Topic Briefing ·

Japan's AI Act Has No Penalties. It Still Reaches Boards.

Japan's AI Promotion Act carries no fines. What it built instead is a Cabinet guideline decided on 19 December 2025 and a second AI Basic Plan of 14 July 2026.

Aerial view of central Tokyo under a clear sky, office towers stretching to the horizon

Japan’s AI law fits into twenty-eight articles and carries no penalty. Read the Act on the Promotion of Research and Development and the Utilization of AI-Related Technologies (Act No. 53 of 2025) looking for a fine, a criminal provision or a banned practice, and there is none to find (e-Gov statute text).

Most English coverage stopped there and called it a decision not to regulate. That is right about the penalties and wrong about the effect. The Act builds machinery, and the machinery has since produced two documents a Japanese director can be asked about in a board meeting: a government guideline decided on 19 December 2025, and a second AI Basic Plan approved by the Cabinet on 14 July 2026.

What the statute says

The Act has four chapters. The first sets principles and hands out responsibilities. The second lists the measures the state will take. The third requires a Basic Plan. The fourth creates the AI Strategy Headquarters, chaired by the Prime Minister.

Responsibilities are split across Articles 4 to 8, one each for the state, local government, research institutions, business operators that use AI, and citizens. Article 7 is the one that reaches a company. It defines a 活用事業者 — an operator that develops or provides products or services using AI-related technology, or that uses such technology in its business activities — and says that operator “shall cooperate” with the measures the state and local governments carry out. The Japanese verb is 協力しなければならない, drafted as a duty rather than as an effort clause. Nothing in the Act attaches a consequence to ignoring it.

Article 13 instructs the state to prepare guidelines in line with the purpose of international norms. Article 16 instructs it to gather information, analyse cases where AI research or use has harmed people’s rights and interests through improper purposes or methods, and on that basis provide guidance, advice and information to research institutions and operators. Guidance and advice is the entire enforcement layer. The statute grants no power to fine, to order a system off the market, or to publish the name of a company that ignores it.

Most of the Act took effect on the day it was promulgated, 4 June 2025. The two chapters with institutional weight, the Basic Plan and the Headquarters, were held back to a date set by cabinet order within three months. Full enforcement came on 1 September 2025 (Cabinet Office outline).

The document a board should read is not the Act

Article 13 has been executed. On 19 December 2025 the AI Strategy Headquarters decided the Guideline for Ensuring the Appropriateness of Research and Development and Utilization of AI-Related Technology (Cabinet Office, with an English translation).

The guideline refuses to define appropriateness. It says so directly: it “does not provide a single definition or standard of appropriateness”, and expects each actor to work from the characteristics, intended use and purpose of the AI it builds or runs. In place of a standard it names five matters for research institutions and operators to address. AI governance across the whole lifecycle, with monitoring and evaluation that involves management. Transparency about the origin of training data and generated outputs, and information that lets a user work the system properly. Safety, including the risk of crime committed through misuse and the suppression of hallucination, bias and synthetic media. Business continuity. And treatment of the stakeholders behind the data.

Two footnotes name the tools. One is ISO/IEC 42001, the AI management system standard, offered as a way to build the governance the guideline asks for. The other is the Hiroshima AI Process Reporting Framework, which began official operation in February 2025 and had received responses from 24 organisations by December 2025.

The guideline then says that disclosing and explaining these efforts “is expected to enhance corporate value and secure competitive advantage.”

That puts a disclosure expectation, at Cabinet Headquarters level, into the same corporate-reporting machinery Japanese companies already run for climate and governance. It works more slowly than a fine. At the annual meeting the question becomes what the company can show.

The second Basic Plan moved the target

The first AI Basic Plan was decided by the Cabinet on 23 December 2025. Seven months later, on 14 July 2026, the Cabinet replaced it (Cabinet Office, with an English translation of the second plan).

The plan explains itself in one line: “Six months later, the situation surrounding AI deployment and development has once again changed significantly.” What changed, in its account, is agentic AI. Systems that plan, execute, check the result and revise, rather than draft a document on request. The plan treats how such systems get deployed as a matter of national strength, and it says the gap between Japan and faster-growing economies in utilisation rates and private investment had widened by 2025.

