Follow-up to 'High-Performance AI Security Threat Response Meeting'

Immunity covers disciplinary sanctions, fines within defined scope

Guidelines on AI security patch priorities and response procedures distributed to financial sector

This image is unrelated to the article. [123rf]
This image is unrelated to the article. [123rf]

Financial regulators have introduced sweeping immunity provisions to encourage the financial sector to take a more proactive stance on high-performance AI security threats. Financial firms will no longer face sanctions for IT outages that occur while using AI for security testing or applying security patches.

However, the immunity applies only to minor incidents — those involving unintentional financial losses of less than 100 million won ($64,600) — and firms must fulfill all consumer protection obligations, including rapid recovery based on a prepared work plan and advance notification to customers.

The Financial Services Commission said Tuesday it convened an immunity review committee on June 30 to deliberate and approve immunity measures for IT outages arising from AI security testing and patching.

The move is intended to help the financial sector mount a vigorous defense against security threats posed by so-called "frontier AI" — including Anthropic's high-performance AI model Mitos — and to encourage thorough security reinforcement. On May 22, the FSC held a "High-Performance AI Security Threat Response Meeting" and announced measures including a relaxation of network-separation regulations for AI used for security purposes.

Activities covered by the immunity include conducting security tests — such as routine vulnerability and port scanning or automated penetration attempts — using AI for security purposes, as well as applying emergency security patches (to operating systems, software and similar systems) or equivalent IT equipment changes in response to vulnerabilities flagged by the FSC, the Financial Supervisory Service or the Korea Financial Security Institute.

Eligibility for immunity will be assessed by comprehensively considering whether the firm has prepared and implemented rapid recovery measures and consumer protection steps in the event of a minor IT outage.

A minor IT outage is defined as an IT incident that does not meet the sanction thresholds set out in the enforcement rules of the regulations on inspection and sanctions of financial companies. To qualify, the incident must meet all of the following criteria: it was unintentional; financial losses were below 100 million won; system downtime did not exceed four hours; and any customer data leak involved fewer than 10,000 cases, excluding personal credit information.

Rapid recovery measures refer to cases where a firm prepares a work plan covering pre-testing, containment of damage and continuity of service, reports it to management and carries it out accordingly. Consumer protection measures are recognized when the firm notifies customers in advance — via its website, SMS or other channels — of the timing and content of the security test or patch and any alternative service options, and implements remedial action if harm occurs.

The immunity covers both disciplinary sanctions against institutions and their officers and employees, as well as administrative fines. However, if a personal credit information leak occurs under the Credit Information Act, existing statutory sanctions will continue to apply.

The FSC also distributed a guideline titled "Frontier AI Security Threat Response Procedures for the Financial Sector," outlining recommended actions for financial firms to effectively counter AI security threats.

The guideline covers six areas: strengthening management accountability, vulnerability and patch management, asset and supply chain management, AI-based defense automation, coordinated industry response and resilience, and breach-containment frameworks.

The guideline makes clear that management bears responsibility for responding to AI security threats. It recommends that security threats be treated as a core agenda item in board-level information security committees, and that the board and CEO — as the ultimate decision-makers — grant the chief information security officer meaningful authority over budget allocation and personnel management.

The guideline will be updated to reflect the results of first- through third-round security AI testing as they become available.

The FSC said it would "actively pursue a range of policy initiatives to support the financial sector's full AI transformation, including a complete lifting of network-separation regulations," and urged the financial industry to "move more swiftly to strengthen IT resource management, vulnerability detection and security patch application."


ehkim@heraldcorp.com