Ruling party lawmaker flags short pilot period; FSC moves to lift network separation rules for security AI
Financial Services Commission Chairman Lee Eok-won said Thursday that "ultimately, the only way to stop AI hacking is to use AI," signaling his determination to ease the country's network separation rules for the financial sector.
Lee made the remarks at the FSC's national audit held at the National Assembly in Yeouido, Seoul, in response to Democratic Party of Korea lawmaker Park Min-gyu, who said financial institutions must "detect signs of intrusion early and respond preemptively through AI-based security monitoring."
Park said that while exceptions to network separation rules have been granted for services such as payments and cloud computing, AI used for security purposes has not received the same treatment. "The weapons hackers use are being upgraded every day, yet banks are unable to deploy security AI because of network separation regulations," he said.
Park also said the financial authorities' response amounted to little more than a limited one-year pilot involving some financial firms, and urged the government to extend the period long enough to encourage long-term security investment.
In response, Lee said the FSC is "considering various phased and effective approaches to reforming the network separation rules" and pledged to "look into the matter carefully."
In his opening statement at the audit, Lee said the FSC "is pursuing the lifting of network separation regulations, premised on security, to support innovation and the strengthening of security capabilities in the financial sector."
Financial regulators have been in discussions with the financial industry since June on easing network separation rules for security AI, and recent AI-related hacking incidents have accelerated those talks. The aim is to allow financial firms to use high-performance external AI and security software-as-a-service to identify security vulnerabilities more quickly and broadly than was possible with conventional methods.
Regulators are also working with the ruling party to amend the Electronic Financial Transactions Act to impose fines for security breaches and strengthen the authority of chief information security officers.
hyuk@heraldcorp.com
