Skip to content

Japan's AI Guidelines for Business: the Soft-Law Approach

9 min read · updated August 11, 2026

Japan’s central AI document is not a statute and does not contain a penalty. It is a set of guidelines published jointly by two ministries, and understanding what it is for is the difference between treating it as paperwork and treating it as the thing a Japanese counterparty will hand you during diligence.

What the document is

The AI Guidelines for Business (AI事業者ガイドライン) were published on 19 April 2024 by the Ministry of Economy, Trade and Industry and the Ministry of Internal Affairs and Communications, working through a joint expert review. Version 1.1 followed in 2025. Their publication was a consolidation exercise as much as a new policy: they replace three earlier documents that had grown up separately— MIC’s AI R&D Guidelines, MIC’s AI Utilisation Guidelines and METI’s Governance Guidelines for Implementation of AI Principles—which between them had left a Japanese company reading three overlapping sets of advice addressed to three different audiences. See METI’s announcement of the Guidelines.

The structure is a main text plus a much longer appendix of worked examples. The main text sets out common principles and then splits into separate parts for each business role. The appendix is where the practical content is: concrete examples of what a control looks like when implemented, checklists, and cross-references to the international frameworks a Japanese company is likely to be asked about anyway.

Three roles, not two

This is the part that does not map cleanly onto anything European and is therefore the part most often summarised wrongly. The Guidelines divide business actors into three:

  • AI developer (AI開発者) — builds and trains the model or system.
  • AI provider (AI提供者) — takes a developed system and offers it as a service or embeds it in a product supplied to others.
  • AI business user (AI利用者) — uses an AI system or service in its own business activity.

The EU AI Act runs on two roles, provider and deployer, with the provider bearing nearly all of the substantive obligations. Japan splits the EU’s “provider” in two, and the split is deliberate: a company that fine-tunes and hosts somebody else’s base model is doing something the Guidelines want to describe separately from the company that trained it. In practice a single organisation frequently occupies all three roles at once for different products, and the Guidelines expect it to read all three parts rather than pick one. If you are working out the equivalent European classification, that is a different exercise with a different answer; see how provider and deployer are drawn under the AI Act.

The common guiding principles

Part 2 sets out principles that apply to every role: human-centricity, safety, fairness, privacy protection, security, transparency, accountability, education and literacy, fair competition, and innovation. Read as a list they are unremarkable and overlap heavily with the OECD AI Principles, which is intentional—Japan chaired the G7 Hiroshima AI Process and the Guidelines are written to sit consistently with its outputs rather than to diverge from them.

The framing around the principles is more interesting than the principles. The Guidelines are built on agile governance: the argument that where the technology and its risks move faster than a legislative cycle, a binding rule fixed today will be enforcing yesterday’s assumptions in three years. The recommended mechanism is an internal loop—set the environment and risk analysis, set a goal, design a system, operate it, evaluate it, and revise—which the reader is asked to run continuously rather than once. That is a governance system, not a control list, and it is the same instinct that produces a certifiable AI management system rather than a product test.

What is actually binding in Japan

Nothing in the Guidelines is. They create no offence, no fine, no regulator with power to order rectification, and no filing. A company that ignores them entirely breaks no Japanese law by that fact alone.

This page describes published guidance and legislation; it is not legal advice, and whether a particular Japanese obligation binds your product depends on facts this page cannot know. Take Japanese advice before relying on the conclusion that something is non-binding—the Guidelines are non-binding, but the general laws underneath them are not.

Those general laws are where the enforceable duties live. The Act on the Protection of Personal Information (APPI) governs personal data used in training or inference, including the rules on providing data to third parties and on transfers outside Japan. The Product Liability Act and the Civil Code govern harm. The Antimonopoly Act governs conduct. Copyright is governed by the Copyright Act, whose Article 30-4 exception for use not aimed at enjoying the expression is the single most consequential Japanese provision for anyone training a model— see what Article 30-4 actually permits. Sector regulators, notably the Financial Services Agency, add their own supervisory expectations.

So the accurate statement is not “Japan does not regulate AI”. It is that Japan has chosen, so far, not to create an AI-specific compliance regime on top of the general law, and to use guidance to shape behaviour instead. The AI Promotion Act of 2025 kept that choice rather than reversing it.

How to use them if you ship into Japan

The Guidelines matter commercially rather than legally, and that makes them behave differently from a statute. A Japanese enterprise buyer, a public-sector procurement, or a partner’s legal team will frequently ask how your governance maps to them—not because failing to map is unlawful, but because the Guidelines are the shared vocabulary. The productive answer is a short document that states which of the three roles you occupy for the product being bought, and points to the evidence you already hold for each principle.

Most of that evidence will already exist if you have done anything for the EU or for an ISO management system: a risk register, a data provenance record, a human-oversight design note, an incident process, a record of what the model was evaluated on. The Guidelines are deliberately compatible with those artefacts, and mapping is cheaper than a parallel programme. What they will ask for that a European programme may not have produced is the literacy element—evidence that the people operating the system understand its limits—which the EU has now also made explicit, as the AI Act’s literacy obligation shows.

The one thing not to do is treat a Japanese request for alignment with the Guidelines as a formality answered by a sentence. The appendix is explicit about the kind of evidence it expects behind each principle, and a counterparty that has read it will notice a claim made without one.