South Korea AI Basic Act (in force 2026-01-22)
Baseline duties for AI operators, heightened duties for "high-impact" AI in sensitive sectors, and AI-content labelling
AIGE-OBL-KR-AIBASIC. Drawn from chapter 08.
Text alternative
- Clause: Korea AI Act, AI Basic Act.
- Duty holder: Not stated.
- Applies from: 2026-01-22, Grace period.
- Artefact: Risk register for high-impact….
- Layers: Layer 01, Layer 02, Layer 04.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- The same topic in 28 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-KR-AIBASIC- Instrument
- South Korea AI Basic Act law
- Clause
- AI Basic Act
- Applies from
- Grace period · MSIT announced a guidance period of at least one year that holds back fact-finding and fines except in exceptional cases, while the duties apply
The artefact that evidences it
Risk register for high-impact AI; AI-use notification; AI-content labelling.
Patterns that build it
No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Risk management
- EU AI Act Art. 9 Risk management system (core)
- ISO 42001 6.1.2 AI risk assessment (core)
- ISO 42001 6.1.3 AI risk treatment (core)
- ISO 42001 8.2 AI risk assessment (operation) (core)
- ISO 42001 8.3 AI risk treatment (operation) (core)
- NIST AI RMF MAP 1 MAP 1: Context is established and understood (core)
- NIST AI RMF MAP 5 MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized (core)
- NIST AI RMF MANAGE 1 MANAGE 1: AI risks based on assessments and other analytical output are prioritized, responded to, and managed (core)
- TC260 Framework 3.0 TC260 2 Classification of AI safety risks (core)
- TC260 Framework 3.0 TC260 Summary table Risks × technological × governance measures (core)
- ISO 23894 23894 6.4 Risk assessment (core) (clause not verified)
- ISO 23894 23894 6.5 Risk treatment (core) (clause not verified)
- NIST AI RMF GOVERN 1.3 GOVERN 1.3: Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance (core)
- NIST AI RMF MAP 1.5 MAP 1.5: Organizational risk tolerances are determined and documented (core)
- NIST AI RMF MANAGE 1.3 MANAGE 1.3: Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented (core)
- NIST AI RMF MANAGE 1.4 MANAGE 1.4: Negative residual risks to both downstream acquirers of AI systems and end users are documented (core)
- NIST AI RMF MEASURE 3 MEASURE 3: Mechanisms for tracking identified AI risks over time are in place (core)
- CSA AICM GRC-02 Risk Management Program (core)
- UK ATRS ATRS 2.5.2 Risks and mitigations (core)
- Singapore Agentic Agentic 2.1 Assess and bound the risks upfront (core)
- CoE Convention CoE Art. 16 Risk and impact management framework (core)
- prEN 18228 prEN 18228 AI risk management (draft; supports Art. 9) (core) (clause not verified)
- GAO AI Accountability 1.6 Risk management: implement an AI-specific risk management plan to systematically identify, analyze, and mitigate risks (core)
- ISO 42001 A.6 AI system life cycle
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics
- TC260 Framework 3.0 TC260 5.3.19 Re-assessment on material change
- China GenAI Measures GenAI Art. 17 Security assessment and algorithm filing
- China Algo. Rec. AlgoRec Art. 27 Security assessment
- EU AI Act Art. 3 Definitions
- ISO 42001 6.1.4 AI system impact assessment
- ISO 23894 23894 6.6 Monitoring and review (clause not verified)
- GPAI Code Safety C1 Commitment 1: Safety and Security Framework
- GPAI Code Safety C3 Commitment 3: Systemic risk analysis
- CSA AICM MDS-12 Open Model Risk Assessment
- OECD AI Principles OECD 1.5(c) Systematic risk management at each lifecycle phase
Governance and accountability
- EU AI Act Art. 17 Quality management system (core)
- ISO 42001 5.1 Leadership and commitment (core)
- ISO 42001 5.2 AI policy (core)
- ISO 42001 5.3 Roles, responsibilities and authorities (core)
- ISO 42001 A.2 Policies related to AI (core)
- ISO 42001 A.3 Internal organization (core)
- NIST AI RMF GOVERN 1 GOVERN 1: Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively (core)
- NIST AI RMF GOVERN 2 GOVERN 2: Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained (core)
- TC260 Framework 3.0 TC260 4 Comprehensive governance measures (core)
- TC260 Framework 3.0 TC260 5.3.12 Traceable chain of responsibility (core)
- China GenAI Measures GenAI Art. 9 Provider responsibility as content producer (core)
- China Algo. Rec. AlgoRec Art. 7 Algorithm-security responsibility system (core)
- China Deep Synthesis DeepSyn Art. 7 Information-security responsibility system (core)
- GDPR Art. 5(2) Accountability (core)
- ISO 42001 9.3 Management review (core) (clause not verified)
- CSA AICM GRC-01 Governance Program Policy and Procedures (core)
- CSA AICM GRC-06 Governance Responsibility Model (core)
- UK ATRS ATRS 2.1 Owner and responsibility (core)
- Singapore GenAI GenAI 1 Accountability (core)
- Singapore Agentic Agentic 2.2.1 Clear allocation of responsibilities within and outside the organisation (core)
- OECD AI Principles OECD 1.5 Accountability (core)
- GAO AI Accountability 1.2 Roles and responsibilities: define clear roles, responsibilities, and delegation of authority for the AI system (core)
- EU AI Act Art. 4 AI literacy
- EU AI Act Art. 87 Reporting of infringements and protection of reporting persons
- ISO 42001 7.2 Competence (clause not verified)
- ISO 42001 9.2 Internal audit (clause not verified)
- ISO 42001 10.1 Continual improvement (clause not verified)
- NIST AI RMF GOVERN 4 GOVERN 4: Organizational teams are committed to a culture that considers and communicates AI risk
- NIST AI RMF GOVERN 5 GOVERN 5: Processes are in place for robust engagement with relevant AI actors
- GPAI Code Safety C8 Commitment 8: Systemic risk responsibility allocation
- CoE Convention CoE Art. 9 Accountability and responsibility
- G7 Code G7 Action 5 Develop, implement and disclose AI governance and risk-management policies
- EN 18286 EN 18286 Quality management system for EU AI Act regulatory purposes
- GAO AI Accountability 1.1 Clear goals: define clear goals and objectives for the AI system
- GAO AI Accountability 1.3 Values: demonstrate a commitment to values and principles established by the entity
Impact assessment
- EU AI Act Art. 27 Fundamental rights impact assessment for high-risk AI systems (core)
- ISO 42001 6.1.4 AI system impact assessment (core)
- ISO 42001 8.4 AI system impact assessment (operation) (core)
- ISO 42001 A.5 Assessing impacts of AI systems (core)
- NIST AI RMF MAP 3 MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs are understood (core)
- NIST AI RMF MAP 5 MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized (core)
- TC260 Framework 3.0 TC260 Appendix 1 Grading principles (core)
- China GenAI Measures GenAI Art. 17 Security assessment (core)
- GDPR Art. 35 Data protection impact assessment (core)
- ISO 42005 42005 5.8 Performing the AI system impact assessment (core) (clause not verified)
- ISO 42005 42005 6.8 Actual and reasonably foreseeable impacts (core) (clause not verified)
- CSA AICM GRC-10 AI Impact Assessment (core)
- UK ATRS ATRS 2.5.1 Impact assessments (core)
- EU AI Act Art. 9 Risk management system
- TC260 Framework 3.0 TC260 2.2 Safety risks in the application of AI
- GDPR Art. 36 Prior consultation
- ISO 42005 42005 5.12 Monitoring and review (clause not verified)
- CSA AICM DSP-09 Data Protection Impact Assessment
- CoE Convention CoE Art. 16 Risk and impact management framework
- GAO AI Accountability 1.5 Stakeholder involvement: include diverse perspectives from a community of stakeholders throughout the AI life cycle
Documentation and transparency
- EU AI Act Art. 11 Technical documentation (core)
- EU AI Act Art. 13 Transparency and provision of information to deployers (core)
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models (core)
- ISO 42001 7.5 Documented information (core)
- ISO 42001 A.6 AI system life cycle (core)
- ISO 42001 A.8 Information for interested parties (core)
- China AI Labelling Label Art. 4 Explicit labels for generated content (core)
- China AI Labelling Label Art. 5 Implicit (metadata) labels (core)
- China GenAI Measures GenAI Art. 12 Labelling of generated content (core)
- China Deep Synthesis DeepSyn Art. 16 Implicit technical labels (core)
- China Deep Synthesis DeepSyn Art. 17 Conspicuous labels for confusable content (core)
- GPAI Code Transparency 1.1 Drawing up and keeping up-to-date model documentation (core)
- GDPR Arts. 13–14 Information to be provided to the data subject (core)
- CSA AICM MDS-03 Model Documentation (core)
- UK ATRS ATRS Tier 1 Summary information (core)
- Singapore GenAI GenAI 3 Trusted Development and Deployment (core)
- CoE Convention CoE Art. 14(2) Documentation sufficient to contest decisions; complaint to authorities (core)
- OECD AI Principles OECD 1.3 Transparency and explainability (core)
- G7 Code G7 Action 3 Publicly report capabilities, limitations and domains of use (core)
- GAO AI Accountability 1.9 Transparency: enable external stakeholders to access information on the design, operation, and limitations of the AI system (core)
- GAO AI Accountability 3.5 Documentation: document the methods for assessment, performance metrics, and outcomes of the AI system (core)
- EU AI Act Art. 50 Transparency obligations for providers and deployers of certain AI systems
- NIST AI RMF MAP 1 MAP 1: Context is established and understood
- NIST AI RMF MEASURE 2.8 MEASURE 2.8: Risks associated with transparency and accountability are examined and documented
- China GenAI Measures GenAI Art. 19 Disclosure to regulators
- China Algo. Rec. AlgoRec Art. 16 Notice that recommendation is used
- GB/T 45654 GB/T 45654 Content labelling Generated-content labelling requirements (clause not verified)
- EU AI Act Art. 86 Right to explanation of individual decision-making
- EU AI Act Art. 18 Documentation keeping
- EU AI Act Art. 43 Conformity assessment
- EU AI Act Art. 53(1)(d) Public summary of the content used for training
- EU AI Act Art. 50(2), 50(4) Machine-readable marking of synthetic content; disclosure of deep fakes
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Art. 30 Records of processing activities
- NIST AI RMF MAP 1.6 MAP 1.6: System requirements are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks
- NIST AI RMF MEASURE 2.9 MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance
- CSA AICM MDS-04 Model Documentation Requirements
- UK ATRS ATRS 2.2 Description and rationale
- CoE Convention CoE Art. 15(2) Notification of interaction with an AI system
- GAO AI Accountability 1.7 Specifications: establish and document technical specifications
Inventory and registration
- EU AI Act Art. 49 Registration (core)
- EU AI Act Art. 71 EU database for high-risk AI systems (core)
- ISO 42001 A.4 Resources for AI systems (core)
- NIST AI RMF GOVERN 1.6 GOVERN 1.6: Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities (core)
- China Algo. Rec. AlgoRec Art. 24 Algorithm filing (core)
- China Deep Synthesis DeepSyn Art. 19 Filing for public-opinion services (core)
- China GenAI Measures GenAI Art. 17 Algorithm filing (core)
- UK ATRS ATRS Tier 1 Summary information (the published record) (core)
- EU AI Act Art. 6 Classification rules for high-risk AI systems
- TC260 Framework 3.0 TC260 App. 2 II.2 Identity and access management
- TC260 Framework 3.0 TC260 4.4.1 CII registration and filing
- EU AI Act Art. 3(1) Definition of an AI system
- EU AI Act Art. 52 Procedure
- NIST AI RMF GOVERN 1.7 GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness
- CSA AICM STA-08 Supply Chain Inventory
- CSA AICM IAM-03 Identity Inventory
- GAO AI Accountability 3.1 Documentation: catalog model and non-model components, along with operating specifications and parameters
Logging and traceability
- EU AI Act Art. 12 Record-keeping (core)
- ISO 42001 A.6 AI system life cycle (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Continuous monitoring and auditing (core)
- TC260 Framework 3.0 TC260 5.3.6 Logs kept and audited (core)
- EU AI Act Art. 26(6) Deployers keep the automatically generated logs (core)
- ISO 42001 A.6.2.8 AI system recording of event logs (core) (clause not verified)
- CSA AICM LOG-09 Log Records (core)
- OECD AI Principles OECD 1.5(b) Traceability of datasets, processes and decisions (core)
- prEN 18229-1 prEN 18229-1 AI trustworthiness framework, Part 1: logging (draft; supports Art. 12) (core) (clause not verified)
- GAO AI Accountability 4.3 Traceability: document results of monitoring activities and any corrective actions taken (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF MANAGE 4 MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored
- NIST AI RMF MEASURE 3 MEASURE 3: Mechanisms for tracking identified AI risks over time are in place
- China AI Labelling Label Art. 5 Implicit metadata labels
- EU AI Act Art. 19 Automatically generated logs
- CSA AICM LOG-12 Transaction/Activity Logging
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
Human oversight
- EU AI Act Art. 14 Human oversight (core)
- ISO 42001 A.9 Use of AI systems (core)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- TC260 Framework 3.0 TC260 App. 2 II.3 Strengthen human approval (core)
- GDPR Art. 22 Automated individual decision-making, including profiling (core)
- NIST AI RMF MAP 3.5 MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function (core)
- CSA AICM GRC-15 Human supervision (core)
- UK DUAA UK GDPR Art. 22C Safeguards for automated decision-making (core)
- UK ATRS ATRS 2.3.2 Human review (core)
- Singapore Agentic Agentic 2.2.2 Design for meaningful human oversight (core)
- GAO AI Accountability 3.9 Human supervision: define and develop procedures for human supervision of the AI system (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF GOVERN 3.2 GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
- China Algo. Rec. AlgoRec Art. 17 User option to switch off
- China GenAI Measures GenAI Art. 10 User guidance and protection
- EU AI Act Art. 14(4)(b) Awareness of automation bias
- OWASP Agentic ASI09 Human-Agent Trust Exploitation
- CoE Convention CoE Art. 8 Transparency and oversight
- OECD AI Principles OECD 1.2(b) Human agency and oversight safeguards
Robustness, security and evaluations
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk (core)
- ISO 42001 A.6 AI system life cycle (core)
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics (core)
- TC260 Framework 3.0 TC260 3 Technological countermeasures (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming (core)
- China Deep Synthesis DeepSyn Art. 15 Technology management and algorithm verification (core)
- China Deep Synthesis DeepSyn Art. 20 Security assessment of new products (core)
- GB/T 45654 GB/T 45654 Security assessment Security-assessment requirements for generative AI services (core) (clause not verified)
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations (core)
- NIST AI RMF MEASURE 2.7 MEASURE 2.7: AI system security and resilience as identified in the MAP function are evaluated and documented (core)
- CSA AICM MDS-06 Adversarial Attack Analysis (core)
- CSA AICM MDS-07 Robustness against Adversarial Attack / Model Hardening (core)
- Singapore GenAI GenAI 5 Testing and Assurance (core)
- Singapore GenAI GenAI 6 Security (core)
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents (core)
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified (core)
- OECD AI Principles OECD 1.4 Robustness, security and safety (core)
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing (core)
- GAO AI Accountability 3.7 Assessment: assess performance against defined metrics to ensure the AI system functions as intended and is sufficiently robust (core)
- EU AI Act Art. 60 Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes
- ISO 42001 9.1 Monitoring, measurement, analysis and evaluation
- TC260 Framework 3.0 TC260 5.3.14 Resilience
- China GenAI Measures GenAI Art. 17 Security assessment
- EU AI Act Art. 15(3) Declared accuracy levels and metrics
- EU AI Act Art. 9 Risk management system
- EU AI Act Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act)
- GPAI Code Safety C6 Commitment 6: Security mitigations
- GDPR Art. 32 Security of processing
- NIST AI RMF MEASURE 2.1 MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented
- NIST AI RMF MEASURE 1 MEASURE 1: Appropriate methods and metrics are identified and applied
- CSA AICM AIS-05 Application Security Testing
- OWASP LLM LLM01:2026 Prompt Injection
- OWASP Agentic ASI05 Unexpected Code Execution (RCE)
- GAO AI Accountability 3.2 Metrics: define performance metrics that are precise, consistent, and reproducible
Incident response and monitoring
- EU AI Act Art. 72 Post-market monitoring by providers and post-market monitoring plan (core)
- EU AI Act Art. 73 Reporting of serious incidents (core)
- ISO 42001 A.8 Information for interested parties (core)
- ISO 42001 10.2 Nonconformity and corrective action (core)
- NIST AI RMF MANAGE 4 MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored (core)
- TC260 Framework 3.0 TC260 5.3.7 Real-time risk monitoring (core)
- TC260 Framework 3.0 TC260 5.3.18 Incident reporting (core)
- China GenAI Measures GenAI Art. 14 Handle and report unlawful content (core)
- China GenAI Measures GenAI Art. 15 Complaint and reporting mechanism (core)
- EU AI Act Art. 26(5) Deployer monitoring, informing the provider and suspending use (core)
- GPAI Code Safety C9 Commitment 9: Serious incident reporting (core)
- GDPR Arts. 33–34 Notification and communication of a personal data breach (core)
- NIST AI RMF MANAGE 4.3 MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented (core)
- CSA AICM SEF-07 Incident Management and Response (core)
- CSA AICM SEF-08 Security Breach Notification (core)
- Singapore GenAI GenAI 4 Incident Reporting (core)
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test (core)
- G7 Code G7 Action 2 Identify and mitigate vulnerabilities, incidents and misuse after deployment (core)
- G7 Code G7 Action 4 Responsible information sharing and reporting of incidents (core)
- GAO AI Accountability 4.1 Planning: develop plans for continuous or routine monitoring of the AI system (core)
- GAO AI Accountability 4.2 Drift: establish the range of data and model drift that is acceptable (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk
- TC260 Framework 3.0 TC260 App. 2 II.6 Emergency plans
- China Algo. Rec. AlgoRec Art. 7 Security management and emergency response
- EU AI Act Art. 3(49) Definition of serious incident
- EU AI Act Art. 20 Corrective actions and duty of information
- GPAI Code Safety 3.5 Measure 3.5: Post-market monitoring
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use
- NIST AI RMF GOVERN 4.3 GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing
Explainability and right to explanation
- EU AI Act Art. 86 Right to explanation of individual decision-making (core)
- EU AI Act Art. 13(3)(b)(iv)–(v) Information relevant to explain output; performance for specific persons or groups (core)
- GDPR Art. 15(1)(h) Meaningful information about the logic involved (core)
- NIST AI RMF MEASURE 2.9 MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance (core)
- CSA AICM GRC-13 Explainability Requirement (core)
- CSA AICM GRC-14 Explainability Evaluation (core)
- UK DUAA UK GDPR Art. 22C Safeguards for automated decision-making (core)
- OECD AI Principles OECD 1.3 Transparency and explainability (core)
- GDPR Art. 13(2)(f) Existence of automated decision-making
- GDPR Art. 22(3) Right to obtain human intervention and to contest the decision
- ISO 42001 A.8.2 System documentation and information for users (clause not verified)
- NIST AI RMF MEASURE 2.8 MEASURE 2.8: Risks associated with transparency and accountability as identified in the MAP function are examined and documented
- UK ATRS ATRS 2.3.5 Appeals and review
- Singapore GenAI GenAI 3 Trusted Development and Deployment
- CoE Convention CoE Art. 14(2) Documentation sufficient to contest decisions; complaint to authorities
- China Algo. Rec. AlgoRec Art. 17 Explain where an algorithm significantly affects user rights
Conformity assessment and certification
- EU AI Act Art. 43 Conformity assessment (core)
- ISO 42006 ISO/IEC 42006 Requirements for bodies providing audit and certification of AI management systems (core)
- CSA AICM A&A-02 Independent Assessments (core)
- EU AI Act Art. 47 EU declaration of conformity
- EU AI Act Art. 48 CE marking
- EU AI Act Art. 40 Harmonised standards and standardisation deliverables
- GDPR Art. 42 Certification (clause not verified)
- ISO 42001 9.2 Internal audit (clause not verified)
- NIST AI RMF MEASURE 1.3 MEASURE 1.3: Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates
- CSA AICM A&A-04 Requirements Compliance
- Singapore GenAI GenAI 5 Testing and Assurance
- EN 18286 EN 18286 Quality management system for EU AI Act regulatory purposes
- China GenAI Measures GenAI Art. 17 Security assessment and algorithm filing
- GAO AI Accountability 1.8 Compliance: ensure the AI system complies with relevant laws, regulations, standards, and guidance
GPAI and foundation models
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models (core)
- EU AI Act Art. 55 Obligations of providers of general-purpose AI models with systemic risk (core)
- GPAI Code Transparency 1.1 Drawing up and keeping up-to-date model documentation (core)
- GPAI Code Safety C1 Commitment 1: Safety and Security Framework (core)
- EU AI Act Art. 51 Classification of general-purpose AI models as general-purpose AI models with systemic risk
- EU AI Act Art. 56 Codes of practice
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations
- GPAI Code Safety C7 Commitment 7: Safety and Security Model Reports
- CSA AICM MDS-12 Open Model Risk Assessment
- CSA AICM MDS-03 Model Documentation
- Singapore GenAI GenAI 8 Safety and Alignment R&D
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing
- China GenAI Measures GenAI Art. 7 Lawful data and foundation-model sources
Content provenance and deepfakes
- EU AI Act Art. 50(2) Machine-readable marking of synthetic content (core)
- EU AI Act Art. 50(4) Disclosure of deep fakes (core)
- Singapore GenAI GenAI 7 Content Provenance (core)
- G7 Code G7 Action 7 Deploy content authentication and provenance mechanisms where feasible (core)
- China AI Labelling Label Art. 4 Explicit labels for generated content (core)
- China AI Labelling Label Art. 5 Implicit (metadata) labels (core)
- China Deep Synthesis DeepSyn Art. 17 Conspicuous labels for confusable content (core)
- EU AI Act Art. 3(60) Definition of deep fake
- CSA AICM MDS-09 Model Signing/Ownership Verification
- OWASP LLM LLM07:2026 Misinformation
- China GenAI Measures GenAI Art. 12 Labelling of generated content
Source
Chapter 08, section Other jurisdictions, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-kr-aibasic.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). South Korea AI Basic Act (in force 2026-01-22) (AIGE-OBL-KR-AIBASIC). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-kr-aibasic. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{South Korea AI Basic Act (in force 2026-01-22) (AIGE-OBL-KR-AIBASIC)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-kr-aibasic},
note = {Version 0.5.0}
}