Skip to content
TEN Brief Ten verified stories a day 2026.08.23 KO

이 기사는 한국어로도 읽을 수 있습니다 →

Tech · 4 min read · Explainer

What high-impact AI is — why medicine, hiring and loan screening are regulated together

High-impact AI is a regulatory category in the Korean AI Framework Act covering artificial intelligence used in eleven listed domains where it may materially affect life, physical safety or fundamental rights. The test is not how capable the model is but **where it is deployed**, and systems that qualify carry duties including prior notice, risk management and explanation. The Act took effect on January 22, 2026 and its grace period ends in January 2027

A sunlit hospital corridor in the morning with a window wall, empty seats along one side and a person walking far away

The three lines

  • Test — not model size or capability but **the domain of use**. The same model can be high-impact in one deployment and not in another
  • Scope — eleven domains including health care, hiring and loan screening, nuclear facilities, transport and school assessment
  • Timing — the Act took effect January 22, 2026. When the grace period ends in January 2027, penalties begin to apply

Key questions

What is high-impact AI?
A category defined in Article 2 of Korea's AI Framework Act (the Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation of Trust). The definition combines two conditions: the system is used in one of the **domains** the Act lists, and it may materially affect **life, physical safety or fundamental rights**. The first condition is the one that surprises people. What matters is not how large or capable the model is but where it is deployed. The same language model used to summarise internal meeting notes is not high-impact; used to evaluate job applicants it may be.
Which domains are covered?
The Act lists energy supply; drinking water production; the provision of health care and the construction and operation of health care systems; the safe management and operation of nuclear material and nuclear facilities; the analysis and use of biometric information for criminal investigation or arrest; judgments or evaluations that materially affect individual rights and obligations, such as hiring and loan screening; the principal operation of transport vehicles, facilities and systems; decisions by state bodies including eligibility determination and the levying of charges for public services; assessment of students in early childhood, primary and secondary education; and a residual clause for other areas materially affecting safety and fundamental rights. Falling within a domain is not automatically decisive — the impact, severity and frequency of the risk to fundamental rights are weighed as well.
When does the grace period end?
January 2027. The Act itself took effect on January 22, 2026, but the government set a guidance period of at least a year, saying it would defer fact-finding investigations and penalties during that time absent a fatality or a serious infringement of rights. In other words **2026 is a year in which the duties exist but enforcement is suspended**. The practical implication is straightforward: an organisation that does not prepare during this window becomes subject to enforcement, unprepared, on the day the window closes.

The usual first question about AI regulation is "how dangerous is this model?"

Korea's AI Framework Act does not ask that. It asks:

"Where is this AI being used?"

That difference is the whole of the high-impact AI category.

1. The definition is two conditions joined

Article 2 of the Act defines high-impact artificial intelligence as follows.

ConditionRequirement
① Domainused in one of the listed domains
② Riskmay materially affect life, physical safety or fundamental rights

Both must hold. And the assessment does not stop at the domain — the impact, severity and frequency of the risk to fundamental rights are weighed too.

2. The listed domains

#Domain
1Energy supply
2Drinking water production
3Provision of health care and the construction and operation of health care systems
4Safe management and operation of nuclear material and nuclear facilities
5Analysis and use of biometric information for criminal investigation or arrest
6Hiring, loan screening and other judgments or evaluations materially affecting individual rights and obligations
7Principal operation of transport vehicles, facilities and systems
8Decisions by state bodies: eligibility determination and levying of charges for public services
9Assessment of students in early childhood, primary and secondary education
10Other areas materially affecting safety and fundamental rights (by Presidential Decree)

Coverage describes this as "11 areas". The enumeration verified here comprises the ten above; one item may not have been captured, so only the verified entries appear.

Read the list and the pattern emerges: these are decisions that are hard to reverse. A rejected applicant, a refused borrower, a poorly assessed student rarely learns why the decision went that way — and rarely can undo it.

3. The same model splits

Same language modelDeploymentHigh-impact?
ASummarising internal meeting notesNo
ADrafting marketing copyNo
AScreening job applicantsPossibly yes
AAssessing loan applicantsPossibly yes
AFirst-line customer enquiriesDepends

Without changing the model, changing where it is used changes its regulatory status.

For a company the implication is direct: "we only use someone else's model" is not an exemption. The axis of regulation sits on the deployment, not on who built the system.

4. Compared with Europe — and where the order reversed

EU AI ActKorea's AI Framework Act
ApproachRisk-based (prohibited / high-risk / limited / minimal)Risk-based (centred on high-impact)
CharacterRegulation-firstPromotion plus trust-building
In forcePhased applicationJanuary 22, 2026
High-risk / high-impact applicationDeferral to end-2027 under considerationGuidance period ends January 2027

Korea became the second jurisdiction after the EU to enact a comprehensive AI framework. But with the EU weighing a deferral of its high-risk obligations, Korea may become the first to apply such rules in full.

This page covered the opposite kind of mechanism on August 21 in "What an AI risk tier is — when the company that built it grades its own work". High-impact AI runs the other way: the tier is set not by the developer but by statute, according to the domain.

5. This is the grace period

PeriodStatus
January 22, 2026Act takes effect
January 2026 – January 2027Guidance period — investigation and penalties deferred absent a fatality or serious rights infringement
After January 2027Enforcement applies

The guidance period is easy to misread. It is not a period without duties; it is a period in which duties exist and enforcement is suspended.

Two things happen in that window. Organisations that prepare build their assessment procedures and documentation. Organisations that do not become subject to enforcement, unprepared, on the day it closes.

The amounts and basis for administrative fines could not be confirmed here.

6. Generative AI carries a separate duty

Distinct from high-impact AI, generative AI carries a disclosure duty: users must be able to tell that output was produced by AI. That was among the central provisions in the enforcement decree published for comment.

So Korea's AI regulation has two axes.

AxisTestCore duty
High-impact AIwhere it is usedprior notice, risk management, explanation
Generative AIthe nature of the outputdisclose that it is AI-generated

A single service can fall under both.

7. Common questions

Q. Does it apply to foreign companies? Overseas operators serving users in Korea must appoint a domestic representative. The detailed thresholds are matters for the enforcement decree.

Q. Do start-ups carry the same duties? The Act is understood to provide for scale-based exceptions, but this page could not confirm the settled thresholds by revenue or user numbers.

Q. Who decides whether a system is high-impact? In the first instance the operator. The government has published a draft "Guideline for Determining High-Impact AI" and set up a business support desk. Whether a final version has been adopted could not be confirmed.

Q. Does falling within a domain settle it? No. The domain is necessary, and the impact, severity and frequency of the risk are weighed alongside it.

8. What is not confirmed

  • One listed item — coverage says "11 areas"; ten enumerated items were verified.
  • The exact end of the guidance period — "January 2027" is widely used, but no government document giving a date could be confirmed.
  • Fine amounts and basis — not confirmed by type of breach.
  • The final guideline — a draft was consulted; adoption could not be confirmed.
  • Small-operator thresholds — revenue and user-number thresholds could not be confirmed.
  • The EU deferral — deferring high-risk obligations to end-2027 is a proposal under review.
  • Next checkpoint — the enforcement decree revisions under discussion in the second half of 2026, and the end of the guidance period in January 2027.

Sources

  1. ZDNet Korea — What the AI Framework Act contains: high-impact AI defined across 11 areas
  2. ZDNet Korea — Ministry of Science and ICT gives notice of the AI Framework Act enforcement decree
  3. Korea.kr Policy Briefing — AI-generated output must be disclosed: enforcement decree notice
  4. Lawtimes — AI regulation at home and abroad: the second half of 2026 as a turning point
  5. Hwawoo — Draft guideline for determining high-impact AI released
  6. CEO Score Daily — AI Framework Act focused on ecosystem building; enforcement deferred at least a year
  7. Unicorn Factory — 'What counts as high-impact AI?' The Act sets up a business support desk

Verification

Published
Last modified
Cross-check
Checked against 7 independent sources.
Unverified
  • Coverage describes high-impact AI as covering '11 areas', while the enumeration this page verified comprises ten items plus a residual clause. One listed item may not have been captured, so only the verified items appear in the text
  • Many sources place the end of the guidance period in 'January 2027', but no government document specifying an exact date could be confirmed
  • The amounts and the basis for administrative fines, including how they vary by type of breach, could not be confirmed
  • The high-impact AI determination guideline consulted was a draft. Whether a final version has been adopted and promulgated could not be confirmed
  • Reporting that the EU is considering deferring high-risk AI obligations to the end of 2027 describes a proposal under review, not a confirmed decision
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related