After the AI Basic Act, What to Do and How: Procurement, Security, and Governance Checkpoints
IT DAILY ·
✦ AI Summary
KMAC, Law Firm Lin, and SelectStar jointly held a seminar titled "Practical Responses After the AI Basic Act: Responsibility, Governance, and Verification" at the Pose Tower Event Hall in Yeoksam, Seoul, on the 17th.
The seminar was designed as a forum to share changes in the procurement market, overlapping legal regulations, security risks, and practical AI governance execution models brought on by the enforcement of the AI Basic Act.
Presentations covered the AI product confirmation certificate, the overlapping application of 3 laws, and the joint discussion of AI governance and technical verification.
KMAC, Law Firm Lin, and SelectStar held a joint seminar on the 17th at the Pose Tower Event Hall in Yeoksam, Seoul. The seminar was titled "Practical Responses After the AI Basic Act: Responsibility, Governance, and Verification." It was organized as a forum to review the practical challenges companies and public institutions will face as the AI Basic Act takes effect.
The seminar aimed to share, in response to the enforcement of the AI Basic Act, changes in the procurement market, overlapping legal regulations, security risks, and practical AI governance execution models for companies and public institutions. Accordingly, procurement, regulation, security, and governance were discussed together at the event.
As a speaker, Bang Suk-ho, adviser at Law Firm Lin, took the stage. Bang said that Article 16, Paragraph 3 of the AI Basic Act, which states that "AI products and services should be considered first," would reshape the KRW 6.5 trillion public procurement market.
In connection with this, the subheading's point was that the confirmation certificate is a substitute, not a certification. Another observation presented as a key point of the day's remarks was that the impact of the legal provision could be significant in public procurement.
Meanwhile, the event photos were taken by reporter Kwon Young-seok.
The "AI product confirmation certificate" is emerging as a new standard for entering public procurement and is functioning as a new gateway. The certificate acquisition process consists of KOSA intake and TTA review. This system is described as easing the threshold for startups. As evidence, a 1.5-point bonus for new vendor evaluation is granted in Multiple Award Schedule (MAS), and the performance requirement for deliveries is also waived.
However, this certificate does not certify the accuracy or reliability of the system. Instead, it has the character of a substitute that replaces the method of proving technical requirements. In other words, it functions as a mechanism that changes how requirements are met in the public procurement entry process, but it is difficult to view it as a certification that guarantees performance or reliability itself.
In this regard, it was also pointed out that there is a fundamental mismatch between the characteristics of AI, which requires continuous learning, and TRL evaluation based on a finished-product standard. The argument was that, because AI has the ability to keep learning and changing, it does not align well with an evaluation method premised on a completed product.
Defense is, in principle, excluded from the priority consideration category. There is also a prohibition on duplicate designation. As a result, it was noted that civilian performance does not lead into defense entry, creating a disconnect.
Yoo Chang-ha, a lawyer at Law Firm Lin, said in his presentation that Bang, the center head, cited the structure behind Palantir's growth as one in which the U.S. Department of Defense purchased technology proven in the civilian market. He also introduced Bang as having said that while differentiation between public procurement and defense procurement is necessary, linking the two systems is also essential. The photo was credited to reporter Kwon Young-seok.
Yoo Chang-ha, a lawyer at Law Firm Lin, presented "Security and governance response measures based on the AI regulatory structure." Yoo explained that the three laws — the AI Basic Act, the Telecommunications Business Act, and the Personal Information Protection Act — are not mutually exclusive, and that the form in which all 3 laws apply to a single AI service is the "intersection."
Based on this structure, Yoo added that security and personal information response cannot be considered separately. Since multiple laws apply simultaneously to a single AI service, a system that separates security response from personal information response cannot cope with the regulatory structure.
