An amendment to the AI Framework Act (Article 33-2, newly added, and Article 34(1), adding items 6 and 7) would give the government a legal basis to designate and manage "high-risk AI models" — those with a potential to cause serious harm to national security or public safety — and to build a nationwide cyber-threat response system for high-impact AI. The bill moved from committee referral to committee review on 2026-09-08; it is not yet law, and no threshold, effective date, or penalty has been set. Developers and operators of AI models that could plausibly be designated high-risk (e.g., models implicated in AI-enabled cyberattacks, large-scale disinformation generation/distribution, or breaches of critical national data) are the group to watch.
What this means for you
- No action is required yet. This is a bill at the committee-review stage, not an enacted duty — there is no designation criterion, threshold, effective date, or penalty in force.
- Track the designation criteria as they firm up. The current text does not define what makes a model "high-risk" beyond the national-security/public-safety framing; that definition will determine who is actually reached.
- If your AI service touches security-sensitive functions (e.g., infrastructure-adjacent systems, large-scale content generation, or data classified as nationally significant), flag this bill for follow-up rather than treating it as settled law.
- Watch for a companion cyber-threat response framework. The bill also proposes a government-run response system for high-impact AI cyber threats, which may carry its own cooperation or reporting expectations once the mechanism is defined.
Source: