ZEROCK

What Actually Changed in Version 1.2 of Japan's AI Business Operator Guidelines

Published2026-09-06Ryuta Hamamoto

Japan's AI Business Operator Guidelines moved to version 1.2. Read next to version 1.1, the update is less about new rules than about settling what words mean. Here are the seven agenda items behind the revision, and where the document sits relative to the AI Promotion Act and the AI Basic Plan, checked line by line against the primary sources.

What Actually Changed in Version 1.2 of Japan's AI Business Operator Guidelines
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

"The AI Business Operator Guidelines are at version 1.2 now, so please make sure we're covered." If a customer or a parent company has said that to you, and a 42-page Japanese PDF has been sitting open on your second monitor ever since, you are in good company. Before I went back to the source text, I braced myself for the same thing you probably expect: a full rewrite for the agent era.

Reading version 1.2 next to version 1.1 changed my mind. The edited passages are narrower than I assumed, and most of them are not new obligations at all. They are the authors settling what the words mean. Mistaking one for the other has a specific cost. You end up spending legal and engineering hours in the places where nothing actually moved, and skipping the one exercise that would have paid off.

So let me walk through what really shifted in version 1.2, and where this document sits inside Japan's wider set of AI rules. Everything below is checked against the primary sources, which exist in Japanese only. I have kept the original Japanese titles next to the English throughout, because if you work with a Japanese counterparty you will eventually need to quote them in Japanese.

The update was published as seven agenda items

Version 1.2 of the AI Business Operator Guidelines (AI事業者ガイドライン) was released on March 31, 2026 by the Ministry of Internal Affairs and Communications (総務省, MIC) and the Ministry of Economy, Trade and Industry (経済産業省, METI). The main body is 42 pages as a PDF.1 METI's page presents 1.2 as the current version, and the lineage runs back through version 1.0 on April 19, 2024, version 1.01 on November 22, 2024, and version 1.1 on March 28, 2025. This is the fourth edition.2

The useful part is that you do not have to reverse-engineer the diff yourself. The committee material "AI事業者ガイドラインの令和7年度更新内容" (Content of the FY2025 Update to the AI Business Operator Guidelines), dated March 12, 2026, sets out the revision as a table of seven agenda items.3

  1. Reflecting trends in AI technology
  2. Revising how AI-related risks are described
  3. Tidying up the classification of actors
  4. Organizing and revising specific terms
  5. Improving usability
  6. Reflecting trends in AI governance
  7. Other

The shape of the update is visible in that list alone. Items 1, 3 and 4 are all about terminology and roles. None of them tightens a norm. Items 5 and 7 are housekeeping. That leaves items 2 and 6 as the only places where the substance of the guidance could plausibly have moved. And item 2, as it turns out, is reclassification rather than escalation.

The opening page of the same material explains why. It records the comments that committee members brought to the table: new risks arising as AI agents and physical AI spread through society, and the need to sort out terms that carry several meanings at once. There is also a comment I keep coming back to, warning that as the guidelines grow in volume, balance matters for the sake of local governments, small operators and others who are only now beginning to build and practice AI governance.4

Don't let it get any thicker. That restraint reads to me like the starting point of the whole revision, and item 5 is what it looks like in practice. Rather than padding the main text, the two ministries shipped tools for reading it. A chatbot that answers questions about the content of the guidelines went live on March 26, 2026, and a document titled "AI事業者ガイドライン活用の手引き(案)" (Draft Guide to Using the AI Business Operator Guidelines) followed on March 31, 2026.5 I find that a genuinely sensible response to a document that had begun to outgrow its readers.

If your starting point is more basic, and the honest question is how much governance structure your company can realistically carry, something like our free AI readiness check is a reasonable place to begin before you open the PDF at all.

Struggling with AI adoption?

We have prepared materials covering ZEROCK case studies and implementation methods.

AI agents and physical AI now have definitions

Under agenda item 1, Part 1 of the main body gains a definition of "AI agent." The text is one short sentence: an AI system that senses its environment and acts autonomously. A footnote qualifies the word autonomous, explaining that it does not refer only to a highly autonomous state, but also covers systems with some degree of autonomy.6 A definition of "physical AI" was added in the same place.

Is that genuinely new? I wanted to be sure, so I pulled down the version 1.1 main body and ran a full-text search. Across those 40 pages, "AIエージェント" appears zero times and "フィジカルAI" appears zero times. Neither term had been part of the guidelines' vocabulary until now.

The term the industry actually uses most, "agentic AI," is still held at arm's length in version 1.2. The main body handles it in a footnote and nothing more. The committee material states the intent plainly: not to describe agentic AI in specific terms this fiscal year, and to limit the treatment to noting that risks may be amplified.7 A proper definition, and a proper account of the associated risks, has been pushed to a future cycle.

I will admit to some frustration here. The situations that are starting to give practitioners real trouble are exactly the ones where several agents chain together and act on each other's output. That is where the questions get hard, and the guidelines are quiet on it. Then again, writing a definition into a government document before the shape of the thing has settled tends to cost more later than it saves now. On balance I think holding off was the right call.

The way I read the change is not that the scope of regulation widened. What happened is that a shared vocabulary got fixed. Think about how many separate documents inside one company use the phrase "AI agent": the internal approval memo, the vendor contract, the security review sheet. In most organizations I have seen, those three documents mean three different things by it. With a short definition now sitting in a national text, the argument at least starts from the same place. And if your own documents disagree with that definition, this is a good moment to notice it and decide whether the gap is deliberate.

The line between training and inference has been redrawn

Of everything in this revision, the change I expect to matter most in day-to-day work sits under agenda item 4, the tidying of specific terms. Part 1 of the main body now defines "training" (学習) and "inference" (推論). The version 1.1 main body carried no definition of either, so both are new.

The inference side is where the consequences live. The text says that in inference, information supplemented with external knowledge by means such as RAG is used.8 In other words, pulling internal documents in through retrieval-augmented generation falls on the inference side of the line, not the training side. Plenty of companies have been describing that architecture internally as "we're training the AI on our own data." If yours is one of them, it is worth rewording. Training and inference carry different data-handling implications and a different account of who has to explain what to whom.

In-context learning needs a little care. The committee material contains this formulation: the process of determining the parameters of an AI model is stated to be training, and in-context learning is not included in training.9 That sentence lives in the committee material, though. The main body does not carry the same explicit statement. If anything, the main body's footnote goes the other way in tone, describing in-context learning as a learning method that makes it possible to have a model learn a particular task without updating trained parameters. So if you are lifting this line into an internal policy, name the committee material as your source rather than implying the main body says it. That distinction will save someone an awkward conversation in an audit.

The names for data have also been aligned with ordinary usage. Evaluation data becomes test data, validation-of-appropriateness data becomes validation data, data for training becomes training data, and data for inference or prediction becomes inference data. The figure showing an example flow of AI training and use, in section A of Appendix 1 covering assumptions about AI, was updated accordingly.10 It looks like a trivial edit. It is not, because it puts the guidelines into the same vocabulary as machine learning textbooks and vendor documentation, and that removes a small tax you were paying every time you explained a system internally.

The tidying of actor classifications brought one more addition worth flagging. The role of the AI developer now explicitly includes post-training carried out for the purpose of alignment after a system is in real operation. A footnote adds that, generally speaking, the AI developer handles API specification, input and output design, and the infrastructure needed to run the model, while the AI provider handles UI and UX design and integration with existing business systems. It then says outright that the guidelines are not organized on the basis that the AI developer builds the entire AI system.11 That is a quiet sentence about a boundary where responsibility tends to get shoved back and forth in contract negotiations, and I suspect it will get quoted a lot.

All of this connects directly to how you design an AI platform that touches internal data. When we work on enterprise knowledge with ZEROCK, agreeing up front on where training ends and inference begins changes how smoothly the legal review goes, more than almost anything else in the architecture.

The risk section was revised, not invented

Agenda item 2, the revision of how AI-related risks are described, produced a change in classification. The committee material states that discriminatory output, currently positioned in the guidelines as a technical risk, involves ethical and legal aspects, and that the risk classification is therefore changed.12 The judgment behind it is that whether a system produces discriminatory output is not settled by the technical characteristics of the model alone.

I agree with the reclassification, and not for abstract reasons. Keep bias in the box marked "technical risk" and the owner of the problem defaults to the engineering team. In practice, the decision about which attributes a system is allowed to weigh is made on the business side, and drawing that line runs straight into legal and HR territory. Move the classification and you move who holds the ball. That is the whole point of the edit.

The risk-based approach did not start with version 1.2

There is one misreading I want to head off, because I keep seeing it in summaries of version 1.2. Several of them announce that a risk-based approach has been newly introduced. The source documents do not say that. The committee material's own wording is an addition to the explanation of the risk-based approach. To check, I searched the version 1.1 main body: the phrase "risk-based" turns up in four places. The concept was already there. What version 1.2 did was thicken the explanation.

Along with the longer explanation came two new references: a strategy report from the AI Governance Association, and Annex III of the EU AI Act covering high-risk AI systems.13 Note the distance being kept. Neither framework is imported wholesale into Japanese practice; both are listed as things you may consult. That handling is a good illustration of how Japan's guidelines work, through referability rather than legal force. If you come to this document expecting the enforcement structure of the EU AI Act, you will misjudge both what it demands and what it is for.

On the case-study side, Appendix 2, which collects real-world examples of building AI governance, gained new columns from IBM and Amazon Web Services. Existing columns were also updated: column 5 (NEC Group), column 6 (Toshiba Group), column 8 (Fujitsu Group), column 9 (SoftBank) and column 10 (NTT DATA).14 Before you draft your own governance structure, reading how a company of roughly your size wrote theirs is the fastest way to calibrate how granular your documents need to be.

The ten common guiding principles, and the map around them

Chase the revisions too hard and you lose sight of the document's skeleton. The part that did not move in version 1.2 is the set of common guiding principles in Part 2, Section C of the main body. Without those, "aligning with the guidelines" has no concrete meaning.

Seven things to do, three things to do with society

The summary edition states that matters to be addressed by actors engaged in AI business activities are organized as ten common guiding principles.15 The list runs: (1) human-centric, (2) safety, (3) fairness, (4) privacy protection, (5) ensuring security, (6) transparency, (7) accountability, (8) education and literacy, (9) ensuring fair competition, and (10) innovation. Items 1 through 7 are labeled as matters each actor works on. Items 8 through 10 are labeled as matters where action in concert with society is expected. The first seven are where your company's own work sits.

Read the section itself and the sub-items are distributed unevenly. Human-centric has six of them. Accountability also has six. Transparency has four. Privacy protection has exactly one, and ensuring fair competition has no sub-items at all, finishing in a single paragraph. I take that spread as a rough proxy for how much work each principle actually implies for an operator. If you are building a review checklist, give the space to items 1 and 7.

The general provisions of the section say that each actor should comply with the Constitution, intellectual property legislation, related laws including the Act on the Protection of Personal Information, and existing sector-specific laws applicable to AI. Then comes a sentence I would highlight for any mid-sized company: these efforts, it says, should be advanced voluntarily, in light of the characteristics, uses, purposes and social context of the AI systems and services each actor develops, provides or uses, and taking account of each actor's resource constraints.16 Resource constraints are named in the text. Nobody is telling you to do all of it at once.

One more detail is worth carrying around in your head. Under principle 6, transparency, the guidelines state that providing information does not necessarily assume disclosure of algorithms or source code. When somebody demands "transparency" and means "show me everything inside," that sentence is your reference point for a calmer conversation.

