Next Article in Journal
Thomas Jefferson’s Vision for Civic Education and the Founding of America’s First Public Universities
Previous Article in Journal
Maintaining Confidentiality in the Exchange of Information on Tax Matters in the Republic of Kazakhstan
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Regulatory Governance of AI in the Generative AI Era: A Comparative Study of South Korea’s AI Basic Act and the EU AI Act for Sustainable Digital Transformation

School of Law, Myongji University, Seoul 03674, Republic of Korea
Laws 2026, 15(3), 42; https://doi.org/10.3390/laws15030042
Submission received: 5 March 2026 / Revised: 23 April 2026 / Accepted: 27 April 2026 / Published: 13 May 2026

Abstract

This study conducts a comparative legal analysis of South Korea’s Framework Act on Artificial Intelligence (enacted January 2025, effective January 2026) and the EU AI Act (effective August 2024), focusing on the structural implications of their divergent regulatory philosophies for sustainable digital governance. Employing legal interpretive analysis (textual, systematic, and teleological) and comparative legal methodology, supplemented by risk-based regulation theory and the theory of hardening of soft norms, this paper examines three interconnected dimensions: the conceptual distinction between “high-impact” and “high-risk” AI, the legal nature of self-regulatory structures, and the potential distortion of civil liability attribution. The analysis reveals that Korea’s adoption of the “high-impact” concept, while strategically reducing compliance costs and avoiding stigma effects, generates significant legal gaps, including potential violations of the constitutional principle of clarity, a “liability lightning rod” phenomenon transferring responsibility from AI operators to frontline practitioners, and insufficient institutional prerequisites for effective self-regulation. In contrast, the EU’s ex-ante preventive framework provides greater legal certainty through direct enumeration of high-risk sectors and mandatory conformity assessments. Drawing on the growing body of EU AI Act scholarship, this paper proposes a five-step legislative model for dynamic regulatory adjustment tailored to Korea’s constitutional structure, encompassing statutory core criteria, periodic re-evaluation with parliamentary oversight, phased mandatory enforcement, and a presumption of conformity system, thereby offering a co-regulatory framework that balances innovation promotion with fundamental rights protection.

1. Introduction

In the context of the international normative competition surrounding AI regulation, the EU and the United States remain among the most prominent regulatory actors, though the global landscape is increasingly competitive and multipolar, with China exerting growing influence through its Interim Measures for the Management of Generative AI Services (Cyberspace Administration of China 2023), its approach to promoting open-source AI models, and its strategic engagement with the Global South through the Belt and Road Digital Economy Initiative. Furthermore, the United States lacks a unified federal AI regulatory framework; its governance relies on a patchwork of executive orders (Biden 2023), agency-specific guidelines (NIST AI RMF), and an increasing number of state-level initiatives such as Colorado’s AI Consumer Protection Act (Colorado General Assembly 2024), resulting in substantial regulatory fragmentation. The EU has adopted a regulatory approach that prioritises consumer protection (Helberger and Diakopoulos 2023) and fundamental rights protection. This regulatory framework is underpinned by the precautionary principle and hard law, creating conditions for a potential ‘Brussels Effect’ in AI regulation—though it should be noted that this phenomenon, originally theorised by Bradford (2020) in the context of data privacy regulation (GDPR) and chemical safety standards (REACH; European Union 2006), remains an emerging rather than established dynamic in the AI regulatory domain (see Smuha 2021; Almada and Radu 2024). Unlike the GDPR, where the Brussels Effect operated through the de facto adoption of EU data protection standards by multinational corporations seeking unified global compliance, the AI Act’s extraterritorial impact is yet to be empirically validated, given the sector’s rapidly evolving technological landscape and the competing regulatory models being advanced by China and the United States (Bradford 2020). The United States, as the technological hegemon that is home to the world’s largest AI companies, adheres to a soft law system that is focused on regulatory minimisation and the promotion of innovation. These two forces, grounded in opposing regulatory philosophies, strive to impose their respective models as global standards. The outcome of this competition has had a significant impact on the current dichotomous landscape of AI regulation.
The Republic of Korea occupies a distinctive dual position between these two poles. Whilst analogous to the US in terms of its domestic AI ecosystem, which includes Naver, Kakao, LG AI Research and Samsung, it is distinguished by structural vulnerabilities that are analogous to those experienced by the EU. These vulnerabilities are exposed to the potential encroachment of global Big Tech on its domestic market and the infringement of citizens’ fundamental rights (Stanford University Human-Centered Artificial Intelligence 2024). The Republic of Korea faces the dual challenge of promoting its domestic platform industry while simultaneously protecting both its industry and its citizens from the substantial economic power of American corporations. The adoption of comprehensive AI legislation, a milestone achieved by only a few countries worldwide, is of particular significance in this context.1
The EU AI Act, which took effect in August 2024, is a regulatory-led legislation prioritising fundamental rights protection. By contrast, the Korean Framework Act on Artificial Intelligence (Framework Act on Artificial Intelligence 2025), set to be implemented in January 2026, is a hybrid legislation aiming to integrate innovation promotion and fundamental rights protection within a single regulatory framework. While both laws ostensibly adopt a ‘risk (or impact)-based approach,’ they form fundamentally distinct normative structures. This divergence extends from the selection of core concepts—‘High-Risk’ versus ‘High-Impact’—to regulatory methodologies, the nature of obligations, and enforcement systems. This discrepancy cannot be attributed merely to legislative technique. This is the result of a legislative philosophical choice: the determination of the optimal equilibrium point on the regulatory scale between the conflicting legal interests of ‘promoting technological innovation’ and ‘ensuring public safety and fundamental rights’.
A number of studies have previously analysed specific aspects of the AI Framework Act. These include its legislative history (Ra 2025, pp. 128–55), its key issues (Kim 2025, pp. 40–75), and potential improvements to the act (Kwon 2025, pp. 25–48). On the EU side, an extensive body of scholarship has examined the EU AI Act and its regulatory implications, including its risk-based classification framework (Veale and Zuiderveen Borgesius 2021; Ebers et al. 2021), its broader implications for regulatory competition (Smuha 2021; Almada and Radu 2024), the civil liability framework (Hacker 2023; Bertolini 2025), accountability mechanisms (Novelli et al. 2024b), the implementation of risk-based regulation (Hacker 2023; Laux et al. 2024), implications for generative AI (Helberger and Diakopoulos 2023), the structural limitations and loopholes of the EU framework (Wachter 2024), and its comparative dimensions (Madiega 2024; Presno Linera and Meuwese 2025). However, despite this rich scholarship on the EU AI Act and the Korean Framework Act respectively, no study has comprehensively examined the internal causal relationship—from the ‘legal design of the high-impact concept’ through the ‘legal nature of the self-regulatory structure’ to the ‘potential distortion of civil liability attribution’—from a combined constitutional, civil law, and regulatory law perspective. The present paper aims to address this lacuna in the existing literature by examining three interconnected research questions: (1) How does the conceptual distinction between ‘high-impact’ and ‘high-risk’ AI generate divergent legal consequences across measurability, obligation structure, and rule-of-law clarity? (2) What are the institutional prerequisites for effective self-regulation under the Korean Framework Act, and to what extent does the current legal design satisfy these conditions? (3) How can a dynamic regulatory adjustment model be designed to maintain innovation momentum while ensuring fundamental rights protection within Korea’s constitutional structure? The study employs a systematic comparative analysis structured around four analytical axes—regulatory philosophy, core regulatory concepts, obligation structure, and enforcement systems—to identify the structural limitations of the AI Framework Act. It then goes on to propose legislative improvements that maintain the momentum for innovation while ensuring the effectiveness of fundamental rights protection. In order to achieve this objective, the methodology employed is a combination of legal interpretive analysis (textual, systematic and teleological interpretation) and comparative legal analysis. Auxiliary tools utilised in this process include risk-based regulation theory and the theory of the hardening of soft norms. Crucially, this study moves beyond a mere textual comparison of the two legal instruments. Rather than cataloguing formal differences between statutory provisions, it examines the underlying constitutional, institutional, and policy contexts that explain why each jurisdiction arrived at its respective regulatory design. The analysis investigates how these design choices produce divergent legal consequences in practice—from the predictability of regulatory scope, through the enforceability of obligations, to the attribution of civil liability—thereby revealing the structural logic that connects legislative text to real-world regulatory outcomes (European Commission 2021; National Assembly Science, Technology, Information, Broadcasting and Communications Committee 2024).
In the following sections, we undertake a comparative analysis of the legislative philosophical underpinnings of the two laws (II), meticulously examine the conceptual framework of the definition clause to articulate the legal distinction between ‘high-impact’ and ‘high-risk’ concepts (III), undertake a dual analysis of the industrial utility and public/private law limitations of high-impact AI regulation (IV), methodically examine the jurisprudence and conditions for effectiveness of the self-regulatory structure (V), and propose a Korean legislative model referencing the EU’s dynamic adjustment system (VI). Finally, it concludes by synthesising the research and suggesting a legislative improvement package (VII).

2. Legislative Background and Regulatory Philosophy of Korea’s Basic Act on Artificial Intelligence

2.1. Legislative History and the Jurisprudential Legacy of Consolidated Review

Prior to the enactment of the AI Framework Act, the legal framework governing artificial intelligence (AI) in Korea was characterised by a series of sector-specific and fragmented regulations. These were centred around the Framework Act on Intelligent Information and Communication, encompassing the Medical Device Act, the Financial Consumer Protection Act, and the Autonomous Vehicle Act. The proposal of the EU AI Act (European Commission 2021) served to underscore the necessity for a cross-sectoral fundamental framework. Despite the proposal of numerous related bills during the 20th and 21st National Assemblies, these were subsequently discarded due to the expiration of their respective terms (Ra 2025, pp. 130–35).
The 22nd National Assembly established the foundation for this transition. The Science, ICT, Broadcasting, and Communications Committee undertook a comprehensive consolidation and review of a total of 19 bills, culminating in the finalisation of a single alternative. The primary points of contention were as follows: The primary consideration is the adoption of a pre-emptive regulatory system analogous to the EU AI Act, as opposed to the adoption of innovation-friendly minimum norms. The secondary consideration is the choice between the concepts of ‘high risk’ and ‘high impact’. The tertiary consideration is whether to directly stipulate core obligations in the law or delegate them to enforcement decrees and guidelines. The final alternative adopted a promotion-first ‘open-door’ approach. This strategy involves entering the market with only a minimal regulatory framework secured upfront, then progressively refining the norms based on technological advancements and market conditions. This objective was articulated in the National Assembly review report as ‘establishing a minimum safety net without hindering the growth momentum of the AI industry’.
The consolidation of 19 bills resulted in the expeditious resolution of legislative issues. However, this process also served to entrench latent internal tensions throughout the law, arising from compromises between divergent regulatory philosophies. While the law’s form may appear to possess the appearance of mandatory regulations, its core obligations are filled with prescriptive and declarative provisions such as ‘shall endeavor,’ ‘may,’ and ‘shall bear responsibility’. Furthermore, the core substantive elements of the regulations—such as the scope of high-impact AI, the criteria for its determination, and the specific content of regulatory obligations—were comprehensively delegated to presidential decrees and guidelines. This suggests the possibility of considerable legal uncertainty continuing for a significant period, even after the law’s implementation. This nature, as a product of legislative compromise, serves as the underlying cause for all legal issues analysed below.

