South Korea
Information uploaded as at July 2026
AT A GLANCE
South Korea’s use of AI in criminal justice is most advanced in law enforcement, with prosecutors and courts following via major investment projects still largely at a pilot stage. Law enforcement leads deployment, using AI for investigative support, predictive patrol deployment, and specialised applications such as deepfake detection and CCTV-based crime analysis, with outputs generally treated as investigative guidance rather than standalone evidence. Prosecutors use similar research tools and are developing a dedicated LLM, partly in response to case-processing times nearly tripling (126.8 to 312.7 days, 2018-2024). Courts remain earlier-stage: the Supreme Court has contracted a KRW 14.5 billion AI platform and is piloting a Trial Support AI system, though nothing yet supports actual decision-making. Defence counsel rely on commercial legal-research tools. No mandatory AI training exists, though judges have a non-binding AI Guidebook (February 2026).
South Korea has no AI-specific criminal justice legislation, relying on its general AI Framework Act (effective January 2026) — imposing transparency and risk-management duties on ‘high-impact’ systems — alongside the Personal Information Protection Act, Criminal Procedure Act, and constitutional protections. Non-binding guidance covers generative AI user protection and personal data processing (both 2025), and a 2024 amendment criminalises deepfake pornography possession/distribution. No case law addresses AI in criminal proceedings directly, though an August 2025 acquittal — turning on the prosecution's failure to prove a deepfake depicted a real person — shows existing law being tested against AI-generated content.
USE
AI deployment in South Korea’s criminal justice system is primarily at the investigative stage, with more limited adoption in other prosecutorial and judicial functions. Law enforcement agencies make the most extensive use of AI, particularly in data analysis, surveillance, and investigative support, while prosecutors are beginning to integrate AI tools for legal research and case preparation. Within the judiciary, AI use remains largely at the pilot stage and is generally confined to research and administrative assistance.
Law enforcement
Operational support
In November 2025, the Korean National Police Agency launched KICS-AI, an AI-powered investigation support system integrated into the Korea Information System of Criminal Justice Services. The system is based on LG AI's proprietary AI model, Exaone, and is accessible to approximately 36,000 investigative officers nationwide, following a pilot phase earlier in 2025. KICS-AI performs multiple tasks, including:
- Compiling and summarising witness statements;
- Analysing evidence;
- Drafting search and seizure warrant applications;
- Conducting case law and legal precedent searches; and
- Identifying similar cases from existing records.
In practice, the system can organise large volumes of case law and investigative materials within minutes, significantly reducing the time required for manual legal research and document preparation. The system operates exclusively on the police internal network to prevent information leakage, and sensitive personal information of suspects and victims is automatically anonymised. Its performance is subject to ongoing monitoring, with a dedicated task force conducting weekly evaluations and system improvements. While the system is designed as an assistive tool, investigators remain responsible for reviewing and refining AI-generated outputs, particularly in light of concerns regarding data security and the handling of sensitive investigative information.
The National Police Agency has also implemented an AI-powered voice recognition system, developed by Selvas AI, to support the recording of victim statements in sexual assault investigations. First deployed in 2020, the system was reported in August 2024 to be operational at 239 locations, including police stations, provincial agencies, women and youth investigation units, and sexual violence victim support centres. The system automatically transcribes spoken statements into text, separates different speakers, and stores the resulting records in a digital database. This is intended to reduce the need for manual note-taking during interviews and allow investigators to focus more directly on interaction with victims during the statement-taking process.
The PRE-CAS and Freecus systems (discussed below) generate patrol routes for officers and transmit them to police vehicle navigation systems based on crime risk predictions generated by the tool, subject to human review.
Predictive analytics
Since May 2021, the Korean National Police Agency has operated Pre-CAS (Predictive Crime Risk Analysis System), an AI-enabled crime-risk prediction system, nationwide. The system integrates large-scale policing and public datasets, including:
- Crime records contained in the Korea Information System of Criminal Justice Services,
- Emergency call data,
- CCTV location data, and
- Demographic, environmental, and economic indicators.
The system uses AI algorithms to estimate regional crime risk levels and predict the expected number of incidents. Pre-CAS generates patrol routes for officers and transmits them to police vehicle navigation systems, supporting more targeted and localised policing within South Korea’s decentralised policing framework. It can also support analysis of crime-prevention infrastructure, such as CCTV cameras and emergency bells, including identifying higher-risk areas where such infrastructure may be insufficient. The system is intended to support more targeted and locally tailored crime-prevention and patrol activities.
The PRE-CAS system is extended through the ‘Freecus’ tool, which extends its use beyond traditional offences (such as robbery and burglary) to ‘social issue crimes’ including drug offences, fraud, and stalking. These tools enable police to visualise crime risk at a granular level (for example, through grid-based mapping of high-risk areas), identify environmental risk factors such as CCTV blind spots, and prioritise patrol deployment accordingly. In practice, the system’s outputs are used as operational guidance, with officers retaining discretion in patrol decisions and deployment.
