Set Data, Approval, and Recovery Rules Before Adopting AI
Public-sector guidelines and Korea's AI Basic Act reveal why assigning data, approval, and recovery duties matters more than picking a model.
BusinessBefore You Pick a Model, You Need to Define the Job
When you adopt AI, it’s easy to start by comparing models. You want to check whether the answers are accurate, how fast the system runs, and how much it costs. But even after you’ve chosen a model, questions remain. What data should it have access to? Which outputs need a human to check them? And who handles it when something goes wrong?
I think of answering these questions as writing guidelines. Not long lists of abstract principles, but concrete decisions about who does what in actual operations. This work has to start alongside model comparison, and there needs to be a clear standard in place before you connect the system to anything that touches customers or citizens.
While preparing this piece, I went through public-sector AI documents in the order they were published. What caught my attention was a recent guideline that went beyond introducing the technology itself to cover planning, budgeting, contracting, building, and operating the system together. That struck me as treating AI adoption as something much broader than simply purchasing a single product.
The Public-Sector Guide Covers the Entire Service Development Process
The Ministry of the Interior and Safety (MOIS, South Korea’s interior ministry) released its “Public Sector AI Adoption and Utilization Guide” on June 10, 2026. The document breaks down how public institutions build services using the government’s shared AI infrastructure into five stages: planning, budgeting, contracting, construction, and operation.
Technology and operations aren’t treated as separate concerns here. For instance, the guide includes a strategy prioritizing RAG. RAG (Retrieval-Augmented Generation) is a method where AI first searches an institution’s documents and then answers based on what it finds. This reduces reliance on what the model has simply memorized, but errors can still occur if the documents are outdated or if the search or response process goes wrong.
Using shared infrastructure also relates to the burden of institutions redundantly building similar equipment and systems. It’s not just about what service to build — institutions also need to decide how to use the existing shared infrastructure and who will operate it.
MOIS explained that the guide was prepared to respond to the shared-infrastructure-first clause in the revised law taking effect on August 28. MOIS’s guide release materials.
What strikes me here isn’t the volume of documentation. It’s that the guide has started addressing, concretely, the budget, contracting, and operational responsibilities needed to actually integrate AI into real administrative work. The mere fact that multiple guides have been issued doesn’t mean most of public-sector AI’s achievements so far have just been paperwork.
The draft looks accurate and complete. No corrections needed.
Public agencies’ AI service lists need to show exactly what’s being used
Starting August 28, Korea’s “Act on the Promotion of Data-Based Administration” was renamed and enforced as the “Act on the Promotion of AI- and Data-Based Administration.” Several provisions were added regarding public agencies’ use of AI.
Article 27 requires the Minister of the Interior and Safety and the Minister of Science and ICT to build and operate shared infrastructure, and obligates the heads of public agencies to make efforts to use that infrastructure preferentially when adopting AI. Article 30 requires agencies to manage the current status of the AI services they provide—their type, purpose, data used, and so on—and to submit this to the Minister of the Interior and Safety, who must then publish the list annually.
Article 31 requires the Minister of the Interior and Safety to establish and publish ethics standards to apply to public agencies. The heads of agencies must make efforts to establish policies and training aligned with those standards. As you can see, the party bound by the obligation and the content of that obligation differ from article to article.
Submitting the list isn’t the only obligation, either. The same law also contains provisions on securing the quality of training and learning data. A newly established provision on public-sector impact assessments takes effect later, per the supplementary rules. You shouldn’t assume that all the newly added provisions took effect simultaneously on the day the law’s name changed. The amendment text and supplementary provisions.
Among all this, I think managing the service list can serve as a starting point for actual practice. You need to know where AI is being used in order to identify who’s responsible, what data is involved, and what the risks are. That said, submitting a list doesn’t automatically make the actual usage picture accurate. When a service changes, you need someone—and some process—to update the record.
Looking at the draft against the source, the translation is accurate, complete, and faithful to all numbers, structure, and links. No Hangul remains, all four paragraphs are preserved, and the single link matches.
Even confirming “high-impact AI” status requires explaining your service
Private companies also need to lay out a service’s purpose and how it works before completing another procedure: confirming whether it qualifies as “high-impact AI” under the AI Framework Act.
Operators are expected to review this themselves beforehand, and can request confirmation from the Ministry of Science and ICT if needed. This doesn’t mean every company must get prior government approval every time it tests an AI system.
Article 25 of the enforcement decree requires that a confirmation request include an overview of the product or service, an overview of the data used in development and training, materials to verify how the system is used and what results it produces, and any other supporting documents. The default response period is 30 days, extendable once by up to 30 more days depending on complexity. There’s also a process for requesting a re-review within 10 days of receiving the result if you disagree with it.
Simply stating which model you’re using isn’t enough to fill out these materials. Even the same model requires a different scope of review depending on who it’s provided to, for what purpose, and what decisions it’s entrusted to make. You can also work on service design and data preparation in parallel while going through the confirmation process. AI Framework Act Support Desk’s guide to the law and enforcement decree.
Check who’s covered before you post the manager’s name or archive records
Article 34 of the AI Basic Act places obligations on businesses that provide high-impact AI or products/services using it: risk management, explanation measures, user protection, human oversight, and preparing and keeping documentation to verify what actions were taken.
