← Back to AI Legal Lab
Insight

Practical checks for AI law and AI business guidelines

Hello, this is Legal Agent.

Japan's AI Act does not read like a law that hands a company a list of prohibited acts and penalties. It sets out a national policy direction, a promotion framework and a general approach to appropriate use, which is exactly why it is hard to work with in practice. Reading the text does not tell a company what to do differently tomorrow.

A framework law, not a checklist

Because the AI Act itself does not map neatly onto specific internal documents, applying it means reading it together with the AI Guidelines for Business (AI事業者ガイドライン), sector guidance, existing laws such as the Act on the Protection of Personal Information and the Copyright Act, and the company's own contracts, then building an internal governance structure from all of it. The Guidelines organise obligations by role: AI developer, AI provider and AI user. The same company can hold more than one role at once: using a generative-AI tool internally makes it a user, embedding AI features into a product for customers adds a provider role, and training or fine-tuning a model, or building an internal database for retrieval-augmented generation, adds a developer role.

Five questions that structure the review

Most of the initial work reduces to five questions: does the information fed into the AI include confidential information, personal data or a third party's copyrighted work; who uses the output, in what business process, and within what limits; can the company explain, through contracts or internal rules, how external transmission, training reuse, log retention and reuse are handled; do the terms of service, privacy policy, internal policy and vendor contract share the same premises; and is there a defined final decision-maker and review step before an AI-generated answer is adopted.

Risks that used to sit in different departments now converge

A contract read by AI surfaces confidentiality, personal-data and copyright questions all at once. AI used in recruitment or performance review adds fairness and labour-law questions to the personal-data question. A customer-facing chatbot mixes misleading-answer risk, labelling rules, terms of service and complaint handling. Tools also tend to enter a company department by department: a sales team adopting a meeting-notes AI, engineering adopting a code-generation AI, HR adopting a job-posting AI. Each choice is individually reasonable, but collectively nobody is left able to say which service is receiving which information.

Building the governance from the ground up

The starting point is an inventory of actual AI use, including personal accounts and browser extensions that were never formally approved, since the riskiest uses are the ones most likely to be missing from an official list. From there, the company's role should be checked service by service, prohibited-input rules should include an approval path for exceptions rather than a flat ban, output rules should fix where human review sits, vendor contracts should be checked for training use, retention and cross-border transfer, and someone should own the recurring task of checking for updates to the law, the Guidelines and the terms of the AI services actually in use.

Keywords
Generative AI policy
Browse all keywords

Related articles

Articles connected to this topic.

Insight / 2026.07.23 Game Payments and Gacha: Reviewing Japan's Payment Services Act and Premiums Rules Together Insight / 2026.07.22 Entertainment and Creator Contracts Should Define Ownership and Secondary Uses First Insight / 2026.07.21 Esports Tournament Operations Require Separate Analysis of Prizes, Sponsors, and Minors
View AI Legal Lab articles