메뉴
BL
VentureBeat AI 12일 전

보안 사고 속출…절반 넘는 기업이 AI 에이전트 자격증명 공유

IMP
9/10
핵심 요약

최근 조사에 따르면 기업 107곳 중 절반 이상이 자율형 AI 에이전트(Agent) 도중 보안 사고를 겪었거나 직면한 바 있습니다. 가장 큰 구조적 취약점은 대부분의 에이전트가 전용 보안 ID(Identity) 없이 자격증명을 공유한다는 점이며, 고위험 에이전트를 샌드박스(Sandbox)로 격리하는 기업도 30%에 불과했습니다. 이는 AI 에이전트의 도입 속도가 이를 통제할 보안 시스템의 성장 속도를 훨씬 앞지르고 있음을 보여주는 중요한 지표입니다.

번역된 본문

107개 기업을 대상으로 한 조사 결과, AI 에이전트들에게 실제 시스템과 데이터에 대한 접근 권한이 부여되고 있는 반면, 이들을 통제하기 위한 보안 장치는 그 뒤처져 있는 것으로 나타났습니다. 절반 이상의 기업이 이미 확인된 에이전트 보안 사고를 겪었거나 아슬아슬하게 사고를 피한 적이 있습니다. 모든 에이전트에 개별 범위가 지정된 ID(Identity)를 부여하는 곳은 약 3분의 1에 불과하며, 대부분의 에이전트는 여전히 자격증명을 공유하고 있습니다. 또한 고위험 에이전트를 격리하는 기업은 10곳 중 3곳에 불과했습니다. 보안 스택은 에이전트 전용으로 구축되기보다는 폭발적으로 모델 제공업체와 하이퍼스케일러(Hyperscaler)의 것을 가져와 쓰는 비율이 압도적으로 높습니다. 관련 예산은 전체 보안 예산의 극히 일부에 불과하며, 자사의 방어 체계가 AI를 활용하는 공격자들을 따라잡고 있다고 생각하는 기업과 그렇지 않은 기업은 반반으로 나뉘었습니다. 그 결과 '에이전트 보안 격차(Agent security gap)'가 발생했습니다. 즉, 자율형 에이전트가 이들을 통제하는 데 필요한 식별, 격리 및 실행 통제 메커니즘보다 훨씬 빠르게 증식하고 있는 것입니다.

이번 VentureBeat Pulse Research 조사는 기업들이 자사의 AI 에이전트를 어떻게 보호하는지 조명합니다. 어떤 도구를 사용하는지, 에이전트의 식별 및 격리를 어떻게 관리하는지, 이미 어떤 문제가 발생했는지, 얼마나 많은 비용을 지출하는지, 그리고 AI 기반 공격자들에 대비한 방어 체계가 제 속도를 내고 있다고 믿는지 등을 살펴보았습니다.

핵심 발견은 바로 '에이전트 보안 격차'입니다. 이는 기업이 에이전트에게 부여하는 자율성과 이를 통제하기 위해 마련된 통제 장치 사이의 거리를 의미합니다. 조직의 절반 이상(54%)은 이미 확정된 에이전트 보안 사고(18%)를 겪었거나 피해가 발생하기 직전에 적발된 아슬아슬한 사고(36%)를 경험했습니다. 이러한 수치 아래에 깔린 구조적 취약점은 바로 '식별(Identity)' 문제입니다. 약 3분의 1(32%)만이 모든 에이전트에 관리되는 전용 범위 ID를 부여합니다. 나머지 기업들은 일부 에이전트가 자격증명을 공유하거나, 대부분의 에이전트가 공유 API 키, 사람 또는 서비스 계정 자격증명을 사용하여 실행된다고 보고했습니다. 에이전트들이 자격증명을 공유할 때, 단 하나의 에이전트가 침해되거나 과도한 권한을 가지게 되면 그 피해 반경(Blast radius)은 매우 커집니다. 그럼에도 단 30%의 기업(10곳 중 3곳)만이 이 피해 반경을 제한하기 위해 고위험 에이전트를 샌드박스(Sandbox) 환경에 격리하고 있습니다.

이러한 격차가 주목받는 이유는 기업들이 이 상황에 상당히 안주하고 있기 때문입니다. 보안 스택은 압도적으로 제공업체의 기본 환경에 의존하고 있습니다. OpenAI의 가드레일(51%), 구글 및 마이크로소프트의 클라우드 통제, Anthropic의 관리형 에이전트 통제가 주를 이루는 반면, 에이전트 보안 전문 솔루션들은 거의 채택되지 않고 있습니다. 그럼에도 이러들이 가져다 쓴 보안 스택에 대한 만족도는 5점 만점에 4.2점으로 높은 편입니다. 하지만 보안 예산에서 AI 에이전트 관련 지출은 여전히 극히 일부에 불과하며, 자사의 AI 방어 체계가 AI 기반 공격자보다 앞서 있다고 믿는 기업은 3분의 1에 불과합니다. 게다가 명확한 다수의 기업이 올해 안에 보안 도구를 교체할 계획을 세우고 있습니다. 기업들은 현재 동시에 교체할 준비를 하고 있는 통제 장치에 만족하고 있는 셈입니다.

조사 방법론 VentureBeat는 지속적으로 진행되는 Pulse Research 시리즈의 일환으로 이번 설문을 진행했습니다. 이번 조사는 기업의 에이전트 보안, 즉 조직이 자율형 AI 에이전트를 보호하기 위해 사용하는 도구, 식별, 격리 및 실행 통제에 초점을 맞췄습니다. 응답은 직원 수가 100명 이상인 조직(표본 수 n=107)을 기준으로 필터링되었습니다. (가장 작은 규모인 직원 수 1~100명 기업의 응답은 제외됨) 이 데이터는 단일 데이터 소스에서 추출되었습니다.

원문 보기
원문 보기 (영어)
Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping pace with AI-enabled attackers. The result is an agent security gap — autonomous agents proliferating faster than the identity, isolation, and enforcement controls needed to hold them.This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong, how much they spend, and whether they believe their defenses are keeping pace with AI-enabled attackers.The central finding is an agent security gap — the distance between the autonomy enterprises are granting their agents and the controls in place to contain them. More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%). The structural weakness beneath those numbers is identity: only about a third (32%) give every agent its own scoped, managed identity, while the rest report that some agents share credentials or that agents mostly run on shared API keys and human or service-account credentials. When agents share credentials, a single compromised or over-permissioned agent carries a wide blast radius — and only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes to bound that radius.What makes the gap notable is how comfortable enterprises are inside it. The security stack is overwhelmingly provider-native — OpenAI’s guardrails (51%), Google’s and Microsoft’s cloud controls, and Anthropic’s managed-agent controls dominate, while the dedicated agent-security specialists barely register — and satisfaction with that borrowed stack is high, averaging 4.2 out of 5. Yet spending remains a thin slice of the security budget, only a third of enterprises believe their AI defenses are ahead of AI-enabled attackers, and a clear majority plan to change tooling within the year. Enterprises are satisfied with controls they are simultaneously preparing to replace.MethodologyVentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent security — the tooling, identity, isolation, and enforcement controls organizations use to secure autonomous AI agents. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single