Korea’s AI Basic Act: the second horizontal law
Lesson 2 of 5 in Asia-Pacific: Japan, South Korea, Singapore, India, and Australia.
On 26 December 2024, South Korea’s National Assembly passed the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust — universally shortened to the AI Basic Act. Promulgated in January 2025, it took effect on 22 January 2026 after a one-year runway. When it did, Korea became the second jurisdiction on Earth with a comprehensive, horizontal, binding AI statute — and the first to follow the EU AI Act with a genuinely different design.
Korea could move fast for reasons worth noticing: it had hosted the AI Seoul Summit (May 2024), stood up its AI Safety Institute (November 2024, under ETRI), adopted a Digital Bill of Rights (2023), and — crucially — built the Act as industrial policy and regulation in one document. Roughly half the statute is about promoting the AI industry: funding, data centres, talent, standardisation. The regulatory half rides on top. That dual character — risk-based rules plus industrial policy — is the Act’s signature, and the reason both government and industry backed it.
Notice what Korea borrowed and what it changed. Like the EU, the trigger is use in sensitive domains, not the technology itself. Unlike the EU, Korea calls the tier high-impact (고영향) rather than high-risk, keeps the list shorter and more sector-shaped, and — the big architectural difference — skips the prohibited tier entirely. There is no Korean list of banned practices; the statute assumes existing law (privacy, criminal, consumer) handles the intolerable cases.
The obligations on high-impact AI will feel familiar from the EU module, at lower intensity: a risk management plan, explanation of results where feasible, user protection measures, human oversight, and documentation demonstrating safety and reliability — with an impact assessment for fundamental rights encouraged, and required for public-sector procurement. There is no Korean equivalent of the EU’s notified-body conformity assessment; compliance is self-managed, checked by the regulator after the fact.
Two more obligation tracks complete the regulatory half:
Generative AI transparency. Operators must tell users in advance that they are interacting with generative AI, and label AI-generated outputs. Deepfake-style synthetic content that could be mistaken for reality carries a stronger notification duty. Korea thus joined China (September 2025), India (February 2026), and the EU (Article 50, from August 2026) in the global labeling convergence — four regimes, one governance idea.
Safety duties for frontier-scale models. AI systems whose training compute exceeds a threshold set by enforcement decree owe safety obligations: identify, assess, and mitigate risks across the lifecycle, install a risk-management system, and report the results to MSIT. Writing the number into a decree rather than the statute was deliberate — Seoul watched the EU struggle with its hard-coded 10²⁵ FLOPs and kept its trigger adjustable.
Reach and teeth. The Act applies extraterritorially: conduct abroad is covered when it affects the Korean market or Korean users. Foreign providers above decree-set thresholds must appoint a domestic representative — a Korean-resident agent responsible for compliance filings, echoing PIPL and GDPR machinery. Enforcement runs through MSIT: fact-finding investigations, corrective orders, and administrative fines of up to KRW 30 million (roughly USD 21,000).
Read that number again. The EU threatens up to 7% of global turnover; Korea caps fines at the price of a mid-range car. The gap is the point: Korea wants the structure of binding obligations with the posture of industrial promotion. Critics call it a paper tiger; defenders answer that corrective orders, investigation powers, and reputational exposure in a compliance-minded market do the real work — and that the ceiling can rise once the regime beds in.
| Dimension | Korea — AI Basic Act (eff. 22 Jan 2026) | EU — AI Act (in force Aug 2024, phasing) |
|---|---|---|
Character | Half promotion (funding, infrastructure, talent), half regulation | Regulation throughout, built on product-safety law |
Risk architecture | Two regulated categories: high-impact AI + generative AI transparency; no prohibited tier | Four tiers: prohibited / high-risk / transparency / minimal, plus a GPAI chapter |
Frontier-model trigger | Compute threshold set by enforcement decree (adjustable; drafts ~10²⁶ FLOPs) | 10²⁵ FLOPs presumption hard-coded in Art 51 |
Pre-market gate | None — self-managed compliance, ex-post MSIT investigation | Conformity assessment + CE marking before high-risk systems reach the market |
Extraterritoriality | Yes — acts abroad affecting the Korean market; domestic representative required for large foreign providers | Yes — providers abroad covered when outputs are used in the EU; authorised representative required |
Maximum fine | KRW 30 million (~USD 21,000) administrative fine | Up to €35 million or 7% of global turnover for prohibited practices |
Lead institution | MSIT, with the presidential National AI Committee and the AI Safety Institute (ETRI) | National market-surveillance authorities + the European AI Office for GPAI |
Does Korea’s AI Basic Act reach you — and with which duties?
Interactive decision tree — outcomes:
- Outside the Act
No Korean users, no Korean market effect — the Act does not attach. Reassess if you expand: extraterritorial scope follows market impact, not incorporation.
- High-impact AI duties
Risk management plan, explanation of results where feasible, user protection, human oversight, and documentation demonstrating safety and reliability. Public-sector deployments add impact-assessment expectations. MSIT can investigate and order corrections; fines up to KRW 30 million.
- High-impact duties + domestic representative
Everything in the high-impact bundle — plus, above decree-set size thresholds, you must appoint a Korean-resident domestic representative accountable for compliance. Check the final enforcement decree for the thresholds.
- Generative-AI transparency duties
Notify users in advance that they are interacting with generative AI and label generated outputs; deepfake-like content carries stronger notification duties. If your model’s training compute exceeds the decree threshold, frontier safety duties (risk identification, mitigation, reporting to MSIT) stack on top.
- Promotion side only
No high-impact or generative duties attach — you mostly encounter the Act’s promotional half (funding programs, standardisation, sandboxes). General law (PIPA, consumer protection) still applies.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.