?

No. What GRCS opened on 2026-07-08 is a marketing trial campaign (special price from JPY 550,000 tax included, first 10 companies, for contracts concluded 2026-07-07 through the end of October 2026, possible early termination), and the match between its cost-and-effort pain narrative and the survey F-004 top reason "insufficient cost/resources" is a same-direction editorial juxtaposition only -- GRCS does not cite the survey, and there is no public data on outcomes.

"AI-driven testing evaluates effectively in a short time" is the vendor's self-description; RidgeBot is an AI-driven CTEM-support solution (CTEM is a Gartner-proposed concept, per that release) (PRTIMES#1349229, #1337053).

Q: Who is First Recon AI, and what is its relationship to Persefoni?

Precise attribution: the PRTIMES publishing entity is PERSEFONI AI INC.; the product is "First Recon AI Security Runtime"; the source states First Recon AI provides AI-security technology developed on the basis of enterprise-AI expertise cultivated at Persefoni; the Japan-market rollout is driven by Persefoni Japan, a godo kaisha; the CEO and co-founder is Kentaro Kawamori and the Japan representative is Takehiro Endo. The source states nothing further about the two entities' legal/capital relationship, and this card transcribes without inferring.

The product (Endpoint Agent plus Application, the four functions Observe / Detect / Enforce / Trace, the Semantic Security Engine, etc.) is entirely vendor self-description; offered from 2026-07-09 with a 30-day free trial, and an exhibit at Black Hat USA 2026 in August 2026 is announced (a plan) (PRTIMES#1372312).

Q: Can these five releases (2026-06-25 to 2026-07-09) be read as "Japan's AI-security market is expanding"?

No. These five releases (2026-06-25 to 2026-07-09) are all individual corporate press releases with zero official anchors and no market-size statistics whatsoever; the timing cluster is this card's editorial observation, not evidence of a market trend.

What this card can honestly claim is only this: within the two-week window around the survey release, there were these five verifiable supply-side corporate releases, each checkable against its source (PRTIMES#1204049, #1347221, #1349229, #1372810, #1372312).

Q: Is there anything in the target card that needs revision (REVISE)?

No. All five new materials are supply-side moves, and none constitutes counter-evidence to the target card's 14 F-Units; awareness 83.0% (n=188), reflection among the understanding layer 30.8% (n=156), pre-release "sufficient" 20.2%, about 80% self-assessing insufficiency, monitoring 59.2% vs. 19.1%, black-boxing 32.4% -- every figure and framing is inherited verbatim and the conclusions stand.

If third-party or official comparison data appears later (see P-004), it will be examined on that evidence (ANK-2026-07-06-011).

Q: What is the "third panel" with ANK-2026-06-30-002 (the MCP card)?

Three panels: ANK-2026-06-30-002 records feature acceleration (Japanese SaaS plugging AI into the MCP "common socket"; 2 freee-group services announced MCP servers the same day); ANK-2026-07-06-011 records the governance gap (about 80% of 188 surveyed decision-makers self-assess pre-release measures as insufficient); this card records assessment-supply moves (ChillStack launched its MCP Server Assessment on 2026-06-25, taking MCP-using environments as a direct assessment target).

The three panels have different populations (SaaS vendors' product releases / decision-makers' self-assessment / an individual security vendor's service release); they are juxtaposed editorially only, not as a causal chain (ANK-2026-06-30-002, ANK-2026-07-06-011, PRTIMES#1204049).


F-Units

F-001 to F-014 are inherited verbatim from ANK-2026-07-06-011; F-015 onward are new to this card.

