The Mythos and Fable access restrictions have heightened the importance of "AI sovereignty," fueling growing calls for the security capabilities of both government and the private sector to evolve rapidly. While the government has hastily launched a public-private joint system to respond to AI security threats, experts say fundamental measures are needed, including the development of security-specialized domestic AI models and a transformation of individual companies' cybersecurity systems.

According to relevant ministries on Tuesday, government bodies including the Office of National Security, the Ministry of Science and ICT (MSIT), the National Intelligence Service (NIS) and the Ministry of National Defense began operating this month the "Cross-Ministry Public-Private Cooperation System for AI Vulnerability Response" announced last month. The cooperation system was established to respond quickly to AI threats by removing the silos under which the NIS handled national and public security while the Korea Internet & Security Agency (KISA), under MSIT, handled private-sector security. Specifically, the system is structured so that MSIT and KISA cooperate with individual ministries to collect and analyze AI vulnerabilities arising at private companies, and to rapidly disseminate patches (updates) that can address them across the public, private and military sectors.
The government created an AI vulnerability response system encompassing all relevant ministries because traditional security methods no longer work. Until now, security responses worked in such a way that when a gap was found in a security service adopted by an institution or company, the security firms that developed the service would install system updates (patches) for their client companies. But as AI technology has advanced, automating vulnerability detection and accelerating the speed of exploitation, such responses have become difficult to keep pace with AI-driven hacking. According to the Cloud Security Alliance (CSA), a global security consortium, the time it takes from the disclosure of a vulnerability to confirmation of actual exploitation plummeted from an average of 2.3 years in 2019 to less than one day in 2026. The CSA cited the advancement of AI, including large language models (LLMs), as the cause of this change.
The industry suggests that a system responding to AI security threats by strengthening AI security capabilities must take root. Indeed, domestic security firms such as AhnLab, Raonsecure and Genians are developing AI-based solutions to enhance their security capabilities. "Individual companies are rushing to adopt AI in their security solutions, but there are limits to private-led efforts," a security industry official said. "The government and the private sector must cooperate to build a stronger security system, including the development of security-specialized AI models." MSIT is also reviewing ways to use the vulnerabilities collected through the public-private cooperation system to improve the competitiveness of domestic AI models.
Raising security awareness and investment at individual companies is also important. According to the information security survey published annually by the Korea Information Security Industry Association, the proportion of companies using an information security budget among the 5,500 to 6,500 companies surveyed has declined from 67.9% in 2022 to 54.8% last year.






