Temporary Easing of Network Separation Rule Available for More Financial Companies for AI Cybersecurity PurposeSep 03, 2026

The Financial Services Commission held a meeting on frontier AI and cybersecurity strategy with officials from the Financial Supervisory Service and the Financial Security Institute on September 3. At the meeting, officials discussed specific measures for the second phase easing of the network separation rule for financial companies.

 

For the second phase easing of the network separation rule, the eligibility criteria and the size of selected companies will be broadened up to include nonbank financial companies and electronic financial service providers, which will help to facilitate more financial companies to test frontier AI models to bolster their cybersecurity capacity.

 

The total number of eligible companies for the second phase testing is 75, an increase from 49 eligible entities for the first phase testing. The size of selected companies will also be increased to 15 entities from 10 companies previously. After preparing adequate internal control mechanisms, selected companies will be able to utilize frontier AI models and SaaS programs to identify and improve upon their own cybersecurity risks.

 

More specifically, the eligibility criteria will be eased from the current level of KRW10 trillion or more in total assets with a regular staff size of 1,000 or more to KRW2 trillion or more in total assets with a regular staff size of 300 or more. The chief information security officer (CISO) should not concurrently hold another information technology-related position within the company. There are 59 companies in total that currently meet these standards.

 

For electronic financial service providers, a distinct set of eligibility criteria will be applied. They should have an annual electronic financial transactions volume of KRW2 trillion or more and have more than 10 percent of sales generated in the field of electronic financial services. The CISO should not concurrently hold another information technology-related position within the company. There are 16 companies in total that currently meet these standards.

 

Those wishing to take part in the second phase testing can apply from September 3 to 14. An application review process will take place in September to evaluate the cybersecurity and AI utilization capacity of companies. After that, a no-action letter (for one year) will be issued in October to selected companies to allow a temporary easing of the network separation rule.

 

Once selected, financial companies and electronic financial service providers will be able to use frontier AI models and SaaS programs for cybersecurity purposes. To supplant the network separation requirement and make sure that they are equipped with adequate cybersecurity measures, companies will need to draw up relevant internal control mechanisms.

 

Additionally, they will need to report test findings, such as specific characteristics of AI cybersecurity risks, anticipated threats of frontier AI when used in cyberattack, and response strategies to boost cyberdefense capacity. Such findings will then be utilized in making updates to AI guidelines and preparing cybersecurity measures.

 

Based on the outcome of operating the first and second phase testing, the government will decide on the schedule and selection size for the third phase testing. Depending on the level of demand shown by companies thereafter, the FSC may consider continuing to offer the temporary easing of the network separation rule or seek a complete lifting of the network separation rule on a permanent basis.


* Please refer to the attached PDF for details.