Skip Navigation
Menu
Newsletters

Implementation of Artificial Intelligence Guidelines in Financial Sector

2026.07.08

With the rapid development of Artificial Intelligence (“AI”), the financial sector is actively adopting AI not only for back-office operations but also for financial services and internal control functions. Considering these industry trends, financial authorities have issued guidance on how to secure the safety and reliability of AI in the financial sector, including the AI Guidelines in the Financial Sector (issued by the Financial Services Commission (the “FSC”) in July 2021), the AI Development and Utilization Guidelines for the Financial Sector (issued by the FSC and others in August 2022), and the AI Security Guidelines for the Financial Sector (issued by Financial Security Institute (“FSI”) in April 2023). Since then, as AI technologies such as generative AI and agentic AI have been incorporated in customer services in the financial sector, financial institutions have established autonomous AI governance frameworks to manage AI risks more systematically.

On December 22, 2025, the FSC announced the “(Proposed) AI Guidelines in the Financial Sector” and its plans to amend and integrate existing AI-related guidelines through the AI council in the financial sector, ahead of the enforcement of the Act on the Development of Artificial Intelligence and Establishment of Trust (the “AI Basic Act”). Under the proposed amendment, seven major financial AI principles—governance, legality, supplemental use, reliability, financial stability, good faith, and security—that financial companies and others must comply with when using AI have been announced. To support the implementation of the AI guidelines in the financial sector, in January 2026, the Financial Supervisory Service (“FSS”) prepared the “(Proposed) AI Risk Management Framework for the Financial Sector (“AI RMF”),” which is intended to serve as a reference framework for AI risk management, and the FSI prepared the “(Proposed) Working-Level Guide on AI Security for the Financial Sector,” which is intended to ensure AI system security (the aforementioned three proposed guidelines are collectively referred to as the “Drafts for Collection of Feedback”).

Thereafter, on June 18, 2026, the FSC unveiled the final version of the “Guidelines on AI in the Financial Sector (the “AI Guidelines in the Financial Sector”)” which incorporated feedback collected from the financial sector and additionally included measures to manage ultra-high-performance AI. On June 19, 2026, the FSI issued the “Guidance on AI Security for the Financial Sector” (the “Financial Sector AI Security Guidance”), which provides practical implementation guidance for the security principles set forth in the AI Guidelines in the Financial Sector, and on June 22, 2026, the FSS issued the final version of the “AI Risk Management Framework for the Financial Sector” (the “Financial Sector AI RMF”), which elaborates on the governance principles set forth in the AI Guidelines in the Financial Sector (these three guidelines are collectively referred to as the “Financial Sector AI Guidelines, Etc.”). Please refer to our newsletter dated January 5, 2026 (Link) for the key details of the Drafts for Collection of Feedback. The key changes made in the final version from the Drafts for Collection of Feedback are as follows:
 

1.

Key Changes
 

(1)

AI Guidelines in Financial Sector
 

  • The definition of “financial companies and others” was expressly expanded to include virtual asset service providers, financial holding companies, and other relevant entities, thereby clarifying that the AI Guidelines in the Financial Sector also apply to such entities[1];

  • The scope of certain principles was expanded from “high-impact AI,” (as defined under the AI Basic Act) to "high-risk AI” (as defined under the AI Guidelines in the Financial Sector);

  • Low-risk AI services were further illustrated as services that support in-house operations or assist/supplement employees' work that does not directly affect customers, such as news summaries, translations, and/or code generation;

  • Human intervention principle and emergency stop (kill switch) measures were added to address situations in which ultra-high-performance AI, such as Claude Mythos, may act in a manner that deviates from human intention;

  • It was further provided that, where financial companies and others use AI systems in the form of SaaS, they must, as AI deployers, continuously monitor and manage whether sufficient technical measures have been established and operated to ensure the security of the AI developers; and

  • With respect to the security principle, the guidelines added guidance on the “use of AI for security purposes” and data protection controls to be implemented as an alternative to network separation, where such separation is relaxed.
     

(2)

Financial Sector AI Security Guidance
 

  • It was clarified that, in order to ensure and maintain the security of AI systems, regular inspections and remediation measures are required, and that such inspections must be carried out by independent personnel who are not involved in the planning, development, or operation of the AI systems. It was also added that, where the service is of high importance or high risk, objective verification by a third party is recommended; and

  • “Practical Tip” was included to provide specific guidance and examples from a practical perspective.
     

(3)

Financial Sector AI RMF
 

  • The descriptions of risk mitigation measures related to the principles of reliability and security among the examples of AI risk mitigation measures have been partially revised; and

  • As a risk mitigation measure under the security principle, the introduction of an security-assessed external solution or the implementation of third-party security verification (AI red teaming) is recommended.
     

2.

