Japan's AI Act & AI Safety Institute: A 2026 Business Briefing
From the 2023 LDP proposal to Japan's AI Act and AISI: a 2026 briefing on AI governance obligations, enforcement direction, and what multinational firms should do now.
Japan’s AI governance journey has moved from voluntary guidelines to a structured legal framework in under two years. With the AI Act now enacted, the AI Safety Institute (AISI) operational, and coordinated work underway with the G7 and major allies, AI policy has become a defining feature of Japan’s digital and industrial strategy. For AI developers, cloud providers, enterprise adopters, and any multinational deploying AI in Japan, this is now a core public affairs, government relations, and public policy issue that sits alongside data protection, cybersecurity, and competition law.
The starting point: the December 2023 urgent proposal
On 14 December 2023, the LDP’s Headquarters for the Promotion of Digital Society published an Urgent Proposal on Ensuring the Safety of AI and Promoting its Utilization. It marked a deliberate pivot from voluntary guidelines to enforceable rules, while still framing AI utilization as strategically important for Japan’s economy. Shortly after, then Prime Minister Fumio Kishida confirmed the establishment of the AI Safety Institute (AISI) within the Information-Technology Promotion Agency (IPA) under METI, drawing together expertise from business, academia, and the public sector.
International context
Japan’s move was tightly aligned with the G7 Hiroshima AI Process, which Japan chaired, and which produced shared principles, a code of conduct for advanced AI developers, and a framework for international cooperation on AI risk and safety. The US, UK, and EU were all moving in parallel, which gave Tokyo both cover and a set of reference points for its own regime.
Where Japan’s AI governance stands in 2026
Two major legal and institutional pillars now define the Japanese approach.
The AI Act
Japan’s AI Act, enacted in 2025, is a principles-based framework rather than a one-for-one copy of the EU AI Act. It establishes government responsibilities for promoting safe and responsible AI, imposes duties on developers and deployers proportionate to risk, and provides for information gathering, guidance, and public disclosure in cases of serious harm. The law emphasizes transparency, safety testing, human oversight, and information sharing, and is designed to be updated quickly as technology evolves.
Key obligations include:
- Risk-based responsibilities for developers and users of significant AI systems, particularly those deployed in high-impact contexts
- Transparency and documentation expectations for training data practices, model capabilities, and known risks
- Incident reporting and cooperation with the government in cases of serious harm or abuse
- Coordination mechanisms with sector regulators covering finance, healthcare, transport, and critical infrastructure
The AI Safety Institute (AISI)
The AISI, operating under METI via the IPA, has matured into Japan’s central technical hub for AI safety. Its work includes safety evaluation methodologies, red-teaming of advanced models, standards development, and coordination with the UK AISI, the US AISI, and equivalent bodies in allied jurisdictions. AISI also feeds directly into policy development and supports the government’s work on deepfakes, election integrity, and AI-enabled cybercrime.
Sectoral and horizontal coordination
AI governance in Japan is a genuinely cross-government file. METI leads on industrial and safety-institute work, the Personal Information Protection Commission (PPC) handles data protection interactions, the Ministry of Internal Affairs and Communications (MIC) oversees telecommunications and AI-related content issues, the Financial Services Agency (FSA) sets expectations for AI in financial services, and the Ministry of Health, Labour and Welfare (MHLW) oversees medical AI. The Cabinet Office and the Cabinet Secretariat’s digital strategy unit coordinate across these actors.
Commercial impact
Foundation model developers and AI platforms
For global AI developers and platforms, Japan has become a meaningful regulatory jurisdiction in its own right, with expectations around safety testing, transparency, and cooperation with AISI. Developers that engage early with AISI on evaluation methodologies, share information on advanced model capabilities, and invest in Japanese-language safety work will find a considerably more constructive environment.
Enterprise adopters
For enterprises deploying AI in Japan, including financial institutions, manufacturers, healthcare providers, retailers, and logistics firms, the AI Act creates clear expectations around internal governance, documentation, and risk management. Adopters should assess where their AI systems sit on the risk spectrum, update policies and training, and align with sector regulator guidance.
Cloud providers and infrastructure
Hyperscalers and specialized AI infrastructure providers are central to Japan’s AI strategy. Expect ongoing engagement with METI, AISI, and the National Cybersecurity Office on sovereign AI infrastructure, data residency, compute allocation, and security of AI supply chains.
Startups and Japanese AI ecosystem
Japanese AI startups benefit from targeted support programs, but also face rising compliance expectations as their products scale. Foreign investors backing Japanese AI companies should factor AISI engagement and AI Act compliance into diligence and post-investment planning.
Enforcement direction and near-term outlook
Japan’s AI Act is deliberately principles-based in its first iteration, with enforcement focused on information gathering, guidance, and public accountability rather than heavy upfront penalties. That is likely to evolve over time as AISI develops evaluation frameworks and specific harms emerge. Key signposts in 2026 include:
- AISI publications on evaluation methodologies and joint work with allied safety institutes
- Sector-specific AI guidelines from the FSA, MHLW, and METI
- The first high-profile enforcement or guidance actions under the AI Act
- Diet oversight of AI governance, election integrity, and deepfake responses
Companies active in Japan’s AI ecosystem should use 2026 to build structured engagement with AISI, METI, PPC, and sector regulators, rather than waiting for individual cases to force the pace.
Why this matters for public affairs in Japan
AI is simultaneously a safety, security, industrial, and competitiveness issue for Japan, which is why it is treated as a whole-of-government priority. For multinationals, that means AI policy cannot be handled by a single team in isolation; it requires coordinated public affairs, government relations, and public policy engagement across AISI, METI, the Cabinet Office, sector regulators, and the Diet. Firms that approach Japan as a genuine AI policy partner, and invest in the relationships, documentation, and safety work this regime expects, will be significantly better positioned as the rules tighten.
Gemini Group K.K. advises AI developers, cloud providers, enterprise adopters, and investors on Japan’s AI Act, AISI engagement, and cross-ministerial AI policy strategy. Contact us to discuss how these developments shape your Japan AI roadmap.