← All briefings
International AI Law · South Korea

The world’s second comprehensive AI law is now in force.

While everyone watched Brussels, Seoul quietly became the second jurisdiction on earth with a comprehensive AI statute. South Korea’s AI Basic Act took effect January 22, 2026, and like the EU’s, it reaches beyond its borders — it can even require a foreign company to appoint someone inside Korea to answer for its AI.

What it covers

The Act is a risk-tiered framework. “High-impact” AI — in areas such as hiring, healthcare, energy, transport, and biometrics — carries real obligations: risk management, a “meaningful explanation” of outcomes, human oversight, impact assessments, and documentation. Generative AI carries transparency duties: tell users they’re dealing with AI, and label AI-generated content, including realistic audio, images, and video.

Why it reaches a U.S. company

The Act is extraterritorial — it applies to acts done abroad that affect Korean users or the Korean market. And foreign operators over certain thresholds (roughly ₩1 trillion in total revenue, ₩10 billion in AI revenue, or one million-plus average daily Korean users) must designate a domestic representative — a local point of legal accountability, echoing the EU’s authorized-representative model. If you have meaningful Korean usage, this can attach to you directly.

Enforcement and grace

Penalties include administrative fines up to ₩30 million and service-suspension orders where an AI system poses a safety threat. There is a one-year enforcement grace after the January 2026 effective date, so the teeth arrive through early 2027 — which is precisely the window to get ready rather than a reason to wait.

The pattern is now unmistakable

EU, then Korea: extraterritorial scope, a local-representative requirement, and mandatory generative-AI labeling keep recurring. A company that builds AI-interaction disclosure, content labeling, and high-impact governance once is building to a template that is going global — not to one country’s quirk. Korea is the clearest sign yet that the EU’s model is becoming the world’s default.

Do these three things now

1. If you have Korean users, check the representative thresholds now. 2. Stand up generative-AI labeling and user disclosure — the same capability EU Article 50 needs. 3. Map any “high-impact” uses (hiring, health, biometrics) and build the explanation-and-oversight file.

South Korea makes it two. The specifics differ from Europe’s, but the shape is the same — and once you’ve built for one extraterritorial, disclosure-and-oversight regime, you’ve built most of the way for the next.

This briefing is general information from Sentinel Assurance Group, not legal advice. Regulatory dates and requirements change — we maintain these briefings, but verify against primary sources and counsel before acting. Last reviewed July 22, 2026.

See how a Gap Assessment maps your exposure →

Not sure which of these reach you?
Find out in 30 minutes.

The free AI Risk Exposure call maps your AI footprint to the obligations that actually apply — and the ones that don’t.

Book the call →