Practice Areas
Our People
News & Resources
Book Consultation

2026-08-13
![[법률돋보기]⑪ 생성형 AI 시대, 기업 데이터도 ‘방어’가 필요하다](/_next/image?url=https%3A%2F%2Fd1tgonli21s4df.cloudfront.net%2Fupload%2Fboard%2Fbroadcast%2F20260813082357061.webp&w=3840&q=100)
Unauthorized crawling emerges as an issue under copyright law and the Unfair Competition Prevention Act
"Preemptive responses such as robots.txt and terms of use are needed"
As generative artificial intelligence (AI) services spread, the possibility of legal disputes arising from the use of content and data accumulated by companies themselves in the AI training process is also growing. Critics point out that when materials a company created with considerable time and cost—such as websites, press releases, and manuals—are collected and used without separate consent, it is necessary to review not only copyright but also whether the Unfair Competition Prevention Act has been violated.
Attorney Kim Yu-jung of Daeryun Law Firm emphasized on the 13th that, regarding corporate data protection in the era of generative AI, a technical and legal defense system prepared against AI's unauthorized data collection is needed.
Attorney Kim said that as cases increase recently in which generative AI services collect corporate websites and external content to use as training data, the management and protection of the data a company has built is emerging as a new challenge.
Under the current Copyright Act, works that creatively express human thoughts or emotions are protected as copyrighted works. Accordingly, whether an act in which AI collects and trains on a company's content constitutes copyright infringement must be judged comprehensively by considering the nature of the data and the method of use.
In particular, debate continues over whether data collection for AI training constitutes fair use as defined in Article 35-5 of the Copyright Act. AI developers may argue fair use on the grounds that they do not provide the original content to users as is, but utilize it in the training process, whereas data rights holders argue that their economic interests can be infringed by unauthorized commercial use.
Attorney Kim explained that since it is hard to say that a consistent legal standard has yet been established for large-scale web crawling for AI-training purposes, companies must closely examine the legal nature and method of use of each piece of data.
For data that is difficult to sufficiently protect under copyright law, she also suggested the possibility of responding through the Unfair Competition Prevention Act.
Article 2, Item 1, Subitem (k) of the Unfair Competition Prevention Act defines as an unfair competition act the act of infringing another's economic interests by using, without authorization and in a manner contrary to fair commercial practices or competition order, the results created by another's considerable investment or effort.
She said that even if the creativity of individual pieces of information itself is not high, if a company invested considerable manpower and cost to collect, classify, and process the information, there is a possibility of it being recognized as a single work product.
In fact, there are cases in which courts have judged that the considerable effort and investment put into the collection and processing of data must be protected, in a case where a competitor collected industrial information that a company had built over a long period through investment and effort using an automated program and used it in its own service.
Attorney Kim viewed that this legal reasoning could also be reviewed in the process of generative AI's data utilization. Her explanation is that if AI collects data or content that a company has built over a long time and utilizes it commercially, infringing the company's economic interests, liability under the Unfair Competition Prevention Act may become an issue separately from whether there is copyright infringement.
She also emphasized that preemptive corporate-level responses are important. First, one can consider technical measures to restrict access by AI crawling bots by setting a 'robots.txt' file on the website. She said it is necessary to specify in the website's terms of use content restricting crawling, scraping, and parsing for AI-training purposes, and to clearly indicate the company's intent regarding data use to the outside world.
However, rather than concluding that such measures alone can legally block all AI data collection, Attorney Kim explained that a company must comprehensively manage the type and scope of disclosure of the data it holds, its terms of use, and the actual methods of collection and use.
Attorney Kim Yu-jung said, "In a situation where the maintenance of related laws and systems lags behind the pace of AI technology development, if a company neglects its data, it can be exposed to new legal and managerial risks," and "It is necessary to review the website operation policy and terms of use and to establish a data compliance system that runs technical blocking measures and legal review in parallel."
[Read the full article]
[Legal Close-Up]⑪ In the Age of Generative AI, Corporate Data Also Needs 'Defense' (Go to link)
All fields At a glance
1/0
Visit Consultation Booking
If you have legal concerns, consult a Litigation Involving Foreign Nationals specialist at a nearby office.