Japan, South Korea And Australia: Three Different Routes
Japan's FSA has asked banks to start post-quantum work now, South Korea leads on AI law, and Australia has the earliest government cryptography date of the three. How the three compare, as of October 2026.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Japan, South Korea and Australia are often grouped together as advanced Asia Pacific economies, but on cryptography and AI they have taken quite different paths. Japan’s financial regulator has moved from a study report to a direct request that banks start post-quantum work now. South Korea has put a horizontal AI law into force but has no verified national post-quantum deadline. Australia’s signals directorate has the earliest government date of the three for retiring today’s public-key cryptography.
This article compares the three as of October 2026, labelling each instrument by its legal weight. It is general information, not legal advice. The regional overview shows where they sit among other jurisdictions.
Japan: From Study To Supervisory Request
Japan’s Financial Services Agency (FSA) has built its position in steps.
Cybersecurity Guidelines for the Financial Sector (Supervisory, 4 October 2024). Among the baseline items, section 2.3.3 covers the choice of encryption method and the lifecycle management of keys and certificates, pointing institutions to the CRYPTREC list, Japan’s government-recommended list of ciphers.1
Study group report on post-quantum cryptography (Guidance, 26 November 2024). An FSA study group on deposit-taking institutions recommended a stocktake of where and which algorithms are used, and said high-priority systems should be able to use post-quantum algorithms by around the mid-2030s, while watching technical progress and overseas rules.2
Request to start now (Supervisory, published 24 June 2025). In notes from a meeting with new-type banks (banks without traditional branch networks), the FSA said institutions should start immediately on a roadmap with their IT vendors, build an inventory listing which cryptography each information asset uses, and assess the risk, including harvest now, decrypt later. It added that banks should not wait for an industry roadmap template.3 The FSA follows this up through its monitoring.
Government systems (Draft). A Cabinet Secretariat interim summary dated November 2025, marked as a draft, says government agencies should in principle migrate to post-quantum cryptography by around 2035, with a roadmap to be drawn up in fiscal year 2026.4 The FSA’s 2026 Strategic Priorities of 15 September 2026 commit it to promoting a smooth transition in the financial sector (Guidance).5
South Korea: AI Law First
South Korea’s Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation of Trust (Act No. 20676) was promulgated on 21 January 2025 and took effect on 22 January 2026 (Binding).6 It makes South Korea one of the few jurisdictions with a horizontal AI statute in force. Japan’s AI Promotion Act, fully in force since 1 September 2025, is a promotion law with no penalty provisions.7 AI regulation at a glance compares both laws with others.
On post-quantum cryptography, the picture is thinner. The Ministry of Science and ICT and the Korea Internet and Security Agency (KISA) supported pilot use of post-quantum cryptography in energy, health care and public administration in 2025, and in January 2026 announced 2026 pilot conversion projects in telecommunications, finance, transport, defence and space (Announcement).8 Reports of a national master plan with a 2035 target could not be traced to a primary government document for this article, so no Korean post-quantum date is given here.
Australia: The Earliest Government Date
ASD guidance (Guidance). The Australian Signals Directorate’s publication “Planning for post-quantum cryptography”, last reviewed on 22 September 2025, explains that ASD’s Information Security Manual (ISM) advises organisations to stop using traditional asymmetric cryptography, including RSA, Diffie-Hellman, ECDH and ECDSA, by the end of 2030.9 The ISM’s cryptography guidelines, in their September 2026 edition, back this up: controls ISM-0472, ISM-0474, ISM-0475 and ISM-0476 stop approving those algorithms after 2030.10 ASD also sets two interim steps, a refined transition plan by the end of 2026 and a transition under way by the end of 2028.9 That is earlier than the 2035 end dates that the UK, EU and US set for completing migration, although the EU and US also target 2030 for their highest-priority systems.
APRA (Guidance and Binding). The Australian Prudential Regulation Authority’s guide CPG 234 (June 2019) expects algorithms from well-established international standards, key lengths sized against current computing power, and managed key lifecycles. It does not mention quantum computing.11 APRA’s binding information security standard, CPS 234, has applied since 1 July 2019 and requires controls that protect information assets in proportion to the threats they face, without naming particular algorithms.12 CPS 230 on operational risk management, also a binding prudential standard, commenced on 1 July 2025; targeted amendments finalised on 30 April 2026 took effect on 1 July 2026.13 No APRA quantum statement was found.
