Despite AI being essential for productivity gains, security authorities recommend overly strict guidelines that bar uploading source code and other confidential files, leaving smaller companies with little room to maneuver

Getty Images Bank
Getty Images Bank

"File uploads are blocked. When you connect from the office, the upload button simply doesn't appear. There are real limits on how we can use AI. Still, they say it's for security reasons, so there's nothing we can do."

That is how a staffer at Company A, a firm that describes itself as an enthusiastic AI adopter, summed up the situation. The company recently began covering monthly AI subscription costs for all employees to encourage active use, citing productivity gains and greater efficiency as its goals. It is even running an internal AI competition, awarding prizes to employees who demonstrate how they have used AI to boost their own output. Yet file uploads remain off-limits.

Mid-sized Company B has also blocked file uploads to AI tools, again citing security concerns. "I think it's right not to do what we're told not to do," a company official said. "If a problem comes up later, the individual has to bear the responsibility — I don't want to create trouble by taking on unnecessary risk." Company B is considered one of the more aggressive AI adopters in its industry, having integrated AI from the product design stage to automate tasks previously done by people. Even so, security restrictions have kept actual utilization well below its potential.

Many small and medium-sized enterprises have been encouraging staff to adopt generative AI while simultaneously blocking file uploads — one of the most critical functions for workplace efficiency — industry sources said Monday. Companies are promoting AI use but restricting its scope out of concern that internal documents, customer data and research and development materials could leak to external AI services.

Frustration on the ground is widespread. "If you can't upload files, the benefit of using AI drops to less than half," workers have said. Most employees, however, appear to accept the situation, saying they will follow company policy.

The main reason mid-sized and smaller firms are restricting access to external generative AI services — including OpenAI's ChatGPT, Google's Gemini and Anthropic's Claude — appears to be guidance from security authorities.

The Korea Internet and Security Agency issued a "Caution security advisory on the use of generative AI" in February last year, setting out security rules for businesses. The advisory told companies not to enter confidential data — including internal documents, source code and customer information — into AI services, and called for restricting unauthorized use on internal networks. The Personal Information Protection Commission separately published guidelines covering personal data handling and safety standards.

Mid-sized and smaller companies have interpreted these advisories conservatively, making file upload blocks their default setting. "In the end, many employees are stuck polishing email wording or asking general questions," one official at a mid-sized firm said. Another said: "If you can't upload files, usability drops to chatbot level. At least one recent improvement is that the system now remembers a question you asked on Monday — that much has become more convenient."

The problem is that the KISA and Personal Information Protection Commission advisories reflect a stricter stance shaped by early AI-related security incidents in South Korea. In 2023, a major domestic conglomerate faced a data leak controversy tied to its adoption of external generative AI and subsequently restricted its use. That company has since reversed course, allowing external generative AI for employees this month after completing security training and system upgrades. Mid-sized and smaller firms, however, still lack robust internal security infrastructure and continue to operate under the same strict advisory standards from years past.

The gap in AI adoption between large companies and smaller ones ultimately comes down to cost. A major biotech company recently built its own generative AI system using proprietary servers, creating an internal cloud environment that pulls in external AI models while allowing full functionality — including file uploads — with plans to eventually extend its AI use to digital twins. "We solved the security problem by building an internal network, giving employees a fully capable AI environment," a company official said. Building such an in-house generative AI system requires an investment of hundreds of millions of won.

Smaller and mid-sized companies that cannot afford such investment have little choice but to continue using AI under restricted conditions, with file uploads blocked and functionality curtailed.

Some government support is available. The Ministry of Science and ICT and the National IT Industry Promotion Agency are supporting AI adoption at small and medium-sized enterprises this year through an AI voucher program, with a budget of 26.625 billion won (about $17.6 million). Industry voices, however, say support needs to go beyond simply subsidizing AI adoption costs to include building secure, company-wide AI frameworks. "The collision between security and efficiency is emerging as a new bottleneck in the corporate AI race," one industry official said.


hong@heraldcorp.com