2.2. The Dual Nature of Regulatory and Promotion Laws and Its Implications for Interpretation

The most significant legislative feature of the AI Framework Act is its integration of the diverse objectives of regulation and promotion within a unified legal framework. Article 1 of the AI Framework Act on Artificial Intelligence (2025) explicitly states the parallel legislative purposes of ‘ensuring the safety and reliability of AI’ and ‘the sound development of AI technology and industry’. This dual-purpose approach stands in contrast to the EU AI Act, which sets the high-level protection of fundamental rights as its primary objective and positions the promotion of industry as a secondary consideration, largely confined to a separate chapter (Chapter 6 of the Framework Act on Artificial Intelligence (2025): ‘Measures in Support of Innovation’, including regulatory sandboxes under Article 57 of the Framework Act on Artificial Intelligence (2025), real-world testing under Article 60 of the Framework Act on Artificial Intelligence (2025), and reduced compliance obligations for SMEs under Article 62 of the Framework Act on Artificial Intelligence (2025)). While dual mandates exist in other jurisdictions—including China’s AI regulations, which combine state-driven innovation promotion with content-focused regulatory control—Korea’s distinctiveness lies in three structural features that are absent from both comparators. First, Korea uniquely embeds promotional concepts (AI industry, AI society, AI ethics) within the definition clause itself (Article 2 of the Framework Act on Artificial Intelligence (2025)), making promotional objectives constitutive of the regulatory framework rather than supplementary to it. Second, the human intervention exception clause (Article 31(4) of the Framework Act on Artificial Intelligence (2025)) simultaneously functions as both a regulatory boundary and an innovation incentive, enabling companies to design their way out of high-impact AI regulation by incorporating human-in-the-loop mechanisms. Third, unlike the EU’s institutional separation between the AI Office (regulatory) and the European AI Board (advisory), or China’s centralised model under the Cyberspace Administration, Korea assigns both promotional and regulatory functions to a single ministry (the Ministry of Science and ICT), creating a uniquely integrated—and potentially conflicted—governance architecture.2
The promotional nature of the Act is clearly evident from the design of its definitions. Article 2 of the Framework Act on Artificial Intelligence (2025) incorporates a range of concepts, including ‘artificial intelligence industry’, ‘artificial intelligence society’, and ‘artificial intelligence ethics’ within its definitions section. This structure is not commonly observed in purely regulatory legislation. Furthermore, provisions such as the establishment of AI specialised zones (Article 13 of the Framework Act on Artificial Intelligence (2025)), the promotion of standardisation (Article 18 of the Framework Act on Artificial Intelligence (2025)), and the prioritisation of public sector adoption with liability exemptions for responsible personnel (Article 22 of the Framework Act on Artificial Intelligence (2025)) are indicative of the state’s intent to foster the AI industry through concrete administrative benefits. This characterisation is more consistent with a special industrial support act than a regulatory law (Kim 2025, p. 50; Joint Ministry Report 2019). The Korean Framework Act on Artificial Intelligence (KAIA) has been designed to prioritise the promotion of artificial intelligence (AI) as a national strategic industry, with the legal infrastructure to support this purpose operating equally, and sometimes even more strongly, than its regulatory purpose of ensuring safety and protecting fundamental rights.
The interpretive implications of this dual-purpose structure are significant. Whilst regulatory interpretation theory as a whole tends to prioritise public interests, such as fundamental rights protection and safety, over business freedom, within the context of this dual-purpose structure, the criterion of ‘not hindering industrial development’ may, albeit implicitly, influence the interpretation of regulatory provisions. Conversely, ‘duty’ provisions could function as preconditions for promotion support. It is evident that neither of these interpretations is firmly rooted in the explicit provisions set out in the statutory text. The dual-purpose structure itself must be identified as an independent interpretive challenge, as it creates a framework that lacks consistent interpretive criteria and relies excessively on administrative discretion.

2.3. Comparison of Legislative Philosophy with the EU AI Act

As demonstrated in the preceding analysis, the EU AI Act represents what scholars have characterised as the most recent illustration of the Brussels Effect (Bradford 2020; Smuha 2021), imposing de facto compliance demands on companies from all nations entering or seeking to enter the European market.3 The enactment of Korea’s Basic Act on Artificial Intelligence is driven by a strategic intent to prevent the unilateral adoption of norms driven by the Brussels Effect and to establish an autonomous AI governance system. Nevertheless, the fundamental starting points for regulatory design are not equivalent. In the context of the EU’s pursuit of regulations aimed at safeguarding fundamental rights, it is noteworthy that the absence of substantial AI big tech companies capable of competing with Google and OpenAI within its borders was a salient factor. In contrast, Korea, like the EU, is engaged in developing its own LLM ecosystem—including HyperCLOVA (Naver), KoGPT (Kakao), and EXAONE (LG AI Research)—while the EU has similarly fostered domestic AI companies such as Mistral AI (France), Aleph Alpha (Germany), and Eleven Labs. The key distinction lies not in the presence or absence of domestic AI companies, but in the relative market position and degree of dependence on foreign AI platforms in critical infrastructure. Korea demonstrated a strong commitment to industrial protection, a factor that exerted significant influence on its regulatory design, with the objective of preventing a decline in the global competitiveness of domestic companies.
The fundamental distinction between the two laws can be attributed to the core difference in their regulatory philosophies. The EU AI Act adopts ex-ante, preventive control prior to market entry as its fundamental design principle. AI that has been classified as high-risk is required to successfully complete a conformity assessment conducted by a third-party body in order to obtain the CE marking. As Veale and Zuiderveen Borgesius (2021) have observed, the AI Act’s risk classification framework has surprising legal implications, while Ebers et al. (2021) have critically assessed this conformity assessment mechanism as the centrepiece of the EU’s preventive regulatory architecture. As Ebers et al. (2021) have critically assessed, this conformity assessment mechanism constitutes the centrepiece of the EU’s preventive regulatory architecture, establishing a clear ex-ante gateway to market access. Violations of this regulation are subject to financial penalties, with the potential for fines to reach up to 7% of the entity’s global annual turnover. In contrast, Korea’s Framework Act on Artificial Intelligence adopts ex-post management and self-regulation as its fundamental design principles. Impact assessments conducted by high-impact AI operators are considered non-binding ‘best efforts obligations’, and sanctions for violations are limited to corrective orders and administrative fines.4
A further fundamental discrepancy between the two legal frameworks pertains to the status of self-regulation. In the EU AI Act, self-regulation (e.g., codes of conduct) functions as a ‘safe harbour’ for operators to demonstrate compliance with mandatory legal obligations.5 Mandatory obligations remain independent of self-regulation, and the absence of self-regulation does not automatically entail the cessation of legal obligations. In contrast, under Korea’s Framework Act on Artificial Intelligence, self-regulation is not merely a supplementary tool but forms the core of the substantive regulatory layer. This is due to the fact that the law provides only a minimal framework at the level of duties and advisory provisions, leaving the specific implementation methods and standards to the autonomous judgment of businesses. This model aligns more closely with a ‘principled self-regulation’ framework, wherein soft law constitutes the primary instrument of substantive regulation. This stands in contrast to the EU’s co-regulation approach, which integrates self-regulation as a supplementary mechanism within hard law. An exhaustive analysis of the operating conditions and limitations of this structure is provided in Section 5.
Each approach presents distinct advantages and trade-offs. The EU’s ex-ante framework offers greater legal certainty, preventive protection of fundamental rights, and higher consumer trust, but entails higher compliance costs, potential barriers to innovation for SMEs and startups, and risks of regulatory rigidity in a rapidly evolving technological landscape. Korea’s ex-post approach provides lower market entry barriers, flexibility to adapt to technological changes, and reduced compliance costs fostering innovation, but carries potential gaps in fundamental rights protection, risks of regulatory capture, and information asymmetry between regulators and regulated entities Table 1 summarises these key differences. In summary, the two legal systems have established a divergent regulatory equilibrium, balancing the conflicting legal interests of promoting innovation and ensuring safety. This phenomenon can be interpreted as a rational choice based on each country’s industrial capabilities and policy orientation. However, the strategic trade-off prioritising innovation has resulted in certain gaps in safety and fundamental rights protection. These gaps require legal supplementation.6 The identification of the precise nature of this gap and the subsequent development of strategies for its remediation represents the core objective of this study.

3. Conceptual Framework Analysis of Article 2 Definitions in the Basic Act on Artificial Intelligence (2025)

The definition clause of a law constitutes more than a mere glossary of terms; it represents a normative core that delineates the scope of regulation and the subjects of obligations, thus establishing the fundamental point of departure for legal interpretation.7 The 12 concepts defined in Article 2 of the Framework Act on Artificial Intelligence (2025) are classified into four layers, as outlined below:
(1)
The Technology Layer, which encompasses AI, AI Technology, AI Systems and Training Data.
(2)
The Regulatory Target Layer, which includes High-Impact AI and Generative AI.
(3)
The Actor Layer, which comprises Business Operator, User and Affected Person.
(4)
The Society/Value Layer, which includes AI Industry, AI Society and AI Ethics. In contrast to the EU AI Act, which defines the ‘AI System’ as the sole regulatory unit and delegates technical methodologies and data to separate legislation, Korean law incorporates the technological, societal and value layers into its definition clauses. This approach is implemented from the conceptual design stage, serving both regulatory and promotional functions.

3.1. Technical Layer

It is evident that within the technology layer, the concepts of ‘artificial intelligence technology’ (Article 2, Paragraph 3 of the Framework Act on Artificial Intelligence (2025)) and ‘training data’ (Article 2, Paragraph 6) are uniquely defined items in Korea, and do not have direct counterparts in the EU AI Act. The former serves as a foundational concept for the legislation pertaining to promotion, including the identification of targets for R&D tax credits, technology export regulations, and R&D support funds.8 The latter is incorporated directly into the core AI legislation, in contrast to the EU’s approach of regulating it through separate data frameworks, such as the Data Governance Act and the Data Act. This is indicative of the recognition that data bias is a primary cause of unfairness in AI outcomes, and of the intent to directly regulate data governance within the AI legal framework.9 The definition of ‘Artificial Intelligence System’ (Article 2(2)) is substantially identical to the AI System definition in EU AI Act Article 3(1). It is evident that both laws are based on the OECD’s AI system definition.10 However, substantive regulatory content, such as quality standards for training data and obligations to prevent bias, is delegated to subordinate legislation. Consequently, the existence of the definition does not inherently imply effective regulation.

3.2. Regulatory Scope: The Legal Distinction Between ‘High Impact’ and ‘High Risk’

The most critical legal issue at the regulatory scope level is how the choice of the term ‘high-impact artificial intelligence’ (Article 2, Item 4) yields different legal consequences compared to the EU AI Act’s ‘high-risk AI System’. A comprehensive analysis of this discrepancy necessitates a multifaceted examination across three distinct domains: measurement methodology, obligation structure, and implications for the rule of law.
In the context of measurement methodology, the term ‘risk’ is defined as an objective, quantifiable concept, which is expressed as the product of occurrence probability and severity of harm.11 The EU AI Act, in Annex III, enumerates high-risk AI across eight sectors directly—namely, medical devices, biometrics, education, recruitment, essential public services, law enforcement, immigration control, and judicial administration—thereby enabling a high degree of predictability regarding regulatory applicability based solely on the legislation.12 In contrast, the term ‘impact’ is a value-neutral, multi-faceted concept encompassing both positive and negative outcomes. In order to ascertain whether an AI system has a ‘significant impact on the protection of fundamental human rights’, it is necessary to assess various contextual factors, including the application domain, the purpose of use and operational methods. This renders prior quantification extremely difficult (cf. (Ebers 2025) for risk-based regulation; (Novelli et al. 2024a) for scenario-based risk assessment; (Laux et al. 2024) for the conflation of trustworthiness and risk acceptability; see also (Veale and Zuiderveen Borgesius 2021; Sunstein 2005)). To illustrate, consider an AI-powered medical diagnostic system that analyses imaging data to detect early-stage cancer: under the EU AI Act, such a system would be classified as high-risk AI under Annex III (medical devices) and subject to mandatory conformity assessment, technical documentation, and human oversight requirements before market entry. Under Korean law, the same system’s classification as ‘high-impact’ would depend on a contextual assessment of whether it ‘significantly affects fundamental rights’—a determination that cannot be made with certainty based on the statute alone.13 For companies as subjects of regulation, it is extremely difficult to predict whether their AI qualifies as high-impact AI based on legislation alone. This uncertainty can create a paradoxical situation where it increases compliance costs while simultaneously providing incentives for regulatory avoidance (Sunstein 2005).
The EU AI Act imposes stringent pre-market obligations on high-risk AI, including conformity assessments, technical documentation, logging, and establishing human oversight systems, based on this logic. In contrast, the concept of ‘impact’ focuses on ex-post outcomes, rendering obligations derived from it more likely to emphasise post-event accountability and transparency over pre-emptive prevention. The AI Framework Act does not oblige high-impact AI operators to undergo pre-market conformity assessments, and even defines impact assessments as merely a ‘best effort obligation’. This finding lends further credence to the notion that the selection of the conceptual term ‘impact’ transcends the confines of mere rhetoric, serving as a means to avert the stigmatisation of AI systems. The term exerts a substantial influence on the very design of the obligation structure itself.
From the perspective of the rule of law, the Constitutional Court has consistently upheld the principle of clarity. The court has stated that regulatory standards restricting fundamental rights must be clearly defined so that those subject to them can predict their content (Constitutional Court of the Republic of Korea 1992, 2002). The current structure, whereby the criteria for judging the ‘significance of impact’ are not explicitly stated in law and all core criteria are delegated to presidential decrees, risks tension with this principle. It is evident that the neutral term ‘impact’ serves to circumvent the stigma associated with ‘risk’, thereby enhancing market acceptability. This observation underscores the implementation of a dual-purpose structure in regulatory and promotion laws, which is evident even at the conceptual terminology level. A balanced evaluation of each conceptual framework reveals distinct comparative advantages and limitations. The ‘high-risk’ concept, as employed in the EU AI Act, offers three principal advantages: first, risk is an objective, quantifiable measure (probability × severity), enabling clear regulatory thresholds; second, the direct enumeration of high-risk sectors in Annex III provides high predictability for regulated entities; and third, the ex-ante orientation facilitates preventive protection of fundamental rights before harm materialises. However, this approach carries inherent limitations: the static nature of the enumerated list risks under-inclusiveness as new AI applications emerge, and the stringent pre-market requirements may disproportionately burden SMEs and startups. The ‘high-impact’ concept, as adopted in the Korean Framework Act, likewise presents notable advantages: the value-neutral terminology avoids the stigma effect; the contextual, outcome-oriented assessment provides flexibility to capture diverse impacts; and the lower compliance threshold fosters a more innovation-friendly market entry environment. Conversely, the limitations are substantial: the conceptual ambiguity undermines regulatory predictability, creating a paradox where compliance costs may actually increase due to uncertainty; the delegation of core criteria to presidential decrees generates tension with the constitutional principle of clarity (Bestimmtheitsgrundsatz); and the absence of ex-ante safeguards may permit harm to fundamental rights before corrective intervention occurs. In conclusion, the opposition between ‘high impact versus high risk’ is a regulatory philosophical turning point yielding distinct legal implications across three dimensions: measurability, obligation structure, and rule-of-law clarity.14

3.3. Actor Level: Integration of the Business Operator Concept and the Significance of ‘Affected Parties’

At the level of individual actors, the AI Framework Act establishes an explicit three-party structure comprising AI business operators, users, and affected parties. In contrast to the EU AI Act, which meticulously categorises roles within the AI supply chain into Provider, Deployer, Importer, and Distributor, and imposes distinct obligations on each, Korean law integrates developers and deployers under the unified definition of ‘AI business operator’ (Article 2, Item 7). Whilst this consolidated definition offers the advantage of regulatory simplicity, it carries the risk of undermining the precision of liability attribution by failing to reflect the differing roles, responsibilities, and levels of information possession held by developers and deployers within the AI supply chain. This is particularly pertinent in the context of high-impact AI systems, where a failure to distinguish between defects arising from algorithm design issues during development and those stemming from inappropriate usage contexts during deployment or operation could result in distorted liability attribution.15
The concept of “user” (Article 2, Item 8) has also been the subject of comparative legal analysis. The EU AI Act defines “user” narrowly as “a person using an AI system under their authority in a professional context,” thereby distinguishing between general consumers and business users. In contrast, Korean law defines it comprehensively without such distinction. This discrepancy gives rise to a divergent balance of emphasis between consumer protection and business regulation in high-impact AI regulation. Specifically, while the comprehensive user concept in Korea provides a robust legal foundation for consumers to challenge AI decisions in B2C AI services, it also carries the paradoxical risk of creating protection gaps by failing to differentiate the regulatory intensity between business and consumer contexts.
The definition of ‘affected person’ as set out in Article 2, Item 9 of the Framework Act on Artificial Intelligence is the most original of the definitions provided. It has been determined that the term comprehensively encompasses groups that do not utilise AI services directly, yet are profoundly impacted in their rights and interests by AI decisions. Illustrative cases encompass job seekers undergoing AI hiring screening, loan applicants receiving AI credit assessments, and individuals subject to AI welfare benefit reviews. This legislative approach can be regarded as more progressive in comparison to the EU AI Act, which only indirectly addresses third-party affected parties within its fundamental rights provisions.16 However, the specific rights that these individuals are permitted to exercise—such as the right to object, the right of access, and the right to request an explanation—are delegated to subordinate legislation. It is important to note that this engenders a limitation: at this stage, the mere existence of these rights does not directly translate into effective safeguards.17

3.4. Overlapping Application Issues at the Social/Value Level and for High-Impact/Generative AI

At the social and value level, the Framework Act on Artificial Intelligence includes definitions for the AI industry, AI society, and AI ethics within its definition clauses. This is a highly unusual occurrence in the AI regulatory frameworks of major global nations. The EU AI Act makes reference to ethical values in its preamble (Recitals) and principles clauses, yet these values are not incorporated within the definition section.18 This design is indicative of the legislator’s intent to recognise AI not solely as a regulatory target, but as an agent of social transformation and an object of promotion policy. It serves to establish the normative context for the various promotion provisions in Section 2. However, the question of whether the placement of AI ethics within the definition clause can be invoked as a legal basis for soft norms in the context of self-regulation is examined separately in Section 5. At the regulatory level, the most practically significant interpretive issue arises when a single AI system simultaneously meets the definitions of both High-Impact AI and Generative AI. The identification of high-impact AI is based on the outcome-level criterion of ‘the severity of the impact it exerts’, while the identification of generative AI is based on the functional-level criterion of ‘the capability to generate text, images, voice, video, or code’. Consequently, it is entirely conceivable that a single AI system may simultaneously satisfy both criteria—for instance, AI-generated medical diagnostic reports or judicial support AI that concurrently drafts court rulings and predicts recidivism risk.
The prevailing legal interpretation of the present legislation is that the two obligation systems (Articles 34 and 36) should be applied in a cumulative and concurrent manner. This interpretation is consistent with a systematic interpretation of the text. Nonetheless, the absence of priority rules when obligations conflict, in conjunction with the lack of explicit legal grounds justifying the imposition of additional obligations, has a deleterious effect on predictability. The EU AI Act partially addresses this issue in Article 25(2) by explicitly stipulating the duty of cooperation between providers and the criteria for allocating obligations when a GPAI Model is integrated into high-risk AI.19
The Korean legal system is found wanting in terms of corresponding provisions, resulting in the relationship of obligations during overlapping application being entirely subject to interpretation. This lacuna in the law calls for legislative supplementation to address this gap Table 2 illustrates the overlap patterns between high-impact AI and generative AI obligations.

3.5. Conclusions

The conceptual framework of Article 2 of the Framework Act on Artificial Intelligence (AAI) provides four key implications. Firstly, the dual purpose of regulation and promotion is embodied from the conceptual design level. The distinctive character of Korea’s definitions, encompassing the concepts of AI industry, AI society, AI ethics, training data, and AI technology, is indicative of a legislative intent to recognise AI not solely as a regulatory target, but as a catalyst for societal transformation and an object of promotion policy.
Secondly, the distinction between the concepts of ‘High-Impact’ and ‘High-Risk’ engenders substantive legal disparities across three dimensions: measurability, obligation structure, and rule-of-law clarity. This distinction fundamentally questions the effectiveness and constitutional legitimacy of high-impact AI regulation, forming the starting point for the analysis in Section 4 and Section 5 below. Thirdly, while the notion of ‘affected persons’ is original, subsequent legislation specifying concrete rights in statutes is indispensable for this to translate into effective rights protection. Fourthly, the overlapping application of high-impact AI and generative AI regulations constitutes a legislative gap requiring clear statutory rules on priority criteria when conflicting with the principle of cumulative obligations.
A synthesis of the comparative significance of the AI Framework Act’s definitional provisions reveals that, in comparison to the EU AI Act, Korean law demonstrates a more advanced legislative approach in protecting affected parties (the concept of affected persons) and integrating data governance (the definition of training data). However, the regulatory framework is not without gaps, particularly in the delegation of core regulatory standards to enforcement decrees (scope of high-impact AI) and the integration of definitions of supply chain participants (AI business operators). This tension between the two aspects forms the basis for the subsequent analysis of regulatory effectiveness and proposed legislative improvements presented in the following chapters.

4. The Industrial Utility and Legal Limitations of High-Impact AI Regulation

As confirmed in the conceptual framework analysis of Section 3, the choice of the term ‘High-Impact’ is a product of regulatory design philosophy. This chapter conducts a thorough examination of the practical outcomes of the design in question. It does so by considering two key aspects: firstly, the industrial and policy utility (Section 4.1); and secondly, the public and judicial law limitations (Section 4.2 and Section 4.3). The chapter then moves on to evaluate the nature of the design as a strategic trade-off (Section 4.4).

4.1. Industrial and Policy Utility

The High-Impact AI regulatory framework is characterised by its utility, which is structured across four dimensions. Firstly, it has been demonstrated that this practice can prevent the stigma effect. The term ‘risk’ is inherently associated with the possibility of harm, leading to consumer avoidance and excessive investor caution. In contrast, ‘impact’ is a value-neutral term encompassing both positive and negative outcomes. This development has the potential to enhance market acceptance and the marketing and investment environment for companies. Secondly, it has been demonstrated to reduce compliance costs. The EU AI Act’s high-risk AI framework mandates third-party conformity assessments, CE marking, technical documentation, and log retention before market entry, creating a significant barrier for startups. In contrast, Korean law does not stipulate pre-market conformity assessments, and impact assessments are merely considered an ‘effort obligation’. This provides a practical foundation for domestic AI startups to swiftly engage in global competition without being hampered by regulatory costs.
Thirdly, the safe harbour function of the human intervention exception clause is considered. The structure that excludes ‘cases where humans intervene and control the final decision-making’ from high-impact AI regulation acts as a powerful design incentive. Should companies internalise human control (Human-in-the-loop) from the system design stage, they may be able to exempt themselves legally from additional regulation. In comparison with the EU AI Act, which imposes mandatory human oversight in high-risk sectors such as healthcare and employment, this reflects a difference in design philosophy: achieving the same policy goals through incentives (exemptions) rather than compulsion (mandates). Fourthly, it is instrumental in safeguarding the domestic AI ecosystem. For the Republic of Korea, a nation that boasts an autonomous LLM ecosystem, the amalgamation of lenient regulations and promotional provisions—including the establishment of AI specialised zones (Article 13), support for standardisation (Article 18), and prioritisation of public sector adoption with liability exemptions for responsible personnel (Article 22)—serves as a bulwark for the global competitiveness of domestic AI companies.

