AI Compliance in South Korea: AI Basic Act — What You Need to Know?

South Korea is one of the first countries in the world, and the first in Asia, to introduce comprehensive artificial intelligence legislation. Its central provision for the generative AI market is Article 31 of the AI Basic Act, which requires companies to warn users about the use of AI and to label generated content. The law has extraterritorial effect, so these requirements may also apply to Ukrainian product and outsourcing companies whose services are used by Korean users.

In this article, we will look at who the transparency obligations apply to, what the three types of obligations under Article 31 are, how to notify users and label content, which exceptions are provided, what risks exist, and what you can do right now.

What Is the AI Basic Act

The AI Basic Act (full title: Framework Act on the Development of Artificial Intelligence and Establishment of Trust) is the framework law of the Republic of Korea on AI development and the building of trust in AI. The law was adopted on January 21, 2025, and has been fully in force since January 22, 2026. The Enforcement Decree entered into force on the same day.

On January 22, 2026, the Ministry of Science and ICT of Korea (MSIT) published the Guidelines on Ensuring AI Transparency, with detailed methods for complying with Article 31, taking industry comments into account. It is the Guidelines that answer the practical question of “how to do this in the interface,” which neither the law nor the decree answered on their own.

Who the Transparency Obligations Apply To

The law is addressed to AI business operators. They are divided into two categories.

CategoryWho they areExample
AI developerA party that develops and provides AI systemsA developer of a large language model
AI-using business operatorA party that builds its own AI products or services on top of ready-made modelsA SaaS service with an AI assistant for writing texts
UserA party that merely uses generated outputs in its own activitiesA video blogger who creates videos using a video generator

The obligations are imposed on the operator that ultimately provides the AI product or service to end users, not on the users themselves. Therefore, a film studio that uses AI-generated graphics in a film is usually considered a user and is not treated as an operator. At the same time, the developer and provider of the AI technology itself are subject to the obligations.

Extraterritorial Effect

The law applies to activities abroad if they affect the market or users in Korea. For Ukrainian businesses, this means that if your AI service is available in Korea and targets Korean users, you should assess the risks of the law applying to you. It is enough for the service to affect the Korean market, and a physical presence in the country is not required.

In addition, some foreign companies are required to appoint a local representative in Korea, which we discuss below.

The Three Obligations under Article 31

Article 31 contains three different requirements that should be clearly distinguished. They may apply to the same product at the same time.

ProvisionWhen it appliesWhat must be doneType of obligation
Art. 31(1)A product or service uses high-impact AI or generative AINotify in advance that the product is based on such AIPrior notification
Art. 31(2)Generative AI, or a product or service based on it, is providedLabel that the output was created by generative AILabeling of outputs
Art. 31(3)An output (audio, image, video) is difficult to distinguish from realityClearly notify or label that it was created by AI, in a way the user can unmistakably recognizeDeepfake regime

For creative and artistic outputs, the law allows notification or labeling to be done in a way that does not interfere with the display and perception of the work. The details of the methods and exceptions are delegated to the Enforcement Decree.

Prior User Notification (Art. 31(1))

Prior notification must inform users of the very fact that the product or service is based on AI. This is not a label on each output but a general warning given before use begins. The Decree and the Guidelines allow the following methods: general terms of use or a contract, display on the screen, and, for offline services, placing the information in a visible location before use begins.

  1. Terms of use or contract. A separate statement about the use of AI in the ToS, during registration, or in the contract. Suitable for web services, SaaS, and B2B contracts.
  2. Display on the screen. A banner, an onboarding screen, or a caption in the interface. Suitable for mobile apps, web platforms, and software.
  3. Placement at the place where the service is provided. A sign or notice before use begins. Suitable for kiosks, devices, and offline services.

However, do not limit yourself to a mention in the ToS alone. For consumer products, it is more reliable to add a prominent notice in the interface, because it is easier to prove during an inspection.

Labeling the Outputs of Generative AI (Art. 31(2))

An output can be labeled in one of two ways: in a way that a human can recognize, or in a machine-readable format, in which case a message (text or voice) must be shown to the user at least once. The MSIT Guidelines distinguish two scenarios depending on where the output ends up.

Scenario 1. The Output Stays within the Service

If the output is shown in the service’s interface, it is sufficient to label it in the output itself or through the interface in a way the user can recognize.

Type of serviceHow to meet the requirement
Conversational services (chatbots)An initial message or a permanent logo in the chat window. You can also indicate on screen that the model generates responses in real time. If space is limited, a tooltip can be used
Voice assistantsA message before use begins (by voice or as on-screen text). For physical devices, a label on the casing. Repeating the notice for every voice interaction is not required
Games and metaversesLabel NPCs or characters controlled by AI (in the name or in an introductory dialogue). Notify about an AI voice when the game is launched or at login
Productivity services (for example, help with writing documents)A logo in the interface and a notice before use. Labeling each individual output is not required

Scenario 2. The Output Is Exported Outside the Service

If the output can be downloaded or distributed, the label must be applied directly to the output itself, even if it was already shown in the service’s interface. If an invisible method is used (for example, metadata), the user must be notified once about this at the time of download.