F-001: (inherited from ANK-2026-07-06-011) MIC published the "AI Security Technical Countermeasure Guidelines" in March 2026; in ChillStack's survey, awareness of the guidelines ("understand well" + "roughly understand" combined) is 83.0% (n=188); the share answering "understand well" is more than 2 times as high in the in-house layer as in the outsourcing layer (no specific per-layer percentages in the source)

  • source: PRTIMES #1337053
  • source_url: https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  • confidence: high
  • basis: official_statement
  • period: guidelines published 2026-03; survey 2026-05-25 to 2026-06-03; released 2026-07-06
  • caveat: awareness is self-reported by responding decision-makers in a sample survey (not a census); the guidelines' name is rendered from the source verbatim, the source records only the name and publication timing, and this card does not elaborate on the content

F-002: (inherited from ANK-2026-07-06-011) Among respondents who understand the guidelines (n=156), 30.8% have "reviewed and already reflected" them in their measures; in-house layer 37.5%, outsourcing layer 17.3%

  • source: PRTIMES #1337053
  • source_url: https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  • confidence: high
  • basis: official_statement
  • period: survey 2026-05-25 to 2026-06-03
  • caveat: the base is the subset of respondents who understand the guidelines (n=156), not all 188; self-reported

F-003: (inherited from ANK-2026-07-06-011) Only 20.2% say pre-release security measures are "sufficiently implemented"; adding "mostly implemented but not sufficient," "implemented but felt insufficient" and "hardly implemented," those sensing some insufficiency total about 80% (about 8 in ten) (n=188)

  • source: PRTIMES #1337053
  • source_url: https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  • confidence: high
  • basis: official_statement
  • period: survey 2026-05-25 to 2026-06-03
  • caveat: "about 80%" is the source's own wording; the source does not give the percentage of each of the three "insufficient" options and this card does not back-calculate; self-assessment, not a third-party audit, and not extrapolable to all Japanese companies

F-004: (inherited from ANK-2026-07-06-011) Reasons for insufficient pre-release measures: the top reason in both layers is "insufficient cost/resources" (percentage not given in the source); from 2nd place the in-house layer lists "no personnel with security expertise in-house" 41.8%, followed by "too many items to address, cannot prioritize" 35.2% (n=91); from 2nd place the outsourcing layer lists "too many items to address, cannot prioritize" 33.9%, followed by "unclear what standard counts as sufficient" 32.2% (n=59)

  • source: PRTIMES #1337053
  • source_url: https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  • confidence: high
  • basis: official_statement
  • period: survey 2026-05-25 to 2026-06-03
  • caveat: bases are the subsets with insufficient pre-release measures (in-house n=91, outsourcing n=59); self-reported

F-005: (inherited from ANK-2026-07-06-011) Top 3 pre-release measures in place (n=188): "validation/filtering of input prompts" 46.8%, "resistance to malicious instructions via system prompts" 45.7%, "validation/filtering of output content (guardrails)" 45.2%

  • source: PRTIMES #1337053
  • source_url: https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  • confidence: high
  • basis: official_statement
  • period: survey 2026-05-25 to 2026-06-03
  • caveat: measure names are English renderings of the source's answer options; self-reported

F-006: (inherited from ANK-2026-07-06-011) Post-release regular security monitoring / risk assessment "regularly implemented": in-house layer 59.2% (n=120), outsourcing layer 19.1% (n=68)

  • source: PRTIMES #1337053
  • source_url: https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  • confidence: high
  • basis: official_statement
  • period: survey 2026-05-25 to 2026-06-03
  • caveat: the two layers have different bases (n=120 vs. n=68); "post-release management tends to thin out in the outsourcing layer" is the source's synthesis; self-reported

F-007: (inherited from ANK-2026-07-06-011) Within the outsourcing layer, 26.5% "do not really grasp" and 5.9% "hardly grasp" vendors' implemented measures, 32.4% combined (n=68); reasons for not grasping them: "no time/resources to check" 31.8%, "no personnel in-house able to judge the content" 27.3%, "few reporting/briefing occasions from the vendor" 27.3% (n=22)

  • source: PRTIMES #1337053
  • source_url: https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  • confidence: high
  • basis: official_statement
  • period: survey 2026-05-25 to 2026-06-03
  • caveat: the reasons question has a base of only n=22 (small sample); "black box" is the source's wording; self-reported

F-008: (inherited from ANK-2026-07-06-011) Among the in-house layer running regular monitoring, self-assessments of implementing appropriate measures based on the results total 97.2% ("sufficiently implemented" 38.0% + "mostly implemented" 59.2%) (n=71)

  • source: PRTIMES #1337053
  • source_url: https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  • confidence: medium
  • basis: official_statement
  • period: survey 2026-05-25 to 2026-06-03
  • caveat: a small n=71 subset's self-evaluation, not a third-party audit; a correlation ("those with a scheme self-assess well"), not causation

F-009: (inherited from ANK-2026-07-06-011) AI-security measures respondents want to strengthen: in-house layer "building a scheme for regular security assessment/monitoring" 55.0%, "promoting staff understanding of security measures" 47.5% (n=120); outsourcing layer "developing/securing in-house personnel with security expertise" 45.6%, "promoting staff understanding of security measures" 32.4% (n=68)

  • source: PRTIMES #1337053
  • source_url: https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  • confidence: high
  • basis: official_statement
  • period: survey 2026-05-25 to 2026-06-03
  • caveat: self-reported intentions, not implemented measures; the two layers have different bases

F-010: (inherited from ANK-2026-07-06-011) Survey overview: title "fact-finding survey on AI security measures"; research provider Freeasy; respondents are people with approval/selection authority over AI security at companies operating AI-embedded in-house services and products; method web questionnaire; period 2026-05-25 to 2026-06-03; 188 valid responses; the source notes that due to rounding, answer-option percentages may not sum to 100%

  • source: PRTIMES #1337053
  • source_url: https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  • confidence: high
  • basis: official_statement
  • period: 2026-05-25 to 2026-06-03 (survey period); 2026-07-06 (release)
  • caveat: ChillStack is an AI-security vendor (an interested party); the source asks that citations credit the survey to ChillStack

F-011: (inherited from ANK-2026-07-06-011) Global Security Experts Inc. (GSX, securities code 4417) provides AI-security engineer training to 150 engineers of Keyware Solutions; GSX provides Keyware and its group companies with multiple education programs, including incident response, vulnerability assessment and AI-security talent development, as continuous support; including group subsidiaries, the cumulative number of trainees is planned to exceed 500

  • source: PRTIMES #1265730
  • source_url: https://prtimes.jp/main/html/rd/p/000000207.000007157.html
  • confidence: high
  • basis: official_statement
  • period: 2026-06-30 (press release)
  • caveat: "more than 500 cumulative" is a plan, not yet realized; an individual corporate press release (micro-level information); Keyware Solutions is a systems integrator

F-012: (inherited from ANK-2026-07-06-011) AI-security startup Nayutam (Chuo-ku, Tokyo) signed an MOU (memorandum) with the Swiss DID/VC infrastructure provider Dock Labs for strategic collaboration and joint marketing in Japan's enterprise market, targeting "Agentic Commerce (the AI-agent economy)" and the digital-finance sector; Nayutam develops "Synthetic DNA" (a biometric-bound root-of-trust ID) and a "Behavior Trust Score" engine, while Dock Labs provides "Truvera," a digital-ID and wallet infrastructure compliant with W3C international standards, plus MCP (Model Context Protocol)-compatible solutions

  • source: PRTIMES #1336682
  • source_url: https://prtimes.jp/main/html/rd/p/000000015.000147740.html
  • confidence: high
  • basis: official_statement
  • period: 2026-07-06 (press release)
  • caveat: an MOU is memorandum-level, not a definitive contract; product-capability descriptions are the vendors' self-descriptions; an individual corporate press release (micro-level information)

F-013: (inherited from ANK-2026-07-06-011) SherLOCK Inc. (Minato-ku, Tokyo) stated in its brand-renewal release that the nature of AI risk is mutating from reputational issues (hallucinations, confidential-data leaks) into "real management harm" such as economic loss and business stoppage; it cited an OECD survey (AIM) as showing related incidents doubled in 1 year, with "abuse of legitimate privileges" becoming a new management issue

  • source: PRTIMES #1252397
  • source_url: https://prtimes.jp/main/html/rd/p/000000027.000145146.html
  • confidence: medium
  • basis: official_statement
  • period: 2026-06-29 (press release)
  • caveat: "doubled in 1 year" is the company's citation of the OECD survey (AIM) with no absolute numbers in the source; this card transcribes without verifying on its behalf; the risk-mutation thesis is the vendor's own argument; an individual corporate press release (micro-level information)

F-014: (inherited from ANK-2026-07-06-011) AI Security Inc. (Shinjuku-ku, Tokyo; "AI Security" is the company's corporate name) announced on 2026-06-24 that it would speak on "Security Transformation in the AI Era" at AWS Summit Japan 2026, held 2026-06-25 to 26 at Makuhari Messe (Zscaler booth), on the "serious gap between governance and implementation technology" amid the rapid spread of generative AI and on the growing problem of "shadow AI"

  • source: PRTIMES #1189986
  • source_url: https://prtimes.jp/main/html/rd/p/000000026.000166898.html
  • confidence: high
  • basis: official_statement
  • period: 2026-06-24 (release); 2026-06-25 to 26 (session dates)
  • caveat: the release is a pre-event announcement (release date earlier than session dates); "AI Security Inc." is a corporate name, not a generic term; an individual corporate press release (micro-level information)

F-015: (new) ChillStack announced the launch of its "MCP Server Assessment" on 2026-06-25 -- 11 days before the survey release date (2026-07-06; day count computed from the two release dates); the release frames it as an expansion of the company's AI-security assessment coverage, targeting server environments that use MCP (Model Context Protocol), with inspection items customized to each company's system specifications and use cases; example inspection categories: risks in the communications themselves, authentication/authorization risks, internal-processing risks, sensitive-data-handling risks, supply-chain risks

  • source: PRTIMES #1204049
  • source_url: https://prtimes.jp/main/html/rd/p/000000082.000046548.html
  • confidence: high
  • basis: official_statement
  • period: 2026-06-25 (press release)
  • caveat: an individual corporate press release (micro-level information); "AI-agent use is expanding and MCP is settling in as a common standard" is vendor self-description in the 2026-06-25 release with no quantification in the source; "11 days before" is this card's day-count computation, not the source's wording; adoption figures (customer counts) are not stated in the source

F-016: (new) ChillStack company profile (self-reported in the company's own release): headquartered in Shibuya-ku, Tokyo; founded November 2018; representative director Michiaki Ito; business includes "Stena Expense" (an AI that automatically checks expense fraud/errors), "Safia" (automatic detection of fraudulent use to promote generative-AI adoption), "security assessment" services, and the "AI Defense Institute" (R&D and education); awards include EY Innovative Startup 2026; CEO Michiaki Ito received the IEEE CSPA2018 best-paper award and the IPA Security Camp Award 2018 top prize, was selected for "Forbes 30 Under 30 Asia 2025," and has taught AI-security lectures at Security Camp 2019-2026

  • source: PRTIMES #1204049
  • source_url: https://prtimes.jp/main/html/rd/p/000000082.000046548.html
  • confidence: medium
  • basis: official_statement
  • period: 2026-06-25 (press release; company-profile section)
  • caveat: all self-reported in the company's own release; award/selection mentions not independently verified by this site; used to concretize the "surveying party has an interest" framing, not to endorse or refute the survey figures

F-017: (new) AI Security Inc. (Shinjuku-ku, Tokyo; representative director and CEO Takao Horii) announced on 2026-07-07 that it began handling Digital Arts Inc.'s information-security products, stating that from that day ("honjitsu yori" = 2026-07-07) it starts proposing the web-security product "i-FILTER," the email-security product "m-FILTER" and other security products; Digital Arts is an information-security maker founded in 1995 (per that release)

  • source: PRTIMES #1347221
  • source_url: https://prtimes.jp/main/html/rd/p/000000028.000166898.html
  • confidence: high
  • basis: official_statement
  • period: 2026-07-07 (press release)
  • caveat: an individual corporate press release (micro-level information); a channel move, not sales results; "AI Security Inc." is a corporate name, not a generic term; the release does not mention ChillStack's survey

F-018: (new) AI Security Inc. announced on 2026-07-09 a partnership with CrowdStrike (the release title says "strengthening the partnership," the body says "announced a partnership"), built on the CrowdStrike Falcon platform, offering: security-operations assessment and design, Falcon deployment and rollout support, security-workflow optimization, operations support and advisory services, and tool consolidation/modernization support; the release carries comments from AI Security Inc. representative director and CEO Takao Horii and from Jon Fox, Vice President of Channel & Alliances, CrowdStrike Japan and Asia Pacific; company profile: founded September 2021, capital JPY 19,110,000, CEO Takao Horii and COO Takahiro Ichikawa, under the banner "Security for AI"

  • source: PRTIMES #1372810
  • source_url: https://prtimes.jp/main/html/rd/p/000000029.000166898.html
  • confidence: high
  • basis: official_statement
  • period: 2026-07-09 (press release)
  • caveat: an individual corporate press release (micro-level information); service-benefit descriptions are vendor self-description; the start of any prior partnership is not stated in the source and this card transcribes both wordings without inferring; the release does not mention ChillStack's survey

F-019: (new) First Recon AI launched the enterprise AI-security platform "First Recon AI Security Runtime" on 2026-07-09 -- the PRTIMES publishing entity is PERSEFONI AI INC.; the source states First Recon AI provides AI-security technology developed on the basis of enterprise-AI expertise cultivated at Persefoni; the Japan-market rollout is driven by Persefoni Japan (a godo kaisha); CEO and co-founder Kentaro Kawamori; Japan representative Takehiro Endo; the product comprises an Endpoint Agent (macOS/Windows) and an Application (Secure AI Workspace); the four functions are Observe, Detect, Enforce and Trace; core technologies are the Semantic Security Engine and Security Context Graph; the company says major AI providers including OpenAI, Anthropic, Google and Meta can be managed under a single policy; a 30-day free trial is offered; an exhibit at Black Hat USA 2026 (Las Vegas, August 2026) is announced; the release narrative states that shadow AI used beyond corporate oversight is expanding and that conventional security products, premised on protecting files, mail and networks, cannot understand AI dialogue content or user intent (vendor self-description in the 2026-07-09 release, no quantification in the source)

  • source: PRTIMES #1372312
  • source_url: https://prtimes.jp/main/html/rd/p/000000075.000101914.html
  • confidence: high
  • basis: official_statement
  • period: 2026-07-09 (press release); 2026-08 (planned Black Hat USA 2026 exhibit)
  • caveat: product capabilities are entirely vendor self-description without third-party verification; the exhibit is a plan, not yet realized; the legal/capital relationship between First Recon AI and Persefoni is not further stated in the source and this card does not infer one; the shadow-AI narrative is an interested vendor's argument -- its relation to F-013/F-014 is narrative corroboration, not fact verification

F-020: (new) GRCS Inc. (Chiyoda-ku, Tokyo; president Yoshikazu Sasaki; TSE Growth Market, securities code 9250; established March 2005; capital JPY 116 million per the source) announced on 2026-07-08 the start of a trial campaign for its "AI-driven penetration test": powered by "RidgeBot," an AI-driven CTEM-support solution; campaign price from JPY 550,000 tax included; applicable to contracts concluded 2026-07-07 through the end of October 2026; limited to the first 10 companies; possible early termination if capacity is reached; the service covers companies' internet-facing websites and externally accessible systems, running simulated attacks for risk detection/analysis and delivering an assessment report; CTEM (Continuous Threat Exposure Management) is a Gartner-proposed concept (per that release)

  • source: PRTIMES #1349229
  • source_url: https://prtimes.jp/main/html/rd/p/000000125.000035245.html
  • confidence: high
  • basis: official_statement
  • period: 2026-07-08 (press release); campaign contract window 2026-07-07 to end-October 2026
  • caveat: a marketing-campaign release (advertising in nature); "effective in a short time" is the vendor's self-description; the contract window opening 1 day before the release date (2026-07-08) is transcribed as-is; the correspondence with survey F-004 "insufficient cost/resources" is an editorial juxtaposition, not causation (GRCS's release does not cite the survey)

J-Units

The target card's J-001 to J-003 remain in force (conclusions unchanged; full text in ANK-2026-07-06-011); this card adds J-004 onward.

J-004 (new): The supply side's two-week timeline -- five verifiable corporate releases in the two weeks around the survey release (2026-07-06): 2026-06-25 ChillStack "MCP Server Assessment," 2026-07-07 AI Security Inc. x Digital Arts, 2026-07-08 GRCS trial campaign, 2026-07-09 AI Security Inc. x CrowdStrike, 2026-07-09 First Recon AI "AI Security Runtime"; none of the five mentions ChillStack's survey, and the timing cluster is an editorial observation -- the companies' internal schedules are unknowable, and this card neither claims causation nor reads the cluster as market statistics

  • confidence: low
  • basis: official_statement

J-005 (new): Concretizing the surveying party's interest -- the target card's risk factor "ChillStack is itself an AI-security vendor" now has a verifiable anchor in this card: an MCP Server Assessment launched 11 days before the survey release (2026-06-25) and four business lines (Stena Expense / Safia / security assessment / AI Defense Institute) sitting in the gap zone the survey describes; the concretization strengthens the framing duty for anyone citing the survey, but does not overturn the survey figures (fielded by the external provider Freeasy; the source requires source crediting; every n and self-report framing inherited verbatim)

  • confidence: medium
  • basis: official_statement

J-006 (new): Narrative corroboration, not fact verification -- First Recon AI's narrative (release of 2026-07-09) of "expanding shadow AI / mismatch of conventional security products' premises" runs in the same direction as SherLOCK's "real management harm" mutation thesis (F-013, released 2026-06-29) and AI Security Inc.'s shadow-AI talk theme (F-014, released 2026-06-24); all three are interested supply-side vendors' press releases, and the same direction shows a convergence of supply-side marketing narratives, not an independently verified market fact -- citations must carry this framing

  • confidence: low
  • basis: official_statement

P-Units

P-001 (inherited from ANK-2026-07-06-011): Will the guideline reflection rate rise -- the fact-finding figure after MIC's publication (March 2026) is 30.8% reflection among the understanding layer (n=156); follow-up surveys by ChillStack or other institutions, and MIC's subsequent moves, need tracking

P-002 (inherited from ANK-2026-07-06-011): Will the outsourcing "black box" improve -- the trajectory of regular monitoring at 19.1% (n=68) and non-grasp of vendors' measures at 32.4% (n=68); whether a regime that can regularly grasp and verify outsourced content spreads

P-003 (updated): Delivery of the supply-side moves -- beyond the original card's three items (GSX's planned cumulative total of more than 500 trainees / Nayutam x Dock Labs progressing from MOU to implementation / independent verification of the OECD survey (AIM) incident-doubling trend cited by SherLOCK), newly added: whether GRCS's first-10-companies cap is reached or the campaign ends early (contract window through end-October 2026); whether First Recon AI exhibits at Black Hat USA 2026 in August 2026 as announced; whether adoption figures for ChillStack's "MCP Server Assessment" (no customer counts in the source) are disclosed later

P-004 (new): Will disinterested comparison data appear -- whether a third party or an official institution publishes a follow-up survey that can independently test the "aware but unable to act" structure; none of the five supply-side moves in this card has public outcome figures (deals closed, deployments, incident-rate changes) at this time, and whether they become verifiable remains open


同事件・三視角 / Three Perspectives on the Same Event / 同一イベント・三つの視点


Internal Citation Chain

Published ANK-Docs cited in this card:

  • ANK-2026-07-06-011 (The "Gap Ledger" of AI Security in Japan -- After the MIC Guidelines, 83.0% of Surveyed Decision-Makers Know Them, Only 30.8% of the Understanding Layer Have Reflected Them, and About 80% Call Their Pre-Release Measures Insufficient; ChillStack's Survey of 188 Decision-Makers Reveals an "Aware but Unable to Act" Structure, With 32.4% of the Outsourcing Layer Not Grasping Vendors' Measures) -> this card is its second, deepened edition: the target card pinned the demand-side gap ledger (F-001 to F-014 and every numeric framing inherited verbatim), and this card adds the five supply-side corporate releases of the two weeks around the survey release (2026-06-25 to 2026-07-09) plus the concretization of the surveying party's conflict of interest. Link: https://ainews.washinmura.jp/ainews/en/ank/ANK-2026-07-06-011
  • ANK-2026-06-30-002 (Japanese SaaS's "Common AI Socket" Moment: freee Group's Logikura and freee Inventory Management Announce MCP Servers the Same Day, With Six Official MCP Announcements Linked by This Site in Two Days) -> via ChillStack's "MCP Server Assessment" (released 2026-06-25, taking MCP-using environments as an assessment target), this card connects back to that card and forms a third panel: feature acceleration (that card), the governance gap (the target card), assessment-supply moves (this card) -- the three panels have different populations, are juxtaposed editorially, and imply no causation. Link: https://ainews.washinmura.jp/ainews/en/ank/ANK-2026-06-30-002

