With the rapid development of Artificial Intelligence (“AI”), the financial sector is actively adopting AI not only for back-office operations but also for financial services and internal control functions. Considering these industry trends, financial authorities have issued guidance on how to secure the safety and reliability of AI in the financial sector, including the AI Guidelines in the Financial Sector (issued by the Financial Services Commission (the “FSC”) in July 2021), the AI Development and Utilization Guidelines for the Financial Sector (issued by the FSC and others in August 2022), and the AI Security Guidelines for the Financial Sector (issued by Financial Security Institute (“FSI”) in April 2023). Since then, as AI technologies such as generative AI and agentic AI have been incorporated in customer services in the financial sector, financial institutions have established autonomous AI governance frameworks to manage AI risks more systematically.
On December 22, 2025, the FSC announced the “(Proposed) AI Guidelines in the Financial Sector” and its plans to amend and integrate existing AI-related guidelines through the AI council in the financial sector, ahead of the enforcement of the Act on the Development of Artificial Intelligence and Establishment of Trust (the “AI Basic Act”). Under the proposed amendment, seven major financial AI principles—governance, legality, supplemental use, reliability, financial stability, good faith, and security—that financial companies and others must comply with when using AI have been announced. To support the implementation of the AI guidelines in the financial sector, in January 2026, the Financial Supervisory Service (“FSS”) prepared the “(Proposed) AI Risk Management Framework for the Financial Sector (“AI RMF”),” which is intended to serve as a reference framework for AI risk management, and the FSI prepared the “(Proposed) Working-Level Guide on AI Security for the Financial Sector,” which is intended to ensure AI system security (the aforementioned three proposed guidelines are collectively referred to as the “Drafts for Collection of Feedback”).
Thereafter, on June 18, 2026, the FSC unveiled the final version of the “Guidelines on AI in the Financial Sector (the “AI Guidelines in the Financial Sector”)” which incorporated feedback collected from the financial sector and additionally included measures to manage ultra-high-performance AI. On June 19, 2026, the FSI issued the “Guidance on AI Security for the Financial Sector” (the “Financial Sector AI Security Guidance”), which provides practical implementation guidance for the security principles set forth in the AI Guidelines in the Financial Sector, and on June 22, 2026, the FSS issued the final version of the “AI Risk Management Framework for the Financial Sector” (the “Financial Sector AI RMF”), which elaborates on the governance principles set forth in the AI Guidelines in the Financial Sector (these three guidelines are collectively referred to as the “Financial Sector AI Guidelines, Etc.”). Please refer to our newsletter dated January 5, 2026 (Link) for the key details of the Drafts for Collection of Feedback. The key changes made in the final version from the Drafts for Collection of Feedback are as follows:
|
1. |
Key Changes |
|
(1) |
AI Guidelines in Financial Sector
|
|
(2) |
Financial Sector AI Security Guidance
|
|
(3) |
Financial Sector AI RMF
|
|
2. |
Response Strategies
Together with the issuance of the AI Guidelines in the Financial Sector, the FSC announced that it would review subtasks through taskforces and other channels beginning in the second half of 2026, including measures for institutional improvements needed to promote AI Transformation (“AX”) in the financial sector, risk management measures for AI adoption, and pilot program operation plans for testing initiatives such as AI agents. Financial companies and others that are actively utilizing AI should (i) establish and enhance AI governance frameworks in response to the implementation of the AI Guidelines in the Financial Sector, (ii) continuously monitor the developments in the AI Basic Laws and follow-up regulatory discussions by the financial authorities, and (iii) proactively advance their response frameworks. |
[1] For reference, non-financial companies (e.g., fintech companies) may also be subject to the guidelines if the results of using AI systems by the non-financial companies may affect the offering of financial transactions.
[2] While the AI Basic Laws prevail in areas where the AI Basic Laws and the Financial Sector AI Guidelines, Etc. overlap, the Financial Sector AI Guidelines, Etc. apply to specialized financial matters not addressed in the AI Basic Laws. Accordingly, it is critical to establish a response framework by clearly distinguishing the scope of application between the two sets of rules.
[3] s provided in the AI Guidelines in the Financial Sector, each company may, at its own discretion, determine the level of application of the guidelines by taking into account all of its level of AI use, the impact of AI use, its own environment and resources, including human and physical resources, types of services, and the provisions of the AI Basic Laws, etc.
[4] 49 financial companies with dedicated CISOs can apply under the Electronic Financial Transactions Act if they meet the following requirements: total assets of a certain size (total assets of KRW 10 trillion or more) and the number of employees (number of full-time employees of 1,000 or more).




