Enterprises operating in Japan face an unusual compliance picture. The country's AI-specific law, the Act on Promotion of Research and Development, and Utilization of AI-related Technology (Act No. 53 of 2025, promulgated 4 June 2025), is a promotion and framework statute. It creates no prohibitions, no penalties, and no mandatory conformity assessment for AI systems. Its only business-facing obligation is a non-binding duty under Article 7 to endeavor to cooperate with national AI measures. The same is true of the government's flagship guidance document, the METI/MIC AI Guidelines for Business, and of sector papers such as the Financial Services Agency's AI discussion paper. All of it is voluntary.

That does not mean Japan is a low-risk jurisdiction for AI deployment. What binds an enterprise using AI in Japan is existing law applied to AI: the Act on the Protection of Personal Information (APPI), the Copyright Act, competition law, and sector-specific regulation for finance, healthcare, and other regulated industries. The practical task for a compliance or governance function is to stop treating "Japan AI regulation" as a single question and instead run two parallel tracks: hard compliance with binding law, and documented alignment with the voluntary standard of care. This checklist sets out both, in the order a governance program should actually work through them.

1. Build a complete AI system inventory

Nothing below this step is possible without an accurate inventory. Enterprises consistently underestimate how many AI systems are in use because much of the exposure comes from tools employees have adopted informally rather than from centrally procured systems.

  • Catalogue every AI system in use in or affecting Japan operations: internally built models, licensed enterprise AI products, embedded AI features in third-party software, and generative AI tools accessed directly by staff.
  • Record for each system: the business function it serves, whether it processes personal information, whether it was trained on or ingests copyrighted material, the vendor and where the vendor processes data, and whether the use case touches a regulated sector (financial services, healthcare, employment decisions).
  • Classify each system by role under the AI Guidelines for Business taxonomy: is your organization acting as an AI developer, an AI provider, or an AI business user for that system. The same organization can hold different roles for different systems, and the expected voluntary measures differ by role.
  • Assign an accountable owner per system and set a review cadence, since AI inventories go stale quickly as new tools and model versions are adopted.

2. Map APPI obligations onto every AI use case

The APPI is enforced by the Personal Information Protection Commission (PPC) and applies to AI systems exactly as it applies to any other processing of personal information. There is no AI carve-out. On 2 June 2023 the PPC issued a public alert on the use of generative AI services, cautioning business operators that entering personal information into prompts must stay within the scope necessary for the specified purpose of use, and that using personal data for purposes beyond generating the response, such as further model training, can raise separate APPI issues if not properly disclosed and consented to.

  • Confirm the purpose of use for personal information fed into any AI system is specified and notified in line with APPI requirements, including where employees paste customer or HR data into a generative AI prompt.
  • Review vendor contracts and terms of service for AI tools to determine whether prompt data or uploaded content is retained or used for the vendor's own model training, and whether that use is disclosed and consistent with your stated purpose of use.
  • Apply APPI's cross-border transfer rules where an AI vendor processes data outside Japan; this is a live compliance point, not a formality, given how many generative AI platforms route data through offshore infrastructure.
  • Treat outputs that reveal or infer sensitive categories of personal information (health, criminal history, and similar special-care items) with the same handling requirements APPI imposes on that data when collected directly.
  • Track the amendment to the APPI, which the Cabinet approved and submitted to the Diet on 7 April 2026. The bill addresses AI-related data use directly, including a proposed "statistical processing" concept intended to clarify some AI training uses, alongside tighter rules on biometric data, minors' data, and expanded PPC enforcement powers. Per the Personal Information Protection Commission's own announcement, the bill passed the Diet on 10 July 2026 and was promulgated on 17 July 2026 (Kanpo Reiwa 8 special issue No. 160, ppc.go.jp/news/press/2026/260717/). Confirm the enforcement date and any transitional provisions against the PPC's published implementation guidance when finalizing compliance timelines.

3. Clear Copyright Act Article 30-4 for training and content use

Article 30-4 of the Copyright Act, in force since 1 January 2019, permits using copyrighted works for information analysis, including AI training, without the rightsholder's authorization, where the purpose is not to allow a person to enjoy the thoughts or feelings expressed in the work. The permission is broad but not absolute: it does not apply where the use would unreasonably prejudice the interests of the copyright owner in light of the nature and purpose of the work or the circumstances of the use.

  • Document the purpose of any Article 30-4 reliance for each training or data-analysis use case: is the system extracting statistical patterns, or does its output risk substituting for the original work in the market.
  • Assess the proviso specifically for cases with elevated risk, such as training on a narrow, curated dataset drawn from a single rightsholder's catalog, or systems whose outputs closely resemble specific existing works, since these are the fact patterns most likely to fall outside the exemption.
  • Consult the Agency for Cultural Affairs' 2024 guidance, including the "General Understanding on AI and Copyright in Japan" published by the Copyright Subdivision's Legal Subcommittee and the accompanying checklist for AI-related copyright questions, both of which set out how the agency currently interprets the Article 30-4 proviso.
  • Separate the training question from the output question. Article 30-4 governs use of works as inputs; whether a specific AI output infringes an existing work is assessed under ordinary infringement analysis, including similarity and reliance, and is not resolved by Article 30-4 at all.
  • Keep records of training data provenance and licensing decisions, since the burden of showing that a use falls within the exemption, or that a license was obtained where it did not, sits with the enterprise if a dispute arises.

4. Align to the AI Guidelines for Business as the de facto standard of care

The AI Guidelines for Business, jointly issued by METI and the Ministry of Internal Affairs and Communications, is the closest thing Japan has to a national AI governance standard, even though it is entirely voluntary. Version 1.0 was published 19 April 2024, consolidating three earlier development, use, and governance guidelines into one framework. Version 1.2, published 31 March 2026, added definitions and risk framing for AI agents and physical AI, plus expanded discussion of hallucination-related risks and possible benefits.

  • Identify which of the three actor categories, AI developer, AI provider, or AI business user, applies to each system in your inventory, since the guidelines set distinct expected measures for each.
  • Work through the common guiding principles that apply across all AI business actors and confirm your governance program addresses each one, rather than treating alignment as a single document review.
  • For any system where you are knowingly not following a relevant guideline recommendation, document the business reason. Because the guidelines are non-binding, the legal risk of deviation is low, but the reputational and litigation-posture risk of an undocumented departure from the recognized standard of care is not.
  • Update your alignment assessment on each new version of the guidelines. Version 1.2's new coverage of AI agents is directly relevant to any enterprise deploying autonomous or semi-autonomous AI agents, since agentic systems raise oversight and human-judgment questions the earlier versions did not directly address.

5. Layer in sector-specific requirements

General AI governance is not sufficient in regulated industries, where sector regulators have published their own AI-specific expectations, some binding through existing licensing and conduct rules, others advisory.

  • Financial services. The Financial Services Agency's discussion paper on sound AI use in the financial sector, first published March 2025 and updated to Version 1.1 on 3 March 2026, is principles-based and non-binding, but it maps AI use cases against existing risk management and governance expectations that financial institutions already operate under. Firms should benchmark AI risk management practices against the paper's discussion points and be prepared to explain gaps in supervisory dialogue.
  • Healthcare and medical devices. AI-based software intended for diagnosis, treatment, or prevention is regulated as a medical device under the Pharmaceuticals and Medical Devices Act where it meets the relevant classification threshold, and requires review by the Pharmaceuticals and Medical Devices Agency (PMDA). PMDA has approved a substantial number of AI-based Software as a Medical Device products, concentrated in radiology, and operates a dedicated SaMD consultation process. Any AI system used for clinical decision support or diagnostic purposes should be screened early for whether it falls within this regime.
  • Competition law. The Japan Fair Trade Commission published a Generative AI Report (Version 1.0) on 6 June 2025 examining competitive dynamics across the infrastructure, model, and application layers of the generative AI market, and has flagged concerns spanning intellectual property infringement, misinformation, cybersecurity, and broader competition-policy risk across those layers. Enterprises building on or licensing dominant AI platforms should be alert to these dynamics, and any use of AI in pricing or algorithmic decision-making should be reviewed for collusion and coordination risk under ordinary competition law principles, which JFTC has indicated it will apply to AI-driven conduct rather than treating it as a novel category.
  • Employment and labor. There is no dedicated Japanese statute governing AI use in hiring or workforce management comparable to emerging rules in other jurisdictions. AI used in recruitment, performance evaluation, or workforce decisions should still be reviewed against general labor law principles on discrimination and fair treatment, and organizations should watch for further Ministry of Health, Labour and Welfare guidance as AI adoption in HR functions increases.
  • For any sector not covered above, confirm with local counsel whether an existing licensing regulator has issued AI-specific guidance; Japanese regulators have generally chosen to extend existing sectoral frameworks to AI rather than legislate new AI-specific rules, so the relevant guidance is often published by the regulator you already report to.

6. Assign board-level accountability

Because Japan's AI-specific rules are non-binding, the primary evidence of an organization having exercised reasonable care is its own governance record, not a regulatory filing. Boards should treat this as a documentation and accountability exercise as much as a technical one.

  • Name a single accountable executive or committee for AI governance, with clear reporting lines to the board, rather than leaving AI risk distributed across IT, legal, and business units without a coordinating owner.
  • Put AI governance on a standing board or risk committee agenda, covering the inventory, APPI and Copyright Act compliance status, AI Guidelines for Business alignment, and sector-specific exposure, at a cadence proportionate to the pace of AI adoption in the business.
  • Track the AI Strategy Headquarters, the Cabinet body chaired by the Prime Minister established under the AI Promotion Act, and the national AI Basic Plan it produces. The first Basic Plan was decided by Cabinet on 23 December 2025 and a revised plan was decided 14 July 2026. Neither creates direct enterprise obligations, but both signal the direction of future government AI measures and inform the Article 7 duty to cooperate.
  • Maintain a documented audit trail of AI governance decisions, including risk assessments, deviations from the AI Guidelines for Business, Article 30-4 assessments, and vendor due diligence outcomes. In a soft-law environment, this record is what demonstrates the organization met the applicable standard of care if a regulator, litigant, or business partner later raises a concern.
  • If the organization operates internationally, ensure the Japan-specific governance program is integrated into, not run separately from, group-level AI governance, and that board members understand where Japan's approach diverges structurally from binding regimes elsewhere, such as the EU AI Act, so that group policies are not assumed to satisfy Japan-specific legal obligations under APPI or the Copyright Act by default.

7. Monitor the evolving landscape on a fixed cycle

Japan's AI governance framework is still being built out. The AI Basic Plan is subject to revision, the AI Guidelines for Business has been updated roughly annually since 2024, the FSA discussion paper has already gone through a version update, and the APPI amendment bill remains before the Diet. A static compliance program will fall behind.

  • Set a recurring review, at minimum semi-annual, to check for new versions of the AI Guidelines for Business, the AI Basic Plan, sector regulator papers relevant to your industry, and progress of the APPI amendment bill.
  • For enterprises with international operations, track Japan's engagement with the G7 Hiroshima AI Process, the international framework Japan launched in May 2023 during its G7 presidency, which produced Guiding Principles and a voluntary International Code of Conduct for advanced AI developers. This remains soft law but signals the international norms Japanese guidance is likely to continue tracking.
  • Reassess sector exposure whenever the business enters a new regulated activity, jurisdiction, or market, since sector-specific AI guidance in Japan is issued regulator by regulator rather than centrally, and new guidance can appear without a coordinated national announcement.

The organizing principle behind all seven steps is the same. Japan has chosen not to legislate AI directly, and its voluntary guidance, however influential, carries no penalty for non-compliance on its own. The legal exposure for enterprises using AI in Japan comes from applying binding law that already exists, principally the APPI, the Copyright Act, and sector regulation, to a new technology, while the voluntary layer defines what good practice looks like around that binding core. A governance program that treats the AI Guidelines for Business as optional in substance as well as in form, on the theory that it carries no penalty, misreads the risk. The program that treats it as the working standard of care, documents its APPI and Copyright Act positions carefully, and keeps a current inventory and audit trail, is the one built to withstand scrutiny regardless of which way Japan's AI-specific rules develop next.

Primary sources

Related articles