Japan AI Guidelines
Evidence request list. 13 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
JP AI Accountability + Governance
Accountability (Sekinin 責任) is the seventh of 10 Principles per Japan AI Guidelines for Business + addresses organisational governance + clear responsibility allocation + stakeholder engagement + regulatory compliance across AI lifecycle. (1) Accountability Principle Definition: (a) clear responsibility allocation across developer + provider + user roles; (b) governance structures + decision rights; (c) chain of accountability traceable to senior management; (d) regulatory + civil + ethical accountability. (2) AI Governance Structure: (a) Board oversight + AI Strategy approval; (b) AI Strategy Officer / Chief AI Officer (CAIO) emerging role; (c) AI Ethics Committee - diverse membership + advisory; (d) AI Risk Committee - operational risk + compliance; (e) DPO Data Protection Officer (APPI) + AI Officer coordination; (f) CISO + Cybersecurity intersection; (g) Privacy + Legal + Compliance
- AI Strategy + Board approved + records + per quarter + Tone at Top
- AI inventory + comprehensive + records + per system + quarterly review + sign-off
- AI Ethics Committee + diverse membership + records + per meeting + escalation log
- Multi-regulator + APPI/FSA/PMDA/sector + records + per obligation + compliance calendar
- Third-party AI + due diligence + audit + records + per vendor + concentration risk
- AI Strategy theoretical (no Board engagement)
- AI inventory incomplete (shadow AI)
- AI Ethics Committee homogeneous (groupthink)
- Multi-regulator compliance siloed
- Vendor AI accepted with weak assurance
JP AI Continuous Monitoring + Lifecycle
Continuous Monitoring + Lifecycle Management is essential to ongoing trustworthy AI per Japan AI Guidelines for Business + integrates Safety + Accountability + Transparency Principles + addresses post-deployment risks. (1) AI System Lifecycle Stages: (a) Conception + Design - requirements + risk + ethics review; (b) Development + Training - data + bias + safety; (c) Validation + Testing - benchmarks + red-team + AISI evaluation where applicable; (d) Pre-Production - sandboxing + limited release; (e) Deployment - phased + monitoring + human oversight; (f) Operation + Monitoring - performance + drift + incident + harm; (g) Update + Retraining - safety re-evaluation; (h) Decommissioning - data deletion + model archive + downstream notification. (2) Performance Monitoring: (a) Accuracy + Precision + Recall + F1 across subgroups; (b) Calibration metrics; (c) Latency + Throughput; (d) Coverage
- Performance monitoring + per subgroup + records + per model + per quarter
- Drift detection + threshold + records + per model + continuous + alerting
- Retraining triggers + documented + records + per trigger + activation
- Safe update + re-validation + records + per release + Model Card version
- Decommissioning + records + per AI system + stakeholder notification + data erasure
- Performance monitoring aggregate only (no subgroup)
- Drift detection threshold absent (drift unnoticed)
- Retraining ad-hoc (no documented triggers)
- Updates skipped re-validation (silent regression)
- Decommissioning incomplete (zombie AI systems)
JP AI Data Governance
Privacy (Puraibasii プライバシー) is the fourth of 10 Principles per Japan AI Guidelines for Business + intersects with APPI Act on Protection of Personal Information (2022 Amendment effective April 2023) + Copyright Act 2018 Amendment Article 30-4 (text and data mining exception). (1) Privacy Principle Definition: (a) personal information protection across AI lifecycle; (b) APPI compliance + Personal Information Protection Commission (PIPC) coordination; (c) Privacy-Enhancing Technologies (PETs) deployment where appropriate; (d) data minimisation + purpose limitation. (2) APPI 2022 Amendment + AI Coordination: (a) effective 1 April 2022 (revisions effective 1 April 2023 + 1 April 2024); (b) personal information includes AI training data containing identifiable individuals; (c) pseudonymous information (Kameisei) category for AI/analytics use with relaxed obligations + retained obligations + s
