Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust
- Document
- 21 January 2025
- Event
- 21 January 2025
- Retrieved
- 16 September 2026
The design
South Korea enacted the “Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust,” commonly called the AI Basic Act. Its own addenda record it as Act No. 20676, promulgated 21 January 2025, with an enforcement date of one year after promulgation. The statute's English translation, published by the Korea Legislation Research Institute, carries the government body listed as the Ministry of Science and ICT. Its Article 2 defines a category the earlier PIPC fine against Iruda's maker did not rely on: “high-impact AI,” an AI system likely to significantly affect or risk human life, safety, or fundamental rights when used in listed areas such as energy supply, medical devices, or hiring decisions.
What the evidence says
The full statute text sets out obligations distinct from the 2021 PIPC enforcement action against Iruda, which found a specific company had unlawfully used chat data; this act instead creates standing, general duties. Article 31 requires a business operator using high-impact or generative AI to notify users in advance that a product is AI-based, and to indicate when output was generated by generative AI. Article 34 requires an operator of high-impact AI to implement risk-management measures, explain a system's outputs to the extent technically feasible, maintain human oversight, and retain documentation of its safety measures. These are the statute's own stated duties, not a regulator's characterization of them, since the act has not yet reached its own enforcement date.
What it asks of people
A user of a high-impact or generative AI system is entitled, once the act is in force, to know in advance that they are dealing with an AI system and to see synthetic outputs labeled as such. An “impacted person,” the act's term for someone significantly affected by an AI product's decision, is not given an explicit individual complaint right in these provisions; oversight instead runs through the Minister of Science and ICT, who can investigate suspected violations of the transparency and high-impact duties and order corrective action.
Privacy and safeguards
The act does not replace South Korea's Personal Information Protection Act, the statute the PIPC used against Iruda; it operates alongside it, adding AI-specific transparency and risk-management duties rather than new data-retention or consent rules. The published translation carries the Institute's own disclaimer that it is unofficial and provided for reference, a limit worth preserving when quoting specific obligations rather than the statute's general structure.
- Which of a companion app's features would place it inside the act's definition of “generative AI” versus “high-impact AI,” given the two carry different duties?
- What implementing decrees has the Ministry of Science and ICT issued ahead of the act's enforcement date?
- How does the act's Article 31 disclosure duty compare with the transparency duty already documented in the EU AI Act?
Where the 2021 Iruda case turned on an existing privacy law applied after the fact, the AI Basic Act is a forward-looking framework statute, and its own text is what will define “high-impact” and “generative” AI once its provisions take effect.
Sources & reading trail
Statute record page confirming the act's title, issuing government body, and Act No. 20676 promulgation on 21 January 2025.
Source published: Not established · Retrieved: 16 September 2026
Full translated text giving Article 2's high-impact AI definition, Article 31's transparency duty, Article 34's operator duties, and the enforcement-date addenda.
Source published: Not established · Retrieved: 16 September 2026
Product documents, regulator records and studies establish the entry; the design reading is AI Companions editorial analysis. This retrospective draft does not imply the site published on the event date.