Amrit DePaulo
← Writing

Korea's AI Act at Six Months: The Details Arrived, and the EU Blinked

Amrit DePauloAugust 2026

On January 22, 2026, South Korea's AI Framework Act entered into force, making it the second jurisdiction in the world, and the first in Asia-Pacific, to enforce comprehensive AI legislation. When I wrote about the law at enforcement, my central concern was deliberate vagueness: critical implementation details, from compute thresholds to high-impact classification criteria to the domestic representative requirement, had all been deferred to Presidential Decrees that were still being finalized as enforcement began.

Six months in, the picture has changed in two directions worth examining.

Korea filled in the blanks

The enforcement decree took effect alongside the Act, and a revised decree effective July 21, 2026 answered most of the open questions. The compute threshold for "high-performance" AI is now set at 10^26 cumulative training FLOPs, roughly ten times the EU's general-purpose AI threshold, which means the added safety obligations focus almost exclusively on frontier model developers. The domestic representative requirement now has concrete triggers: prior-year total revenue of at least KRW 1 trillion, AI-service revenue of at least KRW 10 billion, or one million average daily Korean users.

Just as telling is what regulators chose not to do. The Ministry of Science and ICT is running a grace period through at least the first year, deferring fact-finding investigations and administrative fines except in cases involving serious social harm. Binding law, paired with a deliberate pause on penalties. That combination sounds more like the trust-first strategy the law announced: give companies real obligations, give them runway to comply, and reserve enforcement for genuine harm.

The EU moved its deadline

The EU AI Act's high-risk obligations were scheduled to become enforceable on August 2, 2026. They did not. The Digital Omnibus on AI (Regulation 2026/1744) was published in the Official Journal on July 24, 2026 and entered into force on July 27, six days before the deadline. Standalone high-risk systems under Annex III now have until December 2, 2027. AI embedded in regulated products gets until August 2, 2028. The stated reason: harmonized standards and national competent authorities were not ready.

The EU built a risk-prevention regime with prohibitions, conformity assessments, and fines up to EUR 35 million or 7% of global turnover. Korea built a dual-track regime: transparency and risk-management obligations for high-impact and generative AI, combined with R&D funding, tax incentives, and a National AI Committee chaired by the President with a private-sector majority. Critics called Korea's approach underpowered. Yet as of this summer, Korea has a comprehensive AI law in force with its implementing details largely settled, while the EU has deferred the core of its high-risk regime by sixteen months because the compliance infrastructure was not ready.

Deferral is not failure. The EU's transparency obligations under Article 50 took effect on August 2 as scheduled, and its prohibitions have applied since early 2025. A deadline that moves once, for stated operational reasons, is better than a deadline enforced against standards that do not exist. Korea wrote a law that its regulator could actually operationalize in year one. The EU wrote a law that its own engine could not support on schedule.

What this means for companies

For anyone deploying AI across both markets, the practical guidance has inverted since January. Korea is now the nearer-term compliance obligation, grace period notwithstanding, because its substantive requirements are in force and its details are settled. The EU timeline has moved, but the transparency obligations are live now, and the December 2027 high-risk date will arrive with less flexibility than the first deadline did.

The worst outcome I worried about in January remains the live risk: a fragmented global picture where every major market has fundamentally different AI rules, different thresholds, and now different timelines. That is a recipe for compliance chaos and, paradoxically, less safety.

Korea still does not have all the answers. But six months of evidence says it asked one question better than anyone else: can the regulator actually run the regime it is writing? The jurisdictions drafting AI laws now should be studying that question first.