AI startups without an internal legal team
Organize privacy, contract, and governance priorities before legal issues become fragmented across teams.
AI Act, Privacy & Compliance Review
We review applicability, transparency, high-impact AI, privacy, data processing, governance, contracts, and enterprise questionnaires against the product's actual architecture and business stage.

Suitable clients
The review can be adapted to an early product as well as an operating service. Its scope is set according to the systems, data, vendors, and immediate business concern.
Organize privacy, contract, and governance priorities before legal issues become fragmented across teams.
Trace how information enters, moves through, and leaves the service and which parties take part in processing.
Review privacy, AI governance, vendor, and data-processing questions raised during procurement and contracting.
Identify documentation and governance gaps that may become material during diligence discussions.
Consider notices, terms, inputs, outputs, retention, vendors, and operational controls before launch.
Conduct an initial check of overseas users, infrastructure, vendors, transfers, and potentially relevant requirements.
Common triggers
Review scope
Identify the information handled, its sources and purposes, storage, recipients, vendors, retention, deletion, and overseas movement.
Review the alignment between actual processing and notices, consent, legal bases, outsourcing, third-party provision, transfers, and data-subject rights.
Examine model inputs and outputs, provider data use, retrieval components, prompt and response logs, inappropriate disclosure, and human review processes.
Identify initial issues concerning overseas users, infrastructure, vendors, international transfers, and potentially applicable privacy regimes.
Review output
The form and level of detail depend on the agreed scope. The review is intended to help management, product, engineering, and legal work from a shared set of priorities.
Review process
Timing is determined according to the product architecture, number of systems, readiness of materials, and overseas exposure.
Understand the product, data, vendors, customers, business stage, and immediate concern.
Review the agreed documents, service flows, provider relationships, and relevant product materials.
Assess legal, operational, and AI-specific issues according to their context and priority.
Explain the findings and organize actions that can be taken by the relevant teams.
Information usually requested
Before an engagement is confirmed, do not send sensitive personal information, trade secrets, production data, access credentials, or confidential documents.
Scope boundaries
Unless separately agreed, this service is not the following and does not guarantee regulatory compliance or a particular outcome.
FAQ
It is a scoped legal, privacy, governance, and product-risk review. It is not a statutory, accounting, certification, or comprehensive technical audit.
No. Penetration testing and technical vulnerability testing are outside the standard scope.
The standard review focuses on service architecture, data flows, documents, provider arrangements, and operational controls. A source-code security review is not included.
Yes. Available designs, product flows, provider choices, and planned data uses can be reviewed before every system or document is complete.
The questionnaire and the underlying facts can be reviewed as part of the agreed scope. The company should verify that every response matches its actual technical and operational practices.
An initial exposure check can be included. The depth of foreign-law review depends on the relevant markets, users, infrastructure, and agreed scope.
Usually a product overview, data or system flows, policies and terms, key provider information, and any immediate customer or diligence request are sufficient to begin defining scope.
Follow-up support may be discussed separately according to the findings, priorities, and work required.
Korean AI Act guides
Practical questions for reviewing products and documentation, based on the official Korean AI Act guidance. Each article has one language-neutral URL.
AI 모델을 직접 개발하지 않았다는 이유만으로 AI 기본법 검토가 끝나는 것은 아닙니다. 외부 API를 사용하더라도 회사가 최종 이용자에게 AI 제품·서비스를 제공한다면 역할과 의무를 살펴야 합니다. 반대로 AI 결과물을 내부 업무나 콘텐츠 제작에 단순 활용하는 경우는 구별될 수 있습니다. 먼저 세 가지를 확인하십시오 1. 누가 누구에게 무엇을 제공하는가 : 모델 개발사, API 공급자, 자사, 고객과 최종 이용자의 관계를 그
Read the Korean guide →AI 스타트업에는 긴 정책보다 제품의 현재 상태를 설명할 수 있는 짧고 정확한 기록이 먼저 필요합니다. 다음 열 가지는 법 조문을 복사하는 목록이 아니라 개발·영업·법무가 함께 확인할 실무 체크리스트입니다. 출시 전 체크리스트 1. AI 시스템 목록 : 제품명, 기능, 이용자, 담당자와 배포 상태를 적습니다. 2. 사업자 역할 : 직접 개발, 외부 API 이용, 재판매 또는 내부 이용 중 어디에 해당하는지 구분합니다. 3. 데
Read the Korean guide →OpenAI API를 이용한다는 사실만으로 적용 여부가 일률적으로 결정되지는 않습니다. 핵심은 API의 이름이 아니라 회사가 그 기능을 어떤 제품으로 구성해 누구에게 제공하고, 결과와 이용자 관계를 어떻게 통제하는지입니다. 서로 다른 세 가지 경우 1. 내부 업무 도구로만 이용 직원이 초안 작성이나 요약에 외부 AI를 이용하고 그 결과를 내부에서 검토하는 경우입니다. 최종 이용자에게 AI 제품·서비스를 제공하는 경우와는 구별되
Read the Korean guide →AI Questionnaire는 영업팀만의 설문지가 아닙니다. 개인정보, 보안, 모델, 운영과 계약에 관한 답변이 향후 계약상 진술이나 보증으로 이어질 수 있으므로 제품 담당자와 개발팀이 사실을 확인해야 합니다. 먼저 준비할 여덟 문서 1. AI 기능과 모델의 목록 2. 제품 및 데이터 흐름도 3. 외부 모델·API·인프라 공급자 목록 4. 개인정보 처리와 보관·삭제 기준 5. 공급자 약관과 데이터 이용 설정의 확인 자료 6.
