AI Regulation in Japan.
Japan has an AI-specific law, the Act on Promotion of Research and Development and Utilization of AI-related Technology, which fully took effect on September 1, 2025. It mainly promotes AI development and sets governance responsibilities rather than imposing EU AI Act-style licensing or risk categories, so companies are primarily regulated through personal data protection, copyright, consumer and advertising, and sector-specific laws, with AI enforcement still largely guidance-led.
In force today5 instruments
Get the remaining 3 instruments and the founder FAQ. Free: subscribe once and every briefing on this device unlocks.
Already subscribed? Unlock →
- The July 17, 2026 amendments to the Act on the Protection of Personal Information were promulgated but are mostly scheduled to apply on a future date within two years, with implementing orders, PPC rules, and guidelines still to come.
- The Cabinet adopted an AI Basic Plan on December 23, 2025 and a revised plan on July 14, 2026. Monitor follow-on measures under the AI Act, including the AI guideline framework and any move from voluntary governance toward more specific duties.
- METI and MIC's AI Guidelines for Business Version 1.2, updated April 1, 2026, remain nonbinding but are the main practical benchmark for risk management, transparency, security, human oversight, and incident response.
Pending and recent legislation2 measures
Live from the Global AI Policy Radar.
Founder FAQAI law, regulators, what applies, what is next, penalties
Is there an AI-specific law in force here?
Yes. Japan’s Act on Promotion of Research and Development and Utilization of AI-related Technology fully took effect on September 1, 2025. It is mainly a promotion, governance, and coordination framework, not an EU AI Act-style licensing or risk-classification regime, and most private-sector duties are responsibilities or efforts supported by government guidance.
Who are the key regulators for AI?
The Personal Information Protection Commission oversees personal information issues, including data used to train, test, or operate AI systems. The Consumer Affairs Agency handles misleading consumer and advertising claims. The government also uses the AI-specific Act to coordinate policy, issue guidance, request information, make recommendations, and publicly disclose serious risks or non-cooperation.
Which rules apply to AI systems today?
AI deployments are principally governed by the Act on the Protection of Personal Information, copyright law, consumer and advertising rules, and applicable sector-specific rules. The AI-specific Act also applies, but it does not create a general licensing system, prohibited-practice list, or broad mandatory conformity assessment for private AI providers. Large designated digital platforms may also face transparency and fairness obligations.
What is coming next, and when?
The AI-specific Act is already fully in force as of September 1, 2025. It establishes national AI governance structures and an AI Basic Plan, with further government guidance and measures to promote trustworthy AI. The source does not provide additional dates for future rules.
What are the enforcement and penalty risks?
AI-specific enforcement remains comparatively light and guidance-led, but the government may request information, issue recommendations, and publicly disclose serious risks or non-cooperation. More concrete risks arise under adjacent regimes, where the Personal Information Protection Commission and Consumer Affairs Agency can investigate and take administrative action. Misleading performance claims may lead to corrective measures or surcharges, while privacy breaches, improper data handling, copyright infringement, and failures by covered platforms create additional exposure.
Not legal advice. For educational purposes only. AI-researched against official sources (2026-08-06), links verified.