What high-impact AI is: a complete guide to AI that affects people's safety and fundamental rights, and the duties of providers

High-impact AI is a concept under Korea's AI Basic Act referring to AI that has a significant impact on, or risks endangering, human life, physical safety or fundamental rights, and businesses that provide it bear duties such as risk management, explanation, and human management and oversight.

Why you need to understand high-impact AI

AI has begun to be used in decisions about people.

When AI only summarised documents or helped with search, people had ample room to correct wrong results. Now AI is also used in judgements that directly affect a person's rights and opportunities, such as recruitment, credit assessment and loan screening. When such judgements go wrong, the harm can be hard to reverse.

In Korea, the act on the development of artificial intelligence and the establishment of a foundation of trust, commonly called the AI Basic Act, has been in force together with its enforcement decree since 22 January 2026. The act classifies AI that can significantly affect people's safety and fundamental rights as high-impact AI, designates 10 areas including recruitment and loan screening, and sets separate duties for the businesses that provide it.

Companies that do not develop models themselves but use external AI are no exception. Any organisation planning to apply AI to its work should first check whether its service falls under high-impact AI and, if so, what it needs to prepare.

What high-impact AI actually is: how it differs from general AI services

General AI services and high-impact AI across three axes

First, the basis for classification differs. High-impact AI is determined not by which technology is used but by where the AI is used and what effect it has on people. Even with the same model, the assessment can differ between use for internal document search and use in screening decisions about people.

Second, the duties of the business differ. Services using generative AI have obligations such as informing users of that fact in advance, and the methods of notification and labelling are covered by the transparency guidance issued by the Ministry of Science and ICT. High-impact AI additionally requires a risk management plan, an explanation plan and a user protection plan, together with a system for human management and oversight.

Third, the level of records to keep differs. General services focus on delivering results. For high-impact AI, documents confirming the measures taken to ensure safety and reliability must be prepared and retained, so the decision process and the measures taken must remain on record.

In many cases it is not clear whether a service qualifies. The act provides a procedure for requesting confirmation from the Minister of Science and ICT as to whether a service is high-impact AI, with related documents such as a service overview attached.

Five duties businesses providing high-impact AI must meet

The five duties set by the act

First, establish and operate a risk management plan. Businesses must identify and manage the risks that can arise when AI judges wrongly, and ensure that the plan is actually followed in operation.

Second, establish and implement an explanation plan. Prepare a way to explain the results produced by the AI and the criteria used to reach them.

Third, establish and operate a user protection plan. Prepare and operate measures to protect users affected by the AI's judgements.

Fourth, ensure human management and oversight. Put in place a system through which people can check the AI's judgements and correct them when necessary.

Fifth, prepare documents confirming the measures taken to ensure safety and reliability, and retain them for 5 years.

Detailed standards for each duty are set in subordinate legislation such as the enforcement decree, so actual preparation should proceed while checking the original legal texts.

How to prepare for high-impact AI in practice

Check applicability task by task

List the work in the organisation where AI is used or planned, and mark for each whether the AI's results are used in decisions about people. The size of the impact depends on whether staff only refer to the results or whether they feed directly into decisions.

For work that is hard to judge, obtain a legal review and use the confirmation request procedure where necessary. Recording the results of the check and the reasons for the judgement also provides a basis for reviewing again when the work changes or the use of AI expands.

Keep the grounds and history of judgements

To meet the explanation and document retention duties, it must be possible to show later how the AI reached its results. If an AI Agent is used for document review, record for each case the location in the original that grounded the judgement, the rules applied, and the versions of the model and rules used.

Records must be in a form people can read in order to respond to users' requests for explanation or objections. When a model or rule is changed, also keep the before-and-after comparison of results and the approval record.

Place human confirmation on final decisions

Human management and oversight is hard to satisfy with a formal signature. Provide a review screen that shows the AI's judgement together with its grounds, and keep records of what people approved or corrected. Design the flow so that cases that deviate from criteria are automatically passed to staff.

High-impact AI in the Korean environment

The AI Basic Act treats as AI businesses not only those that develop and provide AI but also those that provide products or services using AI made by others. A company that connects an external model via API to build a screening tool may also be subject to the duties.

The government has stated that it will set a guidance period deferring fact-finding investigations and the imposition of administrative fines for at least 1 year. However, a guidance period is time to prepare, not a period without obligations, so it is better to start early on preparations that take time, such as record-keeping systems.

Frequently asked questions

It may. Businesses that provide services using AI made by others are also included among AI businesses, so if the use falls under high impact, the duties should be reviewed.

It is judged by where the results are used rather than by the technology that reads documents. If the results are used in screening decisions about people, applicability should be reviewed.

The business reviews it first and, if it is hard to judge, can request confirmation from the Minister of Science and ICT.

Even if they are not high-impact AI, there is a notification obligation to inform users in advance that a product or service operates on the basis of generative AI.

The government has stated that it will set a guidance period deferring fact-finding investigations and fines for at least 1 year. Check government announcements for when it ends and how it will operate in detail.

Human management and oversight is one of the duties, so having a confirmation procedure does not remove the others. Risk management, explanation and document retention must also be in place.

This article is an explanation to help understand the term. Specific applicability and responses should be decided after checking the original act and subordinate legislation and obtaining expert review.

Related terms