← Back to Generative AI News
AI News Analysis

AI Guidelines for Business Version 1.2: Action Items for Developers, Providers and Users

A practical overview of the revisions in Version 1.2 of the AI Guidelines for Business and the action items that AI developers, providers and users should check.

News date
Published by LegalAgent
Updated
Reviewed by
Noriaki Asato
Status
Reviewed

Primary sources

The announcements and documents this analysis covers.

On March 31, 2026, following deliberations by the AI Guidelines for Business Study Group and other bodies, the Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry compiled and published the "AI Guidelines for Business (Version 1.2)" (Japanese). This is the second revision, following Version 1.0 published in April 2024 and Version 1.1 revised in March 2025, and its main contents are the addition of descriptions of AI agents and physical AI, a review of the description of risks posed by AI, a reorganization of the categories of actors (AI developers, AI providers and AI users), and clarification of the definitions of "training," "inference" and "data." The guidelines are not a statute but a document intended to support businesses' voluntary efforts. In this article, I identify, based on the published materials, what specifically changed in Version 1.2, and then set out the relationship with the AI Act and the action items to be checked for each of the three types of actors: developers, providers and users.

What the Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry Published in Version 1.2

According to the study group material on the fiscal 2025 updates (Japanese) published by the Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry, this revision is based on seven issues. Central among them is the addition of descriptions of AI agents and physical AI. Under the guidelines, an AI agent is defined as "an AI system that senses its environment and acts autonomously to achieve a specific goal," and physical AI as "a system that takes in information about the physical environment through sensing, processes it with an AI model, and connects it to physical action through actuators and the like." At the same time, unintended operation due to autonomous action, the expansion of attack targets and attack methods, increased difficulty of control due to more complex internal structures, and misuse of code generation were added as risks, and building mechanisms for human judgment to intervene, least-privilege settings, data minimization and periodic review of operation logs were added as points to note for each of AI developers, AI providers and AI users. The material also expressly states that, for the broader concept of "agentic AI," this year's version only mentions it in a footnote, and that the definition and risks are expected to be added from the next fiscal year onward with reference to external literature and other sources.

Next, the description of risks posed by AI was also revised. An explanation of the risk-based approach, under which the priority of measures is considered according to the magnitude and likelihood of risks, was added, and "discriminatory output" was reclassified from a technical risk to a risk relating to ethics and law, on the ground that it cannot be judged by technical characteristics alone. The categories of actors, namely AI developers, AI providers and AI users, were also further organized: model adjustment such as fine-tuning (post-training) was expressly stated to be a role of AI developers, and the guidelines newly showed that formulating API specifications is the responsibility of AI developers while building the API is the responsibility of AI providers, and that a business that provides a system with the assistance of code generation AI falls into both the AI user and the AI provider categories.

Ambiguous terms were also sorted out. "Training" was defined as the process of determining the parameters of an AI model, and it was stated that in-context learning is not included, while "inference" was described as the process of feeding unknown data to a trained model to obtain output, and it was expressly stated that referencing external data through RAG and similar methods is included in inference. In addition, usability was improved through the publication of the "Guide to Utilization (Draft)" and the launch of a chatbot, and descriptions were updated in light of domestic and international developments such as the AI Act and the Hiroshima AI Process.

Legal Nature and Relationship with the AI Act and the Guidelines on Ensuring Appropriateness

Looking at the legal nature of the AI Guidelines for Business, the overview of the main volume (Japanese) describes one of the basic ideas of the guidelines as "supporting businesses' voluntary efforts," and, regarding the "common guiding principles" that each actor should address, states that "it is important to proceed voluntarily while taking into account the degree of risk posed by AI and each actor's resource constraints." The document is understood to function not as a statutory regulation imposing obligations with penalties on businesses, but as soft law that encourages businesses' voluntary efforts.

The relationship between the AI Guidelines for Business and the AI Act also needs to be sorted out so as not to confuse the two. The Act on the Promotion of Research, Development and Utilization of AI-Related Technologies (Act No. 53 of 2025; the "AI Act") (Japanese) is a promotion act promulgated on June 4, 2025 and brought into force on September 1 of the same year, and it provides for the establishment of the AI Strategy Headquarters, the formulation of the AI Basic Plan and other matters. In contrast, the first edition of the AI Guidelines for Business was published in April 2024, so it is a document that existed before the AI Act was enacted. In this revision, the existence of the AI Act was newly added in footnotes and elsewhere, such as in the "Introduction" of the main volume, but this reflects the enactment of the AI Act as a domestic development for reference, and it cannot be said to reposition the AI Guidelines for Business as detailed enforcement rules of the AI Act.