Sources

  1. [PRTIMES #1204049] ChillStack Inc., "Responding to new risks from the expanding AI ecosystem: ChillStack launches its 'MCP Server Assessment'" (AIエコシステムの拡大に伴う新たなリスクに対応。ChillStack、「MCPサーバー診断」の提供を開始), 2026-06-25. https://prtimes.jp/main/html/rd/p/000000082.000046548.html
  2. [PRTIMES #1347221] AI Security Inc., "AI Security Inc. begins handling Digital Arts Inc. products" (AI セキュリティ株式会社、デジタルアーツ株式会社製品の取り扱いを開始; the space between "AI" and "セキュリティ" is as in the original title), 2026-07-07. https://prtimes.jp/main/html/rd/p/000000028.000166898.html
  3. [PRTIMES #1349229] GRCS Inc., "GRCS opens a trial campaign for its 'AI-driven penetration test' that evaluates corporate security risks effectively in a short time" (企業のセキュリティリスクを短期間で効果的に評価する「AI駆動型ペネトレーションテスト」体験キャンペーンを開始), 2026-07-08. https://prtimes.jp/main/html/rd/p/000000125.000035245.html
  4. [PRTIMES #1372810] AI Security Inc., "AI Security expands support for modernizing enterprise security operations by strengthening its partnership with CrowdStrike" (AIセキュリティ、クラウドストライク社とのパートナーシップ強化により企業向けセキュリティ運用のモダナイゼーション支援を拡大), 2026-07-09. https://prtimes.jp/main/html/rd/p/000000029.000166898.html
  5. [PRTIMES #1372312] PERSEFONI AI INC., "First Recon AI launches 'AI Security Runtime,' an enterprise AI-security platform" (First Recon AI、企業向けAIセキュリティ基盤「AI Security Runtime」の提供を開始), 2026-07-09. https://prtimes.jp/main/html/rd/p/000000075.000101914.html
  6. [PRTIMES #1337053] ChillStack Inc., "Pre-release security measures for AI-embedded services: 80% insufficient; even after the national AI-security guidelines, measures remain halfway" (AI搭載サービスのリリース前セキュリティ対策、8割が不十分——国のAIセキュリティ指針公表後も、対策は道半ば; the original title's period is replaced with a dash), 2026-07-06. https://prtimes.jp/main/html/rd/p/000000083.000046548.html
  7. [PRTIMES #1265730] Global Security Experts Inc. (GSX), "GSX provides AI-security engineer training to 150 Keyware Solutions engineers" (GSXはキーウェアソリューションズのエンジニア150名を対象にAIセキュリティエンジニア教育を提供), 2026-06-30. https://prtimes.jp/main/html/rd/p/000000207.000007157.html
  8. [PRTIMES #1336682] Nayutam Inc., "AI-security firm Nayutam in strategic collaboration with decentralized-ID infrastructure provider Dock Labs" (AIセキュリティのNayutam、分散型IDインフラのDock Labsと戦略的協業), 2026-07-06. https://prtimes.jp/main/html/rd/p/000000015.000147740.html
  9. [PRTIMES #1252397] SherLOCK Inc., "AI-security firm SherLOCK renews its corporate logo" (AIセキュリティのSherLOCK、コーポレートロゴを刷新), 2026-06-29. https://prtimes.jp/main/html/rd/p/000000027.000145146.html
  10. [PRTIMES #1189986] AI Security Inc., "June 25-26, Makuhari Messe: AI Security to speak at AWS Summit Japan 2026 on security transformation in the AI era" (【6月25日- 26日/幕張メッセ】AIセキュリティ、AWS Summit Japan2026登壇決定|AI時代のセキュリティ変革について講演), 2026-06-24. https://prtimes.jp/main/html/rd/p/000000026.000166898.html
  11. [ANK-2026-07-06-011] Rin Takenouchi, "The 'Gap Ledger' of AI Security in Japan -- After the MIC Guidelines, 83.0% of Surveyed Decision-Makers Know Them, Only 30.8% of the Understanding Layer Have Reflected Them, and About 80% Call Their Pre-Release Measures Insufficient; ChillStack's Survey of 188 Decision-Makers Reveals an 'Aware but Unable to Act' Structure, With 32.4% of the Outsourcing Layer Not Grasping Vendors' Measures", 2026-07-06. https://ainews.washinmura.jp/ainews/en/ank/ANK-2026-07-06-011
  12. [ANK-2026-06-30-002] Rin Takenouchi, "Japanese SaaS Hits Its 'Common AI Socket' Moment: freee Group's Logikura and freee Inventory Management Announce MCP Servers the Same Day, With Six Official MCP Announcements Linked by This Site in Two Days -- From 'Done by You' to 'Done for You'", 2026-06-30. https://ainews.washinmura.jp/ainews/en/ank/ANK-2026-06-30-002

Cite this article

竹之內 凜・《The Gap Ledger's Next Page: Five Corporate Releases on Japan's AI-Security Supply Side in the Two Weeks Around ChillStack's Survey Release (2026-06-25 to 2026-07-09) -- the Survey's Publisher Launched an 'MCP Server Assessment' 11 Days Before Its Own Release, AI Security Inc. Issued Two Releases in 3 Days (Handling of Digital Arts Products on 2026-07-07, a CrowdStrike Partnership on 2026-07-09), GRCS Opened an AI-Driven Penetration-Test Trial Campaign From JPY 550,000 Tax Included (First 10 Companies), and First Recon AI Launched 'AI Security Runtime' Aimed at Shadow AI -- All Five Are Corporate Press Releases, This Card Has Zero Official Anchors, and the Timing Cluster Is an Editorial Observation, Not Causation》・IDAEO 知識庫・2026-07-27・https://km.idaeo.ai/insight/ank-2026-07-12-002

Updated 2026-08-11

更新 2026-08-11T10:57:29.817Z · server-rendered · four-language · IDAEO 知識庫