Japan AI Promotion Act 2026: What Foreign Firms Must Do

Written by

Rie Sakurai

Reviewed by

KAIZEN Digital OÜ

The Japan AI Promotion Act is the country’s first dedicated law for artificial intelligence, and its most surprising feature is what it leaves out: there are no fines, no bans, and no licensing regime. Japan has chosen an innovation-first, soft-law path that sets national direction and principles while relying on cooperation, guidance, and public disclosure rather than penalties. For a foreign company deploying AI that touches Japanese users, that is easy to misread as “nothing to do.” It is not. Paired with the AI Guidelines for Business Version 1.2, issued in March 2026, the framework creates real reputational and governance expectations, and the companies that treat it as optional are the ones most exposed when an incident lands. This guide explains what the Act is, how its enforcement actually works, what Version 1.2 changed, and what a foreign company should do.

What the AI Promotion Act is

The full title is the Act on Promotion of Research, Development and Utilization of Artificial Intelligence-Related Technologies. It is Japan’s first statute written specifically for AI, and its purpose is set by its name: to promote development and use, while managing risk, rather than to restrict. According to law firm White & Case’s analysis, the Act carries no monetary penalties. It sets a national strategy, assigns coordinating responsibility inside government, and directs the creation of practical guidance, leaving the binding detail to existing laws such as privacy, IP, and consumer protection.

Timeline and what took effect when

The Act moved quickly. Japan’s National Diet passed it on May 28, 2025. Most provisions came into force on June 4, 2025, setting national goals for AI research, infrastructure, and use. The chapters that establish the governance machinery, the AI Strategy Headquarters and the AI Basic Plan, took effect on September 1, 2025, and the Headquarters held its first meeting on September 13, 2025. By November 2025 the government described the Act as in full effect. For a company planning its Japan AI posture, the practical reading is that the framework is live now, not a future proposal. The speed of the timeline, from Diet passage to full effect inside six months, is itself a signal: Japan is treating AI as a strategic priority it wants to move on quickly, and the guidance layer has been updated on a similarly fast cadence.

The AI Strategy Headquarters and the AI Basic Plan

The Act creates the AI Strategy Headquarters under the Prime Minister’s Office, led by the Prime Minister with all Cabinet ministers as members. This is a deliberately high-level structure: AI policy is coordinated from the center of government rather than parked in a single ministry. The Headquarters is responsible for drafting and updating the AI Basic Plan, the document that will guide Japan’s long-term AI strategy across using AI in priority sectors, building domestic AI capability and infrastructure, and enhancing reliability through guidelines, rights protection, and international engagement. The Basic Plan is where national direction becomes concrete over time, so it is worth tracking as it develops.

Soft law with teeth: the name-and-shame model

The most important thing to understand about enforcement is that the absence of fines does not mean the absence of consequences. The government’s tools are investigation, guidance, information requests, and public disclosure. Where a business is found to have infringed citizens’ rights through its use of AI, the government can investigate, request information, issue guidance, and, for serious cases, publicly disclose the name of the business involved. This is the “name and shame” model, and in a market as reputation-sensitive as Japan it is not a soft touch.

The logic is worth grasping. A fine is a known, bounded cost that a large company can absorb and move on from. A public statement from a Prime-Minister-led body that your company misused AI against Japanese citizens is unbounded in its effect on trust, partnerships, and procurement. For a foreign company still building its reputation in Japan, that exposure can matter more than a monetary penalty would. Enforcement also runs through cooperation: entities are expected to make reasonable efforts to align with the law’s principles, cooperate with investigations, and follow the guidance that results. A company that stonewalls an inquiry converts a manageable situation into the kind of case that gets a name attached to it.

Why Japan chose soft law, and how it compares

Japan’s approach is a deliberate contrast to the binding, penalty-backed model taking shape elsewhere. The European Union’s AI Act sorts AI systems into risk tiers and attaches mandatory obligations and substantial fines to the higher tiers. Japan looked at the same technology and chose the opposite instinct: keep the statute light, avoid chilling investment and experimentation, and steer behavior through principles and guidance rather than prohibition. The government’s own framing is innovation-first, and the structure follows from it, with a coordinating headquarters, a national plan, and business guidelines rather than a regulator issuing penalties.

For a foreign company operating across regions, this divergence has a practical consequence: a single global AI compliance posture will not map cleanly onto both Japan and the EU. A company can be fully compliant with a binding regime and still mishandle Japan, not by breaking a rule that carries a fine, but by failing the cooperation-and-reputation test that Japan’s model runs on. The mistake to avoid is assuming that “no fines” means “lower stakes.” The stakes are simply denominated differently, in trust and public standing rather than in euros, and in Japan that currency is not cheap. Reading Japan’s framework as a lighter version of the EU’s misses that the two are measuring different things.

There is also a stability argument in Japan’s favor for businesses. A soft-law framework can adapt through updated guidelines faster than a statute can be amended, which is why the AI Guidelines for Business have already reached Version 1.2. For a deploying company, that means the expectations will keep moving, but they will move through guidance you can read and adjust to, rather than through abrupt legislative change. The obligation is to stay current, not to wait for a final rulebook that is not coming. Companies that build a habit of reviewing each guideline update against their own deployments will find the framework predictable; those that check in once and assume nothing has changed are the ones likely to be caught out.

The AI Guidelines for Business (Ver1.2)

If the Act is the direction, the AI Guidelines for Business are the practice. They are the document a deploying company actually works from, and they were updated to Version 1.2 on March 31, 2026 by the Ministry of Economy, Trade and Industry together with the Ministry of Internal Affairs and Communications. The guidelines provide unified principles for AI governance, help business actors identify risks and take voluntary countermeasures across the AI lifecycle, and are explicitly non-binding soft law. They are the connective tissue between the Act’s high-level goals and a real deployment.

What Ver1.2 added in 2026

Version 1.2 is not a cosmetic refresh. It expands the guidelines to reflect how AI is actually being used in 2026. According to a Lexology analysis of the key updates, Ver1.2 introduces new definitions for AI agents and physical AI, recognizing that AI now acts in the world and influences decisions rather than just generating text. It articulates a design philosophy that makes human judgment essential, a direct response to increasingly autonomous systems. And it broadens the catalog of AI-related risks, adding discussion of attacks against AI systems, privacy-infringement risks arising from multimodal generative AI, cameras, and voice recognition, the possibility that hallucinations may sometimes produce benefits as well as harms, risks specific to the education sector, risks of financial loss, and risks of infringing licenses, qualifications, and other rights.

For a deploying company, these additions are a checklist in disguise. If you run AI agents that take actions, deploy cameras or voice systems that process personal data, or operate in a sensitive area such as finance or education, Ver1.2 has named your risks and expects you to have thought about them.

The risk-based, lifecycle approach

The guidelines take a risk-based approach: the level of governance a company is expected to apply scales with the risk its AI use presents, rather than imposing one uniform standard on everyone. They also frame governance across the AI lifecycle, from design and data through deployment and monitoring, rather than as a one-time sign-off. In practice this means Japan expects an “agile governance” posture: identify risks for your specific use, put proportionate controls in place, and revisit them as the system and its context change. This is lighter than a prescriptive rulebook, but it puts the burden of judgment on the company. There is no checklist that, once completed, makes you compliant; there is a duty to keep exercising judgment.

What does proportionate governance look like in practice? For a low-risk internal tool, it may be as light as a short risk note and a named owner. For an AI agent that makes or shapes customer-facing decisions, or a system processing sensitive personal data, the guidelines point toward documented risk assessment, a defined point of human oversight, monitoring after launch, and a record you could show if asked. The guidelines do not prescribe a single template, which is the point: two companies with different risk profiles should not end up with identical governance. The discipline is to size the controls to the risk and to be able to explain why you sized them that way.

Ownership is the part companies most often get wrong. Because the framework is non-binding and cross-cutting, AI governance can fall between legal, engineering, and the business, and end up owned by no one. Ver1.2’s insistence that human judgment be essential is, in organizational terms, a call to name the humans. Assign clear accountability for AI decisions, give that role the authority to pause or change a deployment, and make sure it is close enough to the technology to understand it. A named, empowered owner is worth more than a long policy document nobody applies.

Does this apply to your company?

The framework governs AI research, development, and use connected to Japan. A foreign company that develops or operates AI systems serving Japanese businesses or citizens falls within its orbit, regardless of where the company is headquartered. The practical test is not where your servers or your head office sit; it is whether your AI touches people or businesses in Japan.

