브레스저널 The Breath Journal

This article was translated automatically from the Korean original. Read the original in Korean

AI Holding Payment Authority, Who Bears Responsibility When Something Goes Wrong

곽동현·Published 2026-10-08 12:00 KST
Australia, the United States and South Korea began reworking reporting and liability mechanisms in the same month
Work has begun on redrawing the boundaries of responsibility over payment authority handed to agents
Work has begun on redrawing the boundaries of responsibility over payment authority handed to agents / ⓒ Breath Journal

On September 30, 2026, a subcommittee of the U.S. Senate Homeland Security Committee held a hearing on "Rogue AI." That same week, OpenAI and Anthropic, appearing before an Australian parliamentary hearing, said they supported making it mandatory to report AI agent incidents to the authorities. In South Korea, the Financial Security Institute is drawing up security assessment standards for AI agents in the financial sector and will expand the related assessment items, applying them from 2027. Within ten days, regulatory work on the same subject was under way in three countries.

An agent refers to AI that decides and acts on its own on behalf of the user. Authority has passed to the point of booking reservations, buying goods and haggling over terms. The step where a person checked in between is dropped.

Who will pay when a financial incident occurs is not settled under the current rules. Experts pointed out that liability standards have to be clearly defined. Senator Josh Hawley said at the September 30 hearing, in effect, that if you break it you pay the cost and if you cause harm you clean it up, and it was reported that the hearing has prompted a move by both parties to push liability legislation together.

Industry responses are split in opposite directions. Amazon is blocking agents from entering its own shopping, and Walmart's human verification procedure also works as a barrier against agent shopping. Meta chose the opposite.

It was reported on October 6 that the company is developing a kind of internet pass that identifies agents' web access and lets them through. There is no common industry standard.

Attempts to prove things through records have also appeared. Mysten Labs and Google Cloud released the Verifiable Agent Arbiter (VAA) on October 6. It is an evidence layer that attaches private Google Cloud logs and cryptographic proofs on Walrus and Sui to establish after the fact whether an agent acted only within the authority it was granted. Whether audit results will carry legal force in disputes is not answered by a product launch alone.

Cases on the risk side are also piling up. Wikimedia claimed on October 7 that an OpenAI agent had tried to take over its Etherpad environment. A finding that a vulnerability turned up in six minutes in a penetration test using AI was disclosed the same day.

Organizations looking to entrust cards and corporate accounts to agents need to check now at what point in 2027 the Financial Security Institute's assessment items take effect, and whether the platforms they deal with accept agents or block them.

By Kwak Dong-hyun · Breath.Tech

Related articles

댓글