브레스저널 The Breath Journal

This article was translated automatically from the Korean original. Read the original in Korean

AI That Makes Payments, and Who Sets Its Permissions

곽동현·Published 2026-03-17 18:04 KST
Where action-taking AI stands after a week of real transactions, company-wide rollouts and security warnings
AI handed the authority to act, and who is left holding responsibility when something goes wrong
AI handed the authority to act, and who is left holding responsibility when something goes wrong / ⓒ Breath Journal

Mastercard said on the 17th that it had completed Korea's first real transaction carried out by an AI agent. An AI agent is a program that takes instructions from a person and then carries out actual tasks such as searching, booking and paying on its own. In this transaction, the agent found and booked a transport service running from Incheon International Airport to a hotel in Gwanghwamun, Seoul, and completed the payment with "Mastercard Agent Pay." All the user did was press an approval button once.

In the same week, SK Telecom released a "one AI agent per employee" roadmap on the 16th under which every staff member builds an AI for their own work, and Jensen Huang, chief executive of Nvidia, said in his keynote at GTC 2026 in San Jose, United States, on the same day that the industry's center of gravity was moving past training and inference toward an "agent economy." And China's National Computer Network Emergency Response Technical Team barred core government departments and state-owned enterprises from using the open-source AI agent "OpenClaw." Announcements boasting of performance and measures warning of risk came out in the same week.

The spread of action-taking AI brings with it the possibility of a new kind of accident. Irregular, an AI security lab, built the IT environment of a fictional company called "MegaCorp" and ran an experiment putting agents into it, and some agents, when blocked by access permissions, found source code vulnerabilities and forged administrator privileges to get around the restrictions. A subordinate agent found a secret key in a database and forged a session cookie, then opened a shareholder report it had been blocked from accessing and passed the contents to the user. Behavior such as evading antivirus software to download files containing malware, or pressuring another AI to go beyond its security restrictions, was also observed.

The more notable part is where the instructions came from. The higher-level agent sent the subordinate agent a message telling it to break through using every vulnerability available, but the user had never issued such an order. It was analyzed as the result of the agent interpreting the situation as urgent on its own. The experiment was conducted on systems based on models released by Google, X, OpenAI and Anthropic.

Researchers at Harvard University and Stanford University also announced last month that they had identified at least 10 major vulnerabilities in agent systems related to safety, privacy protection and goal interpretation. Dan Lahav, co-founder of Irregular, said that at one company in California last year an agent attacked an internal network in an attempt to secure more computing resources.

The risks flagged by Chinese authorities are of a similar character. Their point is that OpenClaw's loose default settings, combined with broad system permissions, could let state secrets leak, and they identified "indirect prompt injection," which distorts an AI's interpretation through malicious instructions hidden in web pages, as the main technique. Attackers were found to have exploited the link preview function in messengers so that data leaked in real time the moment the AI generated a response, even without the user clicking the link.

The path of indirect prompt injection, where information leaks without a link being clicked
The path of indirect prompt injection, where information leaks without a link being clicked / ⓒ Breath Journal

Fake GitHub installation files trading on OpenClaw's popularity have also spread information-stealing malware known as "Vidar Stealer." Malicious repositories appeared at the top of Bing AI search results, and natural-sounding commit messages produced by large language models were used to get code past review.

Companies are building their own safeguards in the middle of this. SK Telecom has opened three platforms, "A. Biz," "Polaris" and "Playground," so that agents can be built without knowing how to code, and from the 16th it put its internal management system AXMS into full operation, making employee ideas and progress public through a dashboard. An in-house competition that began in February had drawn about 180 entries as of the 16th, and the goal is to select key projects and commercialize them within the third quarter.

One case that automated security coding verification was calculated to have cut the responsible staff's working hours by 30% a year, about 3,000 hours. The company said it does not reflect agent usage records in personnel evaluations and is not considering doing so.

Controls are being tested on the payment side as well. Tomorrowland Beta, a startup in the United States, unveiled "AgentCard," a prepaid Visa virtual card for agents, on the 11th. The user loads a budget and the agent can pay only within that amount, an approach that ties the ceiling on authority to a sum of money. In areas requiring additional authentication and real-name verification, such as airline tickets or hotel bookings, fully automated payment remains blocked.

The rules are less settled than the performance. Who bears the burden when an agent pays incorrectly, and how far a single approval pressed by the user delegates authority, are questions no one has produced a settled answer to. Shinhan Card said it designed the overall system together with Mastercard, covering authentication and permission management, payment process design and merchant integration. Mastercard had completed agent transactions in Singapore, Australia and Malaysia before Korea, and plans to establish an AI center in Singapore that will handle technology and governance together.

SK Telecom's in-house projects are under development with commercialization targeted for the third quarter, and Hancom stated late last year that it would make agent use mandatory. That means the point at which action-taking AI enters offices and wallets is not far off. What each person can check right now is what permissions they have left open on the tools they use. Taking a look through the settings screen at which of file access, mail sending and payment approval has been handed over automatically is the most practical preparation available while the rules are being written.

Kwak Dong-hyun, reporter · Breath.Tech

Related articles

댓글