South Korea AI Regulation Overview
South Korea AI Regulation Overview
South Korea
RAI-KR-NA-SUMMARY-2026Tracked instruments in South Korea
22 instruments tracked — 9 In Force, 6 Withdrawn, 4 Adopted, 1 Proposed, 1 Superseded, 1 In Force (Amended). Built directly from our records, so — unlike the article below — it cannot go stale.
South Korea has established a comprehensive AI regulatory framework anchored by the Framework Act on the Development of Artificial Intelligence and Establishment of Trust (in force 2026) and the national AI Action Plan (2026–2028). The regime combines risk-based binding rules for High-Impact AI with extensive privacy and security guidelines.
Full article
Overview
South Korea's legal and policy landscape for artificial intelligence is anchored by the Framework Act on the Development of Artificial Intelligence and Establishment of Trust (commonly referred to as the AI Basic Act), which was enacted on January 21, 2025, and came into full effect on January 22, 2026. This landmark statute positions South Korea among the early pioneering nations with a comprehensive statutory framework regulating artificial intelligence. Operating alongside the AI Basic Act is the statutory Republic of Korea AI Action Plan 2026–2028 (approved February 25, 2026), which sets out 99 execution tasks and over 300 policy recommendations aimed at embedding AI across government, industry, and society to elevate the country into a top-three global AI power by 2028.
South Korea's regulatory journey evolved from foundational strategic documents and ethical guidelines into formal binding statutes and detailed regulatory standards. Early initiatives included the National Strategy for Artificial Intelligence (2019), the Human-Centered Artificial Intelligence Ethics Standards (2020), the Digital Strategy of South Korea (2022), and the Charter on the Values and Principles for a Digital Society of Mutual Prosperity (Digital Bill of Rights, 2023). These policy charters established baseline principles—freedom, fairness, safety, innovation, and solidarity—and laid the groundwork for subsequent statutory amendments to the Personal Information Protection Act (PIPA) and the eventual consolidation of parliamentary bills into the AI Basic Act.
Regulatory Approach
South Korea employs a hybrid regulatory approach that combines binding statutory obligations with extensive soft law guidelines and administrative frameworks. Under the AI Basic Act, the regulatory scheme is explicitly risk-based and tiered. It distinguishes general-purpose AI from High-Impact AI—defined as systems that significantly affect or pose risks to human life, physical safety, or fundamental rights in critical domains such as healthcare, energy, transportation, hiring, loan reviews, and biometric analysis. Operators of High-Impact AI are subject to mandatory risk assessments, lifecycle management, and explanation duties, while providers of Generative AI are subject to user notifications and synthetic content labeling/watermarking.
To foster technological innovation without imposing premature legal barriers, South Korea maintains a general policy stance of prior permissive development combined with targeted ex-post regulation ("allow first, regulate later" in pilot and sandbox contexts). This approach is complemented by detailed operational guidelines issued by central agencies, including the MSIT/KISA AI Security Guide (2025), the KCC Generative AI Service User Protection Guideline (2025), the PIPC AI Privacy Risk Management Model (2024), and PIPC criteria for processing publicly available data for model training.
Key AI Legislation
- Framework Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act) (Enacted 2025, Effective Jan 22, 2026): Landmark primary statute establishing core definitions, obligations for High-Impact AI and Generative AI, extraterritorial applicability, and presidential-level governance.
- Personal Information Protection Act (PIPA) Amendment on Automated Decisions (Enacted 2023, Effective March 15, 2024): Core data privacy statute granting data subjects rights to refuse, request explanation, or seek human review for fully automated decisions that materially affect rights or obligations.
- Act on the Development and Supply (Distribution) of Intelligent Robots (Enacted 2008, Amended 2020 & 2023): Primary sector-specific law regulating quality certification, outdoor mobile robot safety, and ethical design for intelligent robotics.
- Republic of Korea AI Action Plan 2026–2028 (Approved Feb 25, 2026): Three-year statutory national execution roadmap under Article 6 of the AI Basic Act detailing 99 tasks across three policy axes.
- Notice on Personal Information Impact Assessment (PIPC Notice Amendment) (Effective Sept 5, 2025): Mandates AI-specific Privacy Impact Assessment (PIA) evaluation criteria for public institutions covering AI learning/development and operation/management.
- Legislative Precursors and Lapsed Proposals: Consolidated legislative efforts drew from several member bills during the 21st National Assembly, including the Basic Act on AI Technology (2020), the AI Promotion and Trust-Building Bill (2021), the Act on Algorithms and Artificial Intelligence (2021), the AI Industry Promotion and Trust-Building Bill (2022), and the AI Responsibility and Regulation Bill (2023).
Governance & Enforcement Bodies
National AI policy and oversight are structured through a coordinated multi-tier institutional framework. At the apex sits the National AI Strategy Committee (국가인공지능전략위원회), a presidential-level control tower chaired by the President. The committee deliberates on strategic national plans, reviews progress under the AI Action Plan, and aligns inter-ministerial policy direction. Supporting this high-level authority, the Ministry of Science and ICT (MSIT) serves as the lead central administrative ministry responsible for formulating three-year national basic plans, promoting industry R&D, and issuing lifecycle security requirements in collaboration with the Korea Internet & Security Agency (KISA).
Data protection and privacy compliance across AI lifecycles are overseen by the Personal Information Protection Commission (PIPC), an independent central authority empowered to enforce PIPA, issue impact assessment rules, and monitor automated decision-making. Media, user protection, and communications oversight are handled by the Broadcasting and Communications Commission (KCC) in cooperation with the National Information Society Agency (NIA) and the Information and Communication Policy Institute (KISDI). Specialized statutory bodies established under recent legislation include the AI Safety Research Institute (dedicated to technical risk evaluations and standards) and the AI Policy Center.
Penalties & Enforcement
Enforcement under South Korea's AI regulatory framework incorporates both administrative sanctions and phased implementation support. To allow AI business operators time to establish internal risk management frameworks and compliance controls, the AI Basic Act includes a one-year grace period before administrative fines are actively enforced following its January 22, 2026 effective date. During this transitional period, regulatory efforts emphasize administrative guidance, compliance assistance, and advisory audits.
Under the Personal Information Protection Act (PIPA) and related administrative notices, non-compliance with statutory privacy obligations triggers administrative corrective orders and fines. For instance, public institutions that fail to perform or submit required Personal Information Impact Assessments (PIAs) face administrative fines up to KRW 30,000,000 under relevant data protection statutes. While voluntary non-binding guidelines (such as the KCC Generative AI User Protection Guideline or the MSIT AI Security Guide) do not directly prescribe statutory fines, disregard for their baseline standards may result in reputational consequences, formal supervisory inspections, or referrals for enforcement under existing primary legislation.
Data Protection Framework
Data protection in AI development and operation is governed primarily by the Personal Information Protection Act (PIPA), as updated by landmark amendments that took full effect in March 2024. PIPA grants individuals specific rights regarding automated decision-making, including the right to receive concise, meaningful explanations, the right to request human review, and the right to refuse fully automated decisions that result in significant adverse legal or personal effects. Controllers must disclose automated decision criteria and processing procedures in advance through accessible privacy policies.
To support AI model training, the PIPC issued specific operational frameworks, including the 2024 Guide on Processing Publicly Available Personal Data for AI Development and Services and the 2024 AI Privacy Risk Management Model. These frameworks clarify that web-scraped or publicly available personal data may be processed for model training under the "legitimate interests" legal basis (Article 15 of PIPA), provided developers pass a three-part test: legitimate purpose, necessity, and a balancing test against data subject rights. Furthermore, public sector AI deployments must satisfy AI-specific Privacy Impact Assessment (PIA) evaluation criteria introduced in September 2025, verifying legal grounds, training data lifecycle management, access controls, and output filtering for hallucinations or personal data leakage.
Sector-Specific Rules
Sector-specific AI deployment is governed through targeted statutory regimes and tailored risk frameworks. In the robotics domain, the Act on the Development and Supply (Distribution) of Intelligent Robots regulates quality certification, performance testing, and operational safety for intelligent robots. Amendments to the Act establish explicit safety standards and operational approvals for outdoor mobile robots operating in public spaces, alongside a mandatory Robot Ethics Charter for developers and suppliers.
In critical domains such as healthcare, medical devices, energy, transportation, employment screening, credit scoring, and biometric analysis, AI applications fall under the statutory classification of High-Impact AI under the AI Basic Act. Operators in these sectors are subject to mandatory pre-deployment risk assessments, continuous lifecycle monitoring, and explanation mechanisms. Furthermore, sectoral regulators (including the Ministry of Health and Welfare and the Ministry of Land, Infrastructure and Transport) collaborate with MSIT and PIPC to apply domain-specific safety checks and specialized technical reviews.
International Alignment
South Korea's AI regulatory architecture is intentionally designed to align with international norms and emerging global standards. The risk-based categorizations, Privacy Impact Assessment (PIA) subfields, and fundamental rights considerations embedded in the AI Basic Act and PIPC frameworks explicitly mirror concepts found in international frameworks such as the EU AI Act (specifically regarding high-risk classification and fundamental rights impact concepts).
Additionally, South Korea's technical guidelines draw directly from global cybersecurity and risk management frameworks. The MSIT/KISA AI Security Guide (2025) incorporates standards from the NIST AI Risk Management Framework (AI RMF 1.0) and the OWASP Top 10 for LLM Applications. Through the Digital Strategy of South Korea and international outreach with bodies such as the OECD, ITU, 3GPP, and G20, South Korea actively seeks to shape global digital governance and standards for trustworthy AI.
Future Developments
Looking ahead, South Korea's AI regulatory trajectory is guided by scheduled legislative and administrative milestones outlined in the AI Action Plan 2026–2028. Key upcoming developments include the rollout of pilot projects in 2026 for an AI Security Vulnerability Reporting and Disclosure System, followed by participation expansion in 2027 and formal legalization targeted for 2028. The government is also developing an 'AI Basic Society Promotion Plan' through broad social deliberation.
Ongoing regulatory updates include biennial formal reviews of the KCC Generative AI Service User Protection Guideline starting in March 2027, as well as continuous revisions to PIPC implementation guides for Personal Information Impact Assessments. Furthermore, as the one-year penalty grace period under the AI Basic Act concludes in early 2027, central administrative agencies will transition from compliance guidance to active supervisory monitoring and enforcement across High-Impact and Generative AI services.
Enforcement Bodies
| Agency | Mandate | Key Powers | Website |
|---|---|---|---|
| National AI Strategy Committee | Presidential control tower overseeing national AI strategy, basic plans, and policy coordination. | Deliberating and resolving national AI policies, approving national AI basic plans, reviewing action plan execution progress. | |
| Ministry of Science and ICT (MSIT) | Lead central ministry for AI strategy, industry promotion, R&D, and AI security guidance. | Formulating 3-year AI Master Plans, overseeing AI Basic Act implementation, publishing technical and security guidelines, allocating R&D funding. | |
| Personal Information Protection Commission (PIPC) | Central administrative authority for personal data protection and privacy impact assessment. | Conducting privacy inspections, issuing corrective orders, imposing administrative fines, establishing AI privacy models and PIA guidelines. | |
| Broadcasting and Communications Commission (KCC) | Regulatory body overseeing broadcasting and communications services and user protection. | Issuing user protection guidelines, conducting compliance reviews, referring violations under communications laws. | |
| AI Safety Research Institute | Dedicated research institute for AI safety and risk evaluation under the AI Basic Act. | Analyzing AI safety risks, developing evaluation criteria, researching safety technologies and standards. | |
| Korea Internet & Security Agency (KISA) | Specialized cybersecurity agency assisting MSIT in AI security and technical support. | Developing security guidelines, assessing cyber threats, providing technical implementation support. | |
| Korea Institute for Robot Industry Advancement (KIRIA) | Specialized agency under MOTIE for intelligent robot industry promotion. | Overseeing robot product certification, safety testing, and industry promotion programs. |
Real enforcement actions
6 entries recorded · ~€5.97B in finesPublic enforcement actions where regulators cited South Korea AI Regulation Overview. Helps you see how the law is actually applied in practice.
- Enforcement orderApr 24, 2025
Personal Information Protection Commission (PIPC) vs Hangzhou DeepSeek Artificial Intelligence Co., Ltd.
Sector: AI / Technology
The PIPC announced preliminary results of its status examination into DeepSeek, issuing corrective recommendations for issues including privacy policies only in Chinese and English, unauthorized data transfers to China and the U.S. without user consent, and AI model training without user consent. Recommendations included creating a Korean privacy policy, ceasing unnecessary data transfers, introducing opt-out options for AI training data, implementing age verification, and destroying unlawfully transferred data.
Source ↗ - Service ban / suspensionFeb 15, 2025
Personal Information Protection Commission (PIPC) vs Hangzhou DeepSeek Artificial Intelligence Co., Ltd.
Sector: AI / Technology
DeepSeek temporarily suspended its application service in Korea as of February 15, 2025, following a recommendation from the PIPC to enhance compliance with the Personal Information Protection Act. This action was taken after the PIPC's analysis identified issues with third-party data transfers and insufficient transparency in DeepSeek's privacy policy.
Source ↗ - FineJan 31, 2025
Personal Information Protection Commission (PIPC) vs Kakao Pay / Apple / Alipay
5.97BFineThe PIPC fined Kakao Pay KRW 5.97 billion for unlawful cross-border transfer of ~40 million users' data to Alipay, and ordered Alipay to destroy the NSF-score algorithm/model it had built from the unlawfully transferred data.
Source ↗ - OtherNov 5, 2024
Personal Information Protection Commission (PIPC) vs Meta Platforms, Inc.
Sector: Social Media / Advertising / Technology
21.62BFineThe PIPC imposed a penalty surcharge and administrative fine on Meta Platforms, Inc. for collecting and using sensitive data, including religious and political views and same-sex marital status, without obtaining consent from approximately 980,000 domestic users. The enforcement also addressed Meta's rejection of access to personal information without legitimate reasons and its failure to implement adequate safeguards against data breaches.
Source ↗ - OtherJul 26, 2023
Personal Information Protection Commission (PIPC) vs OpenAI OpCo LLC
Sector: AI / Technology
3.6MFineThe PIPC imposed an administrative fine and issued improvement recommendations to OpenAI for failing to comply with the notification requirement regarding a data breach incident that impacted 687 South Korean users of ChatGPT Plus. The recommendations included implementing safeguard measures, ensuring compliance with the Personal Information Protection Act, and cooperating with future fact-gathering and monitoring programs.
Source ↗ - OtherApr 28, 2021
Personal Information Protection Commission (PIPC) vs ScatterLab Co., Ltd.
Sector: AI Chatbot / Technology
103.3MFineThe PIPC imposed a fine and corrective orders on ScatterLab for violating the Personal Information Protection Act by using approximately 9.4 billion KakaoTalk conversation sentences from 600,000 users to develop and operate its AI chatbot 'Iruda' without proper consent, encryption, or deletion of personal information. The company also collected personal information of children under 14 without parental consent and processed sensitive information without separate consent.
Source ↗
Related Regulations
More AI regulation in South Korea
- South Korea - Seoul - AI Administration Plan (SAAPXXX/2024)
- Seoul AI Regulation Summary
- South Korea - Automated Decision Rights Guide
- South Korea - AI Industry Promotion (AIPTRXX/2022)
- South Korea - AI Development Framework
- South Korea - AI Regulation Bill (RAI-KR-NA-ALGARIN-2021)
- South Korea - AI Privacy Risk Management
- South Korea - AI Development and Trust (2021)
© Regulations.AI using Gemini 3.6 Flash · updated on 12 Sep 2026