Guidelines  ·  2026-09-20

KISA (South Korea) announces development of AI Security Guide v2.0 targeting agentic AI risks

GuidelinesMedium impactSouth Korea
On September 15, 2026, KISA told Reuters it is developing an updated version (v2.0) of its national 'AI Security Guide' (first published last year), explicitly to address security risks from agentic AI services. The revised guide will include a checklist for managing agentic AI risks (audit trails, human override, access controls) and may cover common security controls for 'physical AI' systems that interact with real-world devices/machinery. The update was accelerated following the Hugging Face breach involving rogue AI agents. KISA gave no publication date, so this is an announcement of forthcoming guidance rather than a published draft or final standard.
This is a national cybersecurity authority (analogous to CISA/NCSC) signaling that its existing AI security framework will be substantively revised to cover agentic AI autonomy, credential/tool use, and physical AI control systems -- mirroring the same agentic-AI control gaps (identity, scoped authorization, human approval for irreversible actions) that dominated this week's global AI-security discourse. Organizations operating in or serving the South Korean market should anticipate new baseline controls for agentic AI deployments.
Watch for KISA's draft/final AI Security Guide v2.0 publication; organizations with Korea-market AI agent deployments should begin mapping current agent identity, credential, and audit-trail controls against the anticipated checklist areas.
ReutersTechWire AsiaTechRepublic
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →