Written and maintained by CASRAI Editorial Board
Last updated
South Korea’s AI Basic Act is not a forthcoming law. As of this writing it has been in force since January 2026 — which means it is, right now, the most concretely binding AI-specific statute that applies to frontier labs operating in a major market outside the US, the EU, and China. Two of the framework’s obligations make it worth a closer look even for organizations with no Korean office: a mandatory risk-assessment requirement for “high-impact” and generative AI systems, and a requirement that developers and deployers designate a Korea-based local representative — a compliance mechanic that most US and EU AI frameworks do not use at all.
The law’s formal name is the Framework Act on the Development of Artificial Intelligence and Establishment of Trust, etc., commonly abbreviated as the AI Basic Act (인공지능기본법). It was passed by South Korea’s National Assembly in December 2024 and took effect in January 2026, per the U.S. International Trade Administration’s own market-intelligence summary of the act. It is administered by MSIT, South Korea’s Ministry of Science and ICT.
What the Act actually requires
Per ITA’s summary, the AI Basic Act does three concrete things that matter to a frontier lab or any organization deploying generative AI into the Korean market:
- Risk assessments. Businesses that develop and deploy AI systems classified as “high-impact” or generative are made responsible for safety and transparency, including implementing risk-assessment procedures before and during deployment.
- Safety measures. The act establishes legal grounds for a national AI control tower and an AI safety institute, and sets baseline safety and transparency obligations on covered developers and operators.
- A Korea-based local representative. Foreign businesses without a Korean address must designate a representative located in Korea — the mechanism regulators use to have someone locally accountable and reachable for compliance purposes, independent of where the company itself is headquartered.
What the ITA source does not specify — and what CASRAI has not been able to independently verify from a primary source as of this piece’s publication — is the exact quantitative test that makes an AI system “high-impact” under the act (a compute threshold, a revenue figure, a sector-based designation, or something else), or the current, finalized state of the act’s enforcement decree and subordinate regulations. As of the ITA’s April 14, 2025 snapshot, MSIT was still drafting those subordinate regulations, with release expected in the first half of 2025, and the agency had signaled it was aiming to keep the initial regulatory footprint deliberately “minimum” rather than maximal. Whether that subordinate rulemaking was finalized in time for the act’s January 2026 effective date is a detail we could not confirm from a source we trust enough to state as fact here, so we’re flagging it rather than guessing. What corroborates that the law did take effect on schedule: Korean science-press coverage from January 2026 reports MSIT stood up a dedicated support desk for the new framework around the time it came into force, and MSIT’s AI-policy coordination activity continued through September 2026 — both consistent with a law that is live and being administered, not one still pending.
Why the timing matters
Most of the non-US/EU/China AI-safety frameworks CASRAI tracks in this cluster are still in drafting, consultation, or phased-rollout stages. Korea’s AI Basic Act is not: it is a statute already imposing obligations on covered developers and deployers today, with a specific enforcement structure (MSIT plus the act’s AI safety institute) already stood up. For any frontier lab whose generative AI products are reachable from the Korean market — which, for a hosted API or a consumer chat product, is most of them — the local-representative requirement in particular is not a future planning item. It’s already due.
The NIKOLAI angle: a gap, not yet a mapping
NIKOLAI is CASRAI’s own frontier-AI-safety dictionary — an independent, unendorsed reference work, not an official record of any lab’s, regulator’s, or evaluator’s terminology, and certainly not an official record of Korean law. Every crosswalk row in NIKOLAI is a shadow mapping — CASRAI’s own interpretive reading of how an organization’s or jurisdiction’s terms line up with NIKOLAI’s elements — unless and until an organization files its own Mapping Declaration and that declaration clears editorial review.
Two existing NIKOLAI elements in Track N1, Actors, models and scope, map structurally onto exactly the two obligations described above:
- Developer — NIKOLAI’s proposed definition of “the legal person responsible for developing a model or publishing a safety artefact, identified per jurisdiction,” modeled as a compound key of developer × jurisdiction × legal role. That is structurally identical to what Korea’s local-representative requirement demands in practice: a per-jurisdiction, legally accountable identity for a developer that may otherwise have no Korean presence at all.
- Coverage scope threshold — NIKOLAI’s term for the if-then test that determines whether a statute or framework applies to a given developer or model at all. Korea’s “high-impact” and generative AI categories are exactly this kind of scope test, in the same family as the EU AI Act’s Article 51 systemic-risk threshold and California SB 53’s compute-based trigger, both of which already appear as crosswalk rows on that element page.
We checked both element pages directly before writing this: as of publication, neither the Developer element nor the Coverage scope threshold element carries a crosswalk row for Korea’s AI Basic Act — no shadow mapping exists yet. Given that the act is now in force, imposes obligations structurally comparable to ones NIKOLAI already tracks for the EU AI Act’s GPAI systemic-risk provisions and for California SB 53’s capability threshold, and specifies a concrete, checkable compliance artifact (a named local representative), we’re flagging Korea’s AI Basic Act here as a strong candidate for a future NIKOLAI crosswalk addition — not asserting that a mapping exists today.
For the fuller jurisdiction-by-jurisdiction picture, see CASRAI’s AI regulations around the world guide, and for how NIKOLAI’s shadow-mapping system works generally, see Comparing AI Safety Terms Across Frameworks: A NIKOLAI Crosswalk Guide.
Sources
- U.S. International Trade Administration, “South Korea Artificial Intelligence (AI) Basic Act,” April 14, 2025 — enactment date, effective date, MSIT’s role, risk-assessment and local-representative requirements, and subordinate-regulation drafting status as of that date.
- Korean science-press coverage (DongA Science, January 2026) reporting MSIT’s launch of a support desk for the newly effective framework, consistent with the act’s January 2026 effective date.







