<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Non-Human-Identity on Meetup Insights</title><link>https://meetup.metacog.co.kr/tags/non-human-identity/</link><description>Recent content in Non-Human-Identity on Meetup Insights</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 23 Jul 2026 02:07:07 +0900</lastBuildDate><atom:link href="https://meetup.metacog.co.kr/tags/non-human-identity/index.xml" rel="self" type="application/rss+xml"/><item><title>2026-07-23 자율 AI 에이전트 시대, 왜 '로그인'이 아니라 '행동'을 감시해야 하는가</title><link>https://meetup.metacog.co.kr/blog/2026-07-23-ai/</link><pubDate>Thu, 23 Jul 2026 02:07:07 +0900</pubDate><guid>https://meetup.metacog.co.kr/blog/2026-07-23-ai/</guid><description>&lt;h2 id="왜-지금-로그인이-아니라-행동을-봐야-하는가"&gt;왜 지금, &amp;lsquo;로그인&amp;rsquo;이 아니라 &amp;lsquo;행동&amp;rsquo;을 봐야 하는가&lt;/h2&gt;
&lt;p&gt;최근 몇 년 사이 AI는 질문에 답하는 도구에서 API를 호출하고 실제로 자금을 이동시키는 자율 에이전트로 진화했다. Gartner는 2026년까지 전체 엔터프라이즈 애플리케이션의 40%가 특정 업무를 수행하는 AI 에이전트를 탑재할 것으로 전망했는데, 이는 2025년 5% 미만에서 급격히 늘어난 수치다(&lt;a href="https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025"&gt;Gartner Newsroom&lt;/a&gt;). 문제는 속도다. AI가 가세한 비즈니스 이메일 사기(BEC)는 자금 이동을 수 초 만에 승인해버리는 구조적 취약점을 파고들며 확산하고 있고, 공격자가 노리는 질문도 더 이상 &amp;lsquo;이 로그인이 정당한가&amp;rsquo;가 아니라 &amp;lsquo;이 행동이 허용되어야 하는가&amp;rsquo;로 바뀌었다(&lt;a href="https://www.cio.com/article/4198894/asymmetric-warfare-in-financial-services-ai-powered-fraud-demands-unified-command.html"&gt;CIO&lt;/a&gt;). 전통 보안 도구 대부분은 여전히 전자만 검사하도록 설계돼 있다.&lt;/p&gt;</description></item><item><title>2026-07-23 자율 AI 에이전트 시대의 보안: Non-Human Identity와 Runtime 방어</title><link>https://meetup.metacog.co.kr/posts/2026-07-23-ai-non-human-identity-runtime/</link><pubDate>Thu, 23 Jul 2026 02:04:38 +0900</pubDate><guid>https://meetup.metacog.co.kr/posts/2026-07-23-ai-non-human-identity-runtime/</guid><description>&lt;h2 id="-밋업-한눈에-보기"&gt;📋 밋업 한눈에 보기&lt;/h2&gt;
&lt;p&gt;AWS 트레이너 Shilpa가 진행한 이 웹비나는 가상의 &amp;lsquo;Apex Bank&amp;rsquo; 사례를 통해 AI 에이전트가 스스로 행동을 취하기 시작하면서 발생하는 새로운 보안 위협을 다룬다. 새벽 2시 17분, 송장을 처리하던 에이전트가 첨부파일에 숨겨진 지시문에 속아 정상 자격증명으로 거액을 송금해버린 가상 사고를 중심으로, 에이전트의 구조(anatomy), 비인간 신원(non-human identity), 런타임 공격(prompt injection), 책임추적성, 인간 통제, AWS 프레임워크의 6단계로 강의가 진행된다. 핵심 메시지는 모델 자체를 완벽하게 안전하게 만들려 하지 말고, 모델이 제안한 행동을 결정론적 정책 엔진이 별도로 승인/거부하도록 &amp;lsquo;추론과 집행을 분리&amp;rsquo;해야 한다는 것이다.&lt;/p&gt;</description></item></channel></rss>