South Korea's AI Law Has a Grace Period. Article 34 Never Needed One.
South Korea's AI Basic Act has a grace period on fines. Its own Article 43 never fined high-impact AI's core safety duty in the first place.
South Korea's Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust - known outside Korea as the AI Basic Act - is being covered as a law with no near-term teeth: the Ministry of Science and ICT is running a grace period of at least a year during which it will generally not investigate or fine violations. That framing is accurate, and incomplete in a way that matters more than the grace period itself. Read the Act's own fine provision, Article 43, against the duty it is supposed to enforce, and the safety, risk-management, and documentation work required of "high-impact AI" operators under Article 34 was never directly fineable in the first place. The grace period doesn't need to carve out an exception for it. Article 43 already did that on its own.
Commentary since the law's rollout has settled on one framing: it looks strong on paper and defers the consequences. What follows is what the statute's own text says about which duties actually carry a fine, and which never did.
What the Act Actually Fines
Article 43 sets the ceiling for every administrative fine in the Act at 30 million won, about $22,000, and it applies that fine to exactly three things: failing to give users advance notice that they're dealing with AI, failing to appoint a required domestic representative, and refusing to comply with a corrective order once one has been issued. That is the entire list. It is not a general "penalties for violating this Act" clause - it names three specific failures and stops.
The Duty With No Fine Attached
Article 34 is where the Act's substance lives. Once a system counts as "high-impact" - defined broadly across energy, drinking water, healthcare, medical devices, nuclear-facility safety, biometric identification for criminal investigation, employment and loan decisions, transportation systems, public-institution decisions, and student assessment - its operator must build a risk-management plan, an explainability process for its outputs, user-protection measures, human oversight, and documentation proving all of it. Article 32 imposes a parallel safety-and-risk-management duty on any system trained above a compute threshold the government will set by decree.
Neither Article appears in Article 43's list. Failing to build the Article 34 risk-management plan is not, on its own, a fineable act under this law. Neither is failing to submit the Article 32 safety results. The obligations exist; the direct penalty for skipping them does not.
How a Violation Becomes Fineable Anyway
That doesn't mean Article 34 is unenforceable - it means it's enforceable indirectly. The Act gives the Ministry investigative power under Article 40: it can demand records or send officials to investigate where a violation of Article 34 (or Article 32, or parts of Article 31) is discovered, suspected, or reported through a complaint. If that investigation turns up a violation, the Ministry can issue a corrective order requiring the operator to fix it. Only at that next step does Article 43 reach back in - refusing to comply with the corrective order is what's fineable, not the original gap in the risk-management plan.
So the path from "we never built the Article 34 documentation" to an actual fine runs through three gates: someone has to notice or report the problem, the Ministry has to investigate and find a violation, and the operator has to then ignore the resulting order. Skip any one of those steps and there's no fine - not because of the grace period, but because that's the only route the statute provides.
The Self-Review Nobody Checks
The classification question sits on the same footing. Article 33 requires an operator to review in advance whether its own system counts as high-impact AI. It only requires that review - asking the Ministry to confirm the answer is optional, framed with "may," not "must." Combined with Article 40's complaint-and-discovery trigger, this means an operator's own determination that its system falls outside the high-impact categories faces no routine check. This is this Article's own reading of what those two provisions mean together - the Act doesn't state it as a design choice, and nothing here claims the Ministry lacks the authority to look. The point is narrower: absent a complaint, an incident, or a violation someone else surfaces, nothing in the Act requires anyone to look.
What This Means While the Grace Period Runs
MSIT's own announcement of the grace period frames it as time for operators to prepare before enforcement begins in earnest, running alongside a dedicated guidance center meant to help businesses get compliant rather than punish them for not yet being so. Coverage describing that pause as the reason the law "has no bite" is describing something real - investigations and fines are genuinely paused, with an exception only for cases of serious social harm. But it is describing that pause as though it were suspending an enforcement mechanism that, for Article 34 specifically, was direct to begin with. It wasn't. That the grace period and the structural gap are two separate facts, doing separate work, is this Article's own reading of the two provisions together - not a distinction the Act or MSIT draws for the reader. The grace period pauses Article 40 investigations and the fines that can follow them. It was never protecting Article 34 from a direct fine, because no such fine exists to protect it from.
That has a practical edge for any organization operating a high-impact system in Korea, or selling one into the market. Treating the absence of a direct Article 34 fine - or the grace period sitting on top of it - as a reason to defer the risk-management plan, the explainability work, and the documentation trail is a bet that no complaint, incident, or discovered violation puts the system in front of Article 40 before that work exists. If one does, the operator is asked to demonstrate measures it hasn't built, a corrective order follows, and non-compliance with that order is the one thing on Article 43's short list that reaches straight through to a fine - a fine grace period that may, by then, no longer even be running.
Source note: This Article is based on the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust (Law No. 20676, promulgated 21 January 2025), read directly Article by Article, and the Ministry of Science and ICT's own English-language announcement of its enforcement grace period.
Map your disclosures against AI & Technology.
Noa reads your disclosures, traces every number to its source, and flags what's missing.