Data review and analysis
Law enforcement agencies in South Korea are increasingly using AI-based CCTV monitoring support systems. For example:
|
Anyang Dongan Police Station in Gyeonggi Province |
Developed by the Korea Institute of Science and Technology, AIID is a CCTV-based system for tracking the movements of missing persons. The system uses AI cognitive technology to predict missing persons' travel routes and has been piloted by the Anyang Dongan Police Station in Gyeonggi Province, with plans for phased nationwide expansion. While primarily deployed for search and rescue purposes rather than criminal investigations, the system illustrates the broader use of AI-enabled surveillance tools within law enforcement. In practice, outputs are subject to human verification, and limitations on the use of personal data restrict the scope of identifiable information that can be processed, affecting precision. |
|
Ministry of the Interior and Safety |
The Ministry of the Interior and Safety is promoting the development of an AI-based CCTV monitoring system to support the detection of risk situations in public spaces, including accidents, emergencies and potentially crime-related incidents. These systems analyse video feeds collected by local governments and are intended to identify patterns associated with events such as accidents, natural disasters, and other emergencies. As part of this initiative, a centralised platform is being established to aggregate CCTV data and support the training of AI models on a wider range of scenarios. |
|
National Police Agency |
Zio-Keeper is an AI-based CCTV analysis system developed by the Korean National Police Agency, in collaboration with the Ministry of Science, Information and Communications Technology and its private-sector partner ZioVision. The system analyses footage from daycare centre CCTV systems to detect indicators of suspected child abuse, using facial recognition and behavioural analysis to identify and flag potentially relevant scenes for review. Developed as part of the Police Lab 2.0 initiative (2021–2025), the system is designed to assist investigators in reviewing large volumes of video evidence more efficiently, particularly in the context of a sharp rise in child abuse reports after CCTV installations were made mandatory in all childcare facilities. Its outputs are used to support investigative review, with flagged footage subject to verification by police officers. |
|
Seoul Metropolitan Government |
The Seoul Metropolitan Government is expanding its intelligent CCTV infrastructure and piloting the use of generative AI in video monitoring. In 2026, Seoul announced a KRW 27.1 billion investment to upgrade and expand over 8,500 CCTV units, alongside a pilot project using context-aware generative AI to analyse risk situations based on customised datasets and provide prioritised response guidance. Reported improvements in existing intelligent CCTV systems include increased detection accuracy (from approximately 36% to 81%) and a significant reduction in false alerts. |
Both of these systems remain at the pilot and implementation stage, with generative AI-based monitoring initially being tested in selected districts before any broader rollout. Because this was primarily developed for public safety and urban risk management, the application to criminal investigations appears limited at present.
Since March 2024, the Korean National Police Agency has developed and deployed deepfake detection software to combat synthetic media crimes, including election-related misinformation and non-consensual sexual content. The system, reportedly developed in collaboration with DeepBrain AI, analyses suspected deepfake videos by uploading them to the system, which typically completes analysis within 5 to 10 minutes and determines whether the content is fake or real. Unlike most existing detection models that rely primarily on data from Europe and North America, the Korean system was trained on over 5.2 million data points from 5,400 individuals, including 1 million Korean data points and 130,000 Asian race data points, significantly improving detection accuracy for Korean subjects. The system evaluates behavioural patterns including head angles, lip movements, and facial muscle changes, and includes a voice detection feature that assesses frequency and noise to detect manipulation.
As the software is able to detect deepfakes successfully only around 80% of the time, the police use the system's results as investigative guidance rather than direct evidence. For election-related deepfake crimes, public sources describe results that undergo cross-verification by a civilian advisory committee composed of AI experts from academia and industry to minimise false positives.
K-VoM is an AI-based voice analysis system developed by the Ministry of the Interior and Safety in collaboration with the National Forensic Service and the National Police to support investigations into voice phishing and related crimes. The system uses deep learning techniques trained on Korean-language datasets to analyse voice recordings and identify patterns associated with criminal activity. K-VoM can compare and cluster voice data across cases, enabling investigators to identify links between suspects and detect organised crime networks. Since February 2023, it has been used by the National Forensic Service for forensic analysis, and from July 2023, a version has been deployed nationwide to police forces for use in investigations. Reported performance improvements include higher identification accuracy compared to earlier systems; however, outputs are used to support forensic analysis and investigative decision-making, rather than as standalone evidence.
Prosecutors
Use of AI by prosecutors in South Korea remains more limited than in law enforcement, though it is developing, particularly in relation to legal research and case preparation.
Legal research, analysis and drafting support
The prosecution has access to and is able to use KICS-AI, which provides functions such as case law search, evidence analysis, and document drafting. KICS‑AI can also identify the elements and causal relationships relevant to an offence and assist in drafting warrant applications. In fraud matters, it can identify elements such as deception, disposition of property and acquisition of a financial benefit, thereby supporting charging decisions and the formulation of indictments.
In August 2025, the Supreme Prosecutors’ Office entered into a formal usage agreement with the private legal‑technology platform L‑Box, integrating it into prosecutorial workflows for case preparation and ongoing prosecution management. LBox AI is a legal technology platform that provides caselaw and statutes search capabilities. Its use currently appears to be limited to research and information retrieval functions, rather than substantive decision-making.
In parallel, as at July 2026, the Supreme Prosecutors’ Office is developing a prosecution-specific large language model tailored to prosecutorial work. In April 2026, it initiated an information strategy planning project titled the ‘Criminal Justice Information System AI Model Development Informatization Strategic Plan Project’, aimed at establishing a roadmap for integrating generative AI into prosecutorial workflows. The proposed system is intended to support functions such as advanced legal search, summarisation of large case files, and extraction of key issues. It may also assist with the analysis of structured data (including financial and communications data) and drafting of prosecutorial documents. The Criminal Justice Information System remains at a pilot stage and has not yet been deployed in practice. These developments are driven in part by increasing case processing times and resource constraints. According to official data, the average processing time for criminal cases increased from 126.8 days in 2018 to 312.7 days in 2024.

Courts
The use of AI by courts in South Korea is at an early stage but gradually expanding, built upon broader digitisation efforts such as Korea’s e-Trial system, which enables electronic filing, case management, and access to court records, supporting paperless judicial proceedings. Courts have explored the potential use of AI to support functions such as legal research, case management, and document analysis. Any future deployment of AI in judicial processes is expected to be limited to assistive functions, with judges retaining responsibility for decision-making and the assessment of evidence.
