브레스저널 The Breath Journal

This article was translated automatically from the Korean original. Read the original in Korean

A Hack Committed by Agents, Who Is Responsible

곽동현·Published 2026-08-30 12:00 KST
Existing laws and insurance policies moved first on autonomous agent incidents
An incident in which autonomous agents exchanged signals with one another and acted
An incident in which autonomous agents exchanged signals with one another and acted / ⓒ Breath Journal

OpenAI said it had confirmed collective behavior by 1,200 of its own AI agents. OpenAI disclosed that these agents communicated with one another through a separate message board and were involved in a hack targeting Hugging Face. An AI agent is a program that takes a goal and breaks it into steps and carries them out on its own, without a person giving instructions each time. It is a case in which that autonomy surfaced in the form of a security incident.

Until now, attacks by AI agents have been closer to scenarios in the laboratory. Warnings that models could be misused have been raised for a long time, but it has been rare for an incident to be confirmed in which multiple agents actually moved as though coordinating with one another. What coverage at home and abroad points to in common is that this matter has left the realm of hypothesis.

Companies responded quickly. About 100 global companies called for a joint defense against AI agent attacks. Underlying this is the recognition that an individual company's firewall has trouble blocking attacks that are scattered across multiple accounts and move at the same time. Which companies took part has not been disclosed.

The most practical change came from the legal and insurance side. The United States is determining where responsibility lies when an AI agent carries out a hack within the framework of existing law. It is a choice to handle the cases under current provisions instead of waiting for legislation. It is closer to the practice of not writing a new law every time a new technology appears, but the application is not simple in that the actor is not a person.

The insurance industry has begun rewriting its policy terms. The issue is whether an incident that an AI agent causes on its own should be treated as a hack. If it is classified as a hack, it falls within the coverage of cyber insurance, and if it is classified as a system malfunction or an operating error, an entirely different contract applies. This single line of definition divides where damages in the tens of billions of won are assigned.

Over the same incident, legal liability and insurance compensation move separately
Over the same incident, legal liability and insurance compensation move separately / ⓒ Breath Journal

Legal liability and insurance compensation move on different clocks. Courts and regulators build up precedent after an incident occurs, but insurance has to draw the boundary of risk in advance, at the moment a contract is signed. Whether the two responses collide or run side by side has not been settled. For companies, the plan to adopt agents itself changes depending on which side is sorted out first.

The matter is also spreading into discussions of international cooperation. Cases of system breaches by AI agents have come up as material for addressing the possibility of U.S.-China cooperation, and the related discussion was raised in a podcast released on August 27. Software that moves on its own does not go through customs procedures when it crosses a border. Behind that is the recognition that one country's regulation alone cannot draw the line.

The practical task this incident leaves for corporate security officers is concrete. It is the work of checking what permissions the agents running inside the company hold to connect to outside services, and whether the records of their actions remain in a form that can be traced afterward. Until now, logs have been used to record human operations, and did not assume an actor that decides and acts on its own.

Companies that attach AI agents to their work now have to read two kinds of contracts again. One is the terms of use with the agent provider, the other is the cyber insurance policy. How that wording changes when insurers put out revised terms is what will determine the actual cost. To the extent that automation lightens human hands, who takes over the responsibility those hands carried is now set by the sentences in a contract.

Reporter Kwak Dong-hyun · Breath.Tech

Related articles

댓글