Securing the AI Era: Authority, Accountability, and Responsible Innovation
AI has entered an era in which it can make decisions and take action on its own. The key question is no longer simply whether to use AI, but how much authority to grant it to observe, decide, and act. This article shares insights from Vincent Sang Kook Lee, Chief Growth Officer at AhnLab, on cybersecurity in the AI era and the path toward “responsible innovation.”
AI is reshaping the cybersecurity landscape.
AI agents introduce a new set of concerns. They go beyond providing information or analysis. They can access systems, move data, and take real action. Additionally, attackers also use AI to find vulnerabilities faster, combine attack paths, and execute them repeatedly.
Then how must security evolve when AI is accelerating both attack and defense?
At the ISEC 2026 Talk Concert, Vincent Sang Kook Lee, Chief Growth Officer at AhnLab, discussed cyberthreats in the AI era, the principles that should guide cybersecurity companies using AI, and the competitive strengths and future of Korean security vendors.

1. AI's Biggest Impact Is Not 'New Attacks,' but Speed and Scale
Discussions of AI-powered cyberattacks often begin with entirely new forms of attack. Vincent focused on a different issue.
The biggest threat of AI is not creating completely new attacks, but that it increases the speed and scale of existing threats. Vulnerabilities, misconfigured permissions, and unmanaged accounts existed long before AI. What has changed is how quickly attackers can find and exploit them. AI rapidly scans for vulnerabilities, combines multiple attack paths, and executes them repeatedly. Defenders consequently have less time to identify, assess, and respond to such attacks.
During the Talk Concert, Vincent noted that finding vulnerabilities faster does not guarantee a successful attack. An exploit becomes a real attack when vulnerabilities combine with security weaknesses such as excessive privileges, unmanaged assets and accounts, unpatched systems, and access to internal information. AI's threat lies in how quickly it identifies these weaknesses, combines them into attack paths, and executes those paths repeatedly.
The threat that deserves attention in the AI era is not limited to the emergence of entirely new attack techniques. It is equally important to recognize how quickly AI can identify existing security weaknesses and exploit them in attacks.
2. AI Assistants and AI Agents, From Wrong Answers to Wrong Actions
AI agents raise security concerns that differ from those associated with earlier uses of AI. When an AI assistant gets something wrong, the impact is limited to incorrect information. An AI agent, however, can access systems, move data, and take action, which means an incorrect decision can lead to real consequences.
The key difference is whether AI simply provides information or is authorized to act. As AI agents gain access to systems, data, and tools, they also create new attack surfaces.
For CISOs, the focus therefore shifts from whether to adopt AI to how much authority it should have to observe, decide, and act. As organizations expand their use of AI, governing and controlling its authority becomes essential.
Organizations should maintain an inventory of AI assets and apply least privileged access. They also need systems that log AI actions and monitor them in real time. High-impact actions should require human approval, and organizations should be able to shut down AI systems when necessary.
3. Trusting AI Is Not the Same as Governing It to Be Trustworthy
As the AI race accelerates, cybersecurity companies face pressure to incorporate AI into products and services. However, in security, speed does not determine the value of AI innovation.
Vincent emphasized that “responsible innovation” matters just as much as rapid innovation.
The basis for an AI decision should be understandable, and humans should approve high-impact actions. If an error occurs, the AI must be able to stop and revert the change.
Trusting AI and governing it so that it can be trusted are two different things.
Organizations must identify AI assets, record how it is used, monitor its behavior, and restrict access to only the data required. Principles of responsible AI, including fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability, must also be embedded in product development and operations.
4. Why Security Fundamentals Matter Even More in the AI Era
The rise of autonomous AI-powered attacks does not mean there also will be a single, universal solution that can stop them.
Vincent emphasized that while AI can identify vulnerabilities faster, successful attacks still depend on familiar weaknesses such as excessive privileges, unmanaged assets, unpatched systems and access to internal information.
This makes basic security measures even more important. Organizations must maintain an accurate asset inventory and apply security updates. They must manage accounts and privileges, segment networks, protect endpoints, and control data access. Regular assessments and incident response exercises are also necessary.
Additionally, organizations should also regularly test whether their security controls work effectively in real life incident scenarios.
AI makes it tempting to believe that everything must be reinvented. Yet incidents still begin with basic vulnerabilities.
This is why security fundamentals matter more, not less, in the AI era.
5. Start with the Customer's Problem, Not with AI
How should cybersecurity companies apply AI to their products and services?
Vincent highlighted that the starting point should not be a desire to use AI technology, but the problem the customer needs to solve.
The challenges in security operations are already clear.
An overwhelming volume of detection events can obscure critical threats, while teams may lack the resources to analyze them. Organizations also struggle to correlate information generated by different security solutions.
This is where AI can make a practical difference. It summarizes events, prioritizes threats, shortens analysis and response times, and supports security teams as they make decisions and take action.
AhnLab is also moving its solutions and services toward a platform-based model. It connects data generated across endpoints, networks, cloud environments, and threat intelligence, then uses AI to strengthen integration and interoperability across customers' detection, analysis, and response operations.
What matters is not how much a company has applied AI, but which customer problems it solves with AI.
6. From Product Centric to Security Operations Centric
The AI era also brings new challenges to product strategy for cybersecurity companies. Vincent emphasized a shift from product-centric thinking to a model centered on the customer's security operations.
Gaps in detection can delay the identification of risks. Ineffective decision-making can lead to poor prioritization, and inadequate response allows an incident to escalate.
Therefore, endpoint, network, cloud, and threat intelligence solutions should work together within a unified operational flow instead of operating separately. This requires a common data model, open APIs, integrated policy and asset management, consistent risk scoring, and automated response.
Developing every product in-house is not the only option. Technology alliances and joint services among domestic companies, along with global partnerships can be a practical option.
Sales models must also evolve from standalone licensing to subscription and as-a-service offerings aligned with platform services that deliver security outcomes and operational efficiency.
Integration should go beyond bringing multiple products together on a single screen. A truly integrated platform should connect the entire cycle of identifying, assessing, responding to, and learning from risk.
7. Global Competitiveness Starts with Operational Maturity
In the global security market, major vendors compete through integrated platforms and extensive threat intelligence.
Korean cybersecurity companies should not overstate their current position in this market.
Vincent said it would be unrealistic to claim that Korean security technology has reached parity in every area with major global vendors that have spent years adapting to public cloud, SaaS, and AI-enabled environments.
Korean cybersecurity companies nevertheless have distinct competitive strengths.
They are closest to Korean customers and best positioned to understand and solve problems in their actual operating environments.
Their deep knowledge of Korean regulations, closed networks and network separation requirements, public-sector, financial, and manufacturing environments, legacy systems, domestic applications, and business processes is a clear advantage.
They can quickly incorporate customer requirements into products and services and work closely with customers during technical support and incident response. Years of data and response experience involving threats that target Korean businesses provide another competitive advantage.
Local responsiveness alone, however, is not enough. Companies must standardize operational practices proven in Korea and extend them through APIs, cloud-based services, and global partner ecosystems. Success requires both deep local expertise and global scalability.
Companies also need to combine core security capabilities with AI-driven analytics, automation, threat intelligence, and cloud security. By actively adopting international standards and global validation frameworks, they can provide credible evidence of their technical capabilities.
8. Compete on Operational Reliability, Not the Number of Features
What must Korean-built security solutions improve to earn the same level of trust as global alternatives? Vincent mentioned the priority should be the quality of the overall deployment and operations experience, not any single feature or performance metric.
First, API and data interoperability.
As customers do not rely on only one product, solutions must connect easily to other security and IT systems through standardized APIs and data formats.
Second, UI/UX and operational usability.
Instead of simply displaying a high volume of detection results, products should clearly show what matters, why it is risky, and what the user should do next.
Third, global operating capabilities.
Beyond multilingual support, companies must prepare for overseas regulations, technical support across time zones, cloud-region requirements, and global threat intelligence.
It does not mean that an AI feature is effective simply because it responds quickly. The system must explain the basis for its decisions and the sources of its data, and errors must be controllable. These are what make an AI feature reliable in practice, and that reliability matters more than the number of features it offers.
In the AI Era, Security Comes Down to Trust
AI is reshaping both sides of cybersecurity. It allows attackers to identify targets and launch attacks faster, but it also helps security professionals analyze threats and respond more effectively.
As AI is given a greater role in observing, making decisions, and taking action, organizations face a new set of questions.
What should AI be allowed to handle? How much authority should it have? And how should its decisions and actions be governed to ensure they can be trusted?
Those questions cannot be answered by AI technology alone.
Organizations need a strong security foundation that reduces unmanaged assets and accounts and properly manages privileges and updates. They must log and monitor AI actions and ensure human intervention at critical moments. At the same time, security products and data must be connected so that detection, analysis, and response can work as one integrated process.
Rather than trying to match the scale of major global vendors, AhnLab focuses on helping customers address what they need to do now and what they can realistically achieve. The company aims to strengthen its solutions by solving real customer problems and to build a roadmap that balances rapid innovation with responsible innovation.
In the AI era, trust remains the most important asset a cybersecurity company can build. Trust is earned by solving customer problems, not by overstating technology. That trust will shape competitiveness in the AI era and provide the foundation for growth beyond Korea and into global markets.
- AhnLab