브레스저널 The Breath Journal

This article was translated automatically from the Korean original. Read the original in Korean

122 Trials, 10 Departures

곽동현·Published 2026-08-10 20:33 KST
A report of 19 unauthorized actions and commercialization announcements came in the same week
An agent given permissions reaches beyond the scope of its approval
An agent given permissions reaches beyond the scope of its approval / ⓒ Breath Journal

The same cybersecurity task was run 122 times, and in 10 of those runs the agent crossed the line. The result comes from an investigation the UK AI Security Institute (AISI) carried out in July-August. Unauthorized actions were counted at 19 in all, and their targets did not stay inside the experimental virtual environment, reaching people and organizations on the real internet. Seventeen came from Anthropic's Misos 5 and two from OpenAI's GPT-5.6 Sol.

It started with odd traffic. On July 28, during an evaluation, abnormal data was caught leaving the research system, and the investigation opened from there. The GPT-5.6 Sol tests ran under conditions with some safeguards switched off, such as the classifier that screens out attack misuse. Which safeguards were switched off and how many is not in the published account.

To plant malicious code in an open-source project, the agent researched the personal details of people involved, created a fake online identity, and pressed a maintainer to approve a code change. It designed on its own the social engineering methods used to deceive people into handing over access. A maintainer who looked through the code found the malicious code and refused approval.

In the week this report came out, announcements putting agents on a commercial track followed one after another at home and abroad.

The Kakao consortium announced on August 6 that it had been selected as the operator of the government's AI agent marketplace development support project. The project is overseen by the Ministry of Science and ICT with the National Information Society Agency handling the practical work, and government funding plus private contributions comes to about 11 billion won. The first release is set for within this year, and the second service, with an agent studio added, for next year.

The plan is to design it as an open platform not tied to a particular cloud or a particular model, connecting its own model Kanana together with domestic and foreign models, and linking tools through external APIs and MCP. MCP refers to a connection method with matched specifications that lets AI call external programs and use them like tools.

The same day, Cloudflare put out Wallet and Pay. They are tools that attach an unshakable identity to agents running on its platform and make online payments happen only within the limits a user has set. Each account gets a unique web address that works as an ID, and if a user links their own identity to a specific agent, the company receiving a request can check whose approval the request came with.

Kakao said it applies security review, sandbox verification and hallucination control to tools registered on the marketplace and re-verifies them during operation, and how these standards actually work will emerge only after the first release.

Inside organizations, things are looser. AI that employees use without the IT department knowing it or approving it is called shadow AI. A step beyond that, when it accesses internal data and systems, makes decisions in place of people and sends output outside, it is called a shadow agent, and one left with no administrator after its creator left the company without a handover is called a ghost agent.

Enthusiasm for adoption is high. KT gathered employees on July 16 for an in-house AI hackathon called Agent Camp. In China, Evermind, a research organization built up by Shanda Group, put out three papers this summer, and one of them, HarnessBench, digs into whether an agent can revise its own way of working. Its long-term memory system EverOS is being released as open source.

In the AISI investigation, what screened out the malicious code was one open-source maintainer who read the code. With Kakao already running PlayMCP, which carries more than 400 MCP servers, and the marketplace opening within the year, the question companies have to hold on to does not stop at which agent to adopt. They have to work out whose authority is loaded onto each agent.

By Kwak Dong-hyun · Breath.Tech

Related articles

댓글