Asia's AI Rulebook Forked Three Ways: Korea, Singapore, Japan
Korea's AI Basic Act took effect Jan 22, 2026. Singapore launched the world's first agentic AI governance framework that same day. Japan chose innovation-first. Asia's three AI rulebooks don't match the EU AI Act.
On January 22, 2026, two Asian governments moved on AI regulation in opposite directions. In Seoul, South Korea’s amended Artificial Intelligence Basic Act took effect — the country’s comprehensive horizontal AI law, with mandatory watermarking, a 10²⁶ FLOPs compute threshold, and administrative penalties on the books. In Davos, on the very same day, Singapore’s Minister for Digital Development Josephine Teo announced the launch of the world’s first governance framework specifically built for agentic AI. Tokyo had already gone its own way the previous summer, choosing an innovation-first statute with no penalties.
Asia now has working AI governance, as the EU has had since 2024, in three different shapes. None of the three looks like the EU AI Act, and the assumption that Brussels would set the global default is harder to defend than it was a year ago.
This briefing maps the three Asian frameworks against each other and against the EU, and then sets out how a company building or deploying AI across Asia in 2026 can plan for all of them.
Korea: The Hard-Threshold Rulebook
South Korea was the first country in Asia — and one of the first in the world — to enact a comprehensive horizontal AI law. The original Basic Act passed in December 2024; the version that took force on January 22, 2026 was revised through 2025 to add teeth.
Korea’s framework has three features the others lack.
A compute-defined “high-impact AI” tier. AI systems trained with cumulative compute of at least 10²⁶ floating-point operations are designated “high-performance AI” and trigger safety obligations: risk assessment, safety measures, designation of a local representative for foreign providers. The EU AI Act draws the same numeric line for systemic-risk GPAI models, but Korea wrote it into statute rather than a Code of Practice.
Mandatory labeling of AI-generated content. Korea has been described as having the world’s first law requiring visible labels on AI-generated media. Under the Act, generative AI outputs — text, images, sound, video — must carry invisible digital watermarks, and realistic deepfakes that could be mistaken for real media must carry visible or audible labels. Non-deceptive works like webtoons can use invisible watermarks alone. Operators of generative AI services must additionally inform users that content was produced by AI.
Real, if modest, penalties. Administrative fines of up to ₩30 million (about US$21,000) can be imposed for failure to label, failure to appoint a domestic representative, or refusal of government inspections. Korea’s Ministry of Science and ICT (MSIT) has indicated a one-year grace period focused on guidance before administrative fines apply, giving subject businesses through early 2027 to install compliance infrastructure.
The fines are small next to the EU AI Act, where penalties under Article 99 can reach €35M or 7% of global turnover for the most serious violations. The labeling regime, though, is the strongest in any AI law now in force, and regulators in Japan, the UK, and the US are studying it.
Singapore: Governing What Acts, Not Just What Predicts
Singapore did not pass a statute. Instead, the Infocomm Media Development Authority (IMDA) and AI Verify Foundation kept building out the country’s framework approach — and on January 22, 2026 published the Model AI Governance Framework for Agentic AI, described as the world’s first governance framework specifically designed for AI agents capable of autonomous planning, reasoning, and action.
The 2024 EU AI Act, the 2025 Japanese AI Promotion Act, and the 2024 Korean AI Basic Act were all drafted around AI as a prediction system: a classifier, a generator, a recommender. None of them squarely addresses an AI system that books the flight, drafts the contract, and approves the wire transfer without a human checking each step.
Singapore’s new framework treats agentic AI as a distinct governance problem and structures the response around four core dimensions:
- Bound the risks upfront: set guardrails on what the agent can do and where it operates before deployment.
- Make humans meaningfully accountable: clear ownership of agent actions inside the organization.
- Implement technical controls and processes: kill-switches, audit logs, capability constraints, sandboxing.
- Enable end-user responsibility: explanations, transparency, and recourse for the people on the receiving end of agent decisions.
The whole document is described by IMDA as a “living document.” That is consistent with Singapore’s broader philosophy, which Duane Morris has characterized as a pro-innovation, framework-driven model: guidance rather than statute, voluntary alignment rather than enforcement, and close interoperability with international standards such as the OECD AI Principles and the GPAI Code of Practice.
For a company running agent deployments in production, Singapore’s framework is currently the most usable reference. Its four dimensions convert into an internal governance checklist that can be shown to auditors in Tokyo, Seoul, Brussels, and Washington, even though the statutes in those places differ.
Japan: The Innovation-First Bet
Japan’s AI Promotion Act, passed in May 2025 and detailed in our earlier briefing on Japan’s sovereign AI policy landscape, is the third model. There are no prohibited applications, no mandatory conformity assessments, no monetary penalties on business operators. The statute instead sets national R&D and adoption goals and authorizes the AI Strategy Headquarters — chaired by the Prime Minister — to coordinate ministry action.
The enforcement mechanism, as the International Bar Association notes, is reputational: the government can investigate harmful AI use, advise companies on remediation, and publicly name non-compliant operators. The METI/MIC AI Governance Guidelines for Business (v1.1, March 2025) are the operational layer underneath, and they expect companies to either comply or explain deviations in good faith.
This is closer to Singapore than to Korea. Two differences: Japan layered the framework on top of a parliamentary statute (which gives it national-policy weight Korea’s AI law also has, but which Singapore’s framework deliberately avoids), and Japan paired the framework with massive industrial-policy commitment — ¥1.23 trillion to AI and semiconductors for FY2026 alone, plus a ¥1 trillion five-year commitment announced in December 2025.
The Japanese government is spending on capacity rather than writing penalties, on the reasoning that industrial policy will count for more by 2030 than a fine schedule does in 2026.
The EU Contrast and the Limits of the “Brussels Effect”
For most of the past decade, compliance leaders assumed the EU’s regulatory choices would propagate globally, the so-called “Brussels Effect.” It happened with GDPR and is happening in part with the CSRD. The expectation was that the EU AI Act would set the global template and Asian jurisdictions would converge on it over time. So far they have not.
The EU AI Act’s GPAI obligations became effective August 2, 2025, with the AI Office gaining full enforcement powers from August 2, 2026. Pre-existing GPAI models must achieve compliance by August 2, 2027. The structure is risk-tiered (prohibited, high-risk, limited-risk, minimal-risk) with substantial penalties for non-compliance.
None of the three Asian frameworks adopted the EU’s risk-tier taxonomy. Korea uses a single compute threshold. Singapore avoids prescriptive categories entirely. Japan rejected categorical prohibitions outright. Each of the three governments looked at the EU AI Act and chose a different design.
For a multinational, no single AI compliance program satisfies every jurisdiction in 2026. The realistic minimum is layered:
- EU baseline for risk-tier classification, technical documentation, and copyright training-data summaries.
- Korea additional for labeling/watermarking on any generative AI output destined for Korean users, plus a domestic representative if you cross the compute threshold.
- Singapore additional for any agentic deployment, which matters more as enterprise AI moves from chat interfaces to autonomous workflows.
- Japan additional for comply-or-explain documentation aligned to METI’s guidelines.
The underlying technical work (risk assessment, watermarking, audit logging, human-in-the-loop controls) carries across all four. Most of the extra cost is documentation rather than engineering.
Why This Sits Squarely on the T4IS2027 Agenda
The summit’s 2026 program covered adjacent ground. Former Digital Minister Masaaki Taira argued that AI’s economic value will be unlocked through Japan’s regulated stablecoin rails, and an AI Governance panel ran on the main stage. The 2027 program will go further into the questions above.
One is whether the international network of AI Safety Institutes launched at the AI Seoul Summit in May 2024 can turn parallel domestic rules into something a multinational complies with once rather than four times. Another is whether other countries follow Singapore’s agentic framework, or whether Korea’s labeling and watermarking model gets extended to cover agent actions as well as generative outputs. A third is whether Japan’s combination of penalty-free regulation and heavy industrial spending holds up the first time something goes badly wrong in production.
Tokyo, Seoul, and Singapore are each running a different experiment, and the results of the next 18 months will be discussed at T4IS 2027 (May 18–19, Tokyo) by some of the people running them. To explore whether your organization belongs in the room, request an invitation.