AI Compliance · Far East

South Korea's AI Act reaches you from abroad. Japan's has no penalties. Neither leaves you clear.

Four countries, four answers, and the mistake almost everyone makes is to read "no EU-style AI Act" as nothing to comply with. Three of these tie AI to the law they already had about personal information — which binds, carries penalties, and started applying to your AI the day you switched it on. The fourth wrote an AI Act and gave it real reach.

South Korea is the one that legislated properly. Its Framework Act is in force, it reaches conduct outside Korea by the effect that conduct has on the Korean market, and it wants people told when they are dealing with AI and what it generated. Two things about it are widely reported wrongly. It binds the AI industry rather than everybody who uses a tool, so the first question to answer is whether what you sell is itself an AI product or service. And the duty to put a representative in the country is described everywhere as reaching only giants, when ten billion won of AI-service turnover reaches it — and a previous fine reaches it at no size at all.

Japan legislated first and deliberately left the teeth out. Its AI Act sets national policy, asks businesses to co-operate with government guidance, and leaves enforcement to the laws that already existed. Government can investigate a bad case and say publicly what it found, which for a professional firm is the penalty that actually matters.

China is the one most often described wrongly. Its headline generative AI rules — filing, security assessment, labelling — address whoever PROVIDES such a service to the public in China. If you are a firm that merely uses AI, they are not aimed at you. What is aimed at you is the Personal Information Protection Law, which reaches outside the country and asks for a representative inside it however little data you hold.

Singapore did not legislate at all, and then published the most detailed account anywhere of how its binding personal data law applies to AI. Advisory in form. An instruction manual in substance.

What actually governs AI in Japan, South Korea, China and Singapore.

No summaries of summaries. Each of these was read at the publisher's own site, and the obligation is stated as the thing you have to do rather than the clause it comes from.

Japan

The law

The Act on Promotion of Research and Development, and Utilization of Artificial Intelligence-related Technology, alongside the Act on the Protection of Personal Information, which is the one with penalties.

What you have to do

Co-operate with national AI policy and with the guidance the ministries issue, and handle personal information lawfully in everything your AI touches. The AI Act sets no fine; government can investigate a harmful case and publish what it found. The personal information law reaches a business outside Japan that handles the personal information of people in Japan in connection with supplying them goods or services, and it does not require that business to appoint a representative or agent in Japan.

Voluntary, and asked about anyway

Japan led the Hiroshima AI Process and runs a reporting framework through which companies publish how they are meeting the international code of conduct. Voluntary, visible, and increasingly a question on a Japanese partner's due diligence form.

South Korea

The law

The Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, alongside the Personal Information Protection Act.

What you have to do

The Act binds the AI industry — firms that develop AI, and firms that use somebody else's AI to provide an AI product or service of their own. Where that is you: tell users in advance when a product runs on generative or high-impact AI, and label what generative AI produces. Screening job applicants and assessing loans are named high-impact, which requires a risk management plan, an explanation of how results are reached, human supervision, and documents kept to prove all of it. A formal impact assessment is a duty to try rather than a duty to do — but public bodies must give preference to products that have had one. Conduct outside Korea is caught by its effect on the Korean market, and the duty to appoint a representative there begins far lower than it is usually reported: ten billion won of AI-service turnover triggers it, and a previous fine triggers it whatever your size. The Personal Information Protection Act has its own, separate duty: a business with no address or office in Korea must designate a domestic agent there only if its total sales for the previous year reached one trillion won, it held the personal information of an average of at least one million people in Korea, or the Commission has asked it for materials and decided it needs one. Total sales are converted into won at the previous year's average exchange rate.

China

The law

The Personal Information Protection Law, which reaches businesses outside China that handle the personal information of people in China in order to offer them products or services, or to analyse their behaviour. The generative AI rules behind it — the Interim Measures for the Management of Generative Artificial Intelligence Services, and the labelling provisions — bind whoever provides such a service to the public, not every firm that uses one. Providing one means using generative AI to offer the public in China a service that produces text, images, audio or video, including through somebody else's model: a chatbot on your own website that people in China use is your service, not the model maker's. A firm that uses AI only inside its own business is outside those rules.

What you have to do

Have a lawful basis for personal information about people in China, and appoint a representative or an agency inside the country if that reach is the only reason you are caught — it turns on being caught, not on how much data you hold. If you are the one providing a generative AI service to the public there, the provider duties are yours as well: label what it generates, act on unlawful content, and run a complaints route. Filing and a security assessment are needed only where the service has public-opinion attributes or the capacity to mobilise people.

Singapore

The law

The Personal Data Protection Act. There is no AI-specific statute.

What you have to do

Have a lawful basis for the personal data that trains and runs your AI, be able to say who is accountable for it along the supply chain, manage what the system gets wrong, and tell people where AI is involved in something that affects them. Designate at least one person to be responsible for your compliance with the Act, and make that person's business contact details available. The Act does not require that person, or any representative, to be in Singapore.

Voluntary, and asked about anyway

The Personal Data Protection Commission published its Advisory Guidelines on Use of Personal Data in Generative AI on 20 July 2026, following earlier guidelines on AI recommendation and decision systems. Advisory in form, and an account of how a binding law will be applied.