4.2. Public Law Limitations: Principle of Clarity and Prohibition of Blanket Delegation

The most significant public law limitation of the high-impact AI regulatory framework is its potential contravention of the constitutional principle of clarity (Bestimmtheitsgrundsatz). The Constitutional Court has repeatedly ruled that legislation which imposes restrictions on fundamental rights must be clearly defined, to the extent that the subjects concerned can predict the scope and objectives of the regulation in advance. Furthermore, the court has determined that any core elements which restrict fundamental rights must be explicitly stipulated within the legislation itself (Constitutional Court of the Republic of Korea 1992, 2002).
Article 4 of the Framework Act on Artificial Intelligence stipulates that high-impact AI is defined as ‘an artificial intelligence system that may significantly affect or pose a risk to human life, physical safety, and the protection of fundamental rights’. However, the delineation of specific relevant fields and judgment criteria is delegated to Presidential Decrees. The degree of ‘significant impact’ and the requirements for recognizing ‘risk’ are not defined in the law, making it impossible for those subject to the law to predict whether their services fall under this category based solely on the statutes. The designation of high-impact AI as a trigger for obligations (Article 34) entails the establishment of risk management measures, user notifications, human oversight systems, and appeal procedures, in addition to the potential imposition of administrative fines. In the event that the fundamental criteria for the restriction of these rights are not defined in the law itself, but rather delegated entirely to subordinate regulations, this may result in a violation of the principle prohibiting blanket delegation as outlined in Article 75 of the Constitution of the Republic of Korea (1987).20
The EU AI Act (European Union 2024) enumerates the high-risk AI sectors in Annex III of the main text. These sectors include medical devices, biometrics, education, recruitment, essential public services, law enforcement, border management and judicial administration. Consequently, companies can predict their applicability to a significant degree based solely on the law.21 The delegation of authority to amend Annex III to the Commission (Article 7) is subject to strict conditions and procedures, constituting an exceptional adjustment mechanism rather than a blanket delegation. This underscores the necessity for the enhancement of Korea’s Basic Act on Artificial Intelligence, to explicitly enumerate the fundamental criteria for high-impact AI within the legal framework itself.

4.3. Judicial Limitations: Potential Distortion of Liability Attribution and Gaps in Remedies

From a judicial perspective, the most significant limitation is the ‘Liability Lightning Rod phenomenon,’ wherein the human intervention exception clause has the capacity to distort the attribution of civil liability. The exception, which stipulates that “a human intervenes in the final decision-making process and can exercise control”, risks institutionally enabling a structure where companies can legally circumvent stricter regulations by merely adding a formal final approval button to system design. However, in instances where damages arise from AI errors, the responsibility is transferred to the frontline practitioner (e.g., a doctor, bank teller or public official) who approved the final decision, by attributing the harm to a breach of the duty of care as outlined in Article 750 of the Civil Act of the Republic of Korea (2024). Companies that create risks and reap profits from AI technology remain outside the regulatory net, while liability for damages may fall on individuals with limited capital resources.
This concern is not merely abstract; as evidenced by cases from overseas, it is a genuine and pressing issue. The 2018 incident involving Amazon’s AI hiring tool serves as a prime example of the potential risks associated with the use of artificial intelligence in the workplace. Amazon developed an AI system trained on a decade of hiring data to automate resume screening. However, the system reflected the historical data showing a majority of male applicants for technical roles, resulting in a systematic bias that disadvantaged female applicants. Although this system was ultimately scrapped, if a similar AI recruitment tool were operated in Korea, the following legal challenges are anticipated under the current framework of the Basic Act on Artificial Intelligence. If the system merely adds a formal approval step by a human recruiter before the final pass/fail decision, it is highly likely to be excluded from high-impact AI regulation under the human intervention exception clause. In such a case, even if a female job applicant who suffered discriminatory disadvantage due to the AI’s structural bias sought damages from the business operator, she would need to prove all three elements under Article 750 of the Civil Act: the algorithm’s bias, the causal link that it systematically caused unfavorable outcomes for a specific gender, and the operator’s negligence. Since the composition of training data and algorithm design information are monopolized by the business operator, the victim’s burden of proof becomes virtually impossible. Furthermore, the operator can open a legal pathway to shift responsibility for the AI system’s structural bias onto frontline practitioners by arguing that ‘the HR manager made the final decision.’ This scenario concretely illustrates the liability lightning rod phenomenon: the company that designed the biased algorithm and profited from its deployment escapes the regulatory net, while the individual HR practitioner—who may have neither the technical expertise to detect algorithmic bias nor the organisational authority to override the AI system’s recommendation—bears the legal consequences. The structural asymmetry between formal authority (the power to click ‘approve’) and substantive control (the capacity to critically evaluate AI outputs) lies at the heart of this distortion.
This hypothetical scenario illustrates the concrete risks arising from the disconnect between the ‘formal intervention’ and ‘substantive control’ required by human intervention exceptions. Research on automation bias consistently confirms humans’ tendency to approve AI judgments without critical review. Given deep learning’s black-box nature, if practitioners merely sign off without understanding the basis for AI outputs, this does not constitute substantive control in a legal sense. According to the Meaningful Human Control (MHC) theory, genuine control is only recognized when three conditions are met: ① substantive understanding of the basis for AI decisions, ② substantive guarantee of the power to override, and ③ provision of explainability (XAI). However, current laws fail to provide any criteria for judging the ‘substantiality’ of human intervention. This creates a dual problem: allowing formal approvals to circumvent regulation while shifting responsibility onto practitioners.
The structural vulnerability of the civil liability attribution system is also evident in the asymmetry of the burden of proof. Under the current civil law framework, victims must prove the operator’s intent, negligence, the illegality of the AI decision, and causation (Civil Act Article 750), yet the necessary technical documentation, training data, and algorithm design information are mostly monopolized by the operators. Unlike the EU, which introduced a presumption of causation for high-risk AI incidents in its proposed AI Liability Directive and expanded strict liability by including AI systems under the product liability concept in its revised Product Liability Directive, Korea’s Framework Act on Artificial Intelligence contains no provisions to modernize civil liability jurisprudence. Imposing an excessive burden of proof on victims within an information asymmetry structure creates a judicial vacuum that effectively renders effective rights remedies impossible This stands in marked contrast to the EU’s comprehensive approach, which, as Hacker (2023) has analysed, introduces a presumption of causation for high-risk AI incidents through the proposed AI Liability Directive and expands strict liability by including AI systems under the revised Product Liability Directive (see also Bertolini (2025); Wachter (2024) for limitations and loopholes).22

4.4. Conclusion: Evaluation as a Strategic Trade-Off

The Korean AI Framework Act’s high-impact AI regulatory system is not merely a ‘regulatory gap’; rather, it is the product of a conscious, strategic trade-off, as evidenced by a synthesis of the aforementioned analysis. It has been argued that this permits certain gaps in safeguarding public safety and fundamental rights in order to promote the legal interest of technological innovation. Nevertheless, this trade-off evaluation fails to substantiate the legal vacuum. Potential violations of the principle of clarity, possible distortions in liability attribution, and the inability to provide effective remedies for rights violations must be addressed through legal supplementation. In lieu of the transplantation of the EU’s rigid ex ante regulatory paradigm, the conception of ex post coordination mechanisms is imperative. Such mechanisms ought to be designed in such a manner as to both sustain the momentum for innovation and provide expeditious and reasonable remedies for rights infringements. In summary, the three structural limitations identified in this chapter—potential violation of the principle of clarity, distortion of liability attribution through the liability lightning rod phenomenon, and the judicial vacuum created by information asymmetry in the burden of proof—collectively demonstrate that the strategic trade-off embedded in the Korean AI Framework Act requires targeted legislative supplementation. The specific design of these corrective mechanisms is addressed in Section 6.

5. Analysis of the Self-Regulatory Structure in Korea’s Basic Act on Artificial Intelligence

As confirmed in Section 2, the Korean Framework Act on Artificial Intelligence emphasises self-regulation and ex post management over ex ante regulation. The subsequent chapters proceed to analyse the structural substance of the Act across three dimensions. Firstly, the legal status of its multi-layered normative structure composed of the Act, Enforcement Decree, Notices, and Guidelines is examined (Section 1). Secondly, the legal character of its core duty provisions designed as ‘obligations’ and ‘best efforts’ is analysed (Section 2). Thirdly, and finally, the conditions for the effectiveness of self-regulation alongside the vulnerabilities of the current system are considered (Section 3).

5.1. Legal Status of the Multi-Layered Normative Structure and Constitutional Limits

The normative system of the Framework Act on Artificial Intelligence features a vertical, multi-layered structure with the main text of the Act at its apex, followed by Presidential Decrees, Notices, Directives, and Guidelines. However, the core regulatory elements—the scope and criteria for determining High-Impact AI (Article 4), the specific methods for Generative AI labeling obligations (Article 5), and the criteria for high-impact AI operators’ duty fulfillment (Article 34)—are all delegated to presidential decrees or ministerial notices, resulting in a severe downward skew in normative density. It is anticipated that specific guidelines on risk management, impact assessment, and user explanation methods will be provided as non-legally binding administrative guidance-level guidelines. Whilst this approach offers the practical advantage of enabling a rapid response to technological changes, it contains an inherent normative tension between legal predictability and the demands of the rule of law.
Article 75 of the Constitution stipulates that delegations to presidential decrees must be made with ‘specifying the scope in detail’. In accordance with the Constitutional Court’s established criteria for predictability, the framework of the delegating statute is required to facilitate the anticipation of the general structure of content that is intended to be delineated in subordinate regulations. This anticipation is to be achieved through a comprehensive consideration of the statute’s system, intent, and purpose (Constitutional Court of the Republic of Korea 2006). However, Article 4 delegates the entire scope and judgment criteria for high-impact AI, rendering it impossible for regulated entities to predict whether their AI falls under the law based on the statute itself. This effectively delegates the criteria restricting the freedom of business (Article 15 of the Constitution) to the broad discretion of the executive branch.
The most notable legal theory issue within the AI Framework Act system is the de facto binding force of the guidelines. Guidelines are not, in principle, recognised as a source of law as they are not subject to the same legal scrutiny as statutory orders. The Supreme Court recognises the legal effect of administrative rules only when they supplement the content of higher-level statutes based on delegation (Supreme Court of the Republic of Korea 2009). Moreover, the Constitutional Court has ruled that the delegation of matters pertaining to the fundamental content of citizens’ rights and obligations to administrative rules constitutes a violation of the principle of legal reservation (Constitutional Court of the Republic of Korea 2004).23
Guidelines under the Framework Act on Artificial Intelligence occupy a unique position within this spectrum of legal theory. It is important to note that, in the past, these constituted non-binding administrative guidance. However, if administrative agencies effectively utilise compliance with the guidelines as a de facto criterion in business licensing, government support selection, or public procurement reviews, businesses are incentivised to comply with the guidelines, even in the absence of legal obligation. This phenomenon is referred to as the ‘hardening of soft law’.24 Within the domain of domestic administrative law scholarship, there has been a progression of discourse that asserts the necessity of acknowledging the regulatory nature of administrative guidance when it exhibits dispositive effect. Furthermore, the Supreme Court has ruled that the imposition of disadvantageous dispositions for non-compliance with administrative guidance constitutes a violation of the intent of Article 48 of the Administrative Procedure Act (Supreme Court of the Republic of Korea 2005).25 It is highly probable that the guidelines set out in the AI Framework Act will fall precisely into this category of ‘non-mandatory administrative guidance that is nevertheless de facto obligatory to comply with.’ This situation gives rise to two concerns regarding the rule of law: The principle of parliamentary reservation is undermined by the executive branch encroaching upon matters reserved for the legislature. Furthermore, there is a lack of clarity regarding the resolution criteria in legal disputes over compliance with the guidelines.
The EU AI Act is intended to provide legal certainty for self-regulation by means of the grant of a presumption of conformity effect (Article 40). As (Novelli et al. 2024b) have argued, this mechanism creates a structured accountability framework wherein compliance with harmonised standards generates a rebuttable legal presumption, thereby incentivising industry participation while preserving regulatory enforceability. This is to the effect that compliance with Harmonized Standards is presumed to fulfil the relevant obligations. However, the Korean legal system is not equipped with a corresponding system.

5.2. Legal Nature and Normative Limits of Duty Provisions

The core requirement imposed on high-impact AI operators by the Framework Act on Artificial Intelligence is the ‘duty’ under Article 34. A legal obligation constitutes a comprehensive norm that entails direct legal sanctions (administrative fines, penalties, corrective orders, and damages) in the event of violation. In contrast, a duty represents a declaratory/admonitory norm that is devoid of legal coercion. This is analogous to the legal distinction between absolute obligations and natural obligations. Obligations are complete norms enforceable through compulsion, while responsibilities are incomplete norms that encourage but do not compel compliance.
A thorough examination of Article 34 reveals its normative weakness. The specific content and standards for establishing risk management measures, user notifications, human oversight, and control systems are delegated to enforcement decrees or guidelines. Moreover, Article 44 (administrative fines), which contains penalty provisions for violations, is not directly linked to violations of Article 34. Consequently, even in the event of an operator’s failure to fulfil its responsibilities in their entirety, there is no direct basis for the imposition of administrative fines. The EU AI Act (Art. 71) stipulates that all high-risk AI operators are obligated to adhere to risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11), logging (Art. 12), transparency (Art. 13), human oversight (Art. 14), and robustness (Art. 15). Violations of these obligations are subject to financial penalties amounting to up to 7% of the entity’s global annual turnover (Art. 71).26
Nevertheless, it should be noted that this does not imply that the provisions are entirely devoid of normative significance. Three indirect functions are recognised. Firstly, in high-impact AI liability lawsuits, the risk management, user notification, and human oversight systems required by Article 34 could be interpreted as establishing a minimum standard of duty of care for the relevant operator. Secondly, administrative agencies have the capacity to utilise Article 34 as a foundation for inducing de facto compliance through informal administrative pressure, such as implementation recommendations or requests for corrective action. Thirdly, it provides a foundation for the refinement of legislation, with a view to transitioning to mandatory obligations in the future. Nevertheless, these indirect functions alone are inadequate for the provision of effective legal control over the potential infringement of fundamental rights caused by high-impact AI (Coglianese and Mendelson 2010).

5.3. Conditions for the Effectiveness of Self-Regulation and Institutional Vulnerabilities

Information asymmetry is a key concern in the context of AI systems. The technical complexity of these systems often results in regulated companies possessing a substantial advantage in terms of information over regulatory authorities. This imbalance in data availability can lead to the emergence of standards that are more aligned with the interests of corporations, potentially compromising the regulatory integrity and effectiveness. Secondly, the issue of collective action has been identified. If individual companies were to raise their self-regulatory standards, this may result in cost disadvantages relative to competitors, potentially leading to a ‘race to the bottom’. Thirdly, the phenomenon of ‘regulatory capture’ must be considered. This is defined as the risk that regulated entities will exert a dominant influence over the formation of regulatory standards. This, in turn, has the potential to result in the codification of industry interests rather than the public good. A survey indicating that only one in three domestic companies understands the Basic Act on Artificial Intelligence suggests the third failure factor is already highly likely to materialize. The EU’s experience with the GDPR Code of Conduct mechanism under Article 40 of the GDPR offers an instructive comparative benchmark. Although the GDPR established a clear legal framework for approved codes of conduct—including requirements for independent monitoring bodies (Article 41) and binding obligations on adherents—the mechanism’s early implementation revealed three persistent challenges: protracted approval processes (with the first transnational code, the EU Cloud Code of Conduct, taking over three years to gain approval); inconsistent quality of submitted codes across member states; and difficulties in establishing credible, independent monitoring bodies. These challenges demonstrate that even well-designed self-regulatory frameworks embedded within hard law require robust institutional infrastructure to function effectively—a lesson directly applicable to the Korean AI Framework Act’s reliance on self-regulation without comparable institutional safeguards.
A comparison of relevant legal studies indicates that four institutional prerequisites must be met for self-regulation to effectively harmonise with fundamental rights protection. The establishment of an autonomous and expert supervisory entity is imperative. While the EU has established an AI Office within the Commission and mandated National Competent Authorities (NCAs) in each member state (Article 70), Korean law lacks a specialised independent agency for AI oversight. Secondly, the implementation of an independent third-party audit system is imperative. The EU AI Act stipulates the requirement for third-party conformity assessments for high-risk AI (Art. 43), whereas Korea’s ‘AI Reliability Verification and Certification’ (Article 34-3) is a voluntary procedure initiated by business operators. Thirdly, effective redress procedures must be ensured. Current AI-related financial losses are not encompassed within the provisions of the Securities-Related Class Action Act. Consequently, victims of such incidents encounter a considerable procedural burden when pursuing legal redress through general civil lawsuits. In such cases, the onus falls upon the plaintiff to substantiate the presence of intent, negligence, unlawful acts, and the existence of a causal relationship between the incident and the damages sustained. Fourthly, the prevention of regulatory capture is to be achieved through the facilitation of stakeholder participation. The EU AI Act stipulates the involvement of various stakeholders, including civil society, consumer groups, academic institutions, and affected groups, in the establishment of the GPAI Model Code of Practice (Art. 56).27 In contrast, the Korean legal system is predicated exclusively on the general opinion-gathering process as delineated within the framework of the Administrative Procedure Act.
A thorough evaluation of the current Framework Act on Artificial Intelligence reveals that it does not adequately meet any of the aforementioned four conditions. The legislation is deficient in the following ways: firstly, it lacks an independent oversight body; secondly, it does not include mandatory third-party audit systems; and thirdly, it does not provide for provisions for specialised class actions or for shifting the burden of proof for AI-related harm. This is an inevitable consequence of a legislative strategy that has been implemented with undue haste. If the law was enacted without satisfying the minimum conditions for effective self-regulation, this constitutes more than mere incompleteness and risks creating a constitutional vacuum. The National Human Rights Commission’s warning regarding a potential lacuna in fundamental rights protection with regard to the deferred implementation of Articles 31 to 35 must be interpreted in this precise context (National Human Rights Commission of Korea 2024).

5.4. Conclusion: Directions for Redesigning the Co-Regulatory Model

The preceding analysis indicates three fundamental limitations in the self-regulation structure of Korea’s Basic Act on Artificial Intelligence. Firstly, within a multi-layered normative structure, the legal density is excessively low, and core substantive matters are delegated to subordinate statutes and guidelines. This raises concerns about failing to meet constitutional clarity requirements. Secondly, core provisions designed as ‘duties’ and ‘best efforts obligations’ lack direct enforceability, thus failing to provide a legal safety net against self-regulation failures. Thirdly, the absence of essential institutional infrastructure for effective self-regulation, including an independent oversight body, third-party audits, and collective redress procedures, is a salient issue.
In order to address the aforementioned limitations, rather than transplanting the EU AI Act’s preventive hard framework, it is necessary to establish a ‘Korean co-regulatory model’ that codifies the minimum conditions for effective self-regulation while maintaining an innovation-friendly policy stance. The fundamental lesson to be drawn from the EU’s experience is that self-regulation and mandatory regulation are not inherently contradictory. True co-regulation is characterised by the entrustment of specific implementation methods within the framework of mandatory obligations to self-regulation. Conversely, the entrustment of mandatory obligations themselves to self-regulation is more akin to a relinquishment of regulation. The central finding of this chapter is that the co-regulation model in the AI Framework Act exhibits a tendency towards the latter—entrusting mandatory obligations themselves to self-regulation rather than merely delegating implementation methods. This finding, combined with the three identified institutional deficiencies (absence of an independent oversight body, lack of mandatory third-party audits, and unavailability of collective redress procedures), establishes the concrete prerequisites that must be addressed in the legislative reform proposed in Section 6.

6. Legislative Proposals and Conclusions

The legal gaps argued in Section 4 and Section 5 should not be dismissed as mere textual deficiencies. These gaps include potential violations of the principle of clarity, possible distortions in liability attribution, and the lack of effectiveness in self-regulation. Building on comparative insights from the emerging literature on European AI regulation (Presno Linera and Meuwese 2025), the present chapter sets forth concrete legislative alternatives that have been designed to maintain the momentum for innovation while ensuring the protection of fundamental rights and the effective attribution of legal liability. To clarify the direct causal links between the identified problems and the proposed solutions: the potential violation of the principle of clarity (Section 4) is addressed by the statutory core criteria and periodic re-evaluation model (Section 6.2, Stages 1–3); the liability lightning rod phenomenon (Section 4) is addressed by the modernisation of civil liability jurisprudence (Section 6.3); and the insufficient institutional prerequisites for self-regulation (Section 5) are addressed by the presumption of conformity system and phased mandatory enforcement (Section 6.2, Stages 4–5). In accordance with the aforementioned points, an overall assessment of the normative status of the AI Framework Act is provided, as well as a consideration of the future legislative tasks (Section 5).

6.1. Implications of the EU AI Act’s Dynamic Regulatory Adjustment System

The issue of regulatory lag, defined as the emergence of a technology type that was not yet in existence at the time of legislation, subsequently manifesting itself 2–3 years later in a form that poses significant societal risks, cannot be addressed by a static list of regulations.28 The EU AI Act addresses this issue through the implementation of a Dynamic Regulatory Adjustment mechanism. Article 7 authorises the Commission to amend Annex III’s list of high-risk AI systems through delegated acts pursuant to Article 290 TFEU. This must be carefully distinguished from implementing acts under Article 291 TFEU, which serve to establish uniform conditions for the implementation of EU legislation, such as the technical specifications for conformity assessment procedures under the AI Act. Article 290(1) TFEU requires that the delegating act—in this case, the AI Act itself—must explicitly delineate the objectives, content, scope, and duration of the delegation of power. The European Parliament and the Council retain robust oversight mechanisms, including the power to revoke the delegation entirely (Article 290(2)(a) TFEU) and the right to express objections within a specified period, during which the delegated act cannot enter into force (Article 290(2)(b) TFEU). In the specific context of Article 7 of the AI Act, the Commission’s power to amend the Annex III list is subject to three cumulative conditions. The potential for significant hazards to fundamental rights, health, or safety must be demonstrated; substantial empirical data must support the proposed amendment; and the principle of proportionality must be satisfied. This layered safeguard mechanism, as comprehensively documented by Madiega (2024), ensures that the expansion of the high-risk AI list remains within constitutionally defined boundaries, preventing arbitrary regulatory expansion by the executive while maintaining the capacity for responsive governance. It is imperative to note that any proposed amendments must undergo a series of objection procedures by both the European Parliament and the Council. In the context of General Purpose AI (GPAI) models, the principle of flexible regulation, which is intended to keep pace with technological advancement, is enshrined in a Code of Practice framework (Articles 56–58). Moreover, compliance with Harmonized Standards is recognised as a means of demonstrating compliance with obligations (Article 40).
The implications of this structure for Korean law are evident. In order to surmount the limitations of the prevailing system, wherein guidelines function solely as soft norms devoid of legal effect, it is imperative to establish a system of presumption of conformity. This system should entail the conferral of legal presumption effects for compliance with standards, in conjunction with a regular re-evaluation procedure that ensures democratic oversight. It is only in this manner that self-regulation can function as an effective means of compliance, rather than a route for regulatory avoidance.