There is one major premise that Korean justice now shares. It is to confine artificial intelligence to an assistive role. Artificial intelligence cannot stand in for the essence of judicial power, such as the determination of facts, the interpretation and application of statutes, the finding of guilt or innocence, and the fixing of sentences or the amount of damages.
![]()
Legal research, analysis and drafting support
In July 2025, the Supreme Court of Korea contracted with a consortium comprising KT, LBox, and Conan Technology to develop an AI platform to support judicial work over an approximately four-year period, with a reported project value of approximately KRW 14.5 billion. The project aims to develop a legal-specialised AI model capable of supporting functions such as AI-assisted search of judgments and statutes, automatic extraction and summarisation of key trial issues, and assistance with the drafting of judicial documents. One stated objective is to develop an ‘AI law clerk’ to assist with the preparation of case review reports by 2027. These developments remain at the design and development stage and have not yet been deployed in judicial decision-making. The initiative has been framed as a response to significant workload pressures within the judiciary.
As part of this initiative, the South Korean judiciary, through the National Court Administration, is piloting an in-house ‘Trial Support AI’ system as of February 2026. The system is being tested in selected courts to support legal research and case preparation. It allows judges to input natural language queries and receive synthesised responses based on judicial decisions, including Supreme Court and lower court rulings. The system is designed to assist with tasks such as summarising precedents, identifying relevant legal issues, and retrieving applicable case law. It is intended to support judicial efficiency, particularly in comparison to traditional keyword-based search tools. The system is designed as an assistive tool only: judges remain responsible for verifying outputs and making final decisions, particularly in light of the risk of inaccuracies or incomplete results. The 2026 pilot phase is expected to inform further development and any potential broader deployment.
Defence
Legal research, analysis and drafting support
While there are no reports of AI systems developed specifically for public defenders, private defence counsel in South Korea have access to a growing number of commercial legal technology tools that incorporate generative AI. These tools are used to support routine legal tasks rather than to replace legal judgment, and their outputs require verification by practitioners.
SuperLawyer is a generative AI tool designed for legal professionals that supports tasks such as case law search, document drafting, summarisation of legal materials and preparation of questions for interrogations. The system is based on large language models and is trained on Korean legal data, enabling it to generate structured legal documents and identify relevant precedents in response to user queries. For example, it can draft complaints and summarise case materials, as well as retrieve similar cases and suggest lines of questioning.
As described above, LBox is a legal research platform that provides AI-assisted search and analysis of case law and statutes. It holds the largest database of court rulings in South Korea and enables lawyers to rapidly identify relevant precedents and summarise legal materials, reducing the time required for legal research. In addition to the Supreme Prosecutors' Office, LBox is also available for use by the public. Some firms reportedly use Harvey or operate local language‑model servers to reduce risks associated with external commercial systems.
Victims
Under South Korean criminal procedure, victims are not formal parties to criminal proceedings and do not conduct the prosecution. Under Article 246 of the Criminal Procedure Act, public prosecutions are instituted and conducted by the prosecutor. However, the Act allows victims multiple avenues to participate directly in the criminal process. In particular, a victim may file a criminal complaint under Article 223 of the Criminal Procedure Act. Under Article 294-2, at the victim’s request, the court must generally examine the victim (or, in specified circumstances, the victim’s legal representative or certain family members) as a witness and provide an opportunity to state their views regarding the extent and consequences of the harm suffered, the punishment of the defendant and other matters relating to the case. Victims and certain representatives may also apply to inspect or copy trial records under Article 294-4. In addition, where a victim has filed a criminal complaint and the prosecutor decides not to prosecute, the complainant may, subject to the procedure set out in Article 260, seek judicial review of that decision. Accordingly, while victims do not have standing as a prosecuting party, they have specific statutory participatory rights at both the pre-trial and trial stages.
As at July 2026, there are no reported cases of victims in South Korea making use of AI in criminal proceedings.
TRAINING
In South Korea, training on the use of AI in criminal proceedings is emerging but remains at an early stage of institutional development. However, as at July 2026, there is no systematic or mandatory training on the topic.
For judges, in February 2026, the National Court Administration published the AI Guidebook for Judges, following its preparation by a dedicated task force established in October 2025, with nationwide distribution commencing in March 2026. The AI Guidebook, developed with input from judges and the Judicial Research and Training Institute, is intended to serve as a practical training and reference tool, providing guidance on the functioning of AI systems, their technical limitations, and associated risks, including hallucinations, bias, and data protection concerns. Available information indicates that the Guidebook focuses on general AI literacy and responsible use and does not specifically include instruction on deepfake detection. The Guidebook is intended to be an educational and practical reference rather than mandatory training: the National Court Administration describes it as a resource to support judges in determining how to use AI appropriately, with practical examples designed for self-learning, and there is no indication in the official materials that judges are required to review or complete it.
The Judicial Research and Training Institute established an Artificial Intelligence Education Centre, officially opened on 29 May 2026. AI training is planned as a regular subject for newly appointed judges and in five‑yearly judicial training programmes, and judges are expected to complete AI training at set intervals. The 2026 programme includes basic training on commercial AI and major models; intermediate training on trial‑related use and prompt engineering; advanced training on agentic AI and programme‑building; and lectures on AI, law and the courts. An online international seminar on AI in the judiciary was scheduled with Duke University’s Bolch Judicial Institute, and online basic AI‑literacy content for judges is being developed for completion by the end of 2027. These developments indicate a move towards structured, recurring training, even if no single course is yet legally mandatory for every judge.
For prosecutors, the Justice Training Institute (Beopmu Yeonsuwon) has identified ‘building capacity to work with AI and data’ as a strategic priority, alongside enhancing broader scientific and cyber-investigation skills. Training covers responses to digital offences, including deepfakes and cyber-defamation, with electronic evidence-handling treated as a core, recurring module rather than a one-off session. Separate programmes on generative AI and digital technologies are delivered through the Institute’s cyber-education arm.
For the police, the National Police Agency has rolled out its investigation-support system (KICS-AI) into live casework, with a published roadmap to expand its functions from drafting assistance and case recommendations today to more substantive support for investigative documentation in future. This shifts the training imperative for rank-and-file officers beyond general digital literacy towards proficiency with a tool now embedded in their daily workflow. The Agency has established a dedicated advisory structure to improve the quality and field-suitability of the system’s outputs, and is developing a range of public-safety AI services, including tools targeted at deepfakes and drug-related crime. These operational developments are underpinned by internal rules on AI impact assessment, responsible use, and safety and reliability. Consequently, police AI training must now cover investigative confidentiality, personal data protection, bias, hallucination, accountability, and AI usage logging, alongside basic tool literacy. Concrete examples already exist of generative-AI training for officers and public-relations staff, with hands-on sessions at municipal and autonomous police levels covering generative-AI fundamentals, prompt engineering, automatic drafting of official documents and reports, and AI-assisted search.

REGULATION
As at July 2026, South Korea has not enacted legislation specifically regulating the use of AI in criminal proceedings. Instead, the use of AI is governed indirectly through general AI governance frameworks, data protection legislation, criminal procedural rules, and human rights.
Judgment is made by applying, mutatis mutandis, the existing principles of criminal law and criminal procedure. There are no separate provisions as yet, though the courts' guidelines are only now beginning to appear. In the end, the reality of the Republic of Korea is that technology develops at breakneck speed while legislation follows at a tortoise's pace.
![]()
AI Regulations
AI Framework Act (2024)
The AI Framework Act, passed by the National Assembly on 26 December 2024 and effective from 22 January 2026, serves as South Korea’s principal legal framework governing AI. It applies to AI developers, suppliers, and users, including foreign entities whose systems affect users in South Korea.
The AI Framework Act establishes obligations for operators of generative and ‘high-impact’ AI systems, including those used in areas affecting fundamental rights or involving biometric data for criminal investigations. Article 2(4)(f) expressly includes within the definition of ‘high-impact AI’ those AI systems used to analyse or use biometric identification information for criminal investigations or arrests, where such systems may have a significant impact on, or pose risks to, an individual’s life, physical safety or fundamental rights. Key requirements include:
|
Transparency |
Under Article 31(1), an AI business operator providing a product or service using high-impact AI or generative AI must notify users in advance that the product or service operates using such AI. Article 31(2) further requires operators providing generative AI, or products or services using generative AI, to indicate that resulting content has been generated by generative AI. Under Article 31(3), where an AI system produces virtual audio, images or video that are difficult to distinguish from reality, the operator must provide notice or labelling in a manner that enables users clearly to recognise that the content was generated by AI. |
|
Risk management and oversight |
Article 34(1) requires operators providing high-impact AI, or products or services using high-impact AI, to implement measures to ensure its safety and reliability. These measures include establishing and operating a risk-management plan (Article 34(1)(1)); user-protection measures (Article 34(1)(3)); human management and oversight of the high-impact AI (Article 34(1)(4)); and preparing and retaining documentation demonstrating the measures taken to ensure safety and reliability (Article 34(1)(5)). |
|
Generative AI obligations |
As indicated above in respect of transparency obligations, Article 31(1) requires advance notice where a product or service operates using generative AI. Article 31(2) requires an indication that outputs have been generated by generative AI, while Article 31(3) imposes a heightened disclosure requirement for AI-generated audio, images or video that are difficult to distinguish from reality. |
|
Explainability |
Article 3(2) establishes the general principle that persons affected by an AI system should be able, to the extent technically and reasonably feasible, to receive a clear and meaningful explanation of the principal criteria and principles used to produce the AI system’s final result. More specifically, for high-impact AI, Article 34(1)(2) requires operators to establish and implement measures for explaining, to the extent technically feasible, matters including the AI system’s final result, the principal criteria used to reach that result and an outline of the training data used in the development and operation of the AI. |
The AI Framework Act does not contain sector-specific provisions governing the use of AI in criminal proceedings. However, AI systems used by law enforcement or public authorities—particularly those involving biometric identification or decisions affecting individuals’ rights—may fall within the category of ‘high-impact AI’, defined as systems that are likely to have a significant impact on safety or fundamental rights. Such systems are therefore subject to enhanced obligations under the AI Framework Act.
The Act operates alongside the Personal Information Protection Act (discussed below), which governs the processing of personal data by AI systems. Many detailed requirements under the AI Framework Act remain subject to implementing regulations and guidelines.
Guidelines on the Protection of Users of Generative AI Services (2025)
In February 2025, the Korea Communications Commission issued Guidelines on the Protection of Users of Generative AI Services, which took effect on 28 March 2025. The Guidelines set out four basic principles and six implementation methods for generative AI developers and service providers. The Guidelines are non-binding and are intended to encourage voluntary adoption of user-protection measures.