16 dates that decide whether you are compliant.
10 of them have already passed.

South Korea is one line of 8. South Korea's line is marked: it wrote an AI law with a commencement date and a penalty behind it. China is on the chart for the opposite reason — its line is the personal information law rather than an AI law, which is exactly why firms miss it. Japan's AI Act carries no penalty, so nothing falls due on its date and it is not drawn, and Singapore has no statute to draw.

Europe

  • in force Obligations for general-purpose AI models.
  • in force Article 50 transparency duties, deployer obligations, and enforcement powers for national regulators.
  • coming New prohibitions, and Article 50(2) marking of synthetic content.
  • coming Every Member State must have an AI regulatory sandbox running.
  • coming High-risk obligations for Annex III systems — including AI used in recruitment, credit scoring, education and essential services.
  • coming High-risk obligations for Annex I systems — AI embedded in products already covered by EU product safety law.

United Kingdom

  • in force Most Part 5 data protection provisions of the Data (Use and Access) Act 2025, including the wider lawful bases for solely automated decisions and the safeguards that come with them.
  • in force The duty on controllers to operate a complaints procedure and respond to data protection complaints within set time limits.

United States

  • in force Texas HB 149, the Responsible Artificial Intelligence Governance Act — prohibited uses, government AI disclosure, and Attorney General enforcement.
  • in force California SB 942, the AI Transparency Act — free AI detection tool and latent provenance disclosure for large generative AI providers. Delayed from 1 January 2026 by AB 853.
  • coming Colorado SB 26-189 — developer and deployer duties for automated decision-making technology used in consequential decisions. It repealed and reenacted SB 24-205, which never took effect.

Canada

  • in force Ontario ESA / O. Reg. 476/24 — a publicly advertised job posting must disclose the use of AI to screen, assess or select applicants. Employers of 25 or more, including where a third party screens on their behalf.

Australia

  • coming Privacy Act 1988 (Cth), APP 1.7 — a privacy policy must say what kinds of personal information a computer program uses to make decisions that could reasonably be expected to significantly affect a person, and what kinds of decisions those are.

United Arab Emirates

  • in force DIFC Data Protection Regulation 10 — a business deploying an autonomous or semi-autonomous system that processes personal data must tell users, on first use, what the system decides for itself, what it was built to do and what it does with the output.

South Korea this page

  • in force Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust in force. A business in the AI industry must tell users in advance where a product runs on generative or high-impact AI, and label what generative AI produces. It applies to conduct outside Korea that affects the Korean market or its users.

China

  • in force Personal Information Protection Law in force. A business outside China that handles the personal information of people in China — to offer them products or services, or to analyse their behaviour — must have a lawful basis for it and must appoint a representative or a dedicated body inside the country. Nothing in the duty turns on how much data is held.

Does this apply to you?

Most firms read a page like this and conclude it is about somebody bigger. These are the things that decide it, and the first one catches almost everybody.

  1. You use generative AI on anything containing customer or staff information.
  2. You are in somebody's supply chain and cannot yet say who is accountable for the AI in it.
  3. You are bidding for work, or courting a Japanese partner, where alignment with a published AI framework is a question on the form.
  4. You have Korean customers and your AI answers them, drafts to them or scores them, and nothing on screen says so.
  5. You sell to people in China, or analyse what they do, and assumed the AI rules there were somebody else's problem. The AI rules may well be. The personal information law is not.

What we would do about it.

We build AI compliance frameworks — the policy, the register of where AI touches your business, the record that shows a regulator you thought about it before something went wrong. Fixed price, plain English, written for a business owner rather than a lawyer.

Every price, every line and every figure below is read from the same place the checkout reads it, so what the page says and what you are charged cannot drift apart.

Far East AI Compliance Complete
£1,497/year
  • Everything in Far East AI Compliance Foundation
  • Local representative requirements assessment
  • Consumer-facing AI transparency disclosures
  • AI Risk Register (populated for your current tools)
  • Incident Response Procedure
  • HR AI procedures and disclosure templates

In your inbox by the end of the business day · annual — covers you for 12 months, renews yearly, legal updates included

Buy Complete — £1,497/year →

Not sure which countries reach you? That is the first document in both tiers, and it names the ones that do not as well as the ones that do. If you would rather talk it through first, the call below is free and there is no pitch deck.

See a real one

Read it before you buy it.

This is not a mock-up or a contents page. It is a genuine Far East AI Compliance pack — all 11 documents — produced by the same system that will produce yours, for a fictional translation agency we invented to test it. They have no office anywhere in Asia, sell an AI-assisted service into Korea and take orders from individuals in China. The pack says which of the region's laws that brings them under, and which it does not.

Sample pack, page 1 Sample pack, page 2 Sample pack, page 3 Sample pack, page 4 Sample pack, page 5 Sample pack, page 6 Sample pack, page 7 Sample pack, page 8
3 / 8
Open the full sample pack

Opens the PDF exactly as a client receives it. Yours is written around your business, your tools and your sector — not this one.

Find out where you stand in Far East.

A free call, no pitch deck. We will tell you which of the obligations above reach your business and which do not — including if the answer is none of them.

Call Now Claim Your Free Audit