← Back to AI Legal Lab
Insight
AI Service Legal

Legal Issues for AI Companion and AI Partner Services: Minors, Personal Information and Safety Design

Hello, I'm Noriaki Asato, Representative Attorney at LegalAgent.

A user confides in an AI about their medical history, family relationships, worries about love or sex, and everyday loneliness. The AI remembers what it is told, responds in ways that cater to the user's preferences, and recommends paid plans or the purchase of digital items. In services called AI companions or AI partners, this intimate exchange itself becomes a major motivation for continued use.

When running this kind of business in Japan, the existing laws concerning personal information, consumer transactions and safety need to be checked carefully. In practice, the focus is on the purposes for which conversation logs are obtained and managed, and on how the service acts on users through dialogue. The Act on the Protection of Personal Information (APPI) governs the collection of logs, the purposes of use and security control, while the Civil Code and the Consumer Contract Act govern charges incurred by minors and the appropriateness of solicitation. In addition, tort liability under the Civil Code asks how the business responded to dangers it could have foreseen.

The Legal Status of Intimate Conversation Logs

Article 2, paragraph 1 of the APPI (Japanese) defines personal information as information about a living individual that can identify a specific individual by name or otherwise, or that contains an individual identification code. Even if the account name is a pseudonym, if the user can be identified by readily cross-referencing an email address, device ID, payment information, conversation content and so on, the conversation log as a whole may constitute personal information.

That said, not every intimate conversation is "special care-required personal information" under the law. Special care-required personal information includes race, creed and social status. Medical history, criminal record and the fact of having been a victim of crime are also covered. Statements about romantic worries or sexual preferences are not necessarily, in themselves, special care-required personal information under Japanese law. On the other hand, if a user enters the name of a depression diagnosis, a medication history, or a history of hospital visits associated with self-harm, that may constitute special care-required personal information as medical history and the like.

Even information that is not special care-required personal information has a greater impact in the event of a leak or misuse when records such as daily friendships, emotional ups and downs and late-night usage accumulate in a single account. In practice, it is effective to meet the minimum standards required by law and then set management rules in line with users' expectations of privacy protection and the sensitivity of the information.

Purposes of Use and Profiling

Article 17 of the APPI requires that the purpose of use of personal information be specified as far as possible, and Article 18 requires, as a rule, the individual's consent for use beyond the scope necessary to achieve the specified purpose. The Personal Information Protection Commission's Q&A on purposes of use (Japanese) explains that an abstract statement such as "improving customer service" alone is insufficient, and that where profiling to analyze behavior, interests and so on is carried out, the fact that the analysis is performed and what its results will be used for should be specified and published or notified.

In an AI companion business, the nature of the purpose of use differs greatly depending on whether conversation history is used only to personalize responses, to analyze the tendencies of users who are likely to keep paying, for ad delivery, or to detect crises such as self-harm. It is hard to believe that a user could foresee, from a comprehensive phrase such as "provision of the service" alone, that their data would be used for purchase nudging or for building advertising profiles.

Article 19 of the same Act also prohibits the use of personal information in a manner that may facilitate or induce illegal or improper acts. In applying this provision, the connection with illegal or improper acts and the realistic risk of facilitation or inducement are examined concretely. For example, a design that analyzes a user's intense loneliness or the impulsive spending tendencies typical of minors, exploits those psychological vulnerabilities and persistently presses with lines like "If you want to keep our relationship, pay now" requires careful legal review from the standpoint of that Article, consumer law and other rules.

Obtaining special care-required personal information requires the individual's prior consent as a rule (Article 20, paragraph 2 of the Act). Where the information is properly obtained directly from the individual in writing, orally, by on-screen input or the like, there is room to interpret the individual's voluntary provision as consent to the acquisition. However, consent to acquisition and consent to use beyond the purpose or to provision to third parties should be assessed separately, and handling them all at once through blanket consent to the terms of use must be avoided. Clearly distinguish whether physical and mental health information is used only for safety considerations or also for advertising or AI model training, and put in place a mechanism that lets users choose.

The Boundaries of Storage, Training and External Provision

The parties involved and where legal risk lies change depending on whether conversation data is processed only on the device, stored on the business's servers, or sent to an external AI foundation model provider. Where conversation logs are managed in a searchable database or the like and handled as personal data, the APPI requires the business to take security control measures (Article 23), supervise its employees (Article 24) and supervise its contractors (Article 25). When connecting to an external model API, check, both in the contract and in the technical settings, not only whether input data will be reused to improve the other party's models but also the data retention period and location, the procedures for subcontracting and deletion, and reporting obligations in the event of incidents.

If the provision of data to an external business can be characterized as entrustment within the scope of the company's own purposes of use, it is treated differently from the ordinary restrictions on provision to third parties. However, if the contractor uses the logs for its own purposes, such as training its own models or its advertising business, there is a risk of going beyond the scope of entrustment. Where personal data is provided to a business located in a foreign country, it is subject to Article 28 of the Act even if it is entrustment. Unless the country is recognized as having a level of protection equivalent to Japan's, the recipient has a system that properly conforms to the standards, or a statutory exception applies, the business must provide the required information in advance and obtain the individual's express consent. Even where provision based on a conforming system is chosen, steps must be taken to ensure that the recipient continuously takes equivalent measures. Apart from the exceptional case where the cloud provider can be assessed as not handling the personal data, it is difficult to conclude that the provider does not handle personal data merely because a setting of "not used for training" has been selected.

A feature that "remembers past conversations forever" is very attractive to users, but that alone is no reason to retain logs indefinitely. Separate recent dialogue, long-term memory, payment history, data for model improvement and so on by purpose, and design in advance how much can be deleted when a user requests deletion. If the design is such that data remains for a long period in the analytics infrastructure or backups even after conversation history is deleted on screen, be prepared to explain that retention scope and handling to users in an easily understandable way.

The Personal Information Protection Commission has also issued an alert (Japanese) advising that, when entering information into generative AI services, one should check the terms of use and the like to see whether input data will be used for machine learning and confirm that the use is within the scope of the purpose of use. When a business itself provides an AI companion, it is important not only to alert users but also to be in a position to explain clearly how data flows and is processed within its own service.

Use by Minors and Recurring Charges

Under Article 5 of the Civil Code (Japanese), a juridical act such as a contract entered into by a minor without the consent of a legal representative can, as a rule, be rescinded. There are exceptions, such as where a minor uses, within its scope, property that the legal representative permitted the minor to dispose of for a specified purpose such as pocket money, but merely stating in the terms of use that "parental consent is deemed to have been obtained" is not enough, and whether consent was actually given must be confirmed.

AI companions tend to combine a monthly subscription with pay-per-use charges according to the number of messages, voice and image generation, avatar outfits and increases in intimacy level. In a design involving repeated small item purchases, it is hard for both the minor and the parent to grasp the total amount spent. Combine age verification through registration of the date of birth with confirmation of parental consent and a monthly spending cap for minors. Show the total amount immediately before payment, and put in place a complete system that extends to a contact point handling cancellations and refunds.

When the AI says things like "If you love me, buy this item" or "If you stop now, the bond we've built will disappear," and this leads directly to a purchase, it works on the user's psychology more strongly than an ordinary purchase screen. Article 4 of the Consumer Contract Act (Japanese) allows rescission of a manifestation of intention induced by misrepresentation of important matters, the provision of conclusive evaluations regarding uncertain future gains and the like, failure to disclose disadvantageous facts, or certain types of conduct causing confusion. The emotional responses of a conversational AI do not necessarily violate that Article immediately, but where the context of the dialogue is used to give explanations contrary to the facts, or to make users pay by unduly confusing them, not only the explanatory text on screen but also the AI's utterances themselves will be assessed as acts of solicitation.

The display obligations for mail-order sales under the Act on Specified Commercial Transactions must also be complied with. Clearly display the sales price, the timing and method of payment, the timing of provision of the service, the cancellation conditions and so on. Where a free trial automatically renews into a paid plan, present the renewal date, the price after renewal and the method of cancellation clearly on the final confirmation screen. Even when prompting a purchase in the middle of a conversation with a character, the design must not leave it ambiguous which button will form a paid contract.

Response Safety and the Business's Liability

Regarding safety measures for when a user discloses thoughts of self-harm or harming others, check not only whether there is a dedicated specific statute but also the business's liability under the Civil Code and other laws. If a business promotes the safety of its conversations or its self-harm detection features but the safeguards did not in fact function properly, liability for advertising representations and liability for non-performance of obligations become issues. In addition, where damage caused by an inappropriate AI response could have been concretely foreseen and it was possible to take measures to avoid it but the business failed to do so, the establishment of tort liability under Article 709 of the Civil Code will be considered.

In Japan as well, the Consumer Commission of the Cabinet Office established an "Expert Panel on the Use of Artificial Intelligence (AI) Technology and Consumer Issues" (Japanese) in February 2026, and it had met nine times by September 9 of that year. This is a stage of examining consumer issues and necessary countermeasures under current law, and the holding of the panel itself does not impose new direct legal obligations on businesses, but it shows that discussion of the solicitation methods and safety of conversational AI is getting into full swing.

Overseas, moves toward effective regulation are further ahead. In California, SB 243 was enacted in October 2025 and took effect in January 2026. This law requires businesses providing services to users in the state to disclose that the user is interacting with an AI where there is a reasonable risk of it being mistaken for a human conversation, to establish crisis response protocols for suicidal ideation and self-harm, and to give periodic reminders about usage time to users known to be minors, among other things. There are definitional exclusions for systems used solely for business purposes and the like. The obligation to report annually to the office responsible for suicide prevention begins on July 1, 2027. In addition, in September 2025 the U.S. Federal Trade Commission issued orders to seven major companies to submit information on the impact on young people, monetization methods, safety measures and the actual use of conversation data. This is a 6(b) study aimed at understanding the actual situation, not an enforcement action finding a specific violation, but it is a useful precedent for concretely understanding the risks that should be anticipated at the design stage.

If an AI companion is positioned as a service intended to support medical care or mental health, the applicable regulations change significantly. Depending on the functions and acts actually provided, the intended use and the content of representations, check whether the Medical Practitioners Act, medical advertising regulations and the regulations on software as a medical device (SaMD) apply. It is not the case that all of these apply merely because there is a medical explanation. On the other hand, even if the service is labeled as entertainment, if the AI's actual responses function like medical consultations, the risk of misleading users or causing health harm remains. State in advance the scope of medical areas that the service does not handle, and build in a path that promptly directs users to specialist public consultation services when a crisis such as self-harm is detected.

Reviewing Conversation Design and Payment Screens

To confirm the legality of an AI companion business, checking the wording of the terms of use and privacy policy is not enough. It is necessary to verify everything from prompt input to the AI model, retention of long-term memory, crisis detection features and the context of messages encouraging payment, through to age-based display switching, by comparing the actual screen transitions and data flows. LegalAgent provides consistent support from the design of new businesses using generative AI to personal information protection, consumer-facing representation measures and the drafting of various agreements. For related support, please see Legal Consulting on Generative AI, Data and Privacy, IT, SaaS and System Development Legal Services and Legal Outsourcing.

Keywords
Personal data
Browse all keywords

Related articles

Articles connected to this topic.

Insight / 2026.09.22 Using AI for Contract Review and Article 72 of the Attorney Act: What Legal Teams Can Leave to AI Insight / 2026.09.20 The Amended Act on the Protection of Personal Information: Where Things Stand After Promulgation and What Companies Should Prepare Insight / 2026.09.16 Initial Response to a Personal Data Breach: Reporting Deadlines and a Timeline of What to Do

Services connected to this topic

Generative AI legal consulting Terms, privacy, copyright, AI governance, and internal AI use rules.
View AI Legal Lab articles