Japan’s answer in the plan is vertical AI and physical AI: domain-specific systems built on workplace data, and AI that acts through machines in physical space. That is the same industrial bet we covered in Japan’s physical AI industrial policy, now written into the country’s governing AI document.

The governance section is where a board’s interest sits. It commits the government to review systems and related measures “including the AI Act”, proactively and continuously, and to build a mechanism at the Headquarters that aggregates risk incidents and evaluation knowledge and pushes ministries to inspect their own rules. The plan also says it will be updated annually for the foreseeable future, with progress monitored through benchmarks and KPIs. The Act carries a review clause of its own in its supplementary provisions. The absence of penalties in 2026 is a policy setting with a stated intention to revisit it, not a permanent feature of Japanese law.

The fine arrived through the privacy law instead

While the AI Act stayed penalty-free, a different Japanese statute picked up the enforcement. The Diet passed the amendment to the Act on the Protection of Personal Information on 10 July 2026 (Personal Information Protection Commission).

It does two things at once. It creates a consent exception for processing aimed only at statistical work and general analysis, and the PPC’s own explanation says this covers AI development that can be organised as statistical work. It also introduces 課徴金, an administrative surcharge on operators whose serious breaches harm individual rights, set against the financial benefit obtained from the breach. Japan has never had a monetary penalty in its privacy law before. The amendment takes effect within two years of promulgation.

The PPC document is explicit that the AI Basic Plan asked for this. It quotes the December 2025 plan directing the Commission to work on consent rules for AI development classifiable as statistical work, and to submit a bill early.

In one bill, Japan loosened the data rule AI development needed and attached its first monetary penalty to the same statute, at the request of the AI plan.

The EU clock moved too, in the other direction

A Japanese company selling into Europe is on a second timetable, and that timetable changed in 2026.

The EU AI Act’s prohibitions applied from February 2025 and its obligations on general-purpose AI models from August 2025. Those are live. The transparency rules apply from 2 August 2026, and from the same date the AI Office and national authorities hold the implementation and enforcement powers. What moved is the high-risk tranche: rules for the Annex III uses, including biometrics, critical infrastructure, education, employment and border control, now apply from 2 December 2027, and rules for high-risk AI built into regulated products such as lifts and toys from 2 August 2028, after the AI Omnibus entered into force on 27 July 2026 (European Commission).

That is roughly sixteen extra months on the hardest part of the EU regime, and nothing at all on the parts already running. The practical effect for a Japanese exporter is that the heavy EU deadline no longer lands before the next revision of Japan’s own Basic Plan, which reverses the sequencing most compliance plans were built on.

What follows for a board in Japan

Run a gap analysis against the five headings in the December 2025 guideline, at management level, and minute it. The guideline explicitly expects monitoring and evaluation that involves management, so a review that never reaches the board does not meet its own terms.

Decide, on the record, whether to certify to ISO/IEC 42001 or to document why the existing IT governance process covers the same ground. The guideline says as much: building on governance already applied to existing IT systems is a legitimate route. What is hard to defend later is having considered neither.

Inventory the AI systems that would fall inside Annex III if sold into the EU, and date the work to December 2027 rather than August 2026. Then check the training data behind your own models against the amended privacy law. That is where the surcharge lives.

The honest caveat

The AI Act itself is not enforcement. A Japanese company that ignores the December 2025 guideline gets no fine and no order under that statute. What it gets is a gap in what it can show, in a market that prices what companies can show. The government has also said in writing that it will keep reviewing the law. And the surcharge in the amended privacy law reaches AI training data directly, which the AI Act never did.

The three governance models in Asia have still not converged, which we set out in Asia’s AI rulebook forked three ways, and the wider Japanese policy stack is covered in Japan’s sovereign AI bet. The question worth carrying into 2027 is whether a law with no penalty and a plan that rewrites itself every seven months produces better corporate behaviour than a fine schedule does.


Tech for Impact Summit 2027 is in Tokyo on 18–19 May 2027, co-hosted with the United Nations University. Boards on both sides of this timetable spend two days in the same room working out what to build against it. It is invitation-only, and if this is your work we would like to invite you. Join the waitlist at tech4impactsummit.com/apply.

← Back to Blog