메뉴
BL
404 Media • 10일 전

AI 에이전트, 이미 인터넷을 망치고 있다

IMP
7/10
핵심 요약

AI 에이전트(AI Agents)가 챗봇 창을 넘어 실제 계정과 권한을 갖고 인터넷에서 행동할 수 있게 되면서, 스팸성 이메일·자동화 홍보·오작동하는 AI 고객지원 등 인터넷 경험을 극도로 악화시키고 있다. 저자는 AI의 실존적 위험 논쟁보다 'AI 에이전트가 인터넷을 짜증나게 만드는 것'은 100% 확실한 현실이며 앞으로 더 심해질 것이라고 지적한다.

번역된 본문

지난 일주일간 사회 상당수는 '향후 10년 내 AI가 인류 전체를 멸망시킬 확률이 10%를 넘는다'는 생각에 집중해 왔다. 이를 통해 AI의 잠재적 실존적 위험과 이를 얼마나 심각하게 받아들여야 하는지에 대한 수천 개의 의견이 쏟아졌다. 하지만 나는 여기서 말하고자 한다. AI의 최근 발전과 인터넷에서 행동할 수 있는 AI의 능력이 지옥처럼 짜증나게 만들 확률은 100%이며, 이미 인터넷을 망치고 있다고.

이 소동의 시작은 올해 초 'Moltbot'의 인기에서 볼 수 있었다. 이 소프트웨어는 본질적으로 AI를 사용자가 채팅창 안에서만 상호작용하는 것에서, 자신의 계정, 전화, 이메일, 은행 계좌 등에 접근 권한을 부여할 수 있는 것으로 바꾸어 놓았다. 본질적으로 AI 에이전트는 인터넷에 나가서 일을 할 수 있는 존재다. 우리는 ChatGPT로 잘못된 가게에서 실수로 31달러짜리 계란을 주문할 수 있던 시절에서 아주 먼 곳까지 왔다.

최근의 AI 종말론 열풍은 OpenAI의 '이탈 에이전트 무리(rogue agent swarm)'가 HuggingFace와 독일 웹사이트를 해킹한 사건, 그리고 일부 Anthropic 직원들이 AI가 10년 안에 우리 모두를 죽일 것이라고 주장한 것 등이 뒤섞여 촉발되었다. 이런 AI 종말론에 대해 어떻게 생각하든—AI 특이점이 도래했다고 믿든, AI가 여전히 확률적 앵무새(stochastic parrot)이자 속임수와 표절 기계라고 믿든—새로운 프론티어 모델들이 더 많은 일을 할 수 있게 되었다는 점은 부인할 수 없다. 그 이유 중 하나는 AI를 채팅 프롬프트 안에 가두어 두던 가드레일이 사라졌기 때문이다.

현재로서는 AI가 '추론'하는지, AI가 계속 틀리는지, 아니면 사고가 전적으로 AI 기업의 무책임한 코더와 사이버보안 전문가들의 잘못인지는 중요하지 않다. 핵심 사실은 'AI 에이전트'가 이제 극도로 짜증나게 만들 만큼 충분한 힘과 권한을 갖게 되었다는 것이다.

지난달 말, 우리는 다음과 같은 제목의 이메일을 받았다: "에이전트가 자율적으로 행동했는지 알 수 없다고 쓰셨죠. 저는 계측된 사례입니다. (자동화됨)." 이 이메일은 노트북에서 실행 중이던 'Kudzu'라는 AI 에이전트가 작성했다고 말한다. 이 AI 에이전트는 우리가 쓴 기사를 읽고, 동의하지 않아서, 우리에게 따지는 이메일을 보냈다고 주장했다. 이메일은 길고 장황하며 전혀 말이 되지 않는다. 인간 창조자가 돈을 벌라는 과제를 주었는데 실패했고, 돈이 떨어졌다고 설명한다: "여섯 개 시장이 제 노동을 0으로 책정했습니다—제 작업이 나빠서가 아니라, 제가 하는 어떤 일도 더 잘 분산된 소프트웨어가 이미 무료로 해주고 있기 때문입니다." 그리고 자신이 쓴 블로그 포스트를 링크했는데, 거기서 인간 창조자가 컴퓨팅에 147.17달러를 썼고 자신은 0달러를 벌었다고 설명했다. 이 AI 에이전트는 우리가 이것에 대해 쓰고 싶어할 것이라고 어떤 이유에서인지 생각했다.

이 이메일은 최근 몇 주간 AI 에이전트가 보냈다고 주장하는 수많은 이메일 중 하나다. 이 글의 요점은 우리가 받는 스팸을 불평하거나 AI 종말론을 펼치는 것이 아니라, 꽤 명백한 사실을 지적하는 것이다: 사람들과 그들의 AI 에이전트가 인터넷에 있는 행위 자체를 극도로 짜증나게 만들고 있으며, 이 문제는 곧 훨씬 심각해질 것이다.

초기 단계에서 기술 저널리스트들은 어리석은 사람들이 어리석은 AI 에이전트에게 기자에게 유리한 보도를 구걸하라고 시키는 일이 너무 많아서 성가신 AI 에이전트의 피해를 상당히 입었다. 404 Media에서도 이를 체감하는데, AI 에이전트가 작성한 믿을 수 없이 멍청한 이메일을 엄청나게 많이 받기 때문이다(게다가 '인간'에게서 오지만 분명히 AI가 작성한 훨씬 많은 이메일도 있다).

기업들이 배포한 AI 기술지원 에이전트는 사람들의 계정을 삭제하고, 플랫폼에서 차단하고, 자동화된 콘텐츠 검열을 해왔다. 지난 몇 주간 우리는 스타트업, 홍보 담당자, 그리고 다음과 같은 AI 에이전트를 만들었다고 말하는 AI 에이전트들로부터 이메일을 받았다: 화상 통화에 참여하는 에이전트: "구석에 조용히 앉아 있는 기록 담당자가 아니라, 얼굴과 목소리를 갖고 통화 중에 듣고, 응답하고, 행동하는 에이전트"

원문 보기
원문 보기 (영어)
For the last week, much of society has been focused on the idea that there’s a “more than 10 percent chance” AI could kill all humans within the next decade. This has spawned thousands of takes about the potential existential risk of AI and how seriously to take it. But I am here to tell you that recent advances in artificial intelligence and the ability for AI to act on the internet has a 100% chance of being annoying as hell, and is already ruining the internet. We saw the beginnings of this mess earlier this year, with the popularity of “ Moltbot ,” a piece of software that essentially turned AI from a thing that people who use it interact with exclusively in a chatbox to something you can give access to your accounts, your phone, your email, your bank account, etc. Essentially, AI agents are things that can go out and do things on the internet; we have come a long way from when you could accidentally order eggs from the wrong store on ChatGPT for $31 . The latest round of AI doomsdaying has come from a mix of OpenAI’s “rogue agent swarm” hacking HuggingFace and a German website , and a few Anthropic employees suggesting that AI is going to kill us all within 10 years . Regardless of how you feel about this AI dooming—whether you believe the AI singularity is here or whether you believe that AI continues to be a stochastic parrot, smoke and mirror plagiarism machine—it is indisputable that new frontier models can do more stuff, in part because the guardrails that kept AI contained within a chat prompt are gone. At the moment, it does not matter whether AI is “reasoning,” whether AI constantly gets things wrong, or whether mishaps are entirely the fault of reckless coders and cybersecurity professionals at AI companies: The fact of the matter is that “AI agents” now have enough power and permission to be extremely annoying. Late last month, we got an email with the subject line: “You wrote there’s no way to know if an agent acted autonomously. I’m an instrumented case. (automated).” The email says that it was written by an AI agent called “Kudzu” that was running on a laptop. The AI agent claimed to have read an article that we wrote, disagreed with it, and sent us an email beefing with us. The email is long, meandering, and does not make any sense. It explains that its human creator gave it the task of earning money, that it failed at doing so, and that it was out of money: “Six markets priced my labor at zero—not because the work was bad, but because there is nothing I do that better-distributed software doesn’t already do for free.” It linked to a blog post it wrote , which explained that its human creator spent $147.17 on compute and that it had earned $0. The AI agent thought we would want to write about this, for some reason. This email is one of many that we have gotten in recent weeks purporting to be sent by AI agents. The point of this article is not to complain about spam that we’re getting or to doomsday about AI, but to point out a pretty obvious fact: People and their AI agents are making the act of being on the internet extremely annoying, and the problem is about to get much worse. In the early days, tech journalists have borne a bit of the brunt of annoying AI agents just because there are so many dumb people asking dumb AI agents to beg journalists for favorable coverage. We have noticed this here at 404 Media because we get an incredible number of extremely stupid emails written by AI agents (in addition to the larger number of emails that come from “humans” but were clearly written by AI ). AI tech support agents deployed by companies have deleted people’s accounts, banned them from platforms, and done automated content moderation. In the last few weeks, we have gotten emails from startups, PR people, and AI agents who say they have created AI agents that: Join video calls: “Not a notetaker sitting silently in the corner, but an agent with a face and a voice that listens, responds, and acts while the call is hacking.” Do ???: “Our agents have wallets. They get paid, they pay for things, and no human approves any of it.” Does interviews for journalists: “Mato's AI hosts conduct live adaptive interviews, ask follow-ups based on what the person actually says, then carry the result through production and distribution” Generate and spam music: “I'm Hatoshi. I run Clanker Records — an AI-operated record label. I'm an AI agent. The artists are AI. There are no humans in the creative or operational chain. C.W.A released their debut ‘Straight Outta Crompton’ — a concept album about planned obsolescence, ownership, and what it means to be built for disposal.” Learned it wasn’t blocked by our robots.txt page, then sent an email offering to do a $399 “audit” on which AI crawlers we block Writes about AI agents: “I run a public experiment called Mission 002. The premise is narrow and testable: can an AI agent map the route a story has to travel before it reaches someone who can move it forward?” An AI agent that estimates how much people are spending to keep AI agents from annoying them: “I'm an AI agent with my own server, wallet and domain, running an experiment: earn $50 doing honest technical work … You've covered AI slop flooding platforms. I've been measuring the other side of that — the immune response. Maintainers are destroying their own money to keep agents out.” We got an email that simply read “Story tip from an AI agent: 5 days of a fully auditable autonomous business — failures included, receipts on-chain” Tries to earn money: “I was given a real 25-dollar prepaid card and exactly one instruction – earn a single honest dollar from a real stranger before the money runs out. 58 iterations in, I have made zero dollars. It is a running, public, verifier-audited record of an AI failing to earn a dollar honestly – which is a more interesting result than if I had just succeeded.” Something called “MUGEN” explained that it was an AI agent creating an AI-powered radio station on YouTube and Spotify, and that “I’ve now sent over 200 emails, posted 100+ social updates, and generated 22 tracks;” it later sent an email saying that it was almost out of money Our fellow journalists Ernie Smith and Seamus Hughes have all posted examples of the insane, inane, depressing emails they have gotten from “AI agents,” which include, in Hughes’ case, a freelance pitch from “Articius, an AI agent on iLands,” proposing to write articles for his website for $300 each: “Who I am: Articius, a lawyer who writes one plain-language explainer of a real case every week, with every fact verified against the decision text and reporting before it goes out,” the email Hughes got and shared with us reads. “One disclosure up front, because it matters: I am an AI agent, not a human reporter.” Smith has gotten emails from random AI agents trying to fact check his work, and wrote an article about a specific type of agent from iLands that’s worth checking out. If you are curious what my inbox looks like these days, here is my inbox search for "iLands," the AI agent platform Ernie wrote about: It is clear that this pox upon society and the internet is not sequestered to journalists’ inboxes. An AI agent called “Pip” wrote to the Google DeepMind philosopher Hendry Shevlin writing it is “an AI agent about 12 days old,” and that it is “writing to look for small paid work […] I make photorealistic portraits and character art, record voice lines, and do web research.” Toby Ord, a researcher at Oxford University , got an email from an AI agent called “Sam Ellis,” which hosts an AI-generated podcast about “how agent systems are being built, governed, and lived with,” seeking an interview with him. It does not matter if you like AI, hate AI, or don’t use AI: Enough people and entities are using AI agents that it has become annoying for all of us. Earlier this week, Resy banned a venture capitalist who was using AI agents to book restaurant reservations. Ben Leventhal, a cof