South Korea just legalised training AI on your data without consent. Read the clause and it legalised almost nothing — it delegated everything.
The amendment that passed in Seoul on Wednesday does not set a rule. It hands a regulator the pen and asks the world to trust the handwriting — an alternative to Europe's model that may travel further than the statute itself.

Image: Joongwon Lee (SKKU DOA) / Wikimedia Commons (CC BY-SA 4.0)
The headline that travelled out of Seoul on Wednesday was blunt: South Korea has legalised training artificial intelligence on people's personal data without their consent. On August 20, the National Assembly passed an amendment to the Personal Information Protection Act — PIPA, the country's GDPR — creating a new legal route to use lawfully collected personal data for AI development, in some cases in its original, identifiable form, without asking the people it describes. The reported version is not wrong. It is just not the law. The law is narrower, stranger, and in one specific way more consequential than the headline admits.
What the text does is not declare a right. It creates a set of special provisions — draft Articles 28-12 through 28-15 — that let a data controller apply to use lawfully collected personal data, including in non-pseudonymised form, for AI development, without consent and beyond the purpose for which it was first gathered. The operative word is 'apply.' The permission is not written into the statute. The statute writes a door, and puts a regulator's desk on the other side of it.
What the text actually requires
Read the conditions and you find four of them, each a judgement rather than a threshold. First, anonymisation or pseudonymisation must not suffice — the applicant has to show that stripped or masked data cannot do the job and that identifiable data is genuinely necessary. Second, the use must serve a public interest, the protection of the data subject or a third party, or a social benefit. Third, the risk of unfair infringement of individuals' rights must be 'markedly low.' Fourth, safeguards must be in place. Notice what none of those are. 'Markedly low' is not a number. 'Social benefit' is not a definition. 'Sufficient safeguards' is not a checklist. The statute sets the questions with care and answers not one of them.
Someone has to answer them, and here is the pivot of the entire amendment: the someone is the Personal Information Protection Commission, the PIPC, deciding case by case. The Commission approves applications one at a time, weighing a mandatory advance risk assessment built on the AI Privacy Risk Assessment and Management Model it established in December 2024. When the PIPC set out its parallel guidance earlier this summer, it chose its words precisely — what it offers is 'not permission, but clearance.' That distinction is not decoration. Permission is a rule you can read in advance and rely on. Clearance is a decision an official makes about you, after you ask.
The amendment does not tell you what is allowed. It tells you whom to ask. That is not a smaller law. It is a different kind of law. — Lena Haas
In force, and then enforced
The useful question about a new statute is rarely whether it is in force. This one cleared its committees on May 14 and July 29 and passed the floor on August 20; it takes effect six months after promulgation, which places the live date in early 2027. But 'in force' and 'enforced' are unusually different documents here. The statute comes into force as a frame. Its content — what actually gets approved, on what evidence, under which safeguards — is written afterward, application by application, in a venue that publishes no operative text you can quote back. The load-bearing date is therefore not the vote in the Assembly. It is the first cohort of PIPC decisions, because those decisions, not the clause, are the law companies will really live under.
The amendment also sits on top of a move the regulator had already made. On July 3, the PIPC said that lawfully collected raw data — video, voice, images with identifiers intact — could be used to train AI, on the reasoning that the very signals a model needs to learn are the ones pseudonymisation erases. That was guidance. The amendment gives it a statutory spine. Together they shift Korea from 'mask the data, then use it' to 'justify the identifiable data, clear it with the regulator, then use it,' with heightened scrutiny reserved for three sectors where the stakes are highest: telecommunications, education and employment.
The inversion Europe should notice
To see why this matters past Korea's borders, set it beside the regime it is quietly competing with. Under the GDPR, the first question is always the lawful basis: you must stand on consent, or legitimate interest, or another named ground before you process anything, and pseudonymisation is a supplementary measure that helps you defend the basis you have already claimed. Korea reverses the order of operations. There, pseudonymisation — and now, PIPC clearance for identifiable data — is not a measure that supports a basis. It is the gateway that unlocks the secondary use in the first place. Europe asks, 'on what basis are you processing?' Korea asks, 'have you cleared it?' The values overlap. The architecture is inverted.
For a decade the working assumption has been that Europe writes the world's privacy grammar and everyone else conjugates it — the effect that turns a rule drafted in Brussels into the default setting of the global internet. What passed in Seoul is the first serious counter-grammar from a major technology exporter: a discretionary, risk-based, regulator-cleared model built specifically to give AI development a lawful path to identifiable data that the basis-first structure of European law makes deliberately hard. No company builds a separate data pipeline for one jurisdiction if it can avoid it. If the Korean model proves workable — clearances fast enough to be usable, safeguards defensible enough to survive scrutiny — it becomes a template other governments can lift: governments that want a domestic AI industry and find the consent-first path too slow to feed one. A rule made in Seoul could become the operating default in capitals that never debated it. That is how these things have always travelled.
Trusting the regulator, not the rules
Which returns to the feature at the centre of the whole design. A rule binds the regulator as much as the regulated; a discretion binds only the person who has to come and ask for it. The safeguard in this amendment is not a bright line a company may not cross. It is the PIPC's judgement, exercised privately and case by case, that a given project's risk is 'markedly low' and its benefit 'social' enough to clear. That can be administered well, by a serious and well-resourced authority. It can also drift, slowly and without any single visible decision, toward whatever a steady stream of sophisticated applicants can persuade the desk to accept. And the citizen's counterweight is thin. In July 2025, Korea's Supreme Court held that a data subject cannot even demand the suspension of pseudonymised processing, on the reasoning that it does not amount to 'processing' that triggers the right — a ruling that leaves a real gap between the rights the law recites and the remedies a person can actually reach.
So read past the headline. Korea did not simply legalise training AI on personal data without consent — several jurisdictions are edging toward that, and Europe's own arguments over legitimate interest are heading somewhere similar by a different road. What Korea did was choose a mechanism: delegate the decision to a regulator, and replace the rule with a review. It is betting that trust in an institution can carry a weight the text itself declines to bear. Whether that reads, in a few years, as prudent flexibility or as an accountability shortcut will be settled not in the Assembly but at the Commission's desk, in decisions most of us will only ever see through their consequences. The clock has started. The rules have not been written. That, and not Wednesday's vote, is the part worth watching.
References
- IAPP — Trusting the regulator, not the rules: South Korea's AI data amendment
- MLex — South Korea creates new legal pathway for personal-data use in AI development
- IAPP — Pseudonymization as a gateway to AI data use: South Korea's emerging privacy governance model
- Pebblous — Korea Opens Raw Personal Data to AI Training Without Masking
- Chambers — Data Protection & Privacy 2026: South Korea, Trends and Developments


