The Four Major Banks to Invest KRW 1.8 Trillion and Accelerate AI Transformation
- Input
- 2026-07-21 18:23:16
- Updated
- 2026-07-21 18:23:16

According to the information security disclosure portal of Korea Internet & Security Agency (KISA) on the 21st, the four major banks spent a combined KRW 1.8086 trillion on IT last year. KB Kookmin Bank led the group with KRW 531.5 billion, followed by Shinhan Bank with KRW 463.4 billion, Hana Bank with KRW 412.1 billion and Woori Bank with KRW 401.7 billion.
This figure does not represent AI investment alone. It includes computer systems, software, digital channels, data platforms, information security and business systems.
Under KISA's standards, spending on AI-related items such as service fees for AI tools can also be counted as IT investment. To apply AI to actual financial operations, banks need more than just data collection and cleaning. They also need system integration, computing infrastructure and access control, which is why the spending is seen as foundational investment supporting AI transformation.
The institutional framework for AI has also been established. The Framework Act on the Development of Artificial Intelligence took effect in January, and the revised financial-sector AI guidelines were implemented on the 22nd of last month. The guidelines cover loan screening, credit evaluation, chatbots, financial product comparison and recommendation, the Fraud Detection System (FDS), and AI tools that support internal operations. Each financial company may decide how strictly to apply the guidelines based on its human and physical resources, the scope of AI use and the level of service risk.
At the core of the guidelines are seven principles: governance, legality, auxiliary use, reliability, financial stability, good faith and security. They clarify the roles and responsibilities of management, and state that AI should be used as a support tool while final decisions and accountability remain with employees. Financial firms must also prioritize consumer interests and establish security standards, inspection procedures and improvement systems for AI use.
The guidelines also require firms to provide notice, explanation and objection procedures, as required by law, when making decisions unfavorable to customers, such as loan denials or transaction blocks. They must also retain related logs and records of approval and review. The rules further call for regular checks against AI-specific security threats, including data and model contamination, leakage of data or model information, and prompt injection, as well as response systems tailored to the level of risk.
A financial industry official said, "Banks and other financial firms are applying AI agents to internal operations first, then continuously improving their functions by reflecting user feedback." The official added, "While continuing in-house development, they are also expanding the scope of AI use by working with outside specialists to apply the technologies needed for real-world operations."
[email protected] Ye Byeong-jeong Reporter