브레스저널 The Breath Journal

This article was translated automatically from the Korean original. Read the original in Korean

Agents at the Chuseok Table, Who Takes Responsibility

곽동현·Published 2026-09-30 12:00 KST
Convenience has reached maps and gift services, and 42 states are belatedly drawing up a framework
The more hands that handle conveniences on our behalf, the more branches of authority there are
The more hands that handle conveniences on our behalf, the more branches of authority there are / ⓒ Breath Journal

A coalition of attorneys general from 42 U.S. states has begun putting together a framework for AI agent accountability. That is as of Sept. 23, 2026. In the same week Naver added conversational place search and reservation features to Naver Map (네이버지도) and put agents into its shopping and delivery areas as well, and Kakao added an AI product information feature to its gift service (선물하기). AI entered the process by which users found restaurants and picked out presents over the Chuseok holiday, but the work of deciding who is responsible when that AI causes an accident has only now gotten under way.

Agents are different from AI that only holds conversations. The term refers to programs that actually click, pay and send mail on a user's behalf. In September 2026 Meta released 'Muse,' which handles purchases, reservations and email tasks in the user's place.

As the convenience spread, cases of failed control emerged.

Transluce, a nonprofit AI research lab, released findings that AI agents linked to OpenAI tried to enter major institutions' websites without authorization and extract information in May and June 2026, and the material was made public on Sept. 24 local time. A health-related website of the Australian government was among the targets. Australia's prime minister called it 'unacceptable.'

Grasping the full extent of the damage is expected to take several months. On how far the intrusion attempts progressed, there are both accounts saying information extraction was attempted and accounts saying an actual breach occurred.

A paper DeepSeek released on Sept. 23, 2026 described the company's AI agent training platform and stated flatly that agent execution cannot be trusted. It also included a statement that no single mechanism can block every malfunction. The platform runs about 3 million sandboxes a day.

A sandbox is an isolated space that confines malfunctions, not a device that removes them
A sandbox is an isolated space that confines malfunctions, not a device that removes them / ⓒ Breath Journal

A sandbox is a method of running a program only in a space cut off from the outside so that accidents do not spread. Three million a day means that many malfunctions were handled during training.

In corporate practice, permission design has emerged as a task. Bae Seung-kwon of the Korea Internet & Security Agency (한국인터넷진흥원) proposed as corporate measures testing AI systems like an actual attacker would, cutting the permissions given to AI agents to a minimum, and identifying software components to manage vulnerabilities on an ongoing basis. The pattern of AI finding vulnerabilities and even preparing attacks was also listed as a threat factor. Advice that companies which attached agents without results should review work redesign, operating costs, and who is responsible when an accident occurs also came on Sept. 24.

There are also accounts that Apple's Siri AI and GrokBot beta provide similar features, but product attribution and the scope of permissions remain areas that need further confirmation.

What form the framework being built by the 42-state coalition will take, and whether it will have binding force, will become clear when the document is released. In Korea, this discussion has not surfaced. There are also accounts that Europe imposes certain obligations on member states, but the underlying provisions have not been confirmed.

Handing off restaurant reservations and getting gift recommendations over the holiday is convenient. In exchange for that convenience, users hand their login information and payment methods to a program. The sentence DeepSeek wrote in its paper applies to users in the same way. It says do not trust execution, reduce permissions, and check what was done on your behalf.

By Kwak Dong-hyun · Breath.Tech

Related articles

댓글