Skip to content

South Korea Moves to Write New Security Rules for AI Agents That Act Without Human Oversight

Getting your Trinity Audio player ready...

South Korea Moves to Write New Security Rules for AI Agents That Act Without Human Oversight

South Korea’s state cybersecurity watchdog said Tuesday it’s building a fresh set of security guidelines aimed squarely at a problem most existing AI regulation wasn’t written to handle: AI systems that don’t just answer questions, but actually go do things on their own.

The Korea Internet & Security Agency, known as KISA and run under the Ministry of Science and ICT, told Reuters it’s working on an updated version of its AI Security Guide, a document it first put out last year. The new version, which industry sources in South Korea have referred to as version 2.0, is being built specifically around the security headaches that come with agentic AI, software that can plan out a task, take a string of actions to complete it, and adjust its approach along the way with little or no person checking in at each step. KISA said the guide will also cover what it’s calling physical AI, meaning AI systems wired into real machinery and devices rather than confined to a screen, expanding the guidance well beyond the chatbot-style AI most people are used to.

The distinction KISA is drawing here actually matters more than it might sound at first. A language model that helps someone draft an email is, at the end of the day, just a tool, no different in principle from a spellchecker that got a lot smarter. An AI agent that logs into a company database, decides on its own which customers need to be contacted, sends the messages, and then changes its strategy based on how people respond is something else entirely. It’s making decisions and taking actions with real consequences, and if something goes wrong partway through, there often isn’t a person standing there watching in real time to catch it.

Real More:  AgiBot's $24K Lingxi X2 Shows How Cheap China's Humanoid Robots Have Gotten

That gap is exactly what KISA says it wants the new guide to close. According to an official who spoke on condition of anonymity, the goal is to set out minimum safety expectations that both the companies building these AI agents and the businesses deploying them would be expected to follow. The guidance is expected to cover things like audit trails so that an agent’s actions can be reconstructed after the fact, mechanisms that let a human step in and override what an agent is doing, and limits on how much independent authority an agent can be given before its use has to be reported to regulators. KISA has also said it identified a handful of specific risk areas it wants the guide to address directly: misuse of an AI system’s execution permissions, interference with the sensors a physical AI system relies on, outright physical malfunctions, and the tricky question of how you actually verify that an autonomous system made a decision for the reasons it claims to have made it.

South Korea hasn’t published a draft yet, and there’s no confirmed timeline for when the finished guide will be released. But the timing lines up with a broader push happening inside the country’s tech ministry right now. According to reporting from Seoul Economic Daily, the ministry is running what it describes as a two-track approach: one track uses AI itself to detect and respond to cyber threats, something being tested through an AI-based autonomous security operations platform built with companies including Logpresso, Monitorapp, Sands Lab and Tatum, while the other track, the one the new guide falls under, focuses on keeping AI’s own behavior and permissions under control. The ministry is also reportedly planning proof-of-concept testing against high-risk scenarios in sectors like telecommunications, healthcare and manufacturing, industries where an AI agent going off script could cause real damage rather than just an embarrassing chatbot response.

Real More:  OpenAI Loses a Top Data Center Exec

There’s a reasonable case that South Korea has more incentive than most countries to get ahead of this. North Korea has been ranked as the world’s most prolific state sponsor of cyberattacks, and South Korean officials have flagged AI as a technology that could make those attacks meaningfully harder to detect and stop as it gets folded into offensive tooling. Building out defensive guardrails around AI agents isn’t purely an abstract safety exercise for Seoul, it’s tied to a live regional threat that’s already been costing the country money and headaches for years.

It’s also worth noting KISA has said this new guide isn’t meant to single out the largest, most capable frontier AI models specifically, the kind of systems that have drawn scrutiny elsewhere over safety incidents. Instead, it’s meant to apply more broadly to any agentic AI deployment, regardless of which underlying model is powering it. That’s a meaningfully different approach than regulation aimed narrowly at the biggest AI labs, and it reflects a recognition that the risk here often comes down to how much autonomy a system has been handed in a specific business setting, not just how powerful the model underneath happens to be.

The move also puts South Korea ahead of most other governments on this particular issue. Frameworks like the EU’s AI Act and the U.S. National Institute of Standards and Technology’s AI Risk Management Framework were largely written with prompt-and-response AI systems in mind, tools that wait for a human to ask something before doing anything. Neither was built around the idea of software that strings together a chain of independent actions on its own initiative. South Korea already has a head start on the regulatory front more broadly too, having passed its AI Basic Act in December 2024, which took effect this past January and made the country only the second in the world, after the European Union, to adopt a comprehensive legal framework specifically for artificial intelligence. The new KISA guide would sit alongside that broader law, filling in the more technical, agent-specific gap that the original legislation wasn’t built to cover.

Real More:  China's NEXWISE Develops a Modular Net Launcher That Lets Police Capture Suspects From Robot Dogs and Drones Without Firing a Shot

Leave a Comment