South Korea took the opposite path to most of Asia: it enacted a comprehensive, binding AI statute. The AI Basic Act took effect on 22 January 2026, making Korea the second jurisdiction after the European Union, and the first in the Asia-Pacific, to regulate AI through a dedicated national law. It imposes duties on high-impact and generative AI, reaches foreign operators whose AI affects Korean users, and is enforced with administrative fines, though a one-year grace period defers fines to around 2027. This page sets out the instruments, the dates, and which ones are binding versus guidance, with links to the primary sources.
Last reviewed: 22 July 2026 · A factual snapshot; AI policy is evolving, so confirm against the primary sources linked below
The centrepiece of South Korean AI governance is the AI Basic Act. Passed by the National Assembly in December 2024 and promulgated in January 2025, it took effect on 22 January 2026 after a one-year transition, and is widely described as the second comprehensive national AI law in the world after the EU AI Act. It sets out core definitions, promotes AI development, and imposes obligations on operators of high-impact AI and providers of generative AI, backed by administrative fines and enforced by the Ministry of Science and ICT (MSIT).
Two features stand out. The Act reaches beyond Korea: it applies to acts done abroad that affect the Korean market or Korean users, and large foreign operators must appoint a domestic representative. And its enforcement is phased: the obligations apply now, but a one-year grace period means fines are effectively not imposed until around January 2027, except in cases of serious harm. Underneath the Act, binding privacy law, the Personal Information Protection Act (PIPA), including automated-decision rights in force since 2024, and financial-sector guidance also apply to AI.
Article 37-2 of the Personal Information Protection Act (PIPA) came into force, giving individuals the right to refuse a fully automated decision that significantly affects their rights or obligations, and the right to request an explanation or review of such a decision. These are binding rights enforced by the Personal Information Protection Commission (PIPC).
The National Assembly passed the AI Basic Act (the Framework Act on the Development of Artificial Intelligence and Establishment of Trust), consolidating multiple earlier bills. The English name varies across translations; the Korean short title is the settled reference.
The Act was promulgated, starting a one-year transition period before it took effect. During 2025 the Ministry of Science and ICT (MSIT) developed the implementing Enforcement Decree and guidelines that give the Act operational detail.
The presidentially-chaired National AI Strategy Committee was relaunched by presidential decree and held its inaugural meeting on 8 September 2025. It drives Korea's "AI G3" ambition of becoming a top-three global AI power and gained a statutory footing when the Act took effect.
The Financial Services Commission (FSC) released a draft integrated set of AI Guidelines for the Financial Sector for public consultation, updating earlier 2021 guidance. The financial-sector guidance is supervisory and voluntary rather than a new binding statute.
The Act came into force together with its Enforcement Decree, making South Korea the second jurisdiction after the EU, and the first in the Asia-Pacific, with a comprehensive binding national AI law. A one-year grace period applies to administrative fines, so fines are effectively not imposed until around January 2027, except in cases of serious harm.
Unlike most of the region, South Korea has a binding AI Act. The table below sorts the main instruments by whether they carry legal force or are supervisory guidance, noting the phased fine timing.
| Instrument | Status | Applies to / owner |
|---|---|---|
| AI Basic Act (high-impact AI + generative-AI duties) | Binding (fines from ~2027) | Operators of high-impact and generative AI, incl. foreign operators reaching Korean users (MSIT) |
| PIPA automated-decision rights (Article 37-2) | Binding | Organisations making fully automated decisions affecting individuals (PIPC) |
| Personal Information Protection Act (PIPA), general | Binding | Any organisation using personal data, including in AI (PIPC) |
| FSC AI Guidelines for the Financial Sector | Supervisory guidance | Financial institutions (Financial Services Commission) |
| National AI Strategy Committee and the AI G3 vision | Governance body and strategy | Whole-of-government direction (chaired by the President) |
For the wider picture across jurisdictions, see our AI regulation by country comparison, and our detailed guides on AI governance in South Korea and the AI Basic Act compliance guide.
South Korea is one of the few places where AI-specific obligations are law rather than only guidance. Any organisation using AI in a high-stakes sector, or offering generative AI to Korean users, should map its systems to the Act now: identify whether any system is high-impact, and put in place the risk management, explainability, human oversight, documentation and labelling the Act expects. Foreign providers should also check the domestic-representative and extraterritorial provisions.
The grace period on fines is time to comply, not a reason to wait, particularly since binding privacy rights under PIPA already apply to automated decisions. Our AI GRC guide covers how those pieces fit together, and a short governance assessment benchmarks where an organisation stands against a structured model.
Yes. The AI Basic Act took effect on 22 January 2026, making South Korea the second jurisdiction after the European Union, and the first in the Asia-Pacific, to have a comprehensive, binding national AI law. It regulates high-impact AI and generative AI and reaches foreign operators whose AI affects Korean users.
The Act is in force, but MSIT applied a one-year grace period on administrative fines, so fines are effectively not imposed until around January 2027, except in cases of serious harm. The substantive obligations, however, apply now, so organisations are expected to be working toward compliance.
High-impact AI is defined by a two-step test: the system must be used in a listed high-stakes sector (such as healthcare, energy, employment, credit and loan assessment, public services or transport) and must be capable of significantly affecting human life, physical safety or fundamental rights. Operators of high-impact AI face duties including risk management, explainability, human oversight and documentation.
Providers must give advance notice that a product or service uses generative or high-impact AI, label AI-generated outputs (including by machine-readable means such as watermarks), and clearly label realistic synthetic content such as deepfakes so that users can recognise it.
Yes, where their AI affects the Korean market or Korean users; the Act applies extraterritorially. Large foreign operators without a place of business in Korea must appoint a domestic representative, subject to statutory thresholds.
The Act provides for administrative fines of up to 30 million Korean won for specified violations, alongside MSIT fact-finding investigations and corrective orders. A one-year grace period applies before fines are imposed, so the practical enforcement date for fines is around January 2027.
A short, free assessment benchmarks where your organisation stands against a structured AI governance model, a practical first step toward the high-impact and transparency duties the AI Basic Act expects.
This page is general information describing the state of South Korea AI policy as at 22 July 2026, not legal or compliance advice. The AI Basic Act is new and its implementing detail is still settling; always confirm the current position against the primary sources linked above and obtain advice from your own qualified counsel before relying on it.