Page title background (PC version)Page title background (mobile version)

Case Analysis / Legal Updates

Daeryun Law LLC, with expertise across practice areas,
provides analysis of court rulings and legal issues.

AI Framework Act | What the AI Framework Act, Taking Effect Next January, Requires Companies to Prepare

The AI Framework Act is scheduled to take effect on January 22, 2026. This article summarizes Korea's first comprehensive statute regulating artificial intelligence and outlines the matters that affected companies should prepare.

CONTENTS
  • 1. AI Framework Act | Korea Establishes an AI Regulatory Framework, Following the EU
  • 2. AI Framework Act | Legal Definitions and Five Key Provisions
  • 3. AI Framework Act | The Government's Stance on Ethical Standards and Strengthened Responsibility
    • - Obligations of Transparency, Notification, and User Protection Imposed on Companies
  • 4. AI Framework Act | A Summary of the Government's Role, Support, and Policy
  • 5. AI Framework Act | Company Preparations and Key Response Strategies
    • - Ensuring Safety and Accountability at the Service Stage
    • - Aligning a Global Compliance System with Domestic and International AI Regulatory Trends
    • - Strengthening Organization-Wide AI Ethics, Security, and Operational Training and Procedures
  • 6. AI Framework Act | Competitiveness in the Industry Must Be Built on AI Literacy

1. AI Framework Act | Korea Establishes an AI Regulatory Framework, Following the EU

Establishment of AI Framework Act regulation

The AI Framework Act, namely the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust, which is Korea's first comprehensive statute regulating artificial intelligence, will take effect next year.

With this Act, Korea becomes the second country, after the EU, to establish a comprehensive AI regulatory framework.

The AI Framework Act aims to balance two pillars: industrial growth on the one hand, and user protection and risk management on the other.

As a result, most companies that provide AI-based services, including those in manufacturing, platforms, finance, and healthcare, fall within its direct scope.

It is an Act under which compliance costs and regulatory risk may vary significantly depending on whether a company has prepared in advance.

The sections below summarize the key provisions of the AI Framework Act, together with the practical response strategies that companies should begin preparing now.

2. AI Framework Act | Legal Definitions and Five Key Provisions

In a rapidly changing AI technology environment, the AI Framework Act sets out core concepts directly in the statute in order to clarify the standards for regulation, protection, and liability.

Article 2 provides the following basic definitions, centered on artificial intelligence systems.

∙ Artificial Intelligence

: The electronic implementation of human intellectual abilities, such as learning, reasoning, perception, judgment, and language comprehension

∙ High-Impact Artificial Intelligence

: An artificial intelligence system that has a significant effect on, or may pose a risk to, human life, physical safety, and fundamental rights

∙ Generative Artificial Intelligence

: An artificial intelligence system that imitates the structure and characteristics of input data to generate text, sound, images, video, and other various outputs

∙ Artificial Intelligence Industry

: An industry that develops, manufactures, produces, or distributes products using artificial intelligence or AI technology, or that provides related services

∙ Artificial Intelligence Business Operator

: A person engaged in business related to the artificial intelligence industry who falls under any of the following items, including corporations, organizations, individuals, and state agencies

Accordingly, not only AI software but also robots equipped with it, sensor-based automation devices, and edge devices may all become subject to regulation.

With these clear definitional provisions, companies are now able to identify which of their services qualify as AI and which categories they fall under.

3. AI Framework Act | The Government's Stance on Ethical Standards and Strengthened Responsibility

Article 27 of the AI Framework Act clearly provides that the government is the entity responsible for addressing AI ethics issues.

Accordingly, the government may establish and announce AI ethics principles that reflect the following elements.

∙ Safety
∙ Reliability
∙ Accessibility and fairness
∙ Human dignity
∙ Community values

In addition, the Minister of Science and ICT is responsible for developing implementation measures to give practical effect to the ethics principles and for promoting the spread of ethical awareness throughout society through education and outreach.

This will also serve as a standard for companies when they establish their AI policies and internal guidelines.

Obligations of Transparency, Notification, and User Protection Imposed on Companies

Article 31 of the AI Framework Act imposes the following core obligations on AI business operators.

In particular, when a company uses high-impact AI or generative AI, ensuring transparency is mandatory.

1. Obligation to Ensure Transparency

▷ Provide advance notice that the product or service is based on high-impact AI or generative AI

▷ Clearly indicate that an output was generated by generative AI

▷ Where the operator provides "virtual outputs," such as images or audio resembling reality

▷ An obligation to label or give notice so that users can immediately recognize this

A violation may result in an administrative fine of up to 30 million won, so companies should review and adjust their UI/UX, notice wording, and customer guidance standards in advance.

2. Obligation of Advanced Risk Management

Article 32 of the AI Framework Act imposes on AI business operators an obligation to ensure safety based on the entire AI life cycle.

In particular, large-scale AI models whose cumulative computational amount used for training exceeds the threshold set by Presidential Decree will be subject to enhanced safety standards.

The principal obligations that companies must carry out are as follows.

∙ Identify and assess potential risks in advance throughout the AI development, use, and disposal stages

∙ Establish risk-mitigation measures to prevent the occurrence of incidents

∙ Build a system for continuous monitoring of safety incidents and prompt response

∙ Periodically submit safety-related information to the government (the Minister of Science and ICT)

4. AI Framework Act | A Summary of the Government's Role, Support, and Policy

The government's role and support under the AI Framework Act

The AI Framework Act also sets out the government's responsibilities.

∙ Establishment of AI policy directions (the National Artificial Intelligence Committee)

∙ Ensuring AI safety (operation of the Artificial Intelligence Safety Institute)

∙ Promotion of technology development, industry support, and standardization

∙ Policies to cultivate specialized personnel and secure overseas talent

∙ Operation of an AI-related regulatory and supervisory system

In particular, as the draft Enforcement Decree was officially announced for public comment beginning in November 2025, concrete and practical provisions began to take shape on matters such as the criteria for determining high-impact AI, the obligation to give notice of generative AI outputs, the obligation to ensure safety, and AI impact assessments.

The government is broadly gathering opinions from industry and experts, and it plans to provide companies with a preparation period by allowing a grace period of at least one year for administrative fines at the outset.

For companies, this means that the government's regulatory direction, support direction, ethical standards, and supervisory standards are being realized within a single framework.

Accordingly, private companies should also promptly review and align their internal AI strategies, risk-management processes, and transparency notification systems.

5. AI Framework Act | Company Preparations and Key Response Strategies

With the enforcement of the AI Framework Act, companies will be placed in an environment where they must demonstrate the accountability, transparency, and safety of their AI development and operations.

In particular, the more a company deals with high-risk and high-impact AI, the greater its exposure to sanctions and damages if it is insufficiently prepared, so a proactive response strategy is needed.

In the era of the AI Framework Act, a preventive management system that applies legal and ethical standards from the early stages of AI development is central.


When securing training data, companies must thoroughly check for copyright infringement, and because Korea has no text and data mining (TDM) exemption, they must carefully review whether the data meets the standard under Article 35-5 of the Copyright Act (fair use of works).

Compliance with the Personal Information Protection Act must also be a baseline, and companies must systematically satisfy the legal requirements at each data-processing stage, including pseudonymization or anonymization, obtaining consent, and assessing lawful grounds.

Along with this, companies should establish dataset review to minimize algorithmic bias, the introduction of XAI (explainable artificial intelligence, a technology that explains the AI decision-making process so that humans can understand it), and an accuracy-verification system based on performance metrics (such as the F1-score).


Companies should also identify whether the AI under development qualifies as high-impact artificial intelligence and review at an early stage the additional obligations required by the AI Framework Act, such as ensuring the possibility of human intervention.

Ensuring Safety and Accountability at the Service Stage

At the stage where an AI model is provided as an actual service, the lawfulness, safety, and user protection of the outputs are the key issues.

A filtering and verification system is needed to prevent, in advance, the possibility that AI-generated content infringes copyrights, its similarity to existing works, and the generation of false information through hallucination.

Companies must also have technical measures in place to prevent the generation of illegal or harmful content, such as deepfakes and hate speech.

Because user input data (prompts) may contain personal information, companies must align their operating policies so that they fully satisfy the requirements of the Personal Information Protection Act, including consent, the principle of minimal collection, purpose limitation, and the protection of user rights (such as the right to demand an explanation, the right to refuse, and the right to demand review).

By establishing complaint-handling and remedy systems, companies should also strengthen accountability at the service stage.

Aligning a Global Compliance System with Domestic and International AI Regulatory Trends

Companies must build a compliance system that responds not only to Korea's AI Framework Act but also to multiple global regulatory frameworks, such as the EU AI Act and the U.S. FTC guidelines.


In particular, companies entering the EU market must meet demanding conditions, such as risk classification, CE certification, the establishment of a quality management system (QMS), and transparency obligations, so early preparation is needed.


Within Korea, the obligation to identify high-impact AI, the assurance of safety and transparency, and compliance with human-centered principles are mandatory, so companies must operate an integrated compliance policy that considers domestic and overseas regulations at the same time.

Strengthening Organization-Wide AI Ethics, Security, and Operational Training and Procedures

Because AI is not an issue for the development department alone, a company-wide ethics and security training system is indispensable.

Continuous training is needed so that developers, planners, marketing, CS, and operations personnel can all understand matters such as AI ethics principles, data-processing standards, copyright and personal-information rules, and the notification obligations under the AI Framework Act.

In particular, the user-rights procedures that apply to automated processing of personal information must be closely coordinated with the operations and CS departments.

In addition, even after development, an AI model may experience model drift, in which its performance declines over time.

Accordingly, regular performance verification, bias review, safety testing, and a retraining process are indispensable, and a separate incident-response and contingency plan must also be prepared.

When an incident such as a model malfunction or security breach occurs, a system that can quickly restore operations is also key to reducing legal liability.

A system that analyzes user feedback and reflects it in model improvements is likewise an indispensable component in enhancing a company's reliability.

6. AI Framework Act | Competitiveness in the Industry Must Be Built on AI Literacy

Through the National Artificial Intelligence Committee and the Artificial Intelligence Safety Institute, the government is putting in place its policy directions, safety standards, standardization efforts, and supervisory framework.

Accordingly, companies should connect these national policies with their internal AI strategies to establish an AI governance system.

By building a collaborative structure among functional departments such as technology development, data management, legal and compliance, security, and planning, and by operating documented internal rules, companies can minimize the cost of regulatory compliance.

The enforcement of the AI Framework Act carries meaning beyond stronger regulation, and it may herald a shift toward a structure in which companies that use AI safely and responsibly lead the market.

Technological capability alone is no longer sufficient, and data management, transparency, quality control, and adherence to ethical standards become new competitive factors.

In particular, for companies that use high-impact AI and generative AI, the ability to respond to regulation across the entire life cycle, from notification obligations to ensuring safety, protecting personal information, and continuous monitoring, becomes a key asset that determines the company's trustworthiness.

If you have any questions regarding internal controls for AI, risk management, the determination of high-impact AI, or responding to future regulatory risk, you are welcome to have your company's AI operating framework assessed on a tailored basis by an attorney experienced in corporate matters who can advise on the artificial intelligence industry.

Watch related video content
for this case study.

  1. AI basic laws, check out the video

Background

Daeryun's Key Strengths

Daeryun's exclusive AI · IT
litigation strategies
Over 260
key members
1,200+ cases
handled monthly

* January 2026 Bar Association Transit Permit Issuance Criteria

*Complies with Korean Bar Association Advertising Regulations Article 4 Paragraph 1

Attorney
Legal consultation booking

All consultations are conducted by specialized lawyers after reviewing the case. It is carried out on a reservation basis to ensure a professional process.We encourage you to make an early reservation for consultation, and request adherence to the scheduled time. We will do our best to provide a satisfying consultation.

Phone
consultation 1800-7905

Available 24/7, 365 days
for consultation requests

Phone booking

KakaoTalk
consultation

KakaoTalk channel

Daeryun Law Firm Attorneys

KakaoTalk booking

Online
consultation

We provide tailored
legal services.

Online booking
Related Information
Quick Menu

KakaoTalk