South Korea - AI Industry Promotion (AIPTRXX/2022)

AI Industry Promotion and Trust-Building Bill

AI 산업 진흥 및 신뢰 구축 법안

South Korea

RAI-KR-NA-AIPTRXX-2022
Proposed(Officially filed for action)
BillGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

Proposed by Rep. Yoon Doo‑hyun on 7 December 2022, the 'AI Industry Promotion and Trust‑Building' bill aimed to promote AI industry development while establishing baseline measures to secure public trust. The draft emphasized a pro‑innovation principle (often described as 'prior permission, subsequent regulation' / 'prior permissive, post‑regulatory' approach), introduced obligations for high‑risk AI uses (disclosure and reliability measures), and proposed governance structures for national AI strategy coordination.

Overview

The 'AI Industry Promotion and Trust‑Building' bill submitted by Representative Yoon Doo‑hyun on 7 December 2022 was framed as a dual‑track legislative proposal that combined statutory measures to promote South Korea's AI industry with baseline legal duties to secure public trust in AI products and services. The bill gained attention because it explicitly embodied a 'prior permissive, subsequent regulatory' approach (Korean: 우선허용·사후규제) — an orientation aimed at rapid industrial deployment while reserving ex‑post corrective powers for harms. That design made the bill a nucleus for subsequent legislative consolidation and debate. For a snapshot of the bill and its role in later legislative consolidation see the National Assembly information portal and contemporaneous analyses such as press coverage and stakeholder submissions. For the National Assembly bill information system see National Assembly — Bill Search. For stakeholder input on this specific proposal see the Business Software Alliance submission at BSA (submission on bill #18726).

Definitions

The proposal defined key terms to draw regulatory boundaries: 'Artificial Intelligence' (broad systems that perform tasks using algorithms and data), 'high‑risk AI' (AI used in areas with significant potential impacts on life, safety, fundamental rights or public order), 'AI business operator' (entities that develop, provide, or operate AI systems), and 'generative/large‑scale AI' (models that produce text, images or other content). The draft typically aligned definitions pragmatically with existing Korean IT and data laws to facilitate inter‑operation across ministries and avoid duplicative definitions. Definitional choices were central to later debate because they determine the suite of systems subject to mandatory safeguards and disclosure duties.

Governance and Institutional Framework

The bill proposed a layered governance architecture: (1) a national coordinating mechanism to set strategic priorities and the multi‑year basic plan; (2) a national AI support center to execute promotion policy (grants, tech assistance, clusters); and (3) delegated authority to line ministries for sectoral enforcement. In committee debates these roles were debated intensively with proposals to place the oversight body under the President, the Prime Minister, or as an expert council. The practical duties assigned to the Ministry of Science and ICT (and related agencies) included preparation of a 3‑year AI basic plan, standards and conformity coordination, and operational oversight of reliability testing and certification programs. See contemporaneous reporting on committee consolidation for details: Maeil Business (MK) and legislative trackers such as Hankyung — Legislative Explorer.

Key Focus Areas

The proposal focused on the following substantive policy areas: industry promotion (funding, cluster/center supports, public‑private partnership incentives), tiers of AI risk governance (lighter rules for low‑risk experimentation; higher obligations for high‑risk uses), transparency (notice to users when services rely on AI and explicit labelling for generative AI outputs), trust and reliability (documentation, technical records, risk management systems), conformity and certification (voluntary-to-mandatory pathways for high‑risk AI), and enforcement (administrative corrective powers and sanctions for non‑compliance). The bill's high‑risk category list (healthcare, finance, employment, public administration, critical infrastructure) reflected international practice and was a central point of debate because it triggered stronger duties for operators. For press analysis of the tension between innovation and safety see AJU News.

Implementation Framework

Implementation was designed to be operationalized by the Ministry of Science and ICT in cooperation with other ministries and a designated national AI center. The bill included provisions for: issuing implementing regulations (presidential/delegated acts) to specify technical standards for disclosure and documentation; a phased approach for sectoral implementation of high‑risk obligations; pilot certification programs to foster domestic conformity assessment capacity; and funding authorizations for industry promotion and public interest research. The framework envisioned a mix of obligatory duties for clearly‑defined high‑risk applications and supportive measures (grants, training, R&D tax incentives) to accelerate domestic capability building.

Monitoring and Evaluation

Monitoring relied on periodic reporting obligations by AI business operators, obligations to retain technical documentation and logs, and government fact‑finding powers to request or inspect records. The bill proposed 3‑year strategic reviews tied to the national AI basic plan and required publication of progress reports to improve policy transparency. It also envisioned metrics for industry growth and safety incidents to evaluate whether the preferential promotional regime was generating acceptable trade‑offs between innovation and public protection.

Penalties, Liability, and Appeals

To balance promotion with enforceability the bill established administrative enforcement tools: corrective orders, administrative fines, temporary suspension of services and, in serious cases, referral for criminal investigation under existing statutes where willful misconduct or gross negligence caused harm. It further provided for administrative review and judicial appeal rights for regulated entities. The exact quantum of fines and procedural details were left to implementing regulations or later legislative consolidation, which became a point of negotiation in committee proceedings.

Relationship to Other Instruments

The bill was drafted to interact with South Korea's existing legal ecosystem: the Personal Information Protection Act (privacy/data), telecom and electronic communications law (network safety), consumer protection statutes, product safety frameworks, and sectoral rules (health, finance). It proposed regulatory coordination mechanisms to reduce overlap and set rules for cross‑border data flows when relevant. The need to align with other domestic laws and with international instruments (e.g., EU AI Act trends) was frequently highlighted by stakeholders.

International Alignment

The bill explicitly sought to position South Korea competitively with major AI jurisdictions by adopting a pro‑innovation stance while importing elements of international best practice (risk‑based focus, transparency duties for generative systems, conformity pathways). Internationally‑oriented provisions included support for cross‑border testing programs, recognition of foreign certificates where appropriate, and encouragement for industry to comply with international standards to facilitate export competitiveness. Commentators noted parallels and divergences with the EU AI Act and UK 'pro‑innovation' approaches, and recommended continued alignment where practicable.

Implementation Timeline

MilestoneDate / Planned Date
Bill proposed (Rep. Yoon Doo‑hyun)2022‑12‑07
Stakeholder submissions (BSA commentary)2023‑02‑13
Committee consolidation & alternative drafting2023–2024 (iterative)
AI Basic Law (consolidated package) — National Assembly passage2024‑12‑26 (consolidated law passed into AI Basic Law)

Compliance Checklist

RequirementApplicability
Assess whether system falls within 'high‑risk' categoriesAll AI business operators offering systems in regulated sectors
Provide prior notice to users for high‑risk AIHigh‑risk uses (health, finance, employment, safety‑critical)
Maintain technical documentation and recordsOperators of high‑risk and large‑scale systems
Implement risk management & monitoringOperators above size/impact thresholds
Cooperate with fact‑finding requests from authoritiesAll operators subject to oversight

Sources and References

SourceType
National Assembly — Bill Search / 의안정보시스템Primary Source (legislative information system)
BSA — Submission on '인공지능 육성 및 신뢰 확보에 관한 법률안' (Bill #18726)Primary Source (stakeholder submission)
Maeil Business (MK) — coverage of committee progressSecondary / Press
AJU News — reporting on Rep. Yoon's advocacySecondary / Press
Plain English

This South Korean bill, though later consolidated into a broader law, laid the groundwork for regulating artificial intelligence (AI) by promoting industry growth while establishing trust and safety measures for AI developers and operators.

The bill defined "AI business operators" as entities developing, providing, or operating AI systems. It introduced a "prior permissive, subsequent regulatory" approach, meaning AI innovation could proceed rapidly, with regulations and corrective actions applied *after* deployment if issues arose. A key focus was on "high-risk AI," defined as systems with significant potential impact on life, safety, fundamental rights, or public order, including uses in healthcare, finance, employment, and critical infrastructure. Operators of such high-risk AI would have specific obligations: - Providing prior notice to users when their services rely on AI. - Maintaining technical documentation, records, and robust risk management systems. - Explicitly labeling outputs from generative AI models.

While this specific bill's effective date is unknown, its core elements were incorporated into South Korea's consolidated AI Basic Law package, which passed the National Assembly on December 26, 2024. Enforcement mechanisms included administrative corrective orders, fines, and temporary service suspensions. Serious violations could lead to criminal investigations under existing laws. A practical pitfall for businesses is the "prior permissive, subsequent regulatory" model itself: while it reduces upfront hurdles, it places a heavy burden on operators to ensure compliance and manage risks *after* deployment, with significant penalties if harms occur. This means continuous monitoring and adaptability are crucial, rather than a one-time compliance check.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 9 marked complete

Plain-English obligations under South Korea - AI Industry Promotion (AIPTRXX/2022). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market

    Applies to: All AI business operators.

    tiers of AI risk governance (lighter rules for low‑risk experimentation; higher obligations for high‑risk uses)
  2. #2CriticalBefore placing on market

    Applies to: Operators of high-risk AI systems.

    trust and reliability (documentation, technical records, risk management systems)
  3. #3CriticalContinuously from development

    Applies to: Operators of high-risk and large-scale AI systems.

    obligations to retain technical documentation and logs
  4. #4CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    conformity and certification (voluntary-to-mandatory pathways for high‑risk AI)
  5. #5CriticalBefore providing service to users

    Applies to: Providers of high-risk AI systems.

    transparency (notice to users when services rely on AI and explicit labelling for generative AI outputs)
  6. #6CriticalBefore providing service to users

    Applies to: Providers of generative AI systems.

    transparency (notice to users when services rely on AI and explicit labelling for generative AI outputs)
  7. #7CriticalUpon entry into force of implementing regulations

    Applies to: AI business operators.

    issuing implementing regulations (presidential/delegated acts) to specify technical standards for disclosure and documentation
  8. #8CriticalUpon request

    Applies to: All AI business operators subject to oversight.

    government fact‑finding powers to request or inspect records.
  9. #9CriticalAs specified by regulations

    Applies to: AI business operators.

    Monitoring relied on periodic reporting obligations by AI business operators

© Regulations.AI — created on 13-Jun-2026