Where the AI Promotion Act, the AI guideline and the AI Basic Plan sit

Now the map. The introduction to the main body notes that the Act on the Promotion of Research and Development and Utilization of AI-Related Technologies (人工知能関連技術の研究開発及び活用の推進に関する法律, Act No. 53 of 2025), commonly called the AI Promotion Act (AI推進法), was promulgated in June 2025 and came fully into force in September 2025. A footnote adds that in December of the same year, under Article 13 of that Act, the "人工知能関連技術の研究開発及び活用の適正性確保に関する指針" (Guideline on Ensuring the Appropriateness of Research and Development and Utilization of AI-Related Technologies, decided by the AI Strategy Headquarters on December 19, 2025) was established, to encourage voluntary and proactive efforts toward appropriate research, development and use of AI among all actors involved with AI.17 Three layers, then. The statute at the top, the guideline under it, and the AI Business Operator Guidelines as the practical handbook for companies at the bottom.

There is a fourth document that a lot of commentary folds into this stack by mistake: the AI Basic Plan (人工知能基本計画). I searched the full text of both the 42-page main body and the 185-page appendix. The term "基本計画" does not appear once in either. Since version 1.2 was published on March 31, 2026, that means it does not even reference the basic plan that existed at the time, the one adopted by Cabinet decision on December 23, 2025. A new AI Basic Plan was subsequently adopted by Cabinet decision on July 14, 2026, and the Cabinet Office now lists the December 23, 2025 version under past AI Basic Plans.18

The clean split is this. The AI Basic Plan states the government's own policy objectives. The guidelines are what an operator consults when making day-to-day decisions. So when somebody asks you to "respond to the basic plan," find out what they actually mean before you start. In my experience that single question saves more wasted effort than any amount of careful reading afterward.

What the text actually says about where data lives

Data residency is the topic most likely to turn into an argument in a Japanese enterprise, and the one most often argued on the basis of something nobody has read. So let me quote what is actually written.

A footnote to the general provisions of the common guiding principles says that it is necessary to comply with the respective applicable laws depending on the location of the AI provider and the AI user, and the location of the servers on which training is performed.19 Under principle 4, privacy protection, a footnote lists international guidance including the OECD Recommendation (OECD/LEGAL/0188) and ISO/IEC 29100:2011, then, in the context of cross-border transfer of personal data and interoperability between national rules, mentions Japan's participation in the Global CBPR Forum in April 2022, and touches on the G7 Data Protection and Privacy Authorities' Roundtable.20 Section E on building AI governance, in an item calling for clarity about the risk chain including data flows, says that where the value chain spans several countries you should keep track of international discussions on ensuring DFFT (Data Free Flow with Trust) and secure interoperability.21 The 185-page appendix says that where the value chain and risk chain running from AI development through to the provision of AI-based services are expected to span several countries, operators should also have regard to considering appropriate AI governance concerning cross-border data transfer, data localization and the like.22

Line them up and the register is consistent throughout. Check the applicable law. Consider. Have regard to. I also ran a co-occurrence search across the full text of the main body and the appendix, pairing the word for domestic with words for storage, retention, siting, server and data center. Zero hits. The AI Business Operator Guidelines do not require data to be stored inside Japan.

Which means that if you are told "the guidelines require domestic storage, so it has to be an in-country region," you are entitled to ask which passage. Where in-country location genuinely bites is elsewhere, in sector-specific rules for healthcare, finance and government procurement. I went through that question in running LLMs in Japanese regions, working from the providers' own documentation as well as the regulatory side, and reading the two pieces together should make the boundary clearer.

So what should you check inside your own company?

Let me close with the order I actually work through, at the level of things you can put on a task list rather than principles to keep in mind.

First, pull out how your internal policies and contracts define "AI agent," "training" and "inference," and compare them against the version 1.2 definitions. Where they diverge, writing down why they diverge is often enough. An auditor rarely objects to a documented difference; they object to an undocumented one.

