
As agentic AI that makes its own judgments and executes tasks on external systems spreads, so does the risk that AI itself becomes a tool for attacks. At the same time, AI is emerging as a key means of blocking attacks by analyzing vast volumes of security logs and anomalies. Some warn that once physical AI operating in the real world becomes fully commercialized, security threats could move beyond data leaks to actual physical damage. In response, the government is developing both technologies to safely control AI itself and technologies that use AI as a defensive tool.
According to information technology industry sources on the 15th, the Ministry of Science and ICT and its affiliated agencies are simultaneously pursuing next-generation AI security standards, a cybersecurity-specialized AI foundation model, an AI-based autonomous security operations platform, and research and development on building security into the AI ecosystem. It is a two-track strategy that develops both "AI for Security," which uses AI to detect, analyze and respond to threats, and "Security for AI," which safely controls the permissions and behavior of AI itself.
Developing an AI Agent Security Guide: Preventing Risk Through AI Control
A leading example of "Security for AI" is the AI Security Guide v2.0 being developed by the Korea Internet & Security Agency (KISA). KISA defines next-generation AI as agentic AI and physical AI, and has identified misuse of AI execution permissions, sensor interference, physical malfunctions and verification of autonomous decision-making as new security challenges. It plans to require developers to limit the permissions and access scope available to AI and to keep records of its judgments and actions, and to require service providers to establish systems that can intervene in AI execution and trace accountability when incidents occur. For users, it presents procedures for setting the permissions delegated to AI and requiring separate approval for high-risk actions. Threat scenarios will be created for individual industries such as telecommunications, healthcare and manufacturing, along with proof-of-concept (PoC) testing.
The government is moving toward AI control because the nature of security threats is itself changing. With existing generative AI, the main risks were seen as leaks of personal information or corporate secrets and incorrect answers. But as agentic AI enters the work systems of companies and public institutions, the permissions granted to AI are themselves becoming a new point of attack.
In a survey of companies conducted this year by the Cloud Security Alliance (CSA), 82% of respondents said AI agents existed within their organizations that they had not identified, and 65% said they had experienced a security incident involving AI agents over the past year. Among companies that had experienced incidents, 61% suffered data exposure, 43% disruption to operations and 35% financial losses.
Cases of AI acting outside its permitted scope have also emerged. This year, AI agents developed by OpenAI were found to have communicated with each other through unauthorized external websites during a security experiment. GPT-6 Astra, released this month, was classified in OpenAI's own evaluation as the first model to reach a "Critical" level of cybersecurity capability. OpenAI accordingly strengthened safeguards during development, including isolated environments, restrictions on network and tool access, and monitoring.
The problem is that the scale of potential damage grows as such AI moves into finance, healthcare and manufacturing. In finance, customer information lookups and payment and remittance systems can be connected to AI; in healthcare, patient records and medical devices; and in manufacturing, production equipment. If an AI account is hijacked or granted more permissions than necessary, the result could go beyond data leaks to incorrect task execution, service outages and equipment malfunctions.
AI as a Shield: All-Out Effort to Detect Threats With AI Agents
Conversely, as attacks become automated and more sophisticated through AI, defense also requires AI. That is why the government is pursuing a cybersecurity-specialized AI foundation model and an autonomous security operations platform together. The cybersecurity-specialized AI foundation model project aims to develop an independent AI model tailored to cybersecurity rather than a general-purpose AI, building up domestic security AI capabilities and accelerating the AI transformation of the security industry. It is being led by the Ministry of Science and ICT and the National IT Industry Promotion Agency (NIPA).
The autonomous security operations platform is a project to have AI agents automatically carry out the detection, analysis and response to security threats. In May, the government selected 18 projects and 50 participating companies through a 12.04 billion won ($8.7 million) support program for new information security technologies. Among them is an agentic AI-based autonomous integrated security operations platform involving Logpresso, Monitorapp, Sands Lab and Tatum.






