Trustworthy AI Operations in the Era of Korea's AI Basic Act: Security Risk Visibility and Remediation with Security Lens
Session Overview
With Korea's AI Basic Act now in effect, enterprise AI adoption is no longer defined solely by model performance or speed to market. Organizations must also consider how safety, transparency, and trustworthiness are managed throughout the AI service lifecycle. While specific legal obligations vary depending on an organization's role and the type of AI product or service involved, managing risks across the cloud infrastructure, data, IAM permissions, code, and workloads that underpin AI services remains essential to service resilience and customer trust.
In this session, Jeho Park introduces Security Lens, a security operations platform that provides unified visibility into the underlying environments in which AI services operate. Security Lens correlates cloud assets, IAM permissions, data assets, code-level security issues, vulnerabilities, and attack paths, enabling security teams to identify priority risks in context rather than reviewing fragmented findings in isolation.
Through a process-oriented demonstration, the session shows how Security Lens connects identified risks to tickets, SLA tracking, remediation records, and audit evidence. Attendees will gain practical insights into establishing a repeatable security operations process that moves from risk identification and prioritization to remediation, verification, and evidence management.
Key Takeaways
- Why AI service trust operations matter now — distinguishing legal obligations from operational challenges in the AI Basic Act era.
- AI service security risk beyond the model — the attack surface created by cloud, permissions, data, code, and workloads.
- Security Lens asset visibility — identifying priority risk based on asset relationships and attack paths.
- Security Lens security process — connecting risk to tickets, SLAs, remediation history, and audit evidence.
Speaker
Jeho Park is a Cloud Security Solutions Architect at GS Neotek. He holds multiple professional credentials in information security, including Professional Engineer in Information Management and ISMS-P Certification Auditor. He has helped clients across a wide range of industries address complex cloud and security challenges through consulting, infrastructure and solution architecture, and implementation projects. He is currently focused on researching AI security and trustworthy security operations frameworks for the AI agent era.

