To respond to hacking and security threats using artificial intelligence (AI), the financial authorities will expand the relaxation of network separation rules in the financial sector to include small and midsize financial companies and electronic financial businesses. The number of institutions eligible to participate in the network separation relaxation test will increase from 49 to 75, and the number of institutions actually selected will expand from 10 to up to 15.

On the 3rd, the Financial Services Commission said it held the fifth meeting of the Frontier AI contingency task force with the Financial Supervisory Service and the Financial Security Institute, and confirmed this second round of emergency relaxations of network separation rules. Selected financial companies and electronic financial businesses will be able to identify and remediate security vulnerabilities in their IT networks by adopting alternative controls for network separation and using frontier AI and software as a service (SaaS).

A view of the Financial Services Commission inside Government Complex Seoul in Jongno-gu, Seoul. /Courtesy of News1

The Financial Services Commission explained that it lowered the bar for participation because safe operating experience has been accumulated through the first test in Jun. The application criteria for financial companies will be eased from total assets of at least 10 trillion won and at least 1,000 full-time employees to total assets of at least 2 trillion won and at least 300 full-time employees. However, the chief information security officer (CISO) must not concurrently hold other information technology roles. There are 59 financial companies that meet this condition.

Separate criteria apply to electronic financial businesses. Sixteen operators are eligible if their annual electronic financial transaction volume is at least 2 trillion won, revenue from electronic financial business exceeds 10% of their total revenue, and the CISO does not concurrently hold an information technology role. Because electronic financial businesses facilitate electronic financial transactions such as online payments, managing hacking vulnerabilities is important, but applying the same asset and staffing criteria as general financial companies would limit participation.

Companies wishing to participate may apply by the 14th. A private technical advisory group and others will assess security capabilities and AI utilization within this month, and the Financial Services Commission plans to issue letters of no-action for a one-year, temporary relaxation of network separation rules to up to 15 institutions around the 7th of next month.

Authorities said that in the first test, frontier AI showed strength by analyzing source code running into millions to tens of millions of lines within hours and finding a wide range of existing vulnerabilities without omissions. However, opinions also noted that, in preparation for the possibility that threats leveraging AI will fully materialize, it is necessary to manage externally exposed IT assets, speed up security patching, and build a system that "uses AI to defend against AI."

Based on the test results, the Financial Services Commission will determine the timing and scale of the third round of relaxations and, in the long term, will also consider fully lifting network separation rules first for financial companies with advanced AI and security capabilities.

※ This article has been translated by AI. Share your feedback here.