Hello, this is Ryuta Hamamoto from TIMEWELL.
On January 22, 2026, Korea’s AI Basic Act (Framework Act on the Development of Artificial Intelligence and Establishment of a Trust Base) took effect—the world’s second comprehensive AI law after the EU AI Act.
Japanese media barely covered it. As of August 2026, I still meet Japanese companies that only know “Korea made some AI law” and have not noticed the domestic agent duty. That is dangerous.
Here is the Seoul-originated outline, translated into points Japanese companies must act on now.
TL;DR
- Effective January 22, 2026; world’s second comprehensive AI law; one-year grace period on penalties
- Overseas operators: domestic agent appointment duty; non-appointment = Article 43 fine up to 30 million KRW (~USD 21,000)
- High-impact AI limited to ten sectors (energy, healthcare, finance, etc.); no expansion in the decree draft
- Deepfake ads: 5× damages (punitive), plus forced labeling via network-law amendment
- Japanese priority: agent selection, applicability inventory, labeling stack—the grace year decides outcomes
Outline of the law — how it differs from the EU AI Act
The AI Basic Act is a 70-article statute passed by the National Assembly on December 26, 2024. The Lee Jae-myung (Democratic Party) administration initially leaned industrial promotion over regulation; after Trump’s November 2024 US election win and expected US regulatory retreat, Korea instead chased positioning as “the country that made the world’s second comprehensive AI law”1.
Read the text and both grain and reach differ from the EU AI Act. The EU uses four risk tiers and strict duties on all Annex III high-risk categories—a full enumeration model. Korea lists high-impact AI in ten sectors and compresses operator duties to five:
- Transparency — notify generative AI output; labeling; watermarking
- Safety — technical and organizational security measures
- Special duties for high-impact AI operators — risk management plans, social-impact monitoring, respond to data requests and on-site inspections
- AI impact assessment — pre-deployment for high-impact AI
- Domestic agent appointment — overseas operators must appoint (extraterritorial core)
The penalty scale is another gulf. EU AI Act tops out at €35M (¥5.6B) or 7% of worldwide turnover; Korea’s Article 43 maxes at 30 million KRW (¥3M). Read that as behavioral guidance, not deterrence.
I call this a careful second-mover strategy. Two years after the EU AI Act, Korea watched market reaction and landed soft enough not to drive foreign operators out—while still locking easy-to-enforce duties like labeling and agent appointment.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
Article 43 — only three violation types carry fines
Despite many articles, only three types under Article 43 are finable—critical for Japanese compliance design.
| Violation type | Penalty |
|---|---|
| Overseas operator fails to appoint a domestic agent | Up to 30M KRW |
| User notification duty breach (not notifying interaction with generative / high-impact AI) | Up to 30M KRW |
| Breach of government corrective order | Up to 30M KRW |
Other duties (e.g., high-impact risk management plans, impact assessment) have no direct monetary fine—they escalate only after guidance and corrective orders.
That design is unlike the EU AI Act or California SB 53. For Korea, a realistic priority is: clear the three finable types first; treat remaining duties as best-effort for now.
Do not get too optimistic. MSIT set January 22, 2026–January 2027 as a grace period with guidance rather than fines2. The clock for harder enforcement after January 2027 is already running. If I had to pick one Korea checklist item for Japanese SaaS, it would be domestic agent appointment before anything else.
Domestic agent duty — first reason Japanese firms must move now
The highest-impact obligation for Japanese companies is domestic agent appointment.
Same idea as GDPR Article 27: operators without a Korean establishment providing AI services to Korean users must place a local agent as MSIT’s doorway. Thresholds (revenue, user counts) sit in enforcement rules; most global SaaS is in scope.
Agent roles, mainly:
- Contact point for MSIT and user inquiries/complaints
- Respond to data requests and on-site inspections
- Receive administrative orders and relay to HQ
Standard pattern: contract with a Korean law firm, consultancy, or local entity. GDPR representative annual fees often ran €500–2,000; Korea should settle in a similar band.
My first message: do not stop at the contract. Without ops design for which HQ unit responds within how many hours when MSIT inquires, a paper agent is useless. GDPR’s “appointed but HQ freezes” failure mode will repeat.
Ten high-impact AI sectors — closed-list interpretation
High-impact AI sectors in the decree draft are a closed list of ten3:
| Sector | Example systems |
|---|---|
| Energy | Smart-grid optimization; nuclear operations support AI |
| Drinking water / water resources | Water quality; distribution network control AI |
| Healthcare | Diagnostic support; SaMD |
| Finance | Credit scoring; fraud detection; algo trading |
| Biometrics | Face, fingerprint, voiceprint authentication |
| Employment | HR tech; hiring screens; performance scoring |
| Education | Adaptive learning; admissions scoring |
| Public services | Welfare benefit decisions; tax risk scoring |
| Criminal investigation | Predictive policing; crime risk scoring |
| Biometric identification | Crowd recognition; specific-person tracking |
Civil society calls the list too narrow. Business and Human Rights Resource Centre (September 2025) flagged missing human-rights risk framing—especially content moderation, election AI, migration/refugee AI, military/security AI off the list4.
I read that “human-rights gap” as opportunity for Japanese firms: list-out domains (e.g., interview-video analysis, internal comms analytics) can avoid heavier high-impact duties—for now. Opposition and civic groups have said they will push expansion in 2026–2027, so keep an internal watchlist of sectors that may enter later.
Deepfake 5× damages — a Korea-specific model
Separate from the Basic Act itself, deepfake ad rules decided under prime-ministerial lead in December 2025 hit marketing DX teams hard.
Using AI-generated or edited photos/video/audio in ads requires a visible label (“AI-generated,” “not real footage,” etc.). Victims can claim up to five times ordinary damages—the “5× damages” (5배 손해배상) scheme5.
Five times is Korea-specific. US punitive damages caps vary by state (e.g., Texas 2× actual + $750k; Florida 3×). “Up to 5× actual” is heavy by US punitive standards.
Implementation is via amendment of the Network Act (Act on Promotion of Information and Communications Network Utilization and Information Protection), forcing labeling on SNS, video, and ad platforms. Japanese firms running influencer marketing or AI banners into Korea need (1) label embedding at generation, (2) declarations at platform submission, (3) 5× damages risk assessment in operations.
“Japan-facing campaigns need no label” fails—if Korean users view a global campaign, you are in scope. Like US TRAIGA extraterritorial design, the practical reach is “one Korean user and you apply.”
Preparing for the hard-law chain reaction — WARP SECURITY
EU AI Act (general application from August 2, 2026—though substantive high-risk AI duties start December 2, 2027 for Annex III types and August 2, 2028 for Annex I types), Korea AI Basic Act (January 2026), Vietnam AI Law (March 2026). I call 2026 the year of East/Southeast Asia hard-law chain reaction—three comprehensive regimes moving within a short window.
TIMEWELL’s WARP SECURITY builds multi-jurisdiction response on the table, not only in decks: EU Annex III checklists, Korea Article 43 finable list, Vietnam risk classifications—map each AI use case to which jurisdiction lights which duty.
Common patterns:
- Unified generative AI labeling stack — EU, Korea, India, California SB 942, China each differ slightly; pick a max-common-denominator technical spec for all
- Domestic agent network — EU and Korea now; Vietnam/Indonesia may follow; keep standard regional agent contract templates
- Multilingual labeling audit logs — evidence labels actually displayed, with Korea 5× and India DPDP 250 crore in view
I keep seeing Tokyo HQ try to absorb Korea legal intake and fail—if HQ legal cannot handle Korean-language inquiries, agent appointment is empty. Within three months, clarify who is legally accountable for every Korea-facing AI use case.
The grace period ends in January 2027. Work backward from agent selection and contracting through to an HQ that can actually answer an MSIT inquiry, and this is not a sequence you can start near the deadline and still finish.
Latest as of August 2026 — getting the EU AI Act timeline right
The hard-law chain reaction continues, and the biggest movement is on the EU side: the Digital Omnibus amending the AI Act (Regulation (EU) 2024/1689) has been enacted as Regulation (EU) 2026/1744. Adopted July 8, 2026; published in the Official Journal (OJ L 2026/1744) on July 24, 2026; in force July 27, 2026. It is no longer a provisional political agreement—read it as law already on the books.
The single most common misreading among Japanese companies is that “the EU AI Act applies in full on August 2, 2026, and high-risk AI duties all fire at once.” That is wrong. Under the amended Article 113, the general application date remains August 2, 2026, but the substantive high-risk duties sit outside it.