The page for the "Guidelines for Ensuring the Appropriateness of Research, Development and Utilization of AI-Related Technologies" (Japanese), adopted by the AI Strategy Headquarters on December 19, 2025, lists the AI Guidelines for Business first in the "List of guidelines on AI by ministries and agencies," together with the competent ministries (the Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry) and the time of formulation (March 2026). From this arrangement, I think the AI Guidelines for Business were not newly created as a subordinate norm of those guidelines; rather, a cross-ministerial guideline that already existed is positioned so that it is introduced alongside those guidelines. The approach to practical compliance with the AI Act and the AI Guidelines for Business as a whole is set out in Checkpoints for Compliance with the AI Act and the AI Guidelines for Business, so this article focuses on the differences introduced by this revision.

Action Items for Developers, Providers and Users

This revision also further clarified situations in which a single business falls into multiple actor categories. A business that performs fine-tuning and then provides an AI system itself is both an AI developer and an AI provider, and a business that provides an AI system with the assistance of code generation AI is both an AI provider and an AI user. Which actor's action items a company should check is not determined by a single category, and it needs to be checked for each process by which the AI system or service it provides is built.

For AI developers, because model adjustment such as fine-tuning (post-training) was expressly stated to be a role of developers, a company that outsources this to an external model adjustment vendor should check whether the division of roles and the scope of responsibility with that vendor are clear in the contract. When adopting an open-source AI model, check whether the company has procedures for confirming the reliability of the developer and for verifying the authenticity of the model so as not to use a model that has been intentionally altered. Another item to check is whether criteria are in place for limiting the data used for training to the minimum necessary, in order to reduce the risk of unintended transmission of data outside the company.

For AI providers, because the introduction of RAG was this time clearly organized as a role of AI providers, a company that provides a service incorporating RAG functionality should check whether its policy on addressing bias that may be contained in the referenced database is reflected in the provider's explanatory materials. In addition, because setting guardrails and safe prompt design were added to the points to note for AI providers as means of carrying out alignment, check whether the explanations for users of services that include AI agent functionality include these settings. Whether there is a mechanism for limiting the external systems linked with the service to the necessary scope also needs to be checked as part of the specifications of the service provided.

For AI users, in light of the autonomy of AI agents and physical AI, check whether the internal generative AI use policy sets out a mechanism for periodically reviewing and reporting operation logs. For work in which outputs may have a serious impact, another item to check is whether operational rules for having human judgment intervene are prescribed. As the use of code generation AI spreads, I think it is also advisable to check at the same time whether the company has set out a system for maintaining and updating generated output and a method for accumulating internal know-how.

What Companies Should Check Now

In contract review, a starting point is to check whether terms such as "training data" and "trained model" appearing in contracts with vendors are consistent with the definitions of "training" (the process of determining the parameters of an AI model) and "inference" (the process of feeding unknown data to a trained model to obtain output, including referencing external data through RAG and similar methods) clarified in this revision. The items to check in contract clauses are explained in AI Vendor Due Diligence and Contract Review.

For an internal generative AI use policy, when introducing a service that includes AI agent functionality, consider whether to reflect in the rules the frequency of reviewing operation logs, the scope of work in which human judgment intervenes, and the policy for least-privilege settings. For rule design, see How to Create a Generative AI Use Policy.

As for the system for reporting to senior management, given that the guidelines repeatedly position the building of AI governance under the leadership of senior management, consider whether to add the status of reflecting this revision to the matters periodically reported to the board of directors. The items to check are organized in A Checklist for Discussing AI Governance at the Board of Directors. Another matter to check at the same time is whether to reflect the revised checklist (Japanese) and worksheet (Appendix 7) in the company's AI governance self-assessment.

Moves to Watch

As of the date of writing, the following points are undecided or need continued monitoring.

  • The addition of the definition and risks of agentic AI in revisions from the next fiscal year onward
  • When the final version of the "Guide to Utilization," currently at the draft stage, will be published, and the status of updates to the chatbot's answers
  • How the descriptions in the Ministry of Economy, Trade and Industry's "Guide on the Interpretation and Application of Civil Liability in the Use of AI" (Japanese) (published April 9, 2026) and the AI Guidelines for Business will be reconciled going forward
  • The status of updates to related guidelines referenced by the AI Guidelines for Business, such as the Ministry of Internal Affairs and Communications' "Guidelines on Technical Measures for Ensuring the Security of AI"

Each of these, once published, will be a subject for checking consistency with the company's contracts and internal rules.

Related articles

Articles connected to this topic.

Insight / 2026.06.13 Checkpoints for Complying with Japan's AI Act and the AI Guidelines for Business Insight / 2026.06.13 AI Vendor Due Diligence and Contract Review: Points to Check for Adopting Companies and Providers Insight / 2026.06.13 How to Create a Generative AI Use Policy: Checkpoints for Internal Rules, Information Management and Allocation of Responsibility Insight / 2026.05.26 A Checklist for Discussing AI Governance at the Board of Directors

Services connected to this topic

Generative AI Legal Consulting Support for AI terms of use, personal information, copyright, AI governance and internal AI use rules. Generative AI Support for Legal Departments Support for using generative AI in line with your legal team's workflow, usage rules and knowledge management.
More generative AI news