Japan regulates artificial intelligence in healthcare through two layers that operate very differently from one another. The country's new AI-specific legislation, the AI Promotion Act, is a voluntary, non-punitive framework. What actually constrains what a hospital, a medical device maker, or a health-tech developer can do with an AI system in a clinical setting comes from older, sector-specific, and fully binding law: the Pharmaceuticals and Medical Devices Act enforced by the Pharmaceuticals and Medical Devices Agency (PMDA), the Medical Practitioners Act that reserves diagnosis and treatment to licensed physicians, and the Act on the Protection of Personal Information (APPI) as applied to patient data. This article sets out how each of these regimes treats AI in healthcare, and what that means in practice for organizations building or deploying it.

PMDA and the regulation of AI medical devices

Japan regulates medical device software, including AI-based software, under the Act on Securing Quality, Efficacy and Safety of Products Including Pharmaceuticals and Medical Devices, commonly called the PMD Act, which entered into force on 25 November 2014. Software intended for diagnosis, treatment, or disease prevention is treated as Software as a Medical Device (SaMD) when it poses a moderate risk or higher to patients if it malfunctions, corresponding to Class II or above in Japan's four-tier device risk classification (Class I through Class IV). Lower-risk software aimed at health management or general information provision falls outside SaMD regulation. Class I products proceed by notification, many Class II products can be handled through third-party certification against recognized standards, and higher-risk or novel products, which in practice includes most AI-based diagnostic software, require individual approval (shonin) from the PMDA after review of clinical utility, performance, and safety. The PMDA has established a dedicated SaMD review office and offers tiered pre-submission consultation services to help developers determine early whether their product is even in scope. (PMDA, Software as a Medical Device)

Approved AI-based SaMD in Japan is concentrated heavily in radiology and other image-based diagnostic support, where dozens of products have received approval, generally as narrowly scoped tools that assist a clinician within a defined task rather than broad autonomous diagnostic systems. Non-imaging examples exist as well: CureApp SC, a prescription smoking-cessation application incorporating an AI-supported coaching function linked to physician oversight, was among the first digital therapeutics approved under this framework. (Journal of Global Health Medicine, Japanese regulation and approval process for medical AI as SaMD)

Built for AI that keeps changing: IDATEN, DASH, and SAKIGAKE

A defining regulatory problem for AI-based medical devices is that machine learning models can be designed to keep learning after they reach the market, which sits awkwardly with a device approval that is meant to fix a product's specifications at the point of authorization. Japan addressed this earlier than most jurisdictions through IDATEN, Improvement Design within Approval for Timely Evaluation and Notice, in force since September 2020. IDATEN lets a manufacturer submit a pre-agreed change control plan alongside its initial application, so that defined categories of post-market software updates, including certain retraining or performance changes for continuously learning AI, can be implemented under a simplified notification procedure rather than a fresh approval each time. The PMDA has also run DASH for SaMD, an initiative to speed up consultation and review specifically for software products, and the SAKIGAKE designation system, which fast-tracks review for genuinely innovative devices addressing severe unmet clinical needs, both of which AI-based SaMD developers can draw on. (PMDA, Report on AI-based Software as a Medical Device)

Even with these mechanisms, regulators and researchers studying Japan's framework point to unresolved challenges as generative and more broadly adaptive AI models move toward clinical use: defining a fixed "intended use" for a system whose outputs are generated rather than selected from a bounded set, evaluating the reliability of natural-language outputs, and maintaining lifecycle oversight of a system whose performance can drift after deployment. Recommended responses focus on clarifying the scope of what is actually being regulated, strengthening post-market lifecycle management, improving transparency to clinicians, and building clinician literacy about the tools' limits, rather than treating approval as a one-time event.

The physician remains the decision-maker

Underneath the device-approval question sits a separate, and in practice more consequential, legal constraint: only a licensed physician may practice medicine in Japan. The Ministry of Health, Labour and Welfare (MHLW) addressed how this applies to AI directly in a notice dated 19 December 2018 (Isei-i-hatsu 1219 No. 1), clarifying that where a program provides AI-based diagnostic or treatment support, the physician, not the software, is the one conducting the diagnosis or treatment, and the physician bears responsibility for the final judgment. AI is treated as a tool that supports a step within the physician's decision-making process under Article 17 of the Medical Practitioners Act, which reserves the practice of medicine to licensed doctors; a product or workflow that allowed an AI system to make or finalize a diagnosis without a physician's judgment would risk falling foul of that provision. For any hospital or developer, this means clinical AI tools in Japan must be built and deployed as decision support that a physician reviews and signs off on, not as an autonomous clinical actor, regardless of how the underlying model performs.

Where the AI Promotion Act and the AI Guidelines for Business fit

Japan's AI Promotion Act, the country's first national AI law, passed by the Diet on 28 May 2025 and promulgated 4 June 2025, does not create a healthcare-specific regime and does not touch the PMD Act's binding approval requirements. It is a promotion and framework law with no penalties, no prohibitions, and no mandatory conformity assessment; its only business-facing obligation is a non-binding Article 7 duty to endeavour to cooperate with government AI measures. For a hospital or medical AI developer, the Act's practical relevance is limited to the broader institutional architecture it creates, the Cabinet-level AI Strategy Headquarters and the AI Basic Plan, rather than any direct compliance duty layered onto clinical AI use.

The joint METI and MIC AI Guidelines for Business, now at version 1.2 following its 31 March 2026 update, is similarly voluntary but functions as the de facto standard of care for AI governance practice across sectors, including health technology. It is most relevant to healthcare organizations for the AI tools that fall outside PMDA's SaMD threshold altogether: administrative AI, ambient clinical documentation and scribing tools, triage chatbots that do not themselves diagnose, and other systems that support care delivery without meeting the Class II-or-above risk bar that triggers PMD Act regulation. These are common in Japanese hospitals and health-tech products, and for them the Guidelines, not the PMD Act, are the primary governance reference, which makes voluntary adoption of the Guidelines' risk management practices materially more important for that category of tool than the law technically requires.

APPI: the binding constraint on patient data

Patient information used to train, validate, or run a healthcare AI system is almost always "special care-required personal information" (yohairyo kojin joho) under APPI, a category that also covers medical history, alongside race, criminal record, and similar sensitive attributes. Acquiring this category of data requires the individual's prior consent; the opt-out mechanism that APPI otherwise allows for routine third-party data transfers is not available for special care-required information. The Personal Information Protection Commission (PPC), APPI's enforcement authority, has issued sector guidance specifically for medical and nursing care providers on handling personal information, and separately warned generative AI users generally, in its 2 June 2023 alert, about the privacy risks of feeding personal data into generative AI services. (PPC, alert on generative AI service use) Any hospital or vendor piloting a large language model against clinical notes, or a developer training a diagnostic model on patient records, needs to work through APPI consent, cross-border transfer, and safeguard requirements as the binding compliance track, independent of whatever the AI Promotion Act or the Guidelines say.

A dedicated data pathway: the Next-Generation Medical Infrastructure Act

Because APPI consent requirements make large-scale secondary use of medical records for research and AI development difficult, Japan created a separate statute for this purpose, the Act on Anonymized Medical Data That Are Meant to Contribute to Research and Development in the Medical Field, commonly called the Next-Generation Medical Infrastructure Act. It allows certified operators to collect medical information from participating institutions, process it into anonymized (or, after a 2023 amendment that took effect 1 April 2024, pseudonymized) medical data, and supply it to researchers and companies, including for AI model development, without needing to obtain individual consent for each downstream use, subject to an opt-out mechanism at the point of collection. The 2023 amendment's pseudonymized data category matters specifically for regulatory work: because it need not strip outliers or rare-disease identifiers the way anonymized data must, it can be submitted to the PMDA in support of a device approval, which anonymized data generally could not support. (Japanese Law Translation database, Act on Anonymized Medical Data) For medical AI developers, this Act, rather than APPI's standard consent track, is often the realistic route to assembling a training dataset at scale.

System security and the wider digital health context

Hospitals deploying AI tools also sit inside MHLW's Guidelines for the Security Management of Medical Information Systems, revised to version 6.0 in 2023 and restructured into multiple separate volumes rather than a single document. The revision reflects a shift toward zero-trust network thinking and explicit accommodation of cloud-based systems, relevant to any AI tool that runs off-premises or relies on an external vendor's infrastructure rather than an on-site server. This sits within the government's broader Medical DX Reiwa Vision 2030 program, which aims to modernize hospital electronic records and administrative systems, in part specifically to make it easier to deploy generative AI and other modern tooling on top of standardized clinical data. Separately, MHLW's Guidelines for the Proper Implementation of Online Medical Treatment, along with related MHLW policy guidance on telemedicine promotion, govern the AI-assisted remote consultation tools that have grown alongside Japan's telemedicine expansion, within the same physician-responsibility framework described above.

Practical governance considerations for hospitals

  • Classify every AI tool in use by regulatory track before deploying it: PMDA-approved SaMD, non-SaMD administrative or documentation AI governed by the voluntary Guidelines, or a hybrid where a general AI capability feeds into a regulated clinical workflow.
  • Build sign-off workflows that keep a physician as the documented final decision-maker for any AI-assisted diagnostic or treatment output, consistent with the MHLW's 2018 notice on Article 17 of the Medical Practitioners Act.
  • Treat patient data feeding any AI system, including pilots and vendor demonstrations, as special care-required personal information requiring APPI-compliant consent, and confirm whether data will leave Japan before agreeing to any cloud or vendor arrangement.
  • Align system architecture, particularly for cloud-hosted or vendor-managed AI tools, with the current version of MHLW's medical information system security guidelines.
  • For AI-based devices with a change control plan under IDATEN, track which categories of post-market change are pre-approved and which would require a fresh submission, and monitor for performance drift regardless.

Practical governance considerations for health-tech companies and developers

  • Use PMDA's consultation services early, including the SaMD-specific and startup-oriented tracks, to determine classification before committing to a product design or clinical claim.
  • Where the product involves continuous learning, design an IDATEN-compatible change control plan from the outset rather than retrofitting one after initial approval.
  • Source training data through APPI-compliant consent or, for large-scale medical record use, through the Next-Generation Medical Infrastructure Act's certified-operator pathway rather than informal data-sharing arrangements.
  • Where training data includes copyrighted medical literature or images, note that Article 30-4 of the Copyright Act permits use for AI training analysis without rightsholder authorization, but only where the use does not unreasonably prejudice the rightsholder's interests, a case-by-case assessment rather than a blanket exemption.
  • Adopt the AI Guidelines for Business as the working standard of care for any AI functionality that falls outside PMD Act regulation, since that voluntary framework, not device law, is what will be judged against if something goes wrong with a non-SaMD tool.
  • Design clinical-facing outputs so a physician reviews and can override them, since a workflow that lets the AI finalize a diagnostic or treatment decision risks conflicting with Article 17 of the Medical Practitioners Act irrespective of the device's approval status.

The structural takeaway

Healthcare is a clear illustration of the pattern that runs across Japan's AI governance landscape generally: the AI-specific layer, the AI Promotion Act and the AI Guidelines for Business, is voluntary and does not itself create clinical obligations. What actually binds a hospital, developer, or health-tech company comes from law that predates and is not specific to AI: the PMD Act as administered by the PMDA for anything that qualifies as a medical device, the Medical Practitioners Act for who is allowed to diagnose and treat, and APPI for the patient data any AI system depends on. Organizations that treat the AI Promotion Act as the compliance finish line will miss the frameworks that actually carry legal consequences in Japanese healthcare.

Primary sources

Related articles