South Korea - AI Security Guidelines (2025)
AI Security Guide
인공지능(AI) 보안 안내서
South Korea
RAI-KR-NA-SECURIT-2025South Korea's AI Security Guide, published in 2025, sets 113 security requirements for AI models and services, complementing the AI Basic Act.
Summary
South Korea's AI Security Guide, published by MSIT and KISA in December 2025, provides a framework for securing AI models and services against cyber threats. It outlines 113 security requirements for developers, service providers, and users across the AI lifecycle, emphasizing confidentiality, integrity, and availability. This guide operationalizes the AI Basic Act, aligning with global standards like NIST AI RMF 1.0.
Full article
Read full text ↗Overview
The Artificial Intelligence (AI) Security Guide (인공지능(AI) 보안 안내서), published by South Korea's Ministry of Science and ICT (MSIT) and the Korea Internet & Security Agency (KISA) on December 10, 2025, serves as a crucial framework for safeguarding AI models and services against evolving cyber threats. This comprehensive guide aims to provide developers, service providers, and users with detailed security measures and best practices throughout the entire AI lifecycle. It represents a significant step in South Korea's broader strategy to establish a robust AI governance framework, complementing the foundational AI Basic Act passed in December 2024 and effective January 2026. Unlike previous guidelines that primarily focused on the reliability and ethical use of AI-generated content, this guide specifically addresses the prevention and response to external cyber threats, emphasizing a security-centric approach.
The guide is structured around the three core elements of information security—confidentiality, integrity, and availability—and comprises 113 specific security requirements. These requirements are tailored to different stakeholders: AI model developers, AI service providers, and AI users. For developers, the guide outlines security measures from the planning and design phase through data collection, model development, deployment, monitoring, maintenance, and eventual decommissioning. For service providers, it covers aspects from service planning and development to operation, maintenance, and feedback mechanisms. Additionally, it includes practical security rules for end-users to prevent misuse and protect sensitive information. The development of this guide involved extensive analysis of domestic and international AI security policies and expert consultations, ensuring its practical utility and alignment with global standards such as NIST AI RMF 1.0 and OWASP Top 10 for LLM Applications.
Definitions
This AI Security Guide establishes a standardized vocabulary crucial for consistent implementation and understanding across various stakeholders. Key definitions include 'Artificial Intelligence (AI) System,' referring to a machine-based system that, for explicit or implicit objectives, infers how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. 'AI Model Developer' is defined as any entity or individual responsible for the design, training, and testing of AI models, encompassing the entire development lifecycle from conceptualization to deployment preparation. 'AI Service Provider' refers to organizations or individuals that offer AI-powered products or services to end-users, managing their deployment, operation, and maintenance.
The guide also clarifies concepts such as 'AI Security Threats,' which are any potential events or actions that could compromise the confidentiality, integrity, or availability of AI systems, including data poisoning, model evasion, inference attacks, and adversarial attacks. 'Secure by Design' (AI 보안 내재화) is a foundational principle advocating for the integration of security considerations into every stage of the AI system's lifecycle, rather than as an afterthought. 'High-Impact AI Systems' are those identified as having the potential to pose significant risks to public safety, fundamental rights, or critical infrastructure, necessitating enhanced security measures and oversight. These definitions are critical for delineating responsibilities and ensuring a common understanding of the security requirements outlined in the guide, facilitating effective communication and compliance within the AI ecosystem.
Governance and Institutional Framework
The governance and institutional framework for AI security in South Korea is primarily spearheaded by the Ministry of Science and ICT (MSIT) in collaboration with the Korea Internet & Security Agency (KISA). These two bodies are responsible for the development, dissemination, and ongoing updates of the AI Security Guide. The MSIT, as the lead government ministry, sets the overarching policy direction for AI development and security, ensuring that national strategies align with global best practices and domestic innovation goals. KISA, acting as a specialized agency, provides technical expertise, conducts research, and offers practical guidance and support for implementing cybersecurity measures across various sectors, including AI.
This guide operates within the broader legal landscape established by the Framework Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act), which was passed in December 2024 and became effective in January 2026. The AI Basic Act provides the foundational legal basis for AI governance, mandating the establishment of a national governance framework, fostering the AI industry, and proactively preventing potential risks. The AI Security Guide, therefore, serves as a crucial subordinate instrument, providing the detailed, actionable security requirements necessary to operationalize the principles and obligations laid out in the AI Basic Act. The National Intelligence Service (NIS) also plays a role, particularly in distributing an 'AI Security Guidebook' for public institutions, further reinforcing the government's multi-faceted approach to AI security across both public and private sectors. This collaborative effort ensures a comprehensive and coordinated approach to AI security governance.
