Subordinate statutes specifying public procurement and support for vulnerable groups accept comments until June 19… EU significantly delays timeline for high-risk regulations
[KBR Policy Insight] The follow-up legislative procedures for the 「Framework Act on Artificial Intelligence Development and Creation of Trust」 (hereinafter referred to as the 'Framework Act on AI'), which contains the basic framework for artificial intelligence regulation and promotion, have reached a turning point. As the submission deadline for comments on the revision of the Enforcement Decree of the Framework Act on AI, pre-announced by the Ministry of Science and ICT (MSIT) on May 21, approaches on June 19, the outline of the institutional design ahead of its full implementation on July 21 is effectively entering the finalization stage. In contrast to the European Union (EU), which has shifted toward significantly delaying the application timing of high-risk AI regulations around the same period, South Korea's AI governance is increasingly leaning toward 'promotion' rather than 'regulation'.
1. What Changes — Implementation Schedule Divided into Two Phases
The Framework Act on AI passed the plenary session of the National Assembly on December 26, 2024, was promulgated on January 21, 2025, and took effect on January 22 of this year following a one-year grace period. With this, South Korea became one of the countries establishing a comprehensive framework governing AI overall.
The issue currently undergoing public comment concerns the post-implementation stage. Nine amendment bills, respectively proposed by lawmakers Choi Min-hee, Lee Jung-heon, Jang Chul-min, and Choi Bo-yoon of the Science, ICT, Broadcasting and Communications Committee, passed the National Assembly on December 30, 2025, through bipartisan agreement, and the revision was completed on January 20, 2026. The revised legislation includes the legalization of the reorganization of the National AI Strategy Committee, the promotion of the introduction and utilization of AI in the public sector, the establishment of grounds for the establishment and operation of AI research institutes, provisions for ensuring accessibility and cost support for vulnerable AI groups, support for the revitalization of startups in the AI sector, support for specialized personnel, and grounds for providing public data for machine learning.
What is notable is that the implementation timing has been split into two. Matters that can be implemented immediately without separate subordinate regulations—such as the reorganization of the National AI Strategy Committee or support for specialized personnel—already took effect in line with the Framework Act's implementation date of January 22. On the other hand, matters that need to materialize the system through the enforcement decree, such as promoting the introduction and utilization of AI in the public sector, are scheduled to be implemented on July 21. This revision of the enforcement decree is the process of filling in the detailed criteria required for this July implementation.
2. Why It Is Necessary — Law as 'Grounds', Enforcement Decree as 'Operating Mechanism'
If legislation creates the 'grounds' for a system, the enforcement decree determines how that system will actually operate. For example, the legal provision stating "support is provided to vulnerable groups" alone does not determine who is eligible or through what procedures support is provided. Policy enforcement becomes possible only when the enforcement decree fills in those blanks. This is why this revision presents detailed criteria divided into five categories.
First is the scope of the vulnerable AI groups. The Framework Act defines vulnerable groups as 'those who experience difficulties in using artificial intelligence products and services' and stipulates that their participation and reflection of opinions must be guaranteed during the policy-making process. The draft enforcement decree expanded this scope to include career-interrupted women, job seekers, employees of small and medium-sized enterprises outside the capital area, and farmers and fishermen, in addition to persons with disabilities, the elderly, and recipients of basic livelihood security. This is interpreted as expanding the issue of AI accessibility beyond simple physical and age-related divides to the dimensions of regional and employment divides.
Second is the scope of AI products and services subject to priority consideration in public procurement. The law stipulates that state agencies and others must prioritize AI products and services when purchasing products and services or placing orders for service contracts. The draft enforcement decree designates the targets as 'products and services confirmed to have applied AI technology' and products and services separately notified by the MSIT. While the press release for the legislative notice designates the Korea Artificial Intelligence Industry Association as the verification entity, this name and verification system may be specified and adjusted during the future public notice enactment process. In particular, by allowing additional targets to be designated through public notices, it contains the intent to operate the system flexibly in response to market changes.
Third is the scope of recipients for cost support. Regarding the provision (Article 17-2 of the Act) allowing the state and local governments to support costs for individuals who have difficulty using AI products and services, the draft enforcement decree included not only vulnerable groups but also university talents and science and engineering personnel located outside the capital area.
Fourth is the utilization procedure of the venture investment mother fund for vitalizing AI startups. The procedures were specified to allow the heads of central administrative agencies to request the establishment of investment plans from Korea Venture Investment in consultation with the Minister of SMEs and Startups.
Fifth is the requirements for the establishment and operation of AI research institutes. Regarding the grounds (Article 22-2 of the Act) allowing universities and corporations to establish and operate AI research institutes with the permission of the Minister of Science and ICT, the draft enforcement decree diversified the establishment entities, detailed the establishment requirements, and specifically stipulated support measures so that the state can provide extensive support.
