
South Korea has selected a Naver Cloud-led consortium to develop a national artificial intelligence foundation model designed specifically for cybersecurity.
The selection was announced on September 3, 2026, by the Ministry of Science and ICT after an evaluation of proposals submitted by Naver Cloud and SK Telecom. The government said Naver’s consortium was chosen for its technical capabilities, development strategy, industry-academia-research partnerships and proposed use of multiple AI agents coordinated through a harness system.
The project is part of the government’s “Development of AI Foundation Models Specialized in Cybersecurity” program, which is intended to strengthen South Korea’s domestic cybersecurity AI capabilities.
Government support will provide 256 Nvidia B200 GPUs for up to 10 months. The initial support covers five months, with the remaining five subject to an interim evaluation.
The government plans to sign an agreement with the consortium during September and establish a working group to begin the project.
Naver is also committing substantially more computing resources of its own. The company said it has deployed 4,000 Nvidia B200 GPUs and has already begun pre-training before the formal government-backed project starts.
LG is contributing another 256 H200 GPUs. Including the government’s allocation, the project is expected to have access to a total of 4,512 GPUs when all planned resources are counted.
The consortium plans to build two separate cybersecurity models, each ultimately targeting about 700 billion parameters and using a Mixture-of-Experts architecture.
One model will be based on Naver’s HyperCLOVA X and will focus on defensive cybersecurity capabilities.
The second will be based on LG AI Research’s EXAONE and will be developed with a stronger focus on offensive cybersecurity capabilities.
Naver said the two models are intended to complement each other across cybersecurity activities including attack detection, analysis and response.
The consortium also says it has secured about 830 terabytes of real-world cybersecurity data for training.
The data is expected to come from organizations including Naver Cloud, LG CNS, KEPCO KDN, Korea Hydro & Nuclear Power, the Financial Security Institute, the Korea Institute of Science and Technology Information and LG Uplus.
Before the data is used for training, the consortium plans to carry out threat-information collection, labeling, standardization and verification. The broader process is also expected to support vulnerability analysis, attack reproduction and synthetic or augmented data generation.
The models are planned for field testing in seven strategic sectors: energy, finance, science and technology, telecommunications, semiconductors, defense, and aerospace.
Naver said the goal is to continuously improve the models through deployment involving critical infrastructure and major industrial sites.
The consortium also plans to support operation in closed or air-gapped networks where systems cannot freely connect to the public internet.
Naver has pointed to its experience deploying foundation models in restricted and on-premises environments, including sectors such as finance and nuclear power, as part of its proposal.
The government specifically cited the consortium’s proposed multi-agent architecture and harness system among the strengths of its submission.
Under the approach, different AI agents would handle different security tasks while a coordinating system manages their interaction. The available information describes this as part of the proposed architecture rather than an already deployed autonomous cybersecurity system.
Naver’s consortium includes 33 organizations in total, including Naver Cloud, according to the company.
Participants reported in connection with the consortium include LG CNS, LG AI Research, LG Uplus, Logpresso, MarkAny, SANDS Lab, Sparrow, S2W, AI Spera, ESTsecurity, Jiransecurity, Trillion Labs, Theori Korea, Tatum and HyperXcel.
The group also includes organizations such as Korea Aerospace Industries, Korea Hydro & Nuclear Power, KEPCO KDN, the Financial Security Institute and KISTI, along with universities and research organizations including Seoul National University, KAIST, POSTECH, Korea University and Chung-Ang University.
The final competition involved two consortium proposals. The government opened the call for applications on July 22, 2026, and received submissions from Naver Cloud and SK Telecom by the August 26 deadline.
SK Telecom’s consortium included 13 organizations, among them Upstage, SK Shieldus, Secui, AhnLab, Igloo Corporation, RaonSecure, Smart M2M, AIM Intelligence, Genians, Pionlink, the Korea Information Security Industry Association, Korea University and Soongsil University industry-academia foundations.
SK Telecom’s proposal emphasized an agent-based security system designed around continuous security-monitoring data and automation covering detection, analysis, response and remediation.
Separately, SK Telecom has joined Anthropic’s Project Glasswing and received early access to Claude Mythos, Anthropic’s cybersecurity-focused model initiative.
Anthropic introduced Claude Mythos Preview in April 2026 and described it as a model aimed at computer-security tasks, including work involving real software vulnerabilities.
South Korean reporting has connected the emergence of Mythos with growing attention around the country’s own cybersecurity AI efforts, although the government program is also part of South Korea’s broader strategy to strengthen domestic AI and cybersecurity capabilities.
The Naver consortium intends to release the resulting cybersecurity model as open source for commercial use, according to Naver.
The company also says the project will provide free vulnerability and cyberattack detection checks for small businesses and help domestic security companies commercialize AI services through the Naver Cloud Marketplace.
The project is expected to run for up to 10 months under the government-backed program, with the remaining period of GPU support dependent on the interim evaluation after the first five months.
Government and consortium activity is expected to begin in September 2026. Separate reporting has placed the wider development and testing period through around July 2027, with an interim review expected around February 2027.
The project still faces several unresolved questions, including whether the models will outperform established commercial cybersecurity systems, how effectively the 830TB dataset will translate into real-world security performance, and whether the resulting models can operate reliably in restricted environments.
Sources and further reading:
- Naver Cloud’s official announcement
- South Korean government announcement
- Yonhap report on the Naver Cloud selection
- Anthropic’s Claude Mythos research
- SK Telecom’s Project Glasswing announcement
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

