Skip to content

Glossary

AI Basic Act

South Korea's framework law for AI, which sets out to promote the industry and to head off its risks within a single instrument.

In plain terms

A Korean law that tries to do two things at once: grow the country's AI industry and put rules around its risks. Most places have treated those as separate jobs for separate documents, which is what makes this one worth looking at.

01

Why it matters

Because it is the clearest example of a regime that does not treat regulation and promotion as opposites, and anybody comparing jurisdictions will read it wrongly if they expect a risk-only statute. It also names generative systems as a target in their own right rather than folding them into a general category.

02

How it works

It is a framework law, which means it establishes national structure rather than only imposing duties. Setting up governance for AI, fostering the industry systematically and preventing risks in advance all sit inside the same instrument, which is unusual and deliberate.

Promotion and risk are not treated as opposing goals. That framing matters when comparing regimes, because a reader expecting a purely restrictive statute will misread both its intent and the political settlement behind it.

Generative systems are named as a regulatory target in their own right, alongside the category reserved for higher-consequence uses. Elsewhere generative output tends to be handled through general disclosure duties rather than by naming the technology.

The stated concerns are technological limitations as well as misuse and abuse. Including limitations is a meaningful choice: it treats a system that simply is not good enough as a regulatory matter, not only one that somebody has deliberately pointed at a bad end.

Three heads of obligation carry the duties: transparency, safety, and the responsibilities of operators. That last one is the interesting one for buyers, because it puts weight on the party running a system rather than only on whoever built it.

Naming a technology rather than only a use is a design choice with a known cost, which is worth understanding rather than judging. Categories drawn around a technology are easy to apply and age badly as the technology moves; categories drawn around consequences age well and are harder to apply. This regime accepts the first trade where others take the second.

It was passed with a year before it took effect, which is the pattern worth noticing rather than the specific interval. Framework laws of this kind arrive with a preparation window, and the useful question about any regime is what happens during that window rather than what the headline duties say.

Two ways a jurisdiction can write an AI law

Two ways a jurisdiction can write an AI lawMost comparison written for businesses treats these as points on a single line running from permissive to strict, and then places each jurisdiction along it. That framing survives about as long as it takes to read two of the laws. A framework statute that establishes national governance while committing to foster an industry is not a weaker version of a risk-tiered regime; it is answering a different question, one about what the country is building rather than only about what it will not allow. The practical consequence for an organisation operating across several places is that you cannot rank the regimes and comply with the strictest. The obligations are not nested, the categories are drawn differently, and a technology named as a target in one place may be handled through a general duty in another with quite different triggers. What travels is the underlying discipline: knowing what you have deployed, what it affects, who owns it and what happens when it goes wrong. That work is not wasted anywhere, which is the only genuinely portable answer.Risk-firstSorts uses by potential harm.Duties attach to the riskiest.Promotion lives elsewhere.Framework-firstSets up national structure.Growth and risk in oneinstrument.Names technologies, not onlyuses.Neither column is the carefulone and neither is thepermissive one, which is theassumption worth dropping. Theyare different bets about what astate is trying to build, andthey produce different documentsfor different reasons.
Most comparison written for businesses treats these as points on a single line running from permissive to strict, and then places each jurisdiction along it. That framing survives about as long as it takes to read two of the laws. A framework statute that establishes national governance while committing to foster an industry is not a weaker version of a risk-tiered regime; it is answering a different question, one about what the country is building rather than only about what it will not allow. The practical consequence for an organisation operating across several places is that you cannot rank the regimes and comply with the strictest. The obligations are not nested, the categories are drawn differently, and a technology named as a target in one place may be handled through a general duty in another with quite different triggers. What travels is the underlying discipline: knowing what you have deployed, what it affects, who owns it and what happens when it goes wrong. That work is not wasted anywhere, which is the only genuinely portable answer.
03

Seen in the wild

  • Generative systems named as a regulatory target rather than covered by general disclosure rules.

    ChatGPT
  • Weight falling on the organisation running a deployment, not only on whoever built it.

    Glean
  • Transparency, safety and operator responsibility as three headings to evidence against.

    Vanta
04

Common misconceptions

People assume

It is a restrictive law like the European one.

In fact

Its stated design pairs preventing risks with systematically fostering the industry inside one instrument. Reading it as purely restrictive misses both what it is trying to do and why it was politically possible.

People assume

Regulation here is about deliberate misuse.

In fact

The stated concerns include technological limitations alongside misuse and abuse. A system that is simply not good enough for what it is being used for is treated as a matter for the rules, not just one for the buyer.

05

Questions

How does it differ from the European approach?
It combines promoting the industry with preventing risks in a single framework law, rather than separating those aims into different instruments. It also names generative systems as a regulatory target in their own right instead of covering their output through general disclosure duties.
What obligations does it establish?
Three heads: transparency, safety, and the responsibilities of operators. The third is the one buyers should notice, because it places weight on the organisation running a system rather than resting everything on whoever originally built it, which is the opposite of how most people assume these duties fall.
Where should we check what actually applies to us?
The Act itself, through Korea's official legal databases, and with local advice. The categories it defines and the sectors they cover are the operative detail, and they are the part most secondary summaries get subtly wrong or describe from an earlier draft.
06

Key takeaways

  • A framework law: national structure, not only duties on companies.
  • Promotion and risk prevention sit in the same instrument by design.
  • Generative systems are a named target, not a general disclosure case.
  • Duties run to operators, not only to whoever built the system.
08

Tools that use this

  • ChatGPT

    Generative systems named as a target in their own right.

  • Glean

    Weight on the organisation running a deployment.

  • Vanta

    Transparency, safety and operator duties as headings.

Last checked August 2026

All glossary terms