A proposed amendment to the AI Framework Act (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법) moved from committee referral to committee review on 2026-09-08. As drafted, it would add a new Article 15-2 and revise Article 5(1) to state that AI operators may use training data that does not constitute personal information for the development, training, validation, enhancement, and use of AI, and would require the Minister of Science and ICT to set detailed standards for such use in consultation with the Personal Information Protection Commission and other relevant ministries. Where training-data use results in data becoming personal information, or creates a re-identification risk, the bill would route that situation back under the Personal Information Protection Act. This is a bill under committee review, not enacted law — no effective date, threshold, or penalty has been set.

What this means for you

  • If you rely on non-personal training data for an AI product or service reaching Korea, track this bill. It is aimed at exactly the legal-uncertainty gap you may already be navigating — using data that isn't "personal information" under PIPA without a dedicated statutory basis.
  • Do not treat this as current law. The bill is at the committee-review stage; there is no confirmed effective date, and its provisions could change before (or if) it advances.
  • Watch for the follow-on standards. If enacted, the operative detail will sit in standards MSIT is required to develop with the PIPC — that is where thresholds, permitted uses, and re-identification-risk criteria will actually be defined.
  • Re-identification risk stays under PIPA regardless. The bill does not carve out an exception from personal-data rules — if your training data use produces personal information or a re-identification risk, PIPA continues to apply.
  • No source link was provided for this alert.

Source: