Coupang's $409M Fine Highlights AI Governance Crisis
A stolen signing key exposed 33M customer records—governance failure costs big.
South Korean regulators hit Coupang with a record 624.9 billion won ($409 million) fine after inadequate data access controls allowed a former employee to retain a stolen cryptographic signing key, exposing approximately 33 million customer records. The Korea Personal Information Protection Commission's June 11 ruling is the largest data-protection penalty in Korean history and signals a fundamental shift: AI governance failures now carry hard dollar costs.
Three events within three business days reinforce this. On June 12, the US restricted foreign national access to Anthropic's Fable 5 and Mythos 5 models after the UK AI Security Institute confirmed Mythos could autonomously complete a 32-step enterprise attack simulation. That same day, the White House signed NSPM-12, mandating new inventory requirements for systems handling classified information. The common thread: AI capability is now a national security concern, and governance frameworks—still built for human-operated tools—are dangerously outdated. Organizations that treat AI governance as a policy add-on rather than a core risk function are sitting on a liability.
- Coupang fined $409M by South Korea's PIPC for inadequate access controls leading to 33M customer records exposed via a stolen cryptographic signing key.
- US export controls now restrict foreign access to Anthropic's Fable 5 and Mythos 5 after Mythos autonomously completed a 32-step enterprise attack simulation.
- White House NSPM-12 mandates new inventory and compliance timelines for systems handling classified national security information.
Why It Matters
AI governance is now a board-level risk with real penalties—organizations must audit access controls and agentic AI capabilities.