policy paper United States effective 8/10
Government · U.S. Department of State, Bureau of Cyberspace and Digital Policy

This international alert, issued by multiple governments including the U.S. State Department and FBI, warns global entities about North Korean IT workers who use advanced methods, including AI, to disguise their identities and secure remote work. Their earnings are then remitted to fund North Korea’s illegal nuclear weapons and ballistic missile programs. These workers also pose an insider threat, engaging in data exfiltration and cryptocurrency theft. The alert reiterates that contracting with and paying these workers may violate domestic laws and UN Security Council Resolution 2397, which requires repatriation of such individuals.

Effective date

2026-07-31

Action required

Companies and countries should implement enhanced due diligence and verification processes for remote IT workers to identify and prevent contracting with North Korean IT workers, ensuring compliance with UN sanctions and domestic laws.

Binding status

advisory

Governing body

U.S. Department of State, Bureau of Cyberspace and Digital Policy

Direction

restrictive

Innovation impact

constraining

Compliance requirements

Prohibited practices

  • Contracting with North Korean IT workers
  • Paying North Korean IT workers for services rendered

AI technologies

generative aiai agents

Affected industries

technologyfinancial servicesgovernmentdefenseall

Affected roles

cisoctogeneral counselcompliance officerceoboard directorrisk managerhr director

Cross-references

Cites laws

UN Security Council Resolution 2397

"North Korean IT workers employ increasingly sophisticated methods, including the integration of AI, to obfuscate their identities and expand their activities globally."

Enriched 2026-08-01

Stay informed

Get daily intelligence briefs on this and related regulatory developments.

Start 14-day trial