We Resolve Legal Matters
How can we assist you?
Blogs
More-
Korea’s AI Basic Act Six Months On: Disclosure and Labeling Duties for Generative AI Businesses
Korea’s AI Basic Act took effect on January 22, 2026. Under the Act, businesses that provide generative AI products or services are subject to transparency obligations. Compliance, however, does not end with adding a notice to a service screen. The applicable legal risks depend on the AI model used, the information entered by users, where that information is transferred, and how the generated output is used. Advance Disclosure and Output Labeling Are Separate Obligations Article 31 of the AI Basic Act divides transparency obligations into two categories. First, an AI business operator intending to provide a product or service based on generative AI must inform users of that fact in advance. Second, when generative AI or an AI-powered service produces content, the business must indicate that the output was generated using AI. For example, a chatbot or AI document-generation service may need to disclose its use of generative AI through its terms of service or user interface before the service is used. Separately, text, images, audio, or video generated by the service may require an AI-generated content label. Synthetic audio, images, and video that could easily be mistaken for real content require particularly clear disclosure. In practical terms: Before use: disclose that the product or service uses generative AI. After generation: indicate that the resulting content was generated using AI. AI-Generated Content Does Not Always Require a Visible Watermark The required label does not necessarily have to be a visible watermark. The Enforcement Decree permits both: ▪️ Human-readable labeling ▪️ Machine-readable labeling Where only a machine-readable method is used, users must still be informed at least once, through text, audio, or another accessible method, that the content was generated using AI. All or part of the disclosure and labeling requirements may not apply where: ▪️ The service name or interface already makes the use of AI obvious ▪️ The AI is used exclusively for the operator’s internal business purposes ▪️ A separately issued government notice recognizes an exception The internal-use exception should be applied carefully. Materials initially generated for internal use may fall outside the exception once they are included in advertisements, customer reports, consultation materials, or other externally distributed content. Businesses should therefore distinguish between outputs that remain within the service and outputs that can be downloaded, shared, or provided to customers. Businesses Using External AI APIs May Also Be Covered A business does not need to develop its own AI model to fall within the scope of the AI Basic Act. The Act also covers businesses that use AI developed by another provider to offer AI products or services. A company may therefore qualify as an AI business operator where it connects an external large language model through an API and provides services such as: ▪️ AI chatbots ▪️ Image-generation tools ▪️ Document drafting or summarization ▪️ Automated customer consultation The key question is not who developed the underlying model. What matters is whether the company uses AI to provide a product or service to users. Businesses using third-party APIs should therefore review whether they are subject to advance disclosure and AI-output labeling obligations. Disclosure Compliance Is Only One Part of the Legal Review Generative AI services commonly send user inputs to an external AI model and return generated outputs to the user. This process may raise data protection and copyright issues that are legally separate from the labeling requirements under the AI Basic Act. 1. Personal Data Entered into AI Services Where customers or employees enter names, consultation records, contracts, photographs, or internal documents into an external AI service, the business should verify: ▪️ Whether input data is stored or used for model training ▪️ The location and country of the servers processing the data ▪️ Applicable retention periods and deletion procedures ▪️ Whether the arrangement constitutes outsourcing, third-party provision, or overseas transfer ▪️ Whether the data is retransmitted to plug-ins or other external services The legal classification should be based on the actual data flow rather than the name of the agreement with the AI provider. A privacy policy should accurately reflect how personal data is collected, transferred, retained, and deleted throughout the AI service structure. 2. Copyright in AI-Generated Outputs A business does not automatically acquire exclusive copyright merely because an image, document, video, or source code was generated using AI. Relevant considerations include: ▪️ The degree of human creative involvement ▪️ Whether the source materials were lawfully used ▪️ Whether the AI provider’s terms permit commercial use ▪️ Whether the output is substantially similar to existing protected works AI-generated content may also infringe third-party copyrights, image rights, or other intellectual property rights. Businesses using generated outputs for advertising, websites, software, games, or commercial publications should retain records of the model used, prompts, initial outputs, and subsequent human edits. AI Used to Evaluate Individuals May Qualify as High-Impact AI Not every generative AI service is classified as high-impact AI. However, additional review may be required where AI is used beyond basic drafting or guidance and affects a person’s rights, opportunities, or access to essential services. Relevant examples include AI used in: ▪️ Recruitment and applicant evaluation ▪️ Lending, credit scoring, and insurance assessment ▪️ Medical diagnosis or treatment-related decision-making ▪️ Student admission, selection, or performance evaluation For instance, an AI tool that summarizes a résumé may present a different level of legal risk from one that calculates an applicant’s probability of being hired. The assessment depends on how the AI output is used in the actual decision-making process. Where a system qualifies as high-impact AI, the operator may need to implement: ▪️ Risk-management measures ▪️ Procedures for explaining major decision-making criteria ▪️ User-protection procedures ▪️ Human management and oversight ▪️ Preparation and retention of relevant records Documents to Review Before Launching a Generative AI Service Legal review should not begin by drafting a disclaimer in isolation. A business should first map: ▪️ The AI model being used ▪️ The information entered by users ▪️ The data-transfer route ▪️ How generated outputs are used ▪️ Where human review takes place The following documents should then be aligned with the actual service structure. AI Disclosure and Labeling Notices Separate advance disclosure before use from labeling of generated outputs. Terms of Service Define the permitted use of AI outputs and procedures for handling errors, rights infringement, and user complaints. Privacy Policy Reflect the actual collection, processing, storage, overseas transfer, and deletion of personal data involving external AI providers. AI Supply Agreements and API Terms Review provisions concerning data use, cybersecurity incidents, intellectual property, service interruptions, and liability allocation. Internal AI Use Policy Establish restrictions and approval procedures for entering customer data, contracts, source code, and confidential business information into AI tools. Legal Review Based on the Actual AI Service Structure Under Korea’s AI Basic Act, generative AI transparency obligations are divided into advance disclosure before use and labeling of AI-generated outputs. In practice, however, legal risk extends beyond how a notice is displayed. Businesses should also review the use of external AI models, personal data processing and overseas transfers, rights in generated content, potential classification as high-impact AI, and the allocation of liability with AI vendors. Decent Law Firm’s Corporate Practice Group advises AI and technology companies based on their actual service functions and data flows. Our review covers the applicability of the AI Basic Act, disclosure and labeling design, privacy and copyright issues, external AI model agreements, and the legal documentation required for launching and operating AI services in Korea. This content is provided for general informational purposes only and does not constitute legal advice for any individual matter.
-
Why AI Startups in Korea Need IT Legal Counsel
Before you build, make sure your service is structured to survive legally — not just technically. The Best Time for Legal Advice Is Before You Launch Getting an AI model up and running, connecting APIs, and opening a beta service can happen surprisingly fast. But building a service that is legally sustainable — one that properly addresses data use, privacy, copyright, and liability — is an entirely different challenge. Legal counsel is most effective not after development, but at the service planning and data architecture stage. A last-minute terms review before launch is a patch, not a solution. The following questions need to be answered before you write a single line of code. What data can you legally collect, store, and use for training? Is it legally safe to use customer data for model fine-tuning? Who owns the copyright to AI-generated outputs, and who is liable when things go wrong? Building a service without addressing these questions means going to market with structural vulnerabilities already baked in. 3 Regulatory Risks Every AI Startup in Korea Must Address As of 2026, the regulatory environment for AI startups operating in Korea has crystallized around three key areas. First, Korea's AI Basic Act is now in effect, introducing formal requirements around explainability, safety, and accountability for AI services. Second, the Personal Information Protection Commission has introduced punitive fines and class action mechanisms, making data incidents an existential risk rather than a compliance footnote. Third, when your infrastructure combines third-party AI APIs with cloud and SaaS tools, failing to clearly define terms, licensing boundaries, and liability exposure means that in any dispute, the startup absorbs all the risk while platform providers walk away unaffected. If Any of These Apply to You, Get Legal Advice Now You should seek IT legal counsel if you are in any of the following situations. You are designing a data collection or AI training pipeline for a new service You are providing B2B white-label or custom solutions built on third-party AI APIs Your Terms of Service or Privacy Policy do not accurately reflect how your service actually works Your B2B contracts have unclear SLA terms, liability caps, or IP ownership provisions You have already launched but feel uncertain about your data, contract, or terms structure The assumption that "we can fix it after launch" is a costly one. The larger your service grows, the more expensive and disruptive it becomes to restructure the legal foundation underneath it. How Decent Law Firm's Corporate Legal Team Works Decent Law Firm goes beyond reviewing contracts and terms in isolation. We take an integrated approach — examining your service architecture, data flows, and business model together to identify and address legal risks before they become problems. Service structure and data flow analysis AI, privacy, and contract risk mapping Terms of Service, Privacy Policy, and internal policy review B2B and SaaS contract structure design Legal structuring for investment readiness and international expansion If you are building an AI service or have already launched but are uncertain about your legal structure, contact Decent Law Firm today.