Skip to content
KRDEEP coverage

South Korea Framework Act on AI Development and Trust (AI Basic Act): AI Compliance Requirements

South Korea's AI Basic Act (Framework Act on AI Development and Trust; passed by the National Assembly December 26, 2024; promulgated January 21, 2025; effective with its Enforcement Decree January 22, 2026) establishes governance for "high-impact" AI in critical sectors (healthcare, education, employment, public safety, finance, transportation) and for generative AI. Operators of high-impact AI must establish and operate risk-management plans and safety/transparency measures (Arts. 31, 32, 34); a high-impact impact assessment (Art. 35) is encouraged, not mandatory, and there is NO mandatory registration of high-impact AI with any government body. Generative AI outputs must be labelled as AI-generated and users notified that AI is in use (Art. 31). Foreign operators above user/revenue thresholds set by the Enforcement Decree must designate a domestic representative (Art. 36). MSIT has announced a one-year grace period — no administrative fines until on/around January 22, 2027 — to let businesses prepare.

Summary of publicly-available regulatory text as of 2026-08-23. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 22, 2026

Maximum Penalty

Administrative fines up to KRW 30,000,000 (approx. $21,000 USD) under Art. 43 — for failing to notify users that AI is in use, failing to designate a required domestic representative, or failing to comply with corrective orders / refusing inspection. Specific fine tiers are set by the Enforcement Decree; fines may be reduced up to 50% for SMEs, venture companies, and small businesses. The Act relies on administrative fines (no criminal sanctions). MSIT has announced a ONE-YEAR GRACE PERIOD: no administrative fines imposed until on/around January 22, 2027.

What Your Business Must Do

5 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

High-Impact AI Risk Management & Safety Duties

Critical

If you deploy "high-impact AI" in critical sectors (healthcare, employment/HR decisions, education, public safety, financial services, transportation), establish and operate a risk-management plan and safety/reliability measures, and keep documentation of how risks are identified and mitigated. There is NO mandatory registration of high-impact AI with KAISI or MSIT; an operator MAY voluntarily request MSIT confirmation of whether its system is high-impact (Art. 33), and a separate impact assessment (Art. 35) is encouraged but not mandatory.

Deadline: January 22, 2026

AI Basic Act Arts. 32, 34 (risk management); Art. 33 (voluntary confirmation); Art. 35 (encouraged impact assessment)

Generative AI Output Labeling

High Priority

When providing products or services that generate AI-produced content (text, images, audio, video) to Korean users, notify users in advance that AI is in use and label the output as AI-generated; for synthetic media that is difficult to distinguish from reality, display the AI-generated fact so users can clearly recognise it (Art. 31(1)-(3)). This applies to chatbots, content creation tools, and any product built on GPAI models.

Deadline: January 22, 2026

AI Basic Act Art. 31

Domestic Representative Designation (threshold-based)

Medium Priority

Foreign operators without an address or business office in Korea must designate a domestic representative ONLY if they exceed the Enforcement Decree thresholds: prior-year total revenue ≥ KRW 1 trillion, OR prior-year AI-service revenue ≥ KRW 10 billion, OR an average of ≥ 1,000,000 daily Korean users over the preceding three months. The representative liaises with MSIT and handles safety reports, and its contact information must be disclosed. Below these thresholds, no domestic representative is required.

Deadline: January 22, 2026

AI Basic Act Art. 36

AI Ethics Principles

Medium Priority

Align your AI governance with the AI ethics principles that MSIT establishes and publicly announces under the Act (covering safety, reliability, transparency, accountability, and human oversight). These are soft-law / ethics-oriented measures rather than a fixed statutory list of seven principles.

AI Basic Act Art. 27

High-Impact AI Ongoing Monitoring & Findings

Medium Priority

For high-impact AI, operate ongoing monitoring as part of your risk-management plan, retain documentation, and where required submit findings to MSIT (Art. 32). NOTE: the AI Basic Act does NOT impose a fixed-deadline incident-reporting duty — there is no statutory 24-hour MSIT reporting obligation. Maintain internal incident logs and corrective-action records as good practice and to evidence your risk-management plan.

AI Basic Act Arts. 32, 34

Who Does This Apply To?

Applies to any organization developing or deploying "high-impact AI" (고영향 인공지능) in Korea. High-impact AI is defined by sector: healthcare/medical, education, employment/HR decisions, financial services/credit, transportation safety, public safety/policing/justice, and social welfare. Also applies to providers of generative AI services to Korean users — regardless of company location. Foreign operators WITHOUT a Korean address or business office must designate a domestic representative ONLY if they exceed thresholds set by the Enforcement Decree: prior-year total revenue ≥ KRW 1 trillion, OR prior-year AI-service revenue ≥ KRW 10 billion, OR an average of ≥ 1,000,000 daily Korean users over the preceding three months. Smaller foreign operators are NOT required to designate a representative.

Recent Regulatory Guidance

guidance2026-01-21

AI Basic Act Enforcement Decree enacted; MSIT announces one-year grace period

The Enforcement Decree (Presidential Decree) for the AI Basic Act was enacted by the Korean Cabinet on January 21, 2026 and took effect with the Act on January 22, 2026. It sets the domestic-representative thresholds (prior-year total revenue ≥ KRW 1 trillion / prior-year AI-service revenue ≥ KRW 10 billion / ≥ 1,000,000 average daily Korean users over the preceding three months). MSIT has stated it will grant a one-year grace period before imposing administrative fines, to allow businesses to prepare; generative-AI transparency/labelling duties (Art. 31) apply from the effective date. (Verified 2026-06-14 against Cooley, FPF, Securiti and Library of Congress reporting; the previously listed "MSIT Implementation Guide" (which claimed a KAISI online registration system and a 60-day representative window) could not be verified and was removed as unsourced.)

Source

Key Case Law & Precedent

PIPC ruling against Kakao Corp. — KakaoTalk open-chat data leak (2024)

Personal Information Protection Commission (PIPC), Republic of Korea · 2024

On 23 May 2024 the PIPC ruled that Kakao Corp. violated the Personal Information Protection Act after attackers exploited a KakaoTalk open-chat vulnerability to harvest and sell participants' personal information, and Kakao failed to report the leak and notify users. This is a data-security and breach-notification matter (PIPA security-safeguard and notification duties), not an algorithmic / automated-decision case — included as the most significant recent PIPC enforcement bearing on platforms with Korean users.

Outcome: IMPOSED: a KRW 15.1 billion fine plus a KRW 7.8 million penalty surcharge, with corrective orders and public disclosure of the result (PIPC, 23 May 2024).

Case reference

PIPC ruling against ScatterLab, Inc. — "Iruda" AI chatbot training-data consent (2021)

Personal Information Protection Commission (PIPC), Republic of Korea · 2021

The FIRST case where Korea's PIPA was applied to an AI system at all. PIPC found ScatterLab violated PIPA by using ~9.4 billion KakaoTalk messages from 600,000 users to train its "Iruda" AI chatbot without valid consent, failed to delete/encrypt personal information, posted AI training artifacts on GitHub containing identifiable user messages, and collected data from 200,000+ children under 14 without parental consent. This is the foundational Korean precedent for AI training-data consent requirements — directly on point for the AI Basic Act's audience.

Outcome: IMPOSED: a KRW 103,300,000 (~$92,900 USD) fine, corrective orders; ScatterLab agreed to implement PIPC's corrective actions (PIPC, 28 April 2021).

Case reference

PIPC ruling against Kakao Pay Corp. + Apple Distribution International — AI model destruction order (2025)

Personal Information Protection Commission (PIPC), Republic of Korea · 2025

Kakao Pay transferred Korean users' personal data to Alipay (an Alibaba affiliate) without proper consent to calculate "NSF" risk scores as part of Apple Pay's payment-evaluation process, affecting ~40 million users. PIPC's most significant remedy was not the fine but an order to DESTROY the AI model built from the unlawfully transferred data — a directly on-point precedent that an AI model itself can be ordered destroyed as a PIPA remedy, not merely penalized with a fine.

Outcome: IMPOSED: KRW 8,370,000,000 total (~$5.7-5.8M USD; Kakao Pay KRW 5.968B, Apple Distribution International KRW 2.45B + KRW 2.2M) PLUS an order to destroy the AI model (PIPC, 24 January 2025).

Case reference

Quarterly Enforcement Digest

Q1 2026: AI Basic Act and its Enforcement Decree took effect January 22, 2026. Immediate obligation: generative-AI transparency/labelling (Art. 31) — chatbots, image and voice generators must notify users that AI is in use and label AI-generated output to Korean users. High-impact AI operators must run risk-management plans (Arts. 32, 34); there is NO mandatory registration with KAISI or MSIT (an operator may voluntarily request high-impact confirmation under Art. 33). Foreign operators above the Enforcement-Decree thresholds (KRW 1 trillion total revenue / KRW 10 billion AI-service revenue / 1,000,000 average daily Korean users) must designate a domestic representative (Art. 36). MSIT has announced a one-year grace period — no administrative fines until on/around January 22, 2027 — and is in an education/outreach phase; no enforcement actions yet. CYCLE 10 (2026-08-22): re-verified the Kakao PIPC fine figures fresh (Korea Times, dataguidance.com, CyberInsider) — KRW 15.1 billion + KRW 7.8 million surcharge, 2024-05-23, 65,000 affected users — exact match, no fabrication found.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-23.

Industry Playbooks covering South Korea Framework Act on AI Development and Trust (AI Basic Act)

These industry playbooks include jurisdiction-specific checklist items and guidance for South Korea Framework Act on AI Development and Trust (AI Basic Act).

Frequently Asked Questions

Does South Korea Framework Act on AI Development and Trust (AI Basic Act) apply to my business?

South Korea's AI Basic Act (Framework Act on AI Development and Trust; passed by the National Assembly December 26, 2024; promulgated January 21, 2025; effective with its Enforcement Decree January 22, 2026) establishes governance for "high-impact"… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under South Korea Framework Act on AI Development and Trust (AI Basic Act) is: Administrative fines up to KRW 30,000,000 (approx. $21,000 USD) under Art. 43 — for failing to notify users that AI is in use, failing to designate a required domestic representative, or failing to comply with corrective orders / refusing inspection. Specific fine tiers are set by the Enforcement Decree; fines may be reduced up to 50% for SMEs, venture companies, and small businesses. The Act relies on administrative fines (no criminal sanctions). MSIT has announced a ONE-YEAR GRACE PERIOD: no administrative fines imposed until on/around January 22, 2027.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with South Korea Framework Act on AI Development and Trust (AI Basic Act)?

The 5 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.msit.go.kr/eng/bbs/view.do?sCode=eng&mId=4&mPid=2&nttSeqNo=1071

Last updated: 2026-08-23 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan