Skip to content
Industry

Technology, AI, and Digital Policy in Japan

Japan is writing the rules for AI, platforms, data, and cybersecurity at the same time, and mostly through soft law, guidelines, and councils rather than a single statute.

Policy environment

How Technology, AI, and digital policy is made in Japan.

Japan’s approach to technology regulation is deliberately light on hard law and heavy on guidance. The AI Promotion Act, passed in 2025, created an AI Strategy Headquarters and a basic plan rather than prohibitions, while the AI Safety Institute and METI and MIC guidelines carry the practical expectations. The Mobile Software Competition Act, in force from December 2025, is the exception: hard obligations on designated platform operators, enforced by the Japan Fair Trade Commission.

Data protection under the Act on the Protection of Personal Information runs on a three-year review cycle, with the next amendment now moving through the Personal Information Protection Commission. Cybersecurity has shifted from guidance to statute with the Active Cyber Defense law, and the government-cloud program under the Digital Agency decides which providers can serve the public sector. Most of this is decided in advisory councils and public consultations months before it reaches the press.

Key institutions

Who decides.

01

Digital Agency (デジタル庁)

Government cloud, digital ID, public-sector procurement standards such as ISMAP, and cross-ministry digital policy.

02

METI and MIC

AI governance guidelines, telecommunications business registration, and the joint AI and data councils that set expectations for operators.

03

Japan Fair Trade Commission (公正取引委員会)

Enforces the Mobile Software Competition Act and reviews platform conduct.

04

Personal Information Protection Commission (個人情報保護委員会)

APPI amendments, enforcement, and cross-border transfer rules.

05

Cabinet Office AI Strategy Headquarters and AI Safety Institute

The basic plan under the AI Promotion Act and evaluation standards for AI systems.

06

National Cybersecurity Office (旧NISC)

Active cyber defense implementation and critical-infrastructure obligations.

Regulatory and political risks

What can go wrong.

  • Being designated under the Mobile Software Competition Act, or being caught by obligations written for larger platforms.

  • Guideline changes on AI that reset customer and procurement expectations without a formal legal trigger.

  • APPI amendments that tighten consent, cross-border transfer, or breach notification rules on a three-year cycle.

  • Exclusion from government-cloud and public-sector procurement by economic-security or data-residency criteria.

Where to engage

Engagement needs.

  1. 01

    Submit evidence to the METI, MIC, and PPC councils while positions are still forming, in Japanese and framed around the ministry’s own objectives.

  2. 02

    Track JFTC designation and guideline processes early enough to shape scope rather than react to it.

  3. 03

    Build relationships with the Digital Agency and the LDP digital policy divisions that decide procurement standards and the next AI basic plan.

  4. 04

    Coordinate with the relevant industry associations, whose positions ministries consult before they consult individual companies.

Current analysis

Our published work on Technology, AI, and digital.

Complimentary 30-minute briefing

Request a briefing on Japan’s technology and AI policy environment.

Tell us which products and markets you are in. A principal will brief you on the councils, guidelines, and designations that touch them.

Request a Japan issues briefing Or discuss your Japan priorities

Your inquiry will be reviewed personally by Mickey or Kelly Langley. We normally respond within one business day.