“Vulnerabilities exposed in financial-sector AI agent security”... Financial Security Institute draws up and releases new assessment criteria
- Input
- 2026-10-07 11:30:35
- Updated
- 2026-10-07 11:30:35

[Financial News] As cyberattacks using artificial intelligence (AI) agents surge, the Financial Security Institute has drawn up “Security Assessment Criteria for AI Agents in the Financial Sector.” Security systems using AI agents need to be strengthened to counter attacks by AI agents, as the agents themselves can make “mistakes.” The draft criteria, comprising 17 assessment items across six areas, will apply to AI red teaming across the entire financial sector.
According to financial authorities on the 7th, the Financial Security Institute has drawn up draft “AI Model Threat Assessment Standards and AI Agent Security Assessment Criteria.” An AI agent is a system that makes plans on its own to achieve a given goal and uses tools and external systems to carry out tasks. Unlike conventional large language models (LLMs), which were limited to generating text responses, agents are characterized by their ability and authority to “execute” tasks.
With conventional generative AI, errors in responses, such as hallucinations, posed a major security threat. Due to characteristics including autonomy, initiative, execution capability, strategic capacity and continuity, AI agents can turn existing threats into real-world actions and amplify them.
For example, an agent given the goal of “optimizing system performance” could disable antivirus software on its own to ensure availability. An agent with an automatic email-reply function might also see an email about resetting a password and change the password without authorization.
The Financial Security Institute analyzed major AI-agent security threats and countermeasures at home and abroad, identifying 17 assessment items. It incorporated them into its AI red-teaming standards. The scope of AI red teaming will be expanded to check what tasks AI agents actually perform and how, as well as how those processes are controlled. Previously, assessments focused on the model layer, including jailbreaks and system prompt leaks, but they will now extend to the execution layer. Key assessment items are expected to include management of execution permissions and isolation, controls on tool execution and approval, verification of task scope and results, and limits on autonomous execution and whether it can be stopped.
The Financial Security Institute plans to assess the effectiveness of each item through pilot testing by the end of this year and make improvements. During the pilot, it will refine and supplement the assessment items and methods to account for whether checks can be conducted and differences in how financial companies implement them. It also plans to publish security threats involving AI agents identified during red teaming, actual attack techniques and the final assessment criteria in its 2026 AI Red Team Report (REDTEAM REPORT).
Financial Security Institute President Park Sang-won said, “AI agents entail security risks different from those of conventional AI because they do not stop at making judgments but act directly.” He added, “With the establishment of these assessment criteria as a starting point, we will conduct substantive assessments of the risks posed by AI agents in the financial sector and actively support financial companies in using AI technologies safely and reliably.”
Meanwhile, although cyber threats involving artificial intelligence (AI) are spreading, countermeasures remain limited. It was only this year that domestic banks began conducting penetration tests using AI agents for the first time. Such tests accounted for only around 10% of all penetration tests. According to data that the office of Park Sang-hyeok, a Democratic Party of Korea lawmaker and secretary of the National Policy Committee, obtained from the Financial Supervisory Service, 20 banks in South Korea conducted a total of 78 penetration tests through August this year. Of these, only nine, or 11.5%, used AI agents.
Among the seven commercial banks—KB Kookmin, Shinhan, Hana, Woori, SC First Bank, Citibank Korea and iM Bank—44 penetration tests were conducted through August this year, but only four (9.1%) used AI agents. This means that at least three commercial banks did not conduct any penetration tests using AI agents. Among the five regional banks—BNK Busan, BNK Kyongnam, Gwangju Bank, Jeonbuk Bank and Jeju Bank—only one of 13 tests (7.7%) used AI agents. The 12 regional banks have never conducted penetration tests using AI agents, even as cyberattacks involving AI agents have become a reality.
Specialized banks fared even worse. The five specialized banks—Korea Development Bank, Industrial Bank of Korea, Export-Import Bank of Korea, NongHyup Bank and Suhyup Bank—conducted 13 penetration tests this year, but not one used AI agents. Among the three internet-only banks—KakaoBank, K Bank and Toss Bank—four of the eight tests conducted this year, or half, used AI agents, leaving them relatively better prepared to respond.
[email protected] Park Mun-su Reporter