브레스저널 The Breath Journal

This article was translated automatically from the Korean original. Read the original in Korean

World's First AI Framework Act, a Month of Confusion

곽동현·Published 2026-02-25 15:36 KST
The boundary of high-impact AI is blurred, and the field is putting off decisions
The boundary of high-impact AI is blurred, and the field is putting off decisions
The boundary of high-impact AI is blurred, and the field is putting off decisions / ⓒ Breath Journal

The Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust (AI Framework Act) took full effect on Jan. 22, and more than a month has passed. Unlike individual laws that regulate particular industries separately, it is an overarching law covering AI as a whole, so it applies first when other laws contain no special provisions. It was the second such law to be enacted, but it is regarded as the world's first to take full effect. Yet a month after enforcement began, the response on the ground is closer to a halt than to order.

At the center is the concept of "high-impact AI." The law defines high-impact AI as AI whose results have a significant effect on the safety of human life and body or on the enjoyment of fundamental rights, or risk causing harm. The government is understood to have designated 10 fields that fall under this, and medical care and public health, energy, hiring and loan screening are cited as leading examples. Once classified as high-impact, an operator must have risk management measures, measures for explaining results and measures for protecting users.

The problem is the line dividing what counts as high-impact. Even after the law took effect, the scope of application has not been closely sorted out at the level of the provisions, and both academia and industry have said that authoritative interpretations and discussion of additional legislation are needed. When the criteria are blurred, companies choose one of two things. They raise costs through excessive compliance, or they push the decision back.

The medical field felt that blurriness fastest. The AI Research Center at Samsung Medical Center held a seminar on the reorganization of laws and institutions in the era of medical AI on the 23rd and discussed calls to clarify the criteria for classifying high-impact AI. In hospitals, generative AI is used for administrative support such as writing medical records or organizing documents more than for diagnosis, and no yardstick has been set for whether this area, too, should be treated as high-impact. Whether work that does not directly touch patient safety will be bound into the scope of regulation determines hospitals' adoption decisions outright.

There are also points where regulations apply in duplicate. If medical AI falls under medical devices, it must be certified by the Ministry of Food and Drug Safety, and if it is at the same time high-impact AI, obligations under the Ministry of Science and ICT may also apply. Kim Jae-sun, a professor at Dongguk University's Law School, pointed to this possibility of dual application. How far the documents and procedures required by the two sets of regulations can stand in for each other has yet to be sorted out.

What users will notice is somewhat clearer. Products and services that use generative AI must inform users in advance that they run on AI, and a labeling obligation attaches to the output. A measure requiring a visible watermark is also said to be included. Explanations differ over the form and strength of the labeling, leaving developers unable to settle on how to implement it in practice.

The government describes the law as a balanced bill of "70 percent promotion, 30 percent regulation." The law does contain fostering provisions such as AI research and development, the building of training data, support for adoption and the securing of specialists. An AI Framework Act support desk that fields questions about the law is also in operation. However thick the promotion provisions may be, if the boundary of the 30 percent on the regulatory side is blurred, companies move by that 30 percent.

Developments abroad are also worth noting. The EU enacted its AI Act ahead of Korea but shifted toward delaying the timing of enforcement, citing protection of its own industry. Korea, by contrast, moved straight into full enforcement, and in return is finding the gaps in its institutional design in real time.

In Korea, "OpenClaw," a tool that helps AI control a user's computer as a whole, was blocked by Naver and Kakao over security concerns. Each time a new form of AI appears, which box to place it in has to be weighed all over again.

Worse than having no rules is having rules and not knowing how far they apply. For as long as it takes a hospital staffer to ask the legal team about a single program that organizes medical records, and the legal team to ask the ministry in turn, change in the consultation room the patient sees is delayed. Depending on how quickly the boundary is redrawn, this law may become a foundation of trust or a reason to put decisions off.

By Kwak Dong-hyun · Breath.Tech

Related articles

댓글