Type of outputHuman-recognizable methodMachine-readable method
TextA label in the document header. For code generation tools, in the project description or code commentsFile metadata
ImageA visible logo or label on the imageDigital watermark or metadata
VideoA logo on part of the screen or a message at the beginning of the videoDigital watermark or metadata
AudioA short message at the beginning of the recording (not required throughout the entire recording)Audio watermark (detectable after the fact) or metadata
Other file formatsA label in the header or at the beginning of the document, on the first slide for presentationsMetadata (for example, the author field)

Deepfakes (Art. 31(3))

A special regime applies to outputs that are difficult to distinguish from reality: realistic images, video, and audio. The requirements here are stricter than for ordinary generative content.

For ordinary AI content, any of the permitted labeling methods is sufficient, including machine-readable ones: a watermark or metadata. Deepfakes are different: machine-readable labeling cannot be used as the sole method here, because the user must unmistakably recognize that they are looking at AI content, so a clearly visible label is required.

For example, if a video was created with ordinary generative AI, it is enough to show a logo or a message at the beginning. If it is a deepfake, the label must remain on screen throughout the entire playback.

In addition, for ordinary AI content, the law does not separately require taking the characteristics of the audience into account. For deepfakes, you must consider the age, physical abilities, and social circumstances of the users the product is aimed at, so that the label is understandable specifically to them.

For deepfakes, only labeling methods that the user clearly recognizes are permitted. An exception exists for creative and artistic works: the notice may be shown at a different moment than the main content, or conveyed by invisible means, so as not to break the viewer’s immersion.

Exceptions to the Transparency Obligations

The obligations of prior notification or labeling do not apply, in whole or in part, if the use of AI is obvious or if AI is used solely for the operator’s internal needs.

The first exception is the obviousness of AI use. It applies when the user already unambiguously understands that they are interacting with AI, for example, if an app is called “AI Image Generator.” At the same time, the assessment depends on the circumstances, so you should not rely on this exception without analyzing the interface.

The second exception is internal use. It applies when AI is used solely for the operator’s internal business purposes and is not provided to users. If the outputs reach external users, the exception does not apply.

The third exception concerns creative and artistic works. For them, a more flexible method of notification or labeling is allowed, one that does not interfere with the perception of the work. However, this does not cancel the obligation itself: only the way it is fulfilled changes.

Liability and the Grace Period

MSIT has announced a grace period of at least one year, during which no investigations with corrective orders are conducted and no administrative fines are imposed. The countdown runs from the entry into force of the law on January 22, 2026. That is, no fines are expected until at least January 2027, while the obligations apply already now. The law provides that a violation of the transparency requirements may result in a corrective order or a fine of up to KRW 30 million.

Local Representative for Foreign Companies

A foreign operator without an address or office in Korea must appoint a local representative if at least one of the following conditions was met in the previous year: revenue of KRW 1 trillion, revenue from AI services of KRW 10 billion or more, or more than one million daily active users in Korea on average over three months. The thresholds are high, so the requirement applies primarily to large players.

Step-by-Step Algorithm: How to Prepare to Comply with Article 31

Step 1. Determine your role. Find out whether you are an AI developer, a business that uses AI in a product, or merely a user. Whether the obligations apply to you depends on this.

Step 2. Assess your connection to Korea. Check whether your product is available to Korean users, whether there is a Korean-language version, and whether your marketing targets this market.

Step 3. Classify your product’s functions. Make a list of the functions that use generative AI or high-impact AI, and separate out the functions that create audio, images, or video that resemble real ones.

Step 4. Set up prior notification. Add a statement to the terms of use and a prominent message in the interface (onboarding, banner, caption).

Step 5. Determine the labeling scenario. For each type of output, find out whether it stays within the service or can be downloaded or distributed.

Step 6. Implement technical labeling. For exported outputs, add visible labels, watermarks, or metadata according to the type of content. For deepfakes, provide a mandatory visible label.

Step 7. Document your decisions. Keep a record of which methods you chose and why, together with screenshots of the interface. This is evidence of due diligence during an inspection.

Step 8. Monitor changes. Regularly check for updates to the MSIT Guidelines and enforcement practice, especially before the grace period ends.

Conclusion

Korea’s AI Basic Act is a signal to the global IT market that transparency in the use of artificial intelligence is becoming a basic legal requirement. Although fines for violations will begin to be imposed only in 2027, Ukrainian product and outsourcing companies should build content labeling and user notification mechanisms into the architecture of their services already at the development stage. A timely audit of AI functions, updated documentation, and an adapted UI/UX will help avoid regulatory risks in the Korean market and will, at the same time, automatically prepare your products for similar requirements in other key jurisdictions, including under the European AI Act.

Tags
  • AI
  • AI Basic Act
Do you have any questions for the lawyers?
up to 500 characters
An error occurred
The request has been sent Thank you for your message! We will process it as soon as possible.

Articles on the topic

Go to the blog