What Changed
On August 20, 2026, South Korea's National Assembly passed an amendment to the Personal Information Protection Act (PIPA) creating a special legal pathway for AI developers to use original, non-pseudonymized personal data — without the data subject's consent and beyond the data's original collection purpose. Until now, Korean law generally required firms to strip or pseudonymize personal data before using it for secondary purposes like model training. The amendment doesn't repeal that default; it carves an exception, gated by the Personal Information Protection Commission (PIPC).
Per the PIPC's own August 20 announcement, three conditions must all be met: pseudonymized or anonymized data must genuinely be insufficient for the AI development in question; a public-interest or social necessity must be established; and the applicant must pass PIPC deliberation and resolution with enhanced safety measures attached. The PIPC says it will fast-track cases that are "substantially identical or similar" to previously approved projects, and companies using the exception must disclose their processing policies while the PIPC publishes oversight summaries. The law takes effect roughly six months after promulgation — meaning Cabinet sign-off is still pending before the clock even starts.
The Case For It — Steelmanned
Korean regulators aren't wrong about the underlying problem. Frontier AI training genuinely struggles on data that's been pseudonymized into statistical mush: names, timestamps, and identifiers are often exactly the signal a model needs to learn coherent structure, and re-obtaining individual consent from millions of data subjects for a purpose that didn't exist when the data was collected is not realistic. Korea's existing regulatory sandbox let companies test AI uses under a temporary carve-out, but only for two to four years — useless as a durable foundation for products meant to run indefinitely. A permanent, conditioned pathway, gated by an independent regulator rather than left purely to self-certification, is a defensible middle path between "no AI training on personal data, ever" and "anything goes." Countries from Japan to Singapore have made comparable moves toward flexible legal bases for AI training; Korea's approach at least keeps a regulator, not the developer alone, deciding where the line sits.
The Steelman Against
Civil society's objection deserves a fair hearing too. In a joint statement, 36 Korean civil society organizations — opposing earlier versions of this bill sponsored by Reps. Min Byung-deok and Koh Dong-jin — argued the change effectively treats personal data as a "public resource" for national AI ambitions, stripping individuals of a constitutional right to control their own information with no clear mechanism to opt out. They pointed to the 2021 Iruda chatbot scandal, in which a Korean AI companion trained on inadequately anonymized chat logs leaked users' real names, addresses, and phone numbers, as proof that "anonymization" promises don't always survive contact with a trained model. That's a legitimate, specific harm, not a hypothetical one, and it's the strongest argument for keeping data minimization as the default rather than the exception.
Why the Real Risk Is Discretion, Not Data Use
Where the amendment is more vulnerable to criticism — including from a pro-innovation standpoint — is not that it permits AI training on personal data at all, but how it decides which projects qualify. As IAPP's analysis of the bill puts it, the law shifts real decision-making authority away from companies operating inside legible statutory limits and toward the PIPC's case-by-case judgment. For a privacy advocate, that's a rights concern. For a builder, it's an investment-planning problem: a regulator empowered to approve individually, using undefined terms like "public interest" and "social necessity," gives startups and researchers no way to predict in advance whether a given training run will clear review. Firms with in-house regulatory affairs teams and existing PIPC relationships will navigate the fast-track path for "substantially similar" approvals; smaller developers without that history face a genuinely open-ended gate. A bright-line statutory carve-out — say, a defined data-minimization-plus-audit standard any qualifying developer could self-certify against — would have done more for both privacy and innovation than a discretionary approval queue whose contours only case-by-case precedent will reveal.
The PIPC itself seems to sense this is unfinished business. Days before the floor vote, on August 5, it opened a month-long public consultation — running through August 31 — under a newly formed "AI-era Personal Information System Innovation" task force, explicitly seeking proposals on how to modernize a law regulators admit was "designed 30-plus years ago." That's a tacit admission that August 20 is a patch, not a settled framework.
The Bottom Line
Korea was right to recognize that a rigid, consent-only regime cannot survive contact with how modern AI is actually trained, and a regulator-approved exception beats an unauthorized free-for-all. But durable rules for AI training data should look more like clear, appealable standards than a discretionary approval gate — otherwise the next Iruda-style leak becomes a governance failure the PIPC itself is on the hook for, one case-by-case approval at a time.