South Korea is now the second jurisdiction in the world — and the first in Asia-Pacific — with a comprehensive, binding AI law in force. The AI Basic Act took full legal effect on January 22, 2026, consolidating roughly 20 competing bills into one framework, and it applies to foreign companies whose AI affects Korean users just as readily as it applies domestically. If your compliance program only maps the EU, US states, and China, this is the gap most global AI governance programs currently have.

How Korea Got to One Law From Twenty Bills

By late 2024, South Korea's National Assembly had roughly 20 separate AI governance bills circulating simultaneously, each introduced independently by different members after the chamber's new term began in June 2024. Rather than let that fragment into competing, overlapping statutes, the Assembly consolidated them into a single framework: the Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust — officially Act No. 20676, universally shortened to the AI Basic Act or AI Framework Act. It passed the National Assembly on December 26, 2024, was promulgated January 21, 2025, and took full effect exactly one year later, on January 22, 2026, alongside its Enforcement Decree.

Who It Applies To

The Act distinguishes between "AI development business operators" (companies that build AI) and "AI utilization business operators" (companies that deploy AI-embedded products or services) — and both categories are in scope, not just developers. Its extraterritorial reach is explicit and confirmed: it applies to any foreign business whose AI activities affect users in the Korean market, with no exemption for AI hosted or developed entirely outside Korea. This extends further than many compliance teams initially assume — HR systems, performance-evaluation tools, and recruitment algorithms used inside a Korean subsidiary's office fall under the Act's "high-impact AI" employment category regardless of where the underlying system was actually built or hosted.

The Two Thresholds That Matter Most

Category Threshold / Scope
High-impact AI Employment, healthcare, financial services, public safety, education — mandatory lifecycle risk management, impact assessments, compliance reporting
High-performance ("advanced") AI Cumulative training compute of at least 1026 FLOPs — roughly 10x the EU AI Act's GPAI systemic-risk threshold

That compute threshold is worth pausing on if you already track the EU AI Act's GPAI systemic-risk threshold of 10²⁵ FLOPs — Korea set its bar an order of magnitude higher, meaning the Act's most stringent advanced-AI obligations realistically only reach a small handful of global frontier-model developers, not the broader population of companies building on top of them.

Generative AI Transparency Rules

Providers of high-impact or generative AI must notify users in advance that they're interacting with AI. For AI-generated content, disclosure requirements are use-case dependent: in-service outputs — a chatbot reply, a game asset, a metaverse interaction — can often satisfy disclosure through UI notices, badges, or interface explanations, while synthetic content that can be downloaded, shared, or exported (particularly image, video, or audio realistic enough to be mistaken for authentic) is expected to carry clearer, more persistent labeling.

The Grace Period You Need to Plan Around

MSIT (the Ministry of Science and ICT), which implements the Act, has explicitly framed its posture as "minimum regulation" during the transition. A grace period of at least one year from January 22, 2026 defers fact-finding investigations and administrative fines except in exceptional cases involving serious social harm — loss of life or human-rights violations are the examples MSIT has specifically named. Substantive compliance obligations technically apply from day one regardless; the grace period softens enforcement, not the underlying legal requirement. A multi-stakeholder AI Basic Act Institutional Improvement Task Force, with more than 40 members across industry, academia, and civil society, launched in March 2026 specifically to refine implementation details during this window — meaning some open questions about scope and documentation are still being actively worked out even as the law is technically in force.

Governance Architecture

  • National AI Committee — a control tower chaired by the President, overseeing national AI policy and harmonizing regulatory approaches across ministries.
  • AI Policy Center — responsible for strategic and industry development, plus international cooperation on AI governance norms.
  • AI Safety [Research] Institute — evaluates AI risk, develops safety benchmarks, and addresses deepfake-related harms specifically.

Alongside these new bodies, Korea's existing Personal Information Protection Act (PIPA) continues to apply in full — the AI Basic Act supplements rather than replaces data-protection obligations, so an AI system touching personal data needs both tracks addressed.

Regulation Paired With Industrial Promotion

Unlike the EU AI Act's predominantly restrictive posture, roughly half of Korea's AI Basic Act is oriented toward actively promoting the domestic AI industry: government support for R&D, data centers, SME and startup funding, technical standardization, and workforce development sit in the same statute as the safety and transparency obligations. This dual structure — guardrails and industrial policy in one bill — is a genuinely distinct model worth understanding on its own terms rather than assuming it maps cleanly onto either the EU's risk-tier approach or the UK's principles-based, regulator-led model.

What to Do If You Have Any Korean Market Exposure

  • Classify your AI systems against both thresholds — high-impact sector exposure and the 10²⁶ FLOPs compute bar are assessed independently, and most companies will only need to worry about the former.
  • Don't assume a Korean subsidiary's internal tools are out of scope. HR and recruitment AI used domestically inside a Korean office is explicitly captured as high-impact employment AI, regardless of where it was built.
  • Build disclosure into generative AI products now, distinguishing in-service outputs from exportable synthetic content — the labeling expectations differ meaningfully between the two.
  • Use the grace period for documentation, not delay. Substantive obligations are already legally in force; the grace period affects enforcement posture, not the underlying compliance clock.
  • Layer ISO 42001 or NIST AI RMF documentation practices onto Korean-specific requirements rather than building a parallel program — the underlying lifecycle risk management and impact-assessment work overlaps substantially with what both frameworks already ask for.

Frequently Asked Questions

When did South Korea's AI Basic Act take effect?

January 22, 2026, alongside its Enforcement Decree — exactly one year after promulgation on January 21, 2025.

Does the AI Basic Act apply to foreign companies?

Yes. It applies extraterritorially to any foreign business whose AI activities affect users in the Korean market, with no exemption for AI developed or hosted entirely outside Korea.

What is the compute threshold for "high-performance AI" under the Act?

10²⁶ cumulative FLOPs of training compute — roughly ten times the EU AI Act's GPAI systemic-risk threshold of 10²⁵ FLOPs — meaning it primarily reaches large frontier-model developers rather than most companies building applications on top of existing models.

Are fines being enforced immediately?

Not generally. A grace period of at least one year from January 22, 2026 defers fact-finding investigations and administrative fines except in exceptional cases involving serious social harm, such as loss of life or human-rights violations. Substantive legal obligations still apply from the effective date regardless.

Quick answer

South Korea's AI Basic Act took effect January 22, 2026, making it the second comprehensive AI law globally after the EU AI Act and the first in Asia-Pacific. It covers "high-impact AI" in sectors like employment and healthcare, sets a 10²⁶ FLOPs threshold for advanced AI, applies extraterritorially to foreign companies, and is in a grace period deferring most fines through at least January 2027.

Related reading: the EU AI Act's current 2026-2028 timeline, China's layered AI regulatory framework, and the UK's principles-based alternative to comprehensive AI law.