South Korea's AI Framework Act — also referred to as the AI Basic Act — is a binding national statute, widely reported to have begun taking effect in early 2026, that creates risk-based obligations for AI systems with generative AI transparency duties applying broadly and heavier obligations reserved for systems classified as "high-impact." For agent operators, the central compliance decision is the same one the EU AI Act forces: is this deployment high-impact, and if so, what does that classification require you to produce?
Korea's framework is frequently described as the first comprehensive, binding AI statute in Asia, which makes it a useful reference point alongside the EU's approach and China's agent-specific model. But its detailed implementing rules — the specific criteria for high-impact classification in edge cases, sector-specific sub-regulations, and enforcement procedure — are still being specified by the Ministry of Science and ICT (MSIT) as the regime is phased in. Treat the structure below as the framework to build against, and verify implementation detail as it is published.
The structure: baseline transparency, heavier high-impact obligations
The Act applies two tiers of obligation.
Baseline transparency, applying broadly to generative AI. Providers and, in some cases, deployers of generative AI systems are expected to ensure AI-generated content is identifiable — through labelling, watermarking, or equivalent disclosure — so that users and downstream recipients are not misled about whether content originated from a human or a system.
Heavier obligations for "high-impact" AI. AI systems that meet the statute's high-impact criteria — generally, systems used in contexts with significant potential effect on health, safety, or fundamental rights, echoing categories familiar from the EU AI Act's high-risk list such as employment, credit, and critical infrastructure — face additional obligations: risk-management processes, human oversight requirements, a duty to notify users they are interacting with a high-impact AI system, and documentation supporting an impact or risk assessment.
This two-tier structure means your first task, exactly as under the EU AI Act, is classification: is a given agent deployment merely generative-AI-adjacent (baseline transparency only), or does it meet the high-impact bar (the fuller obligation set)?
Where the criteria are still being specified
The Act's Enforcement Decree — its primary sub-regulation — took effect alongside the Act itself on 22 January 2026, so the core operative detail is not still pending. What remains open is sector-level guidance from MSIT and related bodies: the precise boundary of "high-impact" for edge-case deployments, the specific form user notification must take, and the cadence and content of risk-management documentation in particular sectors. Build your compliance program around the categories the Act and its Enforcement Decree already establish, and revisit sector specifics as that guidance publishes.
One operator-relevant detail worth flagging now: a one-year grace period applies to administrative fines from the Act's effective date, with exceptions for cases involving serious social harm. That is a runway to close gaps, not an exemption from the underlying obligations — the classification, transparency, and documentation duties are live from day one even where the fine risk is deferred.
How Korea's approach compares
| Dimension | EU AI Act | China's Implementation Opinions | Korea's AI Framework Act |
|---|---|---|---|
| Instrument type | Binding statute | Jointly issued policy guidance (not a statute), operationalised through sector filing, testing and recall requirements | Binding statute |
| Sorting axis | Use-case risk category | Decision-authority tier | Use-case-driven "high-impact" designation, plus a separate generative-AI transparency layer |
| Applies to | AI systems generally | AI agents specifically | AI systems generally, with generative AI and high-impact systems as distinct tracks |
| Lead implementing body | National market-surveillance authorities per member state | CAC, NDRC, MIIT jointly | Ministry of Science and ICT |
Korea's model is structurally closer to the EU's use-case-driven approach than to China's autonomy-tier model — which matters if you are trying to reuse an existing risk-classification exercise. An EU AI Act high-risk classification is a reasonable starting point for assessing Korean high-impact status, though the criteria are not identical and should be checked independently.
The six obligation categories to prepare for
| Obligation | What the Act requires | Applies to |
|---|---|---|
| Transparency | AI-generated content disclosure; user notification of high-impact AI interaction | Generative AI broadly (content disclosure); high-impact systems (user notification) |
| Human oversight | Documented oversight mechanism for high-impact systems | High-impact systems |
| Risk/impact classification | Determination of whether a system meets the high-impact criteria, with supporting documentation | All systems, as a threshold exercise |
| Record-keeping | Risk-management and impact-assessment documentation | High-impact systems |
| Incident reporting | Expected as part of risk-management obligations; specific mechanics still being clarified | High-impact systems |
| Data localization | Not a general requirement under the AI Framework Act itself; existing Korean data-protection law (PIPA) governs cross-border transfer separately | All systems processing personal data |
Control mapping: what you need to be able to produce
A documented high-impact classification for every agent. This is the analogue of EU risk-tier classification and the single most consequential compliance decision under Korea's Act. Record the reasoning — what domain the agent operates in, what decisions it informs, and why it does or does not meet the high-impact bar — not just the conclusion. See how to classify AI agents under the EU AI Act's risk tiers for a classification methodology that transfers reasonably well to this exercise, with Korea's high-impact criteria substituted for the EU's Annex III categories.
AI-generated content disclosure mechanism. For any agent that produces content a user might reasonably mistake for human-created, build a labelling or disclosure mechanism now — this baseline transparency obligation applies to generative AI broadly, not just to high-impact deployments.
User notification for high-impact interactions. Where an agent is classified high-impact, the user needs to be told, before or during the interaction, that they are dealing with an AI system. Retrofit this into agents that were designed assuming a human-facing UI would make that obvious — assumption is not the same as notification.
Risk-management and impact-assessment records. For high-impact agents, maintain documentation covering the risks the deployment was assessed against, the mitigations applied, and the basis for concluding the deployment is acceptable. Build this as a living document tied to the agent's lifecycle, not a one-time filing.
Human-oversight design evidence. Show that a human can meaningfully review and intervene in a high-impact agent's outputs — not just that an override button exists. See human-in-the-loop approvals for high-risk agent actions for the design considerations that apply directly here.
Cross-border data transfer records under PIPA. Korea's Personal Information Protection Act governs cross-border transfer of personal data separately from the AI Framework Act. If a high-impact agent's data leaves Korea — common when using foundation models hosted elsewhere — document the transfer basis under PIPA specifically.
What good looks like
- Every agent has a documented, reasoned high-impact classification, revisited when the agent's scope or deployment context changes.
- Generative-AI outputs a user could mistake for human-created content carry a disclosure mechanism by default.
- High-impact agents notify users of AI interaction before or during use, not buried in a separate policy document.
- Risk-management and impact-assessment documentation exists for every high-impact agent and is kept current as the agent evolves.
- Human-oversight paths for high-impact agents are functionally exercised, not merely present in the design.
- Cross-border personal-data flows tied to agent operation have a documented PIPA transfer basis.
Common questions
Is every AI agent deployed in Korea automatically "high-impact"?
No. High-impact status depends on the domain the agent operates in and the significance of the decisions it informs, closely paralleling how EU AI Act high-risk classification works. A large share of agent deployments — internal productivity tools, low-stakes customer support — will fall outside the high-impact tier and face only the baseline generative-AI transparency obligations, if those apply at all. The classification exercise, not an assumption in either direction, is the work.
Does the generative-AI content-disclosure obligation apply even to internal, non-customer-facing agents?
The obligation is generally framed around content a recipient could be misled about — which points toward external-facing or publicly distributed content as the primary concern. Purely internal tooling with no external content distribution is a lower-priority case, but confirm this against current guidance rather than assuming it is fully exempt, since internal content sometimes ends up externally distributed in ways the original design did not anticipate.
How mature is enforcement likely to be in the near term?
Expect enforcement to ramp gradually as MSIT publishes sub-regulation and builds supervisory capacity, which is typical for a newly binding statute of this scope. Early enforcement activity, when it appears, is more likely to target clear, well-publicized high-impact deployments than ambiguous edge cases — but "likely to be deprioritised at first" is not the same as "safe to ignore."
This is not legal advice; confirm the current implementation status of Korea's AI Framework Act, including any sub-regulation published since this was written, with counsel before relying on it.
Korea's binding, risk-tiered structure makes it one of the closer analogues to the EU AI Act among the jurisdictions covered in this series — reuse your classification discipline, but verify the high-impact criteria independently rather than assuming EU and Korean risk tiers align exactly.