Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
Context fileUnder Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, Article 34(1)
What does it require?
Operators of high-impact AI must prepare and implement a plan to protect users, and must prepare and keep documents describing the measures they take to secure the AI's safety and reliability, so that they can be shown to the Ministry of Science and ICT on request. Further items may be added by Presidential Decree, and the ministry may publish guidelines on how to meet these duties.
Practical action
Write a user-protection plan for each high-impact system and keep a dated file of the safety and trust measures applied to it.
Who does it apply to?
AI business operators providing high-impact AI or products and services based on it.
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesProcessProduct or model owner · at launch and on material changeTechnical documentation, model cards and instructions for use
Serves 13 recorded duties · evidence: Technical documentation file, Model card or deployer information pack, Instructions for use
Documentation of safety and reliability measures.
-
supportsPolicyExecutive sponsor for AI · annualAI governance policy and accountability structure
Serves 16 recorded duties · evidence: AI policy, Board or executive approval of the AI policy, AI governance forum minutes
User-protection plan and ownership.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| User protection plan | document | |
| Safety and reliability measures file | record |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every South Korea duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 7.5; Annex A.6.2.7, A.9.3 | Documented information, technical documentation and objectives for responsible use. | medium |
| NIST AI RMF 1.0 | GOVERN 1.4, MANAGE 4.1 | Documentation and post-deployment user protection. | medium |
Cite this record
AIPolicyTracker (2026). “Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures (Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust)”. https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-user-protection-and-documentation (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust (AI Basic Act, Act No. 20676), Korea Ministry of Government Legislation, National Law Information Center, https://www.law.go.kr/lsInfoP.do?lsiSeq=268543.
Similar obligations in other instruments
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold — EU AI Act, European Union
- Providers must meet the full set of provider duties for high-risk AI — EU AI Act, European Union
- Use high-risk AI as instructed, monitor it and inform affected people — EU AI Act, European Union
- Providers must supply conformity evidence and log access to authorities on request — EU AI Act, European Union
- Non-EU providers must appoint an EU authorised representative for high-risk AI — EU AI Act, European Union
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI — EU AI Act, European Union
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually — EU AI Act, European Union
- Non-EU providers of GPAI models must appoint an EU authorised representative — EU AI Act, European Union
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.