Analysis covers 37 public institutions under three ministries

First year of mandatory AI disclosure shows no unified usage or security standards

'Network separation alone cannot stop personal device use — guidelines needed'

A staff member at the Seoul Metropolitan Office of Education uses SenGPT, the office's proprietary generative AI tool. [Created with ChatGPT]
A staff member at the Seoul Metropolitan Office of Education uses SenGPT, the office's proprietary generative AI tool. [Created with ChatGPT]

Public institutions under South Korea's Ministry of Trade, Industry and Energy and Ministry of SMEs and Startups apply vastly different standards for the use of generative AI, a parliamentary audit has found.

Some institutions allow generative AI only after employees complete security training and sign a pledge, while many others use it without separating their internal networks from the internet. The findings have prompted calls to overhaul usage and security standards for generative AI at public institutions, amid a rise in AI-assisted hacking incidents in the financial sector and elsewhere.

Democratic Party of Korea lawmaker Im Mun-yeong, a member of the National Assembly's Trade, Industry, SMEs and Energy Committee, analyzed generative AI usage data submitted by 37 public institutions — 20 under the Ministry of Trade, Industry and Energy, 11 under the Ministry of SMEs and Startups, and six under the Korean Intellectual Property Office — and found that standards varied widely from institution to institution.

The Ministry of Trade, Industry and Energy itself separates its internal work network from the internet and, on the internet-facing side, blocks only DeepSeek, the Chinese generative AI service, while permitting access to all other AI services.

Six institutions — Korea Gas Corporation, Kangwon Land, Korea Gas Safety Corporation, Korea Testing Laboratory, Korea Evaluation Institute of Industrial Technology and Public Home Shopping — require employees to submit a use application, obtain approval or sign a security pledge before accessing generative AI.

Korea Gas Corporation blocks commercial AI by default on both its internal and internet networks, requiring employees who need access to apply for site-by-site permission through the company's internal system. Kangwon Land limits commercial AI account applications to 64 employees across all departments and requires each to sign a seven-point security pledge — including a commitment not to enter company business information — before being granted one year of access. Public Home Shopping requires employees to complete AI security training and sign a pledge not to upload confidential or personal information before generative AI use is permitted.

Twenty institutions, including Korea National Oil Corporation, KOTRA and Korea Gas Technology Corporation, block generative AI on their internal networks entirely. Employees at those institutions may use generative AI on a separate internet network without a prior application.

Six institutions, including the Korea Institute for Startup and Entrepreneurship Development, Korea Intellectual Property Protection Agency and Korea Institute of Patent Information, restrict generative AI use to their internal networks only.

Some institutions restrict generative AI on both their internal and internet networks. The Korea Robot Industry Promotion Institute blocks generative AI access through its networks but says it does not prohibit use outright. The institute said employees "use subscription-based AI through their personal smartphones." The Korea Institute of Ceramic Technology said generative AI "cannot be used within the administrative network."

Three other institutions — Korea Industrial Complex Corporation, Korea Product Safety Management Institute and Korea Coal Corporation — said the question was not applicable to them.

Starting this year, public institutions are required to disclose their AI usage under a government initiative to promote AI adoption. In this first year of mandatory disclosure, however, no unified usage or security standards covering all public institutions have been established. The National Intelligence Service issued a "Generative AI Security Guidelines" document last year, calling for information to be classified by sensitivity level — confidential, sensitive or public — rather than simply separating work and internet networks, with security measures applied accordingly.

Calls are growing for each ministry to establish generative AI usage standards and security guidelines applicable to its affiliated institutions. Proposed measures include rules on what information — such as personal data and trade secrets — may not be entered into AI systems, procedures for use approval and account management, settings to exclude data from AI training, and checks on informal use through personal devices or free accounts.

"Information security at public institutions is important, but simply dividing networks and blocking access cannot control employees using AI on their personal devices," Im said. "Ministries must establish common usage standards and security guidelines so that public institutions can use AI safely."


addressh@heraldcorp.com