메뉴
BL
The Decoder 38일 전

AWS, 보안·비즈니스 맥락 강화하는 AI 에이전트 신규 서비스 출시

IMP
8/10
핵심 요약

아마존 웹 서비스(AWS)는 AI 에이전트가 실제 비즈니스 환경에 적용될 때 겪는 보안 및 비즈니스 맥락 부족 문제를 해결하기 위해 두 가지 신규 서비스를 출시했습니다. 'AWS 컨티뉴엄(Continuum)'은 코드 취약점 자동 탐지 및 수정을, 'AWS 컨텍스트(Context)'는 지식 그래프를 통해 AI 에이전트에게 비즈니스 데이터를 제공해 환각을 줄이고 정확한 의사결정을 돕습니다. 이를 통해 기업들은 코드 보안 리스크를 줄이면서 AI 에이전트의 실무 도입을 가속화할 수 있습니다.

번역된 본문

AWS, AI 에이전트의 비즈니스 맥락 및 보안 부족을 지적하며 이를 보완할 두 가지 서비스 출시

핵심 요약: 아마존은 두 가지 새로운 AWS 서비스를 출시합니다. 코드 취약점 수정을 자동화하는 'AWS 컨티뉴엄(Continuum)'과, 지식 그래프를 통해 AI 에이전트에게 비즈니스 지식을 제공해 의사결정을 개선하는 'AWS 컨텍스트(Context)'입니다. 또한 AWS 데브옵스 에이전트(DevOps Agent)는 AI가 생성한 코드가 라이브 환경에 적용되기 전 검증 기능을 포함하도록 업데이트되어, 실제 프로덕션과 유사한 환경에서 자동 테스트를 진행하고 잠재적인 시스템 장애를 조기에 발견합니다. 이와 함께 AWS는 모바일에서 즉각적인 제어가 가능하도록 코딩 에이전트인 키로(Kiro)의 iOS 앱을 출시하고, 베드락 에이전트코어(Bedrock AgentCore) 플랫폼에 추가 데이터 커넥터와 보안 필터를 확장 적용했습니다.

뉴욕에서 열린 AWS 서밋에서 아마존의 클라우드 부문은 AI 에이전트를 실제 비즈니스 환경에 즉시 투입할 수 있도록(production-ready) 고안된 여러 서비스를 공개했습니다. 여기에는 코드 취약점을 해결하는 보안 서비스와 에이전트에게 필요한 비즈니스 맥락을 제공하는 지식 그래프가 포함됩니다.

이번 발표는 두 가지 새로운 서비스를 중심으로 이루어졌습니다. 'AWS 컨티뉴엄'은 코드의 보안 취약점을 해결하고, 'AWS 컨텍스트'는 에이전트를 위한 공유 지식 기반 역할을 합니다. 이 두 서비스는 AI 에이전트를 실무 환경에 배포할 때 발생하는 전형적인 병목 현상을 해결합니다. 즉, 에이전트가 비즈니스 상황에 대한 이해력이 부족하고, 보안 위협이 AI가 코드를 생성하는 속도를 감당하지 못하는 문제를 해결하는 것입니다.

AI 기반 위협이 기존 방어 시스템의 대응 속도를 앞지르면서 보안 자동화가 필수화됨

AWS 컨티뉴엄을 통해 AWS는 탐지 및 우선순위 지정부터 검증, 수정 제안에 이르기까지 코드 취약점의 전체 라이프사이클을 다루는 서비스를 출시했습니다. 이 서비스는 우선 선정된 파일럿 고객에게만 초기 제공됩니다.

AWS는 자사의 보안 블로그를 통해 안스로픽(Anthropic)의 클로드 미토스(Claude Mythos)와 같은 전문화된 보안 모델이 강력한 원동력이라고 언급하며, 이러한 모델은 방어자가 대응하는 것보다 더 빠르게 취약점을 발견하고 공격 경로를 파악할 수 있다고 밝혔습니다. 데이터 수집, 저장 및 대시보드 중심으로 구축된 기존 접근 방식은 이러한 빠른 속도를 감당하도록 설계되지 않았으며, 미해결 문제의 백로그는 계속해서 쌓여가고 있습니다.

컨티뉴엄은 기존의 미해결 취약점 목록을 확인하는 동시에 자체적으로 새로운 취약점을 추가로 스캔합니다. 그런 다음 비즈니스 맥락을 기반으로 발견된 사안의 우선순위를 지정합니다. 예를 들어, 영향을 받는 컴포넌트가 실제로 접근 가능한지? 현재 프로덕션 환경에서 활발히 사용되고 있는지? 등을 평가합니다.

검증 단계에서 이 서비스는 오탐지(False positives)를 실제 위험과 구분하기 위해 격리된 테스트 환경에서 성공적인 공격 시뮬레이션을 시도합니다. 이 과정을 거친 후에야 수정된 네트워크 구성, 조정된 권한 설정 또는 코드 패치와 같은 구체적인 대응 조치를 제안합니다. 컨티뉴엄은 작업에 따라 다양한 최첨단 프론티어 모델(Frontier models)을 선택하여 사용합니다.

이 서비스는 코드 취약점 처리 방식을 점진적으로 자동화할 수 있지만, 처음에는 사람의 승인이 필요한 학습 모드로 시작합니다. 시스템에 대한 신뢰도가 높아지면 팀은 정해진 수정 사항을 자동으로 적용하는 강제 모드(Enforcement mode)로 전환할 수 있습니다. 또한 관련 위협 모델링 도구는 설계 문서나 소스 코드에서 자동으로 잠재적인 공격 시나리오에 대한 개요를 생성합니다.

공유 지식 그래프가 AI 에이전트의 환각을 방지

AWS 컨텍스트는 기존 기업 데이터에서 자동으로 지식 그래프(Knowledge graph)를 구축하여 조직 내의 모든 에이전트에서 사용할 수 있도록 제공합니다. 지식 그래프는 개별 데이터 요소들을 관계의 네트워크로 연결합니다.

이를 통해 에이전트는 어떤 데이터 테이블이 특정 고객에게 속해 있는지, 또는 어떤 출처가 특정 정보에 대해 신뢰할 수 있는 권위 있는 출처인지 스스로 파악할 수 있습니다. 이 서비스는 데이터베이스, 문서, 이메일 및 채팅 메시지에서 이러한 관계를 추출한 다음 비즈니스 규칙과 도메인 지식을 추가로 결합합니다.

AWS는 이러한 계층이 없다면 에이전트가 자신감 넘치게 말하지만 틀린 권고안을 제시하는 일이 너무 자주 발생할 것이라고 주장합니다. AWS 컨텍스트는 아마존의 AI 비서인 큐(Q)와 동일한 지식 그래프 기반 기술 위에 구축되었습니다. 연결된 소스의 메타데이터는 오픈 테이블 포맷으로 AWS 스토리지에 저장됩니다.

원문 보기
원문 보기 (영어)
AWS says AI agents lack business context and security, launches two services to patch the gaps Jonathan Kemper View the LinkedIn Profile of Jonathan Kemper Jun 21, 2026 Midjourney prompted by THE DECODER Key Points Amazon is launching two new AWS services: AWS Continuum, which automates the fixing of code vulnerabilities, and AWS Context, which feeds AI agents business knowledge through a knowledge graph to improve their decision-making. The AWS DevOps Agent now includes verification capabilities that check AI-generated code before it goes live, automatically testing it in production-like environments to catch potential system failures early. AWS is also releasing its coding agent Kiro as an iOS app for on-the-go control, while expanding the Bedrock AgentCore platform with additional data connectors and security filters. Ask about this article… Search At the AWS Summit in New York, Amazon's cloud division unveiled several services designed to make AI agents production-ready. They include a security service for code vulnerabilities and a knowledge graph that gives agents the business context they need. The announcements centered on two new services. AWS Continuum tackles security vulnerabilities in code. AWS Context serves as a shared knowledge base for agents. Both address typical bottlenecks when deploying AI agents in production. Agents lack business context, and security risks can't keep up with the pace of AI-generated code. Ad Automating security as AI-powered threats outpace traditional defenses With AWS Continuum, AWS is launching a service that covers the full lifecycle of code vulnerabilities, from detection and prioritization to validation and recommended fixes. The service is initially available only to select pilot customers. Ad DEC_D_Incontent-1 AWS points to specialized security models like Anthropic's Claude Mythos as the driving force, writing in its security blog that such models can spot vulnerabilities and map out attack paths faster than defenders can respond. Traditional approaches built around data collection, storage, and dashboards weren't designed for that kind of speed, and the backlog of unresolved issues keeps piling up. Continuum takes the existing list of open vulnerabilities and also scans for new ones on its own. Then it ranks findings based on business context. Is the affected component even reachable? Is it actively used in production? Ad During validation, the service tries to replicate a successful attack in an isolated test environment to separate false positives from real risks. Only then does it suggest specific countermeasures like a modified network config, an adjusted permission setting, or a code patch. Continuum picks different frontier models depending on the task. The service can increasingly automate how code vulnerabilities are handled, but it starts in a learning mode that requires human sign-off. As confidence builds, teams can switch it to an enforcement mode where it applies defined fixes on its own. A companion threat modeling tool automatically generates overviews of possible attack scenarios from design documents or source code. Ad DEC_D_Incontent-2 A shared knowledge graph keeps agents from making things up AWS Context automatically builds a knowledge graph from existing enterprise data and makes it available to every agent across an organization. A knowledge graph links individual data points into a network of relationships. Ad That lets an agent figure out which table belongs to which customer or which source is authoritative for a specific piece of information. The service derives these relationships from databases, documents, emails, and chat messages, then layers in business rules and domain knowledge. Without this layer, agents would too often give confident but wrong recommendations, AWS argues. Context is built on the same knowledge graph foundation as Amazon's AI assistant Quick . Metadata from connected sources is stored in AWS storage in an open table format, so customers can keep using their existing tools. There's no need to set up a separate pipeline to pull in data. Built-in access controls make sure agents can only reach information they've been cleared for. With each query, the service learns which sources deliver reliable results. That means later agents benefit from earlier ones. Reviewing AI-generated code before it hits production During a test phase, the AWS DevOps Agent is gaining two new features aimed at the growing volume of AI-generated code. In a Release Readiness Review, the agent checks every code change against production requirements and looks for dependencies that could cause problems across repository boundaries. Teams can define the underlying standards in plain language. Findings show up as comments in GitHub or GitLab and can be accessed from the development environment through a plugin for Kiro or Claude Code. A second feature derives a test plan from the specific change and runs it in a production-like environment rather than relying on a static test suite. The preview is initially available for free in the US East region. The new testing layer comes after a string of incidents where autonomous code changes at AWS itself caused problems . In February, reports emerged that Amazon's AI coding tools were allegedly involved in at least two AWS outages. One was a 13-hour outage after Kiro decided to delete and rebuild an environment. Shortly after, Amazon put an internal policy in place requiring experienced engineers to approve all AI-generated code . Kiro lands on smartphones while AgentCore gets broader integrations AWS is bringing its coding agent Kiro to smartphones as a native iOS app . Sessions still run in a cloud environment. The phone serves as a control interface to start tasks, review code changes, and approve them. Identity, model settings, and connected repositories sync across the IDE, web, and mobile device. Only paying customers get access. Bedrock AgentCore, AWS's platform for production-ready agent operations, is getting a managed knowledge base with connectors to S3, SharePoint, Confluence, and Google Drive, plus built-in web search. Through integration with in-house security filters, agent actions can be checked for manipulative prompts, malicious content, and data leaks. Down the line, signals from third-party security providers like Check Point, Zscaler, Rubrik, Netskope, and SentinelOne will be folded in as well. AI News Without the Hype – Curated by Humans Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section. Subscribe now Source: About Amazon