The South Korea Financial Services Commission finalized a second round of emergency relief from network-separation rules, expanding access to controlled frontier artificial intelligence security testing. The measure increases the pool of eligible financial companies and electronic financial businesses from 49 to 75 and raises the number of participants from 10 to as many as 15, advancing the commission’s phased testing of financial-sector AI applications. Selected firms will receive one-year no-action letters allowing them to use frontier AI and security software as a service to identify and remediate vulnerabilities. For financial companies, the minimum thresholds fall to KRW 2 trillion in assets and 300 permanent employees, from KRW 10 trillion and 1,000 employees. Electronic financial businesses must process at least KRW 2 trillion annually and derive more than 10% of revenue from that business. In both cases, the chief information security officer cannot concurrently perform other information technology duties. Participants must implement alternative controls to network separation and report findings on AI security risks, potential offensive uses and effective defenses for use in revised AI guidance and security measures. An interim review of the first test found that frontier AI could analyze millions to tens of millions of lines of source code within hours and detect existing vulnerabilities broadly and consistently. The commission plans to assess applicants in September and issue the no-action letters in October. It will use progress from the first two rounds to determine the timing and scale of a third test and consider further rounds or a permanent framework.
2026-09-03South Korea Financial Services Commission
South Korea Financial Services Commission expands AI security testing eligibility to 75 firms
The South Korea Financial Services Commission expanded eligibility for its second frontier AI security test from 49 to 75 firms and will select up to 15 participants for one-year relief from network-separation rules. Selected firms must adopt alternative security controls and report their findings, while an interim review of the first round found that AI could scan large codebases rapidly and consistently for vulnerabilities.