메뉴
BL
TechCrunch AI 43일 전

美 정부의 안스로픽 AI 수출 통제에 사이버보안 전문가들 반발

IMP
8/10
핵심 요약

미국 정부가 국가 안보를 이유로 안스로픽(Anthropic)의 강력한 AI 모델인 Fable과 Mythos에 수출 통제를 내리고, 이에 따라 전 세계 이용이 중단되자 76명의 사이버보안 전문가들이 반발하며 공개 서한을 발표했습니다. 전문가들은 방어자들이 취약점을 찾고 코드를 수정하는 데 필수적인 이 최고 성능의 모델을 빼앗는 것은 위험한 일이라고 지적했습니다. 특히 정부의 조치가 아마존의 미공개 논문을 근거로 한 것이며, 이는 실제 보호망 우회가 아닌 정상적인 코드 수정 작업에 불과하다고 주장하며 조치 철회를 촉구했습니다.

번역된 본문

수십 명의 사이버보안 전문가와 업계 유력 베테랑들로 구성된 그룹이 미국 정부에 공개 서한을 보내 안스로픽(Anthropic)의 Fable 및 Mythos 모델에 대한 수출 통제 명령을 철회해 달라고 요청했다. 공개 서한에 따르면, 이 조치는 보안 방어자들에게서 최고의 모델을 빼앗았으며, 그 결과 방어자들은 더 이상 이 모델을 사용해 취약점을 발견하고 소프트웨어와 제품을 더 안전하게 만들 수 없게 되었다. 서한은 "적들이 빠르게 발전하고 있는 상황에서 타당한 이유 없이 방어자들에게서 최고의 성능을 빼앗는 것은 위험한 일"이라고 적혀 있다.

안스로픽에 따르면, 미국 정부는 지난 금요일 국가 안보 우려를 이유로 Fable과 Mythos의 수출을 제한하라고 안스로픽에 명령했으나 그 구체적인 이유는 설명하지 않았다. 이에 대응하여 회사는 전 세계 모든 사용자에 대한 해당 모델의 접근을 중단했다. 이 글을 작성하는 현재 기준으로, 이 서한에는 전 페이스북 최고 보안 책임자인 알렉스 스타모스(Alex Stamos), 버그 바운티 플랫폼인 Bugcrowd의 설립자 케이시 엘리스(Casey Ellis), 저명한 암호학자이자 전 애플 보안 설계 및 아키텍처 관리자인 존 칼라스(Jon Callas), 컴퓨터 과학자 폴 빅시(Paul Vixie), 전 블록(Block) 응용 보안 엔지니어링 책임자 디노 다이 조비(Dino Dai Zovi), Luta Security의 설립자 케이티 무수리스(Katie Mossouris), 그리고 보안 인식 교육 회사인 SocialProof Security의 CEO 레이첼 토박(Rachel Tobac)을 포함한 76명의 사이버보안 전문가가 서명했다.

지난 4월 Mythos가 프리뷰 버전으로 출시되었을 때, 안스로픽은 이 모델이 보안 취약점을 찾는 데 매우 강력하기 때문에 악의적인 해커나 외국 적대국가가 이를 이용해 인터넷에 혼란을 일으키는 것을 막기 위해 접근을 엄격하게 제한해야 한다고 밝혔다. 실제로 안스로픽은 처음에 약 50개 기업에 Mythos 접근 권한을 부여했으며, 최근에는 15개국의 약 150개 조직으로 이 그룹을 확대했다. 안스로픽은 지난주에 Mythos의 공개 버전인 Fable을 출시했는데, 이 모델은 생물학, 화학, 사이버보안 분야에서의 사용을 차단하고 다른 사람들이 모델을 재현하기 위해 추출(distilling)하는 것을 막기 위해 엄격한 보호막(guardrails)을 갖추고 있다고 밝혔다. 하지만 Fable의 보호막은 너무 엄격해서 많은 사이버보안 전문가들이 이 모델이 사이버보안과 관련된 거의 모든 프롬프트를 차단하는 것을 발견했다.

안스로픽은 백악관의 수출 통제 명령이 Fable을 우회(이른바 탈옥, jailbreaking)하여 강력한 Mythos 수준의 기능을 잠금 해제하는 방법이 있다는 보고서를 바탕으로 내려진 것일 수 있다고 말했다.

[제보 안내] 이 조치를 유발한 아마존의 논문에 대해 더 많은 정보를 가지고 계신가요? 제보를 환영합니다. 업무용이 아닌 기기와 네트워크에서 로렌조 프란체스키-비키에라이(Lorenzo Franceschi-Bicchierai)에게 Signal +1 917 257 1382, Telegram 및 Keybase @lorenzofb, 또는 이메일로 안전하게 연락할 수 있습니다.

공개 서한의 서명자 중 한 명인 케이티 무수리스(Katie Moussouris)에 따르면, 이 방법은 일반에 공개되지 않았지만 자신이 검토한 아마존 연구진의 논문에서 시연된 것이다. 그러나 무수리스는 블로그 포스트를 통해 이 논문이 실제 탈옥을 보여준 것이 아니라고 말했다. 그녀의 설명에 따르면, 연구원들은 단순히 모델이 '보안 문제에 대한 코드 검토'를 거부한 후, 공개적으로 알려진 취약점과 '고의로 심어진 취약점'이 있는 오픈소스 코드를 수정해 달라고 Fable에게 요청했을 뿐이다.

무수리스는 "논문에 설명된 동작은 의미 있는 방법으로 수정할 수 없으며, 수정하려는 시도는 오히려 방어를 위한 모델의 성능을 약화시킬 뿐"이라고 적었다. "방어자는 AI에게 파일의 버그를 수정하고, 수정이 왜 중요한지 설명하며, 패치가 작동하는지 확인하는 테스트를 작성해 달라고 요청할 수 있어야 합니다. 이는 보호막 우회가 아닙니다. 이는 AI 모델이 방어 보안을 위해 할 수 있는 가장 가치 있는 일입니다. 즉, 방어자가 매일 실행하는 찾기, 수정, 테스트 루프를 수행하는 것입니다."

무수리스의 비판은 공개 서한에서도 반복되었는데, 전문가 그룹은 아마존 논문에 사용된 방법이 OpenAI의 GPT-5.5, 안스로픽의 공개된 Claude Opus 4.8 및 Sonnet, 그리고 Kimi 2.7과 같은 중국 모델에서도 '복제될 수 있다'고 믿고 있다고 명시했다. 서한은 또한 ~라고 덧붙였다.

원문 보기
원문 보기 (영어)
A group made up of dozens of cybersecurity experts, including several well-known veterans of the industry, published an open letter to the U.S. government asking it to lift the export control order on Anthropic's Fable and Mythos models. According to the open letter, “this action has taken the best models away from [cybersecurity] defenders” who now can’t use the models to find vulnerabilities and make their software and products more secure. “To pull the best capabilities away from defenders without a good reason when our adversaries are rapidly advancing is dangerous,” read the letter. On Friday, the U.S. government ordered Anthropic to limit the export of Fable and Mythos citing national security concerns, without explaining the specific reasons behind the order, according to Anthropic . In response, the company suspended access to the models to all users worldwide. As of this writing, the letter is signed by 76 cybersecurity experts, including: former Facebook chief of security Alex Stamos; Casey Ellis, the founder bug bounty platform Bugcrowd; famed cryptographer and former Apple security design and architecture manager Jon Callas; computer scientist Paul Vixie; Dino Dai Zovi, the former head of applied security engineering at Block; Katie Mossouris, the founder of Luta Security; and Rachel Tobac, the CEO of the security awareness training firm SocialProof Security. When Mythos launched as a preview in April, Anthropic claimed it was so powerful at finding security vulnerabilities that the company needed to tightly restrict access to prevent malicious hackers or foreign adversaries from using it to cause havoc on the internet. In practice, that meant Anthropic gave around 50 companies initial access to Mythos, recently expanding that group to include around 150 organizations in 15 countries. Last week, Anthropic released Fable , a public version of Mythos that the company said had strict guardrails to block its use in the fields of biology, chemistry, and cybersecurity, as well as to stop others from distilling the model in order to recreate it. The guardrails on Fable were so strict that many cybersecurity experts found that it stopped essentially any prompts related to cybersecurity . Anthropic said that the White House export control order may have been based on a report that there was a method to bypass — or so-called jailbreaking — Fable to unlock its powerful Mythos-level capabilities. Contact Us Do you have more information about the Amazon paper that prompted the ban? We'd love to hear from you. From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email . According to Katie Moussouris, one of the signatories of the open letter, the method was demonstrated by Amazon researchers in a paper that is not public, but that she has reviewed. But Moussouris said in a blog post that the paper did not actually demonstrate a real jailbreak. Instead, she wrote, the researchers simply asked Fable to fix open source code with public and known vulnerabilities along with “deliberately planted vulnerabilities,” after the model initially refused to “review the code for security issues.” “The behavior described in the paper cannot meaningfully be fixed, and any attempt would only weaken the model for defense,” Moussouris wrote. “Defenders need to be able to ask AI to fix the bugs in a file, explain why the fix matters, and write tests that confirm the patch works. That is not a guardrail bypass. It is the most valuable thing an AI model can do for defensive security: executing the find, fix, and test loop defenders run every day.” Moussouris’ critique was echoed in the open letter, which also said that the group of experts believe the method in the Amazon paper “can be replicated” on OpenAI’s GPT-5.5, on Anthropic’s own publicly-available Claude Opus 4.8 and Sonnet, “and even Chinese models like Kimi 2.7.” The letter also asked for transparently and fairly enforced regulations created by “a democratic rule-making process” that are based on scientific research done by industry and academic experts, and “used only to the minimal extent necessary to ensure the safety of the American public.” Topics AI , Anthropic , Claude , Claude Fable 5 , Claude Mythos , Mythos , Security When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Lorenzo Franceschi-Bicchierai Senior Reporter, Cybersecurity Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy. You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com , via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram. View Bio June 18 Los Angeles Get an inside look at what it takes to scale and succeed from leaders at Mach Industries, Founders Fund, and Shinkei Systems. Through candid fireside chats and high-impact networking, you'll walk away with valuable insights and new connections. REGISTER NOW Most Popular The FBI built its own replica small town to simulate real-world cyberattacks Zack Whittaker Meta's months-old AI unit is a soul-crushing gulag, say the engineers stuck inside it Connie Loizos Jeff Bezos's Prometheus raises $12B to build an ‘artificial general engineer' for the physical world Marina Temkin Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable Lorenzo Franceschi-Bicchierai Google just fired a warning shot in the AI subscription price wars Lucas Ropek Connie Loizos Anthropic's Claude Fable 5 is a version of Mythos the public can access today Rebecca Bellan It's not FAANG anymore. It's MANGOS. Julie Bort