
The Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation of Trust, or the AI Framework Act for short, came into force on the 22nd. This is the first time a comprehensive statute covering artificial intelligence as a whole in a single law has taken full effect at the national level. Yet six days into implementation, the work of complying with the regulation has been pushed back at companies. What is underway is the interpretive work of determining which box of this law a given service falls into.
The law builds its regulation around the axes of transparency, high impact, and safety. Transparency means disclosing what is AI, and high impact means managing more heavily the AI that significantly affects people's lives. But the law was switched on with the first two axes left without boundary lines drawn. The criteria for identifying high-impact AI and the detailed obligation items have not been prepared, and the scope of "external distribution," which divides the labeling duty for generated output, along with the application standards based on how each service implements its screen, has been left to guidelines.
High-impact AI is defined as systems that intervene in decisions governing the conditions of life, such as citizens' rights and obligations, livelihoods, and credit ratings. Falling under this category requires establishing risk management measures, preparing to explain an overview of training data and how the algorithm works, and putting in place user protection measures and a system in which people directly manage and supervise. In the financial sector, systems such as banks' internal credit scoring models, automated loan screening and limit calculation, and fraud detection systems (FDS) are mentioned as candidates. What procedure applies and who attaches this label have not been settled.
On the labeling duty side, there is comparatively more of a picture. The Guidelines on Securing Artificial Intelligence Transparency, released on the 21st, a day before implementation, divide transparency into advance notice that high-impact or generative AI is being used and the duty to indicate that a result was produced by AI. If the output is used only within the service, looser methods such as on-screen notices or logo displays are allowed. Chatbots may substitute a notice before the conversation begins or a logo on the screen, and games and metaverses may use a notice at login or a character marking.
When the output goes outside, the required level rises. In situations involving export, download, or sharing, a watermark that people can detect with their eyes or ears must be attached, or machine-readable metadata must be embedded after notice is given through text or audio. Generated output that is hard to distinguish from the real thing, such as deepfakes, must use a method that people can clearly recognize. The problem is that in services where output moves through SaaS and APIs, the yardstick for judging where "outside" begins is blurry.
The scope of who bears the obligations also reads two ways. The transparency obligation is described as limited to businesses that directly provide AI products and services to users, but the text of the law includes, in addition to those who develop and provide AI, the user businesses that take AI and build services with it. For a company that sells services built on someone else's model, this difference is not trivial. The point at which preparation must begin and the scale of the budget change entirely.

The survey results on the state of preparation are not good. In a full survey of 118 financial companies in April last year, only 5 banks, 4 insurers, and 1 securities firm had a decision-making body for AI. About 85% of those surveyed had not established AI ethics principles or risk management standards. Another survey found that the share of companies that said they had completed preparations for the AI Framework Act stood at 2%.
Regulations to comply with are stacked in layers in the financial sector. The AI Framework Act has been added as one more layer on top of the Electronic Financial Transactions Act and its supervisory regulations, information protection rules including network separation, the Personal Information Protection Act and the Credit Information Act, internal control and consumer protection rules, and the AI guidelines for the financial sector. Yet no financial ministry is included in the law's control tower. What snags here is who coordinates the circumstances specific to finance, and at which desk.
The government has said it will postpone enforcement such as the exercise of investigative powers and the imposition of fines for at least a year, saying it will reduce confusion in the early stage of implementation. This year is a grace period given to companies and at the same time a deadline by which the government must fill in the standards. The Minister of Science and ICT must establish an AI master plan every three years, and the National Artificial Intelligence Strategy Committee is elevated to a statutory committee. The skeleton of the system has been erected, and the flesh will be added through enforcement decrees and public notices.
The reason for making the law was clear in itself. The provision of the Telecommunications Business Act prohibiting harm to user interests made it difficult to capture the discrimination that algorithms produce, and the Network Act, framed on the premise that information is distributed and disclosed, made it difficult to address the situation in which AI newly creates information. For a law made to fill gaps not to end up leaving gaps again, judgment criteria and borderline cases must appear in documents during the time that remains.
If this law runs properly, the changes users experience are modest and concrete. When they open a consultation screen, they will know from the first line whether the other party is a person, a downloaded image will carry a mark saying it was generated, and when a loan is denied there will be a channel to ask what factored into that decision. Right now all three are in preparation. Over the next year, as the time companies spend with lawyers decreases, what users can check on their screens increases.
