AI Policy Wiki
Dashboard

South Korea AI Basic Act (Framework Act on AI Development and Trust, 2024/2026)

high confidence · updated 2026-06-06

South Korea's comprehensive AI framework law — passed December 2024, effective January 2026. The first Asian comprehensive AI statute, with a 'high-impact AI' tier, transparency and watermarking requirements, and extraterritorial reach.

The Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trustworthiness (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법), commonly called the AI Basic Act or AI Framework Act, is South Korea's comprehensive, horizontal AI statute. It was passed by the National Assembly in December 2024, promulgated in January 2025, and entered into force in January 2026. It is the first comprehensive AI statute in Asia and, after the EU AI Act (Regulation 2024/1689), the second such framework law globally. The Act establishes a "high-impact AI" regulatory tier, transparency and watermarking requirements for generative AI, a frontier-model category styled "AI of national significance," and extraterritorial reach over foreign operators serving the Korean market.

Status and timeline

The Act was enacted by the National Assembly of the Republic of Korea (단원제 — unicameral). The lead ministry is the Ministry of Science and ICT (MSIT). The statute establishes a coordinating architecture comprising the National AI Committee, chaired by the President, and the AI Safety Institute (Korea AISI), established within the Electronics and Telecommunications Research Institute (ETRI).

The legislative and implementation sequence ran as follows:

  • 26 December 2024: passed by the National Assembly
  • 21 January 2025: officially promulgated
  • 22 January 2026: entered into force after a one-year transition period
  • 2026–2027: implementation regulations and sectoral guidelines to be published by MSIT, with enforcement ramp-up expected through 2027

Scope and definitions

The Act is a comprehensive, horizontal AI statute, the first in Asia and the second globally after the EU AI Act (Regulation 2024/1689). It covers the development, provision, and use of AI systems in Korea, including high-impact AI and generative AI, and applies to both domestic and foreign AI providers serving the Korean market.

Its reach is extraterritorial: it applies to foreign operators whose AI systems are used or have effects in Korea, mirroring the EU AI Act's market-access basis. Excluded from the statute are AI for national defence and national security, which fall under a separate regime, and AI used solely for research and development.

Key provisions

"High-impact AI" tier

The high-impact AI tier is the statute's central regulatory category. Sectors designated as high-impact include energy; healthcare and medical devices; nuclear safety; biometric information processing; recruitment and employment decisions; credit evaluation and financial services; public services with significant impact on rights; transportation and autonomous driving; and criminal justice, covering assessment, sentencing support, and policing.

Operators of high-impact AI systems must establish a risk management system; conduct impact assessments, including human-rights and safety impact; provide explanation to affected users about the basis for AI-driven decisions; maintain human oversight capable of intervention; and maintain a user-protection programme that responds to complaints.

Generative AI transparency (Art. 31)

Article 31 sets transparency requirements for generative AI. It mandates labelling of generative-AI outputs when they mimic real-world content, covering images, audio, video, and text that could be mistaken for human-produced material. It requires disclosure to users that they are interacting with an AI system, and watermarking or equivalent technical measures for synthetic media.

Frontier tier

The frontier tier, styled "AI of national significance" and analogous to EU GPAI with systemic risk, was added during late-stage amendments. Obligations include reporting to MSIT on training compute, capabilities, and risk assessment; pre-deployment safety evaluation; cooperation with the Korea AI Safety Institute (AISI); and incident reporting. Specific thresholds such as compute FLOP and parameter count were left to implementing regulation.

Foreign operator obligations

Foreign AI providers serving the Korean market at scale must designate a domestic representative, a structural choice mirroring Korea's Personal Information Protection Act (PIPA) and the GDPR.

Governance structure

The Act establishes a layered governance architecture:

  • National AI Committee — chaired by the President; the highest-level coordinating body, which sets the National AI Basic Plan
  • Ministry of Science and ICT (MSIT) — the lead regulator
  • Korea AI Safety Institute (K-AISI) — the operational arm for safety evaluations and part of the international AISI network
  • Sectoral regulators — including the Financial Services Commission and the Ministry of Health, which retain authority within their domains
  • AI Policy Centre — supports implementation and international coordination

Enforcement and penalties

The Act provides for administrative fines up to KRW 30 million per infraction, approximately USD 22,000, a low headline penalty relative to the EU AI Act's percentage-of-turnover design. MSIT may issue corrective orders. The fine structure is per-infraction rather than aggregate, so the effective ceiling is higher for repeat or multi-system violations. The statute itself contains no criminal penalties, unlike Canada's AIDA proposal.

Comparison with other frameworks

DimensionKorea AI Basic Act[[eu-ai-actEU AI Act]]US patchwork[[china-generative-ai-interim-measuresChina CAC framework]]
StatusEffective Jan 2026Phased 2025–2027No federal AI lawIn force
StructureHigh-impact tier + AI of national significanceFour tiers + GPAISectoral + state-levelContent-control + licensing
Generative-AI labellingMandatory (Art. 31)Mandatory (Art. 50)No federal ruleMandatory (Deep Synthesis + Gen AI)
Extraterritorial reachYes (domestic rep required)YesNoPRC-facing services
PenaltiesKRW 30M / infractionUp to €35M / 7% turnoverVariesLicensing revocation + fines
PhilosophyInnovation + trust, balancedFundamental-rights protectiveDeregulatory (federal) / varied (state)Sovereignty + content control

Several features distinguish the Korean statute from the comparators above. Its KRW 30 million per-infraction ceiling is the lowest headline penalty among the major AI statutes, which commentators read as reflecting an intentional pro-innovation framing relative to the EU. The Act embeds K-AISI in statute, unlike the UK and US AI Safety Institutes, which are non-statutory. Korean officials have consistently framed the Act as a "first Asian" regional template, distinct from China's content-control model and Japan's pro-innovation model. The statute delegates much operational detail to MSIT implementing rules, a "statute-light, regulation-heavy" structure that observers compare to the "skeleton statute" critique levelled at Canada's AIDA.

The labelling mandate places Korea alongside the EU and China as jurisdictions requiring synthetic-media labelling, in contrast to the US state-by-state approach: California SB 53 — Transparency in Frontier AI Act does not require labelling, and the federal TAKE IT DOWN Act addresses non-consensual intimate imagery only. As the first Asian comprehensive AI framework law and the second globally after the EU AI Act, the statute reinforces the EU-style risk-tier structure as a widely adopted template, and raises the question of whether other Asian democracies such as Taiwan, Indonesia, and the Philippines will adopt Korea's model or variants. US frontier labs operating in Korea must navigate high-impact classification, generative-AI labelling, and foreign-operator representation from January 2026.

Reactions and debates

Several aspects of the Act remain contested at and after commencement.

On the balance between innovation and rights protection, Korean civil-society groups including the Korea Progressive Network and Open Net argue that the high-impact scope is too narrow and that enforcement fines are too low to constrain large platform operators. Industry counters that stricter rules would damage Korea's AI-exporter ambitions.

The enforcement fine design draws particular criticism: the KRW 30 million per-infraction ceiling is widely viewed as inadequate for systemic actors. Implementing regulations may add a turnover-based uplift, but this remained unresolved at commencement.

The "AI of national significance" threshold, a late-stage amendment, is also unsettled; compute-based versus capability-based thresholds remain contested in the implementing-regulation process. On foreign-operator compliance, the domestic-representative requirement mirrors GDPR and PIPA but is viewed as protectionist by US industry groups, a concern the US government raised in trade dialogue during 2025.

Two further open issues concern institutional capacity and legal overlap. The statute creates K-AISI but provides modest initial funding, leaving its scaling to the envisaged role of pre-deployment evaluation of AI of national significance uncertain. Separately, Korea's existing PIPA already regulates automated decision-making (Art. 37-2, since 2023); because the AI Basic Act does not explicitly preempt PIPA, operators face dual-track compliance.

Relationships

Sources

  • AI Basic Act source summary
  • Future of Privacy Forum, "South Korea's New AI Framework Act" (2025)
  • IAPP, "Analyzing South Korea's Framework Act on the Development of AI"
  • Cloud Security Alliance, "What You Need to Know About South Korea's AI Basic Act" (Mar 2025)
  • US Department of Commerce / trade.gov, "South Korea Artificial Intelligence (AI) Basic Act"
  • Securiti, "An Overview of South Korea's Basic Act on AI"
  • Korean government portal: https://aibasicact.kr/