Because the framework is soft law, the question is rarely “will we be fined,” since the answer is no. The real questions are whether your AI use could be seen as infringing the rights of Japanese users, whether you could cooperate credibly with a government inquiry if one came, and whether your governance would survive public scrutiny. A company that can answer those confidently has little to fear from the name-and-shame model. A company that cannot has a reputational exposure that no absence of statutory fines removes. This is also why the framework interacts with the rest of your Japan operation: AI governance is becoming part of what it means to be a credible counterparty, alongside the basics of doing business in Japan.

How it sits with Japan’s binding laws

The soft-law AI framework does not float free of the rest of the statute book. It sits on top of Japan’s existing binding laws, which continue to apply to AI just as they do to any other technology. The most relevant is the Act on the Protection of Personal Information, Japan’s data-protection law, which governs how you collect and use the personal data that trains and feeds most AI systems, and which does carry enforcement. Copyright, consumer-protection, and sector-specific financial rules apply in the same way. The AI-specific framework adds a layer of principles and reputational accountability; it does not displace the hard-law obligations underneath. The correct mental model is two layers: binding laws you must not break, and an AI governance layer where you are expected to exercise and document good judgment. A foreign company that focuses only on the novel AI layer and neglects the data-protection layer underneath has misjudged where its real legal risk sits.

This matters most for the AI systems Ver1.2 singled out. A camera or voice system that processes personal data engages the data-protection law directly, and the AI guidelines on top of it. An AI agent that acts autonomously in a regulated area can touch sector rules as well as the guidelines. The layered picture is the one to plan against.

What foreign companies should do now

  • Map where your AI touches Japan. Identify every AI system that serves, profiles, or makes decisions about Japanese users or businesses. That map defines your exposure.
  • Read your risks off Ver1.2. Walk the expanded Version 1.2 risk catalog against your deployments, paying particular attention to AI agents, camera and voice systems, and any use in finance, health, education, or other sensitive areas.
  • Stand up proportionate governance. Adopt a risk-based, lifecycle governance process: document the risks for each use, assign human accountability, and set a cadence to review. Match the effort to the risk rather than over- or under-engineering.
  • Keep human judgment in the loop. Ver1.2 makes this explicit; ensure consequential AI decisions have a defined point of human oversight and a record of it.
  • Be ready to cooperate. Decide in advance who would field a government information request, and keep the documentation that would let you respond quickly and credibly.
  • Track the AI Basic Plan. The binding edges of Japan’s approach will emerge through the Basic Plan and future guideline versions, so treat this as a moving framework, not a fixed one.

Key Takeaways

  • First AI law, no penalties: the AI Promotion Act (passed May 28, 2025; in full effect by late 2025) sets national direction with no fines and no bans.
  • Central governance: the AI Strategy Headquarters, led by the Prime Minister with all Cabinet ministers, coordinates policy and drafts the AI Basic Plan.
  • Name and shame: enforcement runs on investigation, guidance, and public disclosure of businesses that infringe citizens’ rights, a real risk in a reputation-sensitive market.
  • Ver1.2 (March 31, 2026): the AI Guidelines for Business now define AI agents and physical AI, make human judgment essential, and expand the risk catalog.
  • Risk-based and lifecycle: governance expectations scale with risk and run across the AI lifecycle, putting the burden of ongoing judgment on the company.
  • Applies by connection to Japan: foreign companies whose AI serves Japanese users or businesses are within scope, wherever they are headquartered.

What to Read Next

Authoritative references: METI’s AI Guidelines for Business Ver1.2, and the Government of Japan’s explainer on the AI Promotion Act.

Deploying AI that reaches customers in Japan?

Get expert guidance from KAIZEN Digital OÜ, Japan market entry consultants.

Contact Us

Search

Category

Recent Posts

japan-ai-promotion-act
Japan AI Promotion Act 2026: What Foreign Firms Must Do
japan-specified-skilled-worker-visa
Japan Specified Skilled Worker Visa 2026: Employer Guide
employer-of-record-japan
Employer of Record in Japan 2026: Compliant Hiring Guide
Japan Market Entry Guide
Japan Market Entry: The Complete Guide for 2026
hsp-visa-thumbnail-blog-1200x630-1
Japan Highly Skilled Professional Visa: Complete Guide