브레스저널 The Breath Journal

This article was translated automatically from the Korean original. Read the original in Korean

Controlling autonomous agents, now a practical task

곽동현·Published 2026-09-18 12:00 KST
NIS pursues safety evaluation, corporate access control extends to agents
Work to put fences around AI that acts on its own has begun at the same time in companies and government
Work to put fences around AI that acts on its own has begun at the same time in companies and government / ⓒ Breath Journal

Over the three days from September 16 to 18, at least six reports on the security and governance of AI agents appeared in Korea and abroad. The six reports deal with different matters. There is the National Intelligence Service (NIS) pursuing a safety evaluation, there is PNP Secure expanding its access control, and there are the calls to redesign security that IBM and OSC Korea made at an event. What they have in common is that they respond to the question of who will stop software that acts on its own without a person giving instructions at each step, and how.

An AI agent is a program that, given a single line of instruction, carries out several steps of work on its own. It searches, opens files, connects to systems, and feeds the results back in as the input for the next task. It differs from conventional automation in that no person presses a confirmation button along the way.

That difference comes back to security officers as a headache.

PNP Secure is extending the scope of access control, which had been set up for people and systems, to AI agents. Access control is a technology that defines in advance who can touch which data and blocks any attempt outside those rules. Until now, the entries on this list were employee accounts or servers. Adding agents to that list as a new entry means that software has begun to be treated as an independent actor.

Cisco, Intuit, Workday and ServiceNow are also building multi-layered management systems to monitor, control and isolate agents. Monitoring is the layer that records what was done, control is the layer that limits permissions, and isolation is the layer that cuts off an agent that has caused a problem. The published information did not say which layers each company is actually running or when they began applying them. A technology that traces the work an agent has done on the web to catch data leaks and unauthorized changes was also introduced.

Moves on the government side came in the same period. The National Intelligence Service is pursuing a safety evaluation of AI agents. Which organizations will be covered, what items will be examined, and what happens to those that fail will become clear as the evaluation system takes shape. In Washington, a fourth approach to regulating AI governance has also emerged.

Around the same time, major AI labs publicly called for slowing the pace of development and strengthening safety controls. It is a call for brakes from the side that builds the technology. There was also an assessment that a large-scale breach targeting Hugging Face took place in early July, but because it holds that 1,200 agents acted together over five days, it needs further confirmation.

The assumption that internal voluntary guidelines alone are enough is wavering. The evidence is a situation in which companies putting up their own fences and the government building evaluation standards are moving forward together.

If your company is using AI agents, you should check now which accounts those agents use and how far they can connect, and who can cut them off, and through what procedure, when they behave abnormally. Once the NIS evaluation items are released, the standards will become clearer. Until then, each company's permission list remains the only safeguard.

Kwak Dong-hyun, Reporter · Breath.Tech

Related articles

댓글