Using the same hacking incident as a reference, Yoo explained that the reporting and notification deadline under the Telecommunications Business Act is "within 24 hours of recognizing the occurrence," while the reporting and notification deadline under the Personal Information Protection Act is "within 72 hours of recognizing the possibility." He said the response clocks under the two laws do not match, and that if those clocks cannot be integrated into a single incident response system, a delay in response to the same incident will occur twice.
Yoo then noted that if an organization does not align its internal reporting and response systems, sanctions and liability issues could become more serious. He explained that failure to integrate the board reporting system would expose the organization to the risk of fines and the risk of shifting responsibility.
Yoo explained that a 2026 revision introduced the elevation of the CISO to executive level and the government's ex officio investigation authority, while the Personal Information Protection Act codified the representative's responsibility and granted the CPO authority to secure personnel and budget. He also proposed incorporating white-hacker collaboration CVD/VDP into governance.
Son Kwon-sang, head of KMAC, who appears in the photo, delivered a presentation at the event and explained that public institution AX tasks are shifting in focus, with the emphasis moving from "strategy formulation" to "execution and risk control." He also pointed out that there is a problem of having a strategy but no execution system.
Son Kwon-sang, head of KMAC, said that the AI adoption rate stands at 65%, but diagnosed 5 remaining gaps in field execution. He identified those gaps as the lack of principles and rules, an unclear accountability system, the absence of introduction and review procedures, insufficient linkage to performance management, and inadequate data and post-management systems.
He then proposed a 4-pillar framework as the solution. He explained that the 4 pillars consist of principles and rules, organization and R&R, business processes, and change management.
He emphasized a CAIO-centered system at the executive level and proposed an organizational structure consisting of an ethics committee, planning organization, development organization, and operations organization. As a management system, he proposed life-cycle management from planning to disposal, and as a management method, he suggested an SOP and Stage-Gate system.
He also proposed a Logic Flow-based approach for performance management and a 4-stage talent development system. He explained that the 4 stages of talent development consist of sprout, junior, leader, and master.
Son defined AI governance as a collaborative decision-making system for shared goals and explained that clarity in principles, organization, and roles is required for this purpose. He also said that for AI governance to function, clarity in structure and roles must be a prerequisite.
Son went on to say that actual operation of business processes and organization/R&R is necessary. He also identified performance management and talent development as factors that support sustainability.
Next, Lee Hyun-taek, team leader at SelectStar, who spoke as the final presenter, gave a presentation on technical proof as a condition for completing governance. Reporter Kwon Young-seok handled the photography.
Lee Hyun-taek, team leader at SelectStar, introduced a technical verification stage that turns legal and governance discussions into engineering language. He presented transparency, safety, and high-impact risk as the items required by government guidelines, and explained that the way to verify them in the field is to quantify constitutional fundamental rights into measurable indicators and to require actual measurements by the development team.
Lee Hyun-taek said that the timing for applying verification is not limited to a single instance at the time of launch. He then explained that the scope of verification covers the entire life cycle from planning to operations, and that a system of continuous verification needs to be built into the process.
SelectStar supports verification with its in-house AI reliability evaluation platform, "Datumo." Datumo automates the calculation of evaluation metrics when domain data is uploaded, and it also automates red-teaming for vulnerability discovery when domain data is uploaded. Datumo can also be deployed in financial and public-sector environments that require network separation.
As examples of Datumo's use, SelectStar introduced a case in which bias in a commercial bank's credit review AI was resolved. It also introduced a case in which a nationally recognized AI safety benchmark was established. Another example was shortening the verification period for a major bank's financial counseling service.
The team leader said the AI Basic Act is a directional guideline. He said the AI Basic Act contains very little technical guidance related to testing methods. He then stressed that when Law Firm Lin's legal review, KMAC's governance design, and SelectStar's technical verification are combined, a response system that can be presented externally is completed.
Source: IT DAILY · Kwon Young-seok
Original: https://www.itdaily.kr/news/articleView.html?idxno=241697
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.