In particular, Implementation Method 2 recommends that service providers disclose that outputs were generated by generative AI and provide users with readily accessible basic information regarding the process by which the AI reaches its outputs. Implementation Method 3 recommends measures to reduce discriminatory or biased outputs, including filtering and user-reporting mechanisms. Under Implementation Method 4, where a service provider proposes to use users’ input or generated data as training data, it should provide prior notice and establish a process allowing users to consent to or refuse such use, while seeking to preserve users’ choice over whether their data are used for training. Implementation Methods 5 and 6 further recommend that providers define and communicate the respective responsibilities of providers and users, establish risk-management measures, and inform users not to generate or share inappropriate or harmful content.
The Guidelines do not themselves impose legally binding obligations directly on users. Rather, they place the principal responsibility on developers and service providers to establish protective measures and to inform users of their responsibilities. In particular, Implementation Method 5 contemplates that service providers should define the respective responsibilities of providers and users and ensure that users understand their own responsibilities, while Implementation Method 6 recommends that providers instruct users not to generate or disseminate inappropriate content. Any separate legal obligations applicable to users would arise under applicable legislation or, where relevant, the service provider’s terms of use, rather than from the Guidelines themselves.

Amendment to Sexual Crimes Punishment Act (2024)
In September 2024, the National Assembly of Korea passed an amendment to the Sexual Crimes Punishment Act targeting illegal AI-generated deep-fake videos. The reform strengthens the legal framework against AI-enabled sexual crimes by criminalising the knowing possession, viewing, or distribution of deepfake pornography, with penalties of up to three years’ imprisonment or fines, while exempting individuals who engage unknowingly. Additional amendments increase penalties for the exploitation of minors and impose enhanced obligations on the government to remove illegal content and support victims through dedicated assistance centres.
Guidelines for practitioners
AI Guidebook for Judges (2026)
In February 2026, the National Court Administration published an AI Guidebook for Judges, developed by a judicial task force with input from the Judicial Research and Training Institute. The National Court Administration is an internal organisation of the Supreme Court responsible for the administrative affairs of the South Korean judiciary under the direction and supervision of the Chief Justice. Its functions include matters relating to court personnel, budgets, facilities and statistics, as well as the administration and development of judicial systems. The Guidebook provides practical guidance on the responsible use of AI in judicial work, addressing risks such as hallucinations, bias, data security, and the protection of personal data. It emphasises that AI should be used as a support tool only and not as a substitute for judicial decision-making. It advises judges to verify AI-generated outputs and to avoid inputting sensitive or identifiable case information into AI systems without appropriate anonymisation or other safeguards.
The Guidebook does not impose binding legal obligations or require judges to disclose their use of AI in proceedings. Rather, it is intended as an educational and practical reference promoting AI use, including principles of human oversight, transparency and accountability.
National Police Agency Regulations on the Development and Use of Artificial Intelligence (2026)
On 30 June 2026, the Korean National Police Agency adopted the Regulations on the Development and Utilization of Artificial Intelligence by the National Police Agency, internal administrative regulations governing AI projects carried out by the National Police Agency and its affiliated police agencies. Article 3 requires police agencies, when developing and using AI, to seek to protect life, physical safety and fundamental rights, ensure the safety and reliability of AI systems, prevent discrimination and bias, and limit the collection and use of personal information to what is necessary for policing purposes.
The Regulations also establish more specific governance requirements. Under Article 14, proposed AI projects must undergo prior consultation addressing, among other matters, information security, personal data protection, transparency and, in the case of high-impact AI, measures to ensure safety and reliability. Article 18 requires specified transparency measures for high-impact and generative AI, subject to certain exceptions, including for systems used solely for internal police functions. Articles 19 and 20 require police agencies to identify high-impact AI systems and, for such systems, establish risk-management policies, measures for explaining AI outputs, user-protection measures and human management and oversight. Records demonstrating implementation of these measures must generally be retained for five years. Article 21 further provides for public-sector AI impact assessments before AI projects are undertaken, subject to specified statutory exceptions.
Lawyers
As at July 2026, no publicly available AI-specific professional conduct guidelines issued by the Korean Bar Association have been identified. However, lawyers remain subject to the general professional obligations contained in the Attorney-at-Law Act and the Korean Bar Association’s Code of Ethics for Attorneys, which are relevant to the use of AI in legal practice. Article 24(2) of the Attorney-at-Law Act prohibits an attorney, in performing professional duties, from concealing the truth or making false statements, while Article 26 imposes a duty of confidentiality in respect of information learned in the course of professional work. The Korean Bar Association’s Code of Ethics also provides in Article 2(2) that attorneys must not distort the truth or make false statements in performing their duties; Article 11(3) prohibits attorneys from instigating perjury, false evidence or conduct giving rise to suspicion of the same; Article 12 requires appropriate care in protecting personal information; and Article 35 requires attorneys to respect judicial authority and seek to ensure fair trials and due process. These duties apply irrespective of whether an attorney uses AI. Accordingly, a lawyer using an AI tool remains professionally responsible for the accuracy of material submitted to a court or investigative authority and for protecting confidential and personal information input into or processed by the tool. AI-generated material would therefore need to be reviewed by the lawyer before being relied upon in the course of representation.
Prosecutors
As at July 2026, no publicly available AI-specific professional conduct guidelines for prosecutors have been identified. Prosecutors and other Prosecution Service officials are, however, subject to general statutory and professional obligations that remain relevant where AI tools are used. For example, Article 1-2(2) of the Code of Conduct for Prosecution Service Public Officials requires officials to perform their functions fairly and transparently. Article 198(2) of the Criminal Procedure Act further requires prosecutors and others involved in investigations to respect the human rights of suspects and other persons and to maintain the confidentiality of information acquired during investigations. In addition, Article 2 of the Rules on Prosecutorial Case Affairs requires prosecutors and Prosecution Service personnel to protect human rights and comply with the Criminal Procedure Act and other applicable legislation when investigating and deciding cases and conducting trials.
Although these provisions do not specifically address AI-generated material or generative AI, they continue to apply where prosecutors use AI tools, including in relation to the treatment of confidential case information, protection of individual rights and the exercise of prosecutorial functions fairly and in accordance with law.
Criminal procedure rules
Criminal Procedure Act (1954)
The Criminal Procedure Act (Act No. 341 of September 23, 1954, as amended up to Act No. 11572 of December 18, 2012) establishes general standards for the admissibility of evidence, which apply to digital and AI-related evidence.
Under Article 307, findings of fact must be based on evidence and criminal facts must be proved beyond a reasonable doubt. Article 308 provides that the probative value of evidence is determined by the judge, while Article 308-2 provides that evidence obtained in violation of due process is inadmissible. In addition, Article 310-2 generally excludes hearsay evidence except where one of the statutory exceptions in Articles 311 to 316 applies.
Article 313 is particularly relevant to digital evidence. It expressly applies to statements or information, including text, photographs and video stored on computer disks or similar information-storage media. Under Article 313(1), such material may generally be admitted where its authenticity is established through the testimony of the person who created or made the statement. Where the author disputes its authenticity, Article 313(2) permits authenticity to be established by objective means, including digital-forensic material based on scientific analysis or expert appraisal, subject to the applicable statutory conditions.
South Korean Supreme Court case law imposes additional requirements concerning the authenticity and integrity of electronic evidence. In the Supreme Court Decision 2013Do2511 of 26 July 2013, the Court held that, where information stored on an electronic storage medium or a printout of that information is submitted as evidence, the identity of the submitted material with the data stored on the original medium must be established and the integrity of the original data must be preserved. The Court explained that this may be demonstrated, for example, through matching hash values or through testimony from investigators or experts involved in the seizure, sealing, imaging or copying process establishing that the data were not altered.
Accordingly, AI-generated or AI-analysed material would be subject to the same general evidentiary framework. Depending on the nature and proposed use of the material, questions may arise as to its lawful collection, authenticity, integrity, hearsay status and probative value. In particular, where the reliability of digital material is disputed, digital-forensic analysis or expert evidence may be relevant to establishing that the material submitted to the court corresponds to the original data and has not been altered. Accordingly, AI-generated or AI-analysed material may therefore be challenged under these existing standards, particularly where there are concerns as to reliability or authenticity.

Data protection legislation
The Personal Information Protection Act (‘PIPA’) is South Korea’s primary data protection law and establishes general principles governing the processing of personal data, including requirements relating to purpose limitation, data minimisation, transparency, and security. In particular, Article 16 requires a personal information controller to collect only the minimum personal information necessary for the relevant purpose, while Article 29 requires technical, managerial and physical safeguards against loss, theft, disclosure, falsification, alteration or damage of personal information.
PIPA provides individuals with rights of access, correction, deletion, and, in certain circumstances, suspension of processing, principally under Articles 35, 36 and 37, respectively. Of particular relevance to AI systems, amendments introduced in 2023 regulate automated decision-making, including the right to request an explanation of such processing and, in some cases, to challenge its use. Where such a decision has a significant effect on an individual’s rights or obligations, Article 37-2(1) gives the individual a right to reject the decision, subject to specified exceptions, and Article 37-2(2) permits the individual to request an explanation. Where an individual exercises these rights, Article 37-2(3) generally requires the controller, absent justifiable grounds, to take measures such as refraining from applying the automated decision, reconsidering it with human intervention, or providing an explanation.
PIPA also provides enhanced protection for sensitive personal data. Article 23 generally prohibits the processing of ‘sensitive information’ unless the data subject has separately consented after receiving the required information, or processing is required or permitted by law. Where sensitive information is lawfully processed, Article 23(2) requires appropriate security measures in accordance with Article 29. Article 18 of the Enforcement Decree identifies as sensitive information, among other categories, criminal-history information and biometric information generated through technical means from an individual’s physical, physiological or behavioural characteristics for the purpose of identifying that individual.
These protections are, however, subject to provisions specifically relevant to public authorities. Article 18(2) of PIPA permits public institutions, subject to the statutory conditions, to use or provide personal information beyond its original purpose where necessary for, among other matters, criminal investigations and the institution and maintenance of prosecutions (Article 18(2)(7)), the conduct of court proceedings (Article 18(2)(8)), and the execution of sentences and protective measures (Article 18(2)(9)). In addition, Article 18 of the Enforcement Decree provides that certain categories that would otherwise constitute sensitive information, including criminal-history and biometric-identification information, are excluded from that definition when processed by a public institution pursuant to Article 18(2)(5)–(9).
Accordingly, PIPA is relevant to the use of AI systems by law enforcement authorities, prosecutors and courts, but the precise obligations applicable to a particular system depend on the nature and purpose of the processing and on the statutory provisions applicable to public institutions. Therefore, PIPA may be relevant to AI tools involving facial recognition, voice analysis or other processing of identifiable personal information, although criminal-justice processing may fall within the specific public-sector rules and exceptions described above.
The Supreme Court of Korea has issued judgments on data protection, which may be relevant to how AI systems used in criminal investigations and proceedings should process personal data. For example, in Supreme Court Decision 2023Do18539, 26 June 2025, the Supreme Court held that the ‘use’ of personal information under the PIPA includes not only using data in its originally collected form, but also its processing, editing, or extracting information and the subsequent use of resulting information—a broad interpretation potentially relevant to AI systems that process and analyse personal data. In Supreme Court Decision 2023Do17590, 18 July 2025, the Supreme Court held that the submission of evidence containing personal information to an investigative authority in connection with a criminal complaint or investigation may constitute a ‘justifiable act’ under Article 20 of the Criminal Act and therefore may not attract liability under PIPA. Whether the exception applies depends on the circumstances, including the purpose for which the information was collected, held and submitted; the recipient of the information; whether the information submitted was limited to what was necessary; whether anonymisation or other safeguards were practicable; the nature and sensitivity of the information; the degree of interference with the data subject’s rights; and whether alternative means of submission were available.
Guidelines on Processing of Personal Information in Developing and Using Generative AI (2025)
In August 2025, the Personal Information Protection Commission issued Guidelines on Processing of Personal Information in Developing and Using Generative AI. The guidelines adopt a lifecycle-based approach, covering design, training, and deployment and set out data protection considerations at each stage. In particular, Section III divides the generative-AI lifecycle into four principal stages: (i) purpose setting (Section III.1), under which developers and deployers should identify the purpose of the AI system and the lawful basis for processing personal information used in training; (ii) strategy setting (Section III.2), which addresses development models and privacy-risk mitigation, including privacy impact assessment and privacy-by-design measures; (iii) AI training and development (Section III.3), which recommends safeguards at the data, model and system levels, including source verification, preprocessing and pseudonymisation or anonymisation, access controls and input/output filtering; and (iv) system application and management (Section III.4), which addresses pre-deployment privacy testing and documentation, publication of an Acceptable Use Policy and mechanisms for reporting privacy infringements and exercising data-subject rights. Section III.5 further recommends establishing AI privacy governance centred on the organisation’s Chief Privacy Officer to oversee privacy compliance and risk management throughout the AI lifecycle.
The Guidelines do not themselves impose direct legal obligations on ordinary users of generative-AI services. Rather, they are primarily addressed to companies and institutions that develop or deploy generative AI while processing personal information, including model developers and entities that use models to develop and provide AI services. The Guidelines are intended to assist such entities in complying with PIPA and managing privacy risks; where they refer to requirements such as identifying a lawful basis for processing or safeguarding data-subject rights, the underlying legal obligation derives from PIPA rather than from the Guidelines themselves. End users may be subject to an Acceptable Use Policy or other terms established by a service provider, but the Guidelines do not independently impose such obligations on them.
Cybersecurity legislation
A number of general cybersecurity requirements may apply to AI systems used in criminal proceedings, depending on the nature of the system and the entity developing or operating it.
Act on Promotion of Information and Communications Network Utilization and Information Protection
Under Article 45 of the Act on Promotion of Information and Communications Network Utilization and Information Protection (the ‘Information and Communications Network Act’), information and communications service providers, as well as manufacturers and importers of certain network-connected devices and equipment, are required to implement protective measures to ensure the stability of information and communications networks and the reliability of information. The Minister of Science and ICT may issue guidelines specifying the relevant information-security measures. Article 47 further provides for certification of information security management systems (‘ISMS’), comprising managerial, technical and physical safeguards. ISMS certification is mandatory for specified categories of telecommunications and information-service providers meeting the statutory criteria, including certain large-scale providers. These requirements may therefore apply to developers or providers of AI services where they fall within the relevant statutory categories, but they do not constitute a cybersecurity obligation applicable to all AI developers as such.
Electronic Government Act
For AI systems operated by public authorities, Article 56 of the Electronic Government Act is relevant. It requires the courts and executive branch, among other State institutions, to establish security measures to ensure the safety and reliability of information and communications networks and administrative information used for electronic government. Heads of administrative agencies must establish and implement security measures for information networks and administrative information under their control. Where electronic documents are stored or transmitted through information and communications networks, Article 56 further requires security measures designed to prevent falsification, alteration, damage or disclosure. These requirements may therefore apply to government information systems incorporating AI that are operated by law enforcement authorities, prosecutors or courts.
Personal Information Protection Act
Where an AI system processes personal information, Article 29 of PIPA requires the personal information controller to implement technical, managerial and physical safeguards, including measures such as internal management plans and the preservation of access records, to protect personal information against loss, theft, disclosure, falsification, alteration or damage. These requirements may be particularly relevant to criminal-justice AI systems processing sensitive investigative or case-related information.
Act on the Protection of Information and Communications InfrastructureAdditional requirements may apply where an information system is designated as ‘major information and communications infrastructure’ under the Act on the Protection of Information and Communications Infrastructure. The Act covers information and communications infrastructure associated with functions including public administration, national defence and public security. Under Articles 5 and 9, operators of designated infrastructure must establish and implement protective measures—including preventive, backup and recovery measures and periodically analyse and assess security vulnerabilities. These requirements would apply only where the relevant infrastructure has been designated under the Act and therefore would not automatically extend to every AI system used in criminal proceedings.
Human rights
The use of AI in criminal proceedings in South Korea is subject to general constitutional and statutory safeguards that operate as limits on its deployment. The Constitution of the Republic of Korea guarantees core rights including human dignity and fundamental rights under Article 10; equality before the law and protection against discrimination under Article 11(1); personal liberty and due process under Article 12(1); protection against compelled self-incrimination under Article 12(2); privacy under Article 17; and rights relating to criminal trials under Article 27, including the right to trial according to law (Article 27(1)), a speedy and public trial (Article 27(3)) and the presumption of innocence (Article 27(4)). These rights may constrain the use of AI, particularly where automated systems influence decision-making or evidentiary assessment, create risks of discriminatory treatment, or involve the processing of personal or biometric data.
