South Korea AI Basic Act Compliance Checklist
In brief
The South Korea AI Basic Act Compliance Checklist is a free XLSX and DOCX checklist. Every recorded duty of the Korean Framework Act as a checklist per product: advance notice and labelling of generative and high-impact AI, compute-threshold safety measures, high-impact duties and the domestic representative. It is licensed CC BY 4.0 and is not legal advice.
- Format
- XLSX and DOCX · Checklist
- Version
- v1, built 5 Oct 2026
- Duties cited
- 9 from 1 instruments
- Rows from the records
- 18
- Written for
- Provider / developer, Deployer / user organisation, Public authority / government body
- Price and licence
- Free · CC BY 4.0
What's inside
- Checklist sheet: each recorded duty with its article, review status, owner and evidence
- Systems-in-scope sheet deciding which duty groups apply per product
- Document: scope and a section per duty
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Korean AI Basic Act checklist
| Duty | Reference | Record | Status ▾ | Owner | Evidence link | Record link |
|---|---|---|---|---|---|---|
| AI business operators must notify users in advance that a product or service runs on high-impact or generative AI | Article 31(1) | Verified | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-31-advance-notice-of-high-impact-and-generative-ai | |||
| AI business operators must label generative AI output and clearly flag realistic synthetic media | Article 31(2) and 31(3) | Verified | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-31-generative-output-labelling-and-deepfake-notice | |||
| Operators of AI above the compute threshold must run lifecycle risk management and report safety results | Article 32 | Verified | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-32-safety-measures-for-high-performance-ai | |||
| Operators of high-impact AI must establish and operate a risk management plan | Article 34(1) | Verified | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-risk-management-plan | |||
| Operators of high-impact AI must be able to explain outputs and the main criteria behind them | Article 34(1) | Verified | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-explanation-measures | |||
| Operators of high-impact AI must ensure human management and supervision | Article 34(1) | Verified | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-human-oversight |
One row per recorded duty of the Framework Act. Copy the rows for each product or service offered in Korea.
Sheet: Systems in scope
| Product or service | Uses generative AI ▾ | Possibly high-impact AI ▾ | Above the compute threshold ▾ | Operator outside Korea ▾ | Domestic representative | Notes |
|---|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | ||||||
Decide, per product, which of the Act's duty groups apply: notice and labelling (generative and high-impact AI), safety measures (above the compute threshold), the high-impact duties, and a domestic representative for foreign operators.
Sheet: Duties on record
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AI business operators must notify users in advance that a product or service runs on high-impact or generative AI | Transparency and disclosure | Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust | South Korea | Provider / developer, Deployer / user organisation | Legal requirement | Article 31(1) | 2026-01-22 | An AI business operator that provides a product or service operated by high-impact AI or by generative AI must notify users in advance that the product or servi | User notice copy and placement record | Annex A.8.5 | GOVERN 5.1, MANAGE 4.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-31-advance-notice-of-high-impact-and-generative-ai |
| AI business operators must label generative AI output and clearly flag realistic synthetic media | Transparency and disclosure | Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust | South Korea | Provider / developer, Deployer / user organisation | Legal requirement | Article 31(2) and 31(3) | 2026-01-22 | An AI business operator that provides generative AI or a product or service using it must indicate that the output was generated by generative AI. Where the ope | Output labelling design and samples; Synthetic media labelling standard | Annex A.8.2, A.8.5 | MEASURE 2.7, MANAGE 4.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-31-generative-output-labelling-and-deepfake-notice |
| Operators of AI above the compute threshold must run lifecycle risk management and report safety results | Safety testing and evaluation | Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust | South Korea | Provider / developer, General-purpose AI model provider | Legal requirement | Article 32 | 2026-01-22 | An AI business operator whose AI system's cumulative training computation exceeds the threshold set by Presidential Decree must identify, assess and mitigate ri | Lifecycle risk assessment and mitigation record; Safety measures report submitted to the ministry | Clause 6.1.2, 6.1.3, 9.1 | MAP 5.1, MEASURE 2.6, MANAGE 1.3, MANAGE 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-32-safety-measures-for-high-performance-ai |
| Operators of high-impact AI must establish and operate a risk management plan | AI risk management | Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust | South Korea | Provider / developer, Deployer / user organisation, Public authority / government body | Legal requirement | Article 34(1) | 2026-01-22 | An AI business operator that provides high-impact AI, or a product or service using it, must establish and operate a plan for managing the risks of that AI. Hig | High-impact AI risk management plan; High-impact classification record | Clause 6.1.2, 6.1.3, 8.1 | MAP 1.5, MANAGE 1.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-risk-management-plan |
| Operators of high-impact AI must be able to explain outputs and the main criteria behind them | Transparency and disclosure | Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust | South Korea | Provider / developer, Deployer / user organisation, Public authority / government body | Legal requirement | Article 34(1) | 2026-01-22 | Operators of high-impact AI must put in place measures to explain the AI's final results, the main criteria used to reach them, and an overview of the training | Explanation method and decision-criteria documentation | Annex A.8.2, A.7.3 | MEASURE 2.9, GOVERN 5.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-explanation-measures |
| Operators of high-impact AI must ensure human management and supervision | Human oversight | Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust | South Korea | Provider / developer, Deployer / user organisation, Public authority / government body | Legal requirement | Article 34(1) | 2026-01-22 | Operators of high-impact AI must ensure that the AI is subject to human management and supervision, so that people remain able to monitor its operation and inte | Human supervision design and assigned supervisors | Annex A.9.2 | GOVERN 3.2, MANAGE 2.4 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-human-oversight |
Document outline (DOCX)
- South Korea AI Basic Act: compliance checklist
- Scope
- Duties, one by one
- AI business operators must notify users in advance that a product or service runs on high-impact or generative AI
- AI business operators must label generative AI output and clearly flag realistic synthetic media
- Operators of AI above the compute threshold must run lifecycle risk management and report safety results
- Operators of high-impact AI must establish and operate a risk management plan
- Operators of high-impact AI must be able to explain outputs and the main criteria behind them
- Operators of high-impact AI must ensure human management and supervision
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
- Operators of high-impact AI should assess its impact on fundamental rights before use
- Foreign AI business operators above the threshold must designate a domestic representative in Korea
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Fill in your rows. Complete the "Systems in scope" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
- 4Check the duties against your situation. The "Korean AI Basic Act checklist" and "Duties on record" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 5Complete the document. Work through the DOCX sections (South Korea AI Basic Act: compliance checklist, Duties, one by one) and replace each placeholder with your organisation's answer.
- 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (9)
Each is cited in the file with its source reference and a link back to the record.
- AI business operators must notify users in advance that a product or service runs on high-impact or generative AI
- AI business operators must label generative AI output and clearly flag realistic synthetic media
- Operators of AI above the compute threshold must run lifecycle risk management and report safety results
- Operators of high-impact AI must establish and operate a risk management plan
- Operators of high-impact AI must be able to explain outputs and the main criteria behind them
- Operators of high-impact AI must ensure human management and supervision
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
- Operators of high-impact AI should assess its impact on fundamental rights before use
- Foreign AI business operators above the threshold must designate a domestic representative in Korea
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | c6967b988bb5 | First version, built from dataset c6967b988bb5. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the South Korea AI Basic Act Compliance Checklist?
Checklist sheet: each recorded duty with its article, review status, owner and evidence. Systems-in-scope sheet deciding which duty groups apply per product. Document: scope and a section per duty.
Which duties does it cite?
9 recorded duties from Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, including Article 31(1), Article 31(2) and 31(3), Article 32, Article 34(1), Article 35 and Article 36. Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on provider / developer, deployer / user organisation and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v1 was built on 5 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.