South Korea is the AI regulation story most global operators have not yet priced into their compliance planning. It is not a US-style sectoral patchwork, and it is not a light-touch national strategy document. It is a binding statute with a defined higher-risk category, named ministerial enforcement, and a labelling obligation for generative AI, built on a legislative logic that will look familiar to anyone who has read the EU AI Act. Operators deploying AI agents into the Korean market, or building products for a Korean user base, need to treat the AI Basic Act as a live compliance obligation rather than a future consideration.

Key takeaways

  • The AI Basic Act, passed by the National Assembly on 26 December 2024 and promulgated on 21 January 2025, entered into force on 22 January 2026 following a one-year grace period.
  • The Act defines a specific category of high-impact AI, covering energy, critical infrastructure, healthcare, nuclear safety, criminal justice decisions, public benefit eligibility, biometric recognition, and employment decisions, and imposes risk management, human oversight, explainability, and user-notification obligations on operators in those sectors.
  • Generative AI providers face a separate labelling obligation requiring AI-generated content to be marked as such, structurally similar to Article 50 of the EU AI Act.
  • The Ministry of Science and ICT (MSIT) is the lead enforcement authority, supported by the state-run AI Safety Institute for technical assessment of high-impact systems.
  • Administrative fines are capped at KRW 30 million, roughly USD 20,000 to 22,000, for the most serious violations, several orders of magnitude below the EU AI Act's turnover-based penalty regime, even though the underlying classification logic is structurally similar.

The AI Basic Act: legislative history and structure

The AI Basic Act, formally the Act on the Development of Artificial Intelligence and Establishment of Trust, consolidated several competing legislative proposals that had circulated in the National Assembly since 2023.[1] The final text passed the National Assembly on 26 December 2024, was promulgated on 21 January 2025, and entered into force on 22 January 2026, giving industry and regulators a one-year window to prepare implementing rules and internal compliance programmes before the obligations became binding.

The Act's title signals its dual purpose more clearly than most comparable statutes: it is framed as legislation to promote AI development and industrial competitiveness, not solely to constrain it. This dual framing shapes the Act's structure. Alongside the operator obligations described below, the Act establishes a national AI committee chaired at a senior government level, directs government support for AI research and infrastructure, and creates the state-run AI Safety Institute to provide technical capacity for both industrial support and safety assessment functions. Operators reading only the compliance chapters risk missing that the Act was drafted, and is publicly described by MSIT, as much as an industrial policy instrument as a risk regulation.

High-impact AI: the operative classification

The Act's compliance obligations attach to a defined category the legislation calls high-impact AI, artificial intelligence that has a significant effect on human life, physical safety, or fundamental rights.[2] The Act names specific sectors in scope: energy supply, water and other critical infrastructure, healthcare and medical devices, nuclear safety, criminal investigation and prosecution-related decisions, decisions on eligibility for public benefits and services, biometric recognition, and AI used in recruitment, hiring, and other significant employment decisions.

This sector-anchored approach is structurally closer to the EU AI Act's Annex III high-risk list than to a single numeric risk score or a general-purpose capability threshold. An operator's first compliance task under Korean law is the same as under EU law: determine whether the specific AI agent or system falls inside one of the named high-impact categories, because the Act's substantive obligations apply only to systems that do.

A second, narrower category applies horizontally regardless of sector: generative AI. Any provider of a generative AI system serving Korean users faces a labelling obligation, separate from and additional to the high-impact classification, requiring that AI-generated content, including text, images, audio, and video, be marked in a way that is perceptible to users as machine-generated. This mirrors the transparency logic of Article 50 of the EU AI Act, though the Korean labelling requirement is not tied to a risk tier and applies to generative AI as a category on its own terms.

What MSIT requires of high-impact AI operators

The Ministry of Science and ICT is the lead enforcement authority under the AI Basic Act.[3] For operators of high-impact AI, the Act's core obligations are four. First, a risk management plan, covering identification and mitigation of foreseeable risks to life, safety, and fundamental rights arising from the specific deployment. Second, measures for human oversight and safety, ensuring that a person retains the ability to monitor and intervene in the system's operation. Third, a user notification obligation, requiring that individuals be informed when they are interacting with, or subject to a decision made by, a high-impact AI system. Fourth, an explainability obligation, requiring that the operator be able to provide an account of the basis for the system's output on request from an affected individual or from MSIT.

These four obligations map closely to the substance of EU AI Act Articles 9, 14, 26, and 13, even though the Korean Act does not cross-reference the EU framework and was drafted independently within Korea's own legislative process. Operators who have already built EU AI Act Article 26 deployer documentation, covering risk identification, oversight assignment, and output explainability, will find that documentation transfers with moderate adaptation to a Korean high-impact AI compliance file, though the underlying legal tests and evidentiary expectations are separate national requirements that must each be satisfied on their own terms.

The AI Safety Institute, established under Korea's national AI strategy and operating in coordination with MSIT, provides technical assessment capacity for high-impact AI systems, including safety and reliability testing support. Its role is closer to a technical advisory body supporting the ministry than to the EU's network of independent notified bodies conducting formal conformity assessments; the Korean regime does not require third-party conformity assessment or a CE-marking equivalent before a high-impact AI system can be placed on the market.

Enforcement and penalty levels

MSIT holds investigatory and corrective-order powers under the Act, including the ability to require operators to produce documentation, to order corrective measures where a high-impact AI system is found non-compliant, and to impose administrative fines for violations.[4] The maximum administrative fine under the Act reaches KRW 30 million, approximately USD 20,000 to 22,000 depending on the prevailing exchange rate, for the most serious category of violation.

This figure is the single most consequential difference between the Korean and EU regimes for a global operator weighing compliance investment. The EU AI Act's Article 99 penalty ceiling reaches EUR 35 million or 7 percent of worldwide annual turnover for prohibited practice violations, and EUR 15 million or 3 percent of turnover for high-risk obligation violations, whichever is higher in each case. The Korean ceiling is a fixed sum roughly three orders of magnitude smaller and is not calculated as a percentage of turnover at all. An operator with meaningful EU exposure cannot treat Korean compliance investment as calibrated to the same financial stakes, even where the underlying classification and documentation requirements are structurally similar.

That gap in penalty severity does not mean Korean enforcement risk is negligible. MSIT's corrective-order power, including the ability to require operational changes or suspension of a non-compliant high-impact AI deployment, carries commercial consequences independent of the fine amount, particularly for an operator whose Korean deployment is commercially significant or whose brand exposure to a public corrective order would be costly regardless of the monetary penalty attached.

What remains unsettled through 2026

The AI Basic Act is a framework statute, meaning much of its operational detail is delegated to subordinate presidential and ministerial decrees rather than specified in the primary legislative text. Several of these decrees, covering the precise scope of high-impact sub-categories, the detailed content required in a risk management plan, and the technical specifications for generative AI content labelling, were still being finalised by MSIT through the first half of 2026, after the Act's formal entry into force in January. Operators should expect continued regulatory guidance and decree publication through the remainder of 2026 as MSIT completes the implementing framework, in a pattern broadly similar to how the EU AI Office continues to publish guidelines and codes of practice well after the EU AI Act's own phased application dates.

Comparison with the EU AI Act

South Korea and the EU are the two jurisdictions that have committed most clearly to a horizontal, cross-sectoral AI statute built around a defined higher-risk category, which sets both apart from Switzerland's sectoral-adaptation approach and from the United States' state-by-state and executive-order-driven patchwork.[5] The structural resemblance is real: both regimes ask an operator to first determine whether a system falls inside a named higher-risk category, and both then impose risk management, human oversight, transparency, and explainability obligations on systems that do.

The differences are in mechanism and consequence. The EU AI Act requires conformity assessment for high-risk systems, in many cases involving independent notified bodies, and backs its obligations with turnover-based penalties that scale directly with the size of the offending enterprise. Korea's AI Basic Act requires no equivalent third-party conformity assessment and backs its obligations with a fixed, comparatively modest administrative fine. The EU's approach treats non-compliance as a financially existential risk for a large enterprise; Korea's approach, at least as enacted, treats it as a compliance cost to be managed and a reputational and operational risk mediated through MSIT's corrective-order power rather than primarily through fine exposure.

For operators with both EU and Korean market exposure, the practical implication is that Korean compliance should be built as a genuinely separate national programme, informed by EU AI Act documentation practices where the underlying obligations align, but not treated as automatically satisfied by EU compliance work. The two regimes are independent legal instruments administered by separate authorities with separate enforcement priorities, and a Korean high-impact AI classification does not track the EU's Annex III categories exactly. For the EU deployer obligations that remain the highest-stringency reference point globally, see the Article 26 deployer obligations guide on agentliability.eu. Operators assembling a documentation baseline that can flex across multiple high-impact and high-risk regimes may find agentcertified.eu useful as a reference point for certification-style AI governance frameworks.


Frequently asked questions

What is South Korea's AI Basic Act and when did it take effect?

The AI Basic Act, formally the Act on the Development of Artificial Intelligence and Establishment of Trust, was passed by the National Assembly on 26 December 2024, promulgated on 21 January 2025, and entered into force on 22 January 2026 after a one-year grace period. It made South Korea the second major jurisdiction after the European Union to enact a comprehensive, horizontal AI statute, ahead of most other Asia-Pacific markets.

What is high-impact AI under Korean law?

High-impact AI is a defined category covering AI systems that have a significant effect on life, physical safety, or fundamental rights. The Act names specific sectors: energy, water and other critical infrastructure, healthcare and medical devices, nuclear safety, criminal investigation and prosecution decisions, eligibility determinations for public benefits, biometric recognition, and AI used in recruitment and employment decisions. Operators of AI systems in these sectors face the Act's core obligations, in a structure closer to the EU AI Act's Annex III high-risk categories than to a general-purpose AI rulebook.

What does the Ministry of Science and ICT require from high-impact AI operators?

Operators of high-impact AI must implement a risk management plan, maintain measures for human oversight and safety, notify users when they are interacting with a high-impact AI system, and be able to explain the basis for the system's outputs on request. Generative AI providers separately face a labelling obligation, requiring AI-generated content to be marked as such. The Ministry of Science and ICT (MSIT) is the lead enforcement authority, supported by the state-run AI Safety Institute for technical assessment.

How severe are the penalties under Korea's AI Basic Act compared to the EU AI Act?

Materially lower. Administrative fines under the AI Basic Act reach up to KRW 30 million, roughly USD 20,000 to 22,000 depending on the exchange rate, for the most serious violations. The EU AI Act's Article 99 penalties reach EUR 35 million or 7 percent of worldwide annual turnover for prohibited practice violations, and EUR 15 million or 3 percent of turnover for high-risk obligation violations. The two regimes share a similar high-impact classification logic but differ by roughly three orders of magnitude in maximum financial exposure.

How does South Korea's approach compare structurally to the EU AI Act?

Both are horizontal, cross-sectoral statutes built around a defined category of higher-risk AI, which is a structural similarity Korea shares with the EU rather than with Switzerland or the United States. The differences are in mechanism and severity. Korea's Act does not impose a conformity assessment or CE-marking-equivalent process, does not create notified bodies, and carries administrative fines far below the EU's turnover-based penalty regime. Korea also relies more heavily on subordinate presidential and ministerial decrees to fill in operational detail, several of which were still being finalised by MSIT through mid-2026.


References

  1. National Assembly of the Republic of Korea. Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act). Passed 26 December 2024, promulgated 21 January 2025, entered into force 22 January 2026.
  2. AI Basic Act, high-impact AI definition and named sectors: energy, critical infrastructure, healthcare, nuclear safety, criminal justice, public benefit eligibility, biometric recognition, employment decisions.
  3. Ministry of Science and ICT (MSIT), Republic of Korea. Lead enforcement authority under the AI Basic Act, supported by the AI Safety Institute for technical assessment. Available at msit.go.kr.
  4. AI Basic Act, administrative fine provisions. Maximum fine KRW 30 million for the most serious violation category, subject to implementing decree detail published by MSIT through 2026.
  5. Regulation (EU) 2024/1689, Article 99, penalty provisions for comparison. EUR 35 million or 7 percent of worldwide annual turnover for prohibited practices; EUR 15 million or 3 percent for high-risk obligation violations.