South Korea AI Basic Act
Ministry of Science and ICT (MSIT). National AI Committee (established under the Act) for policy coordination. Sector regulators for domain-specific obligations.
January 2026 (enacted January 2024; 2-year transition period)
Status
In Force
Risk Level
High
Jurisdiction
South Korea
Enforcement
January 2026 (enacted January 2024; 2-year transition period)
high risk framework
Organizations developing, deploying, or distributing AI systems in South Korea — including foreign companies whose AI affects Korean individuals.
Overview
South Korea's Framework Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act) was enacted in January 2024 and enters into force in January 2026. It is the first comprehensive AI law in East Asia (outside China) and takes a risk-based approach distinguishing high-impact AI requiring transparency and conformity assessment from general AI. Enforced by the Ministry of Science and ICT (MSIT).
Scope
Organizations developing, deploying, or distributing AI systems in South Korea. High-impact AI systems — defined as AI in areas including public order, education, employment, healthcare, financial services, transportation — face the most stringent requirements.
Applicability
Who Is Affected
- Korean companies developing or deploying high-impact AI in regulated sectors
- Foreign companies whose AI systems affect persons in South Korea
- Public sector bodies deploying AI for administrative decisions
- Companies in healthcare, finance, education, transportation, and employment using AI
Who Is Exempt
- AI used solely for research and development (not yet deployed publicly)
- AI in national security or defence applications (separate national security rules)
- General-purpose AI with minimal risk designation
Key Prohibitions
- AI systems designed to systematically impair human dignity or fundamental rights
- AI manipulating individuals through subliminal techniques beyond their awareness
- AI that produces discriminatory outcomes contrary to constitutional equality principles
- AI in public safety applications without regulatory approval
Risk Tier Classification
High-Impact AI
highAI in critical domains — healthcare, finance, employment, education, transportation, public order — facing enhanced transparency, conformity assessment, and human oversight requirements.
Examples
- • AI-assisted medical diagnosis and treatment recommendations
- • AI credit scoring and financial decision-making
- • AI hiring and employee evaluation systems
- • AI in autonomous vehicles and transportation management
- • AI for student assessment and educational outcomes
Requirements
- ✓ Conformity assessment before deployment
- ✓ Transparency disclosure to affected individuals
- ✓ Human oversight and override mechanisms
- ✓ Technical documentation and record-keeping
- ✓ Post-deployment monitoring and incident reporting
General AI
minimalAll other AI systems — subject to baseline reliability, safety, and transparency principles with no mandatory conformity assessment.
Examples
- • Recommendation engines
- • Content creation tools
- • Customer service chatbots
- • Productivity AI tools
Requirements
- ✓ Voluntary codes of practice encouraged
- ✓ Basic transparency if AI interaction is non-obvious to users
Key Requirements
- Classification of AI systems as 'high-impact' or general — high-impact systems face enhanced requirements
- Transparency obligations: high-impact AI operators must disclose AI decision-making to affected individuals
- Conformity assessment: high-impact AI must undergo testing and verification before deployment
- Human oversight: high-impact AI must support human intervention and override capability
- Reliability and safety: AI systems must be technically reliable, secure, and accurate
- Record-keeping: operators must maintain documentation of high-impact AI systems
- Prohibited AI: AI designed to impair human rights or disrupt social order is prohibited
- Government AI governance: national AI strategy, National AI Committee, and annual AI status reports
Guardrails & Operational Controls
- Human oversight: high-impact AI must provide human intervention and override capability
- Transparency: individuals must be informed when high-impact AI is used in decisions affecting them
- Reliability: AI must perform at the accuracy level specified in technical documentation
- Privacy: AI systems must comply with Korea's Personal Information Protection Act (PIPA)
