2026-09-03 | 87645

Added · Updated

Temporary Easing of Network Separation Rule Available for More Financial Companies for AI Cybersecurity Purpose

The Financial Services Commission discussed measures for the second phase easing of the network separation rule, broadening eligibility to include nonbank financial companies and electronic financial service providers. For financial companies, eligibility criteria are eased to KRW2 trillion or more in total assets and 300 or more regular staff, while electronic financial service providers require an annual electronic financial transactions volume of KRW2 trillion or more and over 10 percent of sales from electronic financial services. Selected companies, totaling 15 from 75 eligible entities, will receive a one-year no-action letter in October, allowing them to temporarily ease the network separation rule to utilize frontier AI models and SaaS programs for cybersecurity purposes, provided they establish adequate internal control mechanisms and report test findings. Applications for this second phase testing are open from September 3 to 14.

Financial Services Commission Korea logo

South Korea

Financial Services Commission Korea

Click to view thumbnail

Press Releases

FaceBook

Twitter

NaverBlog

KakaoStory

Copy URL

Temporary Easing of Network Separation Rule Available for More Financial Companies for AI Cybersecurity Purpose Sep 03, 2026

The Financial Services Commission held a meeting on frontier AI and cybersecurity strategy with officials from the Financial Supervisory Service and the Financial Security Institute on September 3. At the meeting, officials discussed specific measures for the second phase easing of the network separation rule for financial companies.

For the second phase easing of the network separation rule, the eligibility criteria and the size of selected companies will be broadened up to include nonbank financial companies and electronic financial service providers, which will help to facilitate more financial companies to test frontier AI models to bolster their cybersecurity capacity.

The total number of eligible companies for the second phase testing is 75, an increase from 49 eligible entities for the first phase testing. The size of selected companies will also be increased to 15 entities from 10 companies previously. After preparing adequate internal control mechanisms, selected companies will be able to utilize frontier AI models and SaaS programs to identify and improve upon their own cybersecurity risks.

More specifically, the eligibility criteria will be eased from the current level of KRW10 trillion or more in total assets with a regular staff size of 1,000 or more to KRW2 trillion or more in total assets with a regular staff size of 300 or more. The chief information security officer (CISO) should not concurrently hold another information technology-related position within the company. There are 59 companies in total that currently meet these standards.

For electronic financial service providers, a distinct set of eligibility criteria will be applied. They should have an annual electronic financial transactions volume of KRW2 trillion or more and have more than 10 percent of sales generated in the field of electronic financial services. The CISO should not concurrently hold another information technology-related position within the company. There are 16 companies in total that currently meet these standards.

Those wishing to take part in the second phase testing can apply from September 3 to 14. An application review process will take place in September to evaluate the cybersecurity and AI utilization capacity of companies. After that, a no-action letter (for one year) will be issued in October to selected companies to allow a temporary easing of the network separation rule.

Once selected, financial companies and electronic financial service providers will be able to use frontier AI models and SaaS programs for cybersecurity purposes. To supplant the network separation requirement and make sure that they are equipped with adequate cybersecurity measures, companies will need to draw up relevant internal control mechanisms.

Additionally, they will need to report test findings, such as specific characteristics of AI cybersecurity risks, anticipated threats of frontier AI when used in cyberattack, and response strategies to boost cyberdefense capacity. Such findings will then be utilized in making updates to AI guidelines and preparing cybersecurity measures.

Based on the outcome of operating the first and second phase testing, the government will decide on the schedule and selection size for the third phase testing. Depending on the level of demand shown by companies thereafter, the FSC may consider continuing to offer the temporary easing of the network separation rule or seek a complete lifting of the network separation rule on a permanent basis.

  • Please refer to the attached PDF for details.

PREV

Capital Markets Rules Change on Merger Value Expected to Boost Fairness and Prevent Price Distortion

NEXT

No results found.

List

Related Materials

May 25, 2026

Network Separation Rules to be Eased in Financial Sector to Boost Innovation and Cybersecurity in AI Transformation

Apr 20, 2026

Financial Companies Will be Able to Use Cloud-based Software as a Service on Internal Network from April 20

Aug 13, 2024

FSC Introduces Roadmap to Make Improvements to Network Separation in Financial Industry

More like this from FSC

FSC published 5 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share