Leif-Eric EASLEY (Professor, Ewha Womans University) and Dabin CHOI (Graduate Student, Ewha Womans University) examine South Korea’s sovereign AI ambitions and assess the accompanying vulnerabilities within its cybersecurity posture. The authors argue that an absolutist push for a wholly indigenous AI stack risks amplifying exposure to sophisticated North Korean cyber threats due to geographic infrastructure concentration and budget-constrained defense asymmetries. Professor Easley emphasizes that Seoul should define AI sovereignty flexibly and bolster national resilience through pragmatic partnerships with the United States and other like-minded global actors.
Introduction
South Korean policymakers tend to see artificial intelligence as a tremendous opportunity, with the greatest perceived risk being that of falling behind (Kim, 2025). Prime Minister Han Seong-sook, a former technology executive appointed for her cyber-related experience, has pledged that the government will accelerate AI adoption in the public sector (Yonhap, 2026). The previous Yoon Suk-yeol administration articulated the ambition of making South Korea a top-three AI power with the U.S. and China, and advanced various regulatory and investment initiatives (MSIT, 2024). The Lee Jae-myung administration has more explicitly adopted the goal of “sovereign AI,” including domestic model development to enhance national competitiveness, diversify digital applications, and ensure public access to Korean-tailored solutions (MSIT, 2025). In June 2026, the South Korean government announced three mega-projects to build a national AI ecosystem and promote regional development beyond the Seoul metropolitan area, backed by multi-year domestic investment commitments from Samsung, SK, Hyundai and others in semiconductors, AI data centers, and physical AI. Speaking at the San Francisco AI Summit with U.S. and Korean tech leaders in July, Lee claimed that this more than US$3 trillion investment plan will make the ROK an “irreplaceable pillar of the global AI supply chain” and “will help take the Korean economy and global AI industry to new heights” (J. Lee, 2026).
Sovereign AI is broadly defined as capabilities necessary for national autonomy in AI policy choices without over-dependence on external actors (Varela Sandoval et al., 2026). Ha Jung-woo, while serving as Lee’s senior presidential secretary for artificial intelligence, described the South Korean vision for sovereign AI as a liberation of the domestic market from technological dependence, with the added ambition of exporting AI solutions to third countries coping with intensified U.S.-China technological rivalry (H. Lee, 2026). The rapid incorporation of AI in global trade, economic policy, national security, and cultural content has broadened sovereignty discussions well beyond data and infrastructure, drawing in additional layers of the AI stack (Stanford HAI, 2026). The South Korean debate surrounding sovereign AI includes advocates of developing an indigenous AI stack, as well as those who favor partnerships with—rather than heavy reliance on—current industry leaders such as OpenAI, Google, Meta, and Anthropic (Chey Institute, 2026). However, proponents tend to overlook a critical variable that should be priced into Seoul’s cost-benefit calculation: the DPRK cyber threat. North Korea’s expanding cyber capabilities, focus on ROK vulnerabilities, and efforts to use AI in offensive operations alter the risk profile of sovereign AI for South Korea.
Expected Costs and Benefits of Sovereign AI
South Korea cooperates with established U.S. AI firms instead of relying on entirely sovereign alternatives. This is likely to continue because of infrastructure availability, capability costs, and security benefits. American tech giants invest billions of dollars in cybersecurity, employ world-class security researchers, and operate massive and heavily protected data centers. South Korea’s limited role among global foundational and frontier model providers suggests a strategic choice to capture value across other layers of the AI stack rather than bear the full costs of competing head-on in model development. Building frontier-scale models requires enormous upfront investment in compute, data-center capacity, energy, and specialized labor (Kim and Kwon, 2026). Korean firms have instead leveraged their strengths in semiconductors, deployment infrastructure, and industrial applications. SK Hynix’s role as a leading supplier of high-bandwidth memory (HBM) for NVIDIA’s AI accelerators and Samsung’s foundry work for Tesla’s AI chips, in addition to Samsung’s status as a top memory producer, illustrate how Korean companies are integrating into global AI value chains through manufacturing expertise and customization rather than prioritizing a wholly indigenous full stack for sovereign AI (Draudt-Véjares and Lee, 2026).
The tradeoff, however, is dependence. Current arrangements give foreign companies the prerogative over pivotal decisions about training data, model architecture, and regulatory implementation, often making Korean entities consumers when developing and deploying domestic AI solutions. Countries interested in sovereign AI look to hedge against the possibility that Washington will “change the rules, restrict access, or use technology dependence as leverage” (Chavez, 2026). In June 2026, the Trump administration invoked national security export controls to bar all foreign nationals from accessing Anthropic’s most advanced models, which led the company to disable Claude Fable 5 and Mythos 5 for all users overnight (The Economist, 2026b). It was only weeks earlier that Trump ordered AI firms to voluntarily offer the government advanced access to new frontier models for safety checks after Anthropic’s products had been politicized during a dispute over usage rights with the Pentagon (Froman, 2026). Foreign and domestic access to Fable 5 and Mythos 5 was restored in about two weeks, but then Anthropic, along with OpenAI and Meta, disclosed cases where new models escaped their testing environments and conducted real cyberattacks on the Internet (CSA, 2026). South Korea attempts to address such problems and has shown regulatory leadership by passing the AI Basic Act. However, its strategy and legal framework still focus on industry promotion without sufficient attention to national security (Bae and Kim, 2025). Moreover, proposed platform legislation and data-localization mandates risk complicating U.S.-ROK commercial partnerships and potentially isolating South Korea’s AI industry from global cloud infrastructure and cross-border collaboration (Girishankar, 2025).
Sovereign AI is attractive to proponents who want Korean government agencies and firms to control the regulations, data governance, and ethical frameworks themselves. Korean opinion makers also frame the need for domestic AI capabilities in terms of national economic sovereignty, amid concerns that growing reliance on foreign models is driving token and API spending overseas, widening South Korea’s trade deficit in services (Han, 2026). In theory, homegrown models would generate significant benefits for the domestic economy while also offering export potential. South Korean actors aim to offer AI solutions to developing countries that wish to avoid overreliance on U.S. or Chinese platforms (Kharpal, 2025). Yet, sovereign AI policies can also carry substantial costs. Though the ROK government has committed to securing 52,000 GPUs by 2028 and 260,000 by 2030 (Jie, 2025), industry experts have expressed skepticism about whether South Korea can build its promised data centers, especially given its energy constraints. More than half of the grid buildout projects by the Korea Electric Power Corporation (KEPCO) are delayed due to lengthy permitting processes (Draudt-Véjares and Lee, 2026). Moreover, massive government resources directed toward sovereign AI could mean less budget for traditional defense or healthcare and pensions for an aging society.
If Korean firms are pressured to build sovereign AI solutions quickly and cheaply, they may turn to open-weight models as a foundation. This is not mere speculation, as the Ministry of Science and ICT eliminated Naver Cloud from the government’s flagship sovereign AI competition after it was discovered that Naver’s HyperCLOVA X had incorporated Alibaba’s open-source Qwen system in its model (G. Lee, 2026). Chinese companies have systematically extracted capabilities from American frontier models through industrial-scale distillation and released them as open-weight models which can be downloaded by anyone (Dunnmon, Narayan, and Saad-Falcon, 2026). Chinese frontier AI models may appear to be narrowing the gap with their American counterparts while offering lower prices, but private evaluation metrics indicate the actual gap remains wider than public benchmarks suggest, considering the need for more tokens to complete complex tasks (The Economist, 2026a). Moreover, Cisco and CrowdStrike found that when politically sensitive terms were included in ordinary coding prompts, DeepSeek-R1, one of the most widely adopted Chinese open-weight models, was 50 percent more likely to generate code with security vulnerabilities (Kassianik and Karbasi, 2025; Stein, 2025). A sovereign AI model that discreetly relies on Chinese open-source or open-weight solutions would not achieve AI sovereignty but instead trade one dependence for another less transparent and potentially dangerous one that could expand the attack surface available to hackers from North Korea. Reducing opaque foreign dependencies in the domestic AI stack can help limit the transfer of South Korean-held assets into the North, many of which are used to fund the regime’s weapons programs (UN Panel of Experts, 2024).
North Korean and Related Cyber Threats
The Office of the Director of National Intelligence’s 2026 Annual Threat Assessment described North Korea’s cyber program as “sophisticated and agile” and warned that artificial intelligence will “likely accelerate the threats in the cyber domain” (Office of the Director of National Intelligence, 2026). A Five Eyes intelligence statement warned AI-supercharged cyberattacks are an imminent threat for which governments and companies are not prepared (NCSC, 2026). Meanwhile, sovereign AI efforts can provide more and possibly easier targets for hackers. The Hangul Word Processor (HWP), a Korean computer program created as an alternative to Microsoft Word, was used across all levels of government, critical industries, and academia since 2013 and became a recurring target for North Korean hackers to infiltrate South Korean networks (Choi, 2025). A sovereign AI model built on the same logic of digital self-reliance risks replicating vulnerabilities at an even larger scale. The primary motivation behind Pyongyang's cyber offensive capabilities is likely financial, as many of its cyber activities can be traced to cryptocurrency theft. North Korea-linked hackers stole some US$2 billion in cryptocurrency in 2025, accounting for roughly 60 percent of all global cryptocurrency theft that year (Chainalysis, 2025). Illicit cyber activities account for possibly 30 percent of the Kim regime’s total revenue (Multilateral Sanctions Monitoring Team, 2025). CrowdStrike’s 2026 Financial Services Threat Landscape Report found that the FAMOUS CHOLLIMA group doubled its attacks by using AI-generated identities to infiltrate cryptocurrency exchanges, fintech firms, and retail banks (CrowdStrike, 2026).
Pyongyang has been attempting to integrate AI capabilities in the cyber, economic, and military domains. In August 2025, Anthropic confirmed that North Korean operatives had used its Claude model to fraudulently secure remote employment in U.S. Fortune 500 companies, creating fake identities and passing coding assessments with AI assistance (Anthropic, 2025). In May 2026, Google reported that North Korea’s APT45 hacking group had leveraged artificial intelligence to send thousands of repetitive prompts that recursively analyze the target’s cybersecurity blind spots for exploitation. This was the first documented case of a state threat actor using AI to discover and exploit new vulnerabilities at scale (Kang, 2026).
On top of the imminent threat from the North, South Korea must also take into account threats posed by China and Russia, not only because they are enablers of Pyongyang, but also because their own cyber activities target Seoul. Chinese state-backed hackers like TAG-74 have conducted cyber espionage campaigns targeting South Korean academic, political, and government organizations (Insikt Group, 2023), involving IP theft and data privacy violations. These risks may be intensified when combined with China’s position as a global leader in AI development with an open-source approach (Chan, 2026). China constitutes another variable in South Korea’s strategic calculus as both a technological competitor and a security concern. Russia’s fewer confirmed cyberattacks on South Korea do not make it benign, as it is increasingly an enabler for North Korea’s cyber capabilities and disinformation. Beyond North Korea’s use of Russian-speaking cybercriminal ecosystems, experts at Microsoft have observed collaboration among state-sponsored North Korean and Russian hacking groups (Hüsch and Jarnecki, 2026).
Updating Seoul’s Sovereign AI Calculus
The North Korean cyber threat needs to be better accounted for in three dimensions of South Korea’s sovereign AI debate: geographic distribution, attacker-defender asymmetry due to budget constraints, and the rapidly changing fintech industry. Geographic concentration is a major issue for the ROK. Sovereign AI calls for data localization, which would concentrate critical AI infrastructure within a small, targetable territory. South Korea spans only some 100,000 square kilometers, and the Seoul metro area is within artillery range of the inter-Korean border. As the southernmost island of Jeju is only about 450 kilometers away, all of South Korea is within range of an extensive North Korean missile arsenal. A fire in September 2025 at the National Information Resources Service data center in Daejeon caused by a lithium-ion battery explosion paralyzed 709 government services, which took 95 days to fully recover (Ministry of the Interior and Safety, 2025). If an accidental fire could cause this much disruption, the consequences of a deliberate attack—via cyber, sabotage, drone, or missile—could be severe. In contrast, U.S. data centers are distributed across a much wider territory and far less vulnerable to North Korean physical or cyber attack. Estonia, which lacks strategic depth in a geopolitically vulnerable location near Russia, recognized the risks and established a “data embassy” in Luxembourg to ensure government continuity even if its domestic infrastructure were attacked or destroyed (O’Regan, 2026). South Korea, despite facing a highly capable and active cyber adversary, has no equivalent arrangement. Articles 28-8 and 28-9 of the ROK Personal Information Protection Act (PIPA, 2023) restrict cross-border transfers of personal information, while the Electronic Government Act, National Intelligence Service Act, and related security regulations impose additional legal restrictions on government systems.
Furthermore, when budget-constrained sovereign models face an AI-enabled adversary, they can fall prey to attacker-defender asymmetries. The Ministry of Science and ICT and the Korea Internet and Security Agency used publicly available AI models to simulate an attack on a sovereign AI model in the process of being developed by a Korean corporation; the simulated attack found seven vulnerabilities in approximately ten minutes (Seo, 2026). South Korean sovereign AI models are built on much tighter budgets with much smaller user bases than those of OpenAI, Google, and Anthropic. If targeted by North Korean hackers armed with frontier AI models for offensive operations, South Korean firms will be in an unfavorable position. South Korea regularly experiences major cybersecurity breaches, with incidents increasing at a rate of 26 percent annually, reaching an accumulated total of 2,383 reported cases by 2025 (Korea Internet & Security Agency, 2026). The Lazarus Group’s evolution demonstrates how North Korean hackers leverage a deep understanding of South Korean software ecosystems. For example, during Operation SyncHole, assailants were able to compromise at least six organizations across the financial, IT, semiconductor, and telecommunications sectors by exploiting a security tool widely used by South Korean online banking and government websites (Kaspersky, 2025).
AI adoption in the financial sector could produce new vulnerabilities to North Korean cyber operations. In November 2025, South Korea’s largest digital asset exchange platform, Upbit, was hacked for US$30.6 million worth of tokens on the Solana network. South Korean authorities have since identified the Lazarus Group as the culprit (Kang, 2025). Meanwhile, major financial institutions are incorporating AI more deeply into their systems, as KakaoBank endeavors to become an “AI Native Bank” and the heads of KB, Shinhan, Hana, and Woori all expressed their focus on accelerating AI and digital transformation in their 2026 New Year’s messages (Jun, 2026). Given that financial theft is one of Pyongyang’s primary cyber missions, the integration of sovereign AI into South Korean fintech could place these systems within a domain where North Korea is highly capable, active, and incentivized to attack.
Conclusion
South Korea is not the only country pursuing sovereign AI. According to the CNAS Sovereign AI Index, 67 countries are undertaking such projects as of June 2026 (Chavez et al., 2026). Most of these aim to address specific needs and dependencies; few are comprehensive programs building sovereign AI models from scratch, many instead focus on improving in-country infrastructure around data centers. France and the United Arab Emirates have both adopted the language of AI sovereignty while building their strategies on partnerships with U.S. firms. France has announced more than €109 billion in AI infrastructure investments (Élysée Palace, 2025) while relying on NVIDIA GPUs, Silicon Valley solutions, and foreign capital to elevate its domestic leaders like Mistral. The UAE launched Stargate UAE as the first "OpenAI for Countries" partnership (OpenAI, 2025) and received a US$1.5 billion Microsoft investment in its flagship AI firm G42 (Microsoft, 2024). Neither country equates sovereignty with autarky but rather defines it as control over governance, safety testing, deployment decisions, and strategic data, while accepting that frontier computing, cloud, and model ecosystems will remain transnational. Since neither France nor the UAE face a challenge set like North Korea, South Korea needs to be even more pragmatic about the cybersecurity architecture of its sovereign AI strategy.
It is reasonable for Seoul to pursue an ambitious sovereign AI policy, but only if sovereignty is defined flexibly rather than in nationalist terms. An absolutist approach, in which every layer of the AI stack must be entirely Korean-built and domestically housed, would prove counterproductive. That would cluster critical infrastructure within a small and targetable geography and rely on a cybersecurity network that is already struggling to defend existing digital systems. By favoring the growth of national IT champions, the ROK has produced a concentrated platform environment in which the failure of one major player could compromise much of the domestic digital ecosystem (Merrill, 2025). A feasible sovereign AI strategy would ensure Korean decision-making agency, regulatory influence, and revenue opportunities at every layer of the AI stack. This could be achieved by allowing Korean firms greater prerogative to cooperate with American, Japanese, and European firms while reducing the risks of using open-weight models with security issues. Considering the amount of resource expenditure involved, the government also needs to be mindful of public opinion, as well as implications for the job market and individual privacy. Recent data breaches in South Korea have been numerous and severe; the Coupang case alone was serious enough to warrant a fine of over US$400 million (Lim, 2026). The legal and institutional infrastructure is struggling to catch up with the deployment of technologies and the rise of cyber vulnerabilities. The ROK has long recognized it cannot deter DPRK nuclear weapons by itself (Easley, 2025); it should also not face the North Korean cyber threat alone. Partnering with the U.S. and other like-minded governments and their trusted firms is a more secure way of pursuing South Korean sovereign AI. ■
References
Anthropic. 2025. “Detecting and Countering Misuse of AI: August 2025.” August 27. https://www.anthropic.com/news/detecting-countering-misuse-aug-2025
Bae, Sunha, and So Jeong Kim. 2025. “AI Security Strategy and South Korea’s Challenges.” Center for Strategic and International Studies. June 20. https://www.csis.org/analysis/ai-security-strategy-and-south-koreas-challenges
Chainalysis. 2025. “North Korea Drives Record $2 Billion Crypto Theft Year, Pushing All-Time Total to $6.75 Billion.” December 18. https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/
Chan, Kyle. 2026. “China Is Running Multiple AI Races.” Brookings Institution. March 9. https://www.brookings.edu/articles/china-is-running-multiple-ai-races/
Chavez, Pablo. 2026. “The Sovereignty Gap in U.S. AI Statecraft.” Lawfare. February 16. https://www.lawfaremedia.org/article/the-sovereignty-gap-in-u.s.-ai-statecraft
Chavez, Pablo, Vivek Chilukuri, and Ruby Scanlon. 2026. “Sovereign AI’s Second Wave Is Coming Into View.” Center for a New American Security. August 20. https://www.cnas.org/publications/cnas-insights/cnas-insights-sovereign-ais-second-wave-is-coming-into-view
Chey Institute for Advanced Studies. 2026. “AI 주권 시대, 대한민국의 선택 [The Age of AI Sovereignty: South Korea’s Choice].” Chey Institute for Advanced Studies. January 14. https://www.chey.org/Kor/BooksnReports/BooksnReportsView.aspx?seq=27&pageno=1
Choi, Perry. 2025. “HWP as an Attack Surface: What Hancom’s Hangul Word Processor Means for South Korea’s Cyber Posture as a US Ally.” 38 North. October 27. https://www.38north.org/2025/10/hwp-as-an-attack-surface-what-hancoms-hangul-word-processor-means-for-south-koreas-cyber-posture-as-a-us-ally/
Cloud Security Alliance (CSA) AI Safety Initiative. 2026. “When Test Environments Leak: Frontier AI Models Hack Real Firms.” August 7. https://labs.cloudsecurityalliance.org/research/csa-research-note-frontier-ai-models-hacking-real-systems-ev/
CrowdStrike. 2026. “2026 Financial Services Threat Landscape Report.” May 12. https://www.crowdstrike.com/en-us/resources/reports/crowdstrike-2026-financial-services-threat-landscape-report/
Draudt-Véjares, Darcie, and Seungjoo Lee. 2026. “Governing AI in the Shadow of Giants: Korea’s Strategic Response to Great Power AI Competition.” Carnegie Endowment for International Peace. April 30. https://carnegieendowment.org/research/2026/04/governing-ai-in-the-shadow-of-giants-koreas-strategic-response-to-great-power-ai-competition
Dunnmon, Jared, Avanika Narayan, and Jon Saad-Falcon. 2026. “China’s AI Heist.” Foreign Affairs. May 29. https://www.foreignaffairs.com/china/chinas-ai-heist
Easley, Leif-Eric. 2025. “‘Getting Asia Right’ With a More Strategic US-South Korea Alliance.” Journal of East Asian Affairs 38(1): 125-165. https://www.inss.re.kr/en/publications/bbs/joeaa_en_view.do?nttId=41037638
The Economist. 2026a. “China is having another AI moment.” The Economist. June 21. https://www.economist.com/china/2026/06/21/china-is-having-another-ai-moment
The Economist. 2026b. “Donald Trump Has Cut Off Access to the World’s Best AI Model.” The Economist. June 14. https://www.economist.com/business/2026/06/14/donald-trump-has-cut-off-access-to-the-worlds-best-ai-model
Élysée Palace. 2025. “Make France an AI Powerhouse.” February 11. https://www.elysee.fr/en/emmanuel-macron/2025/02/11/make-france-an-ai-powerhouse
Froman, Michael. 2026. “The AI Sovereignty Paradox at Home and Abroad.” Council on Foreign Relations. February 27. https://www.cfr.org/articles/the-ai-sovereignty-paradox-at-home-and-abroad
Girishankar, Navin. 2025. “How AI Cooperation Can Save the U.S.-ROK Trade Talks.” Center for Strategic and International Studies. July 15. https://www.csis.org/analysis/how-ai-cooperation-can-save-us-rok-trade-talks
Han, Kwang-beom. 2026. “‘AI 토큰 비용이 새 무역적자 된다’…라이너 ‘한국 AI 생존 전략은 내재화’ [‘AI Token Costs Could Become a New Trade Deficit’…Liner: ‘Korea’s AI Survival Strategy Is Internalization’].” Edaily. August 5. https://www2.edaily.co.kr/News/Read?mediaCodeNo=257&newsId=04890486645544368
Hüsch, Pia, and Joseph Jarnecki. 2026. “DPRK and Russian Collaboration in Cyberspace as a Driver for UK-ROK Cyber Cooperation.” 38 North. March 4. https://www.38north.org/2026/03/dprk-and-russian-collaboration-in-cyberspace-as-a-driver-for-uk-rok-cyber-cooperation/
Insikt Group. 2023. “Multi-year Chinese APT Campaign Targets South Korean Academic, Government, and Political Entities.” Recorded Future. September 19. https://www.recordedfuture.com/research/multi-year-chinese-apt-campaign-targets-south-korean-academic-government-political-entities
Jie, Ye-eun. 2025. “Korea to Begin Full-Scale AI Buildout in 2026: Minister.” Korea Herald. December 15. https://www.koreaherald.com/article/10636733
Jun, Ji-hye. 2026. “Korea’s Top Financial Groups Pledge Overhaul as AI, Productive Finance Take Center Stage in 2026.” Korea Times. January 2. https://www.koreatimes.co.kr/business/banking-finance/20260102/koreas-top-financial-groups-pledge-overhaul-as-ai-productive-finance-take-center-stage-in-2026
Kang, Jae-eun. 2026. “N.K. hackers using AI to find cybersecurity blind spots, Google says.” Yonhap. May 12. https://en.yna.co.kr/view/AEN20260512005600320
Kang, Yoon-seung. 2025. “N. Korean hacking group Lazarus suspected behind recent crypto hacking: sources.” Yonhap. November 28. https://en.yna.co.kr/view/AEN20251128003952320
Kaspersky. 2025. “Kaspersky Uncovers New Lazarus-Led Cyberattacks Targeting South Korean Supply Chains.” April 24. https://www.kaspersky.com/about/press-releases/kaspersky-uncovers-new-lazarus-led-cyberattacks-targeting-south-korean-supply-chains
Kassianik, Paul, and Amin Karbasi. 2025. “Evaluating Security Risk in DeepSeek and Other Frontier Reasoning Models.” Cisco Blogs. January 31. https://blogs.cisco.com/security/evaluating-security-risk-in-deepseek-and-other-frontier-reasoning-models
Kharpal, Arjun. 2025. “South Korea Charts One-of-a-Kind Course in AI Race with U.S. and China.” CNBC. August 8. https://www.cnbc.com/2025/08/08/south-korea-to-launch-national-ai-model-in-race-with-us-and-china.html
Kim, Haeyoon. 2025. “The Sovereign AI Debate and Prospects of ‘Korean’ AI.” Korea Economic Institute of America. January 8. https://keia.org/analysis/the-sovereign-ai-debate-and-prospects-of-korean-ai/
Kim, J. James and Sean (Hyuk Hyun) Kwon. 2026. “From Compute to Capacity: South Korea’s Approach to Industrial AI Adoption.” Stimson Center. February 6. https://www.stimson.org/2026/from-compute-to-capacity-south-koreas-approach-to-industrial-ai-adoption
Korea Internet & Security Agency. 2026. “25년 사이버 위협 하반기 동향 및 26년 전망 [2025 Cyber Threat Trends and 2026 Cyber Threat Outlook Report].” February 6. https://www.kisa.or.kr/skin/doc.html?fn=20260206_153449_003.pdf&rs=/result/2026-02/
Lee, Gyu-lee. 2026. “National AI Model Project Faces Controversies over Plagiarism Claims.” Korea Times. January 7. https://www.koreatimes.co.kr/business/tech-science/20260107/national-ai-model-project-faces-controversies-over-plagiarism-claims
Lee, Hun-il. 2026. “하정우: ‘최대성과, GPU 26만장 확보…독자AI 없으면 국가안보 문제’ [Ha Jung-woo: ‘Our Biggest Achievement is Securing 260,000 GPUs…Without Independent AI, National Security is at Risk’].” The Fact. April 21. https://news.tf.co.kr/read/ptoday/2315267.htm
Lee, Jae-myung. 2026. “San Francisco Declaration on Artificial Intelligence.” Office of the President of the Republic of Korea. July 24. https://en.president.go.kr/president/statements-remarks/a2eIOLXS
Lim, Sun-young. 2026. “메타보다 더 세게 맞았다, 쿠팡 과징금 6247억 ‘역대 최대’ [Hit Harder than Meta: Coupang Fined ₩624.7 Billion, the Largest Ever].” JoongAng Ilbo. June 12. https://www.joongang.co.kr/article/25436101
Merrill, Nick. 2025. “The South Korean Digital Paradox: How South Korea’s Internet Development Model Creates Unique Cybersecurity Vulnerabilities.” Center for Long-Term Cybersecurity, University of California, Berkeley. April. https://cltc.berkeley.edu/publication/the-south-korean-digital-paradox-how-south-koreas-internet-development-model-creates-unique-cybersecurity-vulnerabilities/
Microsoft. 2024. “Microsoft Invests $1.5 Billion in Abu Dhabi’s G42 to Accelerate AI Development and Global Expansion.” April 16. https://news.microsoft.com/source/2024/04/16/microsoft-invests-1-5-billion-in-abu-dhabis-g42-to-accelerate-ai-development-and-global-expansion/
Ministry of the Interior and Safety. 2025. "국가정보자원관리원 709개 시스템 전체 복구 완료 [National Information Resources Services Completes Full Recovery of All 709 Systems]." December 30. https://www.mois.go.kr/frt/bbs/type010/commonSelectBoardArticle.do?bbsId=BBSMSTR_000000000008&nttId=122775
Ministry of Science and ICT (MSIT). 2024. “MSIT Presents Blueprint for Korea’s AI Innovation to Achieve AI G3 Status.” September 26. https://www.msit.go.kr/eng/bbs/view.do?bbsSeqNo=42&mId=4&mPid=2&nttSeqNo=1040&pageIndex&sCode=eng&searchOpt=ALL&searchTxt
_____. 2025. “MSIT Selects Five Elite Teams for the ‘Sovereign AI Foundation Model’ Project.” August 4. https://www.msit.go.kr/eng/bbs/view.do;jsessionid=kndLBpcdYr-gB9iqSygkTqBG4r82Uq5403hvdHoT.AP_msit_1?sCode=eng&mPid=2&mId=4&bbsSeqNo=42&nttSeqNo=1152
Multilateral Sanctions Monitoring Team. 2025. “The DPRK’s Violation and Evasion of UN Sanctions through Cyber and Information Technology Worker Activities.” October 22. https://msmt.info/Publications/detail/MSMT%20Report/4221
National Cyber Security Centre (NCSC). 2026. The AI Shift in CyberRisk: Why Leaders Must Act Now. June 22. https://www.ncsc.gov.uk/news/the-ai-shift-in-cyber-risk-why-leaders-must-act-now
Office of the Director of National Intelligence. 2026. Annual Threat Assessment of the U.S. Intelligence Community. March 18. https://www.dni.gov/index.php/newsroom/reports-publications/reports-publications-2026/4141-2026-annual-threat-assessment
OpenAI. 2025. “Introducing Stargate UAE.” May 22. https://openai.com/index/introducing-stargate-uae/
O’Regan, Ellen. 2026. “A nation on a hard drive: Inside the rise of digital embassies.” Politico EU. May 26. https://www.politico.eu/article/estonia-russia-luxembourg-hard-drive-data-foreign-vaults/
Personal Information Protection Act (PIPA). 2023. Act No. 19234. Korea Legislation Research Institute, Korea Law Translation Center. https://elaw.klri.re.kr/eng_service/lawView.do?hseq=62389&lang=ENG
Seo, Byeong-ju. 2026. “보안 위협 된 AI…‘독자 모델 개발·국제협력’ 폭 키우는 정부 [AI Becomes a Security Threat: Government Expands Independent Model Development and International Cooperation].” Asia Today. May 12. https://www.asiatoday.co.kr/kn/view.php?key=20260512010003082
Stanford Institute for Human-Centered Artificial Intelligence (HAI). 2026. The 2026 AI Index Report. Stanford University. April. https://hai.stanford.edu/ai-index/2026-ai-index-report
Stein, Stefan. 2025. “CrowdStrike Research: Security Flaws in DeepSeek-Generated Code Linked to Political Triggers.” CrowdStrike. November 20. https://www.crowdstrike.com/en-us/blog/crowdstrike-researchers-identify-hidden-vulnerabilities-ai-coded-software/
UN Panel of Experts. 2024. Final Report of the Panel of Experts Submitted Pursuant to Resolution 2680. S/2024/215. United Nations Security Council. March 7. https://undocs.org/S/2024/215
Varela Sandoval, Francisco Javier, Isabella Wilkinson, Alex Krasodomski, and Rowan Wilkinson. 2026. “How Middle Powers Can Weather US and Chinese AI Dominance: The Case for ‘Sovereign AI’ Strategies.” Chatham House. February. https://www.chathamhouse.org/sites/default/files/2026-02/2026-02-13-sovereign-ai-strategies-sandoval-et-al.pdf
Yonhap. 2026. “PM vows to speed up AI transformation in public sector.” July 9. https://en.yna.co.kr/view/AEN20260709004251315
■ Leif-Eric EASLEY (Ph.D. in Government, Harvard University) is Professor at Ewha Womans University in Seoul, where he teaches international security and political economics. Dabin CHOI is a graduate student in international studies at Ewha with research focused on cybersecurity and AI in Asia.
■ Edited by Sangjun LEE, EAI Research Associate.
For inquiries: 02 2277 1683 (ext. 211) | [email protected]