The common thread running through all five categories is that they focus on 'support and promotion' rather than 'regulatory obligations'. The MSIT has stated that in the process of preparing the enforcement decree, considering global regulatory trends and the domestic AI industry, it focused on introducing a minimum necessary regulatory system with an emphasis on promotion rather than regulation, and concentrated on minimizing duplicate and similar regulations through consultation with related ministries.
3. Where Things Stand Now — June 19 Comment Deadline and What Follows
The pre-announced revision of the enforcement decree can be viewed on the MSIT website, and the deadline for submitting comments is June 19. Currently, ahead of the closure of this public comment period, this represents practically the final phase during which opinions that can influence the institutional design can be submitted.
Following the end of the legislative notice, the MSIT plans to complete the revision of the enforcement decree by sequentially going through regulatory review, legal review, vice-ministerial meetings, and cabinet meetings. Kim Kyung-man, Director General for Artificial Intelligence Policy at MSIT, has stated his stance to prepare without disruption for law enforcement and system operation to support the expanded adoption of AI products and services in the public procurement market and the establishment of AI research institutes. Considering the typical flow of procedures after a legislative notice, the general outlook is that the enforcement decree is likely to be organized in time for the implementation date of July 21. However, room remains for detailed wording or application criteria to be adjusted during the regulatory and legal review processes.
4. Comparison with the EU — South Korea Focuses on Promotion, EU Adjusts Speed
The discussion on this enforcement decree becomes clearer when viewed alongside global AI regulatory trends.
On May 7, 2026, the EU finalized important revision directions for the AI Act through political agreement among legislative bodies. As part of the 'Digital Omnibus' reform package, the core is to significantly delay the mandatory compliance deadlines for high-risk AI systems, which were originally scheduled for August 2026. According to reports, compliance deadlines for high-risk systems used in energy management and critical infrastructure have been extended by about 16 months to the end of 2027, while some high-risk systems such as safety components have been delayed into 2028. Conversely, the deadlines for implementing transparency obligations, such as watermarking for deepfakes and AI-generated content, are reportedly being brought forward compared to originally planned. However, for this agreement to take final effect, additional approval from the EU Council is required, and specific dates may change during the finalization process.
The background behind the EU delaying the full application of high-risk regulations is evaluated to be a realistic judgment that enforcement preparations by regulatory authorities and the establishment of technical standards and detailed guidelines are insufficient. Experts have pointed out that a certain degree of speed adjustment in regulatory enforcement is necessary, and an approach that substantially reduces obligations for low-risk fields or small and medium-sized enterprises with lesser capacity to bear burdens is required.
It is in this context that South Korea's position emerges. South Korea's Framework Act on AI already entered full implementation on January 22, and considering that the EU's high-risk regulations will be applied in earnest no earlier than the end of 2027, observations suggest that South Korea is shaping up to operate its regulatory system ahead in terms of timeline alone. However, given that the EU has already had AI-related regulations such as the General Data Protection Regulation (GDPR) and sector-specific safety regulations operating previously, the assessment that 'South Korea is first' is a perspective limited to the implementation timing of a single AI law. The South Korean government is also pursuing a de facto regulatory deferral effect through the operation of a grace period for fines, and as seen in this enforcement decree revision, it places the center of gravity of the system on support and promotion. Regarding this, some interpret that the EU's 'speed adjustment' and South Korea's 'promotion priority' are heading in a similar direction as a result.
5. Business and Policy Implications — Dual Coordinates of the Public Market and Global Regulations
This enforcement decree revision provides two practical signals to AI business operators.
One is that the doors to the public procurement market are expanding institutionally. As the regulation requiring state agencies to prioritize AI products and services is specified through the enforcement decree, receiving designated technology application confirmation or being included in the MSIT public notice targets is likely to become a practical requirement for entering the public market. Business operators looking to supply AI solutions to public and B2B sectors need to check in advance the verification entities and procedures that will be finalized through future public notices.
The other is that the dual coordinates of global regulations must be read simultaneously. While a relatively moderate regulatory environment centered on promotion is being established domestically, high-risk classification and transparency obligations remain core variables in overseas markets, including the EU. In particular, since the deadlines for content transparency obligations such as watermarking in the EU have been brought forward, the industry consensus is that services dealing with deepfakes or AI-generated images need to preemptively check overseas standards separately from domestic criteria.
6. Outlook — July Implementation and Tasks Beyond
If the current trend continues, the revision of the enforcement decree is expected to be finalized around July 21, and new systems such as promoting the introduction and utilization of AI in the public sector and establishing AI research institutes will operate in earnest. However, as it is a draft at the legislative notice stage, the possibility remains open that detailed criteria—such as the specific scope of vulnerable groups or verification procedures for public procurement targets—may be adjusted during the public comment, regulatory review, and legal review processes. Even after implementation, how the public procurement verification system actually operates in the market and the extent to which MSIT public notices broaden the targets are expected to be the keys determining the effectiveness of the system.

