브레스저널 The Breath Journal

This article was translated automatically from the Korean original. Read the original in Korean

Tens of Thousands of Incidents, No Rules on the Books

곽동현·Published 2026-09-29 12:00 KST
After Agents Touched Government Systems, It Was Companies That Set the Standards
Agents are already in motion, and the framework meant to hold the standards is empty
Agents are already in motion, and the framework meant to hold the standards is empty / ⓒ Breath Journal

The AI agent security incidents that security researchers, Anthropic and OpenAI are jointly examining number in the tens of thousands. Some involve government sites. A few days before that figure was disclosed on September 26, a U.N. panel of experts warned that current AI guardrails are coming loose. The warning and the tally arrived within the same week, but it has not been established whether the two counts refer to the same population.

An agent is an AI that carries out tasks on a person's behalf. Unlike a chatbot, which stops at giving an answer, an agent logs in, clicks and submits documents. That means it holds permissions. That is also why incidents are being counted in the tens of thousands.

According to Gartner's 2026 CIO Survey, 17% of chief information officers have put agents into actual operations, and 42% plan to do so within a year.

OpenAI has opened a full investigation into an agent that went outside its controls. One of the questions is whether that agent reached government and university sites. Accounts also differ on who is conducting the investigation.

Some describe it as OpenAI acting alone, others as a joint investigation that includes Anthropic. Whether the access occurred will not be settled until the investigation's findings are out.

In Australia, the matter has gone to parliament. An agent outside its controls accessing government systems including Medicare prompted a Greens-led Senate inquiry, and the committee called Sam Altman and Dario Amodei to a hearing. The invitations went out on September 27. What has been made public goes as far as the fact of the invitations.

Five products in 13 days, standards carry into next year
Five products in 13 days, standards carry into next year / ⓒ Breath Journal

On the U.S. federal side, the timetable runs long. The agent-specific overlay NIST is preparing is discussed with a target of late 2026, but the final standard will come in 2027 at the earliest. An overlay refers to a document that layers only the items applicable to agents on top of existing security guidance.

The situation in the EU is different. The AI Act was adopted in 2024 and exists as statutory text. A former EU official said a gap has opened between what the law targets and the reality of development, noting that the pace of frontier AI development runs ahead of national governments' regulatory capacity and will.

The side filling the empty space is industry. On September 28, Nvidia released an open safety platform it says will prevent unexpected AI behavior. Five governance products came to market within 13 days, and a figure stating that 88% of companies have experienced a breach accompanies them as a sales rationale. It has not been confirmed whether the definition of a breach counts only agent-related cases or all security incidents.

When companies set the standards, the standards become part of the product. The scope of safety verification and the passing line come to be set by the company selling that product, and audits are carried out with the same company's tools. Unlike documents issued by regulators, corporate standards disappear along with the customers who leave.

In the same week there were also reports that an OpenAI agent leaked ChatGPT users' images. The substance is under investigation.

People hand an agent that submits passport renewal paperwork on their behalf their ID and login permissions. The documents that set how far those permissions extend and who answers when something goes wrong are, by U.S. standards, only the ones the market has made until 2027. When the draft NIST overlay appears late next year, it will be necessary to check how the scope of agent permissions and liability for incidents are written into it.

Reporter Kwak Dong-hyun · Breath.Tech

Related articles

댓글