On June 18, 2026, the Financial Services Commission of Korea announced the Guidelines on Artificial Intelligence in the Financial Sector at an on-site meeting on AI transformation, or AX, in the financial industry. The Guidelines consolidate and revise the existing AI-related guidance applicable to the financial sector and took effect on June 22, 2026.
In line with the implementation of the Guidelines, the Financial Supervisory Service released the Financial Sector AI Risk Management Framework, which further specifies the governance principles under the Guidelines, and the Financial Security Institute published the Financial Sector AI Security Guide, which elaborates on the security principles. Together with the Framework Act on the Development of Artificial Intelligence and Establishment of Trust, which came into effect on January 22, 2026, these developments are expected to form the basic regulatory framework for AI in Korea’s financial sector.
This newsletter summarizes the legal nature and scope of application of the Guidelines, the seven principles for financial AI, the key features of the AI Risk Management Framework and the AI Security Guide, and practical considerations for financial institutions and related businesses.
Background and Development
- Consolidation of Existing Guidance: Korean financial regulators have previously regulated the use of AI in the financial sector through the Guidelines on AI Operations in the Financial Sector issued in 2021, the Guide on the Development and Use of AI in the Financial Sector issued in 2022, and the AI Security Guidelines for the Financial Sector issued in 2023. The newly issued Guidelines integrate these three sets of guidance into a single, comprehensive framework.
- Alignment with the AI Framework Act: The Framework Act on the Development of Artificial Intelligence and Establishment of Trust was enacted in January 2025 and came into effect on January 22, 2026. As the Act introduced statutory obligations for AI business operators, including obligations relating to high-impact AI, there arose a need to align the existing financial-sector AI guidance with the new statutory framework. The financial regulators finalized the Guidelines after gathering opinions from industry participants and experts through the AI Council.
Legal Nature and Scope of Application
- Legal Nature: The Guidelines constitute a set of best-practice standards with the nature of self-regulation and do not, in themselves, have direct legally binding effect. However, the Guidelines may be used as a reference standard in supervisory reviews, including inspections by the Financial Supervisory Service, when assessing the adequacy of internal controls relating to AI. Accordingly, the Guidelines are expected to carry significant practical weight.
- Scope of Application: The Guidelines apply broadly to financial companies that use AI, regardless of business sector or business function. They may also apply to non-financial companies, including fintech companies, where the results of their AI use may affect financial transactions. The Guidelines are recommended to be applied widely not only to customer-facing functions, such as loan screening, credit evaluation, chatbots, financial product recommendations, and suspicious transaction detection, but also to internal support and management functions where AI is used.
- Relationship with the AI Framework Act: Where matters are governed by the AI Framework Act and its subordinate regulations, the statutory provisions take precedence. The Guidelines supplement areas not specifically regulated by law. In particular, the Guidelines classify high-impact AI under the AI Framework Act, such as AI used for decisions or evaluations that may have a significant impact on an individual’s rights and obligations, including loan screening, as high-risk AI for purposes of the Guidelines, regardless of the AI system’s self-assessed risk score. Such AI is therefore subject to enhanced controls under the Guidelines. Conversely, even if an AI system is classified as high-risk AI based on a risk assessment under the Guidelines, it does not automatically constitute high-impact AI under the AI Framework Act. Businesses should therefore carefully distinguish between these two concepts.
The Seven Principles for Financial AI
The Guidelines set out seven basic principles that financial companies and other relevant entities should observe when introducing and using AI, together with detailed implementation requirements for each principle.
① Governance: Financial companies should establish a decision-making body responsible for AI risk management. They should also organize a dedicated risk management function that is independent from the AI planning and development teams. In addition, companies should establish a risk assessment system, internal rules, and business manuals, and implement differentiated controls according to the level of risk.
② Legality: Companies should identify and review in advance the laws and regulations applicable to the development and use of AI and reflect the relevant legal requirements in their internal policies and business procedures. Depending on the business function, various sector-specific laws may apply. For example, the Credit Information Use and Protection Act may apply to loan screening and credit evaluation, the Act on Reporting and Using Specified Financial Transaction Information may apply to suspicious transaction detection, and the Financial Investment Services and Capital Markets Act and the Financial Consumer Protection Act may apply to investment solicitation and advisory services.
③ Use as an Auxiliary Tool: AI should be used as an auxiliary tool in business operations. Final decisions, and the responsibility for those decisions, should remain with the company’s officers and employees. Companies should determine in advance the circumstances in which human intervention is required at each stage of AI system operation. Even where a company uses AI provided by an external vendor, responsibility remains with the financial company using the AI.
④ Reliability: Companies are required to establish and monitor model performance indicators, manage the quality of training and input data, review fairness and bias issues, and ensure explainability in the decision-making process.
⑤ Financial Stability: Companies should assess and manage risks that AI systems may pose to the broader financial market. They should also establish safeguards, such as backup models and emergency stop functions, to address model malfunction, and should maintain a third-party IT risk management framework. Where an incident may escalate into systemic risk, companies should promptly share relevant information with the supervisory authorities.
⑥ Good Faith: Where AI is used in customer-facing services, companies should prevent conflicts of interest, inform consumers in advance that AI is being used, and establish prompt response procedures in the event of consumer harm.
⑦ Security: Companies should identify AI-specific security threats, such as data poisoning and prompt injection, and establish detection and response systems. They should protect core assets, including data and models, and manage supply-chain risks by verifying externally introduced models and data.
Key Features of the AI Risk Management Framework and the AI Security Guide
- AI Risk Management Framework: The AI Risk Management Framework released by the Financial Supervisory Service draws on international examples, including the AI Risk Management Framework of the U.S. National Institute of Standards and Technology. The framework presents three core processes: governance, risk assessment, and risk control. Risk assessment consists of four stages: risk identification and measurement, risk mitigation, residual risk assessment, and risk rating. Based on quantitative assessment scores relating to the principles of legality, reliability, good faith, and security, AI services are classified into risk levels, including low risk, medium risk, high risk, and very high risk. Different levels of control, such as approval procedures, third-party verification, and monitoring, are applied depending on the risk rating. For high-risk AI, prior approval by the highest decision-making body and post-implementation verification are required. For very high-risk AI, the launch of the relevant AI service must be reconsidered.
- AI Security Guide: The AI Security Guide released by the Financial Security Institute provides practical details on the security principle set out in the Guidelines. The Guide covers the identification and management of AI-specific security threats, detection of and response to specialized attacks, including input and output filtering and adversarial attack testing, protection and management of AI assets, including integrity verification and access controls, verification of external models and data, supply-chain security, extension of existing IT security systems to AI, and security verification at each stage from development to operation.
Related Policy Developments
- Planned Regulatory Reforms: Together with the implementation of the Guidelines, the Financial Services Commission announced that it would pursue regulatory reforms to support the use of AI in the financial sector. These reforms include easing network separation requirements, improving the consent regime for personal credit information, and revising regulations relating to the pseudonymization of data. Prior to this announcement, the financial regulators amended the Detailed Regulations on Supervision of Electronic Financial Transactions in April 2026 to expand exceptions to network separation requirements for the use of SaaS in internal networks, subject to certain security requirements.
- Future Agenda: Beginning in the second half of 2026, the Financial Services Commission plans to operate task forces and review institutional improvements for AX in the financial sector, risk management measures relating to AI adoption, and pilot programs for AI agents. The Commission will also operate a help desk to respond to practical inquiries from financial companies in connection with the implementation of the Guidelines.
Practical Implications for Businesses
- Review and Enhancement of Internal Control Systems: Although the Guidelines and the AI Risk Management Framework take the form of self-regulation, if their requirements are reflected in internal rules and incorporated into the responsibilities map, they may be assessed as part of the internal control framework under the Act on Corporate Governance of Financial Companies. If an AI-related incident is found to have resulted from deficiencies in the establishment or operation of AI governance, the financial company and its officers and employees may face internal-control-related responsibility. Accordingly, companies should first review whether they have established an appropriate decision-making body, organized an independent risk management function, and reflected AI-related responsibilities in their responsibilities map.
- Assessment of High-Impact AI: Financial companies that qualify as AI business operators should review in advance whether their AI systems constitute high-impact AI. If an AI system falls within this category, the company must comply with the obligations under Article 34 of the AI Framework Act, including establishing and operating risk management measures, preparing explanation measures, protecting users, ensuring human management and supervision, and retaining relevant documentation. Financial companies operating AI systems that may significantly affect individuals’ rights and obligations, such as loan screening or credit evaluation systems, will be subject both to statutory obligations and to high-risk AI controls under the Guidelines. It is therefore advisable to design an integrated compliance framework covering both regimes.
- Review of Overlapping Sectoral Regulations: A single AI system may be subject not only to the AI Framework Act but also to several other laws and regulations, including the Electronic Financial Transactions Act, which imposes safety and security obligations, the Credit Information Use and Protection Act, including the right to request an explanation of automated evaluations, the Financial Consumer Protection Act, including duties of explanation and suitability requirements, and the Personal Information Protection Act. At the AI service planning stage, companies should comprehensively identify all applicable laws and regulations. When introducing external AI models or cloud services, companies should also secure contractual safeguards, such as restrictions on reuse of data for training and requirements for security assessments.

