AI
South Korea’s AI Basic Act Caps Fines at $21,000
South Korea’s AI Basic Act is in force with a $21,000 fine cap, a three-part 10^26 compute test, and a year-long pause on most penalties.
South Korea’s AI Basic Act took effect on January 22, 2026, with administrative fines capped at 30 million won (about $21,000). The Ministry of Science and ICT, led by Deputy Prime Minister Bae Kyung-hoon, paired the start date with a pause on most investigations and penalties of at least one year.
MSIT wrote the statute as an industrial promotion law first. The duties that actually land on companies are user notices, a named agent in Seoul for the largest foreign operators, and a safety test that needs three conditions, not a compute number alone.
A Promotion-First Law With Extra Homework
The statute’s formal name is the Act on the Development of Artificial Intelligence and Establishment of Trust. The National Assembly passed it in December 2024, it was promulgated on January 21, 2025, and the Enforcement Decree cleared a Cabinet meeting on January 20, 2026, a day before both texts went live. The official English text of the Act covers firms that build AI and firms that put AI into products, and it reaches systems outside Korea if they affect Korean users or markets. National-security systems sit outside that net.
MSIT spent 2025 building the decree with a working group of about 80 private-sector experts, more than 70 consultation sessions, and over 20 briefings for Korean and foreign companies. The ministry’s own account of that process is blunt about the design choice.
According to the “minimum regulation principle,” the Act minimizes obligations and restrictions on AI business operators while broadly incorporating measures to foster the growth of the AI sector.
Ministry of Science and ICT, January 2026 enforcement announcement
That is why the law stands up a Presidential Council on National Artificial Intelligence Strategy, funds data centers and training sets, and still asks operators of generative AI and high-impact AI to tell users that AI is in the product. It is also why the cash penalty is small enough that the real levers are a corrective order, a service suspension, and the reputational cost of a public fight with MSIT.
HOW THE STATUTE REACHED THE START DATE
- December 2024: The National Assembly passes the Act after ruling and opposition talks.
- January 21, 2025: The Act is promulgated, with a one-year run-up to the effective date.
- September 2025: MSIT unveils the draft Enforcement Decree as the presidential council opens.
- November 12 to December 22, 2025: A 40-day legislative notice collects comments on the decree.
- January 20, 2026: The Cabinet approves the decree.
- January 22, 2026: The Act and the decree take effect together.
The ministry also stood up an AI Basic Act Support Desk staffed by people who drafted the subordinate rules, with confidential and anonymous consultations, and said it would keep rewriting guidelines through the grace period.
The Fine Stops at 30 Million Won
Article 43 of the Act sets an administrative fine of up to 30 million won (about $21,000) for three failures: not telling users that AI is in use, not appointing a domestic representative when one is required, and ignoring a corrective order or blocking an inspection. Attorney Hong Seung-kwon has pointed to those three triggers as the practical enforcement path, with criminal exposure under Article 42 limited to leaking committee secrets, up to three years or the same 30 million won.
The European Union’s AI Act, by contrast, puts 35 million euros or 7 percent of worldwide turnover on prohibited practices, 15 million euros or 3 percent on most other breaches, and 7.5 million euros or 1 percent on bad information to a regulator. Korea’s AI statute does not publish an Article 5-style list of banned uses. MSIT can still order a service stopped if it sees a safety threat, which is the lever that actually reaches a large platform.
WHAT THE TWO RULEBOOKS PUT ON THE TABLE
| Term | South Korea AI Basic Act | EU AI Act |
|---|---|---|
| Top AI-specific fine | 30 million won (about $21,000) | 35 million euros or 7% of worldwide turnover |
| Banned AI practices | No statutory banned-use list | Article 5 prohibitions, highest fine tier |
| Training-compute line | 1026 FLOP, plus two extra tests | 1025 FLOP systemic-risk presumption |
| Local representative | Required above revenue or user bars | Authorised representative for some providers |
| Early enforcement | Grace of at least one year, with a harm exception | Phased duties, penalties live from 2 August 2025 |
A separate Korean statute is the one that can take a double-digit slice of turnover. Amendments to the Personal Information Protection Act that took effect on September 11, 2026, raise the ceiling to 10% of total turnover, from 3%, for repeated or large leaks, including cases that hit 10 million people through intent or gross negligence. That is privacy enforcement, not an AI Basic Act fine, and it sits with the Personal Information Protection Commission. On August 20, 2026, the Assembly also passed a PIPA special provision that lets controllers use lawfully collected personal data for AI development, with PIPC approval, when anonymized data is not enough. The industrial bias in Seoul is consistent across both files: grow the models, then police the worst spills with a different statute.
Why 1026 FLOPs Is Not Enough on Its Own
MSIT’s decree does not treat every giant training run as a safety case. Article 24 says a system falls under the duty to ensure safety only if it meets all three tests: cumulative training compute above 1026 floating-point operations, state-of-the-art technology, and a risk of broad and significant impact on fundamental human rights. Guidance on how to apply those last two tests was promised in separate guidelines. Operators that do fall in must identify, assess, and mitigate risks across the system’s life, put a risk-management system in place, and report results to the minister.
THE THREE SAFETY-DUTY TESTS
- Compute floor: Cumulative training compute must exceed 1026 FLOP, ten times the EU’s 1025 systemic-risk presumption.
- Technical bar: The system must incorporate state-of-the-art AI technologies, a qualitative call left to later guidance.
- Rights bar: It must pose a risk of broad and significant impact on fundamental human rights, or the safety duty does not attach.
That 10× gap versus Brussels is the part most January explainers flattened into a single “compute wall.” Epoch AI, which estimates training compute from hardware, duration, and benchmarks, had counted 33 publicly disclosed models at or above 1025 FLOP as of June 2025. GPT-4 sits at about 2.1×1025, under Korea’s line. Grok-3 is estimated at 4.6×1026 with high precision, which clears the numeric floor and still has to meet the other two tests before MSIT’s safety paperwork applies. Several later 2026 flagships have not published training FLOP at all, which leaves operators arguing about estimates until the guidelines get more specific.
A Named Face in Seoul for Foreign Labs
The Act applies to AI that affects Korean users even if the servers sit abroad. Foreign operators without a Korean office must appoint a domestic representative, and tell MSIT, if they trip any one of three bars in the prior year. Cooley’s conversion of the top bar is more than $681 million, a figure that, in the firm’s words, would implicate only the largest technology firms. The agent answers government questions and safety reports. Missing the appointment is one of the three 30 million won fine triggers, once the grace period ends.
DOMESTIC-AGENT TRIGGERS
- Global revenue: Total revenue above 1 trillion won in the previous year (more than $681 million).
- Korea AI revenue: Revenue from AI services above 10 billion won in the previous year.
- Korean users: Average daily users in Korea above one million during the three months preceding the end of the previous year.
Korean counsel was still treating that appointment as a live 2026 filing job well into September, which is the tell. The grace period pauses most fines. It does not pause the duty to have someone in Seoul who can take a letter from MSIT. For a lab already running a Korea-facing chatbot, the agent is the first artifact that makes the extraterritorial clause operational.
Ten Sectors and the Human Override
High-impact AI is a sector list plus a risk call, not a FLOP count. The decree tells MSIT to look at whether the system is used in areas named in the Act and at the level of risk to life, safety, or rights. If a human makes the final decision, the system is treated as controllable and drops out of the high-impact bucket. Operators can also ask the minister to confirm the classification, with a 30-day clock that can be extended once.
High-impact operators have a longer chore list than the generative-AI notice rule. They must check the classification before launch, give a meaningful explanation of outcomes and the data behind them, publish a user-protection plan, keep a human in the loop, document the trust-and-safety work, and make efforts to run a fundamental-rights impact assessment before the system goes into a product.
THE TEN HIGH-IMPACT AREAS
- Energy: Supply and operation in the energy sector.
- Drinking water: Production and provision of drinking water.
- Healthcare: Care delivery and related health services.
- Nuclear: Nuclear facilities and materials.
- Crime investigations: Investigative use, including biometrics for arrest work.
- Recruitment: Hiring decisions that weigh on a person’s rights.
- Credit assessment: Loan screening and similar evaluations.
- Transportation: Core operation of vehicles, facilities, and systems.
- Public services: Government-facing systems in the named public-service set.
- Education: Systems used in education with a serious rights or safety risk.
Landing in a named sector is not automatic coverage. The system still has to risk a serious effect on life, physical safety, or fundamental rights. A hiring tool with a human final sign-off is the cleanest example of the exit ramp the decree wrote on purpose.
Deepfakes Need a Label Users Can See
The consumer-facing fight at launch was labeling, not FLOP math. Operators of high-impact or generative AI must tell users in advance that AI is being used. If an output is hard to tell from reality, including deepfakes, the decree wants a label a user can actually notice, with age taken into account. For other generated work such as animations and webtoons, invisible digital identifiers are allowed, and a pop-up or interface notice can carry the same duty.
MSIT called visible marks on manipulated media a minimum safeguard and said they already match a practice large global companies have adopted. That is the piece Korean users will see. It is also the piece most likely to produce the first ugly screenshot if a model ships unlabeled video into a Korean feed after the grace period. The ministry told companies it would hold startup briefings during the pause, including outside Seoul, because smaller shops were the least ready for the notice rules.
Investigations Pause Until Harm Is Serious
MSIT granted a grace period of at least one year from the January 22, 2026 start, and said fact-finding and penalties would wait. The exception is narrow: investigations can still run in highly exceptional cases such as loss of life, human-rights violations, or other serious social harm. By late September 2026 that pause was still the operating fact. Guidelines were still being refined, and the Support Desk was still the ministry’s advertised front door.
So the law is in force. The fine schedule is not a delayed commencement; it is a live statute with a ministry promise not to use the 30 million won hammer except in those harm cases, at least through the first year. Korean firms selling domestic-agent work in September were not confused about that distinction. A frontier lab can treat 30 million won as a rounding error. It cannot treat a suspension order, a missing Seoul agent, or an unlabeled deepfake that blows up in Korean media as a rounding error.
MSIT said it would keep watching foreign rules and technical change and would adjust. The next hard date on the calendar is the end of that “at least one year” pause, which, unless the ministry extends it, arrives in 2027. Until then the homework is the same: classify the product, label the outputs, and put a name on a Korean door.
Disclaimer: This article is news reporting and analysis of South Korea’s AI Basic Act and related statutes, and it is for information only. It is not legal advice, is not a compliance opinion, and does not tell any company whether it must appoint a domestic representative, label a product, or file with MSIT or the Personal Information Protection Commission. Readers who need to act on these rules should consult a qualified lawyer licensed in Korea, and where personal data is involved a privacy counsel familiar with PIPA, before changing products, contracts, or filings. Figures, grace-period terms, and enforcement posture reflect the ministry announcements and public legal texts cited here and can change as MSIT issues new guidelines or as the National Assembly amends the Act.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
