Japan and the European Union have both concluded, within roughly a year of each other, that artificial intelligence needs a national or regional legal answer. The answers they arrived at are structurally opposite. Japan's Act on Promotion of Research and Development, and Utilization of AI-related Technology (Act No. 53 of 2025) is a promotion law with no penalties, no prohibitions, and no conformity assessment regime. The EU's Artificial Intelligence Act, Regulation (EU) 2024/1689, is a risk-based product-safety and fundamental-rights regulation with binding obligations, mandatory conformity assessment for high-risk systems, and administrative fines reaching into the tens of millions of euros. Following the Digital Omnibus amendment that entered into force on 27 July 2026, the EU Act's toughest deadlines have moved, but its underlying architecture, including its risk-tier classification and conformity requirements, has not changed. For any organisation operating in both markets, the practical consequence is that a compliance programme built for one jurisdiction does not, on its own, satisfy the other.

Philosophy and structure

Japan's AI Promotion Act is explicitly a framework and promotion statute. Its stated purpose is to advance research, development, and utilisation of AI-related technology, not to constrain it through ex ante approval or prohibition. The Act created the AI Strategy Headquarters, a Cabinet body chaired by the Prime Minister with every Cabinet minister as a member, whose provisions took effect on 1 September 2025 and which held its first meeting on 12 September 2025. Its principal output is the AI Basic Plan, a national strategy document rather than a set of enforceable rules. The first AI Basic Plan was decided by Cabinet on 23 December 2025, and a revised, second plan followed on 14 July 2026. The Act's only obligation that touches ordinary businesses is Article 7, a non-binding duty to endeavour to cooperate with government AI measures. There is no licensing regime, no risk classification of AI systems, and no statutory penalty anywhere in the Act (see the official English translation at japaneselawtranslation.go.jp and the Japanese text at hourei.ndl.go.jp).

The EU AI Act takes the opposite starting point. It sorts AI systems into tiers of risk, unacceptable, high, limited, and minimal, and attaches binding obligations that scale with the tier. Practices classified as unacceptable risk are prohibited outright under Article 5. Systems classified as high-risk, whether standalone systems listed in Annex III such as those used in recruitment, credit scoring, or law enforcement, or systems embedded in products already regulated under EU product-safety law under Annex I, must undergo conformity assessment, maintain technical documentation, and implement risk management and human oversight. Standalone Annex III systems must additionally be registered in an EU database before being placed on the market; Annex I embedded systems instead proceed through the conformity assessment procedures of the sectoral product-safety legislation that already applies to them. General-purpose AI model providers carry their own documentation and, above a compute threshold, systemic-risk obligations. The Act is enforced by national market surveillance authorities and, for general-purpose AI models, the EU AI Office, coordinated through the European AI Board.

Binding versus voluntary instruments

The clearest way to compare the two regimes is to separate what is legally binding from what is guidance. In Japan, the entire AI-specific layer, the Promotion Act itself, the AI Basic Plan, and the joint METI and MIC AI Guidelines for Business, is voluntary or non-binding soft law. The Guidelines, now at version 1.2 following a 31 March 2026 update that added risk framing for AI agents, consolidate three earlier development, use, and governance guidelines into a single document (meti.go.jp). They function as a de facto standard of care that regulators, courts, and business counterparties will expect an organisation to have followed, but they create no statutory liability in themselves. The Financial Services Agency's discussion paper on sound AI use in financial services, first published March 2025 and updated to version 1.1 on 3 March 2026, is likewise principles-based and non-binding (fsa.go.jp). The same is true of Japan's contribution to the G7 Hiroshima AI Process, launched in May 2023, which produced international guiding principles and a voluntary code of conduct for advanced AI developers rather than binding regulation (oecd.ai/en/hiroshima).

What actually binds organisations operating in Japan is not AI-specific law at all. It is existing general law applied to AI use cases: the Act on the Protection of Personal Information (APPI), enforced by the Personal Information Protection Commission, which issued a specific alert on generative AI service use on 2 June 2023 (ppc.go.jp); the Copyright Act, whose Article 30-4 exception for information analysis, in force since 1 January 2019, permits use of copyrighted works for AI training without rightsholder authorisation where the purpose is not to personally enjoy the thought or feeling expressed in the work, subject to a proviso that the use must not unreasonably prejudice the copyright owner's interests; and sector-specific regulation that applies regardless of whether AI is involved. This is the structural key to Japan's approach: the AI-specific layer sets direction and expectation, while binding legal exposure runs through pre-existing statutes.

In the EU, the position is inverted. The AI-specific instrument is itself the binding law. Codes of practice, such as the code developed for general-purpose AI model providers, and harmonised technical standards being developed through CEN-CENELEC operate alongside the Act as compliance tools, generally by creating a presumption of conformity, but the core obligations, the prohibitions, the high-risk conformity requirements, and the transparency duties, sit directly in a directly applicable EU regulation with no need for national transposition.

Deadlines and phasing

The EU AI Act entered into force on 1 August 2024 and has been phased in since. Prohibited practices under Article 5 became applicable from 2 February 2025. Obligations on general-purpose AI model providers followed on 2 August 2025. The Digital Omnibus, published in the Official Journal of the European Union on 24 July 2026 and in force from 27 July 2026, deferred the two remaining high-risk deadlines: standalone high-risk systems under Annex III now have until 2 December 2027, and high-risk systems embedded in products already covered by EU product-safety legislation under Annex I have until 2 August 2028. Article 50's general transparency obligations, covering disclosure of AI interaction and labelling of synthetic content, were not postponed and remain applicable from 2 August 2026, although the specific duty under Article 50(2) to apply machine-readable marking carries a grace period to 2 December 2026 for systems already on the market before 2 August 2026.

Japan's timeline runs on a different logic because there are no compliance deadlines to phase in. The Act was passed by the Diet on 28 May 2025 and promulgated on 4 June 2025. Its institutional provisions took effect on 1 September 2025. The dates that matter in Japan are planning milestones, the AI Basic Plan cycle, and guidance-update cycles, such as the AI Guidelines for Business moving from version 1.0 in April 2024 to version 1.2 in March 2026, rather than dates by which a business must have completed a conformity assessment or face liability.

Penalties

This is the sharpest point of divergence. The EU AI Act sets tiered administrative fines under Article 99. Non-compliance with the Article 5 prohibitions carries fines of up to 35,000,000 euros or 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Breach of other operator obligations, including high-risk and general-purpose AI provisions, carries fines of up to 15,000,000 euros or 3 percent of turnover. Supplying incorrect, incomplete, or misleading information to authorities carries fines of up to 7,500,000 euros or 1 percent of turnover. For small and medium-sized enterprises, including startups, the lower of the fixed amount or the percentage applies. The Digital Omnibus amendment extended the compliance deadlines for high-risk obligations; it did not defer or alter the Article 5 prohibitions, which have applied since February 2025.

Japan's AI Promotion Act contains no penalty provision of any kind. There is no fine, no order, and no criminal sanction attached to non-cooperation with the Article 7 duty or to any other provision of the Act. Any monetary or criminal exposure a business faces in connection with AI activity in Japan arises instead from the general laws that apply irrespective of AI, principally APPI, which gives the PPC authority to issue corrective orders and provides for criminal penalties where an order is disobeyed, and the Copyright Act, which carries its own civil and criminal remedies for infringement falling outside the Article 30-4 exception. Sector regulators, such as the Financial Services Agency, can also act on AI-related misconduct using their existing supervisory powers over regulated entities, again independent of the AI Promotion Act itself.

What this means for multinational organisations

The practical consequence for organisations operating in both markets is that governance built to satisfy one jurisdiction does not transfer to the other.

  • Japan-only governance does not satisfy EU AI Act obligations. A compliance programme built around Japan's AI Guidelines for Business, however rigorous, is a voluntary framework. It does not perform a conformity assessment, does not produce the technical documentation the EU Act requires for high-risk systems, and does not satisfy Article 50 transparency duties. The EU AI Act applies extraterritorially to providers placing AI systems on the EU market or whose output is used in the EU, regardless of where the provider is established, so a Japanese company exporting a high-risk AI system into the EU, or a general-purpose AI model used by EU deployers, is a regulated entity under the EU Act whether or not it has ever engaged with Japan's framework.
  • EU AI Act compliance does not satisfy Japan's binding obligations. A conformity assessment file, technical documentation, and CE-style registration built for the EU Act address EU-specific requirements. They do not, by themselves, establish lawful handling of personal information under APPI, do not resolve Copyright Act Article 30-4 questions about training-data use in Japan, and do not substitute for the sector-specific approvals, for example those administered by Japan's financial and healthcare regulators, that apply to regulated activities regardless of AI involvement.
  • The compliance centre of gravity differs by market. In the EU, the AI-specific statute is the primary compliance target. In Japan, general law, principally data protection and copyright law, is the primary compliance target, while the AI-specific guidance sets the standard of care that regulators and counterparties will expect on top of that baseline.
  • Timelines do not align. A multinational tracking a single global AI compliance calendar risks missing that Japan has no statutory compliance deadlines at all, while the EU has several, now reset by the Digital Omnibus to 2 August 2026 for transparency duties, 2 December 2027 for standalone high-risk systems, and 2 August 2028 for embedded high-risk systems.
  • Penalty exposure is asymmetric. An organisation can be fully compliant with Japan's AI-specific framework and still face no AI-specific penalty risk there, while facing turnover-linked fines under the EU AI Act for the same underlying system if it is placed on the EU market without the required conformity work.

Neither model is self-evidently superior. Japan's approach trades binding certainty for flexibility, betting that soft law and sectoral enforcement can keep pace with a fast-moving technology without imposing ex ante approval costs on innovation. The EU's approach trades flexibility for predictability and enforceability, accepting slower, more resource-intensive compliance in exchange for harmonised, binding rules across twenty-seven member states. For a multinational organisation, the operational takeaway is not a judgment about which philosophy is right, but a mapping exercise: identify which of the two regimes' triggers apply to each product and each market, and build separate, jurisdiction-appropriate compliance tracks rather than assuming that satisfying one automatically satisfies the other.

Primary sources

Related articles