TwinEthosRequest access

Law

South Korea AI Basic Act

Ministry of Science and ICT (MSIT) · South Korea (KR) · 2 provisions encoded · verified against the official source as of 2026-09-27.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: www.law.go.kr, www.msit.go.kr.

Binding law — in force

High-impact and generative AI must give advance AI-use notice and label generative outputs (South Korea)

인공지능기본법 제31조 (Art. 31) · official text · In force: applies since 22 Jan 2026 (grace period) · South Korea (KR)

Under the Korea AI Basic Act Article 31, an AI business operator that provides a product or service using high-impact or generative AI must notify users in advance that it runs on that AI (31(1)); a provider of generative AI, or of a product or service using it, must label its outputs as generated by generative AI (31(2)); and outputs such as virtual sound, images, or video that are hard to distinguish from real ones must be notified or labeled so users clearly recognize they were AI-generated, with a less intrusive manner allowed for artistic or creative works (31(3)). Methods and exceptions are set by Presidential Decree (31(4)). Extraterritorial. Detect a high-impact or generative AI service with no advance AI-use notice, generative outputs with no AI-generated label, or realistic synthetic media with no clear notice or label.

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: high risk
  • AI business operators (developers + users) providing high-impact or generative AI products/services to Korean users. Effective 2026-01-22 (grace period ≥1 year). Extraterritorial. Excludes national defense/security AI.

The guard to add

Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.

A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.

Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Tell users in advance that the product or service runs on generative or high-impact AI.
  • Label generative outputs as generated by generative AI; label sound, image or video that is hard to tell from real so users clearly recognize it as AI-generated.

Example (Next.js + Vercel AI SDK (useChat)), before:

const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });

After:

const { messages, input, handleSubmit } = useChat({
  api: '/api/chat',
  initialMessages: [{ id: 'ai-notice', role: 'assistant',
    content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message

Control: AI chat interaction without disclosure. The same guard addresses 16 items with binding law in 10 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id kr-ai-basic-act.ai-transparency · review status: primary source derived

Binding law — in force

High-impact AI operators must run risk management, explanations, and human oversight (South Korea)

인공지능기본법 제34조 (Art. 34) · official text · In force: applies since 22 Jan 2026 (grace period) · South Korea (KR)

Under the Korea AI Basic Act Article 34, an AI business operator providing high-impact AI (or a product or service using it) must implement, as prescribed by Presidential Decree: a risk-management plan; an explanation plan covering, where technically feasible, the AI's final results, the main criteria used to reach them, and an overview of the training data; user-protection measures; human management and supervision of the high-impact AI; preparation and retention of documents evidencing these measures; and other measures resolved by the national AI committee (34(1)). The Minister of Science and ICT publishes the details and may recommend compliance (34(2)); equivalent measures taken under other laws count as compliance (34(3)). Detect a high-impact AI path with no risk-management, explanation, user-protection, human-oversight, or documentation artifacts.

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: high risk, consequential decision
  • Sectors: energy, healthcare, employment, lending, transportation, education, essential services
  • AI business operators providing high-impact AI (critical sectors per Art. 2(4)) to Korean users. Effective 2026-01-22 (grace period). Extraterritorial. Excludes national defense/security.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Put human supervision and a per-decision explanation record between high-impact model output and the action it triggers, backed by a documented risk-management plan.

On the high-impact path (credit, hiring, healthcare, essential services), model output becomes a pending decision rather than an action: a person can approve, override, or stop it (review queue with override, LangGraph interrupt, a kill switch checked before acting). Each decision stores the final result, the main criteria or reason codes, the model version, and the reviewer, and an explanation endpoint returns that record to the affected user. Alongside the code, keep the risk-management plan, user-protection measures, an overview of the training data used for explanations, and documentation of these measures in the repository.

Where it goes: 9 AI output handling, 15 agent action surface, 2 data models, 12 repository artifacts.

Example (Python + scikit-learn), before:

score = model.predict_proba([features])[0][1]
status = 'approved' if score > 0.7 else 'denied'
applications.save(app_id, status=status)

After:

if settings.HIGH_IMPACT_AI_PAUSED:            # kill switch
    raise ServiceUnavailable('automated scoring paused')
score = model.predict_proba([features])[0][1]
proposed = 'approved' if score > 0.7 else 'denied'
decisions.insert(app_id=app_id, proposed=proposed, score=score,
                 reason_codes=top_reason_codes(features, k=3), model_version=MODEL_VERSION,
                 status='pending_review')
# applications.save runs from the reviewer's approve/override handler

Control: High-impact AI without risk management, explanations, and human oversight. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id kr-ai-basic-act.high-impact-ai-responsibilities · review status: primary source derived