What the AI Basic Act actually does
The AI Basic Act is a framework statute: it establishes definitions, categories, and governance structures, but delegates the technical compliance detail to the MSIT Enforcement Decree and subordinate regulations. Its core design resembles the EU AI Act in structure but is less prescriptive on conformity assessment.
The statute's core concepts:
- AI system — a broad, EU-aligned definition covering machine-learning and logic-based systems that infer from inputs to generate outputs such as predictions, recommendations, or decisions.
- High-impact AI — a contextual, use-based category under Article 2(4), not an automatic label for every system used in a listed sector. Article 34 requires specified safety and reliability measures when the category applies. Article 35 separately says an operator should endeavour to assess effects on fundamental rights in advance; it is not drafted as an unconditional mandatory impact assessment.
- High-performance AI — a compute-based category. MSIT has clarified that systems trained with a cumulative compute of at least 10²⁶ FLOPs are designated high-performance AI with associated safety obligations. This threshold is notably different from the EU AI Act's Article 51 systemic-risk threshold of 10²⁵ FLOPs — a model can be a systemic-risk GPAI under the EU regime without being high-performance AI under the Korean regime, or vice versa, depending on the training run.
- Generative AI — providers must clearly disclose to users that they are interacting with AI, and must apply watermarking or labelling to AI-generated content. The specific watermarking standard is delegated to MSIT subordinate regulation.
- Extraterritoriality — the Act explicitly applies to foreign providers whose AI systems affect users in the Republic of Korea, similar in architecture to the EU AI Act's Article 2.
Enforcement is administered by MSIT. MSIT's 22 January 2026 release states that it will provide a grace period of at least one year, generally deferring fact-finding investigations and penalties during that period except for highly exceptional cases involving death, human-rights violations, or other serious social harm. The same release records that the Act, Enforcement Decree, and implementation guidelines took effect or were released on 22 January 2026. This page does not infer from the grace period that the statutory obligations are suspended.
Obligations in force on 22 January 2026
The statute creates tiered obligations based on the category of the AI system. The summary below is based on the enacted text and the Enforcement Decree; details may shift as subordinate regulations are finalised.
Relevant AI business operators
- Check the Act's territorial and operator scope, the role performed, and the category of the product or service. This page does not infer a universal provider-registration duty.
- A foreign operator without a Korean domicile or place of business must designate and report a domestic representative only if an Article 36 and Enforcement Decree Article 29 threshold applies: prior-year total revenue of at least KRW 1 trillion; prior-year AI-service revenue of at least KRW 10 billion; an average of at least one million domestic users per day over the relevant prior three-month period; or the specified Article 43(1)(3) administrative-fine condition.
- Follow applicable MSIT information, investigation, correction, and reporting requirements; the precise power and operator duty should be cited rather than described as a generic audit obligation.
High-impact AI providers
- Establish and operate a risk management system across the AI lifecycle.
- Maintain documentation sufficient to demonstrate how the system works, how it is trained, and how it is monitored.
- Ensure meaningful human oversight of decisions that materially affect individuals.
- Under Article 35, endeavour to assess effects on fundamental rights in advance, reflecting characteristics of AI-vulnerable groups. State and public bodies must give preferential consideration to products or services that have undergone an impact assessment. This soft-duty wording is distinct from Article 34's required measures.
- Provide users and affected parties with clear information about the system's purpose, capabilities, and limitations.
High-performance AI providers (≥ 10²⁶ FLOPs)
- Additional safety and security obligations, to be specified by MSIT subordinate regulation.
- Documentation of the training process, data sources, and evaluation results.
- Incident reporting to MSIT for identified safety failures.
Generative AI providers
- Disclose clearly to users that they are interacting with an AI system.
- Apply watermarking or labelling to AI-generated content such that downstream users and platforms can identify it as AI-generated. The technical watermarking standard is delegated to MSIT subordinate regulation.
What Korean operators and foreign providers should do today
The statute and Enforcement Decree are in force, and MSIT released initial guidelines on 22 January 2026. The practical sequence:
- Determine whether you are a high-impact AI provider by reviewing your deployment domains against the statute's list: healthcare, energy, public-sector use, identification, hiring, creditworthiness assessment, and related sensitive sectors. Extraterritorial reach means foreign providers serving Korean users are in scope.
- Estimate your training compute against the 10²⁶ FLOP threshold. Most production models today sit well below this. If you are building a frontier or near-frontier model, Regula's
regula inventorycommand can annotate detected model references with their tier; add your own internal training-run metadata to confirm. - If you ship generative AI, audit your transparency path. MSIT's official transparency guidance distinguishes prior notice for high-impact or generative AI from labelling AI-generated content and permits specified visible or invisible methods depending on the content. Check the Act, decree, and current guideline rather than assuming one universal watermark format.
- Document your risk management and human oversight. Regula's
regula gapandregula oversightcommands map cleanly onto the high-impact AI obligations. The outputs are not Korean-statute-specific, but the evidence is the same. - Test the domestic-representative thresholds rather than assuming the duty. Article 36 applies to an operator without a Korean domicile or place of business only when at least one Enforcement Decree Article 29 threshold is met: KRW 1 trillion total revenue, KRW 10 billion AI-service revenue, the specified one-million-domestic-users measure, or the stated administrative-fine trigger.
- Watch MSIT's official updates. The Act, decree, and initial guidelines are in force. MSIT has continued to amend the framework and refine guidance during the enforcement grace period.
How the AI Basic Act differs from the EU AI Act
A useful orientation for teams already working on EU AI Act compliance. The two regimes are structurally similar but differ in important details:
- Risk taxonomy. The EU AI Act uses a four-tier taxonomy plus a separate GPAI regime. Korea uses two overlapping categories (high-impact AI + high-performance AI) plus a generative AI transparency layer. A system can be high-impact under both regimes, or high-impact under one but not the other.
- Compute threshold. EU Article 51 uses 10²⁵ FLOPs as the systemic-risk GPAI threshold. Korea uses 10²⁶ FLOPs as the high-performance AI threshold. A model trained between 10²⁵ and 10²⁶ FLOPs is a systemic-risk GPAI in the EU but not high-performance AI under the Korean regime.
- Hard prohibitions. The EU AI Act has a hard prohibition list under Article 5. The Korean AI Basic Act does not have an equivalent hard prohibition list — sensitive use cases are channelled into the high-impact AI obligations instead.
- Conformity assessment. The EU AI Act requires third-party conformity assessment for some Annex I high-risk systems and self-assessment for Annex III. The Korean Act currently relies on provider documentation and MSIT oversight rather than third-party assessment bodies.
- Content marking. EU AI Act Article 50 obligations generally have applied since 2 August 2026, with a 2 December 2026 transition for providers of Article 50(2) systems already on the market before then. Korea's separate disclosure and content-marking rules must be checked against the Korean Act, Enforcement Decree, and current MSIT notices; this page does not treat a secondary summary as the legal text.
- Enforcement. EU enforcement is decentralised across national authorities plus the AI Office. Korean enforcement is centralised under MSIT.
If you are already on a path to EU AI Act readiness, a large share of the evidence and documentation will translate directly — but the thresholds, categories, and watermarking specifications need to be checked separately.
Where Regula fits for Korean operators and foreign providers
Regula includes a Korea-oriented assessment and can report related code indicators. It does not determine coverage or compliance under Korean law. You can take the Korea assessment (9 questions, no signup) or scan your codebase:
pipx install git+https://github.com/kuzivaai/getregula.git@main
regula discover . # AI systems present in the project
regula check . # Risk indicators across all frameworks
regula inventory . # Model references with GPAI tier (use alongside the Korean 10^26 threshold)
regula gap --project . # Gap assessment — maps onto high-impact AI obligations
regula oversight . # Cross-file human-oversight detection
regula docs . # Technical documentation scaffold
regula sbom --ai-bom . # AI Bill of Materials (CycloneDX 1.7)
What Regula does not yet do for Korea specifically: generate watermarking hook code, validate a Korean-standard watermark payload, or produce a Korean-language disclosure template. The first two will land once MSIT publishes the watermarking specification. The third is a straightforward localisation task — open an issue if you need it.
What we are tracking for the South Korea page
This page requires periodic review as the Korean framework changes. Specifically we are watching for:
- MSIT amendments and revised guidance affecting safety, transparency, high-impact determinations, and operator responsibilities.
- First enforcement actions — the first MSIT investigation, corrective order, or administrative fine under the Act.
- Interaction with existing Korean statutes — PIPA (Personal Information Protection Act) enforcement on AI training data, the Information and Communications Network Act on generative AI service providers, and sector regulators issuing their own AI guidance.
- Bilateral alignment with EU AI Act harmonised standards — whether MSIT references CEN-CENELEC JTC 21 work or the final GPAI Code of Practice in its subordinate regulations.
If you spot something we have missed, please open an issue.
Frequently asked questions
When did the South Korean AI Basic Act take effect?
22 January 2026, along with its Enforcement Decree. The statute is in force. MSIT released the Enforcement Decree and initial implementation guidelines on the same date.
What is 'high-performance AI' under the Korean regime?
AI systems trained with a cumulative compute of at least 10²⁶ FLOPs, as clarified by MSIT. This threshold is distinct from the EU AI Act's Article 51 systemic-risk GPAI threshold of 10²⁵ FLOPs — a model can cross one threshold without crossing the other.
Does the Korean AI Basic Act apply to foreign providers?
Yes. The statute has extraterritorial reach and applies to foreign providers whose AI systems affect users in the Republic of Korea. A domestic representative is conditional, however: Article 36 and Enforcement Decree Article 29 apply it only to foreign operators meeting a specified revenue, domestic-user, or administrative-fine threshold.
Do generative AI providers need to watermark output in Korea?
Yes. Generative AI providers must clearly disclose to users that output is AI-generated and must apply watermarking or labelling. The specific technical watermarking standard is delegated to MSIT subordinate regulation and is still being finalised.
How does the Korean AI Basic Act compare to the EU AI Act?
Structurally similar: both are horizontal, risk-based, extraterritorial statutes with documentation and human-oversight obligations. Key differences: no equivalent hard prohibition list, a different compute threshold (10²⁶ vs 10²⁵ FLOPs), centralised MSIT enforcement rather than distributed national authorities, and earlier-in-force generative AI transparency.
Does Regula cover the Korean AI Basic Act?
Partially. Regula's gap assessment, human oversight trace, technical documentation scaffold, and AI Bill of Materials all produce evidence that translates to the Korean regime's high-impact AI review. Regula does not validate compliance with MSIT's transparency guideline or generate Korean-language notices.
Sources
- Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust — KLRI English statute database — Official English statute database text used for Articles 31–36, including the Article 35 endeavour wording and conditional Article 36 domestic-representative rule.
- Enforcement Decree of the AI Framework Act — KLRI statute database — Official decree database entry used for Article 29's domestic-representative revenue, user, and administrative-fine thresholds.
- AI Basic Act and Enforcement Decree enter into force — MSIT, 22 January 2026 — Official ministry account of the effective date, decree, safety threshold, high-impact criteria, and enforcement grace period.
- Guidelines on Ensuring AI Transparency — MSIT, 22 January 2026 — Official ministry summary of Article 31 prior-notice and content-labelling guidance.
- South Korea: Comprehensive AI Legal Framework Takes Effect — Library of Congress Global Legal Monitor — Primary-adjacent official summary of the AI Basic Act and Enforcement Decree taking effect on 22 January 2026.
- Framework Act on the Development of Artificial Intelligence — English translation (CSET, Georgetown) — English translation of the enacted Korean AI Basic Act.
- South Korea's AI Basic Act: Overview and Key Takeaways — Cooley, 27 January 2026 — Primary-adjacent legal summary published the week the statute took effect.
- Analyzing South Korea's Framework Act on the Development of AI — IAPP — Independent analysis from the International Association of Privacy Professionals.
- South Korea Artificial Intelligence (AI) Basic Act — US Department of Commerce ITA — US trade agency summary for American exporters and service providers.
- Ministry of Science and ICT (MSIT) — Lead enforcement ministry. Subordinate AI regulations are published here.
Where does your own system stand?
The browser assessment is free, needs no account, and runs on your device. When the answer turns on something it cannot see, it says so and names the fact, rather than rounding the gap into a score. That makes it a starting point for review, not a legal determination.
Start the free assessment →