Regulatory Governance of AI in the Generative AI Era: A Comparative Study of South Korea’s AI Basic Act and the EU AI Act for Sustainable Digital Transformation
Abstract
1. Introduction
2. Legislative Background and Regulatory Philosophy of Korea’s Basic Act on Artificial Intelligence
2.1. Legislative History and the Jurisprudential Legacy of Consolidated Review
2.2. The Dual Nature of Regulatory and Promotion Laws and Its Implications for Interpretation
2.3. Comparison of Legislative Philosophy with the EU AI Act
3. Conceptual Framework Analysis of Article 2 Definitions in the Basic Act on Artificial Intelligence (2025)
- (1)
- The Technology Layer, which encompasses AI, AI Technology, AI Systems and Training Data.
- (2)
- The Regulatory Target Layer, which includes High-Impact AI and Generative AI.
- (3)
- The Actor Layer, which comprises Business Operator, User and Affected Person.
- (4)
- The Society/Value Layer, which includes AI Industry, AI Society and AI Ethics. In contrast to the EU AI Act, which defines the ‘AI System’ as the sole regulatory unit and delegates technical methodologies and data to separate legislation, Korean law incorporates the technological, societal and value layers into its definition clauses. This approach is implemented from the conceptual design stage, serving both regulatory and promotional functions.
3.1. Technical Layer
3.2. Regulatory Scope: The Legal Distinction Between ‘High Impact’ and ‘High Risk’
3.3. Actor Level: Integration of the Business Operator Concept and the Significance of ‘Affected Parties’
3.4. Overlapping Application Issues at the Social/Value Level and for High-Impact/Generative AI
3.5. Conclusions
4. The Industrial Utility and Legal Limitations of High-Impact AI Regulation
4.1. Industrial and Policy Utility
4.2. Public Law Limitations: Principle of Clarity and Prohibition of Blanket Delegation
4.3. Judicial Limitations: Potential Distortion of Liability Attribution and Gaps in Remedies
4.4. Conclusion: Evaluation as a Strategic Trade-Off
5. Analysis of the Self-Regulatory Structure in Korea’s Basic Act on Artificial Intelligence
5.1. Legal Status of the Multi-Layered Normative Structure and Constitutional Limits
5.2. Legal Nature and Normative Limits of Duty Provisions
5.3. Conditions for the Effectiveness of Self-Regulation and Institutional Vulnerabilities
5.4. Conclusion: Directions for Redesigning the Co-Regulatory Model
6. Legislative Proposals and Conclusions
6.1. Implications of the EU AI Act’s Dynamic Regulatory Adjustment System
6.2. A Five-Step Legislative Model for Dynamic Regulatory Adjustment in Korea
6.3. Modernization of Civil Liability Jurisprudence
- -
- Legal revision within a timeframe of five years. The following five points are to be considered:
- (1)
- The establishment of a mandatory triennial re-evaluation of the high-impact AI list, as well as the basis for establishing an expert committee.
- (2)
- The codification of procedures for reporting re-evaluation results to the National Assembly and for objections.
- (3)
- The addition of a sunset clause to convert Article 34’s duty provisions into mandatory obligations, and the revision of the sales-based penalty system.
- (4)
- The establishment of provisions for presumption of causation in high-impact AI damage compensation lawsuits and liability allocation by supply chain segment.
- (5)
- The establishment of an AI Dispute Mediation Committee and the preparation of collective mediation procedures. Long-term tasks (beyond five years) include: The establishment of an independent supervisory body to separate the Ministry of Science and ICT’s industrial promotion functions from its regulatory and supervisory functions is recommended. Furthermore, the legalisation of the K-AI Safety Standard system and establishment of a presumption of conformity clause for compliance with harmonised standards is advised. Finally, the integration of regulations specialised for foundation models (e.g., GPAI models) into existing laws or the establishment of separate legislation is suggested.
6.4. Conclusion: The Normative Status and Challenges of the Framework Act on Artificial Intelligence
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Almada, Marco, and Anca Radu. 2024. The Brussels Side-Effect: How the AI Act Can Reduce the Global Reach of EU Policy. German Law Journal 24: 646–74. [Google Scholar] [CrossRef] [Scilit]
- Barocas, Solon, Moritz Hardt, and Arvind Narayanan. 2023. Fairness and Machine Learning. Cambridge: MIT Press. [Google Scholar]
- Bertolini, Andrea. 2025. Artificial Intelligence and Civil Liability—A European Perspective. Publication for the Committee on Legal Affairs. Luxembourg: European Parliament. [Google Scholar]
- Biden, Joseph R., Jr. 2023. Executive Order 14110: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence. 88 Federal Register 75191, November 1. Washington, DC: The White House.
- Bradford, Anu. 2020. The Brussels Effect: How the European Union Rules the World. Oxford: Oxford University Press, pp. 23–45. [Google Scholar]
- Calabresi, Guido. 1982. A Common Law for the Age of Statutes. Cambridge: Harvard University Press, pp. 44–58. [Google Scholar]
- Civil Act of the Republic of Korea. 2024. Act No. 20276, Partially Amended 13 February 2024. Seoul: Government of the Republic of Korea. Available online: https://www.law.go.kr/ (accessed on 26 April 2026).
- Coglianese, Cary, and Evan Mendelson. 2010. Meta-Regulation and Self-Regulation. In The Oxford Handbook of Regulation. Edited by Robert Baldwin, Martin Cave and Martin Lodge. Oxford: Oxford University Press, pp. 146–68. [Google Scholar]
- Colorado General Assembly. 2024. Senate Bill 24-205, Consumer Protections for Artificial Intelligence. Signed 17 May 2024. Effective 1 February 2026. Denver: Colorado General Assembly. [Google Scholar]
- Constitutional Court of the Republic of Korea. 1992. Decision 89HunGa104. February 25. Seoul: Constitutional Court of the Republic of Korea. [Google Scholar]
- Constitutional Court of the Republic of Korea. 2002. Decision 2000HunBa57. July 18. Seoul: Constitutional Court of the Republic of Korea. [Google Scholar]
- Constitutional Court of the Republic of Korea. 2004. Decision 99HunBa91. October 28. Seoul: Constitutional Court of the Republic of Korea. [Google Scholar]
- Constitutional Court of the Republic of Korea. 2006. Decision 2005HunBa31. March 30. Seoul: Constitutional Court of the Republic of Korea. [Google Scholar]
- Constitution of the Republic of Korea. 1987. Available online: https://elaw.klri.re.kr/eng_service/lawView.do?lang=ENG&hseq=1 (accessed on 26 April 2026).
- Cyberspace Administration of China. 2023. Interim Measures for the Management of Generative Artificial Intelligence Services. Effective 15 August 2023. Beijing: Cyberspace Administration of China. [Google Scholar]
- Ebers, Martin. 2025. Truly Risk-Based Regulation of Artificial Intelligence: How to Implement the EU’s AI Act. European Journal of Risk Regulation 16: 684–703. [Google Scholar] [CrossRef] [Scilit]
- Ebers, Martin, Veronica R. S. Hoch, Frank Rosenkranz, Hannah Ruschemeier, and Björn Steinrötter. 2021. The European Commission’s Proposal for an Artificial Intelligence Act—A Critical Assessment. Journal of Law, Technology and Society 1: 589–603. [Google Scholar]
- European Commission. 2021. Proposal for a Regulation Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act). COM/2021/206 Final. Brussels: European Commission.
- European Commission. 2022a. Proposal for a Directive on Adapting Non-Contractual Civil Liability Rules to Artificial Intelligence (AI Liability Directive). COM/2022/496 Final. Brussels: European Commission.
- European Commission. 2022b. Proposal for a Directive on Liability for Defective Products. COM/2022/495 Final. Brussels: European Commission.
- European Union. 2006. Regulation Concerning the Registration, Evaluation, Authorisation and Restriction of Chemicals (REACH). Regulation (EC) No 1907/2006. Brussels: European Parliament and Council of the European Union.
- European Union. 2022. Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European Data Governance (Data Governance Act). OJ L 152, 3.6.2022. Brussels: European Union. [Google Scholar]
- European Union. 2023. Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on Harmonised Rules on Fair Access to and Use of Data (Data Act). OJ L, 22.12.2023. Brussels: European Union. [Google Scholar]
- European Union. 2024. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act). OJ L, 12.7.2024. Brussels: European Union. [Google Scholar]
- Framework Act on Artificial Intelligence (Act No. 20676). 2025. Promulgated 21 January 2025, Effective 22 January 2026. Republic of Korea. Available online: https://elaw.klri.re.kr/eng_service/lawView.do?hseq=71019&lang=ENG (accessed on 26 April 2026).
- Gasser, Urs, and Virgilio A. F. Almeida. 2017. A Layered Model for AI Governance. IEEE Internet Computing 21: 58–62. [Google Scholar] [CrossRef] [Scilit]
- Hacker, Philipp. 2023. The European AI Liability Directives—Critique of a Half-Hearted Approach and Lessons for the Future. Computer Law & Security Review 51: 105871. [Google Scholar]
- Helberger, Natali, and Nicholas Diakopoulos. 2023. ChatGPT and the AI Act. Internet Policy Review 12: 1. [Google Scholar] [CrossRef] [Scilit]
- Joint Ministry Report. 2019. National Strategy on Artificial Intelligence. Seoul: Government of the Republic of Korea. [Google Scholar]
- Kim, Kwang-Soo. 2025. Considerations on the Enactment and Implementation of the Framework Act on Artificial Intelligence. Sogang Law Review 14: 40–75. [Google Scholar]
- Kim, Yong-Deok, ed. 2019. Commentary on the General Provisions of the Civil Code, 5th ed. Seoul: Korean Society of Judicial Administration. [Google Scholar]
- Kwon, Soon-Hyun. 2025. Review and Improvement Directions for the Framework Act on Artificial Intelligence. Journal of the Korea Society of Computer and Information 30: 25–48. [Google Scholar] [CrossRef] [Scilit]
- Laux, Johann, Sandra Wachter, and Brent Mittelstadt. 2024. Trustworthy Artificial Intelligence and the European Union AI Act: On the Conflation of Trustworthiness and Acceptability of Risk. Regulation & Governance 18: 3–32. [Google Scholar]
- Lee, Won-Woo. 2008. Regulatory Reform and Deregulation—A Legal Policy Study for Designing Proper Regulatory Policy. Justice 106. [Google Scholar]
- Madiega, Tambiama. 2024. Artificial Intelligence Act. PE 698.792. Brussels: European Parliamentary Research Service.
- National Assembly Science, Technology, Information, Broadcasting and Communications Committee. 2024. Review Report on the Basic Act on the Development of Artificial Intelligence and the Establishment of a Trust-Based Framework (Alternative Bill). Seoul: National Assembly. [Google Scholar]
- National Human Rights Commission of Korea. 2024. Statement of Opinion on Certain Provisions of the Framework Act on the Development of Artificial Intelligence and the Establishment of a Trust-Based System. Seoul: NHRCK. [Google Scholar]
- Novelli, Claudio, Federico Casolari, Antonino Rotolo, Mariarosaria Taddeo, and Luciano Floridi. 2024a. AI Risk Assessment: A Scenario-Based, Proportional Methodology for the AI Act. Digital Society 3: 13. [Google Scholar] [CrossRef] [Scilit]
- Novelli, Claudio, Mariarosaria Taddeo, and Luciano Floridi. 2024b. Accountability in Artificial Intelligence: What It Is and How It Works. AI & Society 39: 1871–82. [Google Scholar]
- OECD. 2019. Recommendation of the Council on Artificial Intelligence. OECD/LEGAL/0449. Paris: OECD. [Google Scholar]
- Pasquale, Frank. 2015. The Black Box Society. Cambridge: Harvard University Press, pp. 190–210. [Google Scholar]
- Presno Linera, Miguel Ángel, and Anne Meuwese. 2025. Regulating AI from Europe: A Joint Analysis of the AI Act and the Framework Convention on AI. The Theory and Practice of Legislation 13: 292–311. [Google Scholar] [CrossRef] [Scilit]
- Ra, Gi-won. 2025. Legislative History and Challenges of the Framework Act on Artificial Intelligence. Legislative Research 69: 128–55. [Google Scholar]
- Smuha, Nathalie A. 2021. From a ‘Race to AI’ to a ‘Race to AI Regulation’: Regulatory Competition for Artificial Intelligence. Law, Innovation and Technology 13: 57–84. [Google Scholar] [CrossRef] [Scilit]
- Stanford University Human-Centered Artificial Intelligence. 2024. AI Index Report 2024. Stanford: Stanford University, p. 142. [Google Scholar]
- Sunstein, Cass R. 2005. Laws of Fear: Beyond the Precautionary Principle. Cambridge: Cambridge University Press, pp. 13–34. [Google Scholar]
- Supreme Court of the Republic of Korea. 2005. Decision 2002Da5474. March 10. Seoul: Supreme Court of the Republic of Korea. [Google Scholar]
- Supreme Court of the Republic of Korea. 2009. Decision 2009Du7967. December 24. Seoul: Supreme Court of the Republic of Korea. [Google Scholar]
- United States v. Carroll Towing Co. 1947. 159 F.2d 169 (2d Cir. 1947). Available online: https://law.justia.com/cases/federal/appellate-courts/F2/159/169/1565896/ (accessed on 26 April 2026).
- Veale, Michael, and Frederik Zuiderveen Borgesius. 2021. Demystifying the Draft EU Artificial Intelligence Act—Analysing the Good, the Bad, and the Unclear Elements of the Proposed Approach. Computer Law Review International 22: 97–112. [Google Scholar] [CrossRef] [Scilit]
- Wachter, Sandra. 2024. Limitations and Loopholes in the EU AI Act and AI Liability Directives: What This Means for the European Union, the United States, and Beyond. Yale Journal of Law & Technology 26: 671–718. [Google Scholar]
| 1 | (Ra 2025, p. 128). The EU AI Act (European Union 2024) entered into force on 1 August 2024; the Korean Framework Act on Artificial Intelligence (Act No. 20676) was promulgated on 21 January 2025, and will take effect on 22 January 2026. |
| 2 | See EU AI Act (European Union 2024), Recital 1 and Article 1. The EU AI Act addresses innovation promotion within the context of ensuring the free movement of AI in the internal market, with the single core objective being the protection of fundamental rights. |
| 3 | |
| 4 | Article 35 of the Framework Act on Artificial Intelligence. For criticism of the ‘duty to make efforts’ for impact assessments, see (Kwon 2025), p. 35. |
| 5 | See EU AI Act, Article 40 (Harmonized Standards). Compliance with harmonized standards confers a presumption of conformity effect. |
| 6 | This is based on the request that, premised on the AI Framework Act being a product of conscious trade-offs, its legal limitations should be empirically examined. |
| 7 | |
| 8 | Article 2(3) of the Framework Act on Artificial Intelligence (2025). Annex I of the EU AI Act (European Union 2024) lists machine learning, logic-based, and statistical approaches as examples of AI techniques but does not define them as separate legal concepts. |
| 9 | See (European Union 2022) (Data Governance Act); (European Union 2023) (Data Act). For issues of bias in training data and unfairness in AI outcomes, see (Barocas et al. 2023), chap. 1. |
| 10 | Article 2(2) of the Framework Act on Artificial Intelligence (2025). The definition of AI System in Article 3(1) of the EU AI Act (European Union 2024) is based on (OECD 2019). |
| 11 | Article 2(4), Article 31, and Article 34 of the Basic Act on Artificial Intelligence. |
| 12 | Learned Hand formula from United States v. Carroll Towing Co. (1947): B < PL (Preventive Cost < Probability of Occurrence × Magnitude of Harm). |
| 13 | For the conceptual distinction between ‘Impact’ and ‘Risk’, see (Veale and Zuiderveen Borgesius 2021). |
| 14 | For the stigma effect and AI regulatory acceptability, see Veale & Borgesius, op. cit., pp. 100–101. |
| 15 | EU AI Act, Article 3(3)(4)(6)(7)(8). The EU AI Act imposes distinct obligations on Providers, Deployers, Importers, Distributors, and Product Manufacturers. The allocation of obligations between Providers and Deployers is designed based on who holds greater information and control within the AI supply chain. |
| 16 | Article 2(9) of the Framework Act on Artificial Intelligence; Kim Kwang-soo, op. cit., pp. 55–58. While GDPR Article 22 grants data subjects the right to request an explanation for automated decisions, Korean law differs by defining affected persons as independent actors within the regulatory framework. |
| 17 | Article 34(1)(4) of the Framework Act on Artificial Intelligence (duty to establish objection procedures). This too is a ‘duty’ provision, limited in that it is not directly linked to sanctions. |
| 18 | The EU AI Act declares respect for human dignity, freedom, equality, and fundamental rights as the foundation for AI regulation in Recital 1, but does not include this in its Definitions (Article 3). Comparatively, Canada’s AIDA and major US AI executive orders also do not include concepts like ethics or industrial promotion in their definitions. |
| 19 | EU AI Act, Article 25(2). |
| 20 | Basic Act on Artificial Intelligence, Articles 4, 34, and 44. Article 75 of the Constitution requires that when delegating authority through presidential decrees, the scope must be “specifically defined.” |
| 21 | EU AI Act, Annex III (List of high-risk AI systems related to Article 6(2)). |
| 22 | European Commission, Proposal for a Directive on adapting non-contractual civil liability rules to artificial intelligence (European Commission 2022a); Proposal for a Directive on liability for defective products (European Commission 2022b). |
| 23 | Constitutional Court Decision 99HunBa91, rendered 28 October 2004 (Constitutional Court of the Republic of Korea 2004). Matters concerning the essence of citizens’ fundamental rights must be determined by the National Assembly itself; delegating this to administrative legislation violates the principle of parliamentary reservation. |
| 24 | See (Lee 2008), Analysis of the phenomenon where soft norms acquire de facto binding force in administrative practice and its implications for the rule of law. |
| 25 | (Supreme Court of the Republic of Korea 2005). The court ruled that imposing disadvantageous measures solely for non-compliance with administrative guidance violates the prohibition on disadvantageous measures under Article 48(2) of the Administrative Procedure Act. |
| 26 | EU AI Act, Articles 9–15, Article 71 (Penalties). |
| 27 | EU AI Act, Article 56 (Codes of Practice). |
| 28 | EU AI Act, Recital 47 and Article 7. |
| 29 | Article 75 of the Constitution. The delegated legislation model under Article 290 TFEU and the delegated legislation system under Article 75 of the Korean Constitution are fundamentally different in terms of the method of parliamentary oversight and the requirements for the limits of delegation. |
| 30 | Regarding the Direction for Amending Article 4 of the Framework Act on Artificial Intelligence. Annex III of the EU AI Act directly enumerates eight high-risk AI sectors within the legal text. |
