As the AI Basic Act enters into force, calls are growing to further break down obligations for AI operators according to their actual roles and scope of control. Critics say the current law does not differentiate between the responsibilities of model developers and service operators.
Industry and legal sources said on Wednesday that the AI Basic Act, which took effect in January, defines those subject to the law as AI operators. AI operators are divided into "AI development operators" that develop and provide AI and "AI use operators" that provide products or services using AI provided by development operators.
Companies that develop their own large language models (LLMs) and provide them externally fall under development operators. Companies that use external LLMs or APIs to build and provide customer services such as counselling chatbots, search, education and medical services could be classified as use operators.
By contrast, companies, individuals and others that use the output of AI services such as ChatGPT only for internal work or for producing content with AI in principle fall under general users.
The problem is that the actual supply structure of the AI industry is more complex than this two-way classification. For example, if a service operator receives an external LLM via an API and builds an AI service with a system integration provider, a model developer, API provider, cloud provider, builder and service operator are all involved in a single service.
A cloud or platform operator may further tune the model or apply safety measures. A service operator also links its own data and business rules and decides the permissions the AI can execute.
An AI industry official said control may differ depending on whether a service error stems from the model's own limitations, from the API connection or system build process, or from an operator granting incorrect permissions. The official said it was questionable whether the current law sufficiently reflects the structure of actual supply chains.
Both developers and service operators must label "AI-generated outputs". Who labels what?
The obligation to label AI-generated output is cited as a representative case that exposes the limits of the current operator classification.
Article 31 of the AI Basic Act requires AI operators that provide generative AI or products and services using it to indicate that the output was created by generative AI. The enforcement decree and guidelines allow not only human-recognisable phrases or logos but also machine-readable methods such as metadata.
But as both model developers and service operators that run apps or platforms using the model are included as AI operators, it is unclear what type of labeling each must implement. Model developers find it difficult to control final service screens or user touchpoints. Service operators, in turn, do not have the technical authority to directly embed metadata compatible with international technical standards inside model-generated outputs.
Sung-yup Lee (이성엽), a professor at Korea University's Graduate School of Technology Management, said that in relation to the AI-generated output labeling system, the role of distribution platforms such as YouTube should also be reviewed alongside development and use operators. He said introducing a concept of a distributor could be a solution.
Legal circles split on solutions, from creating a "model operator" to splitting duties by obligation
There are also differing views in legal circles on how to revise the AI operator framework. Proposals range from explicitly specifying foundation model providers as a separate subject of regulation to maintaining the current development and use operator framework while dividing individual obligations by function.
In-guk Kye (계인국), a professor at Korea University's Graduate School of Public Administration, argues that the concept of an "AI model" should be separately introduced into the current law to regulate model providers directly. Under the current system that classifies operators around AI systems, he said, operators that provide foundation models in API form could fall outside the scope of obligations, while regulation could concentrate on operators that build application services using them.
Kye said the current framework could leave model providers, the fundamental providers, outside legal obligations while only application system builders and providers bear duties. He said it was urgent to create an AI model concept in law to prevent regulatory gaps and unreasonable shifting of regulatory burdens.
Others say that rather than adding operator types, legal status should be determined based on the functions each party actually performs and its scope of control. Under that approach, even within the same company, if it develops a model and also provides application services, it could hold both development operator and use operator status, and obligations could also differ depending on how much it modified the system.
Another option being discussed is to maintain the current two-way classification while splitting individual obligations into technical and service stages. Under that approach, developers would handle internal model safety measures and technical labeling, while service operators would handle user notifications and operational management duties.
A recent revision bill to the AI Basic Act proposed by Ahn Cheol-soo (안철수), a lawmaker from the People Power Party, takes the same approach. The bill requires development operators to apply machine-readable labeling to outputs, while use operators must notify end users in a way they can recognise.
Ahn said making companies that develop AI models responsible for labeling on app screens, while requiring companies that provide apps to implement technical standards inside models, would result in duplicating a single labeling obligation on both sides. He added that the revision would reduce unnecessary duplicated development costs and legal uncertainty for companies, and enable users to more clearly confirm that content is AI-generated.