Full Session of the AI Privacy Public–Private Policy Council

The Personal Information Protection Commission announced that it held a full session of the AI Privacy Public–Private Policy Council on the afternoon of September 23 at the Korea Federation of Banks Building in Jung-gu, Seoul.


Song Kyunghee, Chairperson of the Personal Information Protection Commission, is speaking at the full meeting of the Personal Information Protection Commission held at the Government Seoul Building in Jongno-gu, Seoul on July 29, 2026. Photo by Jo Yongjun

Song Kyunghee, Chairperson of the Personal Information Protection Commission, is speaking at the full meeting of the Personal Information Protection Commission held at the Government Seoul Building in Jongno-gu, Seoul on July 29, 2026. Photo by Jo Yongjun

View original image


The council designs rational regulatory directions so that utilization and protection of personal information are in harmony in the evolving AI era. In response to agentic AI and related issues, the second phase of the council launched in February this year, co-chaired by Song Kyunghee, Chair of the Personal Information Protection Commission, and Kwon Changhwan, Senior Judge at Suwon District Court. A total of 36 members from academia, industry, legal, and civil organizations are participating as committee members. Three working groups cover standards for data processing (Group 1), risk management (Group 2), and protection of data subject rights (Group 3).


At this meeting, Professor Kim Byungpil from KAIST gave a presentation on “Privacy Issues of Agentic AI.” Professor Kim introduced key findings from field interviews, conducted as part of Group 1 activities, along with further areas for review. The interviews, held between July and August, targeted 15 domestic and international organizations involved in AI development and adoption, and identified on-site examples of agentic AI, risk factors relating to personal information protection, and aspects of legal uncertainty.


Organizations participating in the interviews cited prompt injection attacks and excessive authority granted to agentic AI as major risk factors. They expressed the need for standards around boundaries between autonomy and approval, roles and responsibilities for participating parties, and storage and disposal of personal information such as logs and memory. Furthermore, the upcoming guidelines should maintain a principle- and risk-based approach and uphold technological neutrality.


Choi Yoonjung, Director of the Personal Information Protection Policy Division, introduced the “Direction for Institutional Innovation of Personal Information Protection in the AI Era.” The commission plans to reasonably improve formalistic regulations that restrict data utilization, while minimizing negative impacts on the protection of citizens’ rights. Norms needed for the AI era will be established rapidly. In the continuing general discussion, topics included the flexibilization of processing grounds for AI data collection and utilization, rational operation of special rules for personal information use in AI, and establishing effective safeguards and accountability structures suitable for AI environments. The results of these discussions will be reflected in the “Agentic AI Personal Information Processing Guidelines,” which will be released by the commission at the end of this year.



Chair Song Kyunghee stated, “Technological advancement must fully support public benefit while also safeguarding privacy and other rights and safety, so that technology can be truly sustainable,” adding, “We will work to establish a rational and well-balanced AI personal information regulatory framework through close cooperation between the public and private sectors.”


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing