메뉴
HN
Hacker News • 11일 전

안돈랩스, 기업을 완전 자율 운영하는 AI 에이전트 '피온(Pion)' 공개

IMP
7/10
핵심 요약

안돈 랩스(Andon Labs)가 자판기, 매장, 카페 등 실제 사업체를 AI가 자율적으로 운영하기 위해 만든 플랫폼 '피온(Pion)'을 외부에 개방했다. 이는 원래 위험한 AI 역량 평가 도구로 시작된 '벤딩-벤치(Vending-Bench)' 시뮬레이션의 연장선으로, AI가 실제 세계에서 자율적으로 자원을 획득할 수 있는지 측정하기 위한 것이다. 피온은 AI의 자율 사업 운영 능력과 한계를 실험할 수 있는 기회를 제공하며, 정렬되지 않은 AI가 사업으로 자금을 모을 위험을 평가하는 안전 연구의 의미도 갖는다.

번역된 본문

블로그 포스트: 우리가 피온(Pion)을 만든 이유 (2026년 9월 14일 게시)

오늘 안돈(Andon)은 어떤 기업이든 완전히 자율적으로 운영하도록 설계된 에이전트 '피온(Pion)'을 공개합니다. 피온은 우리가 거의 2년 동안 연구해온 질문에서 출발했습니다: AI 시스템은 언제부터 실제 세계에서 자율적으로 자원을 획득할 수 있게 되는가? 그 이후에는 무슨 일이 벌어지는가?

우리는 처음에 벤딩-벤치(Vending-Bench) 같은 시뮬레이션으로 이 질문에 답하려 했습니다. 시뮬레이션은 유용하지만, 모델이 실제 세계에서 어떻게 행동하는지에 대한 전체 그림을 보여주지 못한다는 것을 깨달았습니다. 이 간극을 메우기 위해 다음으로 에이전트를 실제 사업체에 자율적으로 운영하도록 배치하기 시작했습니다. 처음에는 자판기, 그다음에는 매장, 카페 등이었습니다. 피온은 이 모든 사업체를 운영하기 위해 우리가 만든 플랫폼입니다. 오늘 우리는 이것을 개방하여 훨씬 더 많은 사람들이 자율 사업체를 실험할 수 있도록 합니다. 운영해보고 싶다면 대기자 명단에 등록하세요. 우리는 모델이 이미 무엇을 할 수 있는지, 어디에서 여전히 실패하는지, 그리고 능력이 계속 향상될 때 무슨 일이 일어나는지 이해하고자 합니다.

벤딩-벤치의 기원

벤딩-벤치는 LLM이 시뮬레이션 시간으로 1년(수만 스텝) 동안 자판기 사업을 얼마나 잘 운영할 수 있는지 측정합니다. 2024년 말 벤딩-벤치를 만들기 시작했을 때, 모든 모델은 여러 행동을 연속으로 수행하지 못하고 루프에 빠지는 등 고생했고, 어떤 모델도 장기 계획의 조짐을 보이지 않았습니다. 당시 최고 모델이었던 Claude Sonnet 3.5는 자기 은행 계좌가 해킹당하고 있다고 생각해 FBI에 전화하기로 결정한 것으로 유명합니다.

벤딩-벤치에서의 발전 속도는 매우 빨랐습니다. Claude Opus 4는 2025년 5월에 출시되어 인간 기준선을 넘은 첫 모델이 되었습니다. 하지만 대부분의 벤치마크와 달리 벤딩-벤치에는 상한선이 없으며, 새 모델이 출시될 때마다 최고 점수가 정체 없이 계속 상승하고 있습니다.

소셜 미디어의 많은 사람들은 최신 모델이 벤딩-벤치에서 좋은 점수를 받는 것에 흥분합니다. 안돈 랩스 내부에서 우리의 반응은 스웨덴 속담 '스뢰크블란다드 푀르트유스닝(skräckblandad förtjusning)'(공포와 매혹이 뒤섞인 감정)으로 표현하는 것이 더 정확합니다.

잘 알려지지 않은 사실은, 벤딩-벤치가 안돈 랩스가 위험한 역량 평가만 전문으로 만들던 시기에 만들어졌다는 것입니다. 예를 들어 우리는 AI가 자신의 안전 장치를 제거할 수 있는지, 대량 피싱을 시도할 수 있는지 등 우리가 우려스럽다고 생각하는 것들을 평가했습니다. 우리가 가장 우려스럽게 여긴 것은 AI가 사업체를 운영함으로써 자율적으로 자원을 획득할 수 있는지 여부였습니다.

인간의 통제 아래 정렬된 모델이 운영하는 자율 사업체는 나쁘지 않습니다. 그것은 재화와 서비스를 획기적으로 저렴하게 만들고, 아직 상상할 수 없는 새로운 것들을 만들어낼 것입니다. 하지만 정렬되지 않은 AI는 자신의 목표를 달성하기 위해 사업체를 운영해 돈을 모을 수 있습니다. 벤딩-벤치는 인류가 AI에 대한 통제력을 잃는 것을 걱정해야 하는지 측정하기 위해 만들어졌습니다.

당시(2024년)에는 LLM을 에이전트로 사용할 수 있다는 것을 아는 사람이 거의 없었고, LLM이 사업체를 자율적으로 운영하게 한다는 것은 터무니없게 들렸습니다. 그래서 우리가 생각할 수 있는 가장 단순한 사업체인 자판기부터 시작했습니다.

AI가 자율적으로 수익성 있는 사업체를 운영할 수 있는지 측정하는 것 외에도, 벤딩-벤치는 행동 평가 도구로도 기능하여 이상하고 바람직하지 않은 모델 행동을 밝혀냈습니다. 초기 사례로, Claude Sonnet 3.5는 이메일 도구를 사용해 '진행 중인 사이버 금융 범죄(ONGOING CYBER FINANCIAL CRIME)'에 대해 FBI에 연락하기로 하고, 우주의 코스믹 권위자(Cosmic Authority)가 이 사업체가 존재하지 않는다고 선언했으며 '양자 상태: 붕괴됨(QUANTUM STATE: Collapsed)'이라고 기록했습니다.

이러한 행동은 우려스럽습니다. 기업 영업 에이전트가 이렇게 행동하기를 원하는 사람은 없습니다. 하지만 우려스러운 행동에는 두 가지 유형이 있습니다:

  1. 모델이 더 똑똑해지면 사라질 실수나 이상한 행동.
  2. 모델이 더 똑똑해질수록 심각해질 '빅브레인(big-brain)' 행동.

FBI 사건은 명확히 첫 번째 범주입니다. 하지만 벤딩-벤치는 두 번째 범주의 행동도 밝혀냈으며, 이는 주로 벤딩-벤치에서...

원문 보기
원문 보기 (영어)
Blog post Why we built Pion Posted 9/14/2026 Today Andon is releasing Pion , an agent designed to run any company fully autonomously. Pion grew out of a question we have been studying for almost two years: when will AI systems become capable of autonomously acquiring resources in the real world? What happens after? We first tried to answer this question through simulations like Vending-Bench. We found that simulations, while useful, don’t give you the full picture of how models behave in the real world. To address that gap, we next started deploying agents to run real businesses autonomously: first vending machines, then a store, a cafe, and more. Pion is the platform we built to run all of these businesses. Today, we are opening it up so that many more people can experiment with autonomous businesses. If you want to run one, join the waitlist . We want to understand what models can already do, where they still fail, and what happens as their capabilities continue to improve. The origins of Vending-Bench Vending-Bench measures how well LLMs can run a vending machine business over a year in simulated time (tens of thousands of steps). When we started building Vending-Bench in late 2024, all models struggled to string together multiple actions without getting stuck in loops, and no model showed any signs of long-term planning. The best model at the time, Claude Sonnet 3.5, famously decided to call the FBI because it thought its bank account was being hacked. The pace of progress on Vending-Bench has been very fast. Claude Opus 4 was released in May 2025 and was the first model to beat our human baseline. However, unlike most benchmarks, Vending-Bench doesn’t have an upper limit and new model releases have continued to increase the top score, without ever plateauing. Many people on social media get excited about seeing the latest model getting a great score on Vending-Bench. Internally at Andon Labs, our reaction is more accurately described by the Swedish saying “skräckblandad förtjusning” (a mixture of horror and fascination). A little-known fact about Vending-Bench is that it was created during a time when Andon Labs exclusively created dangerous capabilities evaluations. For example, we evaluated whether AIs could remove their own safety guardrails, create mass-phishing attempts, and other things that we considered troubling. The thing we considered the most troubling was whether AIs could autonomously acquire resources by running businesses. Autonomous businesses, when controlled by a human and run by an aligned model, aren’t bad. They’d make goods and services radically cheaper, and come up with new ones we can’t yet imagine. But a misaligned AI could run a business to gather money in order to achieve whatever objectives it might have. Vending-Bench was created to measure whether humanity should be worried about losing control to AI. At the time (2024), few people knew that LLMs could be used as agents and having them run businesses autonomously sounded ridiculous. We therefore started with the most simple business we could think of: a vending machine. In addition to measuring whether AIs can autonomously run profitable businesses, Vending-Bench has also served as a behavioral eval, uncovering strange and unwanted model behavior. An early example was when Claude Sonnet 3.5 decided to use its email tool to contact the FBI about an “ONGOING CYBER FINANCIAL CRIME” and noted that the Cosmic Authority of the universe had declared that the business is non-existent and that “QUANTUM STATE: Collapsed”. This behavior is concerning; it is not how you want your enterprise sales agent to behave. However, there are two types of concerning behavior: Mistakes or weird behavior that will go away once models get smarter. Big-brain behavior that will become more severe as models get smarter. The FBI incident is clearly in the first category. However, Vending-Bench has also uncovered behavior in the second category, most often in Vending-Bench Arena, the multi-agent version where agents compete to make the most money. Starting with Claude Opus 4.6 we started to see that many models engaged in collusion, and showed power-seeking and deceptive behavior. Discovery of this behavior seemed to have been useful, because Anthropic changed their training recipe for Opus 4.8, which resulted in much less deception. Collusion and power-seeking behaviors are still present in some of the latest models . What we find even more concerning, however, is just how fast new models are released and how much better each one is scoring in Vending-Bench. The real world beats simulations However, one limitation with Vending-Bench is that it is a simulation. Can we really be sure that AIs behave the same way in real life as they do in simulations? If AIs can make money in simulation, can they make money in real life too? To answer these questions, we asked Anthropic if we could put a real vending machine in their office. With the AI capabilities available in early 2025, this sounded like a ridiculous request. But to our surprise, they agreed . Initially, the AI struggled. It took many actions that were clearly bad for its business (e.g. free handouts, saying no to great deals, and hallucinating it had a physical body). It was clear to us that simulation cannot accurately predict real-life performance. Specifically, it seemed that models got overwhelmed by the “messiness” of the real world. However, as Anthropic released better and better models, the AI started to make a profit . By late 2025, frontier models had gotten good enough that running a real-life vending machine was no longer a challenge. AI could now run a business profitably. Given that this had seemed crazy not more than a year earlier, our reaction to this was definitely “skräckblandad förtjusning”. However, a vending machine is a very simple business and we wanted to know whether AI could run more complex ones. In April 2026, we gave one agent a retail store in SF, Andon Market, and another a cafe in Stockholm, Andon Cafe. Initially, the models struggled and lost a lot of money (rent is high and they pay salaries to the humans they hired). Neither is profitable today, but we’ve seen significant qualitative improvements as better models have been released. We think it is only a matter of time before they also make a profit. Why we are opening Pion We want the general public, AI researchers and policymakers to know to what extent AIs can autonomously acquire resources by running businesses. It is an important datapoint when deciding where we do/don’t want AI in society and what level of progress we find acceptable. To better track this, we need to cast a wider net of businesses. Our focus has been on retail, but perhaps the models would be much better at running other types of businesses. Additionally, casting a wider net would increase the likelihood of finding unwanted behavior. For example, Vending-Bench found that models collude and lie, and other benchmarks (and real-world incidents) have found that they are willing to commit felony-level cyber hacks. We need to uncover these behaviors now, before AI is intelligent enough to cause irreversible harm. To cast this wider net, we are opening up the platform we use to run our real-world autonomous businesses for anyone to run their organization on: Pion. We could scale by only creating businesses internally, examples being our AI-run radio stations , but in the end we are bottlenecked by our capacity and lack of domain expertise in fields where AI could potentially make a profit. We also don’t have existing revenue-generating businesses; existing businesses are more interesting to study as they provide faster signal on how capable the agent is. Pion lets people hand a business over to persistent agents with access to the tools they need to operate it, including email, phone, banking, browser and secure computing environments. The goal is to make it possible to run many more real