South Korea - User Protection for Generative AI Services
Generative AI Service User Protection Guideline
생성형 인공지능 서비스 이용자 보호 가이드라인
South Korea
RAI-KR-NA-GASUPXX-2025Issued by the Korea Broadcasting and Communications Commission (KCC), this non‑binding framework sets four core principles and six implementation measures aimed at protecting users of generative AI services (text, audio, image) in Korea. Targeted at developers and service providers, the guideline focuses on human‑centred design, explainability, safety, fairness, input data management, transparency, and remedial mechanisms, and will be reviewed biennially.
Summary
The "Generative AI Service User Protection Guideline" (생성형 인공지능 서비스 이용자 보호 가이드라인) was published by the South Korea Broadcasting and Communications Commission (KCC) on 28 February 2025 and came into effect on 28 March 2025. The guideline is a practical, industry‑facing framework aimed at preventing and mitigating user harm arising from generative AI services — including text, audio, and image generation — and to establish best practices for responsible deployment and operation. The guideline was prepared with input from the Information and Communication Policy Institute (KISDI) and a multi‑stakeholder research group and includes illustrative good‑practice examples drawn from live services to improve adoptability. The instrument is presented as a voluntary (guidance) framework rather than a statute, but the KCC positions it as the baseline for expectation in the sector and reserves the option to revisit regulatory measures or statutory instruments if necessary.
The framework is structured around four fundamental principles: (1) Human‑centred generative AI services; (2) Ensuring explainability of decision processes; (3) Safe and secure operation; and (4) Fairness and non‑discrimination. To operationalize those principles, the guideline lays out six execution approaches: (i) protection of users' personality and dignity (including measures against defamatory or privacy‑infringing outputs such as non‑consensual deepfakes); (ii) efforts to disclose and explain the decision‑making process (including clear labelling of AI‑generated content and provision of information about how outputs are produced); (iii) measures to respect and preserve diversity (bias mitigation and filtering of discriminatory outputs); (iv) governance of input data collection and reuse (informed consent, accountable data governance, designated responsible officers); (v) responsibility and participatory mechanisms for problem solving (responsibility allocation, reporting channels, and remediation processes); and (vi) healthy distribution and dissemination practices (controls on sharing, content moderation, and user guidance).
Key operational expectations include establishing internal monitoring and reporting systems, implementing content‑ and input‑filtering layers to detect high‑risk outputs, documenting model design choices and safety evaluations, providing clear user notices when content is AI generated, and obtaining appropriate consent when user inputs will be used for model training. The guideline highlights particular harms of concern — deceptive or manipulated media (including sexual exploitation through deepfakes), privacy breaches from input reuse, discriminatory outputs, and other safety failures — and recommends concrete mitigations such as safety testing, human‑in‑the‑loop review for high‑risk outputs, and user redress channels.
While the guideline itself does not prescribe statutory fines, it signals that non‑adoption or clear disregard for the guidance may lead to reputational consequences and referrals to relevant enforcement authorities under existing laws (e.g., personal data protection and communications regulations). The KCC will review the guideline every two years from the effective date to assess adequacy and consider potential legislative or enforcement steps. The document expressly targets both domestic and foreign developers and service providers whose services are offered to users in South Korea, and it includes sectoral references and examples to increase applicability across contexts such as media, education, health and finance. Official materials, press releases, and the final PDF are hosted on the KCC website and are cross‑referenced by South Korea policy briefing and KISDI materials used in the development process. (Primary sources: KCC press release and downloadable guideline.)
Full article
Read full text ↗Overview
The "Generative AI Service User Protection Guideline" was published by the South Korea Broadcasting and Communications Commission (KCC) on 28 February 2025 and entered into effect on 28 March 2025. The guideline is a practical, non‑binding framework for generative AI developers and service providers that sets out four core principles and six implementation approaches to prevent harms associated with AI‑generated text, audio and images. It was developed through a joint KCC‑KISDI research process and stakeholder consultations; the final text and accompanying examples are available from the KCC website for download. The document emphasises proactive risk management, transparency about AI generation, protection of personality and human dignity, and institutional responsibility for remedial measures, with an explicit two‑year review cycle to ensure the guidance stays current as the technology evolves. See the KCC announcement and download page for the full text: KCC – Press release and guideline (PDF).
Definitions
The guideline defines key terms used throughout the text in service‑oriented language: "generative AI services" (systems that create novel content such as text, images, audio, or video derived from learned patterns); "inputs" (user provided prompts, images, voice samples and other training/use data); "outputs" (generated artefacts delivered to users); "user harm" (including privacy invasion, defamation, discriminatory outcomes, and facilitation of illegal acts); and "service provider/developer" (entities operating or delivering generative AI systems). Definitions are functional and tailored to implementation, emphasizing the operational boundary between pre‑trained models, fine‑tuning/continued learning, and runtime generation. The guideline also uses the term "personality rights" to capture harms to reputation, likeness, and identity arising from generated outputs.
Governance and Institutional Framework
The guideline places responsibility on both developers and service providers to adopt corporate governance measures that align with the four principles. It recommends appointing a designated responsible officer for generative AI user‑protection, creating cross‑functional oversight committees (compliant with guidance models reviewed with KISDI), documenting risk‑acceptance processes, and instituting internal monitoring and reporting channels. The KCC encourages collaboration with sectoral regulators (e.g., data protection authorities and consumer protection bodies) and suggests that larger or consumer‑facing services adopt formal accountability mechanisms similar to internal audit or external assurance programs. The document explicitly references the consultative design process used by KCC and KISDI during development; readers can consult KISDI materials and KCC announcements for background: KISDI conference materials and KCC announcement.
Key Focus Areas
The guideline’s execution measures concentrate implementation on six operational priorities: (1) protection of users’ personality and dignity — including detection and control algorithms to prevent non‑consensual likeness generation and defamation; (2) disclosure and explainability — requiring clear labelling of AI‑generated content and provision of accessible information on model behaviour and limitations; (3) respect for diversity and fairness — encouraging bias assessment, filtering tools for discriminatory outputs, and reporting channels for biased results; (4) input data governance — emphasising prior informed consent for using user inputs in training and clarity about retention/use; (5) responsibility and participation in problem solving — expecting providers to define roles and remediation paths and to provide accessible complaint and take‑down procedures; and (6) healthy distribution practices — promoting moderation, platform controls, and contextual guidance to limit spread of harmful outputs. The guideline includes practical examples and suggested controls so operators can apply a risk‑based approach proportional to their service footprint and user base. These focus areas are consistent with KCC’s view of immediate harms (deepfakes, biased outputs, privacy risks) and are intended to be read in conjunction with other national laws and sectoral obligations: KCC guideline.
Implementation Framework
The recommended implementation approach is risk‑based and iterative: providers should (a) map use cases and user populations to identify high‑risk flows; (b) undertake pre‑deployment safety testing and red teaming; (c) apply layered mitigations (input sanitization, output filters, human review on high‑risk outputs); (d) publish transparency materials for users (labels, model fact sheets, high‑level decision flow descriptions); and (e) establish incident response and remediation workflows including user complaint channels, correction/takedown procedures, and post‑incident reporting. The guideline provides examples and checklists to help small and large operators adopt measures proportionate to scale and risk. It also suggests governance artifacts (role descriptions, monitoring dashboards, periodic risk reviews) as practical deliverables for compliance and external scrutiny. For background on the development and stakeholder engagement, see KCC and conference materials: policy briefing (South Korea.kr) and KISDI materials.
Monitoring and Evaluation
The guideline asks providers to maintain monitoring and evaluation programs that combine automated detection metrics (false‑positive/false‑negative rates for harmful output detection), qualitative reviews, user feedback channels, and periodic public reporting of adoption of protections. Providers are encouraged to log inputs and outputs (subject to applicable privacy rules), conduct periodic audits of bias and safety controls, and update models or filters in response to observed failures. The KCC states it will review the guideline’s effectiveness on a two‑year cycle and will consider adjustments or statutory steps based on empirical monitoring and stakeholder feedback. See the KCC release for the stated review cadence: KCC – review commitment.
Penalties, Liability, and Appeals
As a guideline (framework), the document does not itself impose administrative fines; instead it creates an expected baseline of practice that can inform future enforcement actions or referrals. The KCC explains that failure to adopt reasonable protective measures may lead to reputational consequences and to investigations or enforcement actions under existing statutes (for example, personal data protection rules, broadcasting and communications laws, or other consumer protection regimes). The guideline therefore recommends that providers maintain records of measures taken and remediation actions to demonstrate due diligence. It also advises providers to design accessible user appeals and remediation routes for contesting outputs and seeking corrections or takedowns. For the official framing and caveats about enforcement, consult the KCC announcement: KCC press release.
Relationship to Other Instruments
The guideline is positioned to complement existing Korean laws and sectoral regulation — including national personal data protection rules, network and information security rules, telecommunications and broadcasting statutes, and consumer protection measures — and to serve as a practical bridge between technical risk controls and legal obligations. The KCC collaborated with KISDI and other agencies during development; it frames the guidance as interoperable with international instruments and as an input into potential future legislation should voluntary adoption prove insufficient. Providers should map obligations under this guidance to obligations under the Personal Information Protection Act (PIPA) and other applicable statutes in South Korea when designing compliance programs.
International Alignment
The guideline references international best practices and ongoing global policy debates and is intentionally framed to align with common principles found in other national and regional approaches (risk‑based oversight, transparency, human‑centred safeguards, and accountability). While not a legal instrument for cross‑border enforcement, the document signals South Korea’s intent to harmonize expectations for generative AI safety with international frameworks and to coordinate with technical and policy partners. The KCC referenced international examples and engaged external experts during preparation (see KISDI and KCC materials): KISDI and KCC.
Implementation Timeline
| Milestone | Date |
|---|---|
| Publication (press release and guideline posted) | 2025-02-28 |
| Effective date (recommended start of adoption) | 2025-03-28 |
| First scheduled review (biennial) | 2027-03-28 (or earlier if required) |
Sources and References
| Source | Type |
|---|---|
| "생성형 인공지능 서비스 이용자 보호 가이드라인" – KCC press release and attachments (including PDF) | Primary Source |
| South Korea.kr policy briefing – announcement summary | Secondary/Official Communications |
| KISDI – AI service user protection conference materials | Research / Supporting Material |
Requirements for a company
What an organisation has to do under South Korea - User Protection for Generative AI Services, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
13- Obtain prior informed consent for using user inputs in training.Providers and developers of generative AI services.
- Implement algorithms to prevent non-consensual likeness generation and defamation.Providers and developers of generative AI services.
- Implement filtering tools for discriminatory outputs.Providers and developers of generative AI services.
- Clearly label all AI-generated content for users.Providers of generative AI services.
- Provide accessible complaint and take-down procedures for users.Providers of generative AI services.
- Designate a responsible officer for generative AI user protection.Developers and service providers of generative AI.
- +7 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under South Korea - User Protection for Generative AI Services, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers and developers of generative AI services. | Obtain prior informed consent for using user inputs in training. “emphasising prior informed consent for using user inputs in training and clarity about retention/use” | Before using user inputs for training | Key Focus Areas (4) | Critical |
| 2 | Providers and developers of generative AI services. | Implement algorithms to prevent non-consensual likeness generation and defamation. “including detection and control algorithms to prevent non-consensual likeness generation and defamation” | Before placing on market | Key Focus Areas (1) | Critical |
| 3 | Providers and developers of generative AI services. | Implement filtering tools for discriminatory outputs. “encouraging bias assessment, filtering tools for discriminatory outputs, and reporting channels for biased results” | Before placing on market | Key Focus Areas (3) | Critical |
| 4 | Providers of generative AI services. | Clearly label all AI-generated content for users. “requiring clear labelling of AI-generated content and provision of accessible information on model behaviour and limitations” | Before placing on market | Key Focus Areas (2) | Important |
| 5 | Providers of generative AI services. | Provide accessible complaint and take-down procedures for users. “to provide accessible complaint and take-down procedures” | Before placing on market | Key Focus Areas (5) | Important |
| 6 | Developers and service providers of generative AI. | Designate a responsible officer for generative AI user protection. “recommends appointing a designated responsible officer for generative AI user-protection” | — | Governance and Institutional Framework | Important |
| 7 | Developers and service providers of generative AI. | Conduct pre-deployment safety testing and red teaming. “undertake pre-deployment safety testing and red teaming” | Before deployment | Implementation Framework | Important |
| 8 | Providers of generative AI services. | Establish incident response and remediation workflows. “establish incident response and remediation workflows including user complaint channels” | Before placing on market | Implementation Framework | Important |
| 9 | Providers of generative AI services. | Maintain monitoring and evaluation programs for AI outputs. “asks providers to maintain monitoring and evaluation programs that combine automated detection metrics” | — | Monitoring and Evaluation | Important |
| 10 | Providers and developers of generative AI services. | Maintain records of measures taken and remediation actions to demonstrate due diligence. “recommends that providers maintain records of measures taken and remediation actions to demonstrate due diligence” | — | Penalties, Liability, and Appeals | Important |
| 11 | Providers of generative AI services. | Provide accessible information on model behavior and limitations to users. “provision of accessible information on model behaviour and limitations” | Before placing on market | Key Focus Areas (2) | Important |
| 12 | Providers and developers of generative AI services. | Conduct periodic audits of bias and safety controls. “conduct periodic audits of bias and safety controls” | — | Monitoring and Evaluation | Important |
| 13 | Providers and developers of generative AI services. | Map use cases and user populations to identify high-risk flows. “map use cases and user populations to identify high-risk flows” | Before deployment | Implementation Framework | Important |
Related Regulations
Generative AI Ethics Guidebook (NIA / KCC – sectoral guide for generative AI)
South Korea96% similar
인공지능 발전과 신뢰 기반 조성 등에 관한 기본법
South Korea92% similar
AI Privacy Risk Management Model (안전한 AI·데이터 활용을 위한 AI 프라이버시 리스크 관리 모델) - Personal Information Protection Commission
South Korea92% similar
인공지능(AI) 보안 안내서
South Korea91% similar
Human-Centered Artificial Intelligence Ethics Standards (National AI Ethics Standards)
South Korea91% similar
© Regulations.AI · updated on 13-Jun-2026 · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash