Skip to main content
v2026.11,858 entries · CC-BY 4.0

Direct comparison

Korea vs Japan vs Taiwan AI Basic Acts

Three East Asian AI Basic Acts, three different laws: only Korea binds today. Compare penalties, scope, regulators and timing side by side.

Written and maintained by CASRAI Editorial Board

Last updated

Ask CASRAI · free to try

Ask about Korea vs Japan vs Taiwan AI Basic Acts

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

How do Korea — AI Basic Act (인공지능기본법), Japan — AI Promotion Act, Taiwan — AI Basic Act (人工智慧基本法) compare side by side?

The table below compares Korea — AI Basic Act (인공지능기본법), Japan — AI Promotion Act, Taiwan — AI Basic Act (人工智慧基本法) across 9 procurement-relevant dimensions, from formal name through what “in force” actually buys a compliance team right now.

Side-by-side comparison

DimensionKorea — AI Basic Act (인공지능기본법)Japan — AI Promotion ActTaiwan — AI Basic Act (人工智慧基本法)
Formal nameFramework Act on the Development of Artificial Intelligence and Establishment of Trust, etc. — commonly abbreviated the AI Basic Act.Act on the Promotion of Research and Development and the Utilization of AI-Related Technologies — commonly called the AI Promotion Act. English-language coverage does not use “Basic Act” for this statute; CASRAI uses it here only for the family comparison the task names, not because Japan’s own law calls itself one.Basic Act on Artificial Intelligence (人工智慧基本法). English coverage renders it variously as the “AI Basic Act,” “Artificial Intelligence Fundamental Act,” or “Basic Law on Artificial Intelligence” — translation variation on one Chinese-language statute, not three different laws.
Binding force todayFully binding and in force. The Act imposes concrete, checkable duties — a risk assessment for covered systems and a named local representative — that apply now, not once a future framework is published.Binding as a statute, but its only direct obligation on a private business is a non-binding “duty to cooperate” (a soft “reasonable efforts” standard). Nothing in the Act compels a company to do anything specific; it compels the government to ask.Binding as a framework act, but its operative content is not yet written. The obligations that would flow from a “high-risk” classification cannot attach to anyone until MODA publishes the risk-classification framework Clause 14 orders it to write — which has not happened as of this writing.
Penalties for non-complianceNot confirmed by primary source as of this writing. The U.S. International Trade Administration's summary of the Act, the source CASRAI's Korea guide relies on, does not state a fine amount or enforcement mechanism, and CASRAI has not been able to verify one independently. This is a real gap in public English-language coverage, not evidence either way that penalties exist.None. The Act "contains no explicit penalties, financial or otherwise, for noncompliance or for the misuse of AI" (Future of Privacy Forum). The government's only lever is non-binding administrative guidance, backed at most by publicly naming a noncompliant business.None, by explicit design. Tech Policy Press's reading of the enacted text states the Act "has refrained from legislating specific penalties over violations by domestic or global firms" — a deliberate soft-law choice, not an oversight awaiting amendment.
Designated authorityMSIT — the Ministry of Science and ICT — with the Act also establishing legal grounds for a national AI control tower and a dedicated AI safety institute.The AI Strategy Headquarters, sitting inside the Cabinet Office and chaired by the Prime Minister with every other cabinet minister as a member. The Minister of State for AI Strategy is its public-facing figure.MODA — the Ministry of Digital Affairs — coordinates rather than regulates alone: Clause 16 explicitly directs individual sector agencies to write their own AI safety guidelines and codes of practice for the industries each already oversees, so enforcement authority is distributed across ministries by design rather than centralized in MODA.
Who and what is coveredBusinesses that develop or deploy AI systems classified as “high-impact” or generative — a developer/deployer-focused scope. The exact quantitative test for “high-impact” (compute, revenue, sector) has not been verified from a primary source CASRAI trusts enough to state as settled.Deliberately broad: “AI-related technologies” generally, with named responsibilities running across five separate stakeholder groups — national government, local governments, R&D institutes, business operators, and citizens — rather than one covered-entity test. It reads as a promotion statute assigning roles, not a compliance statute defining a regulated perimeter.Framework-level and still being narrowed. The Act as passed does not itself define a covered-entity test; that test is exactly what MODA's still-unpublished risk-classification framework is supposed to create. Clause 17 does specify one concrete scope carve-out already: developers owe no relief or compensation duty for “high-risk applications” while those applications remain in research and development.
Local presence requirementYes, and it is the Act's most distinctive mechanism. A foreign business with no Korean address must designate a representative located in Korea — a compliance mechanic most US and EU AI frameworks do not use at all.No equivalent requirement identified in CASRAI's sourcing. The Act's enforcement posture (guidance and public naming) does not depend on a locally designated contact the way Korea's risk-assessment regime does.No equivalent requirement identified in CASRAI's sourcing. Taiwan's Act instead conditions its substantive reach on MODA's forthcoming risk framework rather than on where a developer is based.
A distinctive provision the other two lackThe local-representative mandate above — a per-jurisdiction accountability mechanism with no direct counterpart in either Japan's or Taiwan's law.The five-stakeholder-group structure (government, local government, R&D institutes, business, citizens) and the explicit “innovation-first” framing: the Act's purpose is promotion of AI research and use, not primarily risk control, which is a different starting premise than either Korea's or Taiwan's.Clause 15's labor-market provision: government use of AI must “guarantee the labor rights of workers,” and the Act directs compensation for AI-driven skills mismatches — a labor provision with no direct equivalent in Korea's or Japan's basic acts.
Legislative timingPassed by the National Assembly in December 2024; took effect January 2026 — roughly a 13-month gap between passage and effect.Approved by the Diet May 28, 2025; most provisions took effect June 4, 2025 — a gap of about one week, and the fastest passage-to-effect timeline of the three. Japan's law is also the earliest of the three to have taken effect at all, by roughly seven months over Korea and Taiwan.The Executive Yuan approved a draft August 28, 2025; the Legislative Yuan passed the final text December 23, 2025; President Lai Ching-te promulgated it January 14, 2026, effective the same day — about five months from cabinet draft to force.
What “in force” actually buys a compliance team right nowA concrete checklist: assess whether your system is “high-impact” or generative, run the risk assessment, name a Korea-based representative if you have no Korean office. Incomplete only on the precise quantitative threshold and the finalized subordinate regulations.Almost nothing to check against, by design — the Act's own logic is that a business need only be prepared to receive, and respond in good faith to, a request that carries no legal compulsion behind it. The January 2026 Grok case is the clearest evidence available of what that looks like in practice.A holding pattern. A company can confirm it is not yet formally “high-risk” anything, because the classification that would make it so has not been published — but that also means the Act cannot yet be used to demonstrate compliance either, only the absence of an applicable rule.

Common questions

Common questions about Korea — AI Basic Act (인공지능기본법) vs Japan — AI Promotion Act vs Taiwan — AI Basic Act (人工智慧基本法)

Which of the three AI Basic Acts is actually binding on a company today?

+

Only Korea's imposes concrete, checkable obligations right now — a risk assessment for “high-impact” or generative AI systems and a Korea-based local representative for foreign developers with no Korean office, both live since January 2026. Taiwan's Act is formally in force but its substantive content (MODA's risk-classification framework, sector agencies' own codes of practice under Clause 16) has not been published, so nothing concrete has attached to any developer yet. Japan's Act has been in force the longest (most provisions since June 2025) but creates no enforceable duty beyond a non-binding “duty to cooperate” — legally the weakest of the three despite being the oldest.

Do any of these three laws impose fines?

+

Japan's and Taiwan's explicitly do not — both statutes were written without a penalty provision, confirmed independently for each (Future of Privacy Forum for Japan; Tech Policy Press for Taiwan). Korea's position is genuinely unresolved in CASRAI's sourcing: the U.S. International Trade Administration's summary of the Act, which is the primary reference CASRAI's Korea guide relies on, does not state a fine amount or describe an enforcement penalty structure, and CASRAI has not verified one from a source it trusts enough to state as fact. Treat “Korea has no fines” and “Korea has fines” as equally unverified claims until a primary Korean-language source or its finalized subordinate regulations can be checked directly.

Why does Taiwan's Act count as 'binding' if it doesn't do anything yet?

+

Because “binding” and “operative” are different questions. Taiwan's Basic Act on Artificial Intelligence is a validly enacted, promulgated statute with the full force of law — the same legal status Korea's and Japan's acts have. What it lacks is content: it is structured as a framework act that delegates the actual rulemaking (risk tiers to MODA, sector rules to individual agencies under Clause 16) to instruments that have not yet been written. That is a real and useful distinction from Japan's Act, which is equally in force but was never designed to create binding compliance content in the first place — Taiwan's gap is temporary and rulemaking-dependent; Japan's is structural.

Which regulator should a frontier lab actually be watching?

+

All three, but for different reasons and on different timelines. MSIT (Korea) is the only one of the three currently administering live obligations, so it is the one with immediate compliance relevance. MODA (Taiwan) is the one to watch for what happens next — its unpublished risk-classification framework is the document that will turn Taiwan's Act from a statement of intent into an operative regime, and Clause 16's sector-agency rulemaking means the effective regulator for a given company may end up being its sector's own ministry, not MODA itself. Japan's AI Strategy Headquarters, chaired by the Prime Minister, is worth watching less for rulemaking and more for enforcement posture — the January 2026 Grok/X Corp case is the first real test of what “administrative guidance” does when a company does not cooperate quickly, and its outcome will say more about Japan's model than the statute's text does.

Does NIKOLAI have a crosswalk mapping for any of the three?

+

No. NIKOLAI is CASRAI's own independent, unendorsed frontier-AI-safety dictionary, and every crosswalk row in it is a shadow mapping — CASRAI's own interpretive reading, not an official record of any jurisdiction's law — unless an organization files its own Mapping Declaration and that declaration clears editorial review. The closest-fitting element, Coverage Scope Threshold on Track N1, documents exactly the kind of if-then test Korea's “high-impact” category and Taiwan's forthcoming MODA framework represent, in the same family as the EU AI Act's Article 51 threshold and California SB 53's compute trigger. Checked directly before writing this: that element's crosswalk table carries rows for the EU, California, the US federal government, and six AI developers' own frameworks — and none for Korea, Japan, or Taiwan. Korea's threshold is the strongest current candidate for a future row, because it already exists as text (even if the exact quantitative test isn't public); Taiwan's and Japan's are not yet mappable, because Taiwan's framework doesn't exist in published form and Japan's Act was never designed to create one.

Is this the same thing as the EU AI Act or California SB 53?

+

No, and the difference is structural, not just geographic. The EU AI Act and SB 53 both set a quantitative compute or revenue threshold that triggers specific, enumerated obligations for covered systems — the test and the consequence are both in the statute. None of the three East Asian Basic Acts works that way. Korea comes closest, with a concrete risk-assessment duty already in force, but its “high-impact” threshold itself isn't public yet. Japan and Taiwan are further still: Japan never adopted a threshold-and-consequence model at all, and Taiwan's threshold is explicitly deferred to a future MODA framework. A compliance team used to the EU's or California's model should not assume any of the three East Asian acts works the same way by default.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →