Mid-sized and small companies have been actively adopting AI this year, with efficiency and productivity gains as their primary goals. Yet most cannot make full use of AI tools, citing the cost of building in-house AI systems and security advisories from government agencies. [Yonhap]
Mid-sized and small companies have been actively adopting AI this year, with efficiency and productivity gains as their primary goals. Yet most cannot make full use of AI tools, citing the cost of building in-house AI systems and security advisories from government agencies. [Yonhap]

Most SMEs block internal document uploads despite pushing AI adoption

Large firms bypass restrictions with private AI infrastructure; smaller ones can't afford to

'Excessive blocking limits productivity gains'

[The Herald Business = Reporter Hong Seok-hee] "File uploads are blocked. When I log on from the office, the upload button doesn't even appear. It really limits how much I can do with AI. But I'm told it's for security reasons, so there's nothing I can do."

The comment came from an employee at Company A, a firm that has been actively promoting AI adoption. The company recently began covering monthly AI subscription costs for all staff and is running an internal AI competition that rewards employees who demonstrate measurable productivity gains through AI use. Yet file uploads remain prohibited.

Mid-sized Company B has also blocked file uploads to AI tools, again citing security concerns. "I think it's right not to do what you're told not to do," a company official said. "If a problem comes up later, the individual has to bear the responsibility — I don't want to take on that risk." Company B is considered one of the more active AI adopters in its industry, having integrated AI into the product design process to automate tasks previously done by people. Even so, security restrictions have kept actual utilization well below its potential.

Many small and medium-sized enterprises are encouraging the use of generative AI while simultaneously blocking file uploads — the very feature that makes AI most useful for day-to-day work, according to industry sources. Companies are restricting how employees use external AI services out of concern that internal documents, customer data and research and development materials could be exposed. Workers say the limitations are severe. "If you can't upload files, the value of AI drops to less than half," one employee said. Most staff, however, say they are willing to follow company policy.

The main reason mid-sized and small firms are restricting the use of external generative AI tools — including OpenAI's ChatGPT, Google's Gemini and Anthropic's Claude — is guidance from security authorities. The Korea Internet & Security Agency issued a security advisory in February last year warning companies not to enter confidential data such as internal documents, source code or customer information into AI services, and calling for restrictions on unauthorized use within internal networks. The Personal Information Protection Commission has also published guidelines covering personal data handling and safety standards.

Mid-sized and small firms have interpreted these advisories conservatively, making file upload blocks their default setting. "The company actively encourages AI use, but if you can't put in actual work materials, the scope narrows dramatically," one official at a mid-sized firm said. "You end up mostly polishing email wording or asking general questions." Another official said that without file uploads, AI is reduced to little more than a chatbot — though noted that one recent improvement has been the ability to recall past conversations, such as questions asked on May 31.

Part of the problem is that the KISA and Personal Information Protection Commission advisories were shaped by a high-profile security incident in the early days of domestic AI adoption. In 2023, a major South Korean conglomerate faced a data leak controversy tied to its use of external generative AI and subsequently banned the tools. That company has since reversed course and will allow external generative AI starting this month, after completing security training and system upgrades for employees. Mid-sized and small firms, however, lack comparable internal security infrastructure and continue to operate under the same strict advisory standards.

The gap between large companies and smaller ones ultimately comes down to cost. A major biotech firm recently built its own generative AI system using private servers, creating an internal cloud environment that allows employees to use external AI models with full functionality — including file uploads — and plans to eventually expand into digital twin applications. "We solved the security problem by building an internal network," a company official said. "It gives employees a fully functional AI environment." Building such an in-house system is estimated to require an investment of hundreds of millions of won.

Smaller firms that cannot afford such investment have no choice but to continue using AI under restricted conditions, with file uploads blocked. "Preventing leaks of personal data and trade secrets is naturally a top priority for any company," an AI security expert said. "But the productivity gains from generative AI ultimately depend on how safely a company can connect it to internal documents and data." The expert added that simply blocking everything makes it very hard to improve productivity on the ground.

Some government support is available. The Ministry of Science and ICT and the National IT Industry Promotion Agency are supporting AI adoption among small and medium-sized enterprises this year through an AI voucher program with a budget of 26.625 billion won. Industry officials, however, say support needs to go beyond subsidizing basic AI adoption costs to include help building secure in-house AI frameworks. "The collision between security and efficiency is emerging as a new bottleneck in the corporate AI race," one industry official said.


hong@heraldcorp.com