AIPolicyTracker
Legal requirement Safety testing and evaluation South Korea In force

Operators of AI above the compute threshold must run lifecycle risk management and report safety results

Context fileUnder Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, Article 32

Source-linked Open official source

What does it require?

An AI business operator whose AI system's cumulative training computation exceeds the threshold set by Presidential Decree must identify, assess and mitigate risks across the system's life cycle, build a risk management system to monitor and respond to safety incidents caused by the AI, and submit the results of these measures to the Minister of Science and ICT. The threshold and reporting form are set in the Decree.

Practical action

Track training compute against the decree threshold and prepare a safety report covering risk identification, mitigation and incident monitoring for submission to the ministry.

Who does it apply to?

Operators of AI systems whose cumulative training compute exceeds the Presidential Decree threshold, in practice frontier-scale model developers.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesPolicyHead of AI safety · annual
    Frontier model safety and security framework

    Serves 9 recorded duties · evidence: Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority

    Compute tracking, lifecycle risk assessment and reporting to the authority.

  • supportsProcessIncident coordinator · continuous
    AI incident management and regulatory reporting

    Serves 14 recorded duties · evidence: AI incident response playbook, AI incident record, Incident report to an authority

    Incident monitoring and response arm of the risk management system.

  • supportsTechnical measureAI security or safety lead · at launch and on material change
    Adversarial and red-team testing for generative AI

    Serves 8 recorded duties · evidence: Red-team exercise report, Red-team rules of engagement and scenario library, Adversarial findings tracker

    Evidence for the risk identification step.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
Lifecycle risk assessment and mitigation recordreport
Safety measures report submitted to the ministryreport

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every South Korea duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
NIST AI RMF 1.0MAP 5.1, MEASURE 2.6, MANAGE 1.3, MANAGE 4.3Safety evaluation, risk treatment and incident response.medium
ISO/IEC 42001:2023Clause 6.1.2, 6.1.3, 9.1Risk assessment, treatment and monitoring.medium

Cite this record

AIPolicyTracker (2026). “Operators of AI above the compute threshold must run lifecycle risk management and report safety results (Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust)”. https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-32-safety-measures-for-high-performance-ai (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust (AI Basic Act, Act No. 20676), Korea Ministry of Government Legislation, National Law Information Center, https://www.law.go.kr/lsInfoP.do?lsiSeq=268543.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.