South Korea - AI Responsibility Bill

AI Responsibility and Regulation Bill

AI 책임 및 규제 법안

South Korea

RAI-KR-NA-ARRACXX-2023
Withdrawn(Withdrawn)
BillGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

The "AI Responsibility and Regulation Bill" (proposed by Representative Ahn Cheol-soo on 8 August 2023) sought to classify AI into prohibited, high‑risk, and low‑risk categories, impose disclosure and safety obligations on providers, require periodic national AI planning, and introduce a confirmation/verification regime for banned and high‑risk systems. The bill was proposed during the 21st National Assembly but lapsed at the end of the term.

Overview

The "AI Responsibility and Regulation Bill" proposed by Representative Ahn Cheol‑soo in August 2023 sought to create a South Korea‑specific, risk‑based framework that distinguishes between prohibited, high‑risk, and low‑risk artificial intelligence systems and assigns legal duties accordingly. The proposal emphasized preventing systems that could cause bodily or mental harm, undermining democratic rights, or enabling invasive surveillance. It proposed a national coordination mechanism and 3‑year basic planning cycle for AI policy. Key summaries and public notices about the bill are available from government regulatory notice services and contemporary press coverage; see the official regulatory notice for the bill (KOTRA/Ombudsman entry — bill notice) and contemporaneous reporting by national outlets (Segye Ilbo coverage).

Definitions

The bill defines "artificial intelligence" broadly as software that implements human intellectual capabilities by electronic means (learning, perception, judgment, understanding natural language, etc.). "Algorithm" is defined as an organized set of computational steps, rules, or logic for problem solving, task execution, or operation of devices. The bill distinguishes between: (a) Prohibited AI — systems that exploit subconscious manipulation, produce indistinguishable synthetic media without disclosure, compute social scores harming groups, or enable real‑time remote biometric ID for law enforcement; (b) High‑risk AI — systems materially affecting life, safety, health, or basic rights (energy & water, medical care and medical devices, critical infrastructure, employment/credit decisions, transport, public sector systems); and (c) Low‑risk AI — general purpose and benign systems subject to baseline transparency and documentation duties.

Governance and Institutional Framework

The bill assigns the lead coordinating role to the Ministry of Science and ICT and contemplates an AI Committee to conduct review, classification of risk categories, and to advise on the national AI basic plan every three years. The AI Committee would have authority to review confirmation requests for classifying systems as prohibited or high‑risk and to recommend oversight actions. The bill also envisions cooperation with other agencies (e.g., the Ministry of Health and Welfare for medical AI, the Ministry of Land, Infrastructure and Transport for transport systems, and the Personal Information Protection Commission for privacy matters) to ensure cross‑sectoral enforcement and specialized technical review. See the administrative notice and explanatory material published with the bill's consultation entry (regulatory notice).

Key Focus Areas

The bill focuses on: (1) Prohibitions — creating categories of systems that would be banned from development, deployment, or operation; (2) High‑risk controls — mandatory impact assessments, prior verification/confirmation, safety testing, and stricter transparency/disclosure rules for systems in critical sectors; (3) Disclosure obligations — mandatory notice to users when biometric sensing or synthetic media generation is used and clear labeling where outputs may be indistinguishable from reality; (4) Documentation & audits — mandatory developer logs, technical documentation, and incident reporting to enable audits and redress; (5) Rights & remedies — user rights to information, contest adverse automated decisions, and seek remedy; and (6) National planning — a 3‑year national AI basic plan to align policy, safety standards, and review priorities. These focus areas reflect the bill's attempt to balance innovation support with precautionary safety measures.

Implementation Framework

Under the proposed implementation structure, AI business operators developing or deploying classified systems would be required to: (a) perform risk assessments and maintain technical documentation; (b) submit confirmation or registration filings for prohibited and high‑risk systems where the AI Committee or designated regulator requires prior review; (c) implement safety testing and mitigation measures; (d) notify users (and where required, regulators) of use of biometric sensing or generation of photorealistic media; and (e) cooperate with oversight inspections. The Ministry of Science and ICT and associated agencies would publish technical guidance and a schedule for when confirmation or registration would be required. The bill contemplated delegating detailed standards to subordinate regulations to allow technical updates as the field evolves.

Monitoring and Evaluation

The bill establishes monitoring powers for the lead ministry and authorizes requests for information, on‑site inspections, and targeted audits for systems classified as high‑risk or suspected to be prohibited. It further tasks the AI Committee to review programmatic outcomes and to update the 3‑year basic plan. Monitoring metrics include incident reports, verified safety test results, compliance with disclosure obligations, and remedial actions taken by operators. The bill anticipates coordination with privacy and consumer protection authorities for complaint handling and enforcement.

Penalties, Liability, and Appeals

The proposal outlines administrative sanctions for violations (notices, corrective orders, fines) and contemplates civil liability for harm caused by covered AI systems. It provides for appeal mechanisms against administrative determinations, including confirmation/registration decisions and penalties, with judicial review consistent with existing administrative law procedures. The bill also contemplates enhanced penalties for negligent operation of high‑risk systems leading to serious bodily harm or violation of fundamental rights.

Relationship to Other Instruments

At the time of filing, the bill sat alongside other parliamentary AI proposals (e.g., other representatives' AI accountability bills) and government initiatives to produce AI guidelines. The policy landscape ultimately evolved toward a consolidated "AI Basic Act" approach in subsequent legislative sessions; Ahn's bill was one of several inputs and was recorded as lapsed when that parliamentary term ended. The bill was intended to complement sectoral laws (medical device law, personal information protection statute) rather than replace them.

International Alignment

The bill draws on risk‑based regulatory trends visible in international discussions (notably the EU AI Act's risk‑tiered approach and global debates on bans for the most harmful uses). It sought to align South Korea's approach with global best practices by using a three‑tier risk classification, mandatory transparency for synthetic content, and sectoral safeguards for healthcare and critical infrastructure. The bill also foresaw cooperative information‑sharing with foreign regulators on harmful models and cross‑border incident response.

Implementation Timeline

MilestoneDate
Representative filing (대표발의)2023-08-08
Public consultation / 입법예고 (administrative notice)2023-08-30
Press coverage / public debateAug–Sep 2023
End of term / bill lapsed (임기만료 폐기)2024-05-29

Compliance Checklist

RequirementOperator action
Classification check (prohibited/high/low)Assess system against statutory criteria; seek confirmation if uncertain
Disclosure obligationsLabel synthetic media; notify biometric sensing to users
Risk assessmentConduct and document impact assessments for high‑risk systems
Registration/confirmationFile for confirmation/registration where required and maintain records
Incident reportingReport safety incidents to regulator within specified timeframe

Sources and References

SourceType
KOTRA/Ombudsman regulatory notice — "인공지능 책임 및 규제법안" (bill consultation entry)Primary Source
"안철수, AI 규제법안 발의... 위험한 인공지능 정의하고 3년마다 기본계획 수립" — Segye Ilbo (press)Secondary Source
"AI 전쟁 뛰어들 기업도 없는데…규제부터 내놓은 국회" — Hankyung (press)Secondary Source
Plain English

While ultimately not enacted, South Korea's proposed AI Responsibility and Regulation Bill aimed to establish a comprehensive, risk-based framework for artificial intelligence, primarily impacting developers and operators of AI systems within the country.

The bill sought to classify AI systems into three tiers: prohibited, high-risk, and low-risk, assigning legal duties accordingly. Prohibited AI systems would have included those exploiting subconscious manipulation, producing synthetic media without clear disclosure, computing social scores that harm groups, or enabling real-time remote biometric identification for law enforcement. High-risk systems, materially affecting life, safety, health, or basic rights (like in medical care, critical infrastructure, or employment decisions), would have faced stringent controls.

Key obligations for AI operators would have included: - Conducting mandatory impact assessments and prior verification for high-risk systems. - Implementing safety testing and mitigation measures. - Providing clear disclosure to users when biometric sensing or synthetic media generation is used, especially if outputs are indistinguishable from reality. - Maintaining technical documentation and reporting incidents to regulators.

Violations could have led to administrative sanctions, such as corrective orders and fines, with potential civil liability for harm caused by covered AI systems. The bill also envisioned enhanced penalties for negligent operation of high-risk systems resulting in serious harm or rights violations.

A crucial point for product managers and founders is that this bill lapsed at the end of the parliamentary term and never became law. However, it offers valuable insight into South Korea's regulatory thinking and potential future directions for AI governance, reflecting global trends towards risk-based regulation and transparency for synthetic content. It signals areas where future legislation is likely to focus.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under South Korea - AI Responsibility Bill. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalDefinitions (a) Prohibited AI

    Applies to: All AI business operators.

    Prohibited AI — systems that exploit subconscious manipulation
  2. #2CriticalDefinitions (a) Prohibited AI

    Applies to: All AI business operators.

    Prohibited AI — systems that... produce indistinguishable synthetic media without disclosure
  3. #3CriticalDefinitions (a) Prohibited AI

    Applies to: All AI business operators.

    Prohibited AI — systems that... compute social scores harming groups
  4. #4CriticalDefinitions (a) Prohibited AI

    Applies to: All AI business operators.

    Prohibited AI — systems that... enable real-time remote biometric ID for law enforcement
  5. #5CriticalImplementation Framework (a)Before placing on market

    Applies to: AI business operators developing or deploying high-risk AI systems.

    perform risk assessments and maintain technical documentation
  6. #6CriticalImplementation Framework (b)Before placing on market

    Applies to: AI business operators developing or deploying high-risk AI systems.

    submit confirmation or registration filings for prohibited and high-risk systems where the AI Committee or designated regulator requires prior review
  7. #7CriticalImplementation Framework (c)Before placing on market

    Applies to: AI business operators developing or deploying high-risk AI systems.

    implement safety testing and mitigation measures
  8. #8ImportantKey Focus Areas (3)

    Applies to: AI business operators deploying AI systems using biometric sensing.

    mandatory notice to users when biometric sensing... is used
  9. #9ImportantKey Focus Areas (3)

    Applies to: AI business operators deploying AI systems generating synthetic media.

    clear labeling where outputs may be indistinguishable from reality
  10. #10ImportantKey Focus Areas (4)

    Applies to: AI business operators.

    mandatory developer logs, technical documentation
  11. #11ImportantKey Focus Areas (4)

    Applies to: AI business operators.

    incident reporting to enable audits and redress
  12. #12ImportantKey Focus Areas (5)

    Applies to: AI business operators whose systems make automated decisions affecting users.

    user rights to information, contest adverse automated decisions
  13. #13ImportantImplementation Framework (e)

    Applies to: AI business operators developing or deploying classified systems.

    cooperate with oversight inspections

© Regulations.AI — created on 13-Jun-2026