South Korea’s privacy chief outlines a progressive approach to AI governance, emphasising guidance, privacy by design, and flexible rules amid rapid technological advances and a new legal framework.
South Korea’s privacy chief is trying to redraw the boundaries of data protection for an AI economy that is moving faster than the law’s traditional consent model. Song Kyung-hee, chair of the Personal Information Protection Commission, said the country needs rules that preserve privacy without choking off innovation as generative AI gives way to AI agents and physical AI devices that can exchange information with little or no direct human intervention. She said the aim is to reduce uncertainty on the ground through guidance first, then move only the most necessary rules into formal regulation.
Her comments come as South Korea begins implementing a broader AI legal framework. The AI Basic Act took effect on January 22, 2026 and is designed as a framework law, with detailed compliance obligations still being filled in through subordinate rules. Legal analyses published this year say the act introduces transparency duties, a risk-based regime for high-impact systems and extra-territorial application, putting South Korea among the first major jurisdictions outside the European Union to adopt a comprehensive national AI statute.
Song argued that this kind of staged regulation is better suited to a technology landscape that is still changing rapidly. In an interview with E-Daily, she said it would be a mistake to lock every AI scenario into statute at once because many outcomes are still only visible as possibilities, not settled business models. The commission’s approach, she said, is to issue guidance, test how it works in practice and then elevate only the rules that prove necessary into formal notices, instructions or law.
That philosophy also underpins the recent special rule allowing the use of personal data for AI training, which Song described as a potentially transformative provision if paired with safeguards. Industry guidance released in 2025 and 2026 has already tried to clarify how South Korea’s privacy law applies across the AI lifecycle, including model training, deployment and the handling of publicly available data. Song said the real goal is to let useful innovation proceed while keeping the protections proportionate and workable.
She also acknowledged that traditional consent mechanisms are reaching their limits. If AI agents are carrying out tasks on behalf of users, and if devices such as smart glasses can capture bystanders as easily as they capture the wearer’s view, case-by-case consent is not a practical control, she said. The commission is therefore pushing privacy by design, meaning systems should be built from the outset to minimise data collection and exposure. Song said the regulator is preparing guidance with experts and wants third parties to be able to recognise when they are being recorded and, where appropriate, refuse.
The same shift towards front-loaded control is shaping South Korea’s treatment of web scraping and data portability. Song said the country is trying to move activity that once happened quietly and without oversight into a system of prior coordination, where data access is agreed in advance and technical interfaces such as APIs can replace uncontrolled harvesting. She said August 20 marks an initial checkpoint in that transition, not a hard stop, and that the purpose is to create a smoother path for services while making clear how much information is being taken and under what terms.
Enforcement is moving in parallel. Song said the commission will still punish deliberate concealment or destruction of logs after a breach, describing such conduct as an attempt to evade responsibility after the fact. But she also pointed to a more nuanced penalty regime that rewards real security investment and rapid recovery. As South Korea raises possible fines to as much as 10% of total revenue from September 11, the commission is trying to distinguish unavoidable incidents from failures to meet minimum security standards. Song said the country’s strict privacy regime can itself become a commercial advantage, because services built and approved under Korean rules may be seen abroad as safer and more trustworthy.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