- APPI compliance + pseudonymous/anonymous + records + per dataset + PIPC awareness
- Copyright Act 30-4 + records + per training data + opt-out check
- Data provenance + lineage + end-to-end + records + per dataset + versioned
- PETs + differential privacy + pseudonymisation + records + per sensitive processing
- Cross-border + APPI Article 24 + adequacy/SCC/BCR + records + per transfer
- APPI compliance separate from AI workstream
- Copyright Act 30-4 over-applied (output contains copyrighted substantial)
- Data provenance untracked (training data unverifiable)
- PETs not applied (sensitive data raw)
- Cross-border without APPI Article 24 mechanism
JP AI Fairness + Bias
Fairness (Kouseisei 公正性) is the third of 10 Principles per Japan AI Guidelines for Business + builds on Social Principles of Human-Centric AI 2019 + Cabinet Office Council for Science Technology and Innovation guidance. The Principle addresses bias detection + mitigation + inclusive design + discrimination prevention across the AI lifecycle. (1) Fairness Definition per Guidelines: (a) AI systems shall NOT cause unjust discrimination based on race + gender + age + disability + sexual orientation + religion + nationality + socioeconomic status; (b) AI outcomes shall be equitable across protected groups; (c) AI shall not perpetuate or amplify existing social biases; (d) Inclusive design accommodating diverse users + abilities + linguistic backgrounds. (2) Bias Categories: (a) Historical Bias - training data reflects past discrimination; (b) Representation Bias - underrepresentation of minor
- Bias detection + pre-deployment + live + records + per model + per subgroup
- Fairness metrics + selected per use case + records + per subgroup + audit ready
- Mitigation strategies + pre/in/post + records + per bias + per remediation cycle
- Inclusive design + multilingual + JIS X 8341 + records + per UI + per language
- Bias incident + grievance mechanism + remediation + records + per case + Board awareness
- Bias detection limited to development (no live monitoring)
- Fairness metric mismatched with use case
- Mitigation post-hoc rather than systematic
- Inclusive design Japanese-only (foreign worker excluded)
- Bias incidents siloed (no learning loop)
JP AI Generative + Foundation Models
Generative AI and Foundation Models require specific governance attention beyond traditional AI risk frameworks per Japan AI Guidelines for Business + augmented by AISI Japan AI Safety Institute + Hiroshima AI Process Code of Conduct + emerging AI Bill. (1) Generative AI Definition: (a) AI systems capable of generating novel content (text + image + audio + video + code + 3D + multimodal); (b) Foundation Models (Kiban Moderu 基盤モデル) - large-scale pre-trained models adaptable to many downstream tasks (GPT-4 + Claude + Gemini + Llama + Mistral + Japanese models like Stockmark + ELYZA + Sakana AI + PFN); (c) General Purpose AI (GPAI) per EU AI Act Article 3; (d) Frontier AI - capability frontier models warranting enhanced scrutiny. (2) Generative AI Specific Risks: (a) Hallucination - confidently stated falsehoods; (b) Copyright Infringement - training data copyright + output reproducing copy
- Generative AI risk register + hallucination/copyright/deepfake + records + per use case
- Watermarking + C2PA + provenance + records + per output class + standard adoption
- Prompt injection + jailbreak + red-team + records + per model + per quarter
- Frontier AI + AISI eval + records + per capability threshold + RSP awareness
- Copyright Act 30-4 + output filtering + records + per training + opt-out check
- Generative AI risks treated as general AI
- Watermarking absent + AI content indistinguishable
- Prompt injection defence superficial (system prompt only)
- Frontier model deployed without AISI engagement
- Copyright Act 30-4 over-applied (output reproduction)
JP AI Human Oversight
