AI regulation in South Korea is now a concrete legal reality. The country enacted its Framework Act on the Development of Artificial Intelligence and Establishment of Trust Basis - commonly called the AI Basic Act - creating a structured, risk-tiered compliance regime for companies that develop, deploy or distribute AI systems within Korean territory. For international businesses operating in or entering the Korean market, understanding this framework is no longer optional. This guide covers the legislative architecture, the risk classification system, obligations for high-impact AI, sector-specific rules, enforcement mechanisms, and the practical steps foreign companies must take to remain compliant.
South Korea';s AI Basic Act is the primary legislative instrument governing artificial intelligence in the country. The National Assembly passed the Act in late 2024, and it entered into force in stages, with core provisions becoming operative in the current period. The Act establishes a national AI governance framework built around the principle of "trustworthy AI" - a concept that encompasses safety, transparency, accountability and respect for fundamental rights.
The Act applies broadly. It covers AI developers, AI service providers and AI deployers operating in South Korea, regardless of where those entities are incorporated. A foreign company that offers an AI-powered product or service to Korean users, or that processes Korean personal data through an AI system, falls within the Act';s scope. This extraterritorial reach mirrors the approach taken by the EU AI Act and reflects South Korea';s intent to protect its citizens and market from AI-related harms originating abroad.
The Act designates the Ministry of Science and ICT as the lead coordinating authority. It also establishes the Presidential Committee on AI, which advises on national AI strategy and oversees the implementation of the Act';s principles. Sector regulators - including the Financial Services Commission, the Korea Communications Commission and the Ministry of Health and Welfare - retain authority over AI applications within their respective domains, creating a layered regulatory structure.
A non-obvious requirement for many foreign companies is that the Act';s obligations attach to the point of deployment or service provision in Korea, not merely to the location of the AI system';s training or development. A company that trains a model abroad but deploys it to Korean consumers must comply with Korean AI rules as if it were a domestic operator.
The AI Basic Act introduces a risk-tiered classification system that determines the intensity of compliance obligations. This approach is conceptually similar to the EU AI Act but reflects Korean legislative priorities and administrative practice.
At the top of the hierarchy sit high-impact AI systems. These are AI applications that, by their nature or deployment context, carry significant potential to affect fundamental rights, public safety or critical infrastructure. The Act identifies several categories of high-impact AI, including systems used in:
Operators deploying high-impact AI must meet a more demanding set of obligations, described in detail in the section below. Systems that fall outside the high-impact category are subject to lighter-touch requirements focused primarily on transparency and user notification.
The Act also contemplates a category of generative AI systems - large language models, image generators and similar foundation models - which attract specific transparency and disclosure obligations regardless of their risk classification. This reflects the Korean legislature';s recognition that generative AI presents distinct challenges around authenticity, misinformation and intellectual property that cut across the standard risk tiers.
In practice, classification is not always straightforward. The Ministry of Science and ICT has issued guidance on how to assess whether a given system qualifies as high-impact, but many borderline cases remain. A common mistake among foreign companies is to assume that a system used in a low-stakes context abroad automatically carries the same classification in Korea. The classification depends on the Korean deployment context, not the system';s original design purpose.
Companies deploying high-impact AI systems in South Korea face a structured set of obligations under the AI Basic Act. These requirements are designed to ensure that consequential AI decisions are explainable, auditable and subject to human oversight.
Conformity assessment and documentation. Operators of high-impact AI must conduct a conformity assessment before deploying the system. This assessment evaluates whether the system meets the Act';s requirements for accuracy, robustness, safety and non-discrimination. The assessment must be documented and retained for a prescribed period - currently set at a minimum of several years - and must be updated whenever the system undergoes material changes. Unlike some international frameworks, South Korea does not currently require third-party certification for most high-impact AI, though sector regulators may impose additional requirements in specific domains such as medical devices or financial services.
Transparency and disclosure to users. Operators must inform users that they are interacting with or being assessed by an AI system. This obligation applies both to real-time interactions - such as AI-powered customer service chatbots - and to automated decision-making processes that produce outputs affecting users'; rights or interests. The disclosure must be clear, accessible and provided before or at the point of interaction, not buried in terms and conditions.
Human oversight mechanisms. High-impact AI systems must incorporate meaningful human oversight. The Act requires that operators establish procedures allowing human review of AI-generated decisions, particularly where those decisions have significant consequences for individuals. This does not mean that every AI output must be manually reviewed, but operators must be able to demonstrate that human intervention is genuinely possible and practically accessible.
Incident reporting. Operators must report serious incidents involving high-impact AI systems to the relevant authority within a defined timeframe. A serious incident includes cases where an AI system causes or contributes to significant harm to individuals, material financial loss, or a breach of public safety. The reporting obligation applies to the operator deploying the system in Korea, even if the underlying model was developed by a third party.
Data governance. The AI Basic Act intersects with South Korea';s Personal Information Protection Act, which is administered by the Personal Information Protection Commission. AI systems that process personal data must comply with both frameworks simultaneously. This creates a dual compliance burden that many foreign companies underestimate. In practice, founders and compliance officers should map their AI data flows against both the AI Basic Act and the PIPA before deployment.
If your organisation is assessing its obligations under the AI Basic Act, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
South Korea has addressed generative AI and large-scale foundation models with a set of targeted provisions that sit alongside the general risk-tier framework. These provisions reflect the government';s concern about the societal impact of AI-generated content and the concentration of AI capability in a small number of large models.
Providers of generative AI services in Korea must label AI-generated content in a manner that allows users to identify it as such. This applies to text, images, audio and video produced by AI systems. The labelling requirement is technology-neutral - it does not prescribe a specific technical method - but the label must be prominent enough to be noticed by an ordinary user. Providers that operate content platforms, social media services or news aggregation services face heightened obligations in this area, given the potential for AI-generated content to be mistaken for human-created material.
Foundation model developers - companies that train and release large-scale AI models that others build upon - face additional obligations around transparency. They must publish technical documentation describing the model';s capabilities, known limitations, training data sources at a general level, and the measures taken to address safety risks. This documentation must be kept current and made available to downstream deployers who build products on top of the foundation model.
A practical scenario: a European company that has developed a large language model and licenses it to Korean businesses for integration into their products must provide the required technical documentation to those Korean deployers. The Korean deployers, in turn, rely on that documentation to fulfil their own obligations under the Act. A failure by the foundation model provider to supply adequate documentation creates compliance risk for the entire downstream chain.
The Ministry of Science and ICT has indicated that it will issue further guidance on generative AI obligations, particularly around synthetic media and deepfakes. Companies operating in the media, entertainment and communications sectors should monitor these developments closely.
Beyond the AI Basic Act, South Korea maintains a network of sector-specific rules that govern AI applications in regulated industries. These rules often impose requirements that go beyond the general framework, and compliance with the AI Basic Act alone does not guarantee compliance with sector-level obligations.
Financial services. The Financial Services Commission and the Financial Supervisory Service have issued guidance on the use of AI in credit assessment, robo-advisory services and algorithmic trading. Financial institutions using AI for customer-facing decisions must ensure explainability, maintain audit trails and comply with the Act on the Use and Protection of Credit Information. The FSC has also signalled its intention to issue more detailed AI-specific rules for the financial sector as the AI Basic Act';s implementation progresses.
Healthcare. AI systems used in medical diagnosis or treatment recommendation are regulated as medical devices under the Medical Devices Act, administered by the Ministry of Food and Drug Safety. The MFDS has developed a dedicated regulatory pathway for AI-based medical devices, including requirements for clinical validation, post-market surveillance and incident reporting. A company deploying an AI diagnostic tool in Korean hospitals must navigate both the AI Basic Act and the medical device regulatory framework.
Telecommunications and media. The Korea Communications Commission oversees AI applications in broadcasting, telecommunications and online platforms. Platforms that use AI for content recommendation, content moderation or targeted advertising face obligations under the Act on Promotion of Information and Communications Network Utilization and Information Protection, as well as the AI Basic Act';s transparency requirements.
A common mistake among foreign companies entering the Korean market is to treat AI compliance as a single-track exercise. In practice, a single AI product may trigger obligations under three or four different regulatory frameworks simultaneously. Early-stage legal mapping is essential.
The AI Basic Act establishes an enforcement regime with meaningful consequences for non-compliance. Understanding how enforcement works in practice is important for companies assessing their compliance risk.
The Ministry of Science and ICT has primary enforcement authority over the AI Basic Act. It can conduct inspections, request documentation, issue corrective orders and impose administrative fines. The Act provides for fines scaled to the severity of the violation and the size of the operator. For the most serious breaches - such as deploying a high-impact AI system without conducting the required conformity assessment, or failing to report a serious incident - fines can reach a significant percentage of Korean revenue. The Act also provides for criminal penalties in cases of deliberate or grossly negligent violations.
Sector regulators retain parallel enforcement authority within their domains. The Personal Information Protection Commission can act independently where an AI system';s data processing practices violate the PIPA. The Financial Services Commission can impose sanctions on financial institutions that use AI in ways that breach financial sector rules. This means that a single AI-related incident can trigger enforcement action by multiple authorities simultaneously.
In practice, Korean regulators have signalled a preference for engagement and correction over immediate punitive action, at least in the current early phase of the AI Basic Act';s implementation. Companies that proactively engage with regulators, maintain good documentation and demonstrate genuine compliance efforts are likely to receive more favourable treatment than those that ignore their obligations. However, this informal leniency should not be relied upon as a compliance strategy.
A practical scenario: a foreign e-commerce company uses an AI system to personalise product recommendations and set dynamic prices for Korean consumers. If that system also influences credit-related decisions - for example, by determining eligibility for instalment payment plans - it may qualify as high-impact AI under the Act. Failure to conduct a conformity assessment and implement the required transparency measures could expose the company to enforcement action by both the Ministry of Science and ICT and the Financial Services Commission.
For companies that need to assess their current compliance posture or prepare for a regulatory inspection, contact info@vlolawfirm.com. We can assist with documents and filings.
What types of AI systems are considered high-impact under South Korea';s AI Basic Act, and what does that mean in practice?
High-impact AI systems are those deployed in contexts where AI-generated outputs can significantly affect individuals'; rights, safety or material interests. The Act identifies specific domains - including healthcare, financial services, employment and public safety - as presumptively high-impact. In practice, this means that a company deploying an AI system in any of these areas must conduct a conformity assessment before launch, implement human oversight mechanisms, provide clear user disclosures and maintain detailed documentation. The classification is context-dependent: the same underlying model may be high-impact in one deployment and not in another, depending on how it is used and who is affected.
How long does it take to achieve compliance with the AI Basic Act, and what are the main cost drivers?
The timeline for compliance depends heavily on the complexity of the AI system and the maturity of the company';s existing governance processes. For a company with no prior AI governance framework, building the required documentation, conformity assessment processes and human oversight mechanisms typically takes several months of dedicated effort. Professional fees for legal and technical advisory work vary by scope, but companies should budget for meaningful investment in both legal counsel and technical documentation. The main cost drivers are the conformity assessment process, data governance alignment with the PIPA, and the ongoing cost of maintaining and updating documentation as the system evolves. Sector-specific requirements in healthcare or financial services add further complexity and cost.
Does the AI Basic Act apply to foreign companies that have no legal entity in South Korea?
Yes. The AI Basic Act applies to any entity that deploys or provides AI systems to users in South Korea, regardless of where the entity is incorporated or where its servers are located. A foreign company with no Korean subsidiary but with Korean users or customers is within scope if its AI systems affect those users. This extraterritorial application is explicit in the Act and reflects South Korea';s intent to protect its residents from AI-related harms regardless of the operator';s location. Foreign companies should not assume that the absence of a Korean legal entity provides any exemption from compliance obligations.
South Korea';s AI regulatory framework is now operational and applies to a broad range of domestic and foreign operators. The AI Basic Act establishes risk-tiered obligations, with the most demanding requirements falling on high-impact AI systems in healthcare, finance, employment and public safety. Sector-specific rules add further layers of compliance in regulated industries. Enforcement is real, and the extraterritorial reach of the Act means that foreign companies serving Korean users cannot ignore their obligations.
VLO Law Firms advises international clients on AI regulation in South Korea. We can assist with compliance assessments, conformity documentation, sector-specific regulatory mapping, and engagement with Korean authorities. To request a consultation, contact: info@vlolawfirm.com