FINANCE

FSC to select up to 15 firms for second round of network-separation deregulation

by
Park Hye-rim
Published : Sept. 3, 2026 - 15:00:00
    • Copy Completed!

View Korean Original

Second round of network-separation deregulation opens

Eligible pool expands to 75 firms as entry bar lowered

Employees walk through the Financial Services Commission offices at Government Complex Seoul in Jongno-gu. [Herald DB]
Employees walk through the Financial Services Commission offices at Government Complex Seoul in Jongno-gu. [Herald DB]

South Korea's financial regulator is accepting applications for a second round of temporary network-separation deregulation, allowing financial firms to use AI for security purposes. The pool of eligible applicants has grown from 49 to 75, opening the door to smaller financial companies and electronic financial service providers. The Financial Services Commission plans to select up to 15 firms after a review and grant them a one-year temporary exemption from network-separation rules starting in October.

The FSC announced the second-round emergency deregulation plan Thursday after holding the fifth meeting of its "Frontier AI Response Task Force," chaired by Digital Financial Policy Director Yu Yeong-jun, with participation from the Financial Supervisory Service and the Korea Financial Security Institute.

The measure temporarily exempts participating firms from rules requiring the separation of internal corporate networks from the public internet, allowing them to deploy frontier AI and security software-as-a-service tools to detect and remediate security vulnerabilities. The eligible pool was expanded based on operational experience from the first round of testing, which began in June.

The application threshold for financial companies has been significantly lowered. In the first round, only firms with total assets of at least 10 trillion won ($7.3 billion) and a full-time workforce of at least 1,000 were eligible; the second round relaxes those requirements to 2 trillion won in total assets and 300 or more full-time employees. However, only companies whose chief information security officer does not concurrently hold other IT responsibilities — a condition intended to ensure accountability and independence in information security — may apply. Fifty-nine financial companies meet this requirement.

Separate criteria apply to electronic financial service providers: annual electronic financial transaction volume must exceed 2 trillion won, and revenue from electronic financial services must account for more than 10 percent of total sales. The restriction on CISO dual roles applies equally. Sixteen electronic financial service providers qualify, bringing the total pool of eligible applicants to 75 when combined with the financial companies.

Government Complex Seoul in Jongno-gu, which houses the Financial Services Commission. [Herald DB]
Government Complex Seoul in Jongno-gu, which houses the Financial Services Commission. [Herald DB]

The number of firms participating in testing will also increase, from 10 in the first round to a maximum of 15. Interested companies may apply through Sept. 14, and a private technical advisory panel will assess their security capabilities and AI proficiency. The FSC plans to finalize selections around Oct. 7 and issue one-year temporary no-action letters to the chosen firms.

Selected companies must first put in place alternative security controls to replace network separation, after which they may use frontier AI and security SaaS tools to identify and address system vulnerabilities. Participants must submit to the government findings on the characteristics of AI-based security threats observed during testing, the risks posed if such AI were used for offensive purposes, and recommended defensive measures. Financial regulators plan to incorporate these findings into future AI guidelines and sector-wide security frameworks.

The first round of testing also confirmed AI's ability to scan for vulnerabilities. Frontier AI was able to analyze source code running into the tens of millions of lines within a matter of hours and showed particular strength in broadly detecting known vulnerabilities, according to the FSC. However, regulators assessed that the vulnerabilities identified are unlikely to lead directly to security breaches, given that financial firms already operate multiple layers of protection including intrusion prevention and detection systems.

The FSC said it would move quickly to determine the schedule and scale of a third round of testing, and would also consider conducting additional emergency deregulation measures or making the exemption permanent depending on further demand. The regulator added that it is in discussions with relevant agencies on a plan to fully lift network-separation restrictions for financial firms that meet a certain level of AI and security capability — not limited to specific purposes such as security.

ATM machines at major banks in Seoul. [Yonhap]
ATM machines at major banks in Seoul. [Yonhap]

"At a time when AI-driven intrusion threats are increasingly becoming a reality, it is important to give a broader range of financial companies and electronic financial service providers the opportunity to conduct AI security testing so they can be well prepared against such threats," Digital Financial Policy Director Yu said. "We will immediately share the accumulated findings on AI security threat characteristics and response methods with the entire financial sector, so that even firms not participating in the tests are fully equipped to handle security threats."

Meanwhile, the FSC selected 10 financial firms in June as participants in the first round of network-separation deregulation for AI and SaaS use for security purposes. The group included Shinhan, Hana and Woori Bank, Kakao Bank, KB Securities, NH Investment Securities, Samsung Fire and Hanwha Life Insurance, each of which received a one-year temporary no-action letter.


rim@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