Human Oversight is mandated by the Human-Centric Principle (1st of 10 Principles) per Japan AI Guidelines for Business + reinforced by APPI 2022 Amendment Article 21-2 right to human review + intersects with Hiroshima AI Process Code of Conduct. (1) Human-Centric AI Principle (1st of 10): (a) AI for human benefit + dignity preservation; (b) AI augments rather than replaces human judgement; (c) human autonomy preserved in critical decisions; (d) AI does not undermine human capability or agency. (2) Three Levels of Human Oversight: (a) Human-in-the-Loop (HITL) - human reviews EACH AI output before action (high-risk decisions); (b) Human-on-the-Loop (HOTL) - human monitors AI operation + intervenes on exception (medium-risk); (c) Human-out-of-Loop (HOOTL) - AI operates autonomously + human reviews aggregate (low-risk). (3) APPI Article 21-2 Right to Human Review: (a) data subject right wher
- Human oversight level + HITL/HOTL/HOOTL + records + per AI system + per use case
- APPI Article 21-2 + human review + records + per request + 30-day SLA
- Override capability + authority + audit + records + per override + reasoning
- Automation bias + training + UI design + records + per reviewer + periodic refresh
- Kill switch + emergency pause + records + per system + tested annually + recovery plan
- Human oversight nominal (rubber-stamping)
- APPI human review request denied or delayed
- Override capability absent or unauthorised
- Automation bias unrecognised (reviewer over-trusts AI)
- Kill switch absent or untested
JP AI Incident Reporting
AI Incident Reporting + Response is critical to learning + accountability + stakeholder protection per Japan AI Guidelines for Business + Hiroshima AI Process Code of Conduct + emerging AI Bill. (1) AI Incident Definition: (a) any event causing or with potential to cause harm to users + non-users + society + environment + economic systems; (b) includes - harmful output + bias incident + privacy breach + security incident + system failure + unintended consequence + capability emergence; (c) severity tiers - minor + moderate + significant + severe + catastrophic. (2) Internal Incident Management: (a) Incident detection - automated + manual + user-reported; (b) Triage + classification + severity; (c) Containment + immediate harm reduction; (d) Investigation + root cause analysis; (e) Remediation + corrective action; (f) Post-Mortem + lessons learned; (g) Improvement + control change; (h) Co
- Internal incident + detection/triage + records + per incident + audit trail
- AISI + METI + voluntary notification + records + per incident + anonymised
- Sector regulator + PIPC/FSA/PMDA/MLIT + records + per incident + threshold
- Customer + stakeholder + APPI Article 26 + records + per breach + 72-hour where APPI
- Post-mortem + lessons learned + industry sharing + records + per incident + improvement
- Incident management ad-hoc (no documented process)
- AISI + METI notification skipped (industry learning lost)
- Sector regulator notification delayed or omitted
- Customer notification reactive (after media report)
- Post-mortem blameful or absent
JP AI Risk-Based Categorisation
Japan AI Guidelines for Business adopt a risk-based approach to AI system categorisation following Hiroshima AI Process principles + conceptually aligned with EU AI Act tiering though voluntary rather than mandatory. (1) Risk Tiering Framework: (a) High-Risk AI - applications with significant impact on fundamental rights + safety + critical decisions (healthcare diagnosis + autonomous vehicles + judicial decisions + recidivism prediction + employment screening + credit scoring + biometric identification + critical infrastructure operation); (b) Limited-Risk AI - chatbots + AI-generated content + recommendation systems with user impact requiring transparency; (c) Minimal-Risk AI - spam filters + game NPCs + general productivity assistance; (d) Prohibited AI Practices - social scoring + manipulative + exploitative + biometric categorisation without consent (aligning with EU AI Act Article
- AI system inventory + risk tier + records + per system + lifecycle status
- Risk assessment + pre-development + per deployment + records + per AI system
- Sector-specific high-risk + records + per sector + regulator mapping
- Foundation model + capability + AISI + records + per frontier model
- Risk treatment + High/Limited/Minimal + records + per system + DPIA where required
- AI system inventory absent or incomplete
- Risk assessment one-time (no re-assessment)
- Sector-specific high-risk unrecognised
- Frontier model thresholds unmonitored
- Risk treatment uniform regardless of tier
JP AI Safety + AISI
Safety (Anzen 安全) is the second of 10 Principles per Japan AI Guidelines for Business + significantly extended by establishment of the Japan AI Safety Institute (AISI 日本AIセーフティ・インスティテュート) on 14 February 2024. The Principle addresses prevention of physical + psychological harm + system robustness + adversarial resilience + safe deployment practices. (1) Safety Principle Definition: (a) prevention of physical + psychological harm to users + non-users + society; (b) preservation of human autonomy + dignity; (c) avoidance of catastrophic + existential risks for advanced AI; (d) safe failure modes + graceful degradation. (2) Japan AI Safety Institute (AISI) Establishment: (a) inaugurated 14 February 2024; (b) affiliated with Information-Technology Promotion Agency (IPA) under METI; (c) Director-General appointed; (d) ~50+ staff growing; (e) inter-ministerial coordination with MIC + Cabinet Of
- Pre-deployment safety eval + AISI for frontier + records + per model + per release
- Adversarial robustness + PGD + AutoAttack + records + per model + per quarter
- Frontier AI capability + AISI threshold + records + per model + monitoring
- AI safety lifecycle + per stage + records + per AI system + governance
- International coordination + AISI Network + records + per engagement + joint eval
- Pre-deployment safety eval skipped (released without test)
- Adversarial robustness annual only (no continuous)
- Frontier AI threshold not monitored
- Safety lifecycle incomplete (decommission unsafe)
- International cooperation absent (siloed Japan)
JP AI Scope + Society 5.0 + Strategy
Japan AI Guidelines for Business (AI Jigyousha Gaidorain AI事業者ガイドライン) version 1.0 published April 2024 by Ministry of Economy Trade and Industry (METI 経済産業省) and Ministry of Internal Affairs and Communications (MIC 総務省) jointly. The Guidelines consolidate previous separate AI principles (METI AI Governance Guidelines 2021 + MIC AI R&D Guidelines + Social Principles of Human-Centric AI 2019) into a unified framework for businesses developing + deploying + using AI systems in Japan. (1) Origin and Lineage: (a) Social Principles of Human-Centric AI (Cabinet Office, March 2019) - foundational 7 principles approved by Council for Science Technology and Innovation; (b) METI AI Governance Guidelines Version 1.0 (January 2022) + 1.1 (January 2023) - governance-focused guidance for AI deployers; (c) MIC AI R&D Guidelines (July 2017) + AI Utilisation Guidelines (August 2019) - developer-focused; (
- AI Guidelines adoption + documented + records + per business unit + per project
- Role classification + Developer/Provider/User + records + per AI system + obligations mapped
- 10 Principles + per principle + records + per system + maturity assessment
- AI Bill alignment + sector-specific coordination + records + per regulator
- International framework alignment + Hiroshima/G7/EU AI Act + records + per crosswalk
- Guidelines acknowledged but not implemented (compliance theatre)
- Role classification absent (obligations unmapped)
- Principles ad hoc (no systematic implementation)
- AI Bill changes unmonitored
- International alignment piecemeal
JP AI Security + Adversarial
Security (Sekyuritii セキュリティ) is the fifth of 10 Principles per Japan AI Guidelines for Business + addresses cybersecurity throughout AI lifecycle including adversarial attacks specific to ML + traditional cyber threats to AI infrastructure. (1) Security Principle Definition: (a) cybersecurity throughout AI lifecycle; (b) protection against adversarial + traditional attacks; (c) resilience + recovery capability; (d) supply chain security; (e) coordination with national cybersecurity framework. (2) AI-Specific Attack Surface: (a) Training Data Poisoning - adversarial manipulation of training data; (b) Backdoor Attacks - hidden triggers in trained models; (c) Adversarial Examples - imperceptible perturbations causing misclassification; (d) Model Extraction - reverse engineering proprietary models; (e) Model Inversion - reconstruction of training data; (f) Membership Inference - determining
- AI threat modelling + STRIDE/ATLAS + records + per system + per release
- Adversarial robustness + FGSM/PGD/AutoAttack + records + per model + per quarter
- Prompt injection + data poisoning + records + per model + red-team
- Supply chain + AI BOM + foundation model verification + records + per dependency
- AI incident response + AISI/METI + records + per incident + CVD + lessons learned
- AI threat modelling absent (general IT threats only)
- Adversarial robustness annual or absent
- Prompt injection defence superficial
- Supply chain accepted without AI BOM
- AI incident response merged with IT (specialised expertise missing)
JP AI Third-Party + Supply Chain
Third-Party AI Supplier Assurance addresses the complex AI supply chain where most enterprises consume foundation models + cloud AI services + AI-enabled SaaS rather than build from scratch. (1) AI Supply Chain Categories: (a) Foundation Model Providers (FMP) - OpenAI + Anthropic + Google + Microsoft + Meta + Cohere + Mistral + Japanese (Stockmark + ELYZA + Sakana AI + Tooku + Preferred Networks); (b) Cloud AI Service Providers - AWS + Azure + GCP + IBM + Oracle + domestic (NTT Data + Fujitsu + NEC + Hitachi); (c) AI-Enabled SaaS - sector-specific applications; (d) AI Development Tools - MLOps + monitoring + experimentation; (e) Pre-Trained Model Marketplaces - Hugging Face + TensorFlow Hub + PyTorch Hub; (f) Open Source AI libraries + frameworks; (g) Data Providers - training + augmentation + evaluation. (2) Vendor Due Diligence for AI Suppliers: (a) AI Ethics + Governance posture - 10
- Vendor DD + AI ethics + ISO/IEC 42001 + records + per vendor + periodic review
- Foundation model + Model Card + Safety Report + records + per FMP + per release
- Contractual obligations + audit + incident + records + per contract + flow-down
- Sub-processor + chain + records + per sub + concentration risk assessment
- Concentration risk + critical AI + records + per system + multi-vendor strategy
- Vendor DD accepts marketing claims (no audit)
- Foundation model assurance reliant on FMP self-disclosure
- Contractual obligations generic (no AI-specific clauses)
- Sub-processor chain opaque
- Concentration risk unmanaged (single FMP dependency)
JP AI Transparency + Documentation
Transparency (Toumeisei 透明性) is the sixth of 10 Principles per Japan AI Guidelines for Business + reinforced by Hiroshima AI Process Code of Conduct (October 2023) which establishes voluntary transparency commitments for frontier AI developers. (1) Transparency Principle Definition: (a) explainability + documentation + disclosure proportionate to risk; (b) users informed of AI interactions; (c) decision-relevant information accessible; (d) trade secrets + IP protected where reasonable. (2) Tier-Based Disclosure: (a) High-Risk AI - comprehensive Model + System Card + Datasheet + Safety Report + decision explanation; (b) Limited-Risk AI - User Notification + brief disclosure + opt-out; (c) Minimal-Risk AI - basic identification; (d) Frontier AI - Hiroshima Code of Conduct full transparency. (3) Model Card Standard (per Google + Hugging Face): (a) Model details - architecture + parameters +
- Model card + system card + datasheet + records + per AI system + per release + versioned
- User notification + AI interaction + records + per touchpoint + opt-out
- AI-generated content + C2PA + watermark + records + per output + provenance
- Decision explanation + high-risk + records + per request + plain language
- Hiroshima Code + 11 commitments + records + per commitment + annual report
- Model cards minimal or absent for proprietary systems
- User notification buried in terms (no contextual disclosure)
- AI-generated content unwatermarked
- Decision explanations technical (not affected-stakeholder understandable)
- Hiroshima Code commitments not implemented
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Japan AI Guidelines framework page.