Add to Google Preferred Sources
South Korea’s Financial Services Commission, together with the Financial Supervisory Service and Financial Security Institute, has finalized a second round of emergency easing measures for network separation regulations. The application threshold for financial companies has been lowered from total assets of ₩10 trillion (approximately $7.4 billion) and 1,000 full-time employees to ₩2 trillion (approximately $1.5 billion) and 300 employees. Electronic financial business operators now have a separate standard: annual transaction volume of at least ₩2 trillion and related revenue exceeding 10% of total sales. The pool of eligible applicants expands from 49 to 75 institutions, with final selections increasing from 10 to 15. Selected firms will receive a one-year exemption from network separation rules to conduct vulnerability assessments using Frontier AI and security SaaS. First-round testing confirmed AI’s ability to analyze massive volumes of source code within hours and detect vulnerabilities without omission.
Key Elements
South Korea’s financial authorities are significantly lowering the barriers of network separation regulations that have blocked AI-based security assessments. Application eligibility has been relaxed from large institutions with total assets of ₩10 trillion (approximately $7.4 billion) or more to midsize financial companies with ₩2 trillion (approximately $1.5 billion) or more, while separate criteria have been established for electronic financial business operators to broaden participation.
South Korea’s Financial Services Commission announced on the 3rd that it held the fifth meeting of the Frontier AI Situation Response Task Force with the Financial Supervisory Service and Financial Security Institute, finalizing detailed measures for the “Second Emergency Easing of Network Separation Regulations.” The measures temporarily relax network separation rules to allow financial companies to use Frontier AI and cloud-based security services (SaaS) for the purpose of detecting and remediating security vulnerabilities.
South Korea’s financial sector has been subject to network separation regulations that fundamentally block internal business networks from external internet networks. This has made the adoption of generative AI—which requires external network connectivity—effectively impossible. Financial authorities have been conducting the first round of testing with 10 leading financial institutions since June.
The core of this second-round measure is expanding the participant pool. The application requirements for financial companies have been lowered from “total assets of ₩10 trillion or more and 1,000 or more full-time employees” to “total assets of ₩2 trillion or more and 300 or more full-time employees.” However, companies must have a dedicated Chief Information Security Officer (CISO) who does not concurrently hold other IT department responsibilities. Fifty-nine financial companies meet these conditions.
Electronic financial business operators are subject to separate application criteria. They must have annual electronic financial transaction volume of at least ₩2 trillion and related revenue exceeding 10% of total sales. The CISO non-concurrent role requirement applies equally. Sixteen electronic financial business operators meet the criteria. The rationale behind the separate standard is that electronic financial business operators—which intermediate online payments and other electronic financial transactions—face critical hacking vulnerability management needs, but applying the same asset and workforce criteria as general financial companies would make their participation practically impossible.
As a result, the total pool of eligible applicants has expanded from 49 in the first round to 75 in the second, with final selections increasing from 10 to up to 15. The application period runs through the 14th of this month. Financial authorities plan to conduct evaluations through a private-sector technical advisory panel this month, comprehensively assessing security capabilities and AI utilization capacity, and announce final selections around the 7th of next month. Selected companies will receive a no-action letter granting a one-year exemption from network separation regulations.
Companies participating in the testing will establish alternative controls to network separation, then use Frontier AI and security SaaS to detect and remediate vulnerabilities in their systems. They must subsequently report outcome data to the government, including security risks associated with AI use, hacking attack scenarios, and defense strategies.
The meeting also shared interim results from the first round of testing. Frontier AI demonstrated strengths in analyzing source code ranging from millions to tens of millions of lines within just a few hours and consistently detecting vulnerabilities in existing systems without omission. While the assessment indicated that vulnerabilities discovered in the first round were unlikely to immediately lead to security incidents, participants also suggested the need to strengthen management of externally exposed IT assets, implement rapid security patching, and build a response framework of “defending AI with AI” to prepare for future AI-enabled intrusion threats.
Once the first round of testing officially concludes, financial authorities plan to share key findings—including AI assessment know-how and security response strategies—across the entire financial sector, and use these insights to begin revising AI security guidelines. The schedule and scale of the third round of testing will also be finalized soon, and authorities are reviewing a long-term plan to fully lift network separation regulations starting with companies possessing advanced AI and security capabilities.
Yoo Young-joon, Director of Digital Finance Policy at South Korea’s Financial Services Commission, stated: “We will immediately disseminate the AI security threat characteristics and response strategies accumulated from testing results across the entire financial sector, making every effort to ensure that financial companies not participating in the testing can adequately respond to security threats.” He added: “We will enable the financial sector to utilize AI technology in more diverse and continuous ways, not limited to security purposes,” and noted that “we are closely discussing with relevant agencies a plan to fully lift network separation regulations starting with entities possessing advanced AI and security capabilities.”
With this measure opening the door for midsize financial companies and electronic financial business operators—including big tech and fintech firms—to participate in AI-based security assessments, attention is focused on whether AI utilization across the financial sector will expand beyond the security domain.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
