South Korea espionage law took effect on 13 September 2026 with a much wider target than the rule it replaced. The revised Criminal Act allows prosecutors to pursue conduct involving national secrets for a foreign country or an equivalent organisation, instead of leaving the core espionage offence tied mainly to an “enemy state” framework associated with North Korea. Reuters and Aju Press both described the change as a response to technology leakage and intensifying competition around semiconductors and other strategic industries. The legal event is the commencement of Act No. 21450 after its six-month grace period, not a newly announced investigation or an allegation against a particular company. That distinction matters: manufacturers and researchers face a changed risk perimeter from today, while guilt, intent and the status of any information still have to be established in an actual case.

Everyone else is reporting a wider spy offence; we are explaining why the boundary between national secrets, chip know-how and normal cross-border work now matters to technology companies.

South Korea espionage law now reaches foreign-state cases

The South Korea espionage law took effect on 13 September 2026 with a much wider target than the rule it replaced. The revised Criminal Act allows prosecutors to pursue conduct involving national secrets for a foreign country or an equivalent organisation, instead of leaving the core espionage offence tied mainly to an “enemy state” framework associated with North Korea. Reuters and Aju Press both described the change as a response to technology leakage and intensifying competition around semiconductors and other strategic industries. The legal event is the commencement of Act No. 21450 after its six-month grace period, not a newly announced investigation or an allegation against a particular company. That distinction matters: manufacturers and researchers face a changed risk perimeter from today, while guilt, intent and the status of any information still have to be established in an actual case.

What the amended offence changes

The official revision published by Korea’s Ministry of Government Legislation reorganises the espionage provisions and adds a foreign-state route. Independent reports describe the new provision as covering the obtaining, collection, disclosure, transfer or brokering of national secrets when done under a foreign country’s direction, instigation or other communication. Aju Press reports a minimum prison term of three years for that new route. The older enemy-state provision remains more severe and distinct, so it is misleading to compress the whole amendment into one penalty. For technology businesses, the operational change is that the identity of the beneficiary no longer makes a non-North-Korean case automatically fall outside the espionage chapter. Prosecutors still need evidence that the information qualifies as a national secret and that the required foreign connection and mental element exist; ordinary international cooperation is not automatically espionage.

Why semiconductors sit at the centre

South Korea is home to Samsung Electronics and SK hynix, two companies whose memory and manufacturing capabilities are central to global artificial-intelligence infrastructure. Aju Press reported that police detected a record 33 overseas technology-leakage cases in 2025 and that semiconductors were the most frequently targeted industry. Reuters linked the broader statute to Seoul’s effort to protect key technologies amid sharper competition. Those figures explain the policy pressure, but they do not prove that every leaked design or process becomes a national secret. Businesses should separate trade secrets, national core technologies and national secrets in their controls because the labels arise from different laws and tests. Our coverage of the Samsung–Mistral chip AI partnership shows how chip capability increasingly intersects with AI strategy, while the HCLTech semiconductor lab in Bengaluru illustrates why specialised facilities, process documentation and access governance carry commercial value beyond a single product cycle.

South Korea espionage law implementation timelineTimeline separating enactment, current effective milestone, operational response and later evidence.Law madeLegal textEffectiveCurrent dutyOperateControls + recordsEvidenceCases + guidance
The law’s effective milestone is the start of operational evidence, not the end of interpretation.

The compliance question is classification, not a blanket export ban

The South Korea espionage law does not replace export-control licences, confidentiality clauses or the Industrial Technology Protection Act. It adds a criminal pathway where the statutory elements are present. A defensible compliance programme therefore begins by mapping which technical files, samples, recipes, models, source repositories and facility data are subject to which control regime. Companies should identify owners for classification decisions, record why a transfer is permitted, and make approvals visible before engineers share material with overseas affiliates, customers, suppliers or universities. That is especially important when collaboration tools make copying frictionless. A broad prohibition on normal communication would be commercially damaging and is not what the statute says. The better response is evidence: who authorised a transfer, which dataset or document moved, what recipient received it, and what legal basis supported the exchange.

Foreign companies and joint research face a documentation problem

Korea JoongAng Daily reported concerns from defence exporters that imprecise boundaries could make routine overseas dealings harder to assess. That does not establish that lawful exports will be prosecuted, but it identifies the practical ambiguity companies need to manage. Joint development often mixes public research, company know-how, customer specifications and government-restricted material inside the same programme. A single shared folder can therefore contain information with several legal classifications. Foreign multinationals should not assume that a global group structure answers the question: a sister company, overseas laboratory or contracted specialist can still be a foreign recipient. Local counsel will need to interpret the final offence against the facts, while security and engineering teams preserve logs that show access, approvals and the purpose of the collaboration. Clear records protect both national security and legitimate commerce.

China’s response shows the diplomatic sensitivity

Yonhap reported that China’s foreign ministry, responding before the law took effect, called for a fair and non-discriminatory operating environment for Chinese companies while saying firms should follow local laws. That statement demonstrates diplomatic attention; it is not evidence that South Korean authorities will target companies by nationality. Editorially, the safe conclusion is narrower: enforcement choices will be watched for consistency because semiconductor supply chains depend on cross-border investment and customers. The first cases will shape how businesses understand “foreign state or equivalent organisation,” what information courts accept as a national secret and what evidence shows direction or communication. Until judgments arrive, compliance teams should avoid treating commentary as binding interpretation. They should work from the enacted text, official guidance and fact-specific legal advice rather than from headlines that reduce the amendment to a geopolitical contest.

South Korea espionage law operating flowFour-step flow from signal intake to classification, decision and documented response.1. DetectPreserve signal2. ClassifyScope + trigger3. DecideOwner + deadline4. RespondRecord + mitigate
A defensible response links detection to a scoped, documented decision.

A practical control stack for technology teams

Technology companies can respond without freezing legitimate work. First, connect data classification to repositories and laboratory systems so restricted material cannot be exported through an ordinary share link. Second, require a named approver for transfers involving strategic technology and retain the decision record. Third, monitor unusual bulk downloads, removable media use and access from unapproved regions while preserving employee privacy and labour-law safeguards. Fourth, include contractors and departing staff in the same controls because access risk follows credentials rather than payroll status. Fifth, rehearse escalation: security, legal and business leaders should know when to preserve evidence, suspend access and contact authorities. The RBI quantum-proof payments call is a useful parallel in another high-stakes technology domain: institutions need migration plans and accountable controls before a new cryptographic or legal risk becomes an incident.

What the law does not prove

The effective date does not mean every suspected trade-secret leak can now be charged as espionage, nor does it retroactively establish liability for conduct completed before the new rule applied. It does not identify a guilty company, create a public list of protected semiconductor processes or replace the need for prosecutors to prove the statutory elements. The reported 33 overseas leakage cases are context, not a conviction rate and not a measure of losses. Similarly, references to China in news coverage describe the background of some detected cases and a diplomatic reaction; they should not be converted into a claim that nationality determines culpability. These limits belong in the story because regulation is high-risk news. Readers should leave with the exact change and its likely compliance consequence, not an unsupported prediction about prosecutions.

South Korea espionage law control stackLayered control stack showing accountable ownership, technical restrictions and audit evidence.Accountable owner and legal testProduct or information classificationAccess, transfer and response controlsTimestamped evidence and review
Governance, classification, technical controls and evidence reinforce one another.

The bottom line for chip and AI businesses

The South Korea espionage law closes a long-criticised jurisdictional gap by creating a route for foreign-state cases involving national secrets. Its immediate business consequence is a higher premium on knowing exactly what technical information a company holds, who may receive it and why a cross-border transfer is lawful. Semiconductor, defence, AI and advanced-manufacturing firms are the most obvious audiences, but the statute is not a substitute for the separate laws that govern ordinary trade secrets and controlled technologies. The early enforcement record will determine how aggressively the new language reaches real commercial workflows. Until then, precise classification, documented approvals, least-privilege access and preserved audit trails are the practical tools that let companies protect sensitive know-how without mischaracterising every international project as a security threat.

South Korea espionage law facts table

Effective date 13 September 2026
Statute Criminal Act, Act No. 21450
Core change Coverage extends beyond an enemy state to foreign states or equivalent organisations
Covered conduct Obtaining, collecting, disclosing, transferring, brokering or assisting with national secrets under foreign direction or communication
Minimum term reported for the new foreign-state offence Three years’ imprisonment
Business focus Semiconductors, defence technology and other strategically important know-how

South Korea espionage law FAQs

When did the South Korea espionage law change take effect?

Act No. 21450 took effect on 13 September 2026, six months after promulgation.

Does the law now cover every foreign company?

No. The amendment widens the foreign connection in the espionage offence, but prosecutors still need to prove the other statutory elements, including the protected nature of the information and the required conduct and intent.

Why are chip companies affected?

Semiconductor manufacturing know-how is economically and strategically important, and recent reporting links the reform to concern about overseas technology leakage. That does not make every chip trade secret a national secret.

What should companies do first?

Map sensitive information to the relevant legal classification, restrict access, document cross-border transfer approvals and prepare an escalation process with qualified Korean counsel.

Sources

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.