LIVE
EU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series EEU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series EEU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series E

South Korea AI Basic Act

In Force
high risk
South Korea

Ministry of Science and ICT (MSIT). National AI Committee (established under the Act) for policy coordination. Sector regulators for domain-specific obligations.

January 2026 (enacted January 2024; 2-year transition period)

Official Text

Status

In Force

Risk Level

High

Jurisdiction

South Korea

Enforcement

January 2026 (enacted January 2024; 2-year transition period)

high risk framework

Organizations developing, deploying, or distributing AI systems in South Korea — including foreign companies whose AI affects Korean individuals.

Overview

South Korea's Framework Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act) was enacted in January 2024 and enters into force in January 2026. It is the first comprehensive AI law in East Asia (outside China) and takes a risk-based approach distinguishing high-impact AI requiring transparency and conformity assessment from general AI. Enforced by the Ministry of Science and ICT (MSIT).

Scope

Organizations developing, deploying, or distributing AI systems in South Korea. High-impact AI systems — defined as AI in areas including public order, education, employment, healthcare, financial services, transportation — face the most stringent requirements.

Applicability

Who Is Affected

  • Korean companies developing or deploying high-impact AI in regulated sectors
  • Foreign companies whose AI systems affect persons in South Korea
  • Public sector bodies deploying AI for administrative decisions
  • Companies in healthcare, finance, education, transportation, and employment using AI

Who Is Exempt

  • AI used solely for research and development (not yet deployed publicly)
  • AI in national security or defence applications (separate national security rules)
  • General-purpose AI with minimal risk designation

Key Prohibitions

  • AI systems designed to systematically impair human dignity or fundamental rights
  • AI manipulating individuals through subliminal techniques beyond their awareness
  • AI that produces discriminatory outcomes contrary to constitutional equality principles
  • AI in public safety applications without regulatory approval

Risk Tier Classification

High-Impact AI

high

AI in critical domains — healthcare, finance, employment, education, transportation, public order — facing enhanced transparency, conformity assessment, and human oversight requirements.

Examples

  • AI-assisted medical diagnosis and treatment recommendations
  • AI credit scoring and financial decision-making
  • AI hiring and employee evaluation systems
  • AI in autonomous vehicles and transportation management
  • AI for student assessment and educational outcomes

Requirements

  • Conformity assessment before deployment
  • Transparency disclosure to affected individuals
  • Human oversight and override mechanisms
  • Technical documentation and record-keeping
  • Post-deployment monitoring and incident reporting

General AI

minimal

All other AI systems — subject to baseline reliability, safety, and transparency principles with no mandatory conformity assessment.

Examples

  • Recommendation engines
  • Content creation tools
  • Customer service chatbots
  • Productivity AI tools

Requirements

  • Voluntary codes of practice encouraged
  • Basic transparency if AI interaction is non-obvious to users

Key Requirements

  • Classification of AI systems as 'high-impact' or general — high-impact systems face enhanced requirements
  • Transparency obligations: high-impact AI operators must disclose AI decision-making to affected individuals
  • Conformity assessment: high-impact AI must undergo testing and verification before deployment
  • Human oversight: high-impact AI must support human intervention and override capability
  • Reliability and safety: AI systems must be technically reliable, secure, and accurate
  • Record-keeping: operators must maintain documentation of high-impact AI systems
  • Prohibited AI: AI designed to impair human rights or disrupt social order is prohibited
  • Government AI governance: national AI strategy, National AI Committee, and annual AI status reports

Guardrails & Operational Controls

  • Human oversight: high-impact AI must provide human intervention and override capability
  • Transparency: individuals must be informed when high-impact AI is used in decisions affecting them
  • Reliability: AI must perform at the accuracy level specified in technical documentation
  • Privacy: AI systems must comply with Korea's Personal Information Protection Act (PIPA)
  • Non-discrimination: AI outcomes must not discriminate on protected characteristics

Technical Requirements

  • Technical documentation for high-impact AI: architecture, training methodology, intended use cases
  • Conformity assessment records for high-impact AI before public deployment
  • Audit logs for high-impact AI decisions: timestamps, key decision factors, data processed
  • Human oversight mechanism: clear pathway for human intervention in AI decisions
  • Incident reporting procedure for AI system failures with significant impact

Compliance Roadmap

  1. 1STEP 1 - AI Inventory: Identify all AI systems operating in South Korea or affecting Korean individuals
  2. 2STEP 2 - High-Impact Classification: Assess each system against the high-impact sector criteria
  3. 3STEP 3 - Technical Documentation: Prepare documentation for high-impact AI per MSIT guidance
  4. 4STEP 4 - Conformity Assessment: Engage accredited assessment body for high-impact AI systems
  5. 5STEP 5 - Transparency Mechanisms: Implement disclosure notices for individuals affected by high-impact AI
  6. 6STEP 6 - Human Oversight: Define and implement override capability for high-impact AI decisions
  7. 7STEP 7 - PIPA Alignment: Ensure AI data processing complies with Korea's Personal Information Protection Act
  8. 8STEP 8 - Incident Management: Establish reporting procedures for AI safety incidents
  9. 9STEP 9 - Monitor MSIT guidance: Subordinate regulations and implementation guidelines expected 2024–2025

Implementation Guidance

  1. 1Monitor MSIT for subordinate regulations and sector-specific implementation guidelines (expected 2024–2025)
  2. 2Classify AI systems operating in Korea against high-impact sector criteria
  3. 3Align with Korea's PIPA (Personal Information Protection Act) for AI data processing compliance
  4. 4Engage Korean legal counsel familiar with MSIT and sector regulator AI guidance
  5. 5Reference EU AI Act compliance preparations — Korea's Act is structurally similar

Industry Impact

Healthcare

Korea's advanced digital health ecosystem means many clinical AI systems will be high-impact. MFDS (medical device) + MSIT (AI Act) dual oversight.

critical

Financial Services

Korea's major banks, fintechs, and securities firms using AI in decisions must comply. FSC/FSS coordination with MSIT expected.

high

Technology / AI

Korea's leading AI companies (Kakao, Naver, Samsung, LG) must classify their consumer AI products under the Act.

high

Automotive

Korea's automotive sector (Hyundai, Kia) developing autonomous driving AI faces high-impact requirements under transportation category.

high

Education / EdTech

Korea's tech-forward education system has widespread AI adoption in assessment — transparency obligations will require significant adaptation.

high

Regulatory Timeline

PastCurrentUpcoming

Jan 2024

AI Basic Act enacted by National Assembly — signed into law

2024

Presidential Commission on AI Safety established per Act mandate

2024–2025

MSIT developing subordinate regulations and implementation guidelines

Jan 2026

AI Basic Act enters into force — compliance obligations begin

2026–2027

First conformity assessments and enforcement actions anticipated

Penalties for Non-Compliance

Subordinate regulations to specify penalty structure — anticipated to include fines and deployment suspension orders for non-compliant high-impact AI. Administrative penalties expected in the range of KRW 100M–300M ($75k–$225k USD) per violation.

Framework Details

Short Name

Korea AI Act

Jurisdiction

South Korea

Enforcement Date

January 2026 (enacted January 2024; 2-year transition period)

Enforcing Authority

Ministry of Science and ICT (MSIT). National AI Committee (established under the Act) for policy coordination. Sector regulators for domain-specific obligations.

Status

In Force

Risk Level

high

Affected Organizations

Organizations developing, deploying, or distributing AI systems in South Korea — including foreign companies whose AI affects Korean individuals.

Exposure Areas

  • Healthcare AI: diagnostic and clinical decision support systems classified as high-impact
  • Financial AI: credit scoring, fraud detection, robo-advisors all high-impact under financial sector rules
  • Employment AI: AI used in hiring, performance evaluation, or workforce management is high-impact
  • Autonomous vehicles: Level 3+ autonomous driving systems face high-impact requirements
  • EdTech: AI grading and student assessment systems face transparency and fairness obligations

Tags

South KoreaEast AsiaRegulationEnterpriseRisk-Based

This is educational guidance only. Always consult qualified legal counsel for compliance decisions affecting your organization.