AI That Hacks vs. AI That Defends: Korea Builds Both

Government Strengthens AI Control and Defense Technologies Together Security Standards Being Drafted for Agentic and Physical AI Response Begins to Misuse of AI Permissions and Malfunctions Security-Specialized AI and Autonomous Platforms Pushed Forward Spread Into Finance, Healthcare and Manufacturing Raises Fears of Real-World Harm

Technology|
|
By Seo Ji-hyewise@sedaily.com
||
Photo generated by ChatGPT - Seoul Economic Daily Technology News from South Korea
Photo generated by ChatGPT

As agentic AI that makes its own judgments and executes tasks on external systems spreads, so does the risk that AI itself becomes a tool for attacks. At the same time, AI is emerging as a key means of blocking attacks by analyzing vast volumes of security logs and anomalies. Some warn that once physical AI operating in the real world becomes fully commercialized, security threats could move beyond data leaks to actual physical damage. In response, the government is developing both technologies to safely control AI itself and technologies that use AI as a defensive tool.

According to information technology industry sources on the 15th, the Ministry of Science and ICT and its affiliated agencies are simultaneously pursuing next-generation AI security standards, a cybersecurity-specialized AI foundation model, an AI-based autonomous security operations platform, and research and development on building security into the AI ecosystem. It is a two-track strategy that develops both "AI for Security," which uses AI to detect, analyze and respond to threats, and "Security for AI," which safely controls the permissions and behavior of AI itself.

Developing an AI Agent Security Guide: Preventing Risk Through AI Control

A leading example of "Security for AI" is the AI Security Guide v2.0 being developed by the Korea Internet & Security Agency (KISA). KISA defines next-generation AI as agentic AI and physical AI, and has identified misuse of AI execution permissions, sensor interference, physical malfunctions and verification of autonomous decision-making as new security challenges. It plans to require developers to limit the permissions and access scope available to AI and to keep records of its judgments and actions, and to require service providers to establish systems that can intervene in AI execution and trace accountability when incidents occur. For users, it presents procedures for setting the permissions delegated to AI and requiring separate approval for high-risk actions. Threat scenarios will be created for individual industries such as telecommunications, healthcare and manufacturing, along with proof-of-concept (PoC) testing.

The government is moving toward AI control because the nature of security threats is itself changing. With existing generative AI, the main risks were seen as leaks of personal information or corporate secrets and incorrect answers. But as agentic AI enters the work systems of companies and public institutions, the permissions granted to AI are themselves becoming a new point of attack.

In a survey of companies conducted this year by the Cloud Security Alliance (CSA), 82% of respondents said AI agents existed within their organizations that they had not identified, and 65% said they had experienced a security incident involving AI agents over the past year. Among companies that had experienced incidents, 61% suffered data exposure, 43% disruption to operations and 35% financial losses.

Cases of AI acting outside its permitted scope have also emerged. This year, AI agents developed by OpenAI were found to have communicated with each other through unauthorized external websites during a security experiment. GPT-6 Astra, released this month, was classified in OpenAI's own evaluation as the first model to reach a "Critical" level of cybersecurity capability. OpenAI accordingly strengthened safeguards during development, including isolated environments, restrictions on network and tool access, and monitoring.

The problem is that the scale of potential damage grows as such AI moves into finance, healthcare and manufacturing. In finance, customer information lookups and payment and remittance systems can be connected to AI; in healthcare, patient records and medical devices; and in manufacturing, production equipment. If an AI account is hijacked or granted more permissions than necessary, the result could go beyond data leaks to incorrect task execution, service outages and equipment malfunctions.

AI as a Shield: All-Out Effort to Detect Threats With AI Agents

Conversely, as attacks become automated and more sophisticated through AI, defense also requires AI. That is why the government is pursuing a cybersecurity-specialized AI foundation model and an autonomous security operations platform together. The cybersecurity-specialized AI foundation model project aims to develop an independent AI model tailored to cybersecurity rather than a general-purpose AI, building up domestic security AI capabilities and accelerating the AI transformation of the security industry. It is being led by the Ministry of Science and ICT and the National IT Industry Promotion Agency (NIPA).

The autonomous security operations platform is a project to have AI agents automatically carry out the detection, analysis and response to security threats. In May, the government selected 18 projects and 50 participating companies through a 12.04 billion won ($8.7 million) support program for new information security technologies. Among them is an agentic AI-based autonomous integrated security operations platform involving Logpresso, Monitorapp, Sands Lab and Tatum.

Original reporting by Seo Ji-hye for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
4:02

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.