[비즈한국] Following the Mythos Shock, both the public and private sectors are accelerating the reorganization of their response systems under the principle that "AI attacks must be blocked by AI." The financial sector is introducing autonomous AI penetration testing and AI-based security monitoring, while the public sector is also accelerating the transition of its network security architecture under the premise of the AI era.

The financial sector is the fastest to act. As a core national infrastructure where customer information and capital flow are connected in real-time, finance is considered the field where damages could manifest most quickly as AI increases the speed of attacks.
Woori Financial Group recently adopted 'Xint Web,' an AI-based autonomous black-box penetration testing solution from Offensive security firm Theori. This method finds weaknesses by probing the outside of a service like a real hacker, without any internal system information. KB Financial Group is also strengthening its AI-based response by expanding its self-developed AI penetration testing agents and Zero Trust-based security systems.
The Bank of Korea has also begun transitioning to an AI-based security system by introducing equipment from U.S.-based Palo Alto Networks, an initial participating company in 'Project Glasswing,' an international cooperation group for responding to Mythos.
“AI Attacks Must Be Blocked by AI”… Domestic Response in Full Swing
While companies are taking technical measures, the government has also begun establishing institutional foundations. Following the emergence of Mythos, the Financial Services Commission decided to temporarily relax network separation regulations for the use of AI for security purposes. The policy targets 49 financial companies with total assets of over 10 trillion won and 1,000 or more permanent employees, offering a one-year regulatory easing following an evaluation of their security management capabilities. The Ministry of Science and ICT is also focusing on securing AI-based security capabilities, such as discussing cooperation plans with Anthropic, including securing access rights to Mythos.
Experts find the essence of the Mythos Shock not in the "emergence of fully automated AI hackers" itself, but in the fact that the way security tasks are performed is fundamentally changing. Yang Jong-heon, Division Head at big data analysis AI firm S2W, pointed out, "The core is not that full automation is complete right now, but that the unit cost, speed, and repeatability of security tasks have started to change." He added, "This change could shake not only the way vulnerability researchers work but also the entire software supply chain and patch management system."
The explanation is that while human competitiveness in the security sector previously stemmed from the ability to discover vulnerabilities, it will become increasingly important in the future to verify the results found by AI, judge the actual risk, and determine the priority of response.

Even if AI performs a significant portion of attacks and defenses, the final responsibility ultimately returns to humans. This is why a governance system for managing AI is emphasized as much as technological development. Choi Byung-ho, a professor at the Korea University AI Research Institute, said, "In a realistic system, humans and AI must cooperate, and it is inevitable that the structure will hold the cooperating human responsible." However, he added, "Because that governance system is not yet complete, we are helpless when such incidents occur," and warned, "The global community is in a state where the Tier-1 security market is highly likely to be incapacitated."
Division Head Yang noted, "For companies, what is needed first is the visibility of assets and code," adding, "If you don't know what systems you are operating or what open-source libraries you are relying on, it is difficult to connect vulnerabilities found by AI to actual risks." He meant that even if AI finds a large number of vulnerabilities, it is useless if there is no foundational strength to translate and interpret them as actual risks to the company's systems.
Yoo Jun-gu, a senior research fellow at the Sejong Institute, also diagnosed in a related report that "the core of security for major data-based infrastructure does not lie in raising external firewalls, but in how to control permissions when internal accounts are compromised." He argued that instead of assuming perfect security, the direction should be to design rigorous verification steps that attackers must pass through to achieve their goals.
Prioritizing ‘Access and Control’ over Performance… Government Also Weighs Security-Specialized AI
So, how close can South Korea get to Mythos-class top-tier models? Experts suggest that even if access rights are secured, it will not be easy to directly utilize Mythos-class frontier models domestically. This is because as overseas frontier AI is increasingly managed as a national strategic asset, the possibility of restricted access is growing.
Although the Korea Internet & Security Agency (KISA), Samsung Electronics, and SK Telecom have secured access rights to Mythos from Anthropic, the prevailing view is that room for long-term utilization could gradually decrease as the U.S. shifts its policy toward managing frontier AI as a strategic asset. Although the U.S. Department of Commerce lifted export controls on Mythos5 and Fable5 general models after 18 days in June, the application of strengthened safeguards means the scope for utilizing them in security research has actually narrowed.

However, it is pointed out that jumping into a competition to develop super-large models at the same level as Mythos is not a realistic solution. Kim Ho-won, president of the Korea Institute of Information Security & Cryptology and a professor at Pusan National University, said at a seminar on seeking directions for cybersecurity development on the 9th of last month, "If we blindly start developing our own Mythos, we could get caught in a chicken game, and if we use foreign models, we fall into a data sovereignty dilemma." He suggested, "An agent orchestration-based small specialized model (sLLM) strategy that organically controls multiple AIs could be a realistic alternative."
Development capacity is also limited. This is due to the massive computational resources and investment costs involved. Deputy Prime Minister and Minister of Science and ICT Bae Kyeong-hoon mentioned at a press conference marking his first anniversary in office last month, "It is difficult to develop a Mythos-class frontier model with the level of support currently provided for independent AI foundation model projects," adding, "It is estimated that about 10,000 Vera Rubin-class GPUs are needed, and the current price alone is around 3.5 trillion won."
The problem is not just cost and technology. The fact that access itself can be swayed by political decisions has also emerged as a new risk. Wang Yun-jong, a professor of international business at Dongduk Women's University, evaluated the U.S. blocking of access to Anthropic by saying, "The 'switch-off risk,' where another country's generative AI service can be discontinued overnight, has become a reality." He continued, "Sovereign AI needs to be approached from the perspective of being a national-level backup system in case overseas AI access is restricted, rather than a means for market competition."
Additionally, as the predictability of regulations has significantly decreased, he advised that domestic companies should include the U.S. administration's export control measures as an explicit 'force majeure' clause in contracts with global clients.
Overseas, national and corporate-level response systems are already taking shape. On the 27th of last month, Microsoft (MS) unveiled its autonomous AI attack response project 'Perception' and security-specialized AI models, and launched the External Red Teaming Alliance (EXTRA), in which institutions like the Korea Advanced Institute of Science and Technology (KAIST) participate, signaling the start of full-scale AI security competition.
The Mythos Shock foretells an era of competition not just in AI performance, but in utilization and control. For South Korea, the remaining tasks are how to build security systems and institutional responses alongside securing technology.
Accordingly, the government plans to pursue a 'two-track strategy' that examines the possibility of frontier AI development separately from the independent AI foundation model project, while prioritizing the development of 'security-specialized AI' using existing models. Deputy Prime Minister Bae stated, "Even if we cannot build a frontier model right away, we can create a security-specialized AI model that checks for various vulnerabilities by fine-tuning currently held models with security data," adding, "We plan to develop it within this year and start applying it in the public sector."