South Korea Wants an AI Built Specifically for Cybersecurity
Artificial intelligence is changing cybersecurity on both sides.
Security teams can use AI to analyse enormous volumes of logs and detect suspicious behaviour.
Attackers can also use AI to automate reconnaissance, discover vulnerabilities and create more convincing phishing campaigns.
South Korea now wants AI technology developed specifically for defending against that environment.
On 3 September, the country’s Ministry of Science and ICT selected a consortium led by Naver Cloud to develop a specialised cybersecurity AI foundation model.
The objective is not simply to take a general-purpose chatbot and ask it security questions.
South Korea wants models trained and optimised specifically around cybersecurity.
Naver Is Putting Around 4,000 GPUs Into the Project
Building a large foundation model requires enormous computing power.
Naver Cloud says its consortium will proactively deploy approximately 4,000 GPUs as part of the development programme.
The South Korean government will provide additional computing support.
According to the Ministry of Science and ICT, the consortium will receive access to as many as 256 NVIDIA B200 GPUs over a 10-month development period.
NVIDIA’s B200 is designed specifically for demanding AI workloads, making this a substantial computing allocation for a cybersecurity research project.
It also demonstrates an increasingly important reality:
Cybersecurity itself is becoming a major AI computing workload.
Two Huge Security-Focused AI Models Are Planned
Naver’s plan involves developing two independent cybersecurity models at approximately 700 billion parameters each.
The project will use technology derived from two major South Korean AI families:
- Naver’s HyperCLOVA X
- LG AI Research’s EXAONE
According to Korean reports, the models will be developed with different cybersecurity strengths, including defensive security analysis and capabilities for understanding offensive techniques in controlled security contexts.
Understanding both sides is important in cybersecurity.
Defenders need to know how attacks work before they can reliably detect and stop them.
Around 830TB of Security Data Could Be Used
AI models are only as useful as the data and training behind them.
According to Yonhap, approximately 830TB of cybersecurity-related data held by Naver Cloud, LG CNS and organisations responsible for national infrastructure and major industries is expected to contribute to training and development.
That could provide the models with a much more specialised understanding of areas such as:
- Malware behaviour
- Security alerts
- Network activity
- Vulnerability information
- Threat intelligence
- Incident patterns
The important distinction is that the system is being developed around South Korea’s own cybersecurity environment.
That is where the idea of sovereign AI becomes important.
What Is Sovereign AI?
Most businesses currently use AI models developed by a relatively small number of global technology companies.
That works for many applications.
But governments are increasingly asking whether strategically important systems should depend completely on foreign AI technology.
Sovereign AI generally refers to a country’s ability to develop, operate or control AI infrastructure, models and data within its own technological and regulatory ecosystem.
Cybersecurity is an obvious area where that matters.
National security systems can contain highly sensitive information that governments may not want transmitted to external AI platforms.
South Korea’s project therefore aims to develop an AI model customised to its language, infrastructure, threat environment and security requirements.
It Will Be Tested on Critical Infrastructure
This is not intended to remain only a laboratory project.
Naver says the models will be tested across seven strategic industries and national critical infrastructure environments.
Participating organisations include companies and institutions connected to sectors such as:
- Electricity and energy
- Finance
- Semiconductors
- Defence
- Telecommunications
- Public infrastructure
Organisations participating in the wider consortium include LG CNS, LG Uplus, Korea Hydro & Nuclear Power, KEPCO KDN, the Financial Security Institute and the Korea Institute of Science and Technology Information.
Testing the AI in real operational environments will help determine whether it can identify meaningful security threats rather than simply performing well in controlled benchmarks.
Cybersecurity Teams Face Too Much Data
One reason AI could become particularly useful in cybersecurity is the enormous volume of information modern systems produce.
A large organisation may generate security events from:
- Firewalls
- Servers
- Endpoints
- Cloud systems
- Applications
- Authentication platforms
- Email systems
- Network equipment
Security teams cannot manually inspect every event.
Traditional security platforms already use rules and machine learning to filter suspicious activity.
Foundation models could potentially take this further by understanding relationships between different events, summarising incidents and helping security analysts investigate suspicious behaviour faster.
The goal is not necessarily to remove cybersecurity professionals.
It is to help them process more information in less time.
AI Is Also Making Cyberattacks More Powerful
There is another reason governments are investing in security AI.
Attackers have access to AI too.
Generative AI can potentially help malicious actors automate parts of cyber operations, including information gathering, social engineering and analysing vulnerabilities.
More capable AI agents could accelerate some of these tasks further.
That changes the economics of cybersecurity.
An organisation may still have the same number of security engineers, but attackers could increasingly automate activities that previously required significant manual work.
Defensive systems therefore need to become faster as well.
South Korea’s decision to build a dedicated national security AI platform reflects this changing environment.
Why This Matters for Businesses Outside South Korea
Malaysia and other Asian countries should pay attention to this development.
Cybersecurity is increasingly becoming intertwined with:
- Artificial intelligence
- Cloud computing
- Sovereign infrastructure
- Data governance
- Critical infrastructure protection
Many organisations already use AI-powered endpoint protection, email security, threat detection and security monitoring.
The next generation could move towards much larger models capable of understanding an organisation’s entire security environment.
That could eventually change how businesses operate Security Operations Centres and managed cybersecurity services.
Instead of analysts manually switching between dozens of dashboards, specialised AI could help connect information across different systems and identify the incidents that require immediate attention.
Asia Is Building More of Its Own AI
South Korea’s cybersecurity programme also fits a broader trend across Asia.
Countries increasingly want more control over the AI technology used within their economies.
South Korea already has locally developed models such as HyperCLOVA X and EXAONE.
China has developed a large ecosystem of domestic foundation models.
Japan is investing in its own AI infrastructure and models.
Southeast Asian countries are also exploring national AI strategies and locally relevant language models.
The next stage of AI competition therefore may not revolve around one universal model.
We could increasingly see specialised and sovereign models designed for individual countries, industries and applications.
Cybersecurity may become one of the most important examples.
Closing Thoughts
The cybersecurity battle has always been a race between attackers and defenders.
AI is accelerating both sides.
South Korea’s response is ambitious: thousands of GPUs, two enormous specialised models and cybersecurity data drawn from some of the country’s most important industries.
But the bigger story goes beyond South Korea.
As AI becomes embedded deeper into national infrastructure, governments are beginning to treat AI capability itself as strategic infrastructure.
Cybersecurity may therefore become one of the areas where sovereign AI makes the most sense.
The future security platform may not simply detect malware.
It could understand networks, applications, users and threat intelligence together — and help security teams respond before a small warning becomes a major incident.