| Date | What applies from that date |
|---|---|
| February 2, 2025 | Chapter I (general provisions, definitions, Art. 4 AI literacy); Chapter II (Art. 5 prohibited practices) |
| August 2, 2025 | Chapter III Section 4 (notifying authorities); Chapter V (GPAI models); Chapter VII (governance); Chapter XII (penalties, Art. 99 and 100); Art. 78. Art. 101 excluded |
| July 27, 2026 | Amending Regulation 2026/1744 enters into force; AI Act Arts. 102–110 (amendments to other legislation) begin to apply |
| August 2, 2026 (general application date) | Chapter IV (Art. 50 transparency duties); Chapter III Section 5 (Arts. 40–49: harmonised standards, conformity assessment, CE marking, registration); Chapter VI; Chapters VIII–XI; Art. 101 (Commission power to fine GPAI providers) |
| December 2, 2026 | New prohibited practices (Art. 5(1)(ba), (bb); Art. 5(1a), (1b)). Plus the new Art. 111(4): providers of synthetic-content-generating AI placed on the market before August 2, 2026 must comply with Art. 50(2) by this date |
| August 2, 2027 | Art. 111(3): compliance deadline for GPAI models placed on the market before August 2, 2025 |
| December 2, 2027 | Annex III high-risk AI (Art. 6(2)) becomes subject to Chapter III Sections 1–3. Art. 22 (EU authorised representative), Art. 25 (value chain), Art. 26 (deployer duties) and Art. 27 (FRIA) also start here |
| August 2, 2028 | Annex I high-risk AI (Art. 6(1), embedded in products) becomes subject to the same duties |
| August 2, 2030 / December 31, 2030 | Art. 111(2) (use by public authorities) / Art. 111(1) (Annex X large-scale IT systems) |
So what actually starts on August 2, 2026 is Art. 50 transparency duties and the Commission’s power to fine GPAI providers under Art. 101, among others—not the substantive high-risk regime. GPAI-related sanctions run up to €15M or 3% of worldwide turnover; Art. 5 prohibited-practice breaches up to €35M or 7% (Regulatory framework on AI (European Commission)). Next to Korea’s 30M KRW Article 43 ceiling, the fine-scale gap is starker still.
You may also see claims that Art. 50 transparency duties were pulled forward to December 2, 2026. That is also wrong. Chapter IV appears in none of the exceptions in Article 113’s third paragraph, so Art. 50 still applies from August 2, 2026. Regulation 2026/1744 amended only Art. 50(7) (codes of practice); the substantive duties in (1)–(6) are unchanged. Two things happen on December 2, 2026: the new prohibited practices begin, and the Art. 111(4) transition deadline for existing systems falls due.
The legacy provision for high-risk AI already on the market (Art. 111(2)) changed as well. Systems already placed on the market are caught only where significant changes in their designs are made on or after the date Chapter III applies to them. The reference point is no longer a fixed August 2, 2026—it now tracks the Chapter III application dates (December 2, 2027 and August 2, 2028).
My view, for what it is worth: design a shared generative AI labeling stack against EU-weight duties and you can often cover Korea’s agent and notification duties as a subset. Domestically, watch the PIP Act 2026 amendment alongside cross-border data.
Key takeaways
- Korea AI Basic Act: world’s second comprehensive AI law; live Jan 22, 2026; grace to Jan 2027
- Only three Article 43 finable types: no domestic agent; user notification breach; corrective order breach—each up to 30M KRW
- Domestic agent duty is Japanese firms’ top priority; most global SaaS in scope
- High-impact AI: ten-sector closed list; HR tech, credit, SaMD most likely hits
- Deepfake 5× damages is unique; global ads viewed by Korean users apply
Korea’s design looks like a third stance between EU and US: not as strict as the EU, not as free as the US. Soft fines, hard on labeling and agents—“Made in Korea” brand consciousness meeting civic pressure with realism.
For Asian AI regulation, treat Korea as the first market you get right. Fail here and you will fail the same way in Vietnam and later Indonesia/Thailand. Start the agent conversation this week; inventory can wait until next month if you must choose.
Further reading: EU AI Act Digital Omnibus and 2026 schedule, California AI three-pack, Texas TRAIGA vs New York RAISE Act.
References
- South Korea's New AI Framework Act: A Balancing Act - Future of Privacy Forum
- One Law Sets South Korea's AI Policy - ITIF
- South Korea: Comprehensive AI Legal Framework Takes Effect - Library of Congress
- Korea's new AI Basic Act: Characteristics and significance - Law.asia
- Global AI Governance Law and Policy: South Korea - IAPP
Footnotes
-
South Korea's AI Basic Act: Overview and Key Takeaways - Cooley ↩
-
South Korea's Revised AI Basic Act to Take Effect January 22 - BABL AI ↩
-
South Korean Ministry of Science and ICT Issues Package of Regulations - Baker Botts ↩
-
S. Korea: Draft decree for AI Basic Act spark backlash - Business and Human Rights Centre ↩
-
Deepfake Regulation: Korea Orders AI Ad Labels - AI CERTs News ↩






