South Korea AI regulation

South Korea's AI Law Leads With Procurement Incentives, Not Penalties

Seoul's July 21 enforcement decree uses public contracts and a light fine regime to jump-start AI adoption ahead of enforcement.

Korea's AI Law: Incentives First, Penalties Later People of Internet Research · South Korea ₩30M (~$21K) Max administrative fine Cap for violations like failing to… €35M EU AI Act fine ceiling EU's maximum for prohibited AI pra… 1 year Fine grace period MSIT generally defers penalties du… 3→2 firms Multi-supplier requirement eased Confirmed AI vendors need fewer co… peopleofinternet.com
Korea's AI Law: Incentives First, Pena… People of Internet Research · South Korea ₩30M (~$21K) Max administrative f… €35M EU AI Act fine ceiling 1 year Fine grace period 3→2 firms Multi-supplier requirement eased peopleofinternet.com

Key Takeaways

South Korea's Ministry of Science and ICT (MSIT) got its clearest signal yet on how the country intends to run its landmark AI law: lead with the carrot, keep the stick in the drawer. On July 14, 2026, the State Council approved a revised enforcement decree for the AI Basic Act — officially the Basic Act on AI Development and Trust-Building, enacted January 21, 2025 and in force since January 22, 2026 — with the new provisions taking effect July 21. The amendment does almost nothing to expand what counts as risky AI. Instead, it builds out procurement preferences, subsidized access for vulnerable users, startup financing, and a legal basis for new AI research institutes.

What Actually Changed

The centerpiece is a new AI Product/Service Confirmation System, which begins operating in August 2026 with no application fee during its initial phase. Products and services that receive confirmation get real, quantifiable advantages in the ₩243 trillion-scale public procurement process that agencies run every year: the number of competing suppliers required under multi-supplier contracts drops from three firms to two, credit-worthiness scoring gets a bonus for confirmed AI offerings, and software vendors are exempted from having to show a prior delivery track record. That last change matters most for startups, which often lose public bids simply for lacking a government reference client.

The decree also widens the legal definition of "AI-vulnerable groups" — people entitled to subsidized cost support for AI services — beyond the original categories of people with disabilities, seniors 65 and older, and basic welfare recipients. It now explicitly includes job seekers and women re-entering the workforce after a career break, populations the government is betting AI tools (resume writing, retraining, job matching) can serve cheaply. Separately, the decree authorizes AI research institutes to be established by universities, companies, other research bodies, or nonprofits, and clarifies the financial and security requirements they must meet, while directing government-backed venture capital toward AI startups. MSIT Vice Minister Bae Kyung-hun framed the package as accelerating both public-sector AI adoption and citizen access to AI services.

The Regulation Everyone Forgot Was Already Running

It's worth remembering what this decree is not: a rewrite of the AI Basic Act's actual risk regime. That structure — mandatory disclosure for generative AI outputs, risk-management and human-oversight duties for "high-impact AI," and heavier obligations for systems trained above 10²⁶ FLOPs — has been in force since January 22, 2026. Foreign AI operators without a Korean office must appoint a domestic representative only if they clear steep thresholds: roughly $662 million in prior-year global revenue, $6.6 million in Korea-specific AI revenue, or one million average daily Korean users. MSIT has also been running a de facto one-year grace period through the law's first year, generally deferring fact-finding investigations and fines except in cases of serious harm. When fines do apply — for failures like not disclosing AI use or ignoring a corrective order — the cap is ₩30 million, roughly $21,000 per violation, a small fraction of the €35 million (or up to 7% of global turnover) ceiling under the EU AI Act's prohibited-practices tier.

That gap is precisely what critics point to. An IAPP analysis of the law's enforcement design has called it "all roar, no bite": the grace period functions, in the critics' words, like a regulatory moratorium, the fine cap is too small to deter a well-resourced violator, and the threshold for "high-performance AI" obligations was set roughly ten times higher than the EU's comparable standard — meaning very few systems will ever trigger the law's toughest requirements. The renaming of the oversight body from a National AI Committee to a National AI Strategy Committee, they argue, telegraphs where the government's real priority sits.

The Steelman, and Why Seoul's Bet Still Makes Sense

The critics have a real point worth taking seriously. A rulebook whose penalties can't outweigh the cost of compliance risks becoming advisory rather than binding, and vulnerable users — the same people this decree nominally protects — are exactly who suffers when disclosure and oversight duties go unenforced. Deepfakes, opaque hiring algorithms, and AI-driven welfare determinations are not hypothetical harms; Korea has already seen domestic controversies over algorithmic bias in exactly these areas. A government serious about "trust-building," as the law's own title puts it, eventually has to show it will use the fines it wrote into the statute.

But treating the first year of a brand-new statute as the permanent settlement misreads the sequencing. Most jurisdictions that front-load heavy penalties — the EU chief among them — have also front-loaded years of compliance uncertainty, conflicting guidance, and litigation over undefined terms like "high-risk." South Korea is doing the opposite: using the state's own ₩243 trillion procurement budget as demand-side pressure to get real AI products built, tested, and adopted domestically before the enforcement apparatus fully engages. That is a coherent industrial strategy, not a loophole — provided the grace period actually ends on schedule and MSIT follows through on enforcement once vulnerable-group and disclosure obligations have had a fair runway to bed in. The test of this approach won't be the July decree itself; it will be whether Seoul flips from incentives to enforcement when the grace period lapses, or quietly extends it again.

Sources & Citations

  1. Korea's National Law Information Center — AI Basic Act statute
  2. EU AI Act, Article 99 (Penalties) — official text
  3. U.S. International Trade Administration — South Korea AI Basic Act market intelligence
  4. Edaily — State Council approves AI Basic Act enforcement decree
  5. Cooley LLP — South Korea's AI Basic Act: Overview and Key Takeaways
  6. IAPP — South Korea's AI Act designed to be all roar, no bite