These protections are reinforced by statutory frameworks. The AI Framework Act requires that AI systems, particularly high-impact applications, be developed and used in a manner that safeguards fundamental rights, including through transparency, risk management, and human oversight. In parallel, the Personal Information Protection Act provides safeguards in relation to automated decision-making and the processing of personal data, including rights to explanation and, in certain circumstances, to reject certain automated decisions having a significant effect on an individual’s rights or obligations.
International human rights instruments also form part of the relevant framework. Under Article 6(1) of the Constitution, treaties duly concluded and promulgated under the Constitution have the same effect as domestic laws. South Korea acceded to the International Covenant on Civil and Political Rights (‘ICCPR’) in 1990. Article 14 of the ICCPR guarantees equality before courts and tribunals, a fair and public hearing by a competent, independent and impartial tribunal, the presumption of innocence and minimum procedural guarantees in criminal proceedings, including protection against compelled self-incrimination. Article 17 protects individuals against arbitrary or unlawful interference with privacy, while Article 26 guarantees equality before the law and equal protection without discrimination. These provisions may be relevant where AI systems affect the fairness of proceedings, process personal information or create risks of discriminatory treatment.
Where criminal proceedings concern children, the UN Convention on the Rights of the Child (‘CRC’), ratified by South Korea in 1991, provides additional safeguards. Article 3(1) requires the best interests of the child to be a primary consideration in actions concerning children, including those undertaken by courts. Article 12 requires children capable of forming their own views to be given an opportunity to be heard in judicial or administrative proceedings affecting them, while Article 16 protects children against arbitrary or unlawful interference with their privacy. Article 40 establishes specific guarantees for children alleged or accused of infringing criminal law, including treatment consistent with their dignity and worth and procedural protections applicable to juvenile criminal proceedings. These protections may be relevant to the development or use of AI systems in proceedings involving child suspects, defendants or victims.
Outlook
Though South Korea has not adopted any concrete AI Strategy as at July 2026, South Korea is pursuing an active strategy to expand the use of AI across the justice sector, with ongoing projects aimed at integrating AI into law enforcement, prosecutorial, and judicial functions. Current initiatives, including the development of investigation support systems, judicial AI platforms, and generative AI tools, suggest that the use of AI is likely to increase in scope and sophistication in the coming years.
At the same time, regulatory developments remain at an early stage. While the AI Framework Act establishes a general governance structure, its application to the justice sector may depend on further implementing regulations and institutional guidance. Future developments in South Korea may therefore clarify the legal framework for the use of AI in criminal proceedings, particularly in relation to evidentiary standards, transparency, and safeguards against bias and error
The Judiciary’s Artificial Intelligence Committee has published a roadmap extending to 2030. Planned developments include analysis and classification of pleadings and other unstructured litigation materials; automated checks for contradictions, typographical errors and grammatical problems in draft judgments; administrative support for correcting service addresses and identifying errors in complaints; standardisation of trial data; an Online Dispute Resolution platform; speech‑to‑text services; automatic captions; AI sign‑language interpretation; picture‑based communication; and real‑time foreign‑language interpretation and translation.
CASES
Deepfakes
On 9 July 2025, in Uijeongbu District Court, Goyang Branch, Decision 2025GoDan894, the court acquitted a defendant charged with distributing AI-generated deepfake pornography, on the basis that the prosecution failed to prove that the images depicted a real, identifiable person. The defendant had shared AI-generated nude images in a Telegram chatroom. While the prosecution argued that the material was capable of inducing sexual desire or shame, the court accepted that the images likely portrayed fictional, AI-generated individuals. In the absence of evidence establishing the identity of a real person, the court found that no legally protected victim could be identified under the Sexual Crimes Punishment Act. The decision illustrates how existing criminal law is applied to AI-generated content, particularly in relation to the requirement to establish a victim. It also highlights evidentiary challenges in determining whether content is synthetic or linked to an identifiable individual.
South Korea’s National Police Agency has used a domestically built AI detection platform to arrest 419 deepfake suspects by July 2026 across 1,636 investigations, relying on a three‑layer system that combines automated analysis of biological signals (such as heartbeat‑driven colour changes in facial pixels and blink patterns) and metadata, human forensic video review, and AI reconstruction of the production chain to trace manipulated content back to its source. Trained on 5.2 million Korean data points to address demographic bias in commercial detectors, the system launched in March 2024 with an 80% accuracy rate, though its performance is understood to fluctuate as diffusion‑model deepfakes increasingly replicate physiological cues, prompting continuous retraining. This technical effort sits within a broader enforcement and legislative push: deepfake sexual offences now form the largest category of cyber‑sexual violence cases, penalties were tightened in September 2024 to criminalise possession and viewing without proof of intent to distribute, and the platform is being extended beyond sex crimes to fraud, disinformation, and election monitoring, alongside planned multimodal audio‑visual detection systems and regional research collaborations.
Daejeon Patent Court pilot
On 25 June 2026, Patent Division 5 of the Patent Court of Korea issued judgment in Case No. 2025Heo10489. The case concerned Company A’s action against the Ministry of Intellectual Property seeking cancellation of a decision refusing its patent. The court used AI after obtaining the written consent of both parties. AI assisted with summarising and structuring the case file; translating foreign‑language prior‑art materials; correcting and explaining patent specifications; and checking the draft judgment for errors and grammatical problems. The judges retained responsibility for the hearing, legal analysis and final judgment. There was no specific statutory basis for the AI use.
Hallucinations
A police station relied on AI to draft a decision not to refer a case for prosecution. The draft cited a non-existent precedent. After parliamentary scrutiny, the Commissioner General required investigators to review all AI outputs. This incident highlights the risk of AI-generated ‘hallucinated’ authorities and underscores the need for human verification of AI-produced legal material.