6.2. A Five-Step Legislative Model for Dynamic Regulatory Adjustment in Korea

In order to facilitate the implementation of the EU AI Act’s dynamic adjustment mechanism within the Korean context, it is imperative that two fundamental prerequisites are met. Firstly, the ‘open-door’ approach, which is innovation-friendly by its very nature, should not be rejected in its entirety. Rather, it should be supplemented in order to meet the minimum requirements of the rule of law and fundamental rights protection, while maintaining that approach. Secondly, the EU’s delegated legislation model is predicated on the EU Treaty framework (TFEU Article 290) and cannot be directly transplanted into Korea’s constitutional structure (Constitution Article 75), which is based on a unicameral National Assembly and a presidential system. It is therefore evident that the utilization of an independent model is imperative.29
The following five-stage model is proposed on the basis of the aforementioned premise. Stage 1, entitled ‘Core Statutory Regulation and Detailed Delegation’, involves a tiered separation structure where the core criteria for high-impact AI (field, decision-making autonomy, scale of affected individuals) are directly stipulated in law, while only the specific list and detailed judgment criteria are delegated to enforcement decrees. Specifically, it stipulates in law the logical combination of three criteria: The first of these criteria is that there must be seven sectors: medicine, finance, employment, education, law, public safety and large-scale infrastructure. These sectors were selected based on three converging criteria with specific justifications. First, alignment with the EU AI Act’s Annex III high-risk categories (medical devices under the EU AI Act’s Annex III Section 5(a), biometric identification under Annex III Section 1, education under Annex III Section 3, employment under Annex III Section 4, essential public services under Annex III Section 5(b), law enforcement under Annex III Section 6, and judicial administration under Annex III Section 8, all of the EU AI Act), ensuring international regulatory compatibility. Second, these sectors correspond to the domains identified by the Korean National Human Rights Commission in its 2024 Opinion on the AI Framework Act as having the highest potential for systematic impact on constitutional rights, including the right to equality (Article 11), privacy (Article 17), and occupational freedom (Article 15) under the Korean Constitution. Third, empirical evidence demonstrates that AI-driven automated decision-making is already deployed or imminent in these sectors in Korea: AI-assisted medical diagnostics (e.g., Lunit INSIGHT, Vuno Med), AI credit scoring in financial services, and AI-powered recruitment screening tools are already operational. The second is that there must be automated decision-making that substantially impacts human rights, obligations, life, body or property. The third and final criterion is that the scale of affected individuals must exceed the threshold set by presidential decree.30 This enables companies, as the regulated entities, to independently assess their potential regulatory compliance based solely on the legal provisions, significantly enhancing predictability. The regulation also functions as a constitutionally binding upper limit, thereby preventing arbitrary expansion of the scope by administrative authorities.
The second stage, entitled ‘Periodic Reevaluation and Parliamentary Oversight’, stipulates that the Minister of Science and ICT is required to re-evaluate the High-Impact AI List on a triennial basis from the law’s effective date. The three-year cycle was selected for three reasons: it aligns with the existing regulatory review cycles mandated by Article 8 of the Framework Act on Administrative Regulation; it is comparable to the EU’s approach under AI Act Article 112, which requires periodic evaluation and review; and it provides a sufficient empirical observation period to accumulate meaningful data on regulatory impact while remaining responsive to the rapid evolution of AI capabilities, and to make any necessary amendments to the Presidential Decree. The re-evaluation comprises three components: firstly, an assessment of the emergence of new risk areas; secondly, an evaluation of whether risks associated with existing list items have decreased; and thirdly, an assessment of whether any items have regulatory compliance costs that excessively outweigh social benefits. The establishment of a dedicated ‘Artificial Intelligence Impact Assessment Expert Committee (tentative name)’ is to be implemented by law in order to conduct this re-evaluation. In the third stage, designated ‘National Assembly Reporting and Objection,’ the obligation arises for any amendment to the Presidential Decree, including list expansion, to be reported to the National Assembly’s Science, ICT, Broadcasting, and Communications Committee a minimum of 60 days prior to implementation. The standing committee is entitled to raise objections within a period of 30 days. The 60-day advance reporting requirement mirrors the procedure established under Article 7 of the Framework Act on Administrative Regulation (Act No. 19037), which has been empirically validated through two decades of administrative practice. The 30-day objection period aligns with Article 59 of the National Assembly Act and is consistent with the EU’s objection mechanism under Article 290(2)(b) TFEU. In the event that such objections are raised, the effect of the amendment is suspended, and the process transitions to a legal amendment procedure.31 This procedure serves a dual function: to secure democratic legitimacy for the fundamental rights restriction measure of expanding the scope of high-impact AI, while at the same time preventing arbitrary regulatory expansion by the executive branch.
The fourth stage, entitled ‘Transition to Phased Mandatory Enforcement of Obligations,’ addresses the potential adverse consequences of comprehensive mandatory enforcement of current obligations provisions, which could impede innovation. Consequently, for a period of three years following the law’s enactment (22 January 2026 to 21 January 2029), the prevailing obligation system will be sustained. During this period, the government will endeavour to encourage voluntary compliance on the part of businesses by means of the following measures: the dissemination of guidelines, the provision of consultancy services, and the initiation of pilot projects.
Following a three-year preparatory period, the implementation of risk management measures (Article 34, Paragraph 1, Item 1) and user notification (Item 2) will transition to mandatory obligations. Violations of these measures will be subject to the penalty provisions outlined in Article 44. This may be interpreted as a sunset clause.32 The establishment of a human oversight system (Item 3) and appeal procedures (Item 4) will transition to mandatory requirements after five years (21 January 2031). This transition is necessitated by significant sector-specific characteristics, with specific transition timelines for each sector detailed by Presidential Decree. The fifth step, entitled ‘Introduction of Harmonized Standards and Presumption of Conformity’, involves the establishment of a new provision in which the Minister of Science and ICT or the Korea Institute of Artificial Intelligence Safety establishes what may be termed the ‘K-AI Safety Standard’ for high-impact AI. Businesses that comply with this standard are presumed to have fulfilled their obligations under Article 34. Furthermore, a voluntary certification system will be established by third-party institutions in accordance with the law. This system will grant certified businesses priority exemption benefits during administrative agency investigations.33

6.3. Modernization of Civil Liability Jurisprudence

In order to achieve legislative completeness, it is essential that the modernisation of the post-incident rights redress system proceeds in parallel. The following three proposals constitute de lege ferenda recommendations—that is, proposals for what the law ought to be, rather than descriptions of existing legal provisions. Each recommendation is clearly labelled as a proposed amendment to distinguish it from the descriptive analysis of current law presented in the preceding chapters. It is evident that improvements are required in three dimensions.
Firstly, this study proposes the introduction of a new provision that would shift the burden of proof (Proposed Amendment 1: Presumption of Causation). The proposed AI Framework Act will introduce a presumption of causation clause, under which errors or improper design in the AI system will be presumed to have caused damages resulting from high-impact AI. The burden of proof will shift such that the presumption can only be rebutted if the business operator proves its lack of liability. This approach is consistent with the presumption of causation principle that has been adopted in the EU’s proposed AI Liability Directive, while also maintaining consistency with the existing civil law framework (European Commission 2022a).
Secondly, it is recommended that the revised Act establish a framework for allocating liability across AI supply chain segments (Proposed Amendment 2: Supply Chain Liability Allocation). The prevailing legislation characterises both AI developers and distributors as ‘AI business operators’ (Article 2, Item 7), thereby engendering ambiguity regarding the delineation of liability based on roles within the supply chain. The EU AI Act differentiates between Provider and Deployer, and for high-impact AI, responsibility layers are divided into: The following three parties are involved: firstly, the development business operator, who is responsible for the development and provision of the system; secondly, the deployment business operator, who introduces and operates it; and thirdly, the practitioner, who is responsible for the final decision-making. The minimum obligations and scope of liability for each layer are specified in law. Developers are held to strict liability for damages caused by design defects, analogous to product liability law, while deployers are subject to the employer liability doctrine under Article 756 of the Civil Code.34
Thirdly, the introduction of collective dispute mediation procedures is recommended (Proposed Amendment 3: Collective AI Dispute Mediation). It is evident that instances of high-impact AI harm frequently arise from the recurrent implementation of the same algorithm, which results in adverse decisions being made against a specific group. In instances where the damages incurred are minimal and the associated legal expenses exceed the compensation amount, individual lawsuits may not offer a viable solution for redress. The establishment of an AI Dispute Mediation Committee, with the creation of a legal basis in the Framework Act on Artificial Intelligence, is recommended in order to enable collective mediation procedures for the resolution of disputes arising from collective harm (Pasquale 2015).
The following short-term tasks, to be addressed within two years through enforcement decree revisions or legal amendments, have been identified: It is imperative to swiftly define the list of high-impact AI fields in the enforcement decree, while explicitly stating the three judgment criteria in the law to satisfy the principle prohibiting blanket delegation. Furthermore, the minimum standards for the ‘meaningful human control (MHC)’ exception clause (Article 31, Paragraph 4) must be clearly defined in the enforcement decree. In addition, a new legal certainty clause must be established, confirming that guideline compliance cannot serve as grounds for administrative sanctions. Finally, the priority of obligations when generative AI and high-impact AI overlap must be specified in the enforcement decree.
The mid-term tasks encompass the following elements:
-
Legal revision within a timeframe of five years. The following five points are to be considered:
(1)
The establishment of a mandatory triennial re-evaluation of the high-impact AI list, as well as the basis for establishing an expert committee.
(2)
The codification of procedures for reporting re-evaluation results to the National Assembly and for objections.
(3)
The addition of a sunset clause to convert Article 34’s duty provisions into mandatory obligations, and the revision of the sales-based penalty system.
(4)
The establishment of provisions for presumption of causation in high-impact AI damage compensation lawsuits and liability allocation by supply chain segment.
(5)
The establishment of an AI Dispute Mediation Committee and the preparation of collective mediation procedures. Long-term tasks (beyond five years) include: The establishment of an independent supervisory body to separate the Ministry of Science and ICT’s industrial promotion functions from its regulatory and supervisory functions is recommended. Furthermore, the legalisation of the K-AI Safety Standard system and establishment of a presumption of conformity clause for compliance with harmonised standards is advised. Finally, the integration of regulations specialised for foundation models (e.g., GPAI models) into existing laws or the establishment of separate legislation is suggested.

