Japanese enterprises adopting generative AI tools, from ChatGPT Enterprise deployments to Microsoft 365 Copilot rollouts, are governed by a two-layer system that is easy to misread. The AI-specific layer, made up of the AI Guidelines for Business, the AI Promotion Act, and the government's AI Basic Plan, is voluntary. The layer that actually binds a company's conduct is ordinary law applied to a new technology: the Act on the Protection of Personal Information (APPI) and the Copyright Act. Understanding how these layers interact, rather than treating either in isolation, is the starting point for sound generative AI governance in Japan.
What the AI Guidelines for Business (v1.2) say about generative AI
The AI Guidelines for Business (AI事業者ガイドライン) are a joint framework issued by the Ministry of Economy, Trade and Industry (METI) and the Ministry of Internal Affairs and Communications (MIC). Version 1.0 was published on 19 April 2024, consolidating three earlier sets of guidance on AI development, use, and governance into a single document. The current version, v1.2, was published on 31 March 2026 and is available from METI's website.
The Guidelines are legally voluntary but function as the de facto standard of care for AI governance in Japan: regulators, courts, and business partners increasingly reference them as the benchmark for what a reasonably careful organization should be doing. They apply to three categories of actor, AI developers, AI providers, and AI users, and enterprises adopting generative AI tools built by others will generally sit in the "AI user" category, with some overlap into "AI provider" where they build internal applications on top of a foundation model.
On generative AI specifically, the Guidelines identify a set of risks that are qualitatively different from earlier, narrower AI systems. Hallucination is treated as a first-order concern: generative models can produce fabricated information, including invented citations, guidance, or case law, in a fluent and plausible style that makes the error hard to catch downstream. Intellectual property risk is flagged both at the training stage, where training data may incorporate third-party copyrighted works, and at the output stage, where generated content can inadvertently reproduce protected material. Misinformation and disinformation generation and distribution are named as a new category of societal risk that earlier, non-generative AI systems did not present at the same scale. Privacy risk is called out specifically in the context of retrieval-augmented generation (RAG) and multimodal generation, where personal or confidential information embedded in reference or source data can be unintentionally surfaced in a model's output even when the underlying request did not ask for it.
Rather than prescribing a fixed technical checklist, the Guidelines direct organizations toward a risk-based approach: risk does not need to be reduced to zero, but an organization needs a demonstrable framework for identifying, assessing, and managing it across the AI lifecycle, with human-in-the-loop review before AI-assisted actions have external or material effect, audit logging of model use and approvals, and clear allocation of responsibility across the developer, provider, and user roles in a given deployment. In practice, many enterprises build their generative AI incident-response playbooks around a small set of recurring failure patterns, such as leakage of confidential information, mistaken external communications, business decisions made in reliance on hallucinated output, and abuse of AI systems including prompt injection, even though the Guidelines themselves do not prescribe this specific categorization as an official structural feature.
The headline addition in v1.2 is a new risk framing for autonomous AI agents and physical AI, reflecting how quickly agentic deployments have moved from pilot to production since the 1.0 version. For enterprises whose generative AI use includes agentic features, such as a Copilot or ChatGPT-based assistant that can take actions rather than only generate text, this is the part of v1.2 most directly on point, and it reinforces rather than replaces the human-in-the-loop expectations already applied to generative AI use generally.
The AI Promotion Act: important context, limited direct application
Japan's AI Promotion Act (Act No. 53 of 2025), passed by the Diet on 28 May 2025 and promulgated on 4 June 2025, is the country's first national AI statute. It is deliberately structured as a promotion and framework law rather than a regulatory one: it contains no penalties, no prohibitions, and no mandatory conformity assessment regime. Its only business-facing obligation is a non-binding duty under Article 7 to endeavor to cooperate with government AI measures.
For an enterprise governing its generative AI use, the Act's practical relevance is indirect. It established the AI Strategy Headquarters, a Cabinet body chaired by the Prime Minister that took effect on 1 September 2025 and held its first meeting on 12 September 2025, and it tasked that body with producing an AI Basic Plan, a Cabinet-level statement of mid- and long-term AI policy first decided on 23 December 2025 and revised on 14 July 2026. Neither the Headquarters nor the Basic Plan creates enforceable rules specific to generative AI. What the Act does is set the institutional and policy backdrop against which the AI Guidelines for Business, sector regulators, and eventually further legislation will develop. Enterprises should not expect the Act itself to answer questions about what they can or cannot do with employee prompts, customer data, or model outputs; those answers currently come from APPI and the Copyright Act.
APPI and generative AI: where the binding obligations actually sit
The Personal Information Protection Commission (PPC), which enforces APPI, issued two related actions on the same day, 2 June 2023: an alert directed at OpenAI concerning the handling of specially protected personal information (要配慮個人情報) and purpose-of-use notification, and a broader alert to businesses and the public on the use of generative AI services generally. Both remain the PPC's primary published guidance on generative AI as of this writing, and both are available on the PPC's website.
The core message for enterprise use is straightforward but easy to miss in day-to-day practice. When an employee enters a prompt containing personal data into a generative AI service, that input must fall within the scope of the purpose of use the organization has already specified for that personal data under APPI. Feeding customer or employee personal data into a generative AI tool for a purpose unrelated to why that data was originally collected, such as using customer records to draft marketing copy when the stated purpose of collection did not cover that use, risks a straightforward purpose-of-use violation independent of anything specific to AI.
A second, more technical issue concerns cross-border transfer. Many enterprise generative AI deployments, including ChatGPT Enterprise and Microsoft 365 Copilot, are ultimately processed on infrastructure outside Japan. Under APPI, providing personal data to a third party located abroad is subject to Article 28, which generally requires the data subject's prior consent unless an exception applies, such as the recipient being located in a jurisdiction the PPC recognizes as having an equivalent data protection framework, or the recipient having implemented measures verified as meeting APPI-equivalent standards. Separately, outsourcing personal data processing to a vendor is not treated as "provision to a third party" under Article 27 in the way that would otherwise trigger consent requirements, but this entrustment exception does not remove the Article 28 cross-border analysis when the outsourced vendor sits overseas; the PPC's own published guidance and FAQ on cross-border transfer address this interaction directly and should be the reference point for legal review rather than general commentary.
In practice, this means the governance question for an enterprise is less "is generative AI allowed" and more "under what contractual and technical arrangement is this specific vendor processing this specific data." Enterprise and API tiers of major generative AI services typically differ from free consumer tiers in that the vendor contractually commits not to use submitted data to train its models, and reputable vendors publish data processing and residency terms that should be checked against the organization's cross-border transfer obligations before rollout, not after.
Copyright: training-stage permission does not extend to output-stage liability
Article 30-4 of the Copyright Act, in force since 1 January 2019, permits the use of copyrighted works for information analysis, including AI training, without the rightsholder's authorization, provided the purpose is not to personally enjoy the thought or feeling expressed in the work, and provided the use does not unreasonably prejudice the copyright owner's interests. This provision is frequently misunderstood as a general license for AI-related copyright risk. It is not: it addresses the training and development stage only.
At the output stage, ordinary copyright law applies in full. If a generative AI tool produces output that is substantially similar to, and was generated in reliance on, a specific existing copyrighted work, standard infringement analysis under the Copyright Act's reproduction and adaptation rights applies regardless of how the underlying model was trained. The Agency for Cultural Affairs has published detailed guidance on this distinction, including "Approach to AI and Copyright" (AIと著作権に関する考え方について), finalized by the Copyright Subdivision's Legal System Subcommittee on 15 March 2024, and a practical "Checklist and Guidance" document published on 31 July 2024 that walks through the analysis for developers, providers, and users separately. Enterprises using generative AI output in commercial materials, marketing, or products should treat output-stage review, checking generated content against known works before publication or use, as a distinct governance step from any training-stage comfort Article 30-4 provides.
Practical governance steps for a Japanese enterprise adopting generative AI
Drawing the AI Guidelines, APPI, and the Copyright Act together, a workable governance program for enterprise generative AI use in Japan should include the following elements.
- An internal generative AI use policy that classifies data by sensitivity and specifies which categories, particularly personal data and confidential or trade secret information, may or may not be entered as prompts, and under what approval.
- Vendor and tier due diligence confirming whether the deployed tier trains on submitted data, where data is processed and stored, and whether the arrangement is structured, and documented, as an entrustment relationship that the organization properly supervises, consistent with APPI's Article 27 entrustment framework and the PPC's cross-border transfer guidance under Article 28.
- Purpose-of-use screening so that personal data entered into a generative AI tool stays within the purpose of use already specified for that data, with a defined escalation path when a proposed use falls outside it.
- Human-in-the-loop checkpoints before AI-generated output triggers an external action, a customer-facing communication, or a business decision, consistent with the AI Guidelines' general risk-based approach to hallucination and output-reliability risk.
- Output-stage review for both factual accuracy, given known hallucination risk, and copyright exposure, given that Article 30-4 does not cover generated output, before commercial use or external publication.
- Audit logging and an incident-response playbook covering practical failure patterns such as confidential information leakage, mistaken outbound communications, hallucination-driven business errors, and abuse such as prompt injection, a categorization useful for internal governance even though the Guidelines do not mandate it as an official structure.
- Role clarity across the AI developer, AI provider, and AI user categories the Guidelines use, particularly where the enterprise builds internal tools on top of a third-party foundation model and so takes on provider-like responsibilities for that internal deployment.
- Sector overlay where applicable. A financial institution, for example, should also read its use of generative AI against the Financial Services Agency's discussion paper on sound AI use, updated to v1.1 on 3 March 2026, and organizations in regulated sectors such as healthcare or manufacturing should confirm equivalent sector-specific guidance from their own regulator rather than assuming the general AI Guidelines are sufficient on their own.
- Periodic review against the current version of the AI Guidelines, given that the framework has already been revised multiple times, from v1.0 in April 2024 through intermediate v1.01 and v1.1 releases to the current v1.2 in March 2026, with the AI agent and physical AI risk framing in v1.2 being the most recent example of guidance moving to keep pace with how the technology is actually being deployed.
The frame to carry forward
None of the AI-specific instruments, the AI Promotion Act, the AI Guidelines for Business, or the AI Basic Plan, create binding, generative-AI-specific legal obligations in Japan. What binds a Japanese enterprise using ChatGPT, Copilot, or any other generative AI tool is the application of existing law, principally APPI's rules on purpose of use, third-party provision, and cross-border transfer, and the Copyright Act's ordinary infringement rules at the output stage, to a new class of technology. The AI Guidelines for Business supply the risk taxonomy and the operational playbook, hallucination, IP exposure, misinformation, RAG and multimodal privacy leakage, and now agentic risk, but compliance itself rests on getting the APPI and copyright analysis right for each specific tool, tier, and use case. Enterprises that treat the Guidelines as the whole of their obligation, without doing the underlying APPI and copyright work, are missing where the actual legal risk sits.
Primary sources
- AI Guidelines for Business v1.2, 31 March 2026 (METI / MIC, PDF)
- AI Promotion Act, official English translation (Japanese Law Translation)
- AI Promotion Act, official Japanese text (National Diet Library)
- Personal Information Protection Commission, alert on generative AI service use, 2 June 2023
- Agency for Cultural Affairs
- FSA Discussion Paper on AI in Financial Services, v1.1, 3 March 2026
- Cabinet Office, Japan
- Prime Minister's Office of Japan
- Government of Japan Public Relations Office
Related articles
- Japan's AI Strategy Headquarters and the AI Basic Plan: The Governance Machinery Behind Japan's AI Policy
- Japan's Copyright Act Article 30-4 and AI Training: What It Permits, and Where the Limits Are Being Tested
- Japan's FSA Charts a Soft-Law Path for AI in Financial Services
- Japan's AI Promotion Act vs the EU AI Act: A Comparison of Two Governance Models
- Japan AI Governance Checklist for Enterprises: A Practical Compliance Roadmap
- AI Governance in Japanese Healthcare: How PMDA, the AI Promotion Act, and APPI Actually Apply
- AI Governance in Japanese Manufacturing and Robotics: Where Physical AI Meets Old Safety Law
- Japan's AI Promotion Act 2025: The World's Most Innovation-Friendly AI Law
- AI Governance in Japan by Industry: Finance, Healthcare, Manufacturing, and the Soft Law Approach
- Japan AI Policy: The Full Governance Landscape