South Korea's Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust, commonly called the AI Basic Act, was passed by the National Assembly on 26 December 2024, promulgated on 21 January 2025 as Act No. 20676, and entered into force on 22 January 2026. It is in application now. For operators with a Korean presence or user base, the Act creates a compliance layer that shares substantive logic with the EU regime but differs in structure, enforcement and terminology. This guide sets out what matters for cross-border deployers.

Key takeaways

  • The Korea AI Basic Act, Act No. 20676, was passed on 26 December 2024, promulgated on 21 January 2025 and has been in force since 22 January 2026. It is administered by MSIT (Ministry of Science and ICT). Its Enforcement Decree took effect on the same date.
  • High-impact AI systems in sensitive domains face transparency, human oversight, and documentation obligations closely parallel to the EU AI Act's Annex III regime.
  • Korea's regime has no prohibited AI list equivalent to EU AI Act Article 5, but imposes prohibited conduct provisions through general fairness and non-discrimination obligations.
  • Cross-border operators with EU programmes will find substantial overlap. The single most operationally significant incremental duty is Article 36: a foreign operator above the thresholds set by Presidential Decree must designate a domestic representative in Korea. Failure to do so is one of only three fineable breaches in the Act.

Background and context

Korea has a long record of technology legislation. The Personal Information Protection Act (PIPA), first enacted in 2011 and substantially revised in 2023, is among the most mature data protection statutes in the Asia-Pacific region. The Act on Promotion of Information and Communications Network Utilisation and Information Protection (the Network Act) has governed platform conduct for two decades. These instruments created a regulatory culture accustomed to detailed statutory obligations on technology operators, administered through specialist agencies with real enforcement capacity.

The AI Basic Act sits within this tradition. It was prepared through a multi-year National Assembly deliberation process that accelerated through 2023 and 2024, drawing on OECD AI Principles, the EU AI Act's architecture, and domestic consultation with industry and civil society. The National Assembly passed the Act in December 2024. The Ministry of Science and ICT (MSIT), which also administers the Network Act and broader ICT sector regulation, is the primary administrative body. The Enforcement Decree went to legislative notice from 12 November to 22 December 2025 and took effect with the Act on 22 January 2026. Among other things it sets a 10 to the 26 FLOPs training-compute threshold for the Act's safety obligations.

The Act has applied since 22 January 2026. Korea therefore arrived nearly two years ahead of the EU on high-impact obligations, since the Digital Omnibus moved the EU's Annex III date to 2 December 2027. An operator that sequenced Korea behind the EU on the assumption of a common window has that backwards.

Structure of the Act

The AI Basic Act follows a risk-tiered structure that should be legible to operators familiar with the EU AI Act, even though the Korean statutory text uses different terminology and a somewhat different analytical frame.

At the base layer, the Act establishes general AI governance principles applicable to all providers and deployers of AI systems used in Korea. These include accuracy and reliability obligations, a general duty of transparency to users of AI systems, a fairness and non-discrimination principle, and an accountability obligation requiring operators to designate responsibility for AI-related decisions. These principles operate as a floor; they apply to ordinary AI systems that do not meet the high-impact threshold.

The Act's most operationally significant tier covers high-impact AI systems, defined by domain rather than by technical characteristics. High-impact designation triggers a substantively heavier set of obligations: the five duties in Article 34: a risk management plan, a plan for explaining the criteria and the outline of the training data used, a user protection plan, human management and supervision of the system, and documentation with retention. Article 35 adds an impact assessment on fundamental rights. There is no incident notification duty in the Act, and this guide previously said there was.

At the strictest tier sits government-managed AI: AI systems operated by or on behalf of public authorities in consequential administrative decisions. The Act imposes additional procedural requirements on this category, including enhanced documentation, mandatory review mechanisms, and rights of contestation for affected individuals. This tier has no direct private-sector equivalent, though operators providing AI systems to Korean public authorities should treat it as bearing on their contractual and technical obligations.

The Act does not include a list of prohibited AI systems comparable to EU AI Act Article 5. Instead, prohibited conduct is addressed through the general fairness and non-discrimination obligations, through PIPA's existing rules on automated individual decision-making, and through the criminal and civil liability framework that applies across Korean law. Operators who have designed systems around EU Act Article 5 requirements will not find a direct Korean equivalent but should note that the underlying prohibited conduct (mass surveillance, social scoring, subliminal manipulation, exploitation of vulnerability) would likely engage the general fairness and non-discrimination duties at minimum.

High-impact AI: the designated domains

Article 2(4) designates high-impact AI by reference to eleven categories, listed at points (a) through (k) of the Korean text. An earlier version of this guide gave seven domains and included legal services. That was wrong: legal services is not among them, and energy supply, drinking water production, nuclear material and facility safety, and public-body decisions on eligibility for public services were missing. The corrected list, read at law.go.kr, is: energy supply; drinking water production; healthcare provision systems; medical devices and digital medical devices; nuclear material and facility safety; biometric analysis for criminal investigation or arrest; judgments or evaluations materially affecting individual rights, such as hiring and loan screening; transport means, facilities and systems; public-body decisions on eligibility for or cost collection of public services; student assessment in early childhood, primary and secondary education; and other areas set by Presidential Decree. The list is worth comparing to EU AI Act Annex III, because the overlap is real but partial.

Medical devices and clinical diagnosis is the first domain. AI systems used in diagnosis, prognosis, or treatment recommendation, and AI embedded in regulated medical devices, are high-impact under the Korean Act. This maps directly to Annex III, item 5(a), which covers AI systems used as medical devices or safety components of medical devices. The practical compliance obligation is similar: documentation of clinical validation, human oversight in the diagnostic workflow, and incident reporting for adverse outcomes.

Employment decisions is the second domain. AI systems used in recruitment, selection, performance evaluation, termination, or promotion decisions involving workers are high-impact. This is the closest parallel to Annex III item 4, covering AI for employment and worker management. EEOC guidance in the United States and ICO guidance in the United Kingdom address the same domain through different instruments. Operators running hiring automation across multiple jurisdictions will recognise the pattern.

Educational assessment is the third domain. AI systems used to assess student performance, determine placement, or make decisions affecting educational advancement are high-impact. This maps to Annex III item 3 (AI in education and vocational training). Korea's rapidly digitised education sector makes this a practically significant category.

Financial creditworthiness is the fourth domain. AI systems used in credit scoring, loan decisions, insurance underwriting, and related financial determinations are high-impact. The EU AI Act equivalent is Annex III item 5(b) (AI in natural person creditworthiness assessment). Korea's Financial Services Commission (FSC) also maintains sectoral rules for AI in financial services that operate alongside the AI Basic Act framework, creating a layered obligation structure for financial sector operators.

Criminal justice and public safety is the fifth domain. AI systems used in policing, predictive risk assessment, or public safety operations fall in this category. The EU AI Act equivalent is Annex III items 6 and 7, covering law enforcement and justice administration. Given that the Korean Act does not separately regulate law enforcement AI through an equivalent to the EU Act's biometric surveillance provisions, this category in Korea is broader in its practical application than the equivalent EU category.

Critical infrastructure is the sixth domain. AI systems used in the operation of energy, transport, water, communications, and financial market infrastructure are high-impact. This maps to Annex III item 2. The MSIT designation process for critical infrastructure AI is expected to align with Korea's existing Critical Information Infrastructure Protection Act frameworks, which already impose layered security and resilience obligations.

Four categories in the Korean list have no close Annex III analogue and are easy to miss from a European starting point: drinking water production, nuclear material and facility safety, transport means and facilities, and public-body decisions on eligibility for or cost collection of public services. An operator that classified only against Annex III will under-count in Korea. Legal services, which an earlier version of this guide listed as a seventh Korean domain, is not in the Act at all.

Article 2(4)(k) reserves the power to add further areas to Presidential Decree, not to an MSIT ministerial regulation. An earlier version of this guide attributed that power to MSIT alone. Operators should monitor Presidential Decree amendments on the same cadence as they monitor the European AI Office's Annex III update process.

Transparency and human oversight obligations

The Act imposes transparency obligations at two levels, following the structure used in the EU AI Act's Articles 13 and 50.

For all AI systems interacting with users, operators are required to disclose that the user is interacting with an AI system where this would not otherwise be apparent. The disclosure must be clear and accessible, using plain language. This maps directly to EU AI Act Article 50(1), which requires disclosure for AI systems intended to interact with natural persons. Article 31 leaves the method of disclosure and its exceptions to Presidential Decree. An earlier version of this guide asserted a statutory duty to make the disclosure in Korean. That duty is not in Article 31 and the claim has been removed.

For high-impact AI systems, the transparency obligation is substantively heavier. The Act requires operators to provide affected persons with information about: the fact that an AI system was used in a decision affecting them; the basis of the decision at a level sufficient for the affected person to understand and contest it; and the identity of the responsible operator or responsible person within the operator organisation. This maps to EU AI Act Article 26(6) (information to affected workers) and to Article 86 of the GDPR as applied to automated decision-making, though Korea's provision is Act-specific rather than an extension of its PIPA framework.

Human oversight obligations for high-impact AI require operators to designate a named individual or role responsible for monitoring and intervening in the AI system's operation. The designated person must have the technical access and organisational authority needed to intervene. Documentation of the oversight designation is required and must be retained for audit. The structure is closely parallel to EU AI Act Article 26(1)(d), which requires deployers to assign human oversight to natural persons with the necessary competence, training, and authority. Korea's implementing regulations are expected to specify retention periods and documentation standards; until they are published, operators should apply the EU Act standard as a safe proxy.

There is no incident reporting duty in the AI Basic Act. An earlier version of this guide described a notification obligation to MSIT and a statutory definition of "serious incident". Neither exists in the Act, and both have been removed. An operator running a cross-border programme will still want an incident process, because the EU AI Act Article 73 duty and Korea's PIPA breach rules can both bite on the same event, but it should not be built against a Korean provision that is not there.

The MSIT enforcement framework

The Ministry of Science and ICT is the primary enforcement authority for the AI Basic Act. Unlike the EU, which established a dedicated European AI Office and a coordinated system of national supervisors, Korea routes AI Act enforcement through MSIT's existing ICT regulatory infrastructure. This has practical implications for operators. MSIT has decades of enforcement experience in the ICT sector, including under the Network Act and the PIPA framework (the latter jointly administered with the Personal Information Protection Commission, PIPC). Enforcement culture is systematic and documentation-oriented.

There is no registry and no registration duty. The word does not appear in the Act. An earlier version of this guide described an MSIT registry, a registration number and periodic compliance reports; none of that exists and it has been removed. What the Act does impose on a foreign operator is Article 36: above thresholds set by Presidential Decree, designate a domestic representative in Korea. That is the practical entry requirement, and failing it is one of only three fineable breaches.

Penalties do not operate on a graduated scale. Article 43 sets one maximum, KRW 30 million, and attaches it to exactly three failures: failure to give the Article 31(1) prior notice; failure to designate a domestic representative under Article 36(1); and failure to comply with a suspension or corrective order under Article 40(3). An earlier version of this guide described a higher tier for oversight and incident-reporting failures. There is no such tier. MSIT does hold the Article 40 power to issue corrective and suspension orders, and ignoring one is the third fineable breach. MSIT can also refer serious cases to the PIPC where a breach also involves personal data processing, creating a dual-enforcement scenario comparable to the coordination between national AI supervisors and data protection authorities in EU Member States.

Extraterritorial reach follows the pattern of Korea's existing technology legislation. The Act applies to AI systems used in Korea regardless of where the provider or deployer is established. An operator based in Germany whose AI system is deployed to Korean users falls within the regime for those users. This is the same extraterritorial logic as the EU AI Act and the Colorado AI Act. The practical implication is that operators who have already confronted the EU Act's extraterritorial scope question have answered the same question for Korea: the analysis is the same; only the specific operator duties differ by regime.

Practical implications for cross-border operators

For operators who have built a compliance programme to meet the EU AI Act's Article 26 deployer obligations, the Korea AI Basic Act creates incremental rather than parallel obligations. The underlying analytical work, system classification, risk documentation, oversight assignment, and incident protocol, transfers substantially. What Korea adds is primarily a set of Korean-language and MSIT-specific requirements layered on top.

System classification is the first task. Operators should map their deployed AI systems against the eleven Article 2(4) categories, not against Annex III. The lists overlap but are not congruent, and four Korean categories have no close Annex III analogue: drinking water production, nuclear safety, transport means and facilities, and public-body eligibility decisions. A system already classified as Annex III high-risk is likely to be high-impact in Korea. The reverse does not hold.

Documentation must be adapted to Korean requirements. The operator file maintained for EU purposes requires supplementary entries covering: the identity and contact details of the Article 36 domestic representative, the Article 34 risk management plan, explanation plan and user protection plan, the Article 35 impact assessment, and evidence of the Article 31 prior notice actually given. There is no registration number and no MSIT incident log, and an earlier version of this guide asked for both. The underlying risk management record, system description, and monitoring plan can be shared documents with Korean addenda rather than parallel documents.