Key Focus Areas
The South Korea AI Security Guide focuses on several critical areas to ensure the robust protection of AI systems. A primary focus is risk management throughout the entire AI lifecycle. This includes identifying, assessing, and mitigating potential security risks from the initial planning and design phases through data collection, model development, deployment, and ongoing monitoring. The guide emphasizes the importance of establishing a proactive risk management program, which involves adopting written policies, assigning accountable roles, and implementing a governance process to manage risks effectively. This systematic approach aims to embed security considerations into the core of AI development and operation, rather than treating them as external add-ons.
Another key area is safety, testing, and evaluation. The guide provides specific security requirements and verification items for developers and service providers to ensure the reliability and resilience of AI models and services against cyber threats. This includes measures such as data encryption, real-time monitoring of AI models, detection of anomalous service behavior, API and interface security, and the establishment of robust backup systems. The guide also addresses the unique security challenges posed by different types of AI, such as generative, agentic, and physical AI, and proposes 30 specific security countermeasures against 15 identified security threats, including data poisoning. Furthermore, transparency and disclosure are highlighted, with obligations for operators to publicly post core governance information and maintain documentation demonstrating compliance, while also providing specific security rules for users to prevent misuse and protect sensitive information.
Implementation Framework
The implementation framework for the AI Security Guide is designed to be comprehensive, addressing the entire lifecycle of AI systems and the diverse roles of stakeholders. It mandates the integration of security considerations from the earliest stages of AI development, following a "Secure by Design" principle. For AI model developers, the guide outlines a six-stage lifecycle: planning and design, data collection and preparation, model development, model deployment, monitoring and maintenance, and decommissioning. At each stage, specific security requirements are detailed, such as AI model risk management, data encryption, and real-time monitoring during development, and secure deployment practices.
For AI service providers, the implementation framework similarly follows a six-stage service lifecycle: service planning and design, service development and construction, service provision and operation, service maintenance and support, feedback and service improvement, and decommissioning. Key requirements for providers include detecting abnormal service behavior, securing APIs and interfaces, and establishing backup and recovery systems to ensure service resilience. Additionally, the guide provides AI user security rules, emphasizing practices like prohibiting the input of sensitive information, separating personal and work accounts, strengthening account security with strong passwords and multi-factor authentication, and verifying AI-generated outputs. The guide also references international standards like NIST AI RMF 1.0 and OWASP Top 10 for LLM Applications, ensuring a global perspective on implementation.
Monitoring and Evaluation
Monitoring and evaluation are integral components of the AI Security Guide, designed to ensure the continuous effectiveness and adaptability of AI security measures in South Korea. The guide emphasizes the necessity for ongoing vigilance against evolving cyber threats and the dynamic nature of AI technology. For both AI model developers and service providers, continuous monitoring is a core requirement, encompassing real-time surveillance of AI models and systems for anomalies, vulnerabilities, and potential security incidents. This proactive monitoring is crucial for early detection and rapid response to threats such as data poisoning, model evasion, or unauthorized access attempts.
Evaluation mechanisms involve regular assessments of implemented security measures against the 113 security requirements outlined in the guide. This includes internal audits, penetration testing, and vulnerability assessments to identify weaknesses and ensure compliance. The guide also encourages the use of established frameworks for evaluating AI safety and trustworthiness, potentially aligning with the voluntary AI safety and trustworthiness verification and certification supported by the government under the AI Basic Act. Furthermore, the MSIT and KISA are committed to continuously updating the AI Security Guide, reflecting new security threats and technological advancements, which implies an ongoing evaluation process at the national level to maintain the guide's relevance and efficacy. This iterative approach to monitoring and evaluation ensures that South Korea's AI security posture remains robust and responsive to the rapidly changing AI landscape.
Penalties, Liability, and Appeals
While the AI Security Guide itself, as a guideline, does not directly stipulate explicit penalties, liability, or appeal mechanisms, its provisions are intrinsically linked to the broader legal framework established by South Korea's Framework Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act). The AI Basic Act, which came into effect in January 2026, does include provisions for ensuring transparency, safety, and the responsibilities of operators, and provides a legal basis for government support of voluntary AI safety and trustworthiness verification and certification, as well as AI impact assessments. Therefore, non-compliance with the security measures detailed in this guide could potentially lead to regulatory scrutiny or be considered in the context of liability under the overarching AI Basic Act for high-impact AI systems.
The AI Basic Act outlines obligations for operators of "high-impact AI," including establishing risk management programs, preparing explanation plans, instituting user-protection measures, ensuring human oversight, and maintaining documentation. Failure to adhere to these obligations, which are significantly informed by the detailed security requirements of the AI Security Guide, could result in administrative actions or other consequences as defined by the Act and its subordinate regulations. Although the guide itself is non-binding, it sets the expected standard of care for AI security. In cases of AI-related incidents or harm resulting from inadequate security, adherence to this guide could serve as a defense, while negligence in following its recommendations could be a factor in determining liability. Specific details regarding penalties and appeal processes would be elaborated in the enforcement decrees and notifications issued under the AI Basic Act.
Relationship to Other Instruments
The AI Security Guide is a crucial component within South Korea's evolving AI regulatory landscape, designed to complement and operationalize higher-level legal instruments. Its primary relationship is with the Framework Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act), which was passed in December 2024 and took effect in January 2026. The AI Basic Act serves as the foundational law for AI governance in South Korea, establishing broad principles for AI development, trustworthiness, and risk prevention. The AI Security Guide provides the detailed, actionable security requirements and best practices necessary to implement the safety and trustworthiness obligations outlined in the Basic Act, particularly concerning cyber threats to AI systems.
Furthermore, the guide builds upon and differentiates itself from previous AI-related guidelines issued by the South Korean government. Earlier documents, such as the "Reliable AI Development Guide" (신뢰할 수 있는 인공지능 개발 안내서) by MSIT and the "Generative AI Ethics Guidebook" (생성형 AI 윤리 안내서) by the National Information Society Agency (NIA), primarily focused on ethical considerations, reliability, and the trustworthiness of AI outputs. In contrast, the AI Security Guide specifically addresses the prevention and response to external cyber threats from a security perspective, filling a critical gap in the existing regulatory framework. It also aligns with and references international standards and guidelines, such as the NIST AI Risk Management Framework (AI RMF) 1.0 and the OWASP Top 10 for Large Language Model (LLM) Applications, demonstrating South Korea's commitment to global harmonization in AI security. This integration ensures that the guide is not an isolated document but an interconnected part of a comprehensive and globally aware AI governance strategy.
International Alignment
The South Korea AI Security Guide demonstrates a strong commitment to international alignment, drawing upon global best practices and standards to ensure its relevance and interoperability in the global AI landscape. The Ministry of Science and ICT (MSIT) and the Korea Internet & Security Agency (KISA) explicitly referenced international criteria and guidelines during the guide's development, aiming to establish AI security requirements at a global level. This approach ensures that the guide is not only applicable to domestic AI models and services but also possesses versatility and compatibility with international norms, facilitating cross-border cooperation and mutual recognition.
Notably, the guide incorporates insights and references from prominent international frameworks such as the NIST AI Risk Management Framework (AI RMF) 1.0 from the United States and the OWASP Top 10 for LLM Applications. The NIST AI RMF provides a comprehensive, voluntary framework for managing risks associated with AI systems, covering areas like governance, risk assessment, and mitigation. The OWASP Top 10 for LLM Applications, on the other hand, identifies and addresses the most critical security vulnerabilities specific to large language models. By integrating elements from these widely recognized international standards, South Korea positions its AI Security Guide as a globally informed and compatible document. This alignment is crucial for fostering international collaboration in AI development and deployment, ensuring that Korean AI products and services can operate securely and reliably in a globalized digital economy, and promoting a consistent approach to AI security challenges worldwide.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| AI Basic Act Passed by National Assembly | 2024-12-26 | Establishes the foundational legal framework for AI governance in South Korea. |
| AI Basic Act Promulgated | 2025-01-21 | Official publication of the foundational law. |
| AI Security Guide Published | 2025-12-10 | Release of the detailed security guidelines by MSIT and KISA. |
| AI Basic Act Effective Date | 2026-01-22 | The foundational law officially comes into force, providing the legal basis for subordinate regulations and guidelines. |
| Continuous Monitoring & Updates | Ongoing from 2025-12-10 | MSIT and KISA committed to monitoring new threats and updating the guide periodically. |
Sources and References
| Source | Type |
|---|---|
| KISA: 인공지능(AI) 보안 안내서 발간 및 배포 | Official |
| Korea Policy Briefing: 생성형 AI서비스 이용시 보안 유의 | Official |
| KISA Insight 2023: AI 안전 및 보안 규범 | Official |
Requirements for a company
What an organisation has to do under South Korea - AI Security Guidelines (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
11- Establish and implement a comprehensive AI model risk management program across the entire AI lifecycle.AI model developers and AI service providers.
