The AI Framework Act Is Now in Force — What Should SMBs Do Now
A one-page summary of the obligations the AI Framework Act (in force since January 2026) imposes on small and mid-sized businesses, how to tell whether your AI is high-impact, and what to prepare during the grace period.
It's easy to think regulation is a big-company problem. But this time, the smaller you are, the more at risk you are.
Korea Now Has an AI Law Too
In January 2026, the Framework Act on the Development of Artificial Intelligence and Establishment of Trust — the AI Framework Act for short — came into force. Following the European Union (EU), it is the world's second comprehensive AI law.
Yet most of the small and mid-sized businesses that will feel this law's impact the most don't even know they're in scope.
In our Security and Privacy post, we talked about "what you must protect when using AI." This time, we cover the situation where that has become not a recommendation but a law.
"But We Don't Build AI?"
This is the most common misconception. The law doesn't apply only to companies that develop AI. It also covers companies that take AI, attach it to a service, and offer it to users.
In other words, whether you call someone else's AI via API or add a chatbot to your homepage, you are already on this law's stage.
One 20-person online education company we advised thought, "We just integrated an external AI." But that AI was evaluating students' learning achievement. This is an area the law pays special attention to.
The Heart of It Is 'High-Impact AI'
The law does not treat all AI the same. Its center of gravity is high-impact AI — AI that can significantly affect people's life, physical safety, or fundamental rights.
Representative areas include the following.
1. Hiring and personnel evaluation — using AI to screen or rank applicants 2. Lending and credit screening — AI judging financial eligibility 3. Healthcare and health — AI intervening in diagnosis, prescription, or health management 4. Educational assessment — AI deciding learning achievement or pass/fail 5. Transportation and safety — judgments where people's safety is at stake
If your AI is used here in a way that judges people, you bear heavier obligations as a high-impact AI operator: advance risk notice, measures to ensure safety, and users' right to know that "this is a result judged by AI."
The Obligation That Remains Even If You're Not High-Impact: 'Labeling'
It's too soon to relax by saying, "We don't judge people."
Content created by generative AI carries a labeling obligation to disclose that it was made by AI. AI-written product pages, AI-generated images or audio, AI chatbot responses — you must let users know so they don't mistake AI for a human.
The smaller the company, the more easily this part gets neglected. Many make half of their marketing content with AI while disclosing that fact nowhere.
Fortunately, There's Time
The government isn't punishing companies right after the law took effect. It has decided to set a grace and guidance period of at least one year. During this period, operation focuses on guidance and education, and fact-finding investigations occur only in exceptional cases where a serious social problem arises.
That means, in short, that now is the time to prepare. Moving only after the grace period ends is too late.
Four Things SMBs Can Do Now
There's no need for anything grand. This much is enough to make good use of the grace period.
1. Make a list of your AI Write down in one page where and what AI you're using. Most companies don't even have this list.
2. Self-diagnose whether it's high-impact Flag which of them are used to 'judge people.' If any are, address them as a priority.
3. Attach AI labels Mark AI-created content and AI chatbots with "generated/answered by AI." This is the easiest and fastest measure.
4. Keep minimal records Record which AI you used, with what data, and for what purpose. If you have an AI usage policy, this fits naturally on top of it.
Regulation Isn't a Risk, It's a Signal
This law isn't meant to block AI. It's meant to make AI something you can use with trust.
For a prepared company, regulation instead becomes proof of trust. A company that can say "this is how responsibly we use AI," versus one that mumbles at such a question. Customers will soon start to tell the two apart.
Being small is not a reason to dodge regulation — it's an opportunity to get organized first and pull ahead.
This post is intended for general understanding. For whether specific obligations apply, we recommend confirming against the actual statutes and enforcement decrees, and where necessary, through expert review.