South Korea's AI Basic Act, second comprehensive AI law globally
On 22 January 2026, the Republic of Korea's Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness, commonly known as the AI Basic Act or AI Framework Act, came into effect. South Korea is the second jurisdiction globally (after the EU) to adopt a comprehensive AI regulatory framework, and the first in the Asia-Pacific region. The Act was promulgated on 21 January 2025 (Act No. 20676) and took effect one year later, with the Enforcement Decree (Presidential Decree No. 36053) taking effect on the same day.
South Korea has positioned its approach as balancing industrial promotion with risk-based regulation. The Act consolidates 19 separate AI bills into a unified framework that covers research funding, talent programs, AI safety institute establishment, transparency obligations, and high-impact AI risk management. The drafting reflects deliberate departure from the EU's prohibition-heavy approach, South Korea's government has stated it will "prioritise promotion over regulation," with penalty enforcement delayed by at least one year after the Act's implementation.
Scope and applicability
The AI Basic Act has extraterritorial reach: it applies to both domestic and foreign organisations providing AI systems to Korean users, so a global operator headquartered outside Korea must assess whether its Korean-facing activities bring it within scope. For foreign AI businesses above the thresholds set in the Enforcement Decree (prior-year revenue of at least KRW 1 trillion, prior-year AI service revenue of at least KRW 10 billion, or an average of at least one million daily domestic users over the preceding three months), Article 36 requires designation of a Korean domestic representative to liaise with the government, closing a gap that previously allowed unrelated third parties to be designated as domestic agents in formal compliance arrangements without meaningful accountability. The amendment to the Personal Information Protection Act (PIPA) domestic representative system was promulgated on 1 April 2025 and took effect on 2 October 2025; it requires foreign companies with an established local business unit in South Korea to designate that entity as their domestic representative.
Key obligations under the Act
Transparency and disclosure (Article 31). Article 31 sets three separate duties, and they are often run together. Under Article 31(1), operators providing products or services using generative AI or high-impact AI must notify users in advance that the product or service runs on AI. Under Article 31(2), the output of generative AI must be labelled as generated by generative AI. That is a general duty and it is not conditional on the output being hard to recognise. Article 31(3) adds a heightened duty for virtual sound, images or video that are difficult to distinguish from reality: the fact must be indicated in a way users can clearly recognise. Where the output is or forms part of an artistic or creative work the duty is not waived, but the notice may be given in a manner that does not impair the work exhibition or enjoyment, for instance in a caption or accompanying notice rather than across the work itself. Enforcement Decree Article 23 sets out the methods. For the general duty it allows either a human-readable indication or a machine-readable one, but the machine-readable route still requires the AI-generation fact to be conveyed at least once by on-screen text or audio. For deepfake-grade content the indication must be one users can easily confirm, pitched to the age and circumstances of the main user group. These duties run parallel to the EU AI Act Article 50 transparency obligations on AI-generated content, though the technical implementation requirements differ.
Safety obligations for high-performance AI (Article 32). AI business operators must identify, assess, and mitigate risks, and operate a risk management system covering safety incidents, for AI systems where the cumulative computing used for training exceeds prescribed standards. This is a separate track from the high-impact AI duties, which sit in Articles 33 to 35: confirmation of high-impact status, safety and trustworthiness measures, and impact assessment. A system can fall into both tracks at once. The Enforcement Decree sets the technical threshold: AI systems trained with at least 10²⁶ floating-point operations (FLOPs), incorporating state-of-the-art AI technology, and presenting material risk of significant impact. That figure is ten times higher than the 10²⁵ FLOP level that triggers the EU AI Act's presumption of systemic risk for general-purpose AI models, and it matches the 10²⁶ figure used by US Executive Order 14110, which was revoked on 20 January 2025. South Korea's implementation is less prescriptive than the EU's.
High-impact AI sectoral applications. The high-impact domains are enumerated in Article 2, subparagraph 4 of the Act itself, not left to the Enforcement Decree. Ten are listed: energy supply; the production process for drinking water; the provision of healthcare and the building and operation of healthcare delivery systems; the development and use of medical devices and digital medical devices; the safety management and operation of nuclear materials and nuclear facilities; the analysis and use of biometric information for criminal investigation or arrest; judgements or evaluations that materially affect individual rights and obligations, such as hiring and loan screening; the core operation and management of transport means, facilities and systems; decisions by the State, local governments and public institutions on eligibility for public services and the charges levied for them; and student assessment in early-childhood, primary and secondary education. A further subparagraph lets the Enforcement Decree designate additional domains. Falling within a domain is not enough on its own: the system must also risk a serious effect on human life, physical safety or fundamental rights. Medical devices and digital medical devices sit at Article 2(4)(d), which takes effect on 24 January 2026, two days after the Act's own effective date.
Personal Information Protection Act (PIPA) continues to apply. The PIPC published a policy roadmap outlining specialised oversight provisions for AI development, and its 2026 policy directions shift the regime toward prevention and toward obligations scaled to an organisation's size and risk profile. The PIPC Notice on Personal Information Impact Assessment was amended effective September 2025 to add explicit AI-related subfields for public institutions' privacy impact assessments. The PIPC also published its Guidelines for Personal Data Processing for the Development and Utilization of Generative AI on 6 August 2025, which are non-binding but function as the benchmark in enforcement, and its 2025 work direction included preliminary onsite inspections of AI-powered services including AI agents.
Governance architecture
Two institutions established in 2024 form the backbone of South Korea's AI assurance ecosystem. The National AI Committee, operating under the President's Office, serves as the central coordinating body for national AI policy, implementing the national AI strategy, driving public-private collaboration, harmonising regulatory approaches across ministries, and representing South Korea in international AI governance initiatives. The AI Safety Institute is a dedicated research centre responsible for evaluating advanced AI models, developing safety benchmarks, and addressing deepfake and frontier AI risks. The Ministry of Science and ICT (MSIT) is the primary regulatory ministry, with delegated authority to issue subordinate regulations and guidelines.
Civil society and industry response
The draft Enforcement Decree was open for public comment for 40 days, until 22 December 2025, ahead of the Act's full implementation. Civil society organisations including the Digital Justice Network criticised the regulation as "virtually non-existent," arguing the "high-impact AI" definition is too narrow and that penalty deferment removes immediate compliance pressure. Industry voices pushed back that further regulation would hinder AI competitiveness. The MSIT has taken an iterative approach, considering stakeholder feedback through the decree finalisation process while signalling a regulator's intent to prioritise development.
One contrast with the EU AI Act is notable: South Korea's law does not outright ban categories of AI that the EU prohibits (facial recognition in public spaces, exploitation of vulnerabilities, emotion recognition in workplaces and schools). South Korea's approach is closer to disclosure and risk management requirements rather than prohibition.
Additional regulatory frameworks
Generative AI Service User Protection Guideline (February 2025), adopted on 28 February 2025 by the Korea Communications Commission (KCC), whose functions passed to the Korea Media and Communications Commission (방송미디어통신위원회) in October 2025. It took effect on 28 March 2025 as an expressly non-binding framework aimed at preventing user harm from generative AI services. Its four principles are human dignity and human oversight, transparency, safety and security, and fairness.
AI Security Guide (December 2025), published by MSIT and the Korea Internet & Security Agency (KISA), this provides a framework for securing AI models and services against cyber threats, outlining 113 security requirements across the AI lifecycle. The guide operationalises aspects of the AI Basic Act's risk management obligations.
AI Guidelines for the Financial Sector (June 2026), the Financial Services Commission (FSC) consolidated three earlier AI guidelines into a single set of seven principles: governance, legitimacy, use of AI as an aid subject to human supervision, data and model credibility, financial stability, good faith conduct, and security. Announced on 18 June 2026 and effective from 22 June 2026, they apply to all financial companies including fintech firms. They are self-regulatory rather than legally binding, and the AI Basic Act takes precedence where both apply. The Financial Supervisory Service (FSS) provides the accompanying financial sector AI risk management framework.
February 2025 DeepSeek action, the PIPC temporarily suspended new downloads of the Chinese generative AI application DeepSeek over concerns about potential breaches of PIPA. This signalled the PIPC's willingness to take action against foreign AI services on data protection grounds.
What organisations operating in or supplying South Korea should do
Map AI systems against AI Basic Act applicability. Determine which systems are "high-impact" (sector and risk-based) and which involve generative AI outputs requiring labelling. For non-Korean entities that meet the Enforcement Decree's revenue or user thresholds, designate a qualified Korean domestic representative, and ensure that representative has the authority and resources to engage meaningfully with regulators. Update PIPA compliance documentation to address AI-specific processing under the PIPC's 2025 guidelines. For systems triggering the 10²⁶ FLOPs threshold or close to it, implement risk management documentation aligned with the Act's Article 32 requirements. The Enforcement Decree is now in force, so track MSIT's supplementary guidelines and notifications instead, since that is where the technical detail determining compliance scope continues to be filled in during the grace period, which runs for at least one year from 22 January 2026 with fines deferred except in exceptional cases involving loss of life or serious human rights harm. Consider ISO/IEC 42001 implementation as a defensible international standard that maps to South Korea's emerging requirements. Implement AI Trust Mark certification (the voluntary scheme being developed under the Act) where it provides market differentiation.
Sources: Framework Act on the Development of Artificial Intelligence, official text (Korea Law Information Center) · Library of Congress, South Korea: Comprehensive AI Legal Framework Takes Effect · US International Trade Administration, South Korea AI Basic Act (May 2026) · Future of Privacy Forum, thematic analysis of the AI Framework Act · Financial Services Commission, AI Guidelines for the Financial Sector