생명보험사 LLM 기반 언더라이팅 AI 도입의 규제 리스크와 거버넌스 프레임워크 : 법령 분석과 규제 위반 시뮬레이션을 중심으로
Regulatory Risks and Governance Framework for LLM-Based Underwriting AI Adoption in Life Insurance : A Legal Analysis and Regulatory Violation Simulation Approach
The Framework Act on AI, effective January 2026, imposes safety, transparency, and explainability obligations on high-impact AI, fundamentally reshaping AI adoption for Korean financial institutions. Life insurance underwriting AI processes large volumes of sensitive data—diagnostic codes, medical histories, and disability records—and thus faces compound regulatory risk under the Framework Act on AI, the Personal Information Protection Act, the Insurance Business Act, and network-separation regulation when calling cloud large language models (LLMs). Using a mixed methodology combining legal analysis and a regulatory-violation simulation on a life-insurance underwriting database (26 tables, 253 columns), this study finds that 11.9% (30) of columns are regulation-relevant sensitive columns exposed to the LLM prompt without a Semantic Layer. While the Semantic Layer reduces exposure to zero, cloud LLMs still fail to satisfy network-separation and Insurance Business Act requirements. We therefore propose a triple architecture—Semantic Layer, on-premise LLM, and prompt logging—and a three-stage governance framework for compliant adoption.
한국어
2026년 1월 시행된 인공지능 발전과 신뢰 기반 조성 등에 관한 기본법(이하 AI 기본법)은 고영향 인공지능(high-impact AI)에 안전성ㆍ투명성ㆍ설명가능성 의무를 부과하여 금융기관의 AI 도입 환경을 근본적으로 변화시켰다. 생명보험 언더라이팅 AI는 진단코드ㆍ병력ㆍ장해 등 민감정보를 대규모로 처리하므로, 클라우드 거대언어모델(large language model, LLM) 호출 시 AI 기본법ㆍ개인정보보호법ㆍ보험업법ㆍ망분리 규제를 동시에 위반할 복합 리스크에 직면한다. 본 연구는 법령 분석과 규제위반 시뮬레이션을 결합한 혼합 방법론으로 이를 실증한다. 생명보험 언더라이팅 데이터베이스(26개 테이블, 253개 컬럼) 분석 결과, 전체 컬럼의 11.9%(30개)가 규제 대상 민감 컬럼이었으며 의미계층(Semantic Layer) 미적용 시 LLM 프롬프트에 그대로 노출되었다. 의미 계층 적용으로 노출을 0개로 줄일 수 있었으나 클라우드 LLM은 망분리 규제와 보험업법 제177조를 완전히 충족하지 못하였다. 이에 본 연구는 의미 계층ㆍ온프레미스 LLMㆍ프롬프트 로깅을 결합한 3중 아키텍처와 이를 구현하는 3단계 거버넌스 프레임워크를 제안한다.
목차
요약 Ⅰ. 서론 Ⅱ. 이론적 배경 2.1 TOE 프레임워크와 AI 도입의 환경 요인 2.2 AI 거버넌스와 고위험 AI 규제 2.3 InsurTech AI와 보험 도메인의 특수성 2.4 NL-to-SQL과 의미 계층 2.5 선행연구의 한계와 본 연구의 위치 Ⅲ. 규제 환경 분석 3.1 AI 기본법: 고영향 AI 안전성ㆍ투명성 의무 3.2 개인정보보호법: 민감정보 처리 제한 3.3 보험업법: 보험 관련 개인정보 이용자의 의무 3.4 망분리 규제: 외부 LLM API 호출 문제 3.5 규제 간 상호작용과 복합 리스크 Ⅳ. 규제 위반 시뮬레이션 실험 4.1 실험 설계 및 방법론 4.2 시뮬레이션 1: 의미 계층 유무에 따른민감정보 노출 측정 4.3 시뮬레이션 2: 운영 방식별 외부망 전송데이터 위험도 비교 4.4 실험 종합: 규제 요건-기술 솔루션 매핑 Ⅴ. 보험사 LLM AI 거버넌스 프레임워크 5.1 프레임워크 설계 원칙 5.2 3단계 거버넌스 프레임워크 5.3 실무 적용 시 고려사항 Ⅵ. 결론 및 정책 시사점 6.1 연구 결과 요약 6.2 이론적 기여 6.3 실무적 및 정책적 시사점 6.4 연구의 한계 및 향후 과제 참고문헌 Abstract