← All company positions
Naverframework

NAVER ASF 2.0: AI Safety Framework 2.0

Published July 7, 2026 · The English PDF's cover reads Initial Publication Date: July 7, 2026; the Korean PDF gives the same date (최초 제정일: 2026년 7월 7일), and the navercorp.com article hosting both is dated 2026.07.07. Naver's English press release dates the public unveiling to July 8, 2026, at the Seoul Forum on AI Safety & Security; the document's own date, July 7, is used here.

Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.

What it argues for

ASF 2.0 is Naver's revised AI safety framework, and its central move is to shift safety management from models to the services built on them. It recalls that "we established a framework for identifying and managing the risks of frontier AI models through “NAVER ASF (AI Safety Framework) Beta” in 2024", then argues the problem has moved: "AI Safety is no longer just about making a single model safe. It now extends to how we safely design and operate services—built by combining diverse AI models—that serve tens of millions of people." Three changes are given as the reason: Naver's own On-Service AI products (AI Briefing, AI Shopping Agent, AI Tab), the spread of multi-model services, and Korean law — "On January 22, 2026, the Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (hereinafter, the “AI Basic Act”) came into effect." The framework has three pillars joined by an operational structure. A risk taxonomy crosses three subjects of protection (users, members of society, the AI service ecosystem) with "three protected values—protecting life and physical safety, protecting economic value, and preventing unjust discrimination—to form the AI Risk Taxonomy". An impact assessment matrix ties the heaviest duties to Korean law — "The special domain refers to areas where High-Impact AI, as defined under the AI Basic Act, is used" — and for high-impact services there "we conduct a pre-launch impact assessment and continue safety evaluations after launch." Risk management covers safety evaluation, user communication including notices for realistic generated content, and user feedback channels. The operational structure, CHEC 2.0, runs across each service's lifecycle, overseen by an AI Safety Center created in March 2026 and a three-layer oversight system in which "The Board of Directors is the final decision-making body for the AI Safety matters that ASF 2.0 seeks to manage and oversee." The document does not restate the model-level capability thresholds of ASF Beta, and nothing in it addresses catastrophic or frontier-model risk.

Stated positions (16)

  • Safety management moves from the model to the service: "AI Safety is no longer just about making a single model safe. It now extends to how we safely design and operate services—built by combining diverse AI models—that serve tens of millions of people."
  • The same model can carry different risks in different services: "Because the types of risk and required safety levels can vary depending on a service’s domain and scope—even for the same AI model—safety management needs to extend from the model to the service."
  • Multi-model services need checks on how models are combined: "In these environments, safety reviews must go beyond individual models to also examine risks that may emerge from how models are combined and the context in which they are used within a service."
  • Korea's AI Basic Act is named as a driver of the revision: "On January 22, 2026, the Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (hereinafter, the “AI Basic Act”) came into effect."
  • A risk taxonomy crosses subjects of protection (users, the public and the AI service ecosystem) with "three protected values—protecting life and physical safety, protecting economic value, and preventing unjust discrimination—to form the AI Risk Taxonomy".
  • The highest tier is defined by Korean law: "The special domain refers to areas where High-Impact AI, as defined under the AI Basic Act, is used." Services outside it form a general domain, split by whether their scope of use is broad or narrow.
  • High-impact services are assessed before and after launch: "For special domains with a high impact on subjects of protection and protected values, we conduct a pre-launch impact assessment and continue safety evaluations after launch."
  • Low-risk services are handled after launch: "For general domains with a narrow scope of use and a low impact on subjects of protection and protected values, we establish safety measures suited to the service context and then conduct post-launch response and improvement."
  • Safety evaluation is a launch gate plus ongoing monitoring: "Based on the results, we determine whether the service meets our safety standards." and "Even after launch, we conduct ongoing safety evaluations and improvements informed by user feedback and operational insights". No thresholds or pass criteria are published.
  • Realistic generated content is flagged only where confusion or harm is likely: "where generative AI produces outputs that are difficult to distinguish from real content, and there is a risk that users may be misled or harmed, we provide notices in a readily recognizable manner." Watermarking or machine-readable marking is not mentioned.
  • Users get a way to report problems: "NAVER provides channels for users to share feedback or report issues while using AI services."
  • Execution runs through CHEC 2.0, which extends Naver's 2022 AI-ethics consultation process to safety and is "a company-wide operational structure that spans the entire service lifecycle—from the planning of an AI service through to post-launch evaluation."
  • A dedicated safety unit was created in March 2026: "we established the AI Safety Center, a dedicated organization for AI Safety within the Chief Corporate Responsibility Officer (CRO) organization of Team NAVER." It is described as independent: "As a dedicated organization, it maintains its independence while supporting AI Safety management and training".
  • The board has the final say in a three-layer oversight system (service teams execute, the AI Safety Center manages and supports, the board's Risk Management Committee oversees): "The Board of Directors is the final decision-making body for the AI Safety matters that ASF 2.0 seeks to manage and oversee."
  • Outside input is advisory, and reporting is promised: "We enhance the credibility of our governance by seeking advice from independent external experts in AI Safety evaluations and key decision-making processes." and "Through publications such as the NAVER AI Safety Progress Report, we regularly share our AI Safety activities and outcomes, and communicate significant policy developments."
  • AI agents are flagged as the next change in risk: AI services are "expanding into areas where they autonomously reason and act within the scope delegated by users—as in the case of AI agents", and Naver commits to examining the new risks this brings, without yet saying how.

About this document

Published on a navercorp.com article page in the company's AI section, dated 2026.07.07. The page text is in Korean only (the /en/ path serves the same Korean text), but the page attaches an official English PDF of the framework — NAVER_AI Safety Framework 2.0.pdf, 14 pages, headed NAVER ASF 2.0 / AI Safety Framework 2.0 with Initial Publication Date: July 7, 2026 and Managed by: NAVER AI Safety Center — alongside a Korean PDF of the same structure and the September 2026 NAVER AI Safety Progress Report. All quotations in this record are from the English PDF. It has no individual byline and is issued in Naver's corporate voice. After a contents page it runs nine numbered sections: 1 Preface; 2 The Direction of ASF 2.0 (the evolving landscape and an overview of the three pillars and operational structure); 3 Defining and Classifying Risk (the AI Risk Taxonomy); 4 Identifying and Assessing Risk (the AI Impact Assessment Matrix); 5 Managing and Mitigating Risk (safety evaluation and user communication); 6 Operational Structure (CHEC 2.0); 7 AI Safety Governance (including a three-layer management and oversight table); 8 Sharing Our Experience and Insights; 9 Our Path Forward. The English PDF runs to roughly 3,500 words, including its contents page and repeated diagram labels. The only law it names is Korea's AI Basic Act; it cites no foreign law, standard or regulator and asks nothing of government.

How this sits against AI law

Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.

Risk managed at the level of the service, not the model

Because risk and required safety levels vary with a service's domain and scope even for the same model, "safety management needs to extend from the model to the service", including risks "that may emerge from how models are combined" in multi-model services.

European UnionAligned

The Act classifies AI systems as high-risk by their intended purpose (Article 6 and Annex III), so obligations follow the use context rather than the underlying model — the same premise ASF 2.0 adopts.

United StatesAligned

The NIST AI Risk Management Framework is voluntary guidance whose Map function asks organisations to establish the context in which an AI system is used before assessing its risks, the same context-first approach.

Frontier-model and catastrophic risk

ASF 2.0 recalls that ASF Beta addressed frontier-model risk but sets no capability thresholds, names no catastrophic-risk domains and contains no commitment to withhold a model; its risk categories are life and physical safety, economic value and unjust discrimination in services.

European UnionAsks for less

Article 55 requires providers of general-purpose AI models with systemic risk to evaluate them including by adversarial testing, assess and mitigate systemic risks, report serious incidents to the AI Office and ensure cybersecurity. ASF 2.0 does not address systemic model risk; whether any Naver model is a systemic-risk model is not stated.

United StatesAsks for less

SB 53 requires large frontier developers (above 10^26 training operations and $500 million annual revenue) to publish frameworks setting out catastrophic-risk thresholds and mitigations. ASF 2.0 contains no equivalent; nothing public shows Naver is within SB 53's scope, so this compares content, not compliance.

Risk taxonomy covering safety, economic harm and discrimination

Users, members of society and the AI service ecosystem are subjects of protection, combined with "three protected values—protecting life and physical safety, protecting economic value, and preventing unjust discrimination—to form the AI Risk Taxonomy".

European UnionAligned

Article 9 requires the risk management system for high-risk AI systems to identify and analyse known and reasonably foreseeable risks to health, safety or fundamental rights; Naver's three values map onto those, with economic harm made explicit.

United StatesAsks for more

Texas's TRAIGA bars developing or deploying AI with the intent to unlawfully discriminate against a protected class and a list of other intentional harms; Naver commits to screening every service for unjust discrimination and economic harm whatever the intent.

Impact assessment tiered by domain and scope

Services in the special domain — "High-Impact AI, as defined under the AI Basic Act" — get a pre-launch impact assessment and post-launch safety evaluation when impact is high; general-domain services are tiered by breadth of use, and narrow, low-impact ones get safety measures followed by "post-launch response and improvement".

European UnionAligned

The Act sets its heaviest duties on a defined list of high-risk uses (Annex III), requires a risk management system before and during use (Article 9) and, for certain deployers, a fundamental rights impact assessment before first use (Article 27) — a tiered, domain-based model like Naver's.

United StatesAsks for more

America's AI Action Plan sets no impact-assessment duty for private developers or deployers and calls for dismantling unnecessary regulatory barriers; Colorado's SB24-205, which would have required deployer impact assessments for high-risk systems, is recorded as repealed. Naver's pre-launch assessment goes beyond any US federal expectation.

Safety evaluation before launch and monitoring after

Each AI service is evaluated for whether it operates as intended and whether it produces harmful or inaccurate outputs; "Based on the results, we determine whether the service meets our safety standards", and evaluation continues after launch using user feedback and operational insights.

European UnionAligned

Article 9 requires high-risk AI systems to be tested before being placed on the market, and Article 72 requires providers to run a post-market monitoring system that collects and analyses data on performance throughout the system's lifetime.

United StatesAligned

NIST's Generative AI Profile (AI 600-1), voluntary guidance, recommends pre-deployment testing and post-deployment monitoring of generative AI, including feedback from users; Naver's process follows the same pattern and, like the profile, sets no pass criteria.

Disclosure of AI use and generated content

Naver commits to explaining AI use to users at an accessible level, and, where generated output is hard to tell from real content and users could be misled or harmed, to "provide notices in a readily recognizable manner". It says nothing about watermarking or machine-readable marking.

European UnionAsks for less

Article 50 requires providers to ensure people are told when they are interacting with an AI system and to mark all synthetic audio, image, video and text output in a machine-readable, detectable format, not only output likely to mislead; deployers must disclose deepfakes.

United StatesAsks for less

The California AI Transparency Act requires covered generative AI providers (over one million monthly users in California) to embed latent disclosures in generated image, video and audio content, provide a free detection tool and offer visible disclosures — a standing marking duty, where Naver commits only to case-by-case notices.

Board-level governance and a dedicated safety unit

An AI Safety Center set up in March 2026 within the Chief Corporate Responsibility Officer's organisation "maintains its independence while supporting AI Safety management and training"; in the three-layer oversight system "The Board of Directors is the final decision-making body for the AI Safety matters that ASF 2.0 seeks to manage and oversee."

European UnionAsks for more

Article 17 requires providers of high-risk AI systems to have a quality management system including an accountability framework setting out the responsibilities of management and staff, but it does not require board-level decision-making or a dedicated safety unit.

United StatesAligned

SB 53 requires a large frontier developer's published framework to describe its internal governance practices for implementing the framework; Naver discloses who decides, at what level, in the form SB 53 expects, though the Act's scope is frontier developers.

External advice and public reporting

Naver seeks "advice from independent external experts in AI Safety evaluations and key decision-making processes", works with Korea's AI Safety Institute, TTA, Seoul National University's SAPI and the UN Global Compact, and commits to sharing results regularly through the NAVER AI Safety Progress Report.

European UnionAsks for more

The Act's documentation duties for providers (Articles 11 and 53) run to authorities and downstream providers, and the only general public disclosure for general-purpose models is a summary of training content; there is no duty to publish a periodic safety report, which Naver offers voluntarily.

United StatesAsks for less

Illinois's Artificial Intelligence Safety Measures Act (SB 315, effective 1 January 2027) requires large frontier developers to undergo independent third-party audits of their safety protocols. Naver's external experts advise; they do not audit, and ASF 2.0 does not publish their findings.

RAI-US-IL-SB31500-2026Status: Adopted.

AI agents acting on delegated authority

AI services are "expanding into areas where they autonomously reason and act within the scope delegated by users—as in the case of AI agents"; Naver commits to examining the new risks through the same classification, assessment and management cycle, without yet setting specific rules.

European UnionNo equivalent law

The AI Act has no provision specific to AI agents; agents fall under the general rules for AI systems, high-risk uses and general-purpose models according to what they do.

United StatesNo equivalent law

America's AI Action Plan, the closest federal instrument, contains nothing specific to AI agents acting on a user's behalf; the plan's text does not use the word agent at all.

ASF 2.0 is written for Korean law first. It names only Korea's AI Basic Act (Framework Act on the Development of Artificial Intelligence and Establishment of Trust, RAI-KR-NA-SOUTHKO-2025, in force since 22 January 2026) and builds its top risk tier directly on that Act's category of high-impact AI, whose operators must carry out risk management and explanation duties, while the Act's generative-AI rules require users to be notified and outputs labelled. Against the EU AI Act the structure lines up closely, since both attach duties to the use context rather than the model: the special domain corresponds to the Act's high-risk systems, and the pre-launch impact assessment and post-launch evaluation match the Act's risk-management and post-market monitoring duties. Naver's disclosure commitment is narrower than Article 50, though, applying only where "there is a risk that users may be misled or harmed". In the United States there is no federal counterpart — America's AI Action Plan imposes no assessment duty on private companies — and the nearest binding rules are California's content-disclosure law and its frontier-model statute, SB 53. By moving from model-level frontier risk to service-level risk, ASF 2.0 steps away from the model-level catastrophic-risk thresholds that SB 53, Illinois's SB 315 and the EU's systemic-risk duties are built on.

Source

https://www.navercorp.com/media/aiInNaver/buildingAiDetail?seq=10034455
Date on the page:
July 7, 2026
Source checked:
opened and confirmed on 2026-09-30