The Second Comprehensive AI Law Already Took Effect — And It Isn't European
While US software teams spent 2025 preparing for August 2026 in Brussels, South Korea quietly became the second jurisdiction on earth with a horizontal AI statute. It took effect January 22, 2026. It reaches American companies. Almost nobody in US SaaS has read it.
What the Law Actually Is
Its full name is the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust — usually shortened to the AI Framework Act or the AI Basic Act. The National Assembly passed it in December 2024, it was promulgated in January 2025, and after a one-year runway it became effective on January 22, 2026.
The framing matters. This is not an EU-style consumer-protection instrument with a prohibited-practices list and turnover-based fines. It is an industrial policy statute with a trust chapter bolted on: roughly half of it is about funding, data centers, talent, and standards, and the other half creates obligations for the AI businesses that benefit. The Ministry of Science and ICT (MSIT) runs it, and the Enforcement Decree carries most of the operational detail — thresholds, representative triggers, labeling specifics.
Why a US-Only Company Is in Scope
The Act contains an express extraterritoriality clause: it applies to acts performed abroad where those acts have an effect on the domestic market or on domestic users. This is the same reach logic GDPR and the EU AI Act use, and it produces the same result for US SaaS.
- You have Korean paying customers using an AI feature — in scope
- Your product is free but has meaningful Korean usage — in scope
- Your AI output is consumed by people in Korea, even via a Korean reseller — in scope
- You have no Korean entity, no Korean staff, no Korean servers — still in scope
What you do not get is a small-company carve-out from the substantive duties. Size affects whether you must appoint a domestic representative; it does not switch off the transparency and labeling obligations.
The Three Obligations That Actually Touch SaaS
Strip out the industrial-policy chapters and the parts about domestic AI data centers, and three duties land on a typical American software company with Korean users.
Generative AI Disclosure
If your product provides generative AI to users, you must notify them in advance that the output is generated by AI. This is a prior notice duty, not a buried terms-of-service line — it belongs in the interface where the generation happens. For most SaaS, this is the cheapest obligation to satisfy and the easiest one to be caught failing.
Synthetic Content Labeling
AI-generated outputs that are hard to distinguish from reality — synthetic images, video, and audio in particular — must be marked as AI-generated. The Enforcement Decree and ministry guidance carry the specifics on how visible and how persistent the mark must be. If you ship an image or voice generator, this is your highest-effort item.
High-Impact AI Duties
Korea's analogue to 'high-risk.' High-impact AI covers systems that can materially affect human life, physical safety, or fundamental rights — healthcare, energy, hiring and personnel decisions, loan screening, and certain public-service and safety contexts. If you land here, you owe a risk management program, explanation of the system's decision criteria, human oversight, and documentation retained for regulator review.
There is also a duty to confirm, in advance, whether a system you are deploying is high-impact — and to be able to show your reasoning. As with the EU's Article 6(3) derogation, the valuable artifact is often the documented conclusion that you are not in the heavy tier.
The Domestic Representative Requirement
This is the provision that surprises US founders, because it has no US analogue and it mirrors the EU AI Act's authorized representative concept — but with a different trigger. A foreign AI business with no address in Korea that exceeds the size thresholds set in the Enforcement Decree must designate a domestic representative: a person or entity in Korea who receives regulator communications, holds required records, and can be reached by MSIT.
- •Large global revenue with meaningful Korean usage
- •High daily active user counts inside Korea
- •Consumer apps with Korean-language distribution
- •Any foreign provider MSIT designates by decree threshold
- •Early-stage B2B SaaS with a handful of Korean accounts
- •No Korean-language marketing or localization
- •Korean usage incidental to a global English product
- •Still owes disclosure and labeling duties regardless
The thresholds live in the Enforcement Decree rather than the statute, which means they can be revised without a new act of the National Assembly. Do not hard-code an assumption that you are exempt — the number that exempts you today is a regulatory instrument, not a constitutional guarantee.
Where It Diverges From the EU AI Act
If you have already done EU AI Act work, most of it transfers. The differences are where teams get tripped up.
What Transfers From Your EU Work
- ☐Your inventory of which features use AI
- ☐Risk classification reasoning and documentation
- ☐AI-interaction and AI-generated-content disclosures
- ☐Human oversight design for consequential decisions
- ☐The representative-appointment muscle memory
What Doesn't Transfer
- ☐Penalty math — Korea uses flat administrative fines, not % of turnover
- ☐No EU-style prohibited-practices list to screen against
- ☐'High-impact' scope is not identical to Annex III 'high-risk'
- ☐No EU-style public database registration step
- ☐Detail lives in the Enforcement Decree, which moves faster than statute
The Fines Are Small. That's Not the Point.
Korea's penalties are administrative fines in the tens of millions of won per violation — real money for a Korean startup, a rounding error for a funded US SaaS company. Read purely as downside risk, the Act looks ignorable.
That reading misses how these laws actually bite foreign vendors. The enforcement mechanism that costs US companies money is procurement. Korean conglomerates, banks, hospitals, and public agencies run vendor security and compliance reviews, and a statute in force since January 2026 becomes a line item on those questionnaires. You lose the deal or you spend six weeks retrofitting evidence during the sales cycle — long before anyone at MSIT sends you a notice.
A Practical Order of Operations
- Measure your Korean exposure. Pull actual account and usage counts for Korea. Most US SaaS companies have never looked and are surprised in one direction or the other.
- Inventory AI features and mark the generative ones. Generative output is where the disclosure and labeling duties attach.
- Screen for high-impact use. Hiring, lending, healthcare, and safety-adjacent decisions are the categories to check first.
- Ship the disclosures. In-product notice that users are interacting with AI, and marking on synthetic media. This is days of work, not quarters.
- Check the representative threshold against the current Decree. Re-check when your Korean numbers grow.
- Write the memo. One page recording your classification and why. That page is what procurement asks for.
Frequently Asked Questions
We have maybe a dozen Korean users. Do we really need to care?
You are technically in scope, and you almost certainly do not need a domestic representative. The proportionate response is to ship the generative-AI disclosure — which you likely need for the EU anyway — and document that you assessed the domestic representative thresholds and fell below them. That is an afternoon of work and it closes the question.
Does the Act ban anything outright, the way the EU bans social scoring?
Not in the same structure. Korea's framework does not carry an EU-style list of prohibited practices with headline fines attached. Its trust chapter works through transparency, high-impact duties, and safety obligations rather than categorical bans. Other Korean laws — privacy, credit, and sector regulation — still constrain specific uses.
We only call OpenAI and Anthropic APIs. Is this our model vendor's problem?
No. As with the EU AI Act, shipping an AI feature under your own brand to Korean users puts obligations on you regardless of whose model runs underneath. Your model vendor's compliance posture does not satisfy your disclosure and labeling duties in your own interface.
How does this interact with Korea's privacy law?
They are separate regimes and both can apply. Korea's Personal Information Protection Act (PIPA) is a strict, actively enforced privacy law with its own extraterritorial reach and its own regulator, the PIPC — and it has historically produced larger penalties for foreign tech companies than the AI Framework Act's fine schedule contemplates. If you are scoping Korea for the first time, PIPA usually deserves attention before the AI Act does.
Will the thresholds and labeling rules change?
Expect so. Most of the operational detail sits in the Enforcement Decree and ministry guidance rather than the statute, which is precisely the machinery designed to be updated as the technology moves. Treat any threshold you rely on as a value to re-verify annually, not a fact to memorize.
The EU Is Not the Whole Map Anymore
Every US SaaS compliance conversation in 2025 assumed one horizontal AI law existed and it was European. That assumption expired on January 22, 2026. Korea is in force, China's synthetic-content labeling regime is in force, and the list will keep growing.
The companies that handle this well are not the ones with the biggest legal budgets — they are the ones who built a single AI feature inventory with a risk note per feature. That artifact answers Brussels, Seoul, and whoever legislates next, without a new project each time.
This article is general information about a rapidly changing regulatory area, not legal advice. Thresholds and implementing rules under the Enforcement Decree are subject to revision — verify current values with Korean counsel before relying on an exemption.