Skip to main content
South Korea's flag ripples in the wind. It features a swirling red and blue circle on a white field, surrounded by four trigrams, symbols with three black lines.
Analyst Insights

What you need to know about South Korea’s new AI law

Set to go into effect in January, South Korea’s AI Basic Act is a comprehensive AI legal framework that offers a compelling alternative to legislation launched in the EU and Japan. Some experts think its adaptability could make it a model for other nations.

South Korea is on a major roll in its push to become an international leader in AI, pouring money and resources into AI projects to drive economic growth, crafting standout AI guidelines, and getting some high-wattage visibility on the world stage.

Last month, it launched the National AI Strategy Committee, the top body overseeing SK’s AI policies, in keeping with President Lee Jae Myung’s pledge to make the country a top-three global AI powerhouse. Last week, in a historic first for a Korean leader, Lee presided over a high-level debate at the UN Security Council, which focused on the implications of AI for international peace and security. And this month, Lee will again focus on AI when he chairs the annual meeting of the Asia-Pacific Economic Cooperation Forum.

"To turn the changes of the AI era—where light and shadow coexist—into opportunities, it is essential for the international community to unite and uphold the principle of 'responsible use of AI,'" Lee said at the UNSC meeting in New York.

That principle of responsible use, particularly emphasizing safety and trust, pervades South Korea’s new AI Basic Act, passed earlier this year and set to go into effect in January. It is a comprehensive AI legal framework and differs in a few key ways from prior regulations passed around the globe, notably the EU’s more prescriptive AI Act (enacted in 2024) and Japan’s lighter touch, more promotional legislation (launched in June). While experts are evaluating the AI Basic Act’s pros and cons, some think its flexibility could make it a model for other nations.

Balancing act—a primer on South Korea’s new AI law

Ambitious in scope, the AI Basic Act applies to organizations based in and outside of South Korea that provide an AI service or product used in the country. It encompasses areas such as legal, institutional, and cultural measures for implementing a sound AI society, as it strives to balance AI innovation with human rights, safety, and other concerns.

It is essential for the international community to unite and uphold the principle of ‘responsible use of AI.’
South Korean President Lee Jae Myung

Its aim is to promote the development of AI technology and build public trust. According to an assessment by the Center for Strategic International Studies, a nonprofit policy research organization, “It covers national-level policies for AI development, support for industry growth, data center initiatives, ethical principles, obligations to ensure transparency and safety, and regulations for high-risk and generative AI systems.” As if that’s not a big enough ask, it also seeks to implement a risk management system to ensure the overall safety of AI systems and adopts a certification-based trust mechanism for verifying the authenticity of users, devices, and websites in a network.

Passage of the act followed several other steps regarding AI governance:

  • In March 2024, South Korea adopted the UN resolution on safe, secure, and trustworthy AI. The resolution is aimed at steering the use of AI toward global good.
  • In May 2024, the country announced the Seoul Declaration for Safe, Innovative, and Inclusive AI, which confirms of a shared understanding of the opportunities and risks posed by AI and was signed by 10 countries and the European Union.
  • Most recently, in March 2025, South Korea created a new interagency organization, the National AI Security Consultative Group.

[Read also: Racing to deploy AI? Security starts with good governance]

Although they are works in progress, these steps put South Korea in a leadership position worldwide when it comes to addressing AI challenges such as security and data privacy risks. And they are indeed big challenges.

“The growing recognition of AI’s potential to have direct impacts on hard security and social cohesion, not just cybersecurity, has been important,” says Jenny Town, senior fellow and director of the Korea Program at the Stimson Center, a Washington, D.C. think tank. “The fact that there are national and multinational efforts to try to characterize the challenges and come up with law, regulations, and standards across a range of issues is encouraging and needs to continue.”

How South Korea’s AI law incentivizes responsible use

The stated goals of South Korea’s AI Basic Act are to promote safety and reliability of AI technology and to improve quality of life for individuals. “Affected persons shall be provided with a clear and meaningful explanation of the key criteria and principles used to derive the final AI outcomes, to the extent technically and reasonably possible,” according to a translation provided by the Center for Security and Emerging Technology, a policy research organization within Georgetown University’s Walsh School of Foreign Service.

[The EU AI Act’s] highly detailed and broad scope makes it difficult for individual countries to adopt or adapt.
Kwang Bae Park, senior partner, Lee & Ko

The act also created the AI Safety Research Institute to perform tasks designed to protect people's lives, physical well-being, and property from risks associated with AI, and maintaining a foundation of trust in an AI society. The institute will aim to define and analyze safety-related risks, as well as research AI safety evaluation criteria and methods, and AI safety technologies and standardization.

“One standout feature is the act’s use of public procurement to promote responsible AI development,” says Sakshi Shivhare, policy associate for Asia/Pacific at the Future of Privacy Forum, a nonprofit organization focused on ensuring privacy and ethical use of emerging technologies.

Under the act, businesses using AI are encouraged to conduct impact assessments for high-impact AI systems, to evaluate their potential effects on fundamental rights, Shivhare says. “While voluntary, the act creates a real incentive: Government agencies are to prioritize AI products or services that have undergone such assessments when making procurement decisions,” she says.

Public procurement is just one example of a broader suite of measures aimed at balancing innovation with risk mitigation, Shivhare says.

[Read also: What is NIST compliance? It’s often the first step for orgs beginning their compliance journey]

When the AI Basic Act passed in January, South Korea became only the second in the world, following the EU, to pass such a wide-ranging regulatory law on AI. (Japan would pass and launch its own legislation several months later.) That meant the EU’s Artificial Intelligence Act was the only substantial reference point, “but its highly detailed and broad scope makes it difficult for individual countries to adopt or adapt,” asserts Kwang Bae Park, a senior partner at Lee & Ko in Seoul, who heads the law firm’s technology, media and telecommunications group and serves as a data privacy and cybersecurity practice lead. South Korea’s AI Basic Act “offers a simpler, more streamlined legal framework that remains flexible enough to accommodate future technological and ecosystem shifts.”

This adaptability, he feels, will appeal to other nations developing their own AI regulatory regimes and serve as a key element in any “Basic”-inspired blueprint.

South Korea’s AI law is a regulatory work-in-progress

South Korea’s AI Basic Act isn’t perfect, though. “The AI Basic Act was enacted to reflect the government’s position of maintaining minimal regulatory interference at this early stage of AI industry development,” Park says. “However, there appears to be a stark contrast between the perspectives of industry stakeholders and civil society regarding the appropriate scope and intensity of regulation.”

South Korea’s model sits between the EU’s stringent framework and Japan’s promotional stance, aiming to balance regulatory oversight with support for innovation.
Sakshi Shivhare, policy associate for Asia/Pacific, Future of Privacy Forum

Over time, as the AI ecosystem matures, the regulatory framework is expected to grow more sophisticated, Park says. “A key challenge before the Act takes effect next January is defining the scope of ‘high-impact AI systems’—a foundational concept—within subordinate regulations… Many core elements of the act remain unspecified and are expected to be detailed in upcoming subordinate legislation, which has yet to be released.”

Every country ultimately knows best what works for its context, Shivhare says. “It can draw lessons from global counterparts but must adapt them to its unique needs and priorities,” she says. “That said, there are potential areas where the [AI Basic Act] could be strengthened.”

[Read also: Australia’s efforts to promote cybersecurity via its ‘Essential Eight’ has SMBs struggling to comply]

For example, the act relies heavily on future presidential decrees for key operational details, delaying clarity and predictability for stakeholders, Shivhare says. “Given that many AI systems operate in or alongside critical infrastructure, its limited provisions on cybersecurity are another area where stronger safeguards could add value,” she says.

South Korea vs. the EU vs. Japan—how the AI laws stack up

South Korea’s AI Basic Act, the EU’s AI Act, and Japan’s AI Promotion Act all promote trustworthy AI but take distinct approaches.

Being a first mover has its advantages, but it also means its policies will require constant review and revision over time.
Jenny Town, senior fellow and director of the Korea program, Stimson Center

The EU AI Act is a highly prescriptive, risk-based framework with detailed requirements and explicit prohibitions on certain AI uses. South Korea appears to borrow somewhat from the EU playbook in terms of regulating AI based on risk and emphasizing clear record-keeping. It is adopting a layered, transparency-focused approach, placing most obligations on high-impact AI systems while leaving many operational details to future regulations. Japan’s, by contrast, has taken a decidedly promotional approach, setting out broad principles to encourage AI research, development, and utilization.

“Overall, South Korea’s model sits between the EU’s stringent framework and Japan’s promotional stance, aiming to balance regulatory oversight with support for innovation,” Shivhare says.

[Read also: How to comply with the EU’s AI Act—start with your risk level]

Like the EU AI Act, the Korean legislation excludes the defense sector, likely due to the separate regulatory frameworks that govern national security.

“Regarding enforcement, the Act merely grants investigative powers to regulatory agencies without establishing more robust enforcement mechanisms—although this aligns with its intent as a baseline framework,” Park says.

Given the nascent stage of AI development, a comprehensive and rigid framework like the EU AI Act might be impractical for many jurisdictions, Park adds. “The Korean AI Basic Act, with its concise language and emphasis on minimal but flexible regulation, may provide a more pragmatic and adaptable reference point for countries looking to craft AI legislation suited to rapid technological evolution,” he says.

Regulating AI development is still an emerging trend, Town says, and one that will be iterative by nature given how quickly technology advances. “South Korea is one of the countries at the forefront of this trend,” she says. “Being a first mover has its advantages, but it also means its policies will require constant review and revision over time. [Its] experiences will also help other countries consider their own needs and options.”