Financial Authorities Permit Use of AI and SaaS for Security Purposes
"AI Defends against AI"... Network Separation Regulations Eased
Full Lifting of Network Separation for Financial Firms with Outstanding Security and AI Capabilities

The government is moving to significantly ease network separation regulations in the financial sector regarding the use of artificial intelligence (AI) for security purposes. For financial institutions with advanced security and AI capabilities, the authorities are even considering a full lift of network separation requirements. This proactive response comes as concerns about AI-driven cyber threats targeting financial systems are rising globally, following the emergence of Anthropic’s high-performance AI model “Mythos.” The underlying principle is “AI must be countered with AI.”


AI for Security Purposes Allowed on Internal Networks... "AI Must Be Countered with AI"


Financial Firms to Use Generative AI on Internal Networks... Network Separation Regulations Significantly Eased in Response to 'Mythos' Security Threats View original image

According to the Financial Services Commission (FSC) on May 24, Vice Chairman Kwon Daeyoung held a “Financial Sector Security Threat Response Meeting on High-Performance AI” on May 22 to discuss these regulatory reforms. The meeting was attended by Lee Jongoh, Deputy Governor for Digital & IT at the Financial Supervisory Service, Park Sangwon, President of the Financial Security Institute, as well as AI and security experts, and chief information security officers (CISOs) from major banks, securities firms, and card companies.


Until now, financial authorities have maintained network separation regulations that block internal and external networks within financial institutions to prevent hacking incidents. Although the use of cloud-based office management and work support software (SaaS) has recently been allowed on internal networks, this permission has remained limited.


However, the emergence of Mythos has changed the landscape. Mythos is reported to be capable of detecting old vulnerabilities that conventional security programs have difficulty identifying, and is sophisticated enough to plan and execute hacking attacks autonomously. As a result, there are growing assessments that using high-performance AI for defensive purposes can dramatically enhance security capabilities, such as vulnerability detection and threat prevention.


The FSC has decided to temporarily ease network separation regulations exclusively for the use of AI for security purposes. The aim is to strengthen the AI security framework by allowing vulnerability checks using high-performance AI and the establishment of defense systems based on security SaaS solutions.


This policy applies to 49 financial institutions that meet specific criteria, such as total assets of at least 10 trillion won and at least 1,000 full-time employees, each of which has a dedicated CISO. The FSC plans to issue a “no-action letter” after expert evaluation and review, and to ease network separation regulations for the selected financial institutions for one year.


Selected financial institutions will be permitted to conduct AI-based vulnerability testing and use AI and SaaS for security purposes but must comply with enhanced security protocols. They are also required to report the unique security risks and response cases associated with high-performance AI to the government, which the authorities intend to use in preparing future financial sector security guidelines.


The application and review process will take place in three rounds. The first round, targeting up to 10 institutions, will be conducted from June to July. The second round, from August to September, will add 10 to 20 more institutions. Remaining applicants will be considered in the fourth quarter.


Looking ahead, financial authorities are also considering fully lifting network separation regulations for financial institutions with outstanding security and AI capabilities through the innovative financial services process. The plan is to expand AI utilization across all financial services, including chatbot consultations, asset management, credit screening, corporate finance, and internal controls.


Financial Firms to Use Generative AI on Internal Networks... Network Separation Regulations Significantly Eased in Response to 'Mythos' Security Threats View original image

Establishment of the "Financial AI Security Research Center"... Enhanced Support for Small and Medium-Sized Financial Institutions


To strengthen AI-based cyber threat response capabilities, financial authorities will establish the “Financial AI Security Research Center” within the Financial Security Institute, which will be responsible for developing AI security technologies, responding to threats, and training specialists. The center will quickly detect, analyze, and respond to emerging security threats, including AI-driven cyberattacks.


In addition, a “Private Sector Technical Advisory Group” made up of experts in AI, security, and information protection will be operated, and the “High-Performance AI Security Threat Response Task Force”—comprising the FSC, Financial Supervisory Service, Financial Security Institute, and CISOs from all financial institutions—will monitor on-site response situations and challenges.


An “AI Security Support Center” will also be operated to assist small and medium-sized financial institutions and fintech companies. The center will provide support for sharing AI technology and threat trends, offer response strategies, and assist with AI vulnerability assessments.


The authorities also plan to establish financial sector AI security guidelines by June. The guidelines will include standards for classifying IT resources and prioritizing software patches, and will be accompanied by tailored support to strengthen IT asset management capabilities.


Furthermore, for minor system failures that unavoidably occur during proactive security patching, authorities will promote penalty mitigation or exemption on the condition of prompt recovery and consumer protection. For small and medium-sized fintech companies, the government will support the enhancement of security capabilities by subsidizing AI-based security inspection costs and providing vulnerability assessment tools.



Vice Chairman Kwon Daeyoung stated, “High-performance AI security threats are like cold viruses—they must be managed continuously rather than completely blocked. Cyber hygiene, including the establishment of an AI defense system across the financial sector, is essential.” He added, “The AI transformation (AX) of finance is a fundamental structural reform of financial services, and the government will boldly pursue regulatory improvements to expand the productive, inclusive, and trustworthy use of AI in finance.”


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing