The official English title is the Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust, usually called the AI Basic Act. It was promulgated on 21 January 2025 and took effect on 22 January 2026, together with its Enforcement Decree. A partial amendment in force from 21 July 2026 mainly changed promotion provisions, such as training data and the name of the national AI committee; the operator obligations covered here (Articles 31 to 36) are largely unchanged. The five checks below start with what applies to most organisations using AI.
1. Establish whether you are an “AI business operator”
The Act defines two kinds of AI business operator (Article 2(7)).
- AI developer business: develops and provides AI.
- AI user business: uses AI provided by a developer to offer AI products or services.
If you connect an external language model to offer customer support, document generation or decision support, you are an AI user business. If AI is used only for internal work, the Enforcement Decree allows some or all of the notice and labelling rules not to apply (Decree Article 23(4)).
Check: list the AI systems in use and record, for each, whether it is offered to customers or used internally. Every other check starts from this list.
2. Check that users are told they are dealing with AI
Article 31 sets three requirements.
- Before offering a product or service that uses high-impact or generative AI, tell users in advance that it operates on AI.
- Label outputs produced by generative AI as such.
- Where virtual sound, images, video or similar outputs are hard to tell apart from reality, notify or label that they were generated by AI in a way users clearly recognise.
Under Decree Article 23, notice can be given on the product or in the contract, user manual or terms of service, shown on the user's screen or device, or posted where the product is provided. Labels may be readable by people or by machines; if only machine-readable labels are used, users must also be told at least once, in text or by voice.
Check: find the notice yourself on screen and in the terms, then sample a few generated outputs to see whether the label is actually attached. What a policy says and what outputs carry can differ.
3. Assess whether any system is high-impact AI
High-impact AI is AI that may significantly affect, or pose risks to, human life, physical safety or fundamental rights, when used in areas listed in the Act (Article 2(4)). The areas most often relevant to businesses are:
- judgements or evaluations with a significant effect on individuals' rights and duties, such as hiring and loan screening;
- healthcare and medical devices;
- infrastructure such as energy supply, drinking-water production and transport.
The list also covers nuclear facilities, biometric analysis for criminal investigations, decisions by public bodies on public services, and the assessment of pupils in early-childhood, primary and secondary education; further areas may be added by decree.
Operators must review in advance whether their AI is high-impact, and may ask the Ministry of Science and ICT to confirm (Article 33). Under Decree Article 25 the ministry replies within 30 days, extendable once by 30 days.
Check: for each system on your list, assess whether it falls into a listed area, and keep a record of the review and its reasoning. A conclusion that a system is not high-impact also needs reasons you can show later.
4. If it is high-impact, keep evidence of the required measures
Operators that provide high-impact AI must take these measures (Article 34(1)):
- establish and operate a risk-management plan;
- to the extent technically feasible, establish a way to explain the final outputs, the main criteria used to reach them and an overview of the training data;
- establish and operate user-protection measures;
- human management and oversight;
- prepare and keep documents showing the safety and reliability measures taken;
- other matters decided by the national AI committee.
Decree Article 27 requires the evidence of these measures to be kept in writing for five years, and the main points of the risk-management and explanation plans, the user-protection measures, and the name and contact details of the person responsible for oversight to be posted at the office or on the website (trade secrets may be left out). If you build on a third-party model, the risk-management, explanation and user-protection measures (items 1 to 3) taken by the developer count as yours to the extent they were taken, as long as you have not made a major functional change such as substantially altering the system's original purpose (Decree Article 27(3)). Human oversight and documentation are not covered by this rule, so you need to handle them yourself. You may ask the developer for the materials you need. The impact assessment in Article 35 is a best-efforts duty, but public bodies are to give priority to products and services that have been assessed, so it is worth considering if you sell to the public sector.
Check: confirm when a person steps in and where that intervention is recorded. In an audit, a record made at the moment of the decision is easier to rely on than a report written afterwards.
5. Know the enforcement timeline
Where a breach of the output-labelling duties (Article 31(2) and (3)), the safety duties (Article 32) or the high-impact measures (Article 34(1)) is suspected, or a report or complaint is received, the Ministry of Science and ICT may request materials or investigate, and order a suspension or correction if a breach is found (Article 40). Fines go up to KRW 30 million and apply to three cases (Article 43):
- failing to give the advance notice under Article 31(1);
- failing to appoint a domestic representative;
- failing to comply with a suspension or correction order under Article 40.
When the Act took effect, the government said it would defer investigations and fines for at least a year, and investigate during that period only in very exceptional cases such as loss of life or human-rights harm. At the time of writing no end date has been officially announced. What is deferred is enforcement; the obligations already apply.
Also check
- Safety duties (Article 32) apply to frontier AI trained with cumulative compute of 1026 floating-point operations or more, among other conditions (Decree Article 24). Most AI user businesses are not covered.
- Domestic representative (Article 36): an operator with no address or office in Korea must appoint one if its revenue or user numbers exceed thresholds set in the Decree. Check this if your head office is abroad.
The checklist on one page
| Check | Basis | What to confirm |
|---|---|---|
| AI system list | Art. 2(7) | Developer or user; offered to customers or internal |
| Advance notice | Art. 31(1) | Where the notice appears (screen, terms) |
| Output labelling | Art. 31(2), (3) | Whether real outputs carry the label |
| High-impact review | Art. 2(4), 33 | Review record and reasoning |
| High-impact measures | Art. 34; Decree Art. 27 | Records of human oversight, kept five years; posted on the website |
Sources
- Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (opens in a new window) (Act No. 21311, in force from 21 July 2026; Korean text), Korea Law Information Center
- Enforcement Decree of the Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (opens in a new window) (Presidential Decree No. 36580, in force from 20 August 2026; Korean text), Korea Law Information Center
- English translation of the Act (opens in a new window), Korea Legislation Research Institute
- Ministry of Science and ICT announcement of the Act taking effect (opens in a new window) (Korean), Korea.kr, 21 January 2026
This article is general information, not legal advice. For a specific situation, consult a qualified lawyer. Where the English translation and the Korean text differ, the Korean text prevails.