| 31 | This procedure adapts the structural principles of the U.S. Congressional Review Act to suit Korea’s unicameral, presidential constitutional system. |
| 32 | |
| 33 | EU AI Act, Article 40 (Harmonized Standards). |
| 34 | EU AI Act, Article 25. |
| 35 | For the necessity and limitations of judicial supplementation of legislative gaps, see Kim (2019), General Introduction section. Judicial interpretive supplementation of gaps intentionally created by the legislature (bewusste Lücke) faces limitations under the principle of separation of powers, ultimately requiring legislative resolution. |
| 36 | The EU AI Act also adopts a phased implementation structure (e.g., 6 months for prohibitions, 12 months for GPAI, 24 months for high-risk AI) and anticipates continuous refinement of subordinate regulations after entry into force. For AI regulatory frameworks as living law, see Gasser and Almeida (2017). |
| 37 | Bradford (2020) points out that the global influence of a regulatory model depends on its substantive protective effect and enforcement reality. The insight that appropriately enforced regulations yield greater social impact than nominally strong regulations provides important implications for the future operation of Korea’s Framework Act on Artificial Intelligence. |
| Category | Korea’s Basic Act on Artificial Intelligence | EU AI Act |
|---|---|---|
| Legislative Purpose | Regulation + Promotion (Dual Purpose) | Regulation (Single Purpose—Protection of Fundamental Rights and Safety) |
| Core Regulatory Concepts | High-Impact AI | High-Risk AI (Directly Listed in Annex III) |
| Regulatory Approach | Ex-post management + self-regulation (open-door approach) | Pre-market Conformity Assessment (Preventive Approach) |
| Nature of Core Obligations | Responsibility-Centered—Numerous Prescriptive and Declarative Provisions | Mandatory obligations—linked to penalties for violations |
| Regulatory scope finalized | Comprehensive Delegation to Presidential Decrees (Flexibility ↑, Predictability ↓) | Annex III Direct enumeration of statutes (Clarity ↑) |
| Enforcement Agency | Ministry of Science and ICT-centered (Lack of specialized independent agency) | AI Office + Member State Supervisory Authorities |
| Violation Sanctions | Focus on administrative fines (limited economic deterrence) | Global sales-based fines up to 7% |
| Status of Self-Regulation | Core means of substantive regulation (principle of self-regulation) | Auxiliary means for demonstrating compliance (Safe Harbor) |
| System Type (Example) | High-Impact AI | Generative AI | Applicable Obligation Relationship |
|---|---|---|---|
| Hiring Screening AI (Pass/Fail Decision) | O | X | Only high-impact AI obligations apply (Article 34) |
| AI Copywriting Tools (Ad Copy Generation) | X | O | Generative AI obligations only apply (Article 36) |
| AI for Medical Diagnostic Report Generation ★ | O | O | Overlap—Unclear Priority (Legislative Gap) |
| Recidivism risk prediction + AI for drafting court rulings ★ | O | O | Overlap—Unclear whether weighted obligations apply |
| AI News Article Writing (General Information Provision) | X | O | Only Generative AI Obligations Apply (Article 36) |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Bang, J. Regulatory Governance of AI in the Generative AI Era: A Comparative Study of South Korea’s AI Basic Act and the EU AI Act for Sustainable Digital Transformation. Laws 2026, 15, 42. https://doi.org/10.3390/laws15030042
Bang J. Regulatory Governance of AI in the Generative AI Era: A Comparative Study of South Korea’s AI Basic Act and the EU AI Act for Sustainable Digital Transformation. Laws. 2026; 15(3):42. https://doi.org/10.3390/laws15030042
Chicago/Turabian StyleBang, Jungmi. 2026. "Regulatory Governance of AI in the Generative AI Era: A Comparative Study of South Korea’s AI Basic Act and the EU AI Act for Sustainable Digital Transformation" Laws 15, no. 3: 42. https://doi.org/10.3390/laws15030042
APA StyleBang, J. (2026). Regulatory Governance of AI in the Generative AI Era: A Comparative Study of South Korea’s AI Basic Act and the EU AI Act for Sustainable Digital Transformation. Laws, 15(3), 42. https://doi.org/10.3390/laws15030042