- Integrate security considerations into every stage of the AI system's lifecycle from the earliest development stages.AI model developers and AI service providers.
- Implement enhanced security measures and oversight for AI systems identified as high-impact.Providers of high-impact AI systems.
- Implement data encryption, access controls, and secure handling procedures for all AI-related data.AI model developers and AI service providers.
- Deploy real-time monitoring systems for AI models and services to detect anomalies and security incidents.AI model developers and AI service providers.
- Implement specific countermeasures against identified AI security threats like data poisoning, model evasion, and adversarial attacks.AI model developers and AI service providers.
- +5 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under South Korea - AI Security Guidelines (2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | AI model developers and AI service providers. | Establish and implement a comprehensive AI model risk management program across the entire AI lifecycle. “A primary focus is risk management throughout the entire AI lifecycle. This includes identifying, assessing, and mitigating potential security risks.” | Before placing on market | Key Focus Areas | Critical |
| 2 | AI model developers and AI service providers. | Integrate security considerations into every stage of the AI system's lifecycle from the earliest development stages. “'Secure by Design' is a foundational principle advocating for the integration of security considerations into every stage of the AI system's lifecycle.” | Before commencing development | Definitions | Critical |
| 3 | Providers of high-impact AI systems. | Implement enhanced security measures and oversight for AI systems identified as high-impact. “'High-Impact AI Systems' are those identified as having the potential to pose significant risks... necessitating enhanced security measures and oversight.” | Before placing on market | Definitions | Critical |
| 4 | AI model developers and AI service providers. | Implement data encryption, access controls, and secure handling procedures for all AI-related data. “measures such as data encryption, real-time monitoring of AI models... and secure handling procedures for all data used in AI development.” | Before placing on market | Key Focus Areas | Critical |
| 5 | AI model developers and AI service providers. | Deploy real-time monitoring systems for AI models and services to detect anomalies and security incidents. “continuous monitoring is a core requirement, encompassing real-time surveillance of AI models and systems for anomalies, vulnerabilities, and potential security incidents.” | Ongoing from 2025-12-10 | Monitoring and Evaluation | Critical |
| 6 | AI model developers and AI service providers. | Implement specific countermeasures against identified AI security threats like data poisoning, model evasion, and adversarial attacks. “proposes 30 specific security countermeasures against 15 identified security threats, including data poisoning.” | Before placing on market | Key Focus Areas | Critical |
| 7 | AI service providers. | Ensure robust security for all Application Programming Interfaces (APIs) and interfaces used by AI services. “Key requirements for providers include detecting abnormal service behavior, securing APIs and interfaces, and establishing backup systems.” | Before placing on market | Implementation Framework | Important |
| 8 | AI service providers. | Establish and regularly test backup and recovery systems to ensure service resilience and data availability. “Key requirements for providers include detecting abnormal service behavior... and establishing backup and recovery systems to ensure service resilience.” | Before placing on market | Implementation Framework | Important |
| 9 | AI service providers. | Provide clear guidelines to users on safe AI usage, including prohibitions on sensitive information input and strong authentication. “providing specific security rules for users to prevent misuse and protect sensitive information.” | Before placing on market | Key Focus Areas | Important |
| 10 | AI model developers and AI service providers. | Maintain comprehensive documentation of AI system security measures, risk assessments, and compliance efforts. “obligations for operators to publicly post core governance information and maintain documentation demonstrating compliance.” | Ongoing from 2025-12-10 | Key Focus Areas | Important |
| 11 | AI model developers and AI service providers. | Conduct regular assessments, internal audits, penetration testing, and vulnerability assessments of implemented security measures. “Evaluation mechanisms involve regular assessments of implemented security measures... This includes internal audits, penetration testing, and vulnerability assessments.” | Ongoing from 2025-12-10 | Monitoring and Evaluation | Important |
Related Regulations
인공지능 발전과 신뢰 기반 조성 등에 관한 기본법
South Korea93% similar
AI Privacy Risk Management Model (안전한 AI·데이터 활용을 위한 AI 프라이버시 리스크 관리 모델) - Personal Information Protection Commission
South Korea92% similar
South Korea AI Regulation Overview
South Korea92% similar
대한민국 인공지능행동계획 (인공지능 기본계획(2026~2028))
South Korea92% similar
Generative AI Ethics Guidebook (NIA / KCC – sectoral guide for generative AI)
South Korea92% similar
© Regulations.AI using Gemini 2.5 Flash · updated on 11-Jan-2026