Thursday, September 3, 2026

"Active Response to Claude Mythos Threats"...FSC Eases Eligibility for Second Test

Input
2026-09-03 15:00:00
Updated
2026-09-03 15:00:00
Provided by the Financial Services Commission
[Financial News] The Financial Services Commission (FSC) has significantly eased the eligibility requirements for companies seeking to conduct security checks using Claude Mythos-level artificial intelligence (AI) in response to Claude Mythos threats. The move allows small and midsize financial companies and electronic financial business operators, which were previously unable to apply for emergency relaxation of network separation regulations, to submit applications.
On the 3rd, the FSC held the fifth meeting of the “Frontier AI Situation Response Team” at Government Complex Seoul, chaired by Yoo Young-jun, director general of digital financial policy, together with the Financial Supervisory Service and the Financial Security Institute. The meeting finalized detailed measures for the second emergency relaxation of network separation regulations to enable the use of AI for security purposes. The measures were prepared following discussions and consultations with the FSC’s Active Administration Committee and a private-sector technology advisory group.
Under the second emergency relaxation of network separation regulations, eligibility requirements have been eased to include small and midsize financial companies and electronic financial business operators. The number of eligible applicants will therefore increase from 49 to 75—59 financial companies and 16 electronic financial business operators. The number selected will also rise from 10 to no more than 15.
For financial companies, the previous requirements of total assets of at least 10 trillion won and at least 1,000 permanent employees have been eased to total assets of at least 2 trillion won and at least 300 permanent employees. The chief information security officer (CISO) must not concurrently hold another position in the information technology division. Electronic financial business operators must have annual electronic financial transaction volumes of at least 2 trillion won, with revenue related to electronic financial services accounting for more than 10% of total revenue. Their CISOs are likewise subject to restrictions on holding concurrent positions.
Applications will be accepted from September 3 through September 14. After the private-sector technology advisory group and others assess applicants’ security capabilities and AI utilization capacity, one-year no-action letters on network separation regulations are expected to be issued following a report to the FSC on October 7. Selected financial companies and electronic financial business operators will participate in detecting and addressing security vulnerabilities using Frontier AI and security software as a service (SaaS), and will be required to establish alternative controls to network separation. Key findings from the tests, including AI security risks and response procedures, will be reported to the government. The government plans to use them to revise AI guidelines and develop security measures.
An interim review of the first test found that Frontier AI was effective at identifying vulnerabilities, analyzing vast source codebases ranging from several million to tens of millions of lines within hours. It consistently searched for existing vulnerabilities across a broad scope and quickly identified weaknesses without performance differences based on users’ experience or capabilities. Because the financial sector applies various security measures, including intrusion prevention and blocking systems, the vulnerabilities discovered are unlikely to immediately lead to security incidents. However, the review highlighted the need to strengthen response capabilities by identifying and managing the attack surface of externally exposed IT assets, applying security patches promptly, and building AI-based response systems.
The government plans to quickly determine the timing and selection scale for the third test based on applications for the second test and progress in the first and second tests. Depending on additional demand, it will also actively consider conducting further rounds of emergency relaxation of network separation regulations and institutionalizing the measures on a permanent basis. After the first test concludes, key findings—including the types of vulnerabilities discovered, the characteristics and practical know-how of AI-based inspections, and security response procedures—will be shared across the financial sector. Follow-up measures, such as revising AI guidelines, will also be pursued.
Yoo Young-jun, director general of digital financial policy, said, "As threats of attacks using AI are increasingly becoming a reality, it is important to provide a broader range of financial companies and electronic financial business operators with opportunities to conduct AI security tests so they can prepare firmly for such threats." He added, "We will immediately share the characteristics of AI security threats and response procedures accumulated through the tests across the entire financial sector, and take every measure to ensure that financial companies that did not participate in the tests can also respond adequately to security threats." He continued, "We are also discussing closely with relevant agencies ways to fully lift network separation regulations, starting with entities that have advanced AI and security capabilities, so that the financial sector can use AI technology more diversely and on an ongoing basis, rather than limiting its use to security purposes."

[email protected] Park Moon-soo Reporter