Response Strategies

Although the Financial Sector AI Guidelines, Etc. are self-established guidelines that are not legally binding, it is advisable for financial companies and others subject to such guidelines to review government guidelines related to the use of AI technology, including the AI Guidelines in the Financial Sector, the AI Basic Act and its subordinate laws and regulations (the “AI Basic Laws”)[2] and guidelines, and the Personal Information Protection Commission's AI-related guidelines based on their own circumstances and establish a governance framework that can be effectively implemented in practice.[3] Specifically, financial companies and others need to consider the following response measures:
 

  • Establishment of AI Governance Framework: It is necessary to establish a framework based on the seven financial AI principles through, among others, establishing a decision-making body, organizing a dedicated AI risk management team, defining roles and responsibilities (R&R) across departments throughout the AI lifecycle, establishing AI lifecycle work processes and enacting and amending bylaws and manuals related to AI.

  • Establishment of Risk Assessment and Management Measures: It is necessary to establish a risk assessment framework for AI services, determine risk levels by referring to the Financial Sector AI RMF, and prepare differentiated management measures for each risk level. In particular, it would be advisable to apply the enhanced control recommended by the guidelines to “high-impact AI” under the AI Basic Act (e.g., recruitment, loan review, etc.) and AI services assessed as “high-risk AI” under the company's AI RMF.

  • Reflection in Responsibilities Structure: It may be appropriate to reflect AI-related internal control and risk management responsibilities in the responsibilities structure based on the examples provided by the Financial Sector AI RMF.

  • Security Management: When SaaS AI systems or external APIs are used, it is necessary to verify whether the requirements for alternative controls to network separation are satisfied and establish a security management framework.
     

Together with the issuance of the AI Guidelines in the Financial Sector, the FSC announced that it would review subtasks through taskforces and other channels beginning in the second half of 2026, including measures for institutional improvements needed to promote AI Transformation (“AX”) in the financial sector, risk management measures for AI adoption, and pilot program operation plans for testing initiatives such as AI agents. Financial companies and others that are actively utilizing AI should (i) establish and enhance AI governance frameworks in response to the implementation of the AI Guidelines in the Financial Sector, (ii) continuously monitor the developments in the AI Basic Laws and follow-up regulatory discussions by the financial authorities, and (iii) proactively advance their response frameworks.

In addition, the FSC is currently preparing measures to address AI security threats in the financial sector in case ultra-high-performance AI is abused in the security sector, especially in hacking. As part of this effort, the FSC is gradually relaxing regulations[4] on network separation for the use of AI for security purposes, including identifying vulnerabilities of using AI and establishing defense systems through security SaaS solutions (see the FSC's press release dated May 26, 2026, entitled “Meeting on Countermeasures against Security Threats in the Financial Sector Related to High-Performance AI”). As for the financial companies participating in these initiatives, establishing an AI governance framework is an essential task. In addition, large financial companies, particularly their AI security departments, have established and implemented roadmaps to prepare for security threats that may arise from ultra-high-performance AI and establish frameworks for AI security and security through AI (“Security for AI, AI for Security”). Meanwhile, AI strategy departments responsible for promoting AX are enhancing their AX implementation strategies in light of the gradual relaxation of network-separation requirements.

Taken together, these regulatory and technological developments suggest that, for financial institutions using AI in offering of financial products and services, a key task in the second half of 2026 will be to design and implement an integrated AI governance, risk management, and compliance framework from a holistic perspective encompassing legal, technological, and security considerations. Accordingly, financial institutions and others will need to enhance the AI technology and risk management capabilities of their employees and relevant departments, and establish a medium to long-term roadmap in order to respond proactively to the era of sweeping financial AX transformation.
 


[1] For reference, non-financial companies (e.g., fintech companies) may also be subject to the guidelines if the results of using AI systems by the non-financial companies may affect the offering of financial transactions.
[2] While the AI Basic Laws prevail in areas where the AI Basic Laws and the Financial Sector AI Guidelines, Etc. overlap, the Financial Sector AI Guidelines, Etc. apply to specialized financial matters not addressed in the AI Basic Laws. Accordingly, it is critical to establish a response framework by clearly distinguishing the scope of application between the two sets of rules.
[3] s provided in the AI Guidelines in the Financial Sector, each company may, at its own discretion, determine the level of application of the guidelines by taking into account all of its level of AI use, the impact of AI use, its own environment and resources, including human and physical resources, types of services, and the provisions of the AI Basic Laws, etc.
[4] 49 financial companies with dedicated CISOs can apply under the Electronic Financial Transactions Act if they meet the following requirements: total assets of a certain size (total assets of KRW 10 trillion or more) and the number of employees (number of full-time employees of 1,000 or more).

 

[Korean Version]

 

Share

Close

Professionals

CLose

Professionals

CLose