By Dr. Freddie Seba © 2026 Freddie Seba. All rights reserved.
South Korea passed the world’s second comprehensive AI law while navigating a constitutional crisis. Governance does not wait for perfect conditions. Neither should your institution.
What the world’s second comprehensive AI law governs — and what it leaves to your institution Applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI Oversight
Governance as Leadership The organizations that govern AI intentionally will lead. The ones that don’t will follow the consequences.
This series is not about compliance. It is about leadership. Every framework examined here surfaces the same question: not whether your institution is following the rules — but whether your leaders are governing the most consequential technological transformation of our time. Ungoverned: Applied Frameworks Under the Lens exists for leaders who understand the difference.
Previous analysis in this miniseries: Anthropic, OpenAI, Google Gemini, NIST-CAISI, EU AI Act, China, Singapore. This week: South Korea. Coming next: Canada, UK, Japan.
Constructive analysis — three questions, every installment, without exception.
Why this series — and why these frameworks
This series does not examine every AI governance framework that exists. It examines the frameworks that together reveal the full shape of the governance challenge — and the full scope of what institutional leadership must build in response.
The selection logic is deliberate. It begins with the AI labs — Anthropic, OpenAI, Google — because that is where most institutions first encountered the governance gap: in the terms of service of tools already embedded in their workflows. It moves to U.S. federal bodies — NIST-CAISI — because understanding the voluntary, underfunded, and pending-authorization nature of federal AI standards is essential context for every institution that assumed federal governance was someone else’s responsibility.
It then moves outward — to the EU AI Act, China, Singapore, South Korea, and beyond — because AI governance is not a Western conversation, and leaders who govern only within the frameworks they already know will be ungoverned by the ones they do not. South Korea is in this series because it became the first Asia-Pacific nation with comprehensive AI legislation — passed with bipartisan support during a constitutional crisis — and its extraterritorial reach means it may already apply to institutions that have never considered Korean compliance.
The frameworks explored in this series are not the only ones that matter. They are the ones that, examined together, reveal the pattern. The framework governs the platform, the standard, the model, or the market. Only the institution governs the consequences. That pattern is what this series is for.
This is a living series. Frameworks are added as the global AI governance landscape evolves — and it is evolving faster than any publication schedule can fully anticipate.
Series roadmap — a living intellectual agenda
This roadmap reflects the series as currently envisioned. New frameworks will be added as countries, standards bodies, and sector organizations publish governance guidance. The sequence may evolve. The three questions never will.
Tier 1 — AI Labs The governance gap begins here — in the terms of service, privacy policies, and platform decisions of the tools already embedded in institutional workflows.
- Anthropic — United States
- OpenAI — United States
- Google Gemini — United States
Tier 2 — Government & Standards Bodies Federal and national frameworks that shape institutional expectations — and the gaps those frameworks deliberately or structurally leave ungoverned. 4. U.S. NIST-CAISI — United States
Tier 3 — Binding Regulatory Frameworks The binding laws and regulations that define legal compliance floors — and the institutional governance required to meet them. 7. EU AI Act — Europe 8. China AI Safety Governance Framework 2.0 — China 9. Singapore Agentic AI Framework — Asia-Pacific 10. South Korea AI Basic Act — Asia-
Tier 4 — International Standards & Multilateral Bodies The frameworks that aspire to global consensus — and the institutional gaps that consensus cannot close.
Tier 5 — Sector & Vertical Frameworks Where global frameworks meet institutional reality — in education, financial services, and emerging economies.
Tier 6 — Series Synthesis What the frameworks — examined together — leave ungoverned. And what leadership must build in the space they leave behind.Series Synthesis: What the Frameworks Don’t Say
An ongoing series. Full roadmap and all published editions at freddieseba.com New frameworks added as the global AI governance landscape evolves.
Question One — What was the framework designed to govern?
South Korea’s Act on the Development of Artificial Intelligence and Establishment of Trust — formally known as the AI Basic Act — took full legal effect on January 22, 2026, along with its Enforcement Decree. It is the world’s second comprehensive AI law after the EU AI Act and the first in the Asia-Pacific region.
The Act’s passage is itself a governance story worth telling. It consolidated 19 separate AI governance bills — which had been circulating through South Korea’s National Assembly for years — into a single unified framework. It passed the plenary session on December 26, 2024, with overwhelming bipartisan support. That legislative achievement is notable not only for its substance but for its context: it was passed during the constitutional crisis surrounding President Yoon Suk Yeol’s declaration of martial law and subsequent impeachment. South Korea’s AI governance did not wait for political stability. It was built through uncertainty — which is precisely the leadership lesson this edition surfaces for institutional leaders who believe their own organizational complexity is a reason to defer governance.
The Act is governed by the Ministry of Science and ICT, operating under a National AI Committee established under the President’s Office. A dedicated AI Safety Research Institute evaluates advanced AI models, develops safety benchmarks, and addresses emerging risks.
The Act establishes a risk-based governance architecture organized around three tiers. High-impact AI systems — including AI used in healthcare, public services, education, and legal and financial decisions affecting individuals — carry specific obligations for safety, transparency, explainability, and human oversight. Generative AI systems must disclose AI use upfront and label AI-generated content. Large-scale advanced AI systems — defined as those trained with cumulative compute exceeding 10²⁶ FLOPs — face the most demanding obligations including risk identification, assessment, mitigation, and risk management plans.
The Act applies extraterritorially. It governs all organizations providing AI products or services to Korean users regardless of where they are established. Foreign AI operators serving Korean users must designate a Korean domestic representative. A one-year grace period for administrative fines runs through January 2027 — but the substantive compliance obligations apply from January 22, 2026.
Comprehensively. Extraterritorially. With bipartisan legislative backing that survived a constitutional crisis.
Question Two — The Governance Gap: what falls outside the frame, and where leadership begins?
Institutional performance governance.
South Korea’s AI Basic Act defines with precision what trustworthy, safe, and transparent AI performance must look like for high-impact systems. It requires risk management plans, explainability measures, user safeguards, human oversight, documentation, and recordkeeping. What it cannot do — and was not designed to do — is build the internal governance systems your institution needs to meet those standards in practice, demonstrate compliance during the grace period, or respond to enforcement when the grace period ends in January 2027.
The governance gap is particularly acute for foreign institutions operating in or serving South Korean users. The Act’s extraterritorial reach means that a U.S. hospital system whose AI tools are used by Korean patients, a university whose learning platform serves Korean students, or a corporation whose AI-assisted decisions affect Korean employees — all may be inside the scope of this regulation. Foreign operators without a Korean address or business office must review the domestic representative requirement before deployment.
Consider the questions the Act raises that only institutional governance can answer. Has your institution determined whether your AI systems qualify as high-impact under the Act’s defined categories? If so, who owns the risk management plan, the explainability documentation, and the human oversight assignment? Who monitors AI system performance against the trustworthiness and safety standards the Act requires — not at deployment, but on an ongoing basis? Who maintains the documentation that demonstrates compliance before the grace period ends in January 2027? Who is your designated Korean domestic representative if your institution provides AI services to Korean users without a Korean address?
The Act defines the performance standard. Leadership governance builds the institutional capability to meet it — and to demonstrate that it has.
Question Three — What does governance as leadership look like before deployment?
This is where AI Minimum Viable Governance (AI-MVG) begins. Not after a corrective order — before the grace period ends in January 2027, when the institution still has time to build governance with intention rather than urgency. This is not a compliance checklist. It is a leadership architecture.
High-impact AI classification — determine whether your institution’s AI systems qualify as high-impact under the Act’s defined categories in healthcare, public services, education, and individual-affecting decisions Performance monitoring — establish ongoing monitoring of AI system performance against the Act’s trustworthiness and safety standards Explainability documentation — build and maintain documentation demonstrating how each high-impact AI system reaches its outputs Human oversight assignment — name the responsible human for each AI-assisted decision category and define their authority to intervene Generative AI disclosure — implement user notification and AI-generated content labeling for all generative AI systems serving Korean users Domestic representative designation — if your institution serves Korean users without a Korean address, designate a Korean domestic representative before enforcement begins Grace period utilization — use the one-year grace period to build governance, not to defer it Executive accountability — assign a named leader responsible for South Korea AI Basic Act compliance outcomes
This week’s 12 Ps lens: Preparedness
Preparedness — the eleventh P — means your institution has the leadership competence and governance cadence to meet the Act’s obligations before the grace period ends. It means the risk management system is documented before the auditor arrives. It means the explainability measures are built before a regulator asks for them. It means the domestic representative is designated before enforcement begins. Leadership governance means building that preparedness into your institution before the standard demands it — not scrambling to respond after it does.
Problems — Has your institution defined which decision problems your high-impact AI systems are actually solving — and whether those problems fall within the Act’s defined high-impact categories?
Profits — Who benefits from your institution’s AI deployment in Korean markets, and who bears the risk when a high-impact system produces an unexpected outcome?
People — The Act requires human oversight for high-impact AI. Your institution must name the responsible person at each stage — not just the category.
Planet — Large-scale advanced AI systems carry infrastructure and energy implications your institution should assess, particularly for systems approaching the Act’s compute thresholds.
Process — Risk management systems, impact assessments, and documentation processes are all required. Your institution must build and own each required process before the grace period ends.
Policy — The Act’s grace period emphasizes guidance over enforcement — for now. Your institution must translate the Act’s requirements into internal policy with named owners and review cadences before January 2027.
Protections — High-impact AI systems require user safeguards and protections for vulnerable groups. Your institution must implement these before the grace period ends and enforcement begins.
Privacy — The Personal Information Protection Act applies concurrently. Your institution must map the overlap between AI Basic Act obligations and PIPA requirements for any AI system processing Korean user data.
Provenance — The Act requires documentation and record-keeping for high-impact AI systems. Your institution must build and maintain the evidence-based audit trail that demonstrates compliance.
Preparedness — This is the governance gap. The grace period ends January 2027. Your institution must build leadership competence and governance cadence now — not when enforcement begins.
Product Ownership — The Act establishes obligations but does not assign internal institutional accountability for outcomes. Who owns the decision — and the consequences — when high-impact AI in your institution produces an unexpected outcome for a Korean user?
South Korea’s AI Basic Act governs what trustworthy AI performance must look like in one of the world’s most sophisticated technology markets. Institutional leadership governance governs whether your organization has built the systems to deliver — and demonstrate — that performance. One defines the standard. The other builds the capability. That is the foundation of AI Minimum Viable Governance — and with the grace period running through January 2027, the governance clock is already moving.
For executive briefings, board workshops, and keynote presentations → freddieseba.com
About the Author
Dr. Freddie Seba helps boards, trustees, and executive leadership teams build practical AI governance before AI failures make governance unavoidable. Scholar-operator, Silicon Valley founder, and global executive — EdD, USF · MBA, Yale · MA, Stanford.
This analysis is part of Ungoverned: Applied Frameworks Under the Lens, a recurring miniseries applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI Oversight to organizations shaping AI governance globally — including AI labs, governments, standards bodies, and international actors across the United States, Europe, Asia-Pacific, the Gulf, Latin America, and beyond. Drafted with AI-assisted tools. Final editorial judgment and responsibility remain with the author.
This analysis is for informational and educational purposes only. It does not constitute legal, regulatory, or compliance advice. Institutions should consult qualified legal counsel regarding their specific obligations under applicable frameworks.
© 2026 Freddie Seba. All rights reserved.
References
South Korea National Assembly. (2025, January 21). Act on the Development of Artificial Intelligence and Establishment of Trust (Act No. 20676). https://cset.georgetown.edu/publication/south-korea-ai-law-2025/
Library of Congress. (2026, February 20). South Korea: Comprehensive AI legal framework takes effect. https://www.loc.gov/item/global-legal-monitor/2026-02-20/south-korea-comprehensive-ai-legal-framework-takes-effect/
IAPP. (2025, August 27). Global AI governance law and policy: South Korea. https://iapp.org/resources/article/global-ai-governance-south-korea/
SafeAI for Business. (2026, June 3). South Korea AI Basic Act: What foreign companies must know in 2026. https://safeaiforbusiness.com/south-korea-ai-basic-act/
U.S. International Trade Administration. (2026, May 29). South Korea AI Basic Act. https://www.trade.gov/market-intelligence/south-korea-ai-basic-act
Future of Privacy Forum. (2025, April 18). South Korea’s new AI Framework Act: A balancing act between innovation and regulation. https://fpf.org/blog/south-koreas-new-ai-framework-act-a-balancing-act-between-innovation-and-regulation/
Drafted with AI-assisted tools. Final editorial judgment and responsibility remain with the author.
#AIGovernance #SouthKoreaAI #AIMVG #AILeadership #Ungoverned #BoardGovernance #AIPolicy #CIO #AsiaPacific #GlobalAIGovernance
