What happened
South Korea's amended Personal Information Protection Act (Act No. 21445, promulgated March 10, 2026) took effect on September 11, 2026. The amendment introduces a structured legal pathway for AI model training (Article 28-2 pseudonymization exemption for 'scientific research' including AI training), raises maximum fines to up to 10% of global revenue for aggravated violations, imposes CEO-level personal supervisory liability for data protection failures, and tightens breach-notification timelines. The law applies extraterritorially to any entity processing the personal data of South Korea's ~51 million residents for AI training or deployment purposes.
Why it matters
This is now a binding statute in force, not a proposal — any organization training or deploying AI models using data linked to Korean residents (including foreign AI labs) faces direct extraterritorial exposure to revenue-based fines and mandatory governance/documentation obligations at both the training and deployment stages. It is one of the most consequential binding AI-data statutes to take effect globally in this window.
Action needed
AI developers and deployers processing Korean personal data should immediately document lawful bases for AI training and deployment activity, confirm pseudonymization procedures meet Article 28-2 standards, and designate board-level/CEO accountability for data protection compliance.