Operators of high-impact AI must establish and operate a risk management plan
Context fileUnder Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, Article 34(1)
What does it require?
An AI business operator that provides high-impact AI, or a product or service using it, must establish and operate a plan for managing the risks of that AI. High-impact AI is AI used in areas such as energy, drinking water, health care and medical devices, nuclear safety, biometric analysis for criminal investigation, decisions on recruitment or loans, transport, public services and education, where it may materially affect life, safety or fundamental rights.
Practical action
Classify systems against the high-impact areas and write a risk management plan for each one before launch.
Who does it apply to?
AI business operators providing high-impact AI or products and services based on it; operators may ask the ministry to confirm whether a system is high-impact under Article 33.
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesProcessAI system owner · once per ai systemAI risk assessment and lifecycle risk register
Serves 12 recorded duties · evidence: AI system risk assessment, Per-system AI risk register, Residual-risk acceptance
Per-system risk plan with identified risks and treatments.
-
supportsProcessAI governance lead · continuousAI system inventory and classification
Serves 11 recorded duties · evidence: AI system register, Risk-tier classification sign-off, AI intake and classification procedure
Classification of systems against the high-impact list.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| High-impact AI risk management plan | document | |
| High-impact classification record | record |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every South Korea duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 6.1.2, 6.1.3, 8.1 | Risk assessment, treatment and operational planning. | medium |
| NIST AI RMF 1.0 | MAP 1.5, MANAGE 1.3 | Risk tolerance and treatment. | medium |
Cite this record
AIPolicyTracker (2026). “Operators of high-impact AI must establish and operate a risk management plan (Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust)”. https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-risk-management-plan (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust (AI Basic Act, Act No. 20676), Korea Ministry of Government Legislation, National Law Information Center, https://www.law.go.kr/lsInfoP.do?lsiSeq=268543.
Similar obligations in other instruments
- Developers must use reasonable care to avoid algorithmic discrimination — Colorado AI Act, Colorado (United States)
- Deployers must use reasonable care to avoid algorithmic discrimination — Colorado AI Act, Colorado (United States)
- Apply minimum risk-management practices to high-impact AI — OMB M-25-21, United States
- Deployers must implement a risk management policy and programme — Colorado AI Act, Colorado (United States)
- Establish a risk management system for high-risk AI — EU AI Act, European Union
- Ensure AI systems are safe, secure and robust throughout their lifecycle — UK AI regulation framework, United Kingdom (voluntary)
- Prioritise, respond to and monitor AI risks (Manage) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.