What high-impact AI is — why medicine, hiring and loan screening are regulated together
High-impact AI is a regulatory category in the Korean AI Framework Act covering artificial intelligence used in eleven listed domains where it may materially affect life, physical safety or fundamental rights. The test is not how capable the model is but **where it is deployed**, and systems that qualify carry duties including prior notice, risk management and explanation. The Act took effect on January 22, 2026 and its grace period ends in January 2027
The three lines
- Test — not model size or capability but **the domain of use**. The same model can be high-impact in one deployment and not in another
- Scope — eleven domains including health care, hiring and loan screening, nuclear facilities, transport and school assessment
- Timing — the Act took effect January 22, 2026. When the grace period ends in January 2027, penalties begin to apply
Key questions
- What is high-impact AI?
- A category defined in Article 2 of Korea's AI Framework Act (the Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation of Trust). The definition combines two conditions: the system is used in one of the **domains** the Act lists, and it may materially affect **life, physical safety or fundamental rights**. The first condition is the one that surprises people. What matters is not how large or capable the model is but where it is deployed. The same language model used to summarise internal meeting notes is not high-impact; used to evaluate job applicants it may be.
- Which domains are covered?
- The Act lists energy supply; drinking water production; the provision of health care and the construction and operation of health care systems; the safe management and operation of nuclear material and nuclear facilities; the analysis and use of biometric information for criminal investigation or arrest; judgments or evaluations that materially affect individual rights and obligations, such as hiring and loan screening; the principal operation of transport vehicles, facilities and systems; decisions by state bodies including eligibility determination and the levying of charges for public services; assessment of students in early childhood, primary and secondary education; and a residual clause for other areas materially affecting safety and fundamental rights. Falling within a domain is not automatically decisive — the impact, severity and frequency of the risk to fundamental rights are weighed as well.
- When does the grace period end?
- January 2027. The Act itself took effect on January 22, 2026, but the government set a guidance period of at least a year, saying it would defer fact-finding investigations and penalties during that time absent a fatality or a serious infringement of rights. In other words **2026 is a year in which the duties exist but enforcement is suspended**. The practical implication is straightforward: an organisation that does not prepare during this window becomes subject to enforcement, unprepared, on the day the window closes.
The usual first question about AI regulation is "how dangerous is this model?"
Korea's AI Framework Act does not ask that. It asks:
"Where is this AI being used?"
That difference is the whole of the high-impact AI category.
1. The definition is two conditions joined
Article 2 of the Act defines high-impact artificial intelligence as follows.
| Condition | Requirement |
|---|---|
| ① Domain | used in one of the listed domains |
| ② Risk | may materially affect life, physical safety or fundamental rights |
Both must hold. And the assessment does not stop at the domain — the impact, severity and frequency of the risk to fundamental rights are weighed too.
2. The listed domains
| # | Domain |
|---|---|
| 1 | Energy supply |
| 2 | Drinking water production |
| 3 | Provision of health care and the construction and operation of health care systems |
| 4 | Safe management and operation of nuclear material and nuclear facilities |
| 5 | Analysis and use of biometric information for criminal investigation or arrest |
| 6 | Hiring, loan screening and other judgments or evaluations materially affecting individual rights and obligations |
| 7 | Principal operation of transport vehicles, facilities and systems |
| 8 | Decisions by state bodies: eligibility determination and levying of charges for public services |
| 9 | Assessment of students in early childhood, primary and secondary education |
| 10 | Other areas materially affecting safety and fundamental rights (by Presidential Decree) |
Coverage describes this as "11 areas". The enumeration verified here comprises the ten above; one item may not have been captured, so only the verified entries appear.
Read the list and the pattern emerges: these are decisions that are hard to reverse. A rejected applicant, a refused borrower, a poorly assessed student rarely learns why the decision went that way — and rarely can undo it.
3. The same model splits
| Same language model | Deployment | High-impact? |
|---|---|---|
| A | Summarising internal meeting notes | No |
| A | Drafting marketing copy | No |
| A | Screening job applicants | Possibly yes |
| A | Assessing loan applicants | Possibly yes |
| A | First-line customer enquiries | Depends |
Without changing the model, changing where it is used changes its regulatory status.
For a company the implication is direct: "we only use someone else's model" is not an exemption. The axis of regulation sits on the deployment, not on who built the system.
4. Compared with Europe — and where the order reversed
| EU AI Act | Korea's AI Framework Act | |
|---|---|---|
| Approach | Risk-based (prohibited / high-risk / limited / minimal) | Risk-based (centred on high-impact) |
| Character | Regulation-first | Promotion plus trust-building |
| In force | Phased application | January 22, 2026 |
| High-risk / high-impact application | Deferral to end-2027 under consideration | Guidance period ends January 2027 |
Korea became the second jurisdiction after the EU to enact a comprehensive AI framework. But with the EU weighing a deferral of its high-risk obligations, Korea may become the first to apply such rules in full.
This page covered the opposite kind of mechanism on August 21 in "What an AI risk tier is — when the company that built it grades its own work". High-impact AI runs the other way: the tier is set not by the developer but by statute, according to the domain.
5. This is the grace period
| Period | Status |
|---|---|
| January 22, 2026 | Act takes effect |
| January 2026 – January 2027 | Guidance period — investigation and penalties deferred absent a fatality or serious rights infringement |
| After January 2027 | Enforcement applies |
The guidance period is easy to misread. It is not a period without duties; it is a period in which duties exist and enforcement is suspended.
Two things happen in that window. Organisations that prepare build their assessment procedures and documentation. Organisations that do not become subject to enforcement, unprepared, on the day it closes.
The amounts and basis for administrative fines could not be confirmed here.
6. Generative AI carries a separate duty
Distinct from high-impact AI, generative AI carries a disclosure duty: users must be able to tell that output was produced by AI. That was among the central provisions in the enforcement decree published for comment.
So Korea's AI regulation has two axes.
| Axis | Test | Core duty |
|---|---|---|
| High-impact AI | where it is used | prior notice, risk management, explanation |
| Generative AI | the nature of the output | disclose that it is AI-generated |
A single service can fall under both.
7. Common questions
Q. Does it apply to foreign companies? Overseas operators serving users in Korea must appoint a domestic representative. The detailed thresholds are matters for the enforcement decree.
Q. Do start-ups carry the same duties? The Act is understood to provide for scale-based exceptions, but this page could not confirm the settled thresholds by revenue or user numbers.
Q. Who decides whether a system is high-impact? In the first instance the operator. The government has published a draft "Guideline for Determining High-Impact AI" and set up a business support desk. Whether a final version has been adopted could not be confirmed.
Q. Does falling within a domain settle it? No. The domain is necessary, and the impact, severity and frequency of the risk are weighed alongside it.
8. What is not confirmed
- One listed item — coverage says "11 areas"; ten enumerated items were verified.
- The exact end of the guidance period — "January 2027" is widely used, but no government document giving a date could be confirmed.
- Fine amounts and basis — not confirmed by type of breach.
- The final guideline — a draft was consulted; adoption could not be confirmed.
- Small-operator thresholds — revenue and user-number thresholds could not be confirmed.
- The EU deferral — deferring high-risk obligations to end-2027 is a proposal under review.
- Next checkpoint — the enforcement decree revisions under discussion in the second half of 2026, and the end of the guidance period in January 2027.
Sources
- ZDNet Korea — What the AI Framework Act contains: high-impact AI defined across 11 areas
- ZDNet Korea — Ministry of Science and ICT gives notice of the AI Framework Act enforcement decree
- Korea.kr Policy Briefing — AI-generated output must be disclosed: enforcement decree notice
- Lawtimes — AI regulation at home and abroad: the second half of 2026 as a turning point
- Hwawoo — Draft guideline for determining high-impact AI released
- CEO Score Daily — AI Framework Act focused on ecosystem building; enforcement deferred at least a year
- Unicorn Factory — 'What counts as high-impact AI?' The Act sets up a business support desk