Article 27 of the Enforcement Decree requires posting the key details of these obligations at the business office, place of business, or website. This includes the risk management plan, explanation measures, user protection measures, and the name and contact information of the person who manages and oversees the high-impact AI in question. There’s also an exception for trade secrets.
I paused for a moment on that item — the manager’s name and contact information. I read it as a requirement that users be able to identify who manages and oversees the operation, rather than which model was used. That said, this isn’t a blanket rule requiring every private company using AI to post a manager’s name on its website. You first need to check whether the obligation actually applies to your business and service.
The same article also requires keeping documentary evidence of compliance for 5 years. This shouldn’t be stretched to mean that every input, output, and entire conversation containing personal data must automatically be stored for 5 years. You need to work out, alongside this, what records are actually needed to prove which measures were taken, and how personal data and trade secrets will be handled.
Separately, Article 31, Paragraph 1 requires AI businesses seeking to provide products/services using high-impact AI or generative AI to notify users in advance that the service is operated on an AI basis. The management obligations for high-impact AI and the notification obligation for generative AI don’t share the same scope. Article 31’s advance notification obligation.
It’s worth keeping records even during the grace period
Korea’s AI Basic Act and its enforcement decree took effect in January 2026, and the government has announced it will run a fine grace period of at least 1 year to help with initial adjustment. This includes plans to support compliance through consulting and cost assistance. Government’s 2026 policy change guide, AI Basic Act section.
You shouldn’t treat the grace period as identical to the effective date of any individual obligation. The application of an obligation and the enforcement policy around sanctions are two separate things that need to be checked separately. You also need to check separately whether a given provision has its own statutory implementation delay.
In practice, rather than just asking whether a fine applies, it helps to keep a record of what judgment you made and what actions you took at the time. A few months later, when a service has changed or the person in charge has been replaced, it’s hard to reconstruct the reasoning behind a past decision from memory alone.
A good guideline answers real operational questions
What I check for in a guideline is scope of permission, decision-making authority, evaluation criteria, and error handling. For instance, here’s the kind of thing it can spell out.
| Question | What to define |
|---|---|
| What tasks are delegated | Whether it’s limited to drafting, or extends to customer communication and actual execution |
| What data is used | Accessible sources, and conditions for external transfer and storage |
| Who reviews it | The staff member responsible for approval, and the scope allowed to run without review |
| How success is judged | Success criteria, error/exception criteria, and how checks are performed |
| What gets logged | Records confirming decisions and execution, access permissions, and retention period |
| What happens if something goes wrong | How to stop the process, manual fallback, recovery procedures, and who to contact |
This table is the operational standard I’m proposing. Filling in each cell doesn’t mean you’ve satisfied every legal obligation. Conversely, even where the law doesn’t explicitly require a particular approach, you may still need additional controls depending on your operational risk.
NIST’s AI Risk Management Framework also addresses organizational accountability structures, understanding the context of use, and measurement and risk management together. Since it’s a voluntary framework, it’s better used as a reference for reviewing your own organization’s operations rather than treated as if it maps one-to-one onto Korean statutory requirements. Introduction to the NIST AI RMF.
Looking through this fragment, I compared it carefully against the Korean source. The translation is accurate, complete and idiomatic—no Hangul remains, no numbers to check (there are none in the source beyond “four,” which is correctly rendered as “four”), and structure matches exactly.
Run small pilots alongside standard-setting
There’s no need to copy public-sector procurement and audit procedures wholesale into a private organization. A pilot that drafts internal documents from public data and a service that touches customer accounts or payments should be held to different levels of readiness.
For low-risk work, you can start small with provisional standards and refine them as you observe real errors. Even here, it’s worth clearly defining the scope of the data, where the results will be used, and who has the authority to stop things if a problem arises. If you try to build a thick document from day one that anticipates every possible risk, you may lose the chance to actually learn from the pilot.
Standards need content people can actually act on. Rather than writing “use responsibly,” decide under what conditions automated execution should be halted and to whom it should be reported. If you’re going to use numeric thresholds, you also need to specify why that particular level was chosen, and over what time period and count it’s calculated.
The experience of choosing a model, and the evaluation data behind it, are also assets that stay with the organization. The reason I keep emphasizing guidelines isn’t that model selection is meaningless — it’s that you also have to decide how the chosen model will actually be used in real work. When the model changes, permissions and verification methods need to be reviewed again too.
For this week’s adoption discussion, I’d suggest starting by writing down four items: actions, data, approval, and recovery. Four items don’t make a complete policy, but they do let you identify who needs to make the next decision. I think a document has to be that concrete before a guideline actually helps with real execution.
💬 Is there something your organization still hasn’t decided about AI adoption? Tell me about your experience — whether it’s which tasks to hand over, the scope of data, or who’s responsible for approval and recovery.
Keep the perspective, not the noise.
We choose one consequential shift and trace what sits beneath it, every other day.
Confirm once to finish subscribing.
Already a subscriber? Sign in to join the conversation
References & Further Reading
- Ministry of the Interior and Safety distributes AI adoption and use guide for the public sector, June 10, 2026
- Amendments and supplementary provisions to the Act on Promotion of AI and Data-Based Administration
- AI Framework Act Support Desk’s legal statutes and enforcement decree materials
- Article 31 of the AI Framework Act — advance notice obligation
- NIST introduces the AI Risk Management Framework
Worth reading alongside this issue

Your take shapes the next issue
What resonated most in this issue, or where has your experience been different?