Korea AI Basic Act: The First Comprehensive AI Law in Force (And Why It May Apply to You)

Photo by Chris Boland on Unsplash

South Korea’s AI Basic Act took effect on January 22, 2026, making the country the first in the world to fully enforce a comprehensive AI law. The EU passed its AI Act earlier, but it phases in over several years, so Korea got to full enforcement first. If you build or sell an AI product with users in Korea, this law may already apply to you even if your company has never had an office there.

What the Korea AI Basic Act Actually Covers

The law’s formal name is the Basic Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness. It takes a risk-based approach, similar in spirit to the EU AI Act but noticeably lighter, and it bundles industrial promotion into the same statute as the obligations.

Obligations fall into three buckets, depending on what kind of system you operate.

Category Who it covers Core obligation
Generative AI Anyone offering generative AI to Korean users Tell users they’re interacting with AI, and label AI-generated output
High-impact AI Systems used in critical domains Risk management, human oversight, meaningful explanation of outcomes
High-performance AI Models trained above a compute threshold Lifecycle risk management and user protection plans

The high-impact tier is where the real compliance weight sits. According to the Future of Privacy Forum’s analysis, it targets AI used in domains like healthcare, energy, nuclear operations, biometric analysis, and public decision-making. The high-performance tier applies to models trained with 10^26 FLOPs or more, per law firm Cooley’s breakdown, a threshold that in practice captures only frontier labs.

a gavel and open law book representing Korea AI Basic Act compliance obligations

Photo by Sasun Bughdaryan on Unsplash

two people reviewing printed documents across a desk

Photo by Olena Kholina on Unsplash

It Applies to Foreign Companies Too

This is the part most non-Korean teams miss. The law reaches AI activity outside Korea that affects Korean users or the Korean market. The Future of Privacy Forum notes it even covers activity that “indirectly” impacts the Korean market, wording that is arguably broader than the EU AI Act’s extraterritorial reach.

There’s also a local representative requirement. A foreign company with no physical office in Korea must appoint a domestic agent if it crosses any one of three thresholds:

  • More than 1 trillion KRW in global annual revenue
  • More than 10 billion KRW in revenue from AI services
  • More than 1 million average daily users in Korea

Those thresholds are high enough that a small startup with a handful of Korean users almost certainly doesn’t need an agent. The labeling obligations, though, don’t come with a size threshold attached.

⚠️ Warning: This article is a plain-language summary, not legal advice. The Act’s enforcement decree and government guidelines fill in a lot of operational detail, and interpretation is still settling. If your product has meaningful Korean exposure, talk to a lawyer who practices Korean tech law rather than relying on a blog post.
a wooden gavel and block resting on a marble surface

Photo by Tingey Injury Law Firm on Unsplash

Penalties Are Modest, at Least for Now

Administrative fines top out at 30 million KRW, roughly $21,000. That covers things like failing to notify users that AI is in use, refusing to appoint a required domestic representative, or ignoring a corrective order.

Compared to the EU AI Act, where penalties climb into the tens of millions of euros or a percentage of global turnover, that is a rounding error for a large company. Korea also announced a one-year grace period before penalties are fully enforced, giving companies room to adjust.

📌 Note: Low fines don’t make the law toothless. Korean regulators can investigate, demand documentation, and issue corrective orders, and reputational exposure in a market where domestic platforms dominate can matter more than the fine itself.
🔍 Why a modest fine is not the whole exposure: The cost of being investigated rarely appears in the penalty figure. Document requests, a corrective order with a deadline, and the engineering time to satisfy it all land before any fine does, and a corrective order left unmet becomes its own separate breach.

How It Differs From the EU AI Act

Both laws sort AI by risk, but the philosophies diverge. The EU’s framework leans precautionary, with outright prohibited categories of AI. Korea’s version has no equivalent banned list, uses a simpler risk taxonomy, and pairs its obligations with active government support: funding, data centers, and training data for domestic AI development.

One concrete example of that lighter touch is labeling. Deepfake content requires clear, visible disclosure, but for AI output that isn’t deepfake material, an invisible digital watermark is acceptable rather than a visible on-screen label. That is a meaningfully more product-friendly rule than a blanket visible-label mandate.

office towers in central Seoul where companies must comply with the new AI law

Photo by Felix on Unsplash

💬 What Other Users Say: Korean industry commentary on the Act has been split rather than uniformly positive. Startup-side voices have raised concerns about compliance overhead landing hardest on small teams, while civil society groups have argued the opposite, that the penalties and obligations are too weak to change behavior. The government has signaled it will calibrate rules based on real-world feedback during the grace period.

If you’re evaluating AI tools rather than building them, the practical takeaway is smaller: expect to see more explicit “this is AI” disclosures in products serving Korean users. Our guide on how to tell if text was written by AI covers why those disclosures matter more than detection tools do.

FAQ: Frequently Asked Questions

When did the Korea AI Basic Act take effect?

January 22, 2026. Korea became the first country to bring a comprehensive AI law into full force, ahead of the EU AI Act, which is still phasing in its obligations over a multi-year schedule.

Does it apply to my company if I’m not in Korea?

Possibly. The Act applies to AI activity that affects Korean users or the Korean market, regardless of where the company sits. The domestic representative requirement only kicks in above specific revenue or user thresholds, but transparency obligations aren’t limited by company size.

What counts as high-impact AI?

AI used in critical domains such as healthcare, energy, nuclear operations, biometric analysis, and decisions made by public authorities. Operators in these areas carry the heaviest obligations, including human oversight and explaining how the system reached a given outcome.

How large are the penalties?

Administrative fines reach up to 30 million KRW, about $21,000, far below EU AI Act levels. A one-year grace period applies before penalties are fully enforced.

Do I have to label AI-generated content?

If you serve Korean users, generally yes. Deepfake-style synthetic media requires clearly recognizable disclosure, while other AI-generated output can satisfy the requirement with an invisible digital watermark instead of a visible label.