Korea’s AI Basic Act: the second horizontal law

Lesson 2 of 5 in Asia-Pacific: Japan, South Korea, Singapore, India, and Australia.

On 26 December 2024, South Korea’s National Assembly passed the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust — universally shortened to the AI Basic Act. Promulgated in January 2025, it took effect on 22 January 2026 after a one-year runway. When it did, Korea became the second jurisdiction on Earth with a comprehensive, horizontal, binding AI statute — and the first to follow the EU AI Act with a genuinely different design.

Korea could move fast for reasons worth noticing: it had hosted the AI Seoul Summit (May 2024), stood up its AI Safety Institute (November 2024, under ETRI), adopted a Digital Bill of Rights (2023), and — crucially — built the Act as industrial policy and regulation in one document. Roughly half the statute is about promoting the AI industry: funding, data centres, talent, standardisation. The regulatory half rides on top. That dual character — risk-based rules plus industrial policy — is the Act’s signature, and the reason both government and industry backed it.

Notice what Korea borrowed and what it changed. Like the EU, the trigger is use in sensitive domains, not the technology itself. Unlike the EU, Korea calls the tier high-impact (고영향) rather than high-risk, keeps the list shorter and more sector-shaped, and — the big architectural difference — skips the prohibited tier entirely. There is no Korean list of banned practices; the statute assumes existing law (privacy, criminal, consumer) handles the intolerable cases.

The obligations on high-impact AI will feel familiar from the EU module, at lower intensity: a risk management plan, explanation of results where feasible, user protection measures, human oversight, and documentation demonstrating safety and reliability — with an impact assessment for fundamental rights encouraged, and required for public-sector procurement. There is no Korean equivalent of the EU’s notified-body conformity assessment; compliance is self-managed, checked by the regulator after the fact.

Two more obligation tracks complete the regulatory half:

Generative AI transparency. Operators must tell users in advance that they are interacting with generative AI, and label AI-generated outputs. Deepfake-style synthetic content that could be mistaken for reality carries a stronger notification duty. Korea thus joined China (September 2025), India (February 2026), and the EU (Article 50, from August 2026) in the global labeling convergence — four regimes, one governance idea.

Safety duties for frontier-scale models. AI systems whose training compute exceeds a threshold set by enforcement decree owe safety obligations: identify, assess, and mitigate risks across the lifecycle, install a risk-management system, and report the results to MSIT. Writing the number into a decree rather than the statute was deliberate — Seoul watched the EU struggle with its hard-coded 10²⁵ FLOPs and kept its trigger adjustable.

Reach and teeth. The Act applies extraterritorially: conduct abroad is covered when it affects the Korean market or Korean users. Foreign providers above decree-set thresholds must appoint a domestic representative — a Korean-resident agent responsible for compliance filings, echoing PIPL and GDPR machinery. Enforcement runs through MSIT: fact-finding investigations, corrective orders, and administrative fines of up to KRW 30 million (roughly USD 21,000).

Read that number again. The EU threatens up to 7% of global turnover; Korea caps fines at the price of a mid-range car. The gap is the point: Korea wants the structure of binding obligations with the posture of industrial promotion. Critics call it a paper tiger; defenders answer that corrective orders, investigation powers, and reputational exposure in a compliance-minded market do the real work — and that the ceiling can rise once the regime beds in.

Korea’s AI Basic Act vs the EU AI Act (as of September 2026)
DimensionKorea — AI Basic Act (eff. 22 Jan 2026)EU — AI Act (in force Aug 2024, phasing)

Character

Half promotion (funding, infrastructure, talent), half regulation

Regulation throughout, built on product-safety law

Risk architecture

Two regulated categories: high-impact AI + generative AI transparency; no prohibited tier

Four tiers: prohibited / high-risk / transparency / minimal, plus a GPAI chapter

Frontier-model trigger

Compute threshold set by enforcement decree (adjustable; drafts ~10²⁶ FLOPs)

10²⁵ FLOPs presumption hard-coded in Art 51

Pre-market gate

None — self-managed compliance, ex-post MSIT investigation

Conformity assessment + CE marking before high-risk systems reach the market

Extraterritoriality

Yes — acts abroad affecting the Korean market; domestic representative required for large foreign providers

Yes — providers abroad covered when outputs are used in the EU; authorised representative required

Maximum fine

KRW 30 million (~USD 21,000) administrative fine

Up to €35 million or 7% of global turnover for prohibited practices

Lead institution

MSIT, with the presidential National AI Committee and the AI Safety Institute (ETRI)

National market-surveillance authorities + the European AI Office for GPAI

Does Korea’s AI Basic Act reach you — and with which duties?

Interactive decision tree — outcomes:

  • Outside the Act

    No Korean users, no Korean market effect — the Act does not attach. Reassess if you expand: extraterritorial scope follows market impact, not incorporation.

  • High-impact AI duties

    Risk management plan, explanation of results where feasible, user protection, human oversight, and documentation demonstrating safety and reliability. Public-sector deployments add impact-assessment expectations. MSIT can investigate and order corrections; fines up to KRW 30 million.

  • High-impact duties + domestic representative

    Everything in the high-impact bundle — plus, above decree-set size thresholds, you must appoint a Korean-resident domestic representative accountable for compliance. Check the final enforcement decree for the thresholds.

  • Generative-AI transparency duties

    Notify users in advance that they are interacting with generative AI and label generated outputs; deepfake-like content carries stronger notification duties. If your model’s training compute exceeds the decree threshold, frontier safety duties (risk identification, mitigation, reporting to MSIT) stack on top.

  • Promotion side only

    No high-impact or generative duties attach — you mostly encounter the Act’s promotional half (funding programs, standardisation, sandboxes). General law (PIPA, consumer protection) still applies.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.