Read the Korean guide →AI 기본법은 2026년 1월 22일부터 시행 중입니다. 정부가 안내한 계도기간은 법 시행 자체의 연기가 아닙니다. 지금은 과태료 여부만 바라보기보다 실제 서비스와 고지·계약·내부 기록의 차이를 줄이는 기간으로 활용할 필요가 있습니다. 지금 준비할 열 가지 1. 회사가 제공하거나 이용하는 AI 기능을 한 목록에 모읍니다. 2. 개발사업자, 이용사업자, 단순 이용자 등 역할을 서비스별로 검토합니다. 3. 생성형 AI 및 고영향
Read the Korean guide →고영향 AI 여부는 ‘의료 AI’, ‘채용 AI’ 같은 명칭 하나만으로 결정되지 않습니다. 법에서 정한 영역에 활용되는지와 그 목적, 사람의 생명·신체의 안전 및 기본권에 미칠 위험의 영향·중대성·빈도, 영역별 특수성을 함께 살펴야 합니다. 두 단계로 판단합니다 첫째, 제품·서비스가 법에서 정한 영역에 활용되는지 확인합니다. 둘째, 그 영역에서 AI가 실제로 수행하는 기능과 의사결정에 미치는 영향을 분석합니다. 단순 보조인지,
Read the Korean guide →기존 개인정보처리방침에 ‘서비스 제공을 위해 이용한다’는 문장만 추가해서는 AI의 데이터 흐름을 충분히 설명하기 어렵습니다. 실제 프롬프트, 첨부파일, 검색 데이터, 로그와 외부 모델 전송 구조를 먼저 확인해야 합니다. 처리방침과 실제 구조를 맞출 항목 AI 기능별 처리하는 개인정보와 수집 경로 이용 목적과 법적 근거 프롬프트·응답·검색 로그의 보관 기간 모델·API·클라우드 공급자에 대한 위탁 또는 제공 관계 국외 이전 국가
Read the Korean guide →생성형 AI 고지는 이용약관 깊숙한 곳에 한 번 적는 것으로 충분하다고 단정하기 어렵습니다. 이용자가 AI 기반 제품·서비스를 이용한다는 사실과 결과물이 AI로 생성되었다는 사실을 적절한 시점과 방법으로 인식할 수 있어야 합니다. 사전 고지와 결과물 표시를 구별하십시오 공식 투명성 가이드라인은 고영향 AI 또는 생성형 AI 기반 제품·서비스의 운용 사실을 알리는 사전 고지와, 생성형 AI 결과물이 AI에 의해 생성되었다는 사실
Read the Korean guide →AI 거버넌스는 위원회 이름을 만드는 일이 아니라 누가 어떤 기준으로 AI 기능을 승인·변경·중단하는지 기록하는 운영 체계입니다. 초기 스타트업이라면 실제로 유지할 수 있는 최소 문서부터 시작하는 편이 낫습니다. 최소 문서 세트 1. AI 시스템 목록 기능, 모델, 공급자, 이용자, 데이터, 담당자, 배포 상태와 위험등급을 한 표에서 관리합니다. 2. 위험평가 기록 오류, 편향, 개인정보, 보안, 지식재산, 투명성과 기본권 영
Read the Korean guide →기업 고객은 AI 기능만 보지 않습니다. 어떤 데이터가 어디로 이동하고, 공급자가 누구이며, 문제가 생겼을 때 누가 통제할 수 있는지를 함께 확인합니다. 다음 질문은 답변을 미리 꾸미기보다 실제 증빙의 공백을 찾는 데 사용할 수 있습니다. 제품과 모델 1. 어떤 AI 기능과 모델을 사용합니까? 2. 자체 개발과 외부 API의 경계는 어디입니까? 3. 모델·버전 변경은 어떻게 승인하고 통지합니까? 4. 출력의 정확성·편향·안전성
Read the Korean guide →Based on the product architecture, enterprise customer request, investment preparation, or overseas plan, we will explain an appropriate scope and process.
Contact the office →