South Korea: New AI Act
The Korean Ministry of ICT and Science has published a Notice on Methods for Complying with Obligations Regarding Artificial Intelligence Safety.
It specifies the necessary matters regarding the specific implementation methods for measures to ensure the safety of artificial intelligence and the submission of implementation results.
In accordance with the act:
① An AI business operator shall consider the following matters to identify risks:
- The lifecycle and specificity of AI;
- Technical characteristics of AI, such as the possibility of functional errors, data bias, and security vulnerabilities;
- The possibility of misuse and abuse of AI.
② An AI business operator shall establish procedures and methods to systematically identify risks within a reasonably foreseeable scope and shall systematically manage risks.
③ An AI business operator shall document and systematically manage risks, including the following matters, in relation to risk identification.
- Risk Identification Number and Name
- Time of Risk Identification
- Risk Identification Method
- Risk Identification Result
① An AI business operator shall assess the materiality and manageability of risks, the feasibility of risks, and the severity and frequency of their impact, etc., in order to systematically manage risks identified pursuant to Article 4 and to establish appropriate response measures.
② An AI business operator shall establish a risk assessment organization to assess risks. In this case, external agencies or experts may participate in the risk assessment organization.
③ An AI business operator shall establish assessment criteria, assessment methods, and procedures to objectively assess risks, and shall endeavor to ensure that the risk assessment organization established pursuant to Paragraph 2 operates independently.
④ An AI business operator may seek assistance from external agencies or experts to verify the results of the risk assessment pursuant to Paragraph 1.
⑤ In relation to the risk assessment pursuant to Paragraph 1, an AI business operator shall document and systematically manage the following matters:
- Risk identification number and name
- Time of risk assessment
- Risk assessment method
- Risk assessment results

