South Korea’s AI Basic Act Is Now Live

South Korea’s AI Basic Act entered into force on 22 January 2026, combining industrial promotion with obligations for high-impact and generative AI.

Europe is not the only jurisdiction turning AI principles into law. South Korea’s Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust took effect with its Enforcement Decree on 22 January 2026.

The framework is designed to promote AI investment and adoption while establishing minimum expectations for transparency, safety and responsibility. That combination matters. It is not simply a copy of the EU AI Act, and global AI providers should not assume that one compliance package automatically satisfies both.

Two regulatory categories matter

The Korean framework gives particular attention to generative AI and high-impact AI.

High-impact AI is assessed by looking at the area in which it is used and the potential effect on fundamental rights, safety and significant decisions. Relevant applications may include healthcare, energy, public services, employment, credit, education and other areas specified by the framework.

Generative AI is treated separately because users may be unable to distinguish synthetic outputs from human-created or real material.

An organisation should therefore classify the use case, not only the model. The same foundation model may support a low-impact drafting assistant in one deployment and a high-impact decision process in another.

Users must know when AI is involved

The Enforcement Decree requires operators providing products or services using high-impact or generative AI to inform users in advance that AI is being used. Where generated output is difficult to distinguish from reality, the user must be clearly informed that it was AI-generated.

That obligation reaches the interface and content pipeline. A statement hidden in general terms may not communicate at the point where the user encounters the AI function or synthetic output.

Providers need to decide:

  • when notice appears;
  • whether output needs machine-readable as well as visible provenance;
  • how transformations, screenshots and exports preserve the notice;
  • how third-party models are identified;
  • how accessibility and the user’s age or physical condition affect presentation.

High-impact systems need more than a label

Transparency is only one control. Operators of high-impact AI may need processes addressing risk management, explanation, human oversight, reliability and the protection of users’ rights. The Act also provides a basis for AI impact assessments and voluntary safety and trustworthiness verification or certification.

The Korean government has emphasised avoiding duplication where sector-specific legislation already imposes comparable duties. That reduces unnecessary overlap, but it also requires a clear mapping. “Already regulated” is not useful unless the organisation can show which existing control meets which AI obligation.

Frontier-scale systems face a safety threshold

The subordinate framework specifies safety obligations for systems trained above a stated cumulative-compute threshold. Threshold-based rules will need ongoing monitoring because training approaches, model reuse and distributed development can complicate the calculation.

Providers should retain records of model provenance, training runs, fine-tuning and material modifications. A deployed service may rely on a model built by another company, but the local operator still needs enough information to determine its own role and obligations.

Compare deployments across jurisdictions

An international AI register should record at least:

  1. Provider, deployer and local representative roles.
  2. Models and material versions used.
  3. Deployment purpose and affected population.
  4. High-impact classification by jurisdiction.
  5. Required notices and output disclosures.
  6. Human oversight and appeal routes.
  7. Testing, incident and change-management evidence.
  8. Sector-specific obligations that may satisfy or supplement the framework.

The practical lesson

The EU AI Act popularised risk-based AI regulation, but it is not becoming a single global template. Korea places significant weight on innovation policy while still creating enforceable expectations for trust and safety.

Global providers now need a common technical governance layer with jurisdiction-specific rules on top. The model may be shared. The legal classification, notice, oversight and evidence requirements may not be.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *