South Korea Framework Act on AI Development and Trust (AI Basic Act): AI Compliance Requirements
South Korea's AI Basic Act (Framework Act on AI Development and Trust; passed by the National Assembly December 26, 2024; promulgated January 21, 2025; effective with its Enforcement Decree January 22, 2026) establishes governance for "high-impact" AI in critical sectors (healthcare, education, employment, public safety, finance, transportation) and for generative AI. Operators of high-impact AI must establish and operate risk-management plans and safety/transparency measures (Arts. 31, 32, 34); a high-impact impact assessment (Art. 35) is encouraged, not mandatory, and there is NO mandatory registration of high-impact AI with any government body. Generative AI outputs must be labelled as AI-generated and users notified that AI is in use (Art. 31). Foreign operators above user/revenue thresholds set by the Enforcement Decree must designate a domestic representative (Art. 36). MSIT has announced a one-year grace period — no administrative fines until on/around January 22, 2027 — to let businesses prepare.
Summary of publicly-available regulatory text as of 2026-08-23. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
January 22, 2026
Administrative fines up to KRW 30,000,000 (approx. $21,000 USD) under Art. 43 — for failing to notify users that AI is in use, failing to designate a required domestic representative, or failing to comply with corrective orders / refusing inspection. Specific fine tiers are set by the Enforcement Decree; fines may be reduced up to 50% for SMEs, venture companies, and small businesses. The Act relies on administrative fines (no criminal sanctions). MSIT has announced a ONE-YEAR GRACE PERIOD: no administrative fines imposed until on/around January 22, 2027.
What Your Business Must Do
5 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
High-Impact AI Risk Management & Safety Duties
CriticalIf you deploy "high-impact AI" in critical sectors (healthcare, employment/HR decisions, education, public safety, financial services, transportation), establish and operate a risk-management plan and safety/reliability measures, and keep documentation of how risks are identified and mitigated. There is NO mandatory registration of high-impact AI with KAISI or MSIT; an operator MAY voluntarily request MSIT confirmation of whether its system is high-impact (Art. 33), and a separate impact assessment (Art. 35) is encouraged but not mandatory.
Deadline: January 22, 2026
AI Basic Act Arts. 32, 34 (risk management); Art. 33 (voluntary confirmation); Art. 35 (encouraged impact assessment)Generative AI Output Labeling
High PriorityWhen providing products or services that generate AI-produced content (text, images, audio, video) to Korean users, notify users in advance that AI is in use and label the output as AI-generated; for synthetic media that is difficult to distinguish from reality, display the AI-generated fact so users can clearly recognise it (Art. 31(1)-(3)). This applies to chatbots, content creation tools, and any product built on GPAI models.
Deadline: January 22, 2026
AI Basic Act Art. 31Domestic Representative Designation (threshold-based)
Medium PriorityForeign operators without an address or business office in Korea must designate a domestic representative ONLY if they exceed the Enforcement Decree thresholds: prior-year total revenue ≥ KRW 1 trillion, OR prior-year AI-service revenue ≥ KRW 10 billion, OR an average of ≥ 1,000,000 daily Korean users over the preceding three months. The representative liaises with MSIT and handles safety reports, and its contact information must be disclosed. Below these thresholds, no domestic representative is required.
Deadline: January 22, 2026
AI Basic Act Art. 36AI Ethics Principles
Medium PriorityAlign your AI governance with the AI ethics principles that MSIT establishes and publicly announces under the Act (covering safety, reliability, transparency, accountability, and human oversight). These are soft-law / ethics-oriented measures rather than a fixed statutory list of seven principles.
High-Impact AI Ongoing Monitoring & Findings
Medium PriorityFor high-impact AI, operate ongoing monitoring as part of your risk-management plan, retain documentation, and where required submit findings to MSIT (Art. 32). NOTE: the AI Basic Act does NOT impose a fixed-deadline incident-reporting duty — there is no statutory 24-hour MSIT reporting obligation. Maintain internal incident logs and corrective-action records as good practice and to evidence your risk-management plan.
Who Does This Apply To?
Applies to any organization developing or deploying "high-impact AI" (고영향 인공지능) in Korea. High-impact AI is defined by sector: healthcare/medical, education, employment/HR decisions, financial services/credit, transportation safety, public safety/policing/justice, and social welfare. Also applies to providers of generative AI services to Korean users — regardless of company location. Foreign operators WITHOUT a Korean address or business office must designate a domestic representative ONLY if they exceed thresholds set by the Enforcement Decree: prior-year total revenue ≥ KRW 1 trillion, OR prior-year AI-service revenue ≥ KRW 10 billion, OR an average of ≥ 1,000,000 daily Korean users over the preceding three months. Smaller foreign operators are NOT required to designate a representative.
Recent Regulatory Guidance
AI Basic Act Enforcement Decree enacted; MSIT announces one-year grace period
The Enforcement Decree (Presidential Decree) for the AI Basic Act was enacted by the Korean Cabinet on January 21, 2026 and took effect with the Act on January 22, 2026. It sets the domestic-representative thresholds (prior-year total revenue ≥ KRW 1 trillion / prior-year AI-service revenue ≥ KRW 10 billion / ≥ 1,000,000 average daily Korean users over the preceding three months). MSIT has stated it will grant a one-year grace period before imposing administrative fines, to allow businesses to prepare; generative-AI transparency/labelling duties (Art. 31) apply from the effective date. (Verified 2026-06-14 against Cooley, FPF, Securiti and Library of Congress reporting; the previously listed "MSIT Implementation Guide" (which claimed a KAISI online registration system and a 60-day representative window) could not be verified and was removed as unsourced.)
SourceKey Case Law & Precedent
PIPC ruling against Kakao Corp. — KakaoTalk open-chat data leak (2024)
Personal Information Protection Commission (PIPC), Republic of Korea · 2024On 23 May 2024 the PIPC ruled that Kakao Corp. violated the Personal Information Protection Act after attackers exploited a KakaoTalk open-chat vulnerability to harvest and sell participants' personal information, and Kakao failed to report the leak and notify users. This is a data-security and breach-notification matter (PIPA security-safeguard and notification duties), not an algorithmic / automated-decision case — included as the most significant recent PIPC enforcement bearing on platforms with Korean users.
Outcome: IMPOSED: a KRW 15.1 billion fine plus a KRW 7.8 million penalty surcharge, with corrective orders and public disclosure of the result (PIPC, 23 May 2024).
Case referencePIPC ruling against ScatterLab, Inc. — "Iruda" AI chatbot training-data consent (2021)
Personal Information Protection Commission (PIPC), Republic of Korea · 2021The FIRST case where Korea's PIPA was applied to an AI system at all. PIPC found ScatterLab violated PIPA by using ~9.4 billion KakaoTalk messages from 600,000 users to train its "Iruda" AI chatbot without valid consent, failed to delete/encrypt personal information, posted AI training artifacts on GitHub containing identifiable user messages, and collected data from 200,000+ children under 14 without parental consent. This is the foundational Korean precedent for AI training-data consent requirements — directly on point for the AI Basic Act's audience.
Outcome: IMPOSED: a KRW 103,300,000 (~$92,900 USD) fine, corrective orders; ScatterLab agreed to implement PIPC's corrective actions (PIPC, 28 April 2021).
Case referencePIPC ruling against Kakao Pay Corp. + Apple Distribution International — AI model destruction order (2025)
Personal Information Protection Commission (PIPC), Republic of Korea · 2025Kakao Pay transferred Korean users' personal data to Alipay (an Alibaba affiliate) without proper consent to calculate "NSF" risk scores as part of Apple Pay's payment-evaluation process, affecting ~40 million users. PIPC's most significant remedy was not the fine but an order to DESTROY the AI model built from the unlawfully transferred data — a directly on-point precedent that an AI model itself can be ordered destroyed as a PIPA remedy, not merely penalized with a fine.
Outcome: IMPOSED: KRW 8,370,000,000 total (~$5.7-5.8M USD; Kakao Pay KRW 5.968B, Apple Distribution International KRW 2.45B + KRW 2.2M) PLUS an order to destroy the AI model (PIPC, 24 January 2025).
Case referenceQuarterly Enforcement Digest
Q1 2026: AI Basic Act and its Enforcement Decree took effect January 22, 2026. Immediate obligation: generative-AI transparency/labelling (Art. 31) — chatbots, image and voice generators must notify users that AI is in use and label AI-generated output to Korean users. High-impact AI operators must run risk-management plans (Arts. 32, 34); there is NO mandatory registration with KAISI or MSIT (an operator may voluntarily request high-impact confirmation under Art. 33). Foreign operators above the Enforcement-Decree thresholds (KRW 1 trillion total revenue / KRW 10 billion AI-service revenue / 1,000,000 average daily Korean users) must designate a domestic representative (Art. 36). MSIT has announced a one-year grace period — no administrative fines until on/around January 22, 2027 — and is in an education/outreach phase; no enforcement actions yet. CYCLE 10 (2026-08-22): re-verified the Kakao PIPC fine figures fresh (Korea Times, dataguidance.com, CyberInsider) — KRW 15.1 billion + KRW 7.8 million surcharge, 2024-05-23, 65,000 affected users — exact match, no fabrication found.
Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-23.
Industry Playbooks covering South Korea Framework Act on AI Development and Trust (AI Basic Act)
These industry playbooks include jurisdiction-specific checklist items and guidance for South Korea Framework Act on AI Development and Trust (AI Basic Act).
Frequently Asked Questions
Does South Korea Framework Act on AI Development and Trust (AI Basic Act) apply to my business?
South Korea's AI Basic Act (Framework Act on AI Development and Trust; passed by the National Assembly December 26, 2024; promulgated January 21, 2025; effective with its Enforcement Decree January 22, 2026) establishes governance for "high-impact"… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under South Korea Framework Act on AI Development and Trust (AI Basic Act) is: Administrative fines up to KRW 30,000,000 (approx. $21,000 USD) under Art. 43 — for failing to notify users that AI is in use, failing to designate a required domestic representative, or failing to comply with corrective orders / refusing inspection. Specific fine tiers are set by the Enforcement Decree; fines may be reduced up to 50% for SMEs, venture companies, and small businesses. The Act relies on administrative fines (no criminal sanctions). MSIT has announced a ONE-YEAR GRACE PERIOD: no administrative fines imposed until on/around January 22, 2027.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with South Korea Framework Act on AI Development and Trust (AI Basic Act)?
The 5 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://www.msit.go.kr/eng/bbs/view.do?sCode=eng&mId=4&mPid=2&nttSeqNo=1071Last updated: 2026-08-23 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan