메뉴 열기
메뉴 닫기
메뉴 닫기

Recent Developments

|
|
2025.09.19
Korea Releases Draft Enforcement Decree of the AI Framework Act
On September 8, 2025, the Ministry of Science and ICT (MSIT) released the draft Enforcement Decree of the Framework Act on Artificial Intelligence Development and Establishment of a Foundation for Trustworthiness (the AI Framework Act), together with directions for the enactment of subordinate legislation. The draft Enforcement Decree (comprising 34 provisions including the Addenda) was prepared following more than 70 rounds of consultations with diverse stakeholders, including industry, academia, civil society, and relevant ministries. The MSIT emphasized that the draft aims to provide greater clarity on the scope of regulated entities and the criteria for determining whether specific AI systems are subject to statutory obligations, while striking a balance between global regulatory trends and the realities of Korea’s AI industry. In particular, the MSIT highlighted that the draft Enforcement Decree is designed to prioritize promotion of AI development while mitigating regulatory uncertainty and compliance burdens. Public explanatory sessions and consultations with relevant stakeholders are scheduled for the second to fourth weeks of September, during which interested parties may consider submitting their comments. This newsletter highlights the key provisions of the draft Enforcement Decree and their implications for AI businesses. 1. Transparency, Safety, and High-Impact AI Obligations     1) Transparency Obligations         ■ Obligation to provide advance notice             An AI business intending to provide a product or service utilizing high-impact AI or generative AI must provide advance notice by one of the following methods, which may include through terms and conditions, user interfaces, or similar means (Article 22(1) of the draft Enforcement Decree):                 ① stating such fact directly on the product or service (the Products, etc.), or setting it out in a contract, user manual, terms of service, etc.;                 ② displaying such fact on the user’s screen or device;                 ③ posting such fact at the place where the Products, etc. are provided (including places reasonably related thereto) in a manner that is easy to recognize; or                 ④ any other method recognized by the Minister of Science and ICT, taking into account the characteristics of the Products, etc.         ■ Obligation to label outputs generated by generative AI             An AI business may label outputs generated by generative AI in a format that can be recognized by humans or machines (Article 22(2) of the draft Enforcement Decree). The MSIT has indicated that such labeling may take the form of an invisible watermark, and it plans to issue transparency guidelines by December 2025, including unit standards for labeling and examples of the use of invisible watermarks.         ■ Obligation to label deepfake outputs             An AI business, with respect to deepfake outputs (outputs such as virtual sounds, images, or videos generated by an AI system that are difficult to distinguish from reality), shall provide notification or labeling in a manner that enables users to clearly recognize such outputs, taking into account the following (Article 22(3) of the draft Enforcement Decree):                 ① notification or labeling by a method through which users can easily confirm the contents by means of vision, hearing, or by using software, etc.; and                 ② notification or labeling by a method that takes into account the age, physical conditions, and social conditions of the principal users.         ■ Exemptions from transparency obligations             The transparency obligations shall not apply in cases where (i) it is evident, taking into account the product or service name, statements displayed on the user’s screen, or indications on the exterior of the product, that the product or service is operated on the basis of high-impact AI or generative AI, or (ii) the AI system is used solely for the internal business purposes of the AI business (Article 22(4) of the draft Enforcement Decree).     2) Obligation to Ensure Safety         The draft Enforcement Decree defines an AI system subject to the obligation to ensure safety as an AI system whose cumulative computation used for learning is not less than 10²⁶ floating-point operations and which falls within the criteria publicly notified by the Minister of Science and ICT, taking into account the level of development of AI technology and the degree of risk (Article 23(1) of the draft Enforcement Decree).     3) Criteria for High-impact AI         An AI system that may cause a significant impact on, or pose a risk to, human life, physical safety, or fundamental rights, and that is utilized in specified sectors such as energy, healthcare, nuclear power, transportation, and education, shall constitute high-impact AI (Article 2(4) of the AI Framework Act).         The draft Enforcement Decree specifies the criteria for determining whether an AI system constitutes high-impact AI, and provides that the Minister of Science and ICT shall determine such status by comprehensively taking into account (i) the area of use, (ii) the extent, severity, and frequency of risks to fundamental rights, and (iii) the particular characteristics of the area of application (Article 24(2) of the draft Enforcement Decree).         Where an AI business provides products or services utilizing high-impact AI, the AI business shall post on its website, etc., the following matters (Article 26(1) of the draft Enforcement Decree):             ① the key contents of the risk management plan, including the risk management policies and organizational framework, under Article 34(1)(i) of the AI Framework Act;             ② the key contents of the standards and explanation methods under Article 34(1)(ii) of the AI Framework Act;             ③ measures for the protection of users; and             ④ the name and contact information of the person who supervises and manages the relevant high-impact AI.     4) AI Impact Assessment         Where an AI business provides products or services utilizing high-impact AI, the AI business shall endeavor, in advance, to assess the impacts on fundamental rights of individuals (Article 35(3) of the AI Framework Act). Pursuant to the draft Enforcement Decree, the matters to be included in such impact assessment are as follows (Article 27(1) of the draft Enforcement Decree):             ① identification of the subjects who may potentially be affected in their fundamental rights by the products or services utilizing the relevant high-impact AI (including the identification of individuals or groups with certain characteristics);             ② identification of the types of fundamental rights that may be affected in connection with the relevant high-impact AI; and             ③ the contents and scope of the social and economic impacts on fundamental rights of individuals that may arise from the relevant high-impact AI. 2. Operation of a Guidance Period for Administrative Fines and Incentives for Impact Assessments     Under the AI Framework Act, an administrative fine of up to KRW 30 million may be imposed: (i) where advance notice related to transparency has not been made; (ii) where a foreign business exceeding certain thresholds fails to designate a local representative; or (iii) where a corrective order issued for a violation of the AI Framework Act is not complied with (Article 43(1) of the AI Framework Act).     The MSIT has announced that, in order to minimize confusion for companies during the initial enforcement of the AI Framework Act and to achieve an effect substantially equivalent to a regulatory grace period, it will operate a guidance period for administrative fines. The specific duration and details of such guidance period will be finalized through consultation with stakeholders.     In addition, the MSIT has stated that it intends to reduce corporate burdens and provide incentives by offering consulting and financial support for safety and trustworthiness certifications and for the conduct of impact assessments, thereby encouraging voluntary participation. The MSIT also plans to support business operators in fulfilling their obligations, including the confirmation of high-impact AI and the implementation of transparency measures. 3. Subjects and Criteria for Support to Foster the AI Industry     The AI Framework Act provides provisions to foster the development of AI technology and the AI industry, including support for R\&D projects for AI technology development (Article 13 of the AI Framework Act), the establishment of policies related to training data (Article 15 of the AI Framework Act), and support for companies in the introduction and utilization of AI technology (Article 16 of the AI Framework Act).     The draft Enforcement Decree specifies the subjects and criteria for each of the foregoing promotion provisions, and the main contents are as follows:     Main contents of subjects and criteria for support for fostering the AI industry         • Businesses eligible for support for training data (Article 12 of the draft Enforcement Decree)             - Businesses for the development of technologies for the production and processing of training data             - Businesses related to the production, collection, management, distribution, and utilization of training data for the development of AI services             - Businesses related to the development of standards and guidelines for training data, etc.         • Support measures for the introduction and utilization of AI technology (Article 15 of the draft Enforcement Decree)             - Provision of information on AI technology             - Education and technical support necessary for the protection of users or affected persons             - Establishment and provision of AI computing infrastructure, etc. 4. Implications and Future Plans     The MSIT has announced that, based on the results of stakeholder consultations, it plans to proceed with administrative legislation procedures beginning in October, with the aim of completing the enactment of the Enforcement Decree by December 2025. The MSIT also intends to publish, around December, final versions of key guidelines, including:         • Guideline on Criteria and Examples of High-Impact AI         • Guideline on Responsibilities of High-Impact AI Businesses         • Guideline on Safety Obligations for AI         • Guideline on Transparency Obligations for AI         • Guideline on AI Impact Assessment     The Enforcement Decree is expected to be continuously supplemented through stakeholder consultation, and because it contains detailed standards for determining obligations of AI businesses, companies should carefully monitor developments. It will also be important to track the finalized guidance period for administrative fines and to actively refer to the forthcoming guidelines once published. 5. Lee & Ko’s Tech & AI Team     Lee & Ko’s Tech & AI team consists of over 100 seasoned lawyers and regulators specializing in diverse areas of technology regulation, including personal data, IT, cybersecurity, intellectual property, finance, healthcare, antitrust, and trade. We provide comprehensive legal services to support businesses at every stage of AI integration and technological convergence. For expert guidance on navigating the regulatory landscape and achieving compliance with the AI Framework Act, please contact our Tech & AI team.  
FILE download
2025.01.07
A New Era for AI: Republic of Korea Takes a Bold Step with AI Regulation
Amid the recent political turmoil following the impeachment of the President, the National Assembly successfully passed the Framework Act on Artificial Intelligence Development and Establishment of a Foundation for Trustworthiness (AI Framework Act) on December 26, 2024. With this achievement, the Republic of Korea (Korea) becomes the second jurisdiction worldwide, after the European Union, to adopt a comprehensive AI framework law, balancing regulatory requirements with the goal of fostering AI industry growth. I. Key Provisions of the AI Framework Act     1. Definition of Key Concepts         ■ Artificial Intelligence (AI): Systems generating outputs, such as predictions, recommendations, or decisions, which impact real or virtual environments for specific objectives, with varying autonomy and adaptability (Article 2(ii)).           ■ High-Impact AI: AI systems that significantly affect human life, safety, or fundamental rights, and are used in sectors specified under the AI Framework Act and its Enforcement Decree such as energy, healthcare, nuclear operations, biometric data analysis, public decision-making, and education (Article 2(iv)).           ■ Generative AI: Systems producing text, images, videos, or other outputs based on the structure and characteristics of the input data (Article 2(v)).           ■ AI Business: Entities engaged in business related to the AI industry, including “AI development businesses,” which develop and provide AI systems, and “AI utilization businesses,” which offer products or services utilizing AI systems provided by AI development businesses (Article 2(vii)).     2. The Scope of Application         The AI Framework Act applies to activities conducted abroad if they impact Korea’s domestic market or users. However, the Act does not apply to AI systems developed and used exclusively for national defense or security purposes, as designated by Presidential Decree (Article 4).     3. Requirements for AI Safety and Trustworthiness           ■ High-Impact AI             AI businesses must evaluate whether their AI systems qualify as high-impact AI before launching related products or services. The Ministry of Science and ICT (MSIT) may provide guidelines for identifying high-impact AI and confirm its status if requested (Article 33(1)–(3)). When providing products or services utilizing high-impact AI, AI businesses must notify users in advance of such fact (Article 31(1)).               Additionally, AI businesses are required to implement the following measures to ensure the safety and trustworthiness of high-impact AI:                   - Develop and operate risk management plans.                   - To the extent technically feasible, establish and operate a plan to provide explanations for AI-generated outputs, including the criteria used to infer such outputs, and the training data utilized to develop and use the AI.                   - Establish and operate user protection measures.                   - Ensure human oversight of AI systems.                   - Maintain documentation demonstrating the measures taken to ensure the safety and trustworthiness of AI.                   - Address additional measures to ensure safety and trustworthiness as determined by the National AI Committee (Article 34(1)–(3)).               When providing products or services utilizing high-impact AI, AI businesses should also endeavor to obtain prior verification and certification regarding high-impact AI systems and assess their potential impact on fundamental rights (Articles 30(3) and 35).         ■ Generative AI             When providing products or services utilizing generative AI, AI businesses must notify users in advance of such fact. AI businesses must also label outputs of such products or services clearly as AI-generated, particularly when the outputs mimic real-world sounds, images, or videos. For artistic or creative expressions, this obligation can be fulfilled in a manner that does not interfere with the display or appreciation of the work (Article 31(1)–(3)).         ■ Other Requirements             For AI systems exceeding computational thresholds set by Presidential Decree, relevant AI businesses are required to:                 (i) Identify, evaluate, and mitigate risks throughout the AI lifecycle.                 (ii) Implement a risk management system for monitoring and responding to AI safety incidents.                 (iii) Submit the results of (i) and (ii) to the MSIT (Article 32(1)–(3)).             Foreign AI businesses without a place of business in Korea that meet certain thresholds for user numbers or sales (to be specified in the Enforcement Decree) must appoint a local representative with a Korean address or office. The local representative is responsible for:                  ■ Submitting the results of the implementation of safety measures for AI systems.                 ■ Applying for the confirmation of high-impact AI by the MSIT.                 ■ Supporting the implementation of safety and trustworthiness measures.             Failure of the local representative to comply with the aforementioned obligations renders the foreign business liable for the violations (Article 36(1)–(3)).     4. Regulatory Investigations and Sanctions         The MSIT may conduct investigations into suspected violations of the AI Framework Act and issue correction or cease-and-desist orders upon confirming violations (Article 40(1)–(3)). Investigations may address potential violations of the following obligations:             ■ Notification and labeling requirements for generative AI outputs.             ■ Implementation of safety measures and submission of compliance results for AI systems exceeding computational thresholds set by Presidential Decree.             ■ Adherence to safety and reliability standards for high-impact AI systems.         Non-compliance with correction or cease-and-desist orders, failure to fulfill notification obligations for high-impact or generative AI, or failure to designate a local representative may result in administrative fines of up to KRW 30 million (Article 43).     5. AI Development and Industry Promotion         The AI Framework Act requires the MSIT to implement measures for the production, collection, management, distribution, and utilization of AI training data. These measures include selecting and supporting projects that produce and provide training data. The MSIT is also required to establish an integrated system for managing and providing training data to the private sector (Article 15).         The Act establishes a legal framework to establish and promote AI Data Centers through administrative and financial support for their construction and operation. It further emphasizes fostering AI-related expertise by attracting international talent and supporting domestic employment opportunities (Article 25).         Key provisions in the Act also promote:             ■ The development and safe application of AI technology.             ■ Standardization of AI technologies.             ■ Support for small and medium-sized enterprises (SMEs) in adopting AI technologies.             ■ Promotion of AI start-ups and convergence initiatives.             ■ Facilitation of international cooperation and entry into global markets.             ■ Establishment of framework for AI testing and verification to support industry development and technological innovation.         ​​​​​​​These initiatives collectively aim to establish a strong foundation for advancing AI technology and ensuring its safe implementation in Korea. II. Implications     The AI Framework Act aims to balance the establishment of essential baseline regulations for AI development and use while avoiding the imposition of onerous administrative penalties or criminal sanctions that could stifle innovation. The Act also emphasizes and prioritizes supportive measures to foster and advance AI technology and industry growth, including provisions for AI training data, the establishment of AI Data Centers, and workforce expansion. It provides a legal foundation for the creation of the National AI Committee and the AI Safety Research Institute to ensure consistent policy implementation and oversight of AI safety.     According to legislative procedures, bills passed by the National Assembly must be promulgated by the President (or Acting President) within 15 days of being forwarded to the government. The AI Framework Act specifies in its Annex that it will take effect one year after its promulgation, with the effective date anticipated in January 2026. Key details, including definitions of high-impact AI, computational thresholds, and safety measures, will be further clarified through Presidential Decrees or notifications from the MSIT, and companies are encouraged to remain informed on these developments.     Additionally, given that implementing the measures required by the Act—such as measures to ensure the safety and trustworthiness of high-impact AI—is expected to take significant time, companies should consider conducting a preliminary evaluation to determine whether their products or services may involve high-impact or generative AI and implementing the compliance measures outlined in the AI Framework Act to the extent possible to ensure readiness by the enforcement date. ​​​​​​​ Lee & Ko’s Tech & AI team consists of over 100 seasoned lawyers and regulators specializing in diverse areas of technology regulation, including personal data, IT, cybersecurity, intellectual property, finance, healthcare, antitrust, and trade. We provide comprehensive legal services to support businesses at every stage of AI integration and technological convergence. For expert guidance on navigating the regulatory landscape and achieving compliance with the AI Framework Act, please contact our Tech & AI team.  
FILE download