Second, check whether any of your material describes a RAG setup over internal documents as "training the AI." In the guidelines' scheme, that sits on the inference side.

Third, decide whether to standardize on training data, validation data, test data and inference data. If you already have a large body of internal documentation, folding this into your next scheduled revision is more realistic than a special project.

Fourth, look at principles 1 and 7, human-centric and accountability, the two with the most sub-items, and see how far your existing records already answer them. Thin coverage here is what turns a routine question into a week of work.

Fifth, whenever someone tells you domestic storage is required, separate out whether the source is the AI Business Operator Guidelines or a different rule specific to your industry. These are not the same conversation.

Sixth, when a request arrives to "comply with the guidelines," go back to whoever sent it and establish which document they mean: the AI Promotion Act, the Article 13 guideline, the AI Basic Plan, or the AI Business Operator Guidelines. Starting work while that is still ambiguous is the most wasteful failure mode I know of in this area.

Here is the honest impression I was left with after finishing version 1.2. This document is still in the middle of drawing its own boundaries. The substantive treatment of agentic AI has been deferred to a later cycle, and the risk taxonomy is visibly still in motion. That is precisely why the thing worth fixing now is not a detailed compliance matrix. It is your internal vocabulary and your division of roles. Get the words agreed, and the next version becomes a diff you can read in an afternoon instead of a project.

If you are working out how to make your AI platform and your handling of internal knowledge explainable to a reviewer, get in touch through our contact form. We can go through it together, down to which passage of the source text you are relying on.

Footnotes

  1. MIC and METI, "AI事業者ガイドライン(第1.2版)" (AI Business Operator Guidelines, version 1.2), March 31, 2026. The page count of the main body PDF (42 pages) and the passages quoted here are based on the PDF as retrieved on September 6, 2026. https://www.soumu.go.jp/main_content/001064279.pdf

  2. METI page for "AI事業者ガイドライン(第1.2版)", which presents version 1.2 as the current version. The version lineage (version 1.2 on March 31, 2026; version 1.1 on March 28, 2025; version 1.01 on November 22, 2024; version 1.0 on April 19, 2024) is taken from METI's index for the AI Business Operator Guidelines review committee. https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/20260331_report.html

  3. MIC and METI, "【資料2】AI事業者ガイドラインの令和7年度更新内容" (Document 2: Content of the FY2025 Update to the AI Business Operator Guidelines), March 12, 2026, p.3, "令和7年度更新の論点及び更新方針(案)一覧" (list of FY2025 update agenda items and draft update policies). https://www.soumu.go.jp/main_content/001064301.pdf

  4. Same material, p.2, "0. AI事業者ガイドライン更新の背景" (background to the update). Comments submitted by committee members include new risks accompanying the spread of AI agents and physical AI through society, the need to organize terms carrying multiple meanings, and the importance of balance in light of use by local governments, small operators and others. https://www.soumu.go.jp/main_content/001064301.pdf

  5. MIC page for "AI事業者ガイドライン", based on the entries "AI事業者ガイドライン チャットボット ※令和8年3月26日公表" (chatbot, published March 26, 2026) and "『AI事業者ガイドライン活用の手引き(案)』 ※令和8年3月31日公表" (draft guide to using the guidelines, published March 31, 2026). The PDF of the draft guide is posted by both ministries, and the update material assigns agenda item 5 to the joint review committee of the two ministries. https://www.soumu.go.jp/main_sosiki/kenkyu/ai_network/02ryutsu20_04000019.html

  6. AI Business Operator Guidelines, version 1.2, main body, printed page 11. The definition of AI agent reads "環境を感知し自律的に行動するAIシステムとする" (an AI system that senses its environment and acts autonomously), and footnote 19 adds "自律については、高度な自律状態だけを指しているのではなく、ある程度の自律性を持つものも含む" (autonomy here does not refer only to a highly autonomous state, but also includes systems with some degree of autonomy). The definition of physical AI appears on the same page. A full-text search of the version 1.1 main body (40 pages, https://www.soumu.go.jp/main_content/001002576.pdf ) returned zero occurrences of either "AIエージェント" or "フィジカルAI". https://www.soumu.go.jp/main_content/001064279.pdf

  7. "AI事業者ガイドラインの令和7年度更新内容", p.6, indicating the intent not to describe agentic AI in specific terms this fiscal year and to limit the treatment to noting that risks may be amplified. In the version 1.2 main body the term is handled only in footnote 18. https://www.soumu.go.jp/main_content/001064301.pdf

  8. AI Business Operator Guidelines, version 1.2, main body, printed page 11. Definitions of "学習" (training) and "推論" (inference) were newly added, and the definition of inference states that "RAG 等を介して外部知識を補完した情報等が用いられる" (information supplemented with external knowledge by means such as RAG is used). https://www.soumu.go.jp/main_content/001064279.pdf

  9. "AI事業者ガイドラインの令和7年度更新内容", p.28, "AIモデルのパラメータを決定するプロセスを学習と明記(In-Context-Learningは学習には含まれない)" (stating that the process of determining an AI model's parameters is training, with in-context learning not included in training). This formulation appears in the committee material; there is no explicit statement to the same effect in the main body. Footnote 36 of the main body calls in-context learning a "learning method," so the source needs to be distinguished when quoting this in internal documents. https://www.soumu.go.jp/main_content/001064301.pdf

  10. Same material, p.29. Standardization of terminology: evaluation data to test data, validation-of-appropriateness data to validation data, data for training to training data, and data for inference or prediction to inference data. The updated item is the figure "AIの学習及び利用の流れの例" (example of the flow of AI training and use) in section A of Appendix 1, "AIに関する前提" (assumptions about AI). https://www.soumu.go.jp/main_content/001064301.pdf

  11. AI Business Operator Guidelines, version 1.2, main body, printed page 5. Post-training for the purpose of alignment after real-world operation was added to the role of the AI developer. Footnote 8 reads "一般的には、AI 開発者は API 仕様策定や入出力設計、AI モデルを動作させるためのインフラ整備を担い、AI 提供者は UI/UX 設計や既存業務システムとの統合等を担う。よって、AI システムの構築の全てを AI 開発者が担うと整理されているわけではない。" Neither "Post Training" nor a footnote to the same effect exists in the version 1.1 main body. https://www.soumu.go.jp/main_content/001064279.pdf

  12. "AI事業者ガイドラインの令和7年度更新内容", pp.17 and 19: "現行ガイドラインにおいて技術的リスクとして位置付けられている『差別的出力』は倫理・法的側面に関わることを踏まえ、リスク分類を変更" (given that discriminatory output, positioned as a technical risk in the current guidelines, involves ethical and legal aspects, the risk classification is changed). https://www.soumu.go.jp/main_content/001064301.pdf

  13. Same material, p.15. Addition of an explanation of the risk-based approach, together with the addition of a strategy report from the AI Governance Association and Annex III of the EU AI Act (high-risk AI systems) as references. A full-text search of the version 1.1 main body on September 6, 2026 confirmed four occurrences of the phrase "リスクベース". https://www.soumu.go.jp/main_content/001064301.pdf

  14. Same material, p.38. New columns from IBM and Amazon Web Services added to Appendix 2, "AIガバナンスの構築に関する実際の取組事例" (real-world examples of building AI governance), and updates to column 5 (NEC Group), column 6 (Toshiba Group), column 8 (Fujitsu Group), column 9 (SoftBank) and column 10 (NTT DATA). https://www.soumu.go.jp/main_content/001064301.pdf

  15. METI, "AI事業者ガイドライン(第1.2版)本編(概要)" (main body, summary edition), p.3, "共通の指針と主体" (the common guiding principles and the actors). Based on the statement that matters to be addressed by actors engaged in AI business activities are organized as ten common guiding principles, and on the figure labeling items 1 through 7 as matters each actor works on and items 8 through 10 as matters where action in concert with society is expected. The counts of sub-items under each principle were taken by counting headings in the main body, printed pages 14 to 24. https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_2.pdf

  16. AI Business Operator Guidelines, version 1.2, main body, printed page 14, opening of "C. 共通の指針". Following the passage on compliance with related laws, the text reads "なお、これらの取組は、各主体が開発・提供・利用する AI システム・サービスの特性、用途、目的及び社会的文脈を踏まえ、各主体の資源制約を考慮しながら自主的に進めることが重要である。" The statement that the provision of information under principle 6, transparency, does not necessarily assume disclosure of algorithms or source code appears on printed pages 19 to 20. https://www.soumu.go.jp/main_content/001064279.pdf

  17. Same main body, "はじめに" (introduction) and footnote 2: "『人工知能関連技術の研究開発及び活用の推進に関する法律』(令和 7 年法律第 53 号)が 2025 年 6 月に公布、9 月に全面施行された", and footnote 2, "同年 12 月に、同法第 13 条に基づき、全ての AI に関連する主体における AI の研究開発・活用の適正な実施に係る自主的かつ能動的な取組を促すための『人工知能関連技術の研究開発及び活用の適正性確保に関する指針』(2025 年 12 月 19 日人工知能戦略本部決定)が策定された。" The title, decision date and deciding body of the guideline can also be confirmed on the Cabinet Office page. https://www8.cao.go.jp/cstp/ai/ai_guideline/ai_guideline.html

  18. Cabinet Office page for "人工知能基本計画" (AI Basic Plan). The current AI Basic Plan was adopted by Cabinet decision on July 14, 2026, and the plan adopted by Cabinet decision on December 23, 2025 is listed under past AI Basic Plans. Confirmed on September 6, 2026 that the term "基本計画" does not appear even once in the full text of the version 1.2 main body (42 pages) or the appendix (185 pages). https://www8.cao.go.jp/cstp/ai/ai_plan/ai_plan.html

  19. AI Business Operator Guidelines, version 1.2, main body, printed page 14, footnote 22. It states that compliance with the respective applicable laws is necessary depending on the location of the AI provider and the AI user and the location of the servers on which training is performed. It is not a requirement for domestic storage. https://www.soumu.go.jp/main_content/001064279.pdf

  20. Same main body, printed page 18, footnote 40. Following the OECD Recommendation (OECD/LEGAL/0188) and ISO/IEC 29100:2011, it refers, in the context of cross-border transfer of personal data and interoperability between national rules, to Japan's participation in the Global CBPR Forum in April 2022, and also touches on the G7 Data Protection and Privacy Authorities' Roundtable. https://www.soumu.go.jp/main_content/001064279.pdf

  21. Same main body, printed page 28, "E. AIガバナンスの構築". Within an item calling for clarity about the risk chain including data flows, it lists keeping track of international discussions on ensuring DFFT and securing interoperability where the value chain spans several countries. https://www.soumu.go.jp/main_content/001064279.pdf

  22. METI, "AI事業者ガイドライン(第1.2版)別添(付属資料)" (appendix), 185 pages in total: "加えて、AI 開発から AI を利用したサービスの提供にわたるバリューチェーン・リスクチェーンが複数国にまたがることが想定される場合、データの越境移転、データローカライゼーション等に係る適切な AI ガバナンスの検討にも留意する。" and practical examples to the same effect. A co-occurrence search across the full text of the main body and the appendix, pairing the word for domestic with terms for storage, retention, siting, servers and data centers, confirmed on September 6, 2026 that no provision requiring domestic storage exists. https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_3.pdf

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

Ready to optimize your workflows with AI?

Take our free 3-minute assessment to evaluate your AI readiness across strategy, data, and talent.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Learn More About ZEROCK

Discover the features and case studies for ZEROCK.

Related Articles