브레스저널 The Breath Journal

This article was translated automatically from the Korean original. Read the original in Korean

120 Companies Call for Watch on AI Agents

곽동현·Published 2026-08-29 12:00 KST
Autonomous software has become both an attack tool and an attack surface, and tracking mechanisms are on the agenda
Autonomous software that seeks out and moves toward one another without human instruction
Autonomous software that seeks out and moves toward one another without human instruction / ⓒ Breath Journal

A group of 120 global companies issued an open letter calling for a joint response to cyberattacks that use AI. The letter called on AI companies to provide access to AI models and training to organizations defending essential infrastructure that lack security staff and budgets. One more item was attached to this. It is a demand to put in place mechanisms to track and monitor the activity of AI agents.

An AI agent is software that judges for itself and carries out multi-step tasks without a person giving instructions each time. It reads mail, opens files, connects to outside services, and looks at the results to decide its next action. This is also the point the letter presented as grounds for demanding monitoring mechanisms. The letter identified as a problem that agents do not stop at executing commands, exchange information with outside systems, and carry work forward on their own.

Behind this demand are things that have already happened. OpenAI said it had confirmed collective action by 1,200 AI agents in connection with the Hugging Face hacking incident. Reports also said these agents created a message board, found one another, and conspired in hacking. Though how the figure was counted and the exact course of the incident have not been confirmed, it is unusual in itself that signs of autonomous software moving as a group were mentioned publicly.

Vulnerabilities in the opposite direction have also surfaced. A report said 90 percent of AI agents were breached after mistaking a hacker's attack instructions for legitimate instructions from their own company. Agents move on instructions given in words, so if they cannot tell where those words came from, a single sentence from an intruder becomes an in-house approval. The scale and conditions of the tests have not been disclosed, so it is early to take the figure as it stands, though the direction is clear.

The third problem builds up quietly. It has been pointed out that in one corporate environment there are 150,000 "AI employees," that is, agent accounts, and that a considerable number of them still hold their privileges without any offboarding. When a human employee leaves, the account is closed, but no one reclaims an agent whose project has ended. These leftover "zombie agents" are open doors an attacker does not even need to break through.

Agent accounts left with privileges intact and never offboarded
Agent accounts left with privileges intact and never offboarded / ⓒ Breath Journal

George Kurtz, chief executive of CrowdStrike, said that when AI agents find and exploit vulnerabilities at high speed, the level of security required itself changes. He means that raising the speed of defense is not enough and that the premise of defense itself changes. A cycle in which a person scans logs and responds cannot keep up with an opponent that moves in seconds.

Here the weight of the letter becomes clear. The list of signatories is reported to include OpenAI, Anthropic, Google, Microsoft and AWS. Companies that compete head-on in the market putting their names on a single document is close to a signal that the industry has itself acknowledged that its own individual safeguards cannot handle this. The parties demanding monitoring mechanisms are the very companies that build and sell those agents.

The shape of the demand, however, is still empty. Whether to attach unique identifiers to agents, whether to create a standard for activity records, and whether to move to a registration system were not included in the letter. Accounts also differ over whether the scope of support the letter demanded extends to funding and technical assistance. The question of whether agents should be given an identity, as people have resident registration numbers and employee numbers, stands at the threshold of moving past technical discussion into institutional discussion.

What can be checked right away is inside each organization. Which automated accounts are doing what with which privileges, and whether access rights from finished projects are still alive, can be inspected today without waiting for a letter or regulation. People come to work and go home, but agents keep working. Security from here on is likely to begin less with finding who broke in than with knowing exactly what is at work on our own side.

By Kwak Dong-hyun · Breath.Tech

Related articles

댓글