Korea’s AI Basic Act Six Months On: Disclosure and Labeling Duties for Generative AI Businesses
Korea’s AI Basic Act took effect on January 22, 2026.
Under the Act, businesses that provide generative AI products or services are subject to transparency obligations. Compliance, however, does not end with adding a notice to a service screen.
The applicable legal risks depend on the AI model used, the information entered by users, where that information is transferred, and how the generated output is used.
Advance Disclosure and Output Labeling Are Separate Obligations
Article 31 of the AI Basic Act divides transparency obligations into two categories.
First, an AI business operator intending to provide a product or service based on generative AI must inform users of that fact in advance.
Second, when generative AI or an AI-powered service produces content, the business must indicate that the output was generated using AI.
For example, a chatbot or AI document-generation service may need to disclose its use of generative AI through its terms of service or user interface before the service is used.
Separately, text, images, audio, or video generated by the service may require an AI-generated content label. Synthetic audio, images, and video that could easily be mistaken for real content require particularly clear disclosure.
In practical terms:
Before use: disclose that the product or service uses generative AI.
After generation: indicate that the resulting content was generated using AI.
AI-Generated Content Does Not Always Require a Visible Watermark
The required label does not necessarily have to be a visible watermark.
The Enforcement Decree permits both:
▪️ Human-readable labeling
▪️ Machine-readable labeling
Where only a machine-readable method is used, users must still be informed at least once, through text, audio, or another accessible method, that the content was generated using AI.
All or part of the disclosure and labeling requirements may not apply where:
▪️ The service name or interface already makes the use of AI obvious
▪️ The AI is used exclusively for the operator’s internal business purposes
▪️ A separately issued government notice recognizes an exception
The internal-use exception should be applied carefully.
Materials initially generated for internal use may fall outside the exception once they are included in advertisements, customer reports, consultation materials, or other externally distributed content.
Businesses should therefore distinguish between outputs that remain within the service and outputs that can be downloaded, shared, or provided to customers.
Businesses Using External AI APIs May Also Be Covered
A business does not need to develop its own AI model to fall within the scope of the AI Basic Act.
The Act also covers businesses that use AI developed by another provider to offer AI products or services.
A company may therefore qualify as an AI business operator where it connects an external large language model through an API and provides services such as:
▪️ AI chatbots
▪️ Image-generation tools
▪️ Document drafting or summarization
▪️ Automated customer consultation
The key question is not who developed the underlying model.
What matters is whether the company uses AI to provide a product or service to users. Businesses using third-party APIs should therefore review whether they are subject to advance disclosure and AI-output labeling obligations.
Disclosure Compliance Is Only One Part of the Legal Review
Generative AI services commonly send user inputs to an external AI model and return generated outputs to the user.
This process may raise data protection and copyright issues that are legally separate from the labeling requirements under the AI Basic Act.
1. Personal Data Entered into AI Services
Where customers or employees enter names, consultation records, contracts, photographs, or internal documents into an external AI service, the business should verify:
▪️ Whether input data is stored or used for model training
▪️ The location and country of the servers processing the data
▪️ Applicable retention periods and deletion procedures
▪️ Whether the arrangement constitutes outsourcing, third-party provision, or overseas transfer
▪️ Whether the data is retransmitted to plug-ins or other external services
The legal classification should be based on the actual data flow rather than the name of the agreement with the AI provider.
A privacy policy should accurately reflect how personal data is collected, transferred, retained, and deleted throughout the AI service structure.
2. Copyright in AI-Generated Outputs
A business does not automatically acquire exclusive copyright merely because an image, document, video, or source code was generated using AI.
Relevant considerations include:
▪️ The degree of human creative involvement
▪️ Whether the source materials were lawfully used
▪️ Whether the AI provider’s terms permit commercial use
▪️ Whether the output is substantially similar to existing protected works
AI-generated content may also infringe third-party copyrights, image rights, or other intellectual property rights.
Businesses using generated outputs for advertising, websites, software, games, or commercial publications should retain records of the model used, prompts, initial outputs, and subsequent human edits.
AI Used to Evaluate Individuals May Qualify as High-Impact AI
Not every generative AI service is classified as high-impact AI.
However, additional review may be required where AI is used beyond basic drafting or guidance and affects a person’s rights, opportunities, or access to essential services.
Relevant examples include AI used in:
▪️ Recruitment and applicant evaluation
▪️ Lending, credit scoring, and insurance assessment
▪️ Medical diagnosis or treatment-related decision-making
▪️ Student admission, selection, or performance evaluation
For instance, an AI tool that summarizes a résumé may present a different level of legal risk from one that calculates an applicant’s probability of being hired.
The assessment depends on how the AI output is used in the actual decision-making process.
Where a system qualifies as high-impact AI, the operator may need to implement:
▪️ Risk-management measures
▪️ Procedures for explaining major decision-making criteria
▪️ User-protection procedures
▪️ Human management and oversight
▪️ Preparation and retention of relevant records
Documents to Review Before Launching a Generative AI Service
Legal review should not begin by drafting a disclaimer in isolation.
A business should first map:
▪️ The AI model being used
▪️ The information entered by users
▪️ The data-transfer route
▪️ How generated outputs are used
▪️ Where human review takes place
The following documents should then be aligned with the actual service structure.
AI Disclosure and Labeling Notices
Separate advance disclosure before use from labeling of generated outputs.
Terms of Service
Define the permitted use of AI outputs and procedures for handling errors, rights infringement, and user complaints.
Privacy Policy
Reflect the actual collection, processing, storage, overseas transfer, and deletion of personal data involving external AI providers.
AI Supply Agreements and API Terms
Review provisions concerning data use, cybersecurity incidents, intellectual property, service interruptions, and liability allocation.
Internal AI Use Policy
Establish restrictions and approval procedures for entering customer data, contracts, source code, and confidential business information into AI tools.
Legal Review Based on the Actual AI Service Structure
Under Korea’s AI Basic Act, generative AI transparency obligations are divided into advance disclosure before use and labeling of AI-generated outputs.
In practice, however, legal risk extends beyond how a notice is displayed.
Businesses should also review the use of external AI models, personal data processing and overseas transfers, rights in generated content, potential classification as high-impact AI, and the allocation of liability with AI vendors.
Decent Law Firm’s Corporate Practice Group advises AI and technology companies based on their actual service functions and data flows. Our review covers the applicability of the AI Basic Act, disclosure and labeling design, privacy and copyright issues, external AI model agreements, and the legal documentation required for launching and operating AI services in Korea.
This content is provided for general informational purposes only and does not constitute legal advice for any individual matter.