Japan Legible

AI and Governance

Japan's AI plan is a governance signal, not a product licence.

By Japan Legible

Published
Last checked
Reading time
9 minutes
An evolving indigo plan scroll orbits a transparent AI mechanism while a separate cobalt product gate remains unstamped.

The operator decision is to use Japan's AI policy as a trigger for continuing governance, not as a product approval route. The national AI Act, the appropriateness guidelines, and the July 2026 Basic Plan establish direction, responsibilities, and mechanisms for government action. They do not create a general licence that certifies an AI product as lawful or safe.

A company launching or using AI in Japan still needs to identify the people affected, the applicable sector and existing laws, the data and intellectual-property basis, the human decision point, the expected failure modes, and the evidence retained through the product lifecycle.

A national plan is not a product licence.. Maintain an AI system register and product-specific launch controls while monitoring annually changing national plans and guidance.
A national plan is not a product licence.Cabinet Office, Artificial Intelligence Act page.

The AI Act is a promotion-and-governance framework

The Cabinet Office's AI Act page records that the Act was promulgated and partly brought into force on June 4, 2025. It became fully effective on September 1, 2025, when provisions including the AI Strategy Headquarters took effect.

The Act's structure combines promotion with risk response. It establishes national policy machinery, requires a Basic Plan, supports research, facilities, talent, and international rule formation, and calls for guidance aligned with international norms. It also supports information gathering, analysis of incidents that infringe rights and interests, investigation, and guidance, advice, and information for businesses.

That is more than a public aspiration, but it is not a product-registration system. There is no general Cabinet Office procedure in these materials through which a vendor submits a model and receives permission to sell it.

The immediate governance implication is that an operator should be able to explain its AI use and respond to evolving official inquiry or guidance. A policy statement without a system inventory or incident evidence will not perform that function.

The guidelines favor risk-based, active governance

The AI Strategy Headquarters adopted the appropriateness guidelines on December 19, 2025. They apply across actors and are intended to encourage voluntary and active measures for trustworthy AI.

The guidelines avoid one absolute definition or uniform adequacy threshold. They ask each actor to respond at an appropriate level based on its size, position, AI characteristics, purpose, and risk, using the technology and knowledge available at the time.

The principles include human-centered design, fairness, safety, transparency, accountability, security, privacy and personal information, fair competition, AI literacy, and innovation. The operating approach emphasizes risk basis, stakeholder engagement, end-to-end governance, and agile improvement.

This supports proportionality. A low-impact internal drafting assistant does not need the same safeguards as an agent that initiates transactions, controls equipment, or affects access to an important service. It also means there is no single checklist that proves compliance for every use.

What the official framework changes. Map the applicable scope before choosing the control.
What the official framework changesCabinet Office, Artificial Intelligence Act page. · Cabinet Office, Artificial Intelligence Basic Plan Phase II.

Phase II shows how quickly policy can move

Japan's first AI Basic Plan was adopted on December 23, 2025. The Cabinet approved Phase II on July 14, 2026, about seven months later.

The second plan responds to the rapid growth of agentic AI. It describes AI moving from a support tool toward systems that can plan, execute, verify, and revise work. Its policy priorities are organized around accelerating AI use, strengthening development capacity, leading AI governance, and continuously transforming society for human-AI collaboration.

The plan puts particular emphasis on vertical AI for specific fields, physical AI acting in the real world, domestic computing and data capacity, government AI adoption, technical evaluation, cybersecurity, workforce effects, and human responsibility for decisions.

It also says the Basic Plan will be changed annually for the time being and monitored with appropriate benchmarks or KPIs. That is a strong signal against annual policy review alone. A company needs a mechanism that can absorb changes in guidance, sector rules, technical expectations, and incident patterns during the year.

The policy watch should translate each official change into a controlled question. A new emphasis on agentic AI should lead the operator to identify systems that can plan or execute actions, not merely add the phrase to a corporate policy. A stronger focus on physical AI should route review toward systems connected to equipment or real-world movement. A statement about human decision responsibility should be tested against actual approval, override, and incident procedures.

This translation step keeps national strategy and product governance separate but connected. The Basic Plan sets direction for government action. The company's register shows which deployments may be affected, which control owner must review them, and what evidence supports the next internal decision. Where the plan announces further examination rather than a completed rule, the appropriate status is "monitor," not "compliant" or "noncompliant."

Governance should follow the system, not the model name

A useful AI register should be organized around deployments and decisions rather than a list of model vendors. The same model can create very different exposure depending on data, tools, autonomy, users, and consequences.