6.4. Conclusion: The Normative Status and Challenges of the Framework Act on Artificial Intelligence

The Framework Act on Artificial Intelligence can be evaluated in accordance with the following synthesis of the aforementioned analysis:
Firstly, the AI Framework Act does not emerge from the phenomenon of ‘regulatory gaps’, but rather from ‘conscious trade-offs’. This outcome materialised as a consequence of the resolution of contentious disagreements pertaining to 19 bills during the course of the consolidated review process in the 22nd National Assembly. This development can be interpreted as a deliberate legislative decision that favours a shift in the regulatory balance, with the objective of promoting technological innovation taking precedence over the protection of fundamental rights. The selection of the concept of ‘High-Impact’, the obligation structure centred on ‘duty’ and ‘duty to endeavour’, and the extensive delegation to subordinate statutes and guidelines all express this decision. The demand for the invalidation of this choice itself or a complete redesign fails to acknowledge the realities of legislation and the inevitability of political compromise.
Secondly, however, the characterisation of this phenomenon as a trade-off does not provide a sufficient justification for the legal vacuum that has been observed. The lacunae in legislation identified in the preceding analysis—which have the potential to contravene the principle of clarity, result in distortions in the attribution of liability, and compromise the efficacy of self-regulation—must be the subject of legislative supplementation in light of the minimum standards stipulated in Article 75 of the Constitution and Article 750 of the Civil Act of the Republic of Korea (2024). It is evident that neglecting to address this discrepancy results in the transfer of the burden of harm to individuals whose fundamental rights are violated. Furthermore, it increases the judicial system’s responsibility of addressing legislative lacunae through interpretation.35
Thirdly, the AI Framework Act is characterised by its inherent quality as a ‘living law’. The strategy of initially establishing a minimal regulatory framework, with subsequent progressive refinement of norms as technology advances and the market matures, forms the basis of its very existence. Following the implementation of the law, there are a number of tasks that must be pursued in a continuous manner. These include the refinement of enforcement decrees, the enhancement of guidelines, the modernisation of liability doctrines, and the establishment of oversight infrastructure. It is hoped that the five-stage legislative model posited in this study will function as a concrete reference standard for this process.36
The European Union’s approach to AI governance, characterised by its robust, pre-emptive hard law system, stands in stark contrast to the Korean model, which offers a distinct alternative. This Korean model combines a supportive environment for innovation with minimal regulatory oversight and a strong emphasis on self-regulation. The experimental outcomes of these two models will provide valuable comparative data for future global AI governance discussions. Nevertheless, the comparative advantage of any regulatory model is ultimately contingent upon its efficacy in safeguarding people’s lives and rights while facilitating innovation. For the Framework Act on Artificial Intelligence to function not merely as a nominal framework but as a substantive, operational norm, subsequent legislation and administrative measures must swiftly minimise the adverse effects of the strategic trade-offs inherent in this law. As artificial intelligence becomes increasingly embedded within the fundamental decision-making processes of society, the design of these systems to be transparent, fair and accountable is not a matter of technological implementation, but rather one of legal governance.37

Funding

This work was supported by 2023 Research Fund of Myongji University.

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

No new data were created or analyzed in this study. Data sharing is not applicable to this article.

Conflicts of Interest

The author declares no conflicts of interest.

References

  1. Almada, Marco, and Anca Radu. 2024. The Brussels Side-Effect: How the AI Act Can Reduce the Global Reach of EU Policy. German Law Journal 24: 646–74. [Google Scholar] [CrossRef] [Scilit]
  2. Barocas, Solon, Moritz Hardt, and Arvind Narayanan. 2023. Fairness and Machine Learning. Cambridge: MIT Press. [Google Scholar]
  3. Bertolini, Andrea. 2025. Artificial Intelligence and Civil Liability—A European Perspective. Publication for the Committee on Legal Affairs. Luxembourg: European Parliament. [Google Scholar]
  4. Biden, Joseph R., Jr. 2023. Executive Order 14110: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence. 88 Federal Register 75191, November 1. Washington, DC: The White House.
  5. Bradford, Anu. 2020. The Brussels Effect: How the European Union Rules the World. Oxford: Oxford University Press, pp. 23–45. [Google Scholar]
  6. Calabresi, Guido. 1982. A Common Law for the Age of Statutes. Cambridge: Harvard University Press, pp. 44–58. [Google Scholar]
  7. Civil Act of the Republic of Korea. 2024. Act No. 20276, Partially Amended 13 February 2024. Seoul: Government of the Republic of Korea. Available online: https://www.law.go.kr/ (accessed on 26 April 2026).
  8. Coglianese, Cary, and Evan Mendelson. 2010. Meta-Regulation and Self-Regulation. In The Oxford Handbook of Regulation. Edited by Robert Baldwin, Martin Cave and Martin Lodge. Oxford: Oxford University Press, pp. 146–68. [Google Scholar]
  9. Colorado General Assembly. 2024. Senate Bill 24-205, Consumer Protections for Artificial Intelligence. Signed 17 May 2024. Effective 1 February 2026. Denver: Colorado General Assembly. [Google Scholar]
  10. Constitutional Court of the Republic of Korea. 1992. Decision 89HunGa104. February 25. Seoul: Constitutional Court of the Republic of Korea. [Google Scholar]
  11. Constitutional Court of the Republic of Korea. 2002. Decision 2000HunBa57. July 18. Seoul: Constitutional Court of the Republic of Korea. [Google Scholar]
  12. Constitutional Court of the Republic of Korea. 2004. Decision 99HunBa91. October 28. Seoul: Constitutional Court of the Republic of Korea. [Google Scholar]
  13. Constitutional Court of the Republic of Korea. 2006. Decision 2005HunBa31. March 30. Seoul: Constitutional Court of the Republic of Korea. [Google Scholar]
  14. Constitution of the Republic of Korea. 1987. Available online: https://elaw.klri.re.kr/eng_service/lawView.do?lang=ENG&hseq=1 (accessed on 26 April 2026).
  15. Cyberspace Administration of China. 2023. Interim Measures for the Management of Generative Artificial Intelligence Services. Effective 15 August 2023. Beijing: Cyberspace Administration of China. [Google Scholar]
  16. Ebers, Martin. 2025. Truly Risk-Based Regulation of Artificial Intelligence: How to Implement the EU’s AI Act. European Journal of Risk Regulation 16: 684–703. [Google Scholar] [CrossRef] [Scilit]
  17. Ebers, Martin, Veronica R. S. Hoch, Frank Rosenkranz, Hannah Ruschemeier, and Björn Steinrötter. 2021. The European Commission’s Proposal for an Artificial Intelligence Act—A Critical Assessment. Journal of Law, Technology and Society 1: 589–603. [Google Scholar]
  18. European Commission. 2021. Proposal for a Regulation Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act). COM/2021/206 Final. Brussels: European Commission.
  19. European Commission. 2022a. Proposal for a Directive on Adapting Non-Contractual Civil Liability Rules to Artificial Intelligence (AI Liability Directive). COM/2022/496 Final. Brussels: European Commission.
  20. European Commission. 2022b. Proposal for a Directive on Liability for Defective Products. COM/2022/495 Final. Brussels: European Commission.
  21. European Union. 2006. Regulation Concerning the Registration, Evaluation, Authorisation and Restriction of Chemicals (REACH). Regulation (EC) No 1907/2006. Brussels: European Parliament and Council of the European Union.
  22. European Union. 2022. Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European Data Governance (Data Governance Act). OJ L 152, 3.6.2022. Brussels: European Union. [Google Scholar]
  23. European Union. 2023. Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on Harmonised Rules on Fair Access to and Use of Data (Data Act). OJ L, 22.12.2023. Brussels: European Union. [Google Scholar]
  24. European Union. 2024. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act). OJ L, 12.7.2024. Brussels: European Union. [Google Scholar]
  25. Framework Act on Artificial Intelligence (Act No. 20676). 2025. Promulgated 21 January 2025, Effective 22 January 2026. Republic of Korea. Available online: https://elaw.klri.re.kr/eng_service/lawView.do?hseq=71019&lang=ENG (accessed on 26 April 2026).
  26. Gasser, Urs, and Virgilio A. F. Almeida. 2017. A Layered Model for AI Governance. IEEE Internet Computing 21: 58–62. [Google Scholar] [CrossRef] [Scilit]
  27. Hacker, Philipp. 2023. The European AI Liability Directives—Critique of a Half-Hearted Approach and Lessons for the Future. Computer Law & Security Review 51: 105871. [Google Scholar]
  28. Helberger, Natali, and Nicholas Diakopoulos. 2023. ChatGPT and the AI Act. Internet Policy Review 12: 1. [Google Scholar] [CrossRef] [Scilit]
  29. Joint Ministry Report. 2019. National Strategy on Artificial Intelligence. Seoul: Government of the Republic of Korea. [Google Scholar]
  30. Kim, Kwang-Soo. 2025. Considerations on the Enactment and Implementation of the Framework Act on Artificial Intelligence. Sogang Law Review 14: 40–75. [Google Scholar]
  31. Kim, Yong-Deok, ed. 2019. Commentary on the General Provisions of the Civil Code, 5th ed. Seoul: Korean Society of Judicial Administration. [Google Scholar]
  32. Kwon, Soon-Hyun. 2025. Review and Improvement Directions for the Framework Act on Artificial Intelligence. Journal of the Korea Society of Computer and Information 30: 25–48. [Google Scholar] [CrossRef] [Scilit]
  33. Laux, Johann, Sandra Wachter, and Brent Mittelstadt. 2024. Trustworthy Artificial Intelligence and the European Union AI Act: On the Conflation of Trustworthiness and Acceptability of Risk. Regulation & Governance 18: 3–32. [Google Scholar]
  34. Lee, Won-Woo. 2008. Regulatory Reform and Deregulation—A Legal Policy Study for Designing Proper Regulatory Policy. Justice 106. [Google Scholar]
  35. Madiega, Tambiama. 2024. Artificial Intelligence Act. PE 698.792. Brussels: European Parliamentary Research Service.
  36. National Assembly Science, Technology, Information, Broadcasting and Communications Committee. 2024. Review Report on the Basic Act on the Development of Artificial Intelligence and the Establishment of a Trust-Based Framework (Alternative Bill). Seoul: National Assembly. [Google Scholar]
  37. National Human Rights Commission of Korea. 2024. Statement of Opinion on Certain Provisions of the Framework Act on the Development of Artificial Intelligence and the Establishment of a Trust-Based System. Seoul: NHRCK. [Google Scholar]
  38. Novelli, Claudio, Federico Casolari, Antonino Rotolo, Mariarosaria Taddeo, and Luciano Floridi. 2024a. AI Risk Assessment: A Scenario-Based, Proportional Methodology for the AI Act. Digital Society 3: 13. [Google Scholar] [CrossRef] [Scilit]
  39. Novelli, Claudio, Mariarosaria Taddeo, and Luciano Floridi. 2024b. Accountability in Artificial Intelligence: What It Is and How It Works. AI & Society 39: 1871–82. [Google Scholar]
  40. OECD. 2019. Recommendation of the Council on Artificial Intelligence. OECD/LEGAL/0449. Paris: OECD. [Google Scholar]
  41. Pasquale, Frank. 2015. The Black Box Society. Cambridge: Harvard University Press, pp. 190–210. [Google Scholar]
  42. Presno Linera, Miguel Ángel, and Anne Meuwese. 2025. Regulating AI from Europe: A Joint Analysis of the AI Act and the Framework Convention on AI. The Theory and Practice of Legislation 13: 292–311. [Google Scholar] [CrossRef] [Scilit]
  43. Ra, Gi-won. 2025. Legislative History and Challenges of the Framework Act on Artificial Intelligence. Legislative Research 69: 128–55. [Google Scholar]
  44. Smuha, Nathalie A. 2021. From a ‘Race to AI’ to a ‘Race to AI Regulation’: Regulatory Competition for Artificial Intelligence. Law, Innovation and Technology 13: 57–84. [Google Scholar] [CrossRef] [Scilit]
  45. Stanford University Human-Centered Artificial Intelligence. 2024. AI Index Report 2024. Stanford: Stanford University, p. 142. [Google Scholar]
  46. Sunstein, Cass R. 2005. Laws of Fear: Beyond the Precautionary Principle. Cambridge: Cambridge University Press, pp. 13–34. [Google Scholar]
  47. Supreme Court of the Republic of Korea. 2005. Decision 2002Da5474. March 10. Seoul: Supreme Court of the Republic of Korea. [Google Scholar]
  48. Supreme Court of the Republic of Korea. 2009. Decision 2009Du7967. December 24. Seoul: Supreme Court of the Republic of Korea. [Google Scholar]
  49. United States v. Carroll Towing Co. 1947. 159 F.2d 169 (2d Cir. 1947). Available online: https://law.justia.com/cases/federal/appellate-courts/F2/159/169/1565896/ (accessed on 26 April 2026).
  50. Veale, Michael, and Frederik Zuiderveen Borgesius. 2021. Demystifying the Draft EU Artificial Intelligence Act—Analysing the Good, the Bad, and the Unclear Elements of the Proposed Approach. Computer Law Review International 22: 97–112. [Google Scholar] [CrossRef] [Scilit]
  51. Wachter, Sandra. 2024. Limitations and Loopholes in the EU AI Act and AI Liability Directives: What This Means for the European Union, the United States, and Beyond. Yale Journal of Law & Technology 26: 671–718. [Google Scholar]
1
(Ra 2025, p. 128). The EU AI Act (European Union 2024) entered into force on 1 August 2024; the Korean Framework Act on Artificial Intelligence (Act No. 20676) was promulgated on 21 January 2025, and will take effect on 22 January 2026.
2
See EU AI Act (European Union 2024), Recital 1 and Article 1. The EU AI Act addresses innovation promotion within the context of ensuring the free movement of AI in the internal market, with the single core objective being the protection of fundamental rights.
3
Bradford (2020) analyses, on pages 23–45, the conditions for the extraterritorial spread of EU regulatory power, including market size, regulatory intensity, compliance costs for domestic companies, and market dependence of foreign companies.
4
Article 35 of the Framework Act on Artificial Intelligence. For criticism of the ‘duty to make efforts’ for impact assessments, see (Kwon 2025), p. 35.
5
See EU AI Act, Article 40 (Harmonized Standards). Compliance with harmonized standards confers a presumption of conformity effect.
6
This is based on the request that, premised on the AI Framework Act being a product of conscious trade-offs, its legal limitations should be empirically examined.
7
See Kim (2019), Introduction section.
8
Article 2(3) of the Framework Act on Artificial Intelligence (2025). Annex I of the EU AI Act (European Union 2024) lists machine learning, logic-based, and statistical approaches as examples of AI techniques but does not define them as separate legal concepts.
9
See (European Union 2022) (Data Governance Act); (European Union 2023) (Data Act). For issues of bias in training data and unfairness in AI outcomes, see (Barocas et al. 2023), chap. 1.
10
Article 2(2) of the Framework Act on Artificial Intelligence (2025). The definition of AI System in Article 3(1) of the EU AI Act (European Union 2024) is based on (OECD 2019).
11
Article 2(4), Article 31, and Article 34 of the Basic Act on Artificial Intelligence.
12
Learned Hand formula from United States v. Carroll Towing Co. (1947): B < PL (Preventive Cost < Probability of Occurrence × Magnitude of Harm).
13
For the conceptual distinction between ‘Impact’ and ‘Risk’, see (Veale and Zuiderveen Borgesius 2021).
14
For the stigma effect and AI regulatory acceptability, see Veale & Borgesius, op. cit., pp. 100–101.
15
EU AI Act, Article 3(3)(4)(6)(7)(8). The EU AI Act imposes distinct obligations on Providers, Deployers, Importers, Distributors, and Product Manufacturers. The allocation of obligations between Providers and Deployers is designed based on who holds greater information and control within the AI supply chain.
16
Article 2(9) of the Framework Act on Artificial Intelligence; Kim Kwang-soo, op. cit., pp. 55–58. While GDPR Article 22 grants data subjects the right to request an explanation for automated decisions, Korean law differs by defining affected persons as independent actors within the regulatory framework.
17
Article 34(1)(4) of the Framework Act on Artificial Intelligence (duty to establish objection procedures). This too is a ‘duty’ provision, limited in that it is not directly linked to sanctions.
18
The EU AI Act declares respect for human dignity, freedom, equality, and fundamental rights as the foundation for AI regulation in Recital 1, but does not include this in its Definitions (Article 3). Comparatively, Canada’s AIDA and major US AI executive orders also do not include concepts like ethics or industrial promotion in their definitions.
19
EU AI Act, Article 25(2).
20
Basic Act on Artificial Intelligence, Articles 4, 34, and 44. Article 75 of the Constitution requires that when delegating authority through presidential decrees, the scope must be “specifically defined.”
21
EU AI Act, Annex III (List of high-risk AI systems related to Article 6(2)).
22
European Commission, Proposal for a Directive on adapting non-contractual civil liability rules to artificial intelligence (European Commission 2022a); Proposal for a Directive on liability for defective products (European Commission 2022b).
23
Constitutional Court Decision 99HunBa91, rendered 28 October 2004 (Constitutional Court of the Republic of Korea 2004). Matters concerning the essence of citizens’ fundamental rights must be determined by the National Assembly itself; delegating this to administrative legislation violates the principle of parliamentary reservation.
24
See (Lee 2008), Analysis of the phenomenon where soft norms acquire de facto binding force in administrative practice and its implications for the rule of law.
25
(Supreme Court of the Republic of Korea 2005). The court ruled that imposing disadvantageous measures solely for non-compliance with administrative guidance violates the prohibition on disadvantageous measures under Article 48(2) of the Administrative Procedure Act.
26
EU AI Act, Articles 9–15, Article 71 (Penalties).
27
EU AI Act, Article 56 (Codes of Practice).
28
EU AI Act, Recital 47 and Article 7.
29
Article 75 of the Constitution. The delegated legislation model under Article 290 TFEU and the delegated legislation system under Article 75 of the Korean Constitution are fundamentally different in terms of the method of parliamentary oversight and the requirements for the limits of delegation.
30
Regarding the Direction for Amending Article 4 of the Framework Act on Artificial Intelligence. Annex III of the EU AI Act directly enumerates eight high-risk AI sectors within the legal text.
31
This procedure adapts the structural principles of the U.S. Congressional Review Act to suit Korea’s unicameral, presidential constitutional system.
32
For legislative techniques regarding sunset clauses, see Calabresi (1982).
33
EU AI Act, Article 40 (Harmonized Standards).
34
EU AI Act, Article 25.
35
For the necessity and limitations of judicial supplementation of legislative gaps, see Kim (2019), General Introduction section. Judicial interpretive supplementation of gaps intentionally created by the legislature (bewusste Lücke) faces limitations under the principle of separation of powers, ultimately requiring legislative resolution.
36
The EU AI Act also adopts a phased implementation structure (e.g., 6 months for prohibitions, 12 months for GPAI, 24 months for high-risk AI) and anticipates continuous refinement of subordinate regulations after entry into force. For AI regulatory frameworks as living law, see Gasser and Almeida (2017).
37
Bradford (2020) points out that the global influence of a regulatory model depends on its substantive protective effect and enforcement reality. The insight that appropriately enforced regulations yield greater social impact than nominally strong regulations provides important implications for the future operation of Korea’s Framework Act on Artificial Intelligence.
Table 1. Comparison of Regulatory Philosophies in Korea’s Basic Act on Artificial Intelligence and the EU AI Act.
Table 1. Comparison of Regulatory Philosophies in Korea’s Basic Act on Artificial Intelligence and the EU AI Act.
CategoryKorea’s Basic Act on Artificial IntelligenceEU AI Act
Legislative PurposeRegulation + Promotion (Dual Purpose)Regulation (Single Purpose—Protection of Fundamental Rights and Safety)
Core Regulatory ConceptsHigh-Impact AIHigh-Risk AI (Directly Listed in Annex III)
Regulatory ApproachEx-post management + self-regulation (open-door approach)Pre-market Conformity Assessment (Preventive Approach)
Nature of Core ObligationsResponsibility-Centered—Numerous Prescriptive and Declarative ProvisionsMandatory obligations—linked to penalties for violations
Regulatory scope finalizedComprehensive Delegation to Presidential Decrees (Flexibility ↑, Predictability ↓)Annex III Direct enumeration of statutes (Clarity ↑)
Enforcement AgencyMinistry of Science and ICT-centered (Lack of specialized independent agency)AI Office + Member State Supervisory Authorities
Violation SanctionsFocus on administrative fines (limited economic deterrence)Global sales-based fines up to 7%
Status of Self-RegulationCore means of substantive regulation (principle of self-regulation)Auxiliary means for demonstrating compliance (Safe Harbor)
Table 2. Analysis of Overlap Types Between High-Impact AI and Generative AI.
Table 2. Analysis of Overlap Types Between High-Impact AI and Generative AI.
System Type (Example)High-Impact AIGenerative AIApplicable Obligation Relationship
Hiring Screening AI (Pass/Fail Decision)OXOnly high-impact AI obligations apply (Article 34)
AI Copywriting Tools (Ad Copy Generation)XOGenerative AI obligations only apply (Article 36)
AI for Medical Diagnostic Report Generation ★OOOverlap—Unclear Priority (Legislative Gap)
Recidivism risk prediction + AI for drafting court rulings ★OOOverlap—Unclear whether weighted obligations apply
AI News Article Writing (General Information Provision)XOOnly Generative AI Obligations Apply (Article 36)
Note: O indicates that the obligation applies; X indicates that the obligation does not apply. ★: Overlapping cases where priority of obligations under current law is unclear. See Articles 34 and 36 of the Framework Act on Artificial Intelligence.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Bang, J. Regulatory Governance of AI in the Generative AI Era: A Comparative Study of South Korea’s AI Basic Act and the EU AI Act for Sustainable Digital Transformation. Laws 2026, 15, 42. https://doi.org/10.3390/laws15030042

AMA Style

Bang J. Regulatory Governance of AI in the Generative AI Era: A Comparative Study of South Korea’s AI Basic Act and the EU AI Act for Sustainable Digital Transformation. Laws. 2026; 15(3):42. https://doi.org/10.3390/laws15030042

Chicago/Turabian Style

Bang, Jungmi. 2026. "Regulatory Governance of AI in the Generative AI Era: A Comparative Study of South Korea’s AI Basic Act and the EU AI Act for Sustainable Digital Transformation" Laws 15, no. 3: 42. https://doi.org/10.3390/laws15030042

APA Style

Bang, J. (2026). Regulatory Governance of AI in the Generative AI Era: A Comparative Study of South Korea’s AI Basic Act and the EU AI Act for Sustainable Digital Transformation. Laws, 15(3), 42. https://doi.org/10.3390/laws15030042

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop