South Korea's AI Basic Act: Effective January 2026
10 min read · updated August 11, 2026
South Korea passed a comprehensive AI statute before almost anyone outside the EU, and it takes effect on a fixed date rather than in phases. Reading it as a smaller AI Act is a mistake: it is a promotion statute and a regulation in one document, and the regulatory half is deliberately thin at the level of the Act itself.
Dates and status
The Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust—usually shortened to the AI Basic Act or AI Framework Act—passed the National Assembly on 26 December 2024 and was promulgated on 21 January 2025, taking effect one year after promulgation, on 22 January 2026. The Ministry of Science and ICT is the competent ministry. The authoritative Korean text and the ministry’s English rendering are available through the Korea Law Information Centre, which is operated by the Ministry of Government Legislation.
The structural point to hold on to is that a Korean framework act is typically paired with a Presidential Enforcement Decree that supplies thresholds, categories and procedures. The Act sets out who owes what in general terms; the decree decides which systems are in scope, what compute threshold triggers the safety duties, and what a compliant notification looks like. A summary of the Act alone is therefore incomplete by construction.
High-impact AI
The Act’s central regulated category is high-impact AI—AI used in areas that may significantly affect human life, physical safety or fundamental rights. Rather than a general risk test, the Act enumerates domains, which in the promulgated text cover areas including energy supply, drinking water, healthcare and medical devices, nuclear facilities, biometric analysis for criminal investigation, decisions on hiring and on loans, transport, education assessment, and decisions in the delivery of public services.
An operator of a high-impact AI system carries obligations that will be familiar from the European instrument, though expressed more briefly: establishing and operating a risk management scheme, providing explanations of the criteria used and an outline of how the system is trained where technically feasible, protecting users, ensuring human oversight, and keeping documentation demonstrating safety and reliability. There is also a duty to check, before deploying, whether the system falls within the high-impact category at all, and operators may seek the ministry’s confirmation on that question.
Two things differ sharply from the EU AI Act’s tiers. There is no prohibited-practices tier in the Korean Act—no equivalent of the European bans on social scoring or on untargeted facial scraping. And there is no third-party conformity assessment or CE-style marking route; the Korean scheme runs on operator duties, ministry supervision and voluntary certification rather than on notified bodies.
Transparency and generative AI
The transparency duties are the provisions most likely to touch a product that is not in a high-impact domain at all, and they are the reason a general-purpose chat or content product cannot ignore the Act.
- Notice that AI is being used. An operator providing a product or service based on AI must notify users in advance that it is AI-based.
- Notice for generative AI output. Where the service is generative, the operator must notify users that the output is generated by AI.
- Marking of synthetic content. Output that is difficult to distinguish from reality—virtual results presented as though real—must be marked in a way users can plainly recognise. The detail of how, and the exceptions, are the subject of the Act’s labelling duty.
There is also a safety-obligation track keyed to training compute: operators training models above a threshold of cumulative computation set by the decree must identify, assess and mitigate risks across the model lifecycle and report to the ministry. That threshold is a decree number, not an Act number, which is precisely why the decree matters more than the statute for working out whether you are caught.
Foreign providers and the domestic representative
The Act applies to acts done abroad that affect the domestic market or users in Korea, so a foreign provider with Korean users is within scope without any Korean establishment. Above thresholds set by the decree— based on user numbers and revenue—a foreign operator without a Korean address must designate a domestic representative, in writing, who performs the operator’s duties in Korea and is the point of contact for the ministry.
This is the same mechanism as the EU’s authorised representative requirement and it creates the same practical problem: the representative must actually be able to produce documentation on request. Appointing one without giving them access to the records is a common and visible failure, and it is the first thing an inspection tests. Compare the AI Act’s authorised representative duty.
Enforcement, and what the decree still decides
The ministry may conduct fact-finding investigations where there is reason to believe the Act has been breached, and may order corrective measures. Administrative fines are available for breaches including failures of the transparency duties and failure to appoint a domestic representative, at a level measured in tens of millions of Korean won per violation—an order of magnitude below the European penalty regime, and consistent with the Act’s framing as a trust-building rather than deterrence instrument. See how the AI Act’s penalties are tiered for the contrast.
Three things were still genuinely open in the run-up to the effective date and should be checked rather than assumed: the final content of the Enforcement Decree, including the compute threshold and the domestic representative thresholds; the ministry’s guidance on what a compliant high-impact risk management scheme looks like in practice; and the enforcement posture in the first year, where Korean regulators have historically favoured guidance and correction over immediate penalties, and where a grace period on fines was under discussion during the consultation on the decree.
None of that changes the date. The Act takes effect on 22 January 2026 whether or not the guidance is complete, and the transparency duties are the ones that bind the widest range of products from day one.