South Korea AI Regulation Overview

South Korea AI Regulation Overview

South Korea

RAI-KR-NA-SUMMARY-2026
Governance and OversightRisk ManagementData Protection and Privacy
Export PDF

Tracked instruments in South Korea

22 instruments tracked — 9 In Force, 6 Withdrawn, 4 Adopted, 1 Proposed, 1 Superseded, 1 In Force (Amended). Built directly from our records, so — unlike the article below — it cannot go stale.

InstrumentTypeStatusYearEffective
South Korea AI Action Plan 2026-2028PolicyIn Force202625 Feb 2026
South Korea - AI Impact AssessmentRegulationIn Force20255 Sep 2025
South Korea - User Protection for Generative AI ServicesGuidelineIn Force202528 Mar 2025
South Korea AI Security GuideGuidelineIn Force202510 Dec 2025
South Korea AI Trust Framework ActActIn Force202522 Jan 2026
South Korea - AI Privacy Risk ManagementGuidelineIn Force202419 Dec 2024
South Korea - Automated Decision Rights GuideGuidelineAdopted2024—
South Korea - Public Data Processing GuideGuidelineIn Force202417 Jul 2024
South Korea - AI Responsibility ActBillWithdrawn2023—
South Korea - AI Responsibility BillBillWithdrawn2023—
South Korea - Digital Bill of RightsPolicyAdopted2023—
South Korea - Generative AI Ethics GuidebookGuidelineIn Force202328 Dec 2023
South Korea - Personal Data Protection (19234/2023)ActIn Force202315 Mar 2024
South Korea - AI Industry Promotion (AIPTRXX/2022)BillProposed2022—
South Korea - Digital Transformation StrategyPolicyAdopted202228 Sep 2022
South Korea - AI Development and Trust (2021)BillWithdrawn2021—
South Korea - AI Development FrameworkBillWithdrawn2021—
South Korea - AI Regulation Bill (RAI-KR-NA-ALGARIN-2021)BillWithdrawn2021—
South Korea - AI Ethics Standards (2020)GuidelineSuperseded202023 Dec 2020
South Korea - AI Technology Framework (RAI-KR-NA-BATRMXX-2020)BillWithdrawn2020—
South Korea - National AI StrategyPolicyAdopted201917 Dec 2019
South Korea - Intelligent Robot Promotion Act (2008)ActIn Force (Amended)200829 Sep 2008

South Korea has established a comprehensive AI regulatory framework anchored by the Framework Act on the Development of Artificial Intelligence and Establishment of Trust (in force 2026) and the national AI Action Plan (2026–2028). The regime combines risk-based binding rules for High-Impact AI with extensive privacy and security guidelines.

Full article

Overview

South Korea's legal and policy landscape for artificial intelligence is anchored by the Framework Act on the Development of Artificial Intelligence and Establishment of Trust (commonly referred to as the AI Basic Act), which was enacted on January 21, 2025, and came into full effect on January 22, 2026. This landmark statute positions South Korea among the early pioneering nations with a comprehensive statutory framework regulating artificial intelligence. Operating alongside the AI Basic Act is the statutory Republic of Korea AI Action Plan 2026–2028 (approved February 25, 2026), which sets out 99 execution tasks and over 300 policy recommendations aimed at embedding AI across government, industry, and society to elevate the country into a top-three global AI power by 2028.

South Korea's regulatory journey evolved from foundational strategic documents and ethical guidelines into formal binding statutes and detailed regulatory standards. Early initiatives included the National Strategy for Artificial Intelligence (2019), the Human-Centered Artificial Intelligence Ethics Standards (2020), the Digital Strategy of South Korea (2022), and the Charter on the Values and Principles for a Digital Society of Mutual Prosperity (Digital Bill of Rights, 2023). These policy charters established baseline principles—freedom, fairness, safety, innovation, and solidarity—and laid the groundwork for subsequent statutory amendments to the Personal Information Protection Act (PIPA) and the eventual consolidation of parliamentary bills into the AI Basic Act.

Regulatory Approach

South Korea employs a hybrid regulatory approach that combines binding statutory obligations with extensive soft law guidelines and administrative frameworks. Under the AI Basic Act, the regulatory scheme is explicitly risk-based and tiered. It distinguishes general-purpose AI from High-Impact AI—defined as systems that significantly affect or pose risks to human life, physical safety, or fundamental rights in critical domains such as healthcare, energy, transportation, hiring, loan reviews, and biometric analysis. Operators of High-Impact AI are subject to mandatory risk assessments, lifecycle management, and explanation duties, while providers of Generative AI are subject to user notifications and synthetic content labeling/watermarking.

To foster technological innovation without imposing premature legal barriers, South Korea maintains a general policy stance of prior permissive development combined with targeted ex-post regulation ("allow first, regulate later" in pilot and sandbox contexts). This approach is complemented by detailed operational guidelines issued by central agencies, including the MSIT/KISA AI Security Guide (2025), the KCC Generative AI Service User Protection Guideline (2025), the PIPC AI Privacy Risk Management Model (2024), and PIPC criteria for processing publicly available data for model training.

Key AI Legislation

  • Framework Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act) (Enacted 2025, Effective Jan 22, 2026): Landmark primary statute establishing core definitions, obligations for High-Impact AI and Generative AI, extraterritorial applicability, and presidential-level governance.
  • Personal Information Protection Act (PIPA) Amendment on Automated Decisions (Enacted 2023, Effective March 15, 2024): Core data privacy statute granting data subjects rights to refuse, request explanation, or seek human review for fully automated decisions that materially affect rights or obligations.
  • Act on the Development and Supply (Distribution) of Intelligent Robots (Enacted 2008, Amended 2020 & 2023): Primary sector-specific law regulating quality certification, outdoor mobile robot safety, and ethical design for intelligent robotics.
  • Republic of Korea AI Action Plan 2026–2028 (Approved Feb 25, 2026): Three-year statutory national execution roadmap under Article 6 of the AI Basic Act detailing 99 tasks across three policy axes.
  • Notice on Personal Information Impact Assessment (PIPC Notice Amendment) (Effective Sept 5, 2025): Mandates AI-specific Privacy Impact Assessment (PIA) evaluation criteria for public institutions covering AI learning/development and operation/management.
  • Legislative Precursors and Lapsed Proposals: Consolidated legislative efforts drew from several member bills during the 21st National Assembly, including the Basic Act on AI Technology (2020), the AI Promotion and Trust-Building Bill (2021), the Act on Algorithms and Artificial Intelligence (2021), the AI Industry Promotion and Trust-Building Bill (2022), and the AI Responsibility and Regulation Bill (2023).

Governance & Enforcement Bodies

National AI policy and oversight are structured through a coordinated multi-tier institutional framework. At the apex sits the National AI Strategy Committee (국가인공지능전략위원회), a presidential-level control tower chaired by the President. The committee deliberates on strategic national plans, reviews progress under the AI Action Plan, and aligns inter-ministerial policy direction. Supporting this high-level authority, the Ministry of Science and ICT (MSIT) serves as the lead central administrative ministry responsible for formulating three-year national basic plans, promoting industry R&D, and issuing lifecycle security requirements in collaboration with the Korea Internet & Security Agency (KISA).

Data protection and privacy compliance across AI lifecycles are overseen by the Personal Information Protection Commission (PIPC), an independent central authority empowered to enforce PIPA, issue impact assessment rules, and monitor automated decision-making. Media, user protection, and communications oversight are handled by the Broadcasting and Communications Commission (KCC) in cooperation with the National Information Society Agency (NIA) and the Information and Communication Policy Institute (KISDI). Specialized statutory bodies established under recent legislation include the AI Safety Research Institute (dedicated to technical risk evaluations and standards) and the AI Policy Center.

Penalties & Enforcement

Enforcement under South Korea's AI regulatory framework incorporates both administrative sanctions and phased implementation support. To allow AI business operators time to establish internal risk management frameworks and compliance controls, the AI Basic Act includes a one-year grace period before administrative fines are actively enforced following its January 22, 2026 effective date. During this transitional period, regulatory efforts emphasize administrative guidance, compliance assistance, and advisory audits.

Under the Personal Information Protection Act (PIPA) and related administrative notices, non-compliance with statutory privacy obligations triggers administrative corrective orders and fines. For instance, public institutions that fail to perform or submit required Personal Information Impact Assessments (PIAs) face administrative fines up to KRW 30,000,000 under relevant data protection statutes. While voluntary non-binding guidelines (such as the KCC Generative AI User Protection Guideline or the MSIT AI Security Guide) do not directly prescribe statutory fines, disregard for their baseline standards may result in reputational consequences, formal supervisory inspections, or referrals for enforcement under existing primary legislation.

Data Protection Framework

Data protection in AI development and operation is governed primarily by the Personal Information Protection Act (PIPA), as updated by landmark amendments that took full effect in March 2024. PIPA grants individuals specific rights regarding automated decision-making, including the right to receive concise, meaningful explanations, the right to request human review, and the right to refuse fully automated decisions that result in significant adverse legal or personal effects. Controllers must disclose automated decision criteria and processing procedures in advance through accessible privacy policies.

To support AI model training, the PIPC issued specific operational frameworks, including the 2024 Guide on Processing Publicly Available Personal Data for AI Development and Services and the 2024 AI Privacy Risk Management Model. These frameworks clarify that web-scraped or publicly available personal data may be processed for model training under the "legitimate interests" legal basis (Article 15 of PIPA), provided developers pass a three-part test: legitimate purpose, necessity, and a balancing test against data subject rights. Furthermore, public sector AI deployments must satisfy AI-specific Privacy Impact Assessment (PIA) evaluation criteria introduced in September 2025, verifying legal grounds, training data lifecycle management, access controls, and output filtering for hallucinations or personal data leakage.

Sector-Specific Rules

Sector-specific AI deployment is governed through targeted statutory regimes and tailored risk frameworks. In the robotics domain, the Act on the Development and Supply (Distribution) of Intelligent Robots regulates quality certification, performance testing, and operational safety for intelligent robots. Amendments to the Act establish explicit safety standards and operational approvals for outdoor mobile robots operating in public spaces, alongside a mandatory Robot Ethics Charter for developers and suppliers.

In critical domains such as healthcare, medical devices, energy, transportation, employment screening, credit scoring, and biometric analysis, AI applications fall under the statutory classification of High-Impact AI under the AI Basic Act. Operators in these sectors are subject to mandatory pre-deployment risk assessments, continuous lifecycle monitoring, and explanation mechanisms. Furthermore, sectoral regulators (including the Ministry of Health and Welfare and the Ministry of Land, Infrastructure and Transport) collaborate with MSIT and PIPC to apply domain-specific safety checks and specialized technical reviews.

International Alignment

South Korea's AI regulatory architecture is intentionally designed to align with international norms and emerging global standards. The risk-based categorizations, Privacy Impact Assessment (PIA) subfields, and fundamental rights considerations embedded in the AI Basic Act and PIPC frameworks explicitly mirror concepts found in international frameworks such as the EU AI Act (specifically regarding high-risk classification and fundamental rights impact concepts).

Additionally, South Korea's technical guidelines draw directly from global cybersecurity and risk management frameworks. The MSIT/KISA AI Security Guide (2025) incorporates standards from the NIST AI Risk Management Framework (AI RMF 1.0) and the OWASP Top 10 for LLM Applications. Through the Digital Strategy of South Korea and international outreach with bodies such as the OECD, ITU, 3GPP, and G20, South Korea actively seeks to shape global digital governance and standards for trustworthy AI.

Future Developments

Looking ahead, South Korea's AI regulatory trajectory is guided by scheduled legislative and administrative milestones outlined in the AI Action Plan 2026–2028. Key upcoming developments include the rollout of pilot projects in 2026 for an AI Security Vulnerability Reporting and Disclosure System, followed by participation expansion in 2027 and formal legalization targeted for 2028. The government is also developing an 'AI Basic Society Promotion Plan' through broad social deliberation.

Ongoing regulatory updates include biennial formal reviews of the KCC Generative AI Service User Protection Guideline starting in March 2027, as well as continuous revisions to PIPC implementation guides for Personal Information Impact Assessments. Furthermore, as the one-year penalty grace period under the AI Basic Act concludes in early 2027, central administrative agencies will transition from compliance guidance to active supervisory monitoring and enforcement across High-Impact and Generative AI services.

Enforcement Bodies

AgencyMandateKey PowersWebsite
National AI Strategy CommitteePresidential control tower overseeing national AI strategy, basic plans, and policy coordination.Deliberating and resolving national AI policies, approving national AI basic plans, reviewing action plan execution progress.
Ministry of Science and ICT (MSIT)Lead central ministry for AI strategy, industry promotion, R&D, and AI security guidance.Formulating 3-year AI Master Plans, overseeing AI Basic Act implementation, publishing technical and security guidelines, allocating R&D funding.
Personal Information Protection Commission (PIPC)Central administrative authority for personal data protection and privacy impact assessment.Conducting privacy inspections, issuing corrective orders, imposing administrative fines, establishing AI privacy models and PIA guidelines.
Broadcasting and Communications Commission (KCC)Regulatory body overseeing broadcasting and communications services and user protection.Issuing user protection guidelines, conducting compliance reviews, referring violations under communications laws.
AI Safety Research InstituteDedicated research institute for AI safety and risk evaluation under the AI Basic Act.Analyzing AI safety risks, developing evaluation criteria, researching safety technologies and standards.
Korea Internet & Security Agency (KISA)Specialized cybersecurity agency assisting MSIT in AI security and technical support.Developing security guidelines, assessing cyber threats, providing technical implementation support.
Korea Institute for Robot Industry Advancement (KIRIA)Specialized agency under MOTIE for intelligent robot industry promotion.Overseeing robot product certification, safety testing, and industry promotion programs.

Real enforcement actions

6 entries recorded · ~€5.97B in fines

Public enforcement actions where regulators cited South Korea AI Regulation Overview. Helps you see how the law is actually applied in practice.

  1. Enforcement orderApr 24, 2025

    Personal Information Protection Commission (PIPC) vs Hangzhou DeepSeek Artificial Intelligence Co., Ltd.

    Sector: AI / Technology

    The PIPC announced preliminary results of its status examination into DeepSeek, issuing corrective recommendations for issues including privacy policies only in Chinese and English, unauthorized data transfers to China and the U.S. without user consent, and AI model training without user consent. Recommendations included creating a Korean privacy policy, ceasing unnecessary data transfers, introducing opt-out options for AI training data, implementing age verification, and destroying unlawfully transferred data.

    Source ↗
  2. Service ban / suspensionFeb 15, 2025

    Personal Information Protection Commission (PIPC) vs Hangzhou DeepSeek Artificial Intelligence Co., Ltd.

    Sector: AI / Technology

    DeepSeek temporarily suspended its application service in Korea as of February 15, 2025, following a recommendation from the PIPC to enhance compliance with the Personal Information Protection Act. This action was taken after the PIPC's analysis identified issues with third-party data transfers and insufficient transparency in DeepSeek's privacy policy.

    Source ↗
  3. FineJan 31, 2025

    Personal Information Protection Commission (PIPC) vs Kakao Pay / Apple / Alipay

    5.97B
    Fine

    The PIPC fined Kakao Pay KRW 5.97 billion for unlawful cross-border transfer of ~40 million users' data to Alipay, and ordered Alipay to destroy the NSF-score algorithm/model it had built from the unlawfully transferred data.

    Source ↗
  4. OtherNov 5, 2024

    Personal Information Protection Commission (PIPC) vs Meta Platforms, Inc.

    Sector: Social Media / Advertising / Technology

    21.62B
    Fine

    The PIPC imposed a penalty surcharge and administrative fine on Meta Platforms, Inc. for collecting and using sensitive data, including religious and political views and same-sex marital status, without obtaining consent from approximately 980,000 domestic users. The enforcement also addressed Meta's rejection of access to personal information without legitimate reasons and its failure to implement adequate safeguards against data breaches.

    Source ↗
  5. OtherJul 26, 2023

    Personal Information Protection Commission (PIPC) vs OpenAI OpCo LLC

    Sector: AI / Technology

    3.6M
    Fine

    The PIPC imposed an administrative fine and issued improvement recommendations to OpenAI for failing to comply with the notification requirement regarding a data breach incident that impacted 687 South Korean users of ChatGPT Plus. The recommendations included implementing safeguard measures, ensuring compliance with the Personal Information Protection Act, and cooperating with future fact-gathering and monitoring programs.

    Source ↗
  6. OtherApr 28, 2021

    Personal Information Protection Commission (PIPC) vs ScatterLab Co., Ltd.

    Sector: AI Chatbot / Technology

    103.3M
    Fine

    The PIPC imposed a fine and corrective orders on ScatterLab for violating the Personal Information Protection Act by using approximately 9.4 billion KakaoTalk conversation sentences from 600,000 users to develop and operate its AI chatbot 'Iruda' without proper consent, encryption, or deletion of personal information. The company also collected personal information of children under 14 without parental consent and processed sensitive information without separate consent.

    Source ↗

© Regulations.AI using Gemini 3.6 Flash · updated on 12 Sep 2026