Hello, this is Ryuta Hamamoto from TIMEWELL.
“I want public-private investment to create AI treated as crisis-management investment within Japan’s growth strategy and pushed with force.”
Prime Minister Sanae Takaichi said that at the first AI Strategy Headquarters meeting on December 19, 2025. Calling it crisis-management investment symbolizes Japan’s AI policy moving from industrial policy into economic security territory.
The same week’s December 23 Cabinet decision produced Japan’s first AI Basic Plan: over ¥1 trillion AI investment, Government AI for 100,000 public servants using generative AI, AISI expansion toward UK-scale 200 staff—orders of magnitude above classic IT policy.
Three months later, on March 31, 2026, METI and MIC published AI Business Guidelines v1.2—42 pages main text, 185 pages annexes. AI agents and physical AI appear as explicit regulatory targets for the first time.
Neither hard-law EU, fragmentation US, nor light-touch UK: here is the soft-law nation Japan, read from the Act and Guidelines v1.2.
TL;DR
- AI Promotion Act fully effective September 1, 2025: principles law with no penalties; AI Strategy HQ and AI Basic Plan at the core
- AI Basic Plan (Cabinet decision Dec 23, 2025): ¥1T+ investment; Government AI, domestic foundation models, AISI 200 staff
- AI Business Guidelines v1.2 (March 31, 2026): first explicit scope for AI agents and physical AI
- Core: staged Human-in-the-Loop and training-data traceability
- Japan sits between EU/Korea/China hard law and US/UK light touch—its own soft-law lane
AI Promotion Act — choosing a principles law without penalties
The AI Promotion Act (Act on Promotion of Research, Development and Utilization of AI-Related Technologies) was promulgated and partially enforced June 4, 2025, fully effective September 11. When talking Japanese AI regulation, “no penalties” is the most important fact.
EU AI Act: up to €35M or 7% of worldwide turnover for banned practices. Korea AI Basic Act: a tougher penalty architecture including criminal tracks. China’s generative AI interim measures: administrative orders and business suspension. Against that backdrop, the Promotion Act only frames “government sets a basic plan; businesses cooperate”—extremely soft.
Core elements:
- AI Strategy Headquarters (Cabinet; PM as chair)
- AI Basic Plan (government R&D and utilization policy)
- Business cooperation as an effort obligation (no penalties)
- Promotion of AI R&D (subsidies, tax relief)
No penalties means compliance officers do not face direct statutory violation risk—and also that implementation judgment sits entirely with businesses. I call that trade-off high freedom, heavy judgment responsibility.
Choosing no penalties looks realistic given EU AI Act operational burden. Japan’s AI industry is dominated by SMEs without full EU AI Act capacity; penalty-style rules could freeze the sector—that fear pushed soft law.
Further reading: EU AI Act and Digital Omnibus simplification; zero-penalty UK model: UK DUA Act section 80 and AI Growth Lab.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
Seven AI Strategy HQ directives — inside the ¥1 trillion plan
The first AI Strategy HQ meeting under the Act was December 19, 2025. The seven priorities PM Takaichi directed sketch the whole policy2.
| # | Priority | Numbers / goals |
|---|---|---|
| 1 | Government AI | From May 2026, 100,000+ public servants use generative AI |
| 2 | AISI strengthening | Toward 200 staff (UK-comparable) |
| 3 | Domestic frontier foundation models | Trusted Japan-origin frontier models |
| 4 | Investment promotion tax | New AI development investment deductions |
| 5 | Deeper R&D tax relief | Further preference on existing R&D tax |
| 6 | Talent | Scale AI engineers and adopters |
| 7 | Data strategy | Training data and shared platforms |
Crossing ¥1T marked elevation to economic security, not “just AI policy.” Nikkei reporting flags physical AI (robotics) and domestic foundation models as investment centers3.
AISI’s 200-staff goal mirrors the UK AI Security Institute (formerly AI Safety Institute)—tightly linked to the UK rebrand discussed in UK DUA Act section 80 and AI Growth Lab. With the US AISI shrinking under the Trump administration, Japan–UK AISI cooperation hints at a shift from US–UK toward Japan–UK as a security–regulation intersection I watch closely.
Government AI (formerly “Government AI Gennai,” now usually just “Government AI”) embeds generative AI into administrative work from May 2026—alongside the UK Civil Service AI strategy and Singapore’s WoG AI initiatives.
AI Business Guidelines v1.2 — discipline for the agent era
Published jointly by METI and MIC on March 31, 20264: 42 + 185 pages, ~two years after v1.1 (April 2024).
Biggest change: AI agents and physical AI explicitly in scope. Focus moves from “use generative AI well” to “AI agents executing external actions.”
Agent regulation cores on staged Human-in-the-Loop (HITL)5. Key principle: not every action needs human approval.
| Risk level | Examples | HITL requirement |
|---|---|---|
| Low | Calendar booking, internal search, summarization | Post-hoc monitoring (log review) |
| Medium | Customer email send, meeting invites | Sampled review |
| High | Contract execution, money transfer, clinical judgment, machine control | Prior approval required (human gate) |
That risk-tier design borrows high-risk AI thinking from the EU AI Act but is more flexible: same product can re-score by use case. Under the EU AI Act, landing in a high-risk category triggers heavy duties; under v1.2 you re-evaluate by use case and tune HITL.
Second pillar: training-data traceability6.
- Record provenance of RAG sources and fine-tuning data
- Keep license/contract evidence
- Maintain process history (prep, filtering, transform) for auditability
It resembles EU AI Act Article 10 data governance—so it doubles as EU extraterritorial prep. Meet v1.2 traceability and you cover roughly 80% of EU AI Act extraterritorial data work.
Physical AI is also new: robots, autonomous driving, drones, IoT-embedded AI—responsibility for physical-world behavior, safe-stop mechanisms, log retention. That tracks physical AI’s priority in the 2025 ¥1T plan.
Japan’s position — soft-law nation
| Stance | Regions | Philosophy |
|---|---|---|
| Hard law (comprehensive + penalties) | EU, Korea, China | Risk-based comprehensive regulation |
| Hard law (fragmentation) | US (states) | No federal AI act; state patchwork |
| Light touch (existing law + sandboxes) | UK | Regulator coordination + experiments |
| Regulatory gap + sector fill | Canada | No federal AI act; provincial fill |
| Soft law (basic act + guidelines) | Japan | No-penalty basic act + detailed guidelines |
Japan’s soft law is the middle: not as binding as hard law, not as free as pure light touch. I read it as a strategic choice to tolerate regulatory uncertainty for industrial trial-and-error.
EU-style interpretation fights create operational chaos; US state rules explode compliance cost. Japan leaves legal uncertainty so industry can still experiment.
Uncertainty costs, though, sit with businesses. “Following the guidelines means no violation” is weaker than clear statute compliance. If “we ignored the guidelines” becomes an issue in litigation or administrative guidance, explanation burden is heavy.
I recommend treating Guidelines v1.2 as a crosswalk kit for ISO/IEC 42001 and NIST AI RMF. Soft law itself has no fines, but the structure ports into 42001 certification and US federal procurement-style NIST AI RMF programs.
Priority order for v1.2 — design with WARP SECURITY
How I sequence client AI governance work:
Stage 1: AI agent inventory
Find systems that hit external APIs and act autonomously—sales SaaS automation, GitHub Copilot Agent mode, support auto-reply bots, invoice AI. Many owners say “Copilot is just an assistant, not an agent”—if it triggers external actions, Microsoft Copilot Studio and Salesforce Agentforce fit v1.2’s agent definition.
Stage 2: Risk-tiered HITL design
Classify agents low/medium/high. Prior gates on high; sampling on medium; post-hoc on low. Hard part: the same “sales SaaS integration” changes risk with customer size and contract value—context-sensitive logic, not fixed rules.
Stage 3: Training-data traceability
Often the longest workstream. Teams embed internal docs for RAG without recording access rights and licenses on sources.
TIMEWELL’s WARP SECURITY delivers the three stages as workshop + implementation support + certification prep: half-day inventory workshop; 1–2 months HITL implementation; 3–6 month roadmap toward ISO/IEC 42001 for traceability.
We especially productize mapping v1.2 risk items to ISO 42001 Annex A—so domestic guideline response doubles as international certification prep.
Latest as of July 2026
As of July 2026, soft-law Japan’s environment is moving. The EU AI Act activates Commission supervision/enforcement over GPAI providers on August 2, 2026—sanctions up to €15M or 3% worldwide turnover (Regulatory framework for AI (European Commission)). The contrast with penalty-free Japan sharpens. Domestically, a Personal Information Protection Act amendment including AI training / statistical use easing and surcharge systems was Cabinet-decided and Diet-submitted April 7, 2026 (PPC three-year review). Align v1.2 training-data traceability with that amendment track. Details: PIP Act 2026 amendment.
Key takeaways
- AI Promotion Act: full effect Sep 1, 2025; no-penalty basic law; Strategy HQ + Basic Plan
- AI Basic Plan (Dec 23, 2025): ¥1T+ AI investment; Government AI, domestic models, AISI 200
- Guidelines v1.2 (Mar 31, 2026): first explicit AI agents and physical AI
- Core requirements: staged HITL and training-data traceability
- Japan between EU/Korea hard law and US/UK light touch—soft-law nation
No-penalty basic law fits Japan’s industry reality. But no penalty means self-responsibility, not free rein. Nearly 300 pages of guidelines show soft law still means a lot of work.
I expect Japan’s AI regulation posture not to swing hard within five years—industry is too thin for full penalty conversion, and deregulation alone would break alignment with EU AI Act and ISO/IEC 42001. Soft-law nation is the medium-term axis.
How the ¥1T is executed—physical AI, domestic models, Government AI—will redraw the industry map. That is the multi-year watch item. On Monday morning, start with the agent inventory: which systems hit external APIs and act without a human in the loop.
Further reading: EU AI Act and Digital Omnibus, UK DUA Act section 80 and AI Growth Lab, Canada after AIDA.
References
- AI Act fully in force — next phase - Cabinet Office
- AI-related technologies R&D and utilization promotion act (AI Act) - Cabinet Office
- AI Business Guidelines v1.2 complete guide | agent regulation and 5 steps - ailead
- AI Business Guidelines v1.2 - Mori Hamada & Matsumoto
Footnotes
-
Act on Promotion of Research, Development and Utilization of AI-Related Technologies - e-Gov ↩
-
December 19, 2025 AI Strategy Headquarters - Prime Minister’s Office ↩
-
Government to invest ¥1T in AI; domestic foundation models and physical AI - Nikkei ↩
-
AI Business Guidelines (v1.2), March 31, 2026 - MIC / METI ↩
-
Government to revise AI Business Guidelines toward human judgment in autonomous AI execution - Nikkei xTECH ↩
-
Reading v1.2 “traceability” from a data pipeline foundation view - primeNumber ↩