For each deployment, the register should identify:

  • the business purpose and owner;
  • whether the system develops, provides, or uses AI;
  • the model and supplier dependencies;
  • input data and prohibited data;
  • affected users and non-users;
  • the decision or action the AI can influence;
  • human review and override;
  • testing and monitoring;
  • security and access controls;
  • incident and complaint routes; and
  • the date and reason for reassessment.

Agentic systems require additional attention because they may call tools, change data, or initiate actions. A conventional output-review control may be inadequate if execution occurs before a person sees the result.

The register also needs change criteria. A new model version, added data source, expanded user group, new tool permission, or shift from recommendation to execution can alter the evaluated use even when the product name stays the same. The owner should decide in advance which changes trigger reassessment and which can proceed under an existing approval. That makes the guideline's agile approach observable: review follows material changes in use and risk rather than a fixed annual anniversary alone.

The operating decision. Maintain an AI system register and product-specific launch controls while monitoring annually changing national plans and guidance.
The operating decisionCabinet Office, Artificial Intelligence Basic Plan Phase II. · AI Strategy Headquarters, AI appropriateness guidelines.

Product approval remains a separate company decision

The national plan encourages experimentation and wider use, including in government, municipalities, small and medium-sized businesses, and regional settings. That policy direction does not decide whether a specific product should launch.

A product approval should combine legal, safety, security, privacy, intellectual-property, operational, and customer analysis. It should specify the use that was evaluated. Approval for internal summarization does not automatically cover automated customer decisions or external tool execution.

The record should also state residual uncertainty. AI testing rarely establishes that a system cannot fail. It can show which scenarios were tested, what thresholds were used, what controls remain, and who accepted the residual risk.

This is consistent with the guidelines' agile approach. Governance is not complete at launch. Monitoring, incident review, and material-change reassessment are part of the decision.

Existing law remains active

The Cabinet Office's official overview says the AI Act works in addition to existing criminal law and individual sector laws. Depending on the use, privacy, copyright, consumer, competition, employment, financial, medical, transport, or other requirements may apply.

The absence of a general product licence therefore does not create a legal vacuum. It means the operator must map the deployment to the laws and regulators that govern the activity.

The same distinction applies to standards and guidelines. They can help define reasonable controls and evidence. Alignment does not itself create a statutory safe harbor unless a relevant law or authority says so.

The counterargument. Keep the boundary visible.
The counterargumentCabinet Office, Artificial Intelligence Act page.

Counterargument: "not a licence" can understate the framework

The strongest counterargument is that the AI Act gives government meaningful tools. It supports investigation of problematic cases, analysis, official guidance, and future policy revision. A company should not dismiss it as non-binding ethics.

That counterargument is correct. "Not a product licence" should prevent a false claim of approval, not minimize governance consequences. The framework can shape regulatory expectations, procurement, sector guidance, and the evidence expected after an incident.

The appropriate response is neither certification language nor complacency. It is a documented, risk-based system capable of showing active control.

Unknowns and source limitation

Phase II leaves important matters under continued examination. These include responsibility boundaries for agentic AI, legal treatment of rights infringement and loss, governance of high-performance AI, sector implementation, and the specific KPIs used to monitor the plan.

The official sources used here are central Cabinet Office materials. They describe the cross-government framework but do not cover every ministry guideline or regulated industry. A product assessment must add the relevant sector's primary sources and current law.

The plan is also intentionally changeable. Statements about future implementation should be presented as policy direction unless a concrete measure has been adopted.

Legal and program-scope caution

Do not say the AI Act licenses, certifies, or guarantees an AI system. Do not say the framework is purely voluntary or has no enforcement relevance. Guideline alignment is not a universal safe harbor, and national promotion policy does not displace existing legal duties.

What remains unknown. The next decision needs entity-level evidence.
What remains unknownEditorial synthesis or stated unknown; see the article source limitation.

Practical operator decision

Create a living AI governance register tied to launch and change approval. Require a named owner, deployment-specific risk analysis, data and rights basis, human responsibility, testing evidence, incident route, and reassessment date.

Add a policy watch that distinguishes enacted law, adopted guidance, government plans, and proposals. When the Basic Plan or sector guidance changes, route the change to affected systems rather than issuing a general memo.

The result should let management answer two separate questions: why the company believes this AI use is acceptable now, and what evidence would cause that decision to change. Japan's policy framework is a signal to maintain that capability. It is not a substitute for it.

Evidence

Sources

  1. Artificial Intelligence Act pageCabinet Office · June 4, 2025
  2. Artificial Intelligence Basic PlanCabinet Office · July 14, 2026
  3. Artificial Intelligence Basic Plan Phase IICabinet Office · July 14, 2026
  4. AI appropriateness guidelinesAI Strategy Headquarters · December 19, 2025