A Bottleneck Lawmakers Want to Break
South Korea is one plenary vote away from rewriting the legal basis for AI training data. On July 29, 2026, the National Assembly's Legislation and Judiciary Committee cleared a bill amending the Personal Information Protection Act (PIPA) with bipartisan support, following passage by the Political Affairs Committee on May 14, 2026. The bill would, for the first time, let data controllers use personal information in its original, non-pseudonymized form to develop AI systems — without the data subject's consent and beyond the purpose for which it was originally collected — provided the Personal Information Protection Commission (PIPC) approves each use (IAPP). Only a floor vote remains, expected as early as mid-August 2026, though a separate, unrelated fight over National Assembly Act amendments has left the exact floor date unconfirmed (Digital Times). The law would take effect six months after promulgation.
What the Bill Actually Permits
The exception is narrower than "AI companies can now use any data they want." Under the version reported out of committee, a controller may use previously, lawfully collected raw data for AI development only when four conditions are jointly satisfied: anonymization or pseudonymization is technically insufficient to achieve the AI development purpose; adequate safety measures are in place; the purpose serves public interest, the protection of the data subject or a third party, or broader social benefit; and the risk of unfairly infringing the rights of data subjects or third parties is markedly low (Korea Policy Briefing). Crucially, none of that is self-certified. The PIPC must deliberate and approve each case before the data can be used — the commission, not the statute, decides where the line sits.
The Case Lawmakers Are Making
It's worth taking that case seriously before arguing against it. Korean industry has argued for years that pseudonymization — the default legal path for repurposing personal data — strips out exactly the signal that computer-vision and voice AI need to work: facial expressions, gait, or the surrounding context in a video frame become unusable once identifying detail is scrubbed. The PIPC itself has been building toward this for eighteen months, from its August 2025 guidance on personal-data processing for generative AI, to its December 2025 work plan explicitly framed around "promoting an AI convergence society based on personal data protection trust" (Korea Policy Briefing). Seen that way, the amendment isn't a giveaway to platforms; it's an attempt to give Korean AI developers — who compete directly with US and Chinese labs training on far looser data regimes — a lawful path to the raw data those models increasingly require, gated by a regulator that has spent two years building the technical competence to police it.
Why a Case-by-Case Gate Isn't a Substitute for a Rule
That argument holds up better as a description of PIPC's intentions than as a guarantee about the statute's text. Civic groups, including the People's Solidarity for Participatory Democracy, objected as soon as the bill cleared the Political Affairs Committee, warning that it authorizes use of original personal data without subject consent and demoting purpose limitation and data minimization — core PIPA principles — to secondary status relative to industry development. They asked the Legislation and Judiciary Committee to examine the bill for constitutional exposure before advancing it (NSP통신); the committee cleared it anyway, though it did narrow an earlier draft so that any provisions excluded from normal PIPA safeguards are separately reviewed and approved by the PIPC rather than blanket-waived. That's a real improvement, but it doesn't resolve the deeper structural issue the amendment creates: predictability shifts from the statute to the regulator's case file. A company cannot read PIPA and know in advance whether a given training use is lawful — it has to ask the PIPC and wait. For a jurisdiction competing to attract AI investment, that is a meaningful cost, even if each individual approval is well-reasoned.
The Same Regulator Now Holds the Carrot and a Much Bigger Stick
Context matters here: this is not a commission gaining power in a vacuum. A separate PIPA amendment, promulgated March 10, 2026 and taking effect September 11, 2026, authorizes fines of up to 10% of a company's total worldwide turnover and places direct supervisory liability on CEOs for data-protection failures (IAPP). Read together, the two amendments hand the PIPC both the discretion to approve novel, consent-free AI data use and the authority to impose some of the largest privacy fines in Asia if a company gets it wrong. That combination can work — it mirrors how competition regulators use conditional clearances — but only if the PIPC publishes its approval reasoning, not just its yes/no outcomes, and gives rejected applicants a genuine appeal path rather than a closed-door redo.
Our View
Korea's AI sector has a legitimate data problem, and a regulator-mediated exception is a more proportionate fix than either a blanket ban or unrestricted access. But discretion this broad needs a paper trail: published approval criteria, anonymized case summaries so a competitor can gauge what qualifies, and a statutory sunset or mandatory review once the PIPC has a caseload to evaluate. Absent that, the National Assembly will have replaced one bright line with the PIPC's judgment call — better than no path forward, but a weaker guarantee than the consent principle it replaces.