Sung Yun Kang
Attorney

Sung Yun Kang is an attorney at Kim & Chang, specializing in emerging areas of law related to new technologies. Her primary focus is on financial artificial intelligence (AI), particularly AI governance, where she advises a broad spectrum of financial institutions, including banks, brokers, financial holding companies, insurance companies and credit card companies.

Sung Yun’s practice further extends to digital assets, stablecoins, decentralized finance (DeFi) and crypto-finance.

Her expertise encompasses not only M&As, cross-border transactions, and corporate governance, but also financial and data regulations, compliance, and licensing matters. Her transactional and regulatory practice encompasses fintech, information technology, e-business, foreign exchange transactions, anti-money laundering, privacy, and data protection.

Sung Yun advises a diverse range of clients, including domestic and international financial institutions, virtual asset service providers, crypto projects, as well as companies in the entertainment, gaming, fintech, IT, e-business sectors, and various start-ups.

Junho Bae
Foreign Attorney

Junho Bae is a foreign attorney at Kim & Chang. His practice focuses on regulatory and transactional matters, particularly within the financial services industry.

Junho Bae advises global and domestic financial institutions and corporates on sales and trading, licensing, compliance and corporate governance issues, cross-border securities offerings and exchange-traded/OTC derivatives transactions, the development of compliance and supervisory policies, and a number of other cross-border regulatory and enforcement matters including those involving digital assets and artificial intelligence.

Prior to joining Kim & Chang, Junho Bae worked at Nomura Financial Investment (Korea) Co., Ltd. as the Head of Korea Legal, Compliance and Controls, responsible for managing all aspects of legal and compliance matters.

AI REGULATIONS IN KOREAN FINANCIAL INDUSTRY

On December 26, 2024, the National Assembly of Korea passed the Act on the Development of Artificial Intelligence and Establishment of Trust (the “AI Basic Act”), which was subsequently promulgated and is scheduled to become effective on January 22, 2026. In comparison to the Artificial Intelligence Act in the European Union, the AI Basic Act provides for less severe maximum penalty for breach of the obligations set forth thereunder, consisting of KRW 30 million in administrative fine. This reflects the key legislative purpose of the AI Basic Act, which is to foster development of domestic AI industry ecosystem and infrastructure. Consistent with such purpose, the AI Basic Act reflects the underlying principle of ensuring autonomy and promoting innovation of private AI businesses which extends to regulating the AI governance, ethics and reliability.

The AI Basic Act in principle applies to all industries including the financial industry. While the financial companies are currently subject to strict IT compliance regulations as well as privacy, governance and internal control regulations in Korea, the existing financial regulatory regimes do not contemplate and are not adequate to comprehensively regulate the risks related to the financial companies’ use of new AI technologies such as generative AI. As such, the introduction of the AI Basic Act is expected to regulate and at the same time promote the financial companies’ use of new innovative AI technologies in Korea.

In connection with scheduled implementation of requirements set forth in the AI Basic Act, the National Assembly of Korea is currently deliberating a number of proposals which may lead to amendments of certain parts of the AI Basic Act and possible change to its scheduled effective date. In addition, the Democratic Party’s Party Platform, which was announced during President Lee Jae-myung’s presidential campaign before he was elected on June 3, 2025 contains a number of AI-related proposals which may influence the new administration’s AI policy.

The following contains a brief overview of the AI Basic Act and key considerations for financial companies.

  1. Overview of the AI Basic Act

The AI Basic Act sets forth obligations applicable to those parties which are deemed as an “AI business operator” (consisting of “AI developer” and “AI deployer”, collectively, “AI business operator”). As financial companies that provide AI services to their customers using AI may fall under the “AI business operator” category, it would be prudent for financial companies operating in Korea to familiarize themselves with the key provisions of the AI Basic Act and take steps to comply with relevant obligations as necessary.

In order to formulate and implement detailed regulatory requirements per the authority delegated under the AI Basic Act, the Ministry of Science and ICT (the “MSIT”) has launched the AI Basic Act Lower Statute Alignment Bureau (the “Bureau”) to draft and finalize subordinate regulations of the AI Basic Act as soon as possible. Led by three working groups composed of experts from the MSIT as well as relevant industries, academia and legal circles, the Bureau is working to collect opinions from relevant experts and stakeholders and based on such input prepare a draft Enforcement Decree of the AI Basic Act. Dedicated teams each assigned to analyse different key issues also have been formed to establish guidelines on relevant subjects pursuant to the AI Basic Act.

As the AI Basic Act contains only high-level information and simply refers to subordinate regulations including the Enforcement Decree of the AI Basic Act for detailed regulatory requirements and obligations, the precise scope of requirements and obligations under the AI Basic Act would become clearer once the Enforcement Decree of the AI Basic Act and relevant guidelines are released.

Key Obligations under the AI Basic Act

While the basic principles of the AI Basic Act are similar to those of the Artificial Intelligence Act in the European Union, one notable difference is that the AI Basic Act does not provide for severe penalty to be imposed for breach of obligations thereunder, in consideration of the risk of discouraging innovation.1For financial companies which are currently subject to various business conduct, governance and IT regulatory requirements, there is a possibility that the AI-related incidents may trigger administrative measures under the existing financial regulatory regimes.

The AI Basic Act applies to AI developers and AI deployers (as those terms are defined thereunder),2The standards for determining the scope of entities that would fall under the “AI developer” and “AI deployer” categories under the AI Basic Act are currently being prepared by the Bureau established by the MSIT. and the financial companies which use AI in conducting their business may fall under either category depending on the circumstances, although the use of AI by a financial company in its business would not automatically subject such financial company to the AI Basic Act. The scope of entities that would fall under the AI developers and AI deployers and hence under the purview of the AI Basic Act would become clearer once the Enforcement Decree of the AI Basic Act and the guidelines are finalized.

The AI Basic Act imposes the following obligations on AI business operators depending on the type of AI used, as summarized in the below table. It would be advisable for financial companies to preemptively identify applicable regulations and, once the Enforcement Decree of the AI Basic Act is finalized, take steps to implement measures to comply with relevant regulatory requirements.

AI business operators without physical presence in Korea that meet certain standards, such as the threshold number of users and sales amount, would be required to appoint a local agent and report such appointment to the Minister of the MSIT. The domestic agent appointment requirement is not unique to the AI Basic Act; other Korean statutes such as the Personal Information Protection Act (the “PIPA”), Telecommunications Business Act and the Network Act also provide analogous domestic agent appointment requirements that apply to offshore service providers doing business in Korea. It remains to be seen whether the domestic agent requirement under the AI Basic Act will be different from those under the existing statutes.

As summarized above, the AI Basic Act imposes various obligations on AI business operators, who may be subject to fact-finding investigation, suspension, corrective orders and administrative fine for breach of the obligations thereunder. As explained above, (i) details of the obligations under the AI Basic Act will be further specified in the Enforcement Decree of the AI Basic Act and relevant guidelines and (ii) one proposal that’s pending before the National Assembly contemplates delay in the scheduled effective date of the AI Basic Act. In consideration of such background, it would be advisable to follow status of the Enforcement Decree of the AI Basic Act and the guidelines and liaise with relevant government agencies as appropriate

AI Guidelines for the Financial Companies

In 2021 and 2022, the Financial Services Commission (“FSC”) issued the “Guidelines for the Operation of AI in the Financial Sector” and the “Guidelines for the Development and Utilization of AI in the Financial Sector,” respectively. Both guidelines contain recommended standards and principles related to reliability, fairness, transparency, and consumer protection in connection with financial companies’ use of AI and also emphasize the importance of having risk management system in place during different stages of the AI lifecycle.

While the FSC’s guidelines do not create legally binding obligations on financial companies, the financial regulators may consider breach of recommendations set forth therein as one of the factors in determining relevant financial companies’ compliance with internal control and/or other obligations under the existing financial regulatory regimes.

Subsequently in March 2024, a group of financial regulatory agencies consisting of the Financial Supervisory Service, the Korea Credit Information Service, the Financial Security Institute, and the Korea Capital Markets Institute jointly established the “Financial AI Counsel” to analyse the impact of AI in financial sector and prepare updates to the existing AI guidelines issued by the FSC in 2021 and 2022.

In light of recent focus on the increased use of generative AI and importance of strengthened risk control and consumer protection, the Korean financial regulators are preparing to issue a new guideline on the use of AI in the financial sector, which will integrate the existing AI guidelines issued by the FSC and is expected to emphasize the following seven principles.

In addition to the anticipated new regulatory guideline on the financial companies’ use of AI, the FSC indicated through a series of announcements its plan to transform the financial security regulatory regime into a voluntary security system by proposing a new digital financial security legislation. As AI systems used by financial companies would also be subject to existing financial IT regulations, it would be advisable for financial companies to closely monitor changes in IT, security and privacy regulatory regimes.

Separately, personal information leakage has recently become a significant social issue, with an increasing number of financial companies facing penalties for violating the PIPA or the Credit Information Act. As the Personal Information Protection Commission (the “PIPC”) strengthens its oversight of financial companies, it would be prudent for financial companies to carefully monitor and

take steps to ensure compliance with any guidance issued by the PIPC pertaining to the use of personal information in connection with development, training and use of AI.

Implications

Previously, financial companies faced difficulties using AI models on external cloud networks due to network separation regulations. However, with the August 2024 release of the “Roadmap for Improvement of Network Separation in the Financial Sector”, financial companies are now permitted to utilize AI models on external cloud networks – provided they do not process personal credit information and unique identification information – upon obtaining approval through the financial regulatory sandbox.

As a result, many financial companies are contemplating seeking financial regulatory sandbox approvals for AI use and actively exploring various AI applications in preparation for the AI-driven transformation of the financial industry.

Looking ahead, as AI technology continues to evolve and regulations change, financial companies are expected to adopt AI more extensively. As such, it would be advisable for financial companies to consider taking the following steps in order to ensure safe and effective use of AI:

Conclusion

In Korea, a new legislation that aims to foster domestic AI industry ecosystem and infrastructure while ensuring robust AI governance framework has been promulgated and is scheduled to take effect soon. Considering the Korean government’s focus on promoting development and growth of domestic AI industry, the government will likely remain focused on smooth implementation of regulatory framework that ensures rapid growth and development of domestic AI industry rather than active enforcement and imposition of penalties for breach of regulatory obligations under the AI Basic Act.

Notwithstanding the Korean government’s focus on promoting development and growth of domestic AI industry, the primary policy goal of the new administration under President Lee and the Korean financial regulators concerning financial industry consists of strengthened protection of financial consumers

and aggressive enforcement of market abuse conduct to enhance integrity of the market and revitalize domestic financial markets. Therefore, it would be advisable for financial companies to carefully assess and manage AI-related regulatory risks and take steps to comply with requirements under the AI Basic Act, while ensuring robust compliance with existing financial regulations.