South Korea - AI Responsibility Act
Artificial Intelligence Responsibility Act
인공지능 책임 법안
South Korea
RAI-KR-NA-AIRARXX-2023The AI Responsibility Bill (인공지능책임법) was introduced by Rep. Hwang Hee on 28 February 2023 to establish basic principles for AI development and use, define and regulate 'high‑risk AI', set state and private duties, create dispute‑resolution mechanisms, and require transparency and human oversight to protect life, safety and fundamental rights. The bill aimed to create an institutional framework (national AI plan, PM‑level AI committee, national AI center) and obligations for providers and users of high‑risk AI systems.
Summary
Read full text ↗Plain English
Overview
The Artificial Intelligence Responsibility Act (commonly referred to in Korean coverage as the "AI Responsibility Bill" or "인공지능책임법") was introduced as a stand‑alone draft law by Representative Hwang Hee on 2023-02-28. The draft law sought to establish statutory principles for safe and trustworthy artificial intelligence, to allocate duties between the State and AI operators, to define a category of "high‑risk AI", to create enforceable user rights (including explanation and remedies), and to establish institutional mechanisms for dispute resolution and oversight. The bill was framed as a comprehensive legal attempt to promote beneficial AI uses while restraining or mitigating AI applications that may harm life, bodily integrity, property, or fundamental rights. The proposal was part of legislative activity during the 21st National Assembly but did not complete the legislative process; the draft is recorded as ended (lapsed) with the close of that legislative term.
Definitions
The draft bill included working definitions for core terms used throughout the text, including "artificial intelligence system", "developer", "operator", and "user". The most notable definitional element was the proposed legal concept of "high‑risk AI", which targeted AI uses and deployments that pose a significant risk to life, safety, property, or fundamental rights. Definitions were designed to be technology‑neutral, intended to capture both algorithmic decision‑making systems and generative/learning models insofar as they affected or were deployed in regulated domains. The bill aimed to ensure definitional breadth sufficient to encompass emergent AI applications while enabling risk‑based differentiation of regulatory duties and obligations.
Governance and Institutional Framework
The draft established several institutional elements to implement and oversee the proposed regime. It allocated coordination responsibilities to relevant ministries, notably identifying the Ministry of Science and ICT in coordination roles, and contemplated periodic preparation of a national AI basic plan. The bill proposed the creation of a specialized AI dispute‑mediation or adjustment committee/council to adjudicate or mediate AI‑related disputes and to provide a focused mechanism for resolving claims of harm or for facilitating remediation. The bill anticipated interagency coordination for classification of high‑risk uses and for supervisory activity, envisaging that sectoral authorities and central ministries would collaborate on rulemaking, supervision, and guidance to operationalize obligations. The proposal also referenced the need for standards, conformity mechanisms, and potential insurance arrangements as governance tools.
Key Focus Areas
- Definition and scope of "high‑risk AI" — the bill proposed a legal category for AI applications that impose a substantial risk to life, safety, property, or fundamental rights, with examples including biometric identification, critical infrastructure, personnel assessment, emergency services, credit or essential public services, state investigative/immigration uses, and other high‑impact domains.
- State duties and planning — obligations for the State to prepare and periodically update a national AI plan, coordinate policy across ministries, and establish supervisory or advisory bodies and processes.
- Operator duties — mandatory risk assessments, adoption of technical and organizational measures (robustness, security, data governance), maintenance of documentation and logs, and obligations for pre‑deployment assessment and post‑deployment monitoring for high‑risk systems.
- Transparency and user rights — duties to inform affected users, provide meaningful explanations or information about substantive decisions that affect individuals, and ensure access to remedies and dispute resolution.
- Dispute resolution and remediation — establishment of a specialized AI dispute‑mediation/adjustment body to handle AI‑specific complaints, facilitate compensation, and coordinate remedies alongside existing civil liability channels.
- Cybersecurity, data governance and non‑discrimination — measures to address secure development and operation, recordkeeping of training and validation data, and safeguards against discriminatory outcomes.
- Insurance and financial resilience — provisions encouraging or requiring insurance arrangements or other compensation mechanisms for harms arising from high‑risk AI.
- Standards and conformity — encouragement of industry standards, conformity assessment procedures, and certification or documentation regimes to demonstrate compliance and support supervisory oversight.
Implementation Framework
The draft adopted a risk‑based regulatory architecture. High‑risk AI systems were subject to stronger and more prescriptive duties — including pre‑deployment impact assessments, mandatory technical safeguards for robustness and security, stricter transparency requirements, ongoing monitoring obligations, and the maintenance of detailed development and deployment documentation (such as training data provenance, validation and testing procedures, and change logs). The bill required operators to prepare records to enable oversight and post‑incident review and envisioned that regulators would issue technical guidance and rulemaking to operationalize requirements. It also recommended phased implementation tied to risk classification: immediate obligations for clearly high‑risk uses, and phased or staged obligations for other categories to allow time for standards and conformity mechanisms to be developed. The bill anticipated that formal rulemaking and supervisory instruments would follow enactment to define technical standards, impose conformity assessment procedures, and allocate supervisory responsibilities to competent bodies.
Monitoring and Evaluation
Monitoring and evaluation under the proposed regime were to be supported by supervisory recordkeeping, interagency coordination, and the proposed AI dispute‑mediation/adjustment committee. Operators were required to maintain development and deployment documentation and logs (including training data records, validation and testing outcomes, and impact assessments) so that regulators and adjudicative bodies could review systems after incidents or complaints. The bill envisaged ongoing monitoring obligations for high‑risk systems and empowered regulators to require reporting, conduct audits, and issue binding directions where systems posed imminent dangers. The draft also anticipated regular national AI planning cycles (for example multiyear AI basic plans) to assess policy outcomes, update risk classifications, and refine supervisory and technical standards over time.
Penalties, Liability, and Appeals
The draft provided for administrative enforcement mechanisms including corrective orders, mandatory mitigation steps, disclosure duties, and potential administrative sanctions for non‑compliance with substantive obligations. It envisaged facilitation of compensation and remediation for victims via the specialized dispute‑mediation body in addition to ordinary civil liability channels, and allowed regulators to issue binding directions for high‑risk AI systems that posed imminent danger. The bill sought to balance administrative enforcement tools (orders, fines, mitigation requirements) with dispute resolution pathways geared to AI‑specific harms and to enable victims to obtain practical remedies. Specific penalty amounts or precise civil liability reforms were not finalized in the draft text as introduced; enforcement was framed through the combination of administrative powers and access to mediation/adjustment mechanisms.
Relationship to Other Instruments
The draft was explicitly designed to sit alongside Korea's sectoral regulatory framework and existing statutes rather than to wholly displace them. It referenced coordination with sectoral laws governing transport, medical devices, telecommunications, and other safety regimes, and with personal data protection requirements under Korea's Personal Information Protection Act. The bill aimed to fill gaps specific to AI responsibility that sectoral laws or existing privacy and consumer protections might not fully address, proposing coordination mechanisms so that AI‑specific obligations could be harmonized with sectoral supervision and data protection enforcement.
International Alignment
The bill referenced international regulatory developments and suggested Korea align its risk‑based approach with leading jurisdictions. While the draft did not prescribe adherence to any single foreign instrument, it signalled an intent to consider comparative regulatory models and to align principles and risk‑based categorization with international practice to the extent possible. The proposal intended to position Korean regulatory policy in dialogue with global developments in AI governance and to draw on evolving international standards and guidance in the design of conformity assessment and supervisory arrangements.
Implementation Timeline
| Date | Event |
|---|---|
| 2023-02-28 | Bill introduced (Representative Hwang Hee) |
| 2023-04-29 | Press interview and coverage reporting on bill features (MoneyToday) |
| 2023-05-24 | Bill discussed / referenced in committee and sector reporting |
| 2024-06-28 | Bill status: lapsed/ended with close of legislative term (21st National Assembly) |
Compliance Checklist
| Requirement | Description |
|---|---|
| Risk assessment and impact analysis | Conduct and document pre‑deployment risk and impact assessments for AI systems, with enhanced assessments required for systems classified as high‑risk. |
| Technical and organizational measures | Implement robustness, safety, and security measures; adopt organizational governance (roles, responsibilities) to manage AI risks during development and operation. |
| Documentation and recordkeeping | Maintain comprehensive development and deployment documentation, including training data provenance, validation/testing procedures, change logs, and monitoring records to support oversight and incident review. |
| Transparency and user rights | Provide clear information to users about AI services, offer meaningful explanations or information regarding substantive decisions affecting individuals, and notify users where high‑risk systems are employed. |
| Pre‑deployment assessment and monitoring | For high‑risk AI: perform mandatory pre‑deployment conformity checks/assessments and establish ongoing monitoring and reporting processes post‑deployment. |
| Cybersecurity and data governance | Adopt cybersecurity safeguards and data governance practices to protect integrity of systems and training/operational data and to prevent data breaches or manipulation. |
| Insurance and compensation preparedness | Develop or obtain appropriate insurance arrangements or financial instruments to support remediation and compensation for harms arising from high‑risk AI operations where required or encouraged. |
| Standards and conformity mechanisms | Engage with sectoral and national standards; utilize conformity assessment procedures and certifications where available to demonstrate compliance with statutory duties. |
Sources and References
| Source | Type |
|---|---|
This South Korean bill, which has now lapsed, aimed to create a framework for the responsible development and use of Artificial Intelligence, particularly focusing on systems that pose significant risks to life, safety, property, or fundamental rights. It would have applied to both developers and operators of AI systems, especially those deemed "high-risk." Key obligations included mandatory risk assessments, implementing technical and organizational safeguards like robust security and data governance, and maintaining detailed documentation of AI development and deployment. The bill also sought to ensure transparency for users, requiring explanations for decisions affecting individuals and establishing a specialized committee for dispute resolution and remedies. Although the bill did not pass, it signaled a strong intent to regulate AI through a risk-based approach, with administrative enforcement mechanisms like corrective orders and potential sanctions for non-compliance. A practical pitfall for businesses would have been the need to proactively identify if their AI systems fell into the "high-risk" category, as this would trigger more stringent compliance requirements, including pre-deployment assessments and ongoing monitoring.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 10 marked completePlain-English obligations under South Korea - AI Responsibility Act. Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Before deployment
Applies to: Operators of AI systems
“mandatory risk assessments, adoption of technical and organizational measures... and obligations for pre‑deployment assessment”
- #2Critical⏰ Before deployment (checks), Ongoing (monitoring)
Applies to: Operators of high-risk AI systems
“obligations for pre‑deployment assessment and post‑deployment monitoring for high‑risk systems.”
- #3Critical⏰ Before deployment
Applies to: Operators of AI systems
“adoption of technical and organizational measures (robustness, security, data governance)”
- #4Critical⏰ Ongoing
Applies to: Operators of AI systems
“maintenance of detailed development and deployment documentation (such as training data provenance, validation and testing procedures, and change logs).”
- #5Critical⏰ Before affecting users
Applies to: Operators of AI systems
“duties to inform affected users, provide meaningful explanations or information about substantive decisions that affect individuals”
- #6Critical⏰ Before deployment
Applies to: Operators of AI systems
“safeguards against discriminatory outcomes.”
- #7Critical⏰ Ongoing
Applies to: Operators of AI systems
“measures to address secure development and operation, recordkeeping of training and validation data”
- #8Critical⏰ Ongoing
Applies to: Operators of AI systems
“ensure access to remedies and dispute resolution.”
- #9Important⏰ Before deployment
Applies to: Operators of high-risk AI systems
“provisions encouraging or requiring insurance arrangements or other compensation mechanisms for harms”
- #10Recommended⏰ Before deployment
Applies to: Operators of AI systems
“encouragement of industry standards, conformity assessment procedures, and certification or documentation regimes”
Related Regulations
AI Responsibility and Regulation Bill (Representative: Ahn Cheol-soo, proposed Aug 8, 2023)
South Korea96% similar
Act on Algorithms and Artificial Intelligence
South Korea96% similar
AI Promotion and Trust-Building Bill (Act on Promotion of Artificial Intelligence and Establishment of Trust)
South Korea94% similar
Bill on Artificial Intelligence (Representative: Lee Yong-bin, proposed July 19, 2021)
South Korea93% similar
인공지능 발전과 신뢰 기반 조성 등에 관한 기본법
South Korea92% similar
© Regulations.AI — created on 13-Jun-2026