For operators without an existing EU programme, the rational approach is to design a single programme to the higher of the two standards, treating the EU Act's Article 26 requirements as the procedural baseline and adding Korean-specific elements. An operator that can evidence the five shared obligations (risk management, transparency, human oversight, documentation, incident response) is in a defensible position in both regimes. See also the EU AI Act operator obligations guide at agentliability.eu for the detailed EU framework. For the broader Asia-Pacific context in which Korea's Act sits, see Asia-Pacific AI governance in 2026. For the transatlantic comparison, see US, EU, UK: three approaches to the same question.

Certification and assurance may support compliance positioning. The Agent Certified methodology applies across jurisdictions and provides a structured evidence framework for documenting compliance across the five shared obligations. A certified operator has produced the documentation that both MSIT and an EU national supervisor would expect to review.

Five shared obligations. Both the EU AI Act and the Korea AI Basic Act require: risk management, transparency to users, human oversight, documentation, and incident response. An operator with a well-built EU programme requires targeted adaptation for Korea, not a parallel programme.

Related reading

For the detailed EU deployer framework, see EU AI Act operator obligations 2026 at agentliability.eu. For the Asia-Pacific context, see Asia-Pacific AI governance in 2026. For the three-jurisdiction comparison, see US, EU, UK: three approaches to the same question.

Frequently asked questions

What is the Korea AI Basic Act and when does it apply?

The Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (the AI Basic Act, Act No. 20676) was passed by the National Assembly on 26 December 2024, promulgated on 21 January 2025, and entered into force on 22 January 2026. It is administered by the Ministry of Science and ICT (MSIT). It is in application now.

What is a high-impact AI system under the Korea AI Basic Act?

Article 2(4) lists eleven categories: energy supply; drinking water production; healthcare provision systems; medical devices and digital medical devices; nuclear material and facility safety; biometric analysis for criminal investigation or arrest; judgments or evaluations materially affecting individual rights, such as hiring and loan screening; transport means, facilities and systems; public-body decisions on eligibility for or cost collection of public services; student assessment in early childhood, primary and secondary education; and other areas set by Presidential Decree. High-impact designation triggers the Article 34 duties.

How does the Korea AI Basic Act compare to the EU AI Act?

The two regimes share the same structural logic: a risk-tiered approach with heightened obligations for high-impact uses, transparency duties for most systems, and human oversight requirements. Korea's regime is narrower in procedural detail than the EU Act but covers the same substantive ground. The key practical difference for cross-border operators is that Korea does not yet have a dedicated AI supervisory authority comparable to the European AI Office; the MSIT administers the regime through existing ICT enforcement infrastructure.

Does the Korea AI Basic Act have a list of prohibited AI systems?

No. Unlike EU AI Act Article 5, the Korean Act does not enumerate a list of prohibited AI systems. Prohibited conduct is addressed through the general fairness and non-discrimination obligations, through PIPA's automated decision-making provisions, and through the general civil and criminal liability framework. Operators designing systems around the EU prohibited uses list will not find a direct Korean parallel but should treat the general fairness duties as covering substantially the same ground.

Who enforces the Korea AI Basic Act and what are the penalties?

MSIT is the enforcement authority. Article 43 sets a single maximum administrative fine of KRW 30 million, attaching to exactly three failures: failure to give the prior notice required by Article 31(1); failure to designate a domestic representative under Article 36(1); and failure to comply with a suspension or corrective order under Article 40(3). There is no higher tier, no oversight fine and no incident-reporting fine in the Act.

References

  1. Republic of Korea, Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (AI Basic Act, in Korean: 인공지능 발전과 신뢰 기반 조성 등에 관한 기본법), Act No. 20676. Passed 26 December 2024, promulgated 21 January 2025, in force 22 January 2026. Text read at law.go.kr on 17 August 2026.
  2. Ministry of Science and ICT (MSIT), Korea, guidelines on the implementation of the AI Basic Act, 2025.
  3. Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), Annex III high-impact AI systems, for comparison.
  4. OECD, AI Principles (2024 revision), as a reference standard shared across the two regimes.
  5. Korea Personal Information Protection Commission, enforcement data on technology sector compliance, 2024.