- Non-discrimination: AI outcomes must not discriminate on protected characteristics
Technical Requirements
- Technical documentation for high-impact AI: architecture, training methodology, intended use cases
- Conformity assessment records for high-impact AI before public deployment
- Audit logs for high-impact AI decisions: timestamps, key decision factors, data processed
- Human oversight mechanism: clear pathway for human intervention in AI decisions
- Incident reporting procedure for AI system failures with significant impact
Compliance Roadmap
- 1STEP 1 - AI Inventory: Identify all AI systems operating in South Korea or affecting Korean individuals
- 2STEP 2 - High-Impact Classification: Assess each system against the high-impact sector criteria
- 3STEP 3 - Technical Documentation: Prepare documentation for high-impact AI per MSIT guidance
- 4STEP 4 - Conformity Assessment: Engage accredited assessment body for high-impact AI systems
- 5STEP 5 - Transparency Mechanisms: Implement disclosure notices for individuals affected by high-impact AI
- 6STEP 6 - Human Oversight: Define and implement override capability for high-impact AI decisions
- 7STEP 7 - PIPA Alignment: Ensure AI data processing complies with Korea's Personal Information Protection Act
- 8STEP 8 - Incident Management: Establish reporting procedures for AI safety incidents
- 9STEP 9 - Monitor MSIT guidance: Subordinate regulations and implementation guidelines expected 2024–2025
Implementation Guidance
- 1Monitor MSIT for subordinate regulations and sector-specific implementation guidelines (expected 2024–2025)
- 2Classify AI systems operating in Korea against high-impact sector criteria
- 3Align with Korea's PIPA (Personal Information Protection Act) for AI data processing compliance
- 4Engage Korean legal counsel familiar with MSIT and sector regulator AI guidance
- 5Reference EU AI Act compliance preparations — Korea's Act is structurally similar
Industry Impact
Healthcare
Korea's advanced digital health ecosystem means many clinical AI systems will be high-impact. MFDS (medical device) + MSIT (AI Act) dual oversight.
Financial Services
Korea's major banks, fintechs, and securities firms using AI in decisions must comply. FSC/FSS coordination with MSIT expected.
Technology / AI
Korea's leading AI companies (Kakao, Naver, Samsung, LG) must classify their consumer AI products under the Act.
Automotive
Korea's automotive sector (Hyundai, Kia) developing autonomous driving AI faces high-impact requirements under transportation category.
Education / EdTech
Korea's tech-forward education system has widespread AI adoption in assessment — transparency obligations will require significant adaptation.
Regulatory Timeline
Jan 2024
AI Basic Act enacted by National Assembly — signed into law
2024
Presidential Commission on AI Safety established per Act mandate
2024–2025
MSIT developing subordinate regulations and implementation guidelines
Jan 2026
AI Basic Act enters into force — compliance obligations begin
2026–2027
First conformity assessments and enforcement actions anticipated
Penalties for Non-Compliance
Subordinate regulations to specify penalty structure — anticipated to include fines and deployment suspension orders for non-compliant high-impact AI. Administrative penalties expected in the range of KRW 100M–300M ($75k–$225k USD) per violation.
Framework Details
Short Name
Korea AI Act
Jurisdiction
South Korea
Enforcement Date
January 2026 (enacted January 2024; 2-year transition period)
Enforcing Authority
Ministry of Science and ICT (MSIT). National AI Committee (established under the Act) for policy coordination. Sector regulators for domain-specific obligations.
Status
Risk Level
Affected Organizations
Organizations developing, deploying, or distributing AI systems in South Korea — including foreign companies whose AI affects Korean individuals.
Exposure Areas
- Healthcare AI: diagnostic and clinical decision support systems classified as high-impact
- Financial AI: credit scoring, fraud detection, robo-advisors all high-impact under financial sector rules
- Employment AI: AI used in hiring, performance evaluation, or workforce management is high-impact
- Autonomous vehicles: Level 3+ autonomous driving systems face high-impact requirements
- EdTech: AI grading and student assessment systems face transparency and fairness obligations
Tags
This is educational guidance only. Always consult qualified legal counsel for compliance decisions affecting your organization.