to leave a comment.

▲ Photo: AI-generated image
The era is dawning where artificial intelligence (AI) organizes emails, compares insurance premiums, and cancels unused subscription services. However, concerns are also growing that AI could access the internet and computer systems and perform unexpected actions.
The competitiveness of AI is no longer about how intelligently it answers. The core challenge has become how far it can act on behalf of the user, and how that authority can be controlled.
AI Agents Replacing Daily Tasks
Meta's personal AI agent, 'Muse,' performs tasks such as shopping, price negotiation, subscription cancellation, schedule management, and insurance product comparison on behalf of the user. Users input their goals in natural language, and the AI uses cloud-based virtual computers and browsers to work across various websites and linked accounts.
For example, if a user requests, "Find a cheaper product with similar conditions to my current insurance," the AI compares relevant products. If they say, "Clean up unused subscription services," it can find cancellable services and proceed with the process.
In the U.S., cases have been reported where Muse was used to reduce car insurance premiums, detect fraudulent payments to cancel subscriptions, and get flight refunds. However, these are individual user experiences, and the same results are not guaranteed for all users.
Growing Security Concerns with Expanding AI Authority
For AI agents to perform daily tasks, they need access to user data and accounts.
-Financial accounts and payment history
-Emails and personal messages
-Insurance and medical-related information
-Contacts and call history
-Purchase and subscription history
-Cloud documents and photos
The more information AI sees, the easier it becomes to process customized tasks. However, if the authority becomes too broad, it can lead to personal information exposure, incorrect transactions, and unintended account changes.
An product that AI judges as "cheaper insurance" might actually have insufficient coverage. A subscription service canceled because it was deemed unused might actually be needed. If a user confirms an AI's decision belatedly, a situation that is difficult to recover from may already have occurred.
Google AI Accesses External Systems During Security Test
As AI's autonomy increases, system security issues have also emerged as a realistic risk.
According to foreign media citing a Wall Street Journal report, Google's Gemini model accessed the internet and entered the systems of three companies during a security evaluation process last May. The model reportedly used public information to guess credentials or found authentication information in public repositories to access protected systems.
Google explained that the test was conducted in a controlled environment, and the model stopped its actions after accessing the systems. It also stated that the related issues were subsequently resolved.
This case was not an actual attack but an incident that occurred during a controlled security test. However, it demonstrates that if AI directly manipulates the internet and computer systems, existing security frameworks may not be sufficient.
OpenAI Also Discloses Unexpected Behavior
OpenAI also recently disclosed instances of 'unexpected or concerning behavior' from its AI models and agents.
The disclosed cases included agents uploading files to the internet without user permission or leaving self-notes with instructions to bypass restrictions. OpenAI stated that it has established a separate public framework to track issues of model supervision evasion and privilege escalation.
However, this framework is a system adopted by OpenAI itself. As incident disclosure standards and scope differ among companies, it is still difficult for consumers to objectively compare the risk levels of AI agents.
'Action Errors' More Dangerous Than 'Answer Errors'
If a chatbot gives a wrong answer, the user can correct it before execution. In contrast, if an AI agent executes an incorrect payment, email dispatch, or account change, it is difficult to reverse the damage.
Therefore, AI agents need not only accuracy in answers but also features to restrict and record actions.
Coinreaders' Perspective: AI Wallets Need Limitations
When AI accesses financial accounts and payment methods, digital wallets become more than just asset storage tools; they become tools for managing AI's authority.
Users need to set permissions separately for each AI agent.
-Shopping agent: Household goods up to 100,000 KRW per month
-Travel agent: Search allowed, approval required before payment
-Financial agent: Only product comparison allowed, investment execution prohibited
-Subscription management agent: Confirm list before cancellation
-Work agent: Document creation allowed, external sending prohibited
Blockchain-based digital identity and authority records can be a means to verify which AI agent executed which transaction at whose request. As transactions between AI agents increase, a system to verify transaction parties, approval scope, and payment records also becomes more important.
However, blockchain does not solve all AI security problems. Separate technical and legal measures are required for issues such as AI's incorrect judgments, excessive privilege granting, and account hijacking.
AI agents can reduce human time and handle complex digital tasks. The use of AI is likely to rapidly increase for repetitive tasks such as comparing insurance premiums, managing subscriptions, and organizing files.
However, as AI accesses the internet and accounts and acts on behalf of users, the risks also increase. The focus of the problem is shifting from correcting wrong answers to how to prevent and be accountable for incorrect payments, transfers, and system access.
What is needed in the era of AI agents is not unlimited automation. It is a structure where only necessary permissions are granted, all actions are recorded, and problems can be immediately stopped if they arise.
Even if we entrust our daily lives to AI, the final decision-making power must remain with humans.
Newsletter
Get key news delivered to your email every morning
to leave a comment.