2026년 1월 22일 시행을 앞둔 「인공지능 발전과 신뢰 기반 조성 등에 관한 기본법」(이하 '인공지능기본법')은 에너지의 공급, 원자력 시설의 관리, 채용·대출 심사 등 11개의 영역을 '고영향 ...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17404409
서울 : 고려대학교 대학원, 2026
학위논문(석사) -- 고려대학교 대학원 , 법학과 행정법 전공 , 2026. 2
2026
한국어
서울
170 p ; 26 cm
지도교수: 이희정
I804:11009-000000308583
0
상세조회0
다운로드2026년 1월 22일 시행을 앞둔 「인공지능 발전과 신뢰 기반 조성 등에 관한 기본법」(이하 '인공지능기본법')은 에너지의 공급, 원자력 시설의 관리, 채용·대출 심사 등 11개의 영역을 '고영향 ...
2026년 1월 22일 시행을 앞둔 「인공지능 발전과 신뢰 기반 조성 등에 관한 기본법」(이하 '인공지능기본법')은 에너지의 공급, 원자력 시설의 관리, 채용·대출 심사 등 11개의 영역을 '고영향 인공지능'으로 규정한다. 문제는 원자력 시설과 같이 물리적인 위험을 정량화할 수 있는 영역과 채용과 같이 알고리즘 편향이 문제되는 영역이 규제 이론적으로 전혀 다른 성격을 갖는다는 점이다. 그럼에도 인공지능기본법은 모든 영역에 동일한 규제를 부과하고 있다.
제2장에서는 규제 이론의 발전 과정을 추적하면서 인공지능 규제에 적용할 수 있는 이론적 틀을 정립하고자 하였다. 전통적 규제법이 명령-통제 방식에서 과학적인 리스크 관리를 거쳐 리스크 기반 규제로 진화한 과정을 검토하고, 영향평가 제도가 갖는 의미를 분석하였다. 리스크 기반 접근과 영향평가는 방법론적 차이에도 불구하고 사전예방원칙과 비례원칙이라는 규범적 토대를 공유하며 상호보완적이다. 인공지능기본법은 이중 기준을 단순하게 병렬하여 "중대한 영향을 미치거나 위험을 초래할 우려"라고만 규정함으로써 판단기준의 불명확성을 야기한다.
제3장에서는 주요국의 규제 체계를 비교법적으로 분석하였다. EU AI Act는 전통적인 안전기준(부속서 I)과 사용 맥락(부속서 III)을 구분해서 규율하고, 미국 OMB 메모랜덤은 '안전영향(safety-impacting)'과 '권리영향(rights-impacting)'을 구분한다. 반면 인공지능기본법은 이러한 이론적 구분 없이 11개의 영역을 단순하게 나열한다. 캐나다가 인공지능·데이터법(AIDA)의 제정을 추진하였으나 정의 규정의 불명확성을 이유로 입법이 좌초된 것은 명확한 기준 설정의 중요성을 보여준다.
제4장에서는 현행 인공지능기본법의 고영향 인공지능 체계를 분석하고, 11개 영역을 세 가지 유형으로 재분류하였다. 유형 1(원자력·에너지·먹는물·교통)은 물리적 위해가 명확하고 정량적인 리스크 평가가 가능한 영역이다. 유형 2(채용·대출·생체인식·공공서비스·학생평가)는 의사결정의 중요도가 크고 차별적 영향 가능성이 있는 영역이다. 유형 3(의료기기·자율주행차)은 물리적 안전과 기본권이 동시에 문제되는 혼합 영역이다.
제5장에서는 유형별로 차별화된 판단기준을 체계화하였다. 유형1에는 EU의 리스크 기반 접근과 미국 안전 규제를 결합한 3단계 평가체계를 적용한다. 유형 2에는 캐나다 알고리즘 영향평가와 EU 기본권 보호 체계를 결합한 4단계 평가구조를 제시하였다. 유형 3에는 두 방법론을 통합하되 영역 특성에 따라 비중을 조절하는 방식을 제안한다.
제6장에서는 인공지능 법제 개선방안을 제안하였다. 법 제2조 제4호에서 유형별 구분을 명시하도록 법률을 개정하고, 시행령에서는 유형별 선정기준을 구체화하여야 한다. 법 제34조 사업자 의무도 차등화가 필요하다. 법 제35조의 영향평가는 의무화하고 구체적인 절차를 설계하여야 한다. 캐나다 알고리즘 영향평가 도구처럼 구체적인 질문 항목과 점수 체계를 마련하여 사업자가 스스로 활용할 수 있어야 한다.
2025년 11월, EU는 AI Act 개정안을 발표하며 고위험 인공지능시스템 의무의 이행 시점을 최장 16개월 연기할 가능성을 공표하였다. 신기술 규제는 기술 발전 속도와 산업 현실을 고려하여 지속적인 조정이 필요하다는 것을 보여준다. 인공지능기본법의 시행을 앞둔 지금, 우리는 글로벌 규제 변화에 신속하게 대응하면서도 안정적인 제도의 시행을 확보하여야 하는 이중 과제에 직면하고 있다.
이 연구는 리스크 기반 접근과 영향평가를 통합한 이론적 틀을 체계화하고, 11개 영역의 이질성을 규명해 유형별 접근법을 제시하였다. 시행령과 가이드라인 제정에 바로 활용할 수 있는 구체적 선정기준과 판단기준을 도출했다. 실증 데이터의 부족, 신기술 발전에 따른 예측의 한계, 영역별 심화 분석의 미흡 등은 후속 연구 과제로 남는다. 그럼에도 이 연구가 제시한 유형별 차별화된 규제체계가 급변하는 기술 환경에서 규제의 예측가능성과 유연성을 동시에 확보하는 실천적 도구로 기능하기를 기대한다.
다국어 초록 (Multilingual Abstract)
The Framework Act on Artificial Intelligence Development and Trustworthy Improvement (hereinafter "AI Framework Act"), scheduled to take effect on January 22, 2026, designates 11 domains including energy supply, nuclear facility management, and hiring...
The Framework Act on Artificial Intelligence Development and Trustworthy Improvement (hereinafter "AI Framework Act"), scheduled to take effect on January 22, 2026, designates 11 domains including energy supply, nuclear facility management, and hiring and loan screening as "high-impact artificial intelligence." The problem is that domains where physical risks can be quantified, such as nuclear facilities, and domains where algorithmic bias is the primary concern, such as hiring, have fundamentally different regulatory characteristics. Nevertheless, the AI Framework Act imposes uniform regulations across all domains.
Chapter 2 traces the evolution of regulatory theory to establish a theoretical framework applicable to AI regulation. It examines how traditional regulatory law evolved from command-and-control approaches through scientific risk management to risk-based regulation, and analyzes the significance of impact assessment systems. Risk-based approaches and impact assessments, despite their methodological differences, share common normative foundations in the precautionary principle and the principle of proportionality, and are complementary. The AI Framework Act creates ambiguity in judgment criteria by simply juxtaposing these dual standards, stating only "having significant impacts or posing risks."
Chapter 3 analyzes major countries' regulatory frameworks from a comparative law perspective. The EU AI Act distinguishes between traditional safety standards (Annex I) and use-context-based classifications (Annex III), while the U.S. OMB Memorandum differentiates between "safety-impacting" and "rights-impacting" systems. In contrast, the Korean AI Framework Act simply lists 11 domains without such theoretical distinctions. Canada's failure to enact its proposed Artificial Intelligence and Data Act (AIDA) due to ambiguous definitions demonstrates the importance of establishing clear criteria.
Chapter 4 analyzes the current AI Framework Act's high-impact AI system and reclassifies the 11 domains into three types. Type 1 (nuclear, energy, drinking water, transportation) encompasses domains where physical harm is clear and quantitative risk assessment is feasible. Type 2 (hiring, loans, biometric identification, public services, student evaluation) covers domains where decision-making significance is high and discriminatory impact is possible. Type 3 (medical devices, autonomous vehicles) represents hybrid domains where both physical safety and fundamental rights are at stake.
Chapter 5 systematizes differentiated judgment criteria for each type. Type 1 applies a three-stage evaluation system combining EU risk-based approaches with U.S. safety regulations. Type 2 proposes a four-stage evaluation structure combining Canada's Algorithmic Impact Assessment with the EU's fundamental rights protection framework. Type 3 integrates both methodologies while adjusting their respective weights according to domain characteristics.
Chapter 6 proposes improvements to the AI legal framework. Article 2, Paragraph 4 should be amended to specify type-based distinctions, and the enforcement decree should detail type-specific selection criteria. Article 34 obligations for AI operators also require differentiation. Article 35 impact assessments should be mandatory with specific procedural design. Like Canada's Algorithmic Impact Assessment tool, concrete questionnaire items and scoring systems should be developed for operators' self-assessment.
In November 2025, the EU announced an AI Act amendment potentially delaying implementation of obligations for high-risk AI systems by up to 16 months. This demonstrates that emerging technology regulation requires continuous adjustment considering technological development pace and industrial realities. As the AI Framework Act's implementation approaches, Korea faces the dual challenge of responding swiftly to global regulatory changes while ensuring stable institutional implementation.
This study systematizes a theoretical framework that integrates risk-based approaches with impact assessments, and identifies the heterogeneity of the 11 domains to propose type-specific approaches. It derives concrete selection criteria and judgment criteria directly applicable to enforcement decree and guideline development. Limitations such as insufficient empirical data, prediction constraints due to technological advancement, and inadequate in-depth analysis by domain remain as future research tasks. Nevertheless, this study's type-differentiated regulatory framework is expected to function as a practical tool for simultaneously securing regulatory predictability and flexibility in rapidly changing technological environments.
목차 (Table of Contents)