Photo by Chris Boland on Unsplash
South Korea’s AI Basic Act took effect on January 22, 2026, making the country the first in the world to fully enforce a comprehensive AI law. The EU passed its AI Act earlier, but it phases in over several years, so Korea got to full enforcement first. If you build or sell an AI product with users in Korea, this law may already apply to you even if your company has never had an office there.
What the Korea AI Basic Act Actually Covers
The law’s formal name is the Basic Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness. It takes a risk-based approach, similar in spirit to the EU AI Act but noticeably lighter, and it bundles industrial promotion into the same statute as the obligations.
Obligations fall into three buckets, depending on what kind of system you operate.
| Category | Who it covers | Core obligation |
|---|---|---|
| Generative AI | Anyone offering generative AI to Korean users | Tell users they’re interacting with AI, and label AI-generated output |
| High-impact AI | Systems used in critical domains | Risk management, human oversight, meaningful explanation of outcomes |
| High-performance AI | Models trained above a compute threshold | Lifecycle risk management and user protection plans |
The high-impact tier is where the real compliance weight sits. According to the Future of Privacy Forum’s analysis, it targets AI used in domains like healthcare, energy, nuclear operations, biometric analysis, and public decision-making. The high-performance tier applies to models trained with 10^26 FLOPs or more, per law firm Cooley’s breakdown, a threshold that in practice captures only frontier labs.

Photo by Sasun Bughdaryan on Unsplash

Photo by Olena Kholina on Unsplash
It Applies to Foreign Companies Too
This is the part most non-Korean teams miss. The law reaches AI activity outside Korea that affects Korean users or the Korean market. The Future of Privacy Forum notes it even covers activity that “indirectly” impacts the Korean market, wording that is arguably broader than the EU AI Act’s extraterritorial reach.
There’s also a local representative requirement. A foreign company with no physical office in Korea must appoint a domestic agent if it crosses any one of three thresholds:
- More than 1 trillion KRW in global annual revenue
- More than 10 billion KRW in revenue from AI services
- More than 1 million average daily users in Korea
Those thresholds are high enough that a small startup with a handful of Korean users almost certainly doesn’t need an agent. The labeling obligations, though, don’t come with a size threshold attached.

Photo by Tingey Injury Law Firm on Unsplash
Penalties Are Modest, at Least for Now
Administrative fines top out at 30 million KRW, roughly $21,000. That covers things like failing to notify users that AI is in use, refusing to appoint a required domestic representative, or ignoring a corrective order.
Compared to the EU AI Act, where penalties climb into the tens of millions of euros or a percentage of global turnover, that is a rounding error for a large company. Korea also announced a one-year grace period before penalties are fully enforced, giving companies room to adjust.
How It Differs From the EU AI Act
Both laws sort AI by risk, but the philosophies diverge. The EU’s framework leans precautionary, with outright prohibited categories of AI. Korea’s version has no equivalent banned list, uses a simpler risk taxonomy, and pairs its obligations with active government support: funding, data centers, and training data for domestic AI development.
One concrete example of that lighter touch is labeling. Deepfake content requires clear, visible disclosure, but for AI output that isn’t deepfake material, an invisible digital watermark is acceptable rather than a visible on-screen label. That is a meaningfully more product-friendly rule than a blanket visible-label mandate.

Photo by Felix on Unsplash
If you’re evaluating AI tools rather than building them, the practical takeaway is smaller: expect to see more explicit “this is AI” disclosures in products serving Korean users. Our guide on how to tell if text was written by AI covers why those disclosures matter more than detection tools do.
FAQ: Frequently Asked Questions
When did the Korea AI Basic Act take effect?
January 22, 2026. Korea became the first country to bring a comprehensive AI law into full force, ahead of the EU AI Act, which is still phasing in its obligations over a multi-year schedule.
Does it apply to my company if I’m not in Korea?
Possibly. The Act applies to AI activity that affects Korean users or the Korean market, regardless of where the company sits. The domestic representative requirement only kicks in above specific revenue or user thresholds, but transparency obligations aren’t limited by company size.
What counts as high-impact AI?
AI used in critical domains such as healthcare, energy, nuclear operations, biometric analysis, and decisions made by public authorities. Operators in these areas carry the heaviest obligations, including human oversight and explaining how the system reached a given outcome.
How large are the penalties?
Administrative fines reach up to 30 million KRW, about $21,000, far below EU AI Act levels. A one-year grace period applies before penalties are fully enforced.
Do I have to label AI-generated content?
If you serve Korean users, generally yes. Deepfake-style synthetic media requires clearly recognizable disclosure, while other AI-generated output can satisfy the requirement with an invisible digital watermark instead of a visible label.
