
Digital rights management (DRM) is drawing renewed attention as artificial intelligence and cloud computing widen the range of places corporate data travels. Unlike conventional security, which focuses on blocking outside intrusion, DRM encrypts sensitive data itself and controls access rights by user, so that even if files leave the company, the contents cannot be read or used. As companies increasingly move internal data to the cloud and to AI systems in order to apply generative AI to their work, DRM is expanding beyond document security into a core data security technology for the AI era.
DRM is technology that controls unauthorized use of or access to digital content. Ordinary consumers know it as technology that prevents illegal copying of music and video, but in South Korea's corporate security market the term usually refers to enterprise data security solutions that are classified overseas as enterprise DRM, or EDRM.
The key is that it protects the data itself rather than the place where the data sits. A document is encrypted the moment it is created, and permissions are checked each time a user opens the file. When an authorized user runs an encrypted document, user authentication, permission verification, retrieval of the encryption key and decryption are carried out automatically. Depending on the permissions granted, controls can extend beyond opening a document to individual actions such as editing, copying, printing and screen capture.
For companies, the advantage is that security holds even after a file leaves internal systems. If a hacker breaks through a corporate network and steals a file, or an insider takes material outside, the encryption and usage rights remain in place and prevent the information from being exposed. In effect, it adds another line of defense that protects the data itself, on top of existing security systems designed to stop cyberattacks from penetrating a company in the first place.

Fasoo AI (150900.KQ), the leading DRM company in South Korea, takes the same data-centered approach with its Fasoo Enterprise DRM, or FED. The product automatically encrypts files in real time the moment they are created and keeps them encrypted as they are distributed and used. It breaks down usage rights for each piece of data and tracks usage history. Fasoo AI defines this as Hyper DRM, a step beyond conventional DRM.
FED focuses in particular on maintaining the same security policy regardless of where a document is stored. Corporate documents were once concentrated on in-house PCs and file servers, but storage and usage environments have become more dispersed in recent years, spreading to mobile devices and the cloud. FED encrypts documents from the moment of creation and maintains security not only on PCs, servers and mobile devices but also in cloud environments.
Design drawings in manufacturing, where security is relatively difficult to apply, are also covered. Computer-aided design files, which contain a company's core technologies and intellectual property, have been hard to bring under a consistent security policy because they are handled across many different programs and versions. FED encrypts drawing files regardless of the CAD program or version and allows the entire process of creation and distribution to be tracked and managed.
The product also supports varied work environments, including Mac. On Mac, it applies encryption of the data itself, screen capture blocking and watermarking. Fasoo AI says this narrows the security blind spots that can arise when operating systems or work environments differ.

What has changed DRM's role most in recent years is generative AI. For companies to apply generative AI such as Microsoft Copilot to their work, they must use internal documents in cloud environments. But if encrypted documents have to be unlocked every time, the risk of data leakage rises and the use of AI is constrained.
Fasoo AI addressed this by linking its product with Microsoft 365. Local documents encrypted with FED are automatically converted into Microsoft Information Protection documents in the Microsoft 365 environment, so they can be used in the cloud while retaining existing policies and permissions. That allows them to be used for collaboration and also as training data for Microsoft Copilot. For companies, it reduces the either-or choice between giving up AI for the sake of security and loosening security in order to use AI.
The full process from a document's creation to its disposal can also be managed. FED tracks the entire life cycle of data, including creation, derivative versions and disposal, and applies different security policies at each stage. DRM's role is shifting beyond simply locking files toward a data control platform that manages who used which document, when and how.
Fasoo AI has recently extended its protection to source code. Because source code is read and written repeatedly across a variety of development tools and applications, applying conventional file-level encryption as is can slow development. The company is therefore using approaches such as virtualization and isolation to protect source code, a core corporate asset, without significantly changing developers' work environments.
An official at Fasoo AI said that in an environment where data constantly moves between the cloud, generative AI and mobile devices, unlike the era when data stayed on in-house PCs and servers, it is difficult to set security boundaries based solely on where data is located. "The more AI broadens the scope of how corporate data is used, the more DRM's role is shifting from a document lock to security infrastructure that controls the data itself," the official said.







