브레스저널 The Breath Journal

This article was translated automatically from the Korean original. Read the original in Korean

Thirteen years of network separation, the axis of regulation moves

곽동현·Published 2026-02-12 20:45 KST
To records instead of blocking, financial and content regulation converge on one path
Lines of records are laid where the blocking wall has disappeared
Lines of records are laid where the blocking wall has disappeared / ⓒ Breath Journal

The Financial Services Commission is reviewing the whole body of financial regulation that blocks commercial banks from using generative AI. At the center of the review, led by the Director General for Digital Finance Policy, is the question of changing the principle of "physical network separation," kept in place for 13 years, to "logical network separation." Physical network separation lays the internet network and the business network on entirely different lines, while logical network separation uses a single line but divides data and access rights through software. The review has not moved beyond internal discussion, and no date has been set for putting it into effect.

The substance of this change is already out in the field. On the 21st of last month, the Bank of Korea applied the National Intelligence Service's multi-layered security system and divided its work data into three grades: confidential, sensitive and public. It then allowed AI to be used on the internal network only for data in the public grade. Instead of blocking all data alike, it turned the principle toward handling data differently by grade.

A grade tag is attached to each piece of data, access rights are divided by grade, the channel that calls outside AI services is controlled, and activity logs of who did what are recorded in full. If the first three devices set "how far to allow," the log record makes it possible "to trace back later what happened." The core of this trend lies in that full recording of activity logs.

Why the banks have been waiting for this change becomes clear from the procedures they have gone through. Major commercial banks including KB Kookmin, Shinhan, Hana and Woori have repeatedly applied for the regulatory sandbox, that is, designation as an innovative financial service, in order to use Microsoft 365, ChatGPT and Slack on their internal networks. It means that tools used at ordinary workplaces without any particular approval could be used by bank employees only with case-by-case exemptions. An official at the Financial Services Commission said it is also looking at the need to revise the existing "financial AI guidelines" and ease regulations on data use.

The same principle appears in an entirely different area. The EU plans to put out in June the final draft of a code of practice covering the labeling and transparency of AI-generated content. The body that will announce it and the scope of its binding force have not been fixed, but the point it aims at is clear. Instead of banning the use of AI itself, it makes the fact of use visible.

Industry self-regulation had reached the same conclusion earlier. In its production guidelines last August, Netflix recognized generative AI as an aid to creation, while requiring partner production companies not to infringe copyright, to keep the data they enter from being reused in model training, and to respect creators' rights. It is a guideline to leave traces of use.

In Korea, the "Framework Act on the Development of AI and the Establishment of a Basis for Trust" took effect on the 22nd of last month. The act sets a grace period for guidance, so sanctions do not operate right away. Assessments of whether Korean regulation is heavier or lighter than that of other regions are still divided. There is the reading that it is moving toward easing, and the reading that putting the framework act into effect ahead of time has imposed a burden.

The technology supply side is moving in line with these conditions as well. The AI solutions company Slexon will take part in AW 2026, held at COEX in Seoul on March 4-6, and present an on-premise AI-native R&D platform. On-premise places the system on the company's internal servers instead of an outside cloud. The setup joins Puteron AI, an LLM infrastructure, the coding tool CodeCenter and the history management tool Trace.Space, and targets corporate R&D sites where AI adoption has been put off because of security and network constraints.

The remaining tasks are also clear. Leaving logs and actually looking into those logs are different things. Who will assign data grades and by what standard, and who takes responsibility when they are assigned wrongly, remain at the design stage. Whether the private financial sector can take the National Intelligence Service's system and use it as it is another matter to be settled.

Picture a bank teller reviewing loan documents and asking an AI something. Right now, an exemption approval is needed before asking that way. Once the axis of regulation has moved, the question can be asked at once, and in return, which grade of data that exchange touched is quietly recorded. The demonstration stand at COEX in March and the EU's announcement of the code in June will be two checkpoints showing how far the grammar of that record has been agreed.

By Kwak Dong-hyun · Breath.Tech

Related articles

댓글