
In the third and fourth weeks of May, discussions that looked different in character were held one after another. On the 20th, at the National Assembly Members' Office Building, there was a forum on the liability questions raised by AI that has a body, such as robots and autonomous driving, and on the 21st in Gangnam a seminar on responding to AI and cybersecurity regulation was held for exporting companies. On the 22nd the Financial Services Commission discussed the security threats of high-performance AI at the Financial Security Institute in Yongin and put forward a plan to ease network separation rules.
All three events touched on the same question. Regulatory attention is moving from what AI said to what AI moved and who bears responsibility for the result.
Until now AI regulation has been aimed at the sources of training data and the accuracy of outputs. Large language models choose the next word by probability on the basis of the statistical relationships among the words contained in their training data, so hallucination, the plausible fabrication of false content, is built in from the cause. One case came at the end of 2025, when a certified labor attorney cited in a brief a nonexistent precedent made up by ChatGPT in an unfair dismissal case. In March 2026 the Supreme Court, through a dedicated task force, put forward measures requiring disclosure of the use of AI and sanctioning the citation of false statutes.
At Air Canada in 2024, a chatbot gave guidance on refunds and discounts that were not in the rules. It was a case showing that a wrong sentence can be treated as the company's promise. Harm up to that point is converted into documents and money. Things change when the other party has arms or wheels.
That was where the focus of the National Assembly forum lay. The current Product Liability Act requires the victim to prove directly that a defect existed and the causal relationship by which that defect led to the harm. Attorney Seo Chi-won noted that in lawsuits over autonomous driving and advanced driver assistance systems, courts have repeatedly acknowledged that it is difficult for consumers to prove their case and yet dismissed the claims on the ground that proof of a defect fell short. The question raised is whether it is right to apply the same standard to victims when manufacturers hold the software logs and the sensor records.
The controversy over Hyundai Motor's introduction of Atlas pushed the term "physical AI" to the front of the discussion. A proposal to shift the burden of proof toward manufacturers was made, but whether a bill containing it has been introduced has not been confirmed.

Exporters are feeling this shift fastest. According to Yang Song-i, chair of the TBT AI and Cybersecurity Committee at the Korean Agency for Technology and Standards (CEO of Connect AI), overseas buyers check at the contract stage which part of a product contains AI, whether customer data is used for training, in what way security updates are provided, and who receives vulnerability reports and who patches them. A growing number of companies are being asked to provide in document form a list of AI functions, a data flow diagram, vulnerability response procedures, the software bill of materials known as SBOM, and an incident response system.
The EU Cyber Resilience Act is the background. In force since December 10, 2024, with its main obligations applying from December 11, 2027, the law imposes security requirements across hardware and software products that contain digital elements. Manufacturers must build security into every stage of planning, design, development and maintenance, and even after a product is sold they must manage vulnerabilities and provide updates throughout its life cycle. It is a form in which regulation works as a gateway to market entry beyond approval procedures.
In the financial sector a measure running in the opposite direction came out. The Financial Services Commission is accepting applications to ease network separation only from the 49 financial companies that meet the requirements of 10 trillion won or more in total assets and 1,000 or more full-time employees and that have a dedicated CISO under the Electronic Financial Transactions Act. Companies that are approved may use vulnerability testing with high-performance AI and security SaaS solutions on a temporary basis for one year. The measures began from concern that Mythos, a high-performance AI from Anthropic of the United States, could find old security vulnerabilities and be abused for hacking.
The logic is that since the attacking side has begun using AI, the same tool is allowed to the defending side. The first round of review covers no more than 10 companies and will be completed in June-July, the second round targets 10-20 companies in August-September, and the third round runs in the fourth quarter. For financial companies that do not apply, the Financial Security Institute will support AI vulnerability checks aimed at external attack surfaces for up to 17 companies by July. A financial AI security research institute and an AI security support center for small and mid-sized financial companies will each be newly set up at the Financial Security Institute, and a private technical advisory group with academia and industry taking part will also be formed.
Easing and tightening appear to be going on at the same time, but the principle is the same. The move is from a way of blocking risk in advance to a way of opening the door to actors with the necessary capacity while placing after-the-fact responsibility and management duties on them. Through the AI Framework Act, the government is imposing risk management duties on businesses that develop and provide AI in high-risk areas. Whether the point at which the door opens and the procedure for assigning responsibility are moving at the same pace is a separate matter.
Two things will be confirmed in June. The Financial Services Commission will distribute AI security guidelines covering classification criteria for computing resources and priorities for program patches, and the results of the first round of review for easing network separation will come out. In the meantime, AI with a body keeps increasing in factories and on roads. What a person pushed by a robot has to prove with the medical certificate handed to them at the hospital remains unsettled, and June's schedule has no entry for it.