Cyber Security Act 2024 (Binding). Assented on 29 November 2024, it introduced, among other measures, mandatory reporting of ransomware payments.14 It does not set cryptography requirements.
| Country | Post-quantum cryptography | Cyber and operational resilience | AI |
|---|---|---|---|
| Japan | Supervisory: FSA request to start inventory and roadmap now; mid-2030s guidance for high-priority bank systems; around 2035 for government (draft) | Supervisory: FSA cybersecurity guidelines, with keys and certificates under CRYPTREC | Binding but non-punitive: AI Promotion Act in force from 1 September 2025 |
| South Korea | Announcement: ministry and KISA pilots, extended to finance in 2026; no verified national deadline | Not covered in this article | Binding: AI Framework Act in force from 22 January 2026 |
| Australia | Guidance: ASD recommends ending traditional asymmetric cryptography by end 2030 | Binding: APRA CPS 234 and CPS 230 (since 1 July 2025); Cyber Security Act 2024 | No AI statute verified for this article; see the AI comparison |
Deadlines To Watch
- In effect
Australia · Australian Prudential Regulation Authority Binding
Operational risk management and business continuity standard commences.
- In effect
South Korea · National Assembly of Korea Binding
The AI Framework Act takes effect.
- Upcoming
Australia · Australian Signals Directorate Guidance
Stop using traditional asymmetric cryptography such as RSA, Diffie-Hellman, ECDH and ECDSA.
What This Means In Practice
The three countries agree on one thing even though their instruments differ: the first task is to know where cryptography is used. Japan’s FSA has asked for that inventory directly, and both the ASD and APRA expectations assume it, because algorithms cannot be retired or keys resized without it. Cryptography Compliance covers how such an inventory is built, and AI Governance And Regulation covers the AI frameworks in depth.
Footnotes
-
Financial Services Agency of Japan, “Cybersecurity Guidelines for the Financial Sector”, 4 October 2024. fsa.go.jp ↩
-
Financial Services Agency of Japan, report of the study group on deposit-taking institutions’ response to post-quantum cryptography, 26 November 2024, pages 9, 42 and 48. fsa.go.jp ↩
-
Financial Services Agency of Japan, notes from its meeting with new-type banks, section 6 on post-quantum cryptography migration, published 24 June 2025. fsa.go.jp ↩
-
Cabinet Secretariat of Japan, interim summary (draft) on migration of government agencies to post-quantum cryptography, November 2025. cas.go.jp ↩
-
Financial Services Agency of Japan, “2026 Strategic Priorities”, 15 September 2026. fsa.go.jp ↩
-
Korea Ministry of Government Legislation, Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation of Trust, Act No. 20676, promulgated 21 January 2025. law.go.kr ↩
-
Korea Internet and Security Agency, notice on the briefing for the 2025 post-quantum cryptography pilot support programme (in Korean), 8 January 2025 (kisa.or.kr); and notice on the briefing for the 2026 post-quantum cryptography pilot conversion projects (in Korean), 14 January 2026. kisa.or.kr ↩
-
Australian Signals Directorate, “Planning for post-quantum cryptography”, last reviewed 22 September 2025. cyber.gov.au ↩ ↩2
-
Australian Signals Directorate, “Information Security Manual: Guidelines for cryptography”, September 2026. cyber.gov.au ↩ ↩2
-
Australian Prudential Regulation Authority, “Prudential Practice Guide CPG 234 Information Security”, June 2019, Attachment E. apra.gov.au ↩
-
Australian Prudential Regulation Authority, “Prudential Standard CPS 234 Information Security”, July 2019. apra.gov.au ↩
-
Australian Prudential Regulation Authority, “Operational risk management” (CPS 230). apra.gov.au ↩
-
Federal Register of Legislation, “Cyber Security Act 2024” (C2024A00098). legislation.gov.au ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.