South Korea's Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust, usually called the AI Basic Act or AI Framework Act, passed the National Assembly on 26 December 2024, was promulgated on 21 January 2025 and took effect on 22 January 2026 together with its Enforcement Decree. It is a comprehensive AI law in the same family as the EU AI Act, and it applies to foreign companies whose AI products reach Korean users.

This article reads the Act as an engineering problem. It covers which systems it touches, what each obligation means for a product team, how to build the inventory, classification, notice, labeling and evidence systems that satisfy it, and where it differs from the EU regime. It is not legal advice. The Decree and MSIT guidelines fill in many details, some reporting on thresholds is still secondary, and you should confirm specifics with Korean counsel before relying on them.

Turning the Korean AI Framework Act into an engineering control systemAI inventoryevery model and featureClassifierKorea exposure + 4 testsNotice + labelingArt. 31: generative, high-impactHigh-impact dutiesArt. 34: risk, explain, oversightFrontier safetyArt. 32: compute thresholdDomestic representativeArt. 36: foreign operatorsEvidence storeversioned recordsMSIT requestsmaterials, correctionsexportOptional: impact assessmentArt. 35, encouraged
From inventory to evidence: classify each AI system, route it to the obligation tracks that apply, and keep versioned records for MSIT.

The shape of the Act

The Act is mostly a promotion law. Much of it sets up national planning, funding, data centres, talent and standards, administered by the Ministry of Science and ICT (MSIT), with a National AI Committee under the President and an AI Safety Research Institute. The regulatory part is narrower than the EU's. It prohibits no AI practices outright, and its maximum administrative fine is KRW 30 million (around USD 21,000).

The obligations attach to three kinds of system, plus one kind of company:

  • Generative AI: transparency duties under Article 31.
  • High-impact AI: Article 2(4) defines it as AI that may significantly affect or endanger human life, physical safety or fundamental rights and is used in a listed area: energy supply, drinking water, health care and medical devices, nuclear materials, biometric analysis in criminal investigations, judgments with significant effect on rights such as hiring and loan screening, transport systems, decisions by public bodies, and student evaluation in early childhood, primary and secondary education, plus areas added by Decree. These carry the transparency duties and the safety and reliability duties of Article 34.
  • Systems above a training-compute threshold: Article 32 safety duties. The Decree reportedly sets the threshold at 1026 floating-point operations of cumulative training compute.
  • Foreign operators above size thresholds: they must appoint a domestic representative (Article 36).

The duties fall on AI business operators, a term that covers both companies that develop AI and companies that offer products or services built on it. That matters for supply chains. If you build on a vendor's model, the vendor may carry the developer-side duties, but you still owe notice and labeling to your own users and still need high-impact controls if your use falls in a listed area. If you sell an API to other businesses, your customers may owe notice to theirs. Write the split into contracts: who shows the notice, who applies labels, who keeps which records, and who answers an MSIT request. The Act also reaches conduct abroad that affects the Korean market, so serving Korean users from servers elsewhere does not take a product out of scope.

The shape of the Act

The Act is mostly a promotion law. Much of it sets up national planning, funding, data centres, talent and standards, administered by the Ministry of Science and ICT (MSIT), with a National AI Committee under the President and an AI Safety Research Institute. The regulatory part is narrower than the EU's. It prohibits no AI practices outright, and its maximum administrative fine is KRW 30 million (around USD 21,000).

The obligations attach to three kinds of system, plus one kind of company:

  • Generative AI: transparency duties under Article 31.
  • High-impact AI: Article 2(4) defines it as AI that may significantly affect or endanger human life, physical safety or fundamental rights and is used in a listed area: energy supply, drinking water, health care and medical devices, nuclear materials, biometric analysis in criminal investigations, judgments with significant effect on rights such as hiring and loan screening, transport systems, decisions by public bodies, and student evaluation in early childhood, primary and secondary education, plus areas added by Decree. These carry the transparency duties and the safety and reliability duties of Article 34.
  • Systems above a training-compute threshold: Article 32 safety duties. The Decree reportedly sets the threshold at 1026 floating-point operations of cumulative training compute.
  • Foreign operators above size thresholds: they must appoint a domestic representative (Article 36).

The duties fall on AI business operators, a term that covers both companies that develop AI and companies that offer products or services built on it. That matters for supply chains. If you build on a vendor's model, the vendor may carry the developer-side duties, but you still owe notice and labeling to your own users and still need high-impact controls if your use falls in a listed area. If you sell an API to other businesses, your customers may owe notice to theirs. Write the split into contracts: who shows the notice, who applies labels, who keeps which records, and who answers an MSIT request. The Act also reaches conduct abroad that affects the Korean market, so serving Korean users from servers elsewhere does not take a product out of scope.

The obligations, article by article

ObligationApplies toWhat it means in a product
Advance notice (Art. 31)Products using generative or high-impact AITell users before use that the service runs on AI
Output labeling (Art. 31)Generative AI outputsIndicate outputs are AI-generated; clearly mark audio, images and video that are hard to tell from reality
Frontier safety (Art. 32)Systems above the compute thresholdIdentify, assess and mitigate risks, monitor incidents, run a risk management system, report results to MSIT
High-impact review (Art. 33)Operators of possibly high-impact AIAssess in advance whether a system is high-impact; MSIT can be asked to confirm
Safety and reliability (Art. 34)High-impact AIRisk management plan, explanation plan, user protection, human oversight, retained documentation
Impact assessment (Art. 35)High-impact AIAssess effects on fundamental rights; framed as an effort-based duty rather than a hard mandate
Domestic representative (Art. 36)Foreign operators above thresholdsA Korea-based representative reported to MSIT

Article 34's explanation plan asks for the criteria behind AI decisions and an overview of the training data, so far as technically feasible. That is a documentation and product-design duty, not a demand for full interpretability.

Enforcement, fines and the grace period

MSIT can request materials, investigate suspected violations and order corrective measures. Fines of up to KRW 30 million cover a short list of violations. Legal summaries name three: failing the advance-notice duty, failing to appoint a required domestic representative, and failing to comply with a corrective or suspension order. Reports differ on whether failing to label generative outputs is separately fineable, so for planning, treat labeling as enforceable.

The government announced a guidance period of at least one year from January 2026, during which investigations and fines are deferred except where serious harm occurs, and set up a support desk for compliance questions. A grace period does not remove the obligations. Plan to have controls in place, with evidence, before it ends.

For foreign operators, the reported Decree thresholds for appointing a representative are any of: total revenue of at least KRW 1 trillion in the prior year, AI-service revenue of at least KRW 10 billion, or an average of at least one million daily Korean users over the preceding three months. Check the current Decree text, since these figures come from secondary reporting.

Inventory and classification

Compliance starts with an inventory. You cannot label outputs or review high-impact systems you do not know about. Record every model and every feature that uses one, including vendor APIs, with an owner, purpose, output types, markets served and decision role. Then classify each entry with a function the whole company uses, so that answers are consistent and every result has a recorded reason:

HIGH_IMPACT_AREAS = {
    "energy", "drinking_water", "healthcare", "medical_device", "nuclear",
    "biometric_criminal_investigation", "hiring", "credit_screening",
    "transport", "public_decision", "student_evaluation",
}
COMPUTE_THRESHOLD_FLOP = 1e26          # as reported for the Enforcement Decree; confirm

def classify_kr(system):
    if not system.serves_korean_users:
        return {"in_scope": False, "reasons": ["no Korean users"]}
    duties, reasons = set(), []
    if system.generates_content:
        duties |= {"notice", "label_outputs"}
        reasons.append("generative AI (Art. 31)")
        if system.realistic_media:
            duties.add("clear_synthetic_media_label")
    area_hit = HIGH_IMPACT_AREAS & set(system.use_areas)
    if area_hit and system.significant_effect_on_rights_or_safety:
        duties |= {"notice", "high_impact_review", "risk_plan", "explanation_plan",
                   "user_protection", "human_oversight", "documentation"}
        reasons.append(f"high-impact candidate in {sorted(area_hit)} (Art. 2(4), 33, 34)")
    if (system.training_flop or 0) >= COMPUTE_THRESHOLD_FLOP:
        duties.add("frontier_risk_management")
        reasons.append("above compute threshold (Art. 32)")
    return {"in_scope": bool(duties), "duties": sorted(duties), "reasons": reasons,
            "needs_counsel": bool(area_hit)}     # borderline high-impact calls go to legal

Two design choices matter. Put the classifier in the product launch checklist, so a feature cannot ship to Korea without a recorded result. And send every high-impact candidate to a human decision, since the significance test is a judgment the code cannot make. Record the decision and its rationale as evidence.

Notice and labeling as middleware

Notice and labeling are the duties most products will hit, so build them as shared middleware rather than per-feature work. A notice is shown before first use and stored with the user's acknowledgement. Labels go on every generated output, with a visible indication where people will see the content, plus machine-readable metadata so downstream systems can carry it along. The Act requires the indication; it does not name a technical standard, so C2PA-style manifests and watermarks are good practice, not a stated requirement.

def label_output(output, feature, locale="ko-KR"):
    meta = {"ai_generated": True, "feature": feature.id,
            "model": feature.model_version, "created": now_iso()}
    if output.kind == "text":
        output.display_footer = t("ai_generated_text_notice", locale)
    elif output.kind in ("image", "audio", "video"):
        output.attach_metadata(meta)                  # embedded manifest where the format allows
        if feature.realistic_media:
            output.overlay = t("ai_generated_media_badge", locale)   # visible, not removable by default
    audit_log.write("label_applied", output.id, meta)
    return output

The audit log is the point. When MSIT asks, you need to show that labels were applied, from when, on which features and in which versions. A dashboard of label coverage, labeled outputs divided by generated outputs per feature, turns that into a number you can watch.

The evidence store and frontier duties

Every obligation above ends in a record, so design the evidence store once. Each record should say which system and version it covers, which duty it satisfies, who approved it and when, and where the artefact lives. Make records append-only and versioned. Regulators ask what was true on a past date, not only what is true today.

evidence_record = {
    "system_id": "loan-prescreen-api",
    "system_version": "3.4.1",
    "jurisdiction": "KR",
    "duty": "explanation_plan",            # notice | label_outputs | risk_plan | human_oversight | ...
    "article": "34",
    "artefact_uri": "s3://compliance/kr/loan-prescreen/3.4.1/explanation_plan.pdf",
    "approved_by": "ai-governance-board",
    "approved_at": "2026-03-02T10:15:00+09:00",
    "supersedes": "loan-prescreen-api/3.3.0/explanation_plan",
}

Article 32's frontier duties fit the same pattern. A developer above the compute threshold needs records of risk identification, assessment and mitigation, incident monitoring and the risk management system, and must report the results to MSIT. Few teams train at that scale. If you do, the safety cases and evaluation reports you already write for other regimes are the starting point. If you only call such a model through an API, ask your provider in the contract how it meets the duty.

Worked example: a foreign operator with two products

A US company with large revenue offers two products in Korea: an image generator and a loan pre-screening API used by Korean lenders.

  1. Domestic representative. Its revenue is above the reported threshold, so it appoints a Korean representative and reports it to MSIT.
  2. Image generator. Classified as generative AI. The sign-up flow gets a Korean-language AI notice. Every image carries embedded metadata, and photorealistic images of people carry a visible badge. Label coverage is monitored per release.
  3. Loan pre-screening. Credit screening is a listed area and the outputs affect access to loans, so it is a high-impact candidate. Counsel confirms it. The team writes a risk management plan, documents the decision criteria and a training-data overview for the explanation plan, routes declines to human review at the lender, adds user protection measures, and retains all of it in the evidence store.
  4. Shared duty. The lenders deploying the API also owe notice to their customers. The contract states who shows the notice and who keeps which records.
  5. Impact assessment. Not a hard mandate, but the team runs one anyway because it reuses their EU fundamental-rights work and strengthens their position with Korean lenders.

How it compares with the EU AI Act

TopicKorea AI Framework ActEU AI Act
StructurePromotion law with targeted dutiesRisk-tiered product regulation
Prohibited practicesNoneArticle 5 bans eight practices
Main regulated tierHigh-impact AI in listed areasHigh-risk AI (Annex I and III)
TransparencyNotice plus generative output labeling (Art. 31)Article 50 disclosure and marking
Large modelsSafety duties above a compute threshold (Art. 32)GPAI duties; systemic-risk presumption at 1025 FLOP
Maximum fineKRW 30 millionUp to EUR 35 million or 7% of global turnover

If you already run an EU AI Act programme, most Korean controls are a subset: reuse the inventory, risk management, documentation and labeling, then add Korea-specific notice text, the domestic representative and Korea's own list of high-impact areas, which does not match Annex III exactly.

Failure modes

  • Assuming small fines mean low risk. Corrective and suspension orders and reputational cost can matter more than KRW 30 million.
  • Labeling only the main surface. Exports, downloads, APIs and share links strip labels unless metadata travels with the output.
  • Inventory drift. A vendor model added through a feature flag never reaches the register.
  • Treating the grace period as an exemption. Serious-harm cases are not deferred.
  • Copying EU high-risk classification. The two lists overlap but differ; classify against Korea's own areas.

Related reading

To build the wider programme around these controls, read the EU AI Act, the NIST AI RMF, data governance for AI and AI regulation in depth.

What to do next

  1. Build or update the AI inventory with a Korean-users flag, use areas, output types and training compute.
  2. Run the classifier on every entry and send high-impact candidates to counsel for a recorded decision.
  3. Check the domestic-representative thresholds against current Decree text and appoint one if needed.
  4. Ship shared notice and labeling middleware with Korean text, metadata and a label-coverage dashboard.
  5. For high-impact systems, write the risk plan, explanation plan, oversight design and retention policy.
  6. Set up the evidence store so you can answer an MSIT materials request within days.
  7. Track MSIT guidelines and Decree amendments before the guidance period ends.
Key takeaway: Korea's AI Framework Act is lighter than the EU AI Act, with no bans and small fines, but it is in force and reaches foreign operators. Most teams will hit advance notice and output labeling; teams in listed areas will hit high-impact duties. Treat it as a control system: an inventory, a shared classifier, labeling middleware with coverage metrics, and an evidence store, finished before the guidance period ends.