We Resolve Legal Matters
How can we assist you?
Blogs
More-
Korea’s AI Basic Act Six Months On: Disclosure and Labeling Duties for Generative AI Businesses
Korea’s AI Basic Act took effect on January 22, 2026. Under the Act, businesses that provide generative AI products or services are subject to transparency obligations. Compliance, however, does not end with adding a notice to a service screen. The applicable legal risks depend on the AI model used, the information entered by users, where that information is transferred, and how the generated output is used. Advance Disclosure and Output Labeling Are Separate Obligations Article 31 of the AI Basic Act divides transparency obligations into two categories. First, an AI business operator intending to provide a product or service based on generative AI must inform users of that fact in advance. Second, when generative AI or an AI-powered service produces content, the business must indicate that the output was generated using AI. For example, a chatbot or AI document-generation service may need to disclose its use of generative AI through its terms of service or user interface before the service is used. Separately, text, images, audio, or video generated by the service may require an AI-generated content label. Synthetic audio, images, and video that could easily be mistaken for real content require particularly clear disclosure. In practical terms: Before use: disclose that the product or service uses generative AI. After generation: indicate that the resulting content was generated using AI. AI-Generated Content Does Not Always Require a Visible Watermark The required label does not necessarily have to be a visible watermark. The Enforcement Decree permits both: ▪️ Human-readable labeling ▪️ Machine-readable labeling Where only a machine-readable method is used, users must still be informed at least once, through text, audio, or another accessible method, that the content was generated using AI. All or part of the disclosure and labeling requirements may not apply where: ▪️ The service name or interface already makes the use of AI obvious ▪️ The AI is used exclusively for the operator’s internal business purposes ▪️ A separately issued government notice recognizes an exception The internal-use exception should be applied carefully. Materials initially generated for internal use may fall outside the exception once they are included in advertisements, customer reports, consultation materials, or other externally distributed content. Businesses should therefore distinguish between outputs that remain within the service and outputs that can be downloaded, shared, or provided to customers. Businesses Using External AI APIs May Also Be Covered A business does not need to develop its own AI model to fall within the scope of the AI Basic Act. The Act also covers businesses that use AI developed by another provider to offer AI products or services. A company may therefore qualify as an AI business operator where it connects an external large language model through an API and provides services such as: ▪️ AI chatbots ▪️ Image-generation tools ▪️ Document drafting or summarization ▪️ Automated customer consultation The key question is not who developed the underlying model. What matters is whether the company uses AI to provide a product or service to users. Businesses using third-party APIs should therefore review whether they are subject to advance disclosure and AI-output labeling obligations. Disclosure Compliance Is Only One Part of the Legal Review Generative AI services commonly send user inputs to an external AI model and return generated outputs to the user. This process may raise data protection and copyright issues that are legally separate from the labeling requirements under the AI Basic Act. 1. Personal Data Entered into AI Services Where customers or employees enter names, consultation records, contracts, photographs, or internal documents into an external AI service, the business should verify: ▪️ Whether input data is stored or used for model training ▪️ The location and country of the servers processing the data ▪️ Applicable retention periods and deletion procedures ▪️ Whether the arrangement constitutes outsourcing, third-party provision, or overseas transfer ▪️ Whether the data is retransmitted to plug-ins or other external services The legal classification should be based on the actual data flow rather than the name of the agreement with the AI provider. A privacy policy should accurately reflect how personal data is collected, transferred, retained, and deleted throughout the AI service structure. 2. Copyright in AI-Generated Outputs A business does not automatically acquire exclusive copyright merely because an image, document, video, or source code was generated using AI. Relevant considerations include: ▪️ The degree of human creative involvement ▪️ Whether the source materials were lawfully used ▪️ Whether the AI provider’s terms permit commercial use ▪️ Whether the output is substantially similar to existing protected works AI-generated content may also infringe third-party copyrights, image rights, or other intellectual property rights. Businesses using generated outputs for advertising, websites, software, games, or commercial publications should retain records of the model used, prompts, initial outputs, and subsequent human edits. AI Used to Evaluate Individuals May Qualify as High-Impact AI Not every generative AI service is classified as high-impact AI. However, additional review may be required where AI is used beyond basic drafting or guidance and affects a person’s rights, opportunities, or access to essential services. Relevant examples include AI used in: ▪️ Recruitment and applicant evaluation ▪️ Lending, credit scoring, and insurance assessment ▪️ Medical diagnosis or treatment-related decision-making ▪️ Student admission, selection, or performance evaluation For instance, an AI tool that summarizes a résumé may present a different level of legal risk from one that calculates an applicant’s probability of being hired. The assessment depends on how the AI output is used in the actual decision-making process. Where a system qualifies as high-impact AI, the operator may need to implement: ▪️ Risk-management measures ▪️ Procedures for explaining major decision-making criteria ▪️ User-protection procedures ▪️ Human management and oversight ▪️ Preparation and retention of relevant records Documents to Review Before Launching a Generative AI Service Legal review should not begin by drafting a disclaimer in isolation. A business should first map: ▪️ The AI model being used ▪️ The information entered by users ▪️ The data-transfer route ▪️ How generated outputs are used ▪️ Where human review takes place The following documents should then be aligned with the actual service structure. AI Disclosure and Labeling Notices Separate advance disclosure before use from labeling of generated outputs. Terms of Service Define the permitted use of AI outputs and procedures for handling errors, rights infringement, and user complaints. Privacy Policy Reflect the actual collection, processing, storage, overseas transfer, and deletion of personal data involving external AI providers. AI Supply Agreements and API Terms Review provisions concerning data use, cybersecurity incidents, intellectual property, service interruptions, and liability allocation. Internal AI Use Policy Establish restrictions and approval procedures for entering customer data, contracts, source code, and confidential business information into AI tools. Legal Review Based on the Actual AI Service Structure Under Korea’s AI Basic Act, generative AI transparency obligations are divided into advance disclosure before use and labeling of AI-generated outputs. In practice, however, legal risk extends beyond how a notice is displayed. Businesses should also review the use of external AI models, personal data processing and overseas transfers, rights in generated content, potential classification as high-impact AI, and the allocation of liability with AI vendors. Decent Law Firm’s Corporate Practice Group advises AI and technology companies based on their actual service functions and data flows. Our review covers the applicability of the AI Basic Act, disclosure and labeling design, privacy and copyright issues, external AI model agreements, and the legal documentation required for launching and operating AI services in Korea. This content is provided for general informational purposes only and does not constitute legal advice for any individual matter.
-
M&A Legal Due Diligence Costs and Scope in Korea: A Practical Guide
The cost of M&A legal due diligence is not simply a lawyer’s fee. It depends on the size of the transaction, the complexity of the target company, and the scope of the review itself. For foreign companies and investors entering the Korean market, understanding how legal due diligence works is critical because the findings can directly affect pricing, indemnity structures, and even whether the transaction proceeds at all. What Is Legal Due Diligence in an M&A Transaction? Legal due diligence (LDD) is the process of identifying and reviewing the legal risks of a target company before completing an acquisition or investment. In Korea, legal due diligence is typically conducted after the signing of an LOI (Letter of Intent) and before the execution of the SPA (Share Purchase Agreement). Key review areas usually include: Material contracts and commercial arrangements Litigation and disputes Employment and labor issues Regulatory compliance Intellectual property rights Corporate governance and shareholder structure Licenses and permits Subsidiaries and overseas entities The purpose is not simply to “find problems,” but to assess legal exposure that may transfer to the buyer after closing. The results of due diligence often directly influence: Purchase price adjustments Representations & warranties (R&W) Indemnification clauses Escrow arrangements Closing conditions Deal restructuring decisions What Determines M&A Legal Due Diligence Costs? There is no fixed pricing standard for legal due diligence in Korea. Costs are generally determined by several combined factors. 1. Transaction Size Larger transactions typically involve: Broader review scope Higher legal exposure Increased reporting requirements More intensive negotiation support Cross-border transactions and strategic acquisitions usually require deeper review compared to early-stage investments. 2. Complexity of the Target Company Costs increase when the target company has: Multiple subsidiaries Overseas entities Large numbers of commercial contracts Regulated business operations Complex shareholder arrangements Convertible securities, SAFE, or stock option structures Industries such as fintech, crypto, healthcare, SaaS, and platform businesses often require additional regulatory analysis. 3. Scope of Due Diligence The scope of review is one of the biggest cost variables. • Full Scope Due Diligence A full-scope review examines the overall legal condition of the company in detail. This is commonly used in: Strategic acquisitions Large-scale M&A deals Transactions involving operational integration (PMI) While more expensive and time-consuming, it can significantly reduce post-closing legal risks. • Red Flag Due Diligence A red-flag review focuses only on major legal risks that could materially affect the transaction. This approach is often used by: Financial investors Venture capital firms Early-stage investors Buyers operating under tight timelines It is generally faster and less expensive, but risks outside the agreed review scope may remain unidentified. How Are Legal Due Diligence Fees Structured? In practice, Korean law firms usually structure due diligence fees in one of three ways. Hourly Billing Fees are calculated based on: Time spent Hourly rates of lawyers involved This model is commonly used when the review scope may change during the transaction. Fixed Fee A fixed fee is agreed upon based on: Defined review scope Estimated timeline Expected workload This structure offers budget predictability but may require additional fees if the scope expands later. Hybrid Structure Many mid-to-large transactions use a hybrid model: Base scope under a fixed fee Additional work billed hourly This approach balances flexibility with cost predictability. Data Room Preparation Also Affects Costs The quality of document organization can significantly impact due diligence efficiency. Well-structured VDRs (Virtual Data Rooms) reduce: Review time Additional document requests Follow-up interviews Reporting delays Poorly organized materials often increase both costs and transaction risks. Importantly, legal advisors can only assess documents actually provided to them. Missing or incomplete disclosures may limit the scope of legal responsibility and the reliability of the review itself. Why Due Diligence Findings Matter Legal due diligence findings can materially change the transaction structure. Purchase Price Adjustments Material legal risks may justify: Lower valuations Deferred payments Escrow retention Representation & Warranty Negotiations Discovered risks are often reflected in: Disclosure schedules Liability caps Survival periods Basket thresholds Specific indemnities Deal Restructuring or Termination Serious legal issues may lead to: Changes in acquisition structure Asset deals instead of share deals Conditional closing arrangements Transaction termination Proper Scope Design Is Critical One of the most common problems in M&A transactions is starting due diligence without clearly defining the review scope. When the scope is unclear: Costs become unpredictable Timelines expand Review items continue increasing Negotiations become inefficient A properly structured process usually follows this order: Define review scope Discuss fees and timeline Execute engagement agreement Open VDR and begin review Deliver due diligence report Reflect findings in SPA negotiations Legal due diligence should not be evaluated solely based on price. The more important question is whether the legal team can accurately identify transaction-critical risks and translate them into practical deal protections. Decent Law Firm advises domestic and international clients on M&A transactions, startup investments, cross-border acquisitions, and regulatory risk analysis in Korea. If you are considering an acquisition or investment in Korea and would like to discuss an appropriate due diligence scope and fee structure, our corporate advisory team would be happy to assist.