Digital Agency Guidelines on Generative AI Procurement and Use Version 2.0: Implications for Corporate Procurement
An explanation of the changes in Version 2.0 of the Digital Agency's guidelines on the procurement and use of generative AI, and the items that private companies can apply to their own vendor review and procurement.
Primary sources
The announcements and documents this analysis covers.
On June 12, 2026, the Digital Agency published the "Guidelines on the Procurement and Utilization of Generative AI for the Evolution and Innovation of Public Administration (Version 2.0)" (Japanese). The decision-making body is the Executive Committee of the Digital Society Promotion Council, and this is the first full revision of the first edition formulated on May 27, 2025. It includes an expansion of the scope of generative AI covered, expanded descriptions of intellectual property rights and security, and clarification of the matters to be handled by the Chief AI Officer (CAIO). That said, these guidelines are internal rules of government agencies and others, and they are addressed to government officials. In this article, I confirm the official name and legal nature and the changes in Version 2.0, and then set out the items that private companies can use as they are in vendor review and procurement procedures.
Official Name, Formulating Body and Legal Nature
The official name of the guidelines is "Guidelines on the Procurement and Utilization of Generative AI for the Evolution and Innovation of Public Administration (Version 2.0)," and they are positioned as one of the Digital Society Promotion Standard Guidelines (document number DS-920). The cover of the guidelines expressly states, as the positioning of the document, that it is "a document setting out content to be complied with as rules on the development and management of government information systems," and the guidelines have the nature of internal rules to be complied with for generative AI systems procured and operated by government agencies and others.
They apply, as a rule, to government information systems that include as a component generative AI that takes text or audio as input and outputs text, images or audio. Systems that handle specially designated secrets, important economic security information or other sensitive information relating to national security or public safety are excluded. Incorporated administrative agencies and designated corporations are expected to take measures in conformity with the guidelines, and local governments are expected to refer to them as necessary, but neither is obligated to do so.
The persons expressly identified as covered are categories of government officials: the Chief AI Officer (CAIO), planners, developers, providers and users. Businesses that contract with the government to provide generative AI systems are not themselves directly covered by the guidelines, and ensuring compliance by contracted businesses is to be carried out by planners and providers through procurement procedures, contracts and supervision of the businesses.
Main Changes in Version 2.0
The first edition was formulated on May 27, 2025, and this is the first revision. According to the revision history in the guidelines, the main changes are as follows.
Regarding the scope of generative AI covered, it was expressly stated that systems that take images or video as input, generate video, or perform advanced tasks such as AI agents are included in the scope of the AI governance framework, although they are not subject to the specific action items. The description of intellectual property rights was also expanded, and checking whether Article 30-4 of the Copyright Act applies at the training stage, as well as examples of measures concerning the use of copyrighted works, designs, trademarks, likenesses and voices at the generation stage, were added as matters for planners to address.
On the security side, access control for information requiring confidentiality and the collection and management of logs of inputs, outputs and access history of generative AI systems were newly stated as matters to address at the planning stage. At the same time, the detailed explanations of [Annex 3] Procurement Checksheet and [Annex 4] Contract Checksheet, which are consulted at the time of procurement, were moved from the main text to the annexes, and a caution regarding the appointment of a Chief AI Officer (CAIO) was also added.
Applies to Government Agencies and Others; Not Binding on Private Companies
Since the guidelines remain internal rules of government agencies and others, I think there is no legal relationship under which a company must comply with each of their items when it provides AI services or uses generative AI in its own business. On the other hand, a business that bids for an AI system procurement contract with the government will in effect be required to comply with the content of the guidelines through the requirements that planners include in specifications and contracts. In my view, a company that provides AI services to the government should check in advance whether it can reflect, in its own service design and contract terms, the requirements that may be included in procurement specifications.
Items That Can Be Used in Private Companies' Vendor Review
[Annex 3] Procurement Checksheet and [Annex 4] Contract Checksheet of the guidelines are organized for government agencies, but the items themselves can be used for reviewing generative AI vendors in general.
Regarding the handling of data, Basic Item 6 of the Procurement Checksheet requires appropriate management of the handling of data that is input, output or processed, and gives as examples of measures setting the purposes and conditions of use of inputs, managing retention periods and deletion, and managing external provision and provision to third parties. If you add fields to your company's vendor review form for whether input data is used for training and, if so, whether there is a means of opting out, this item can be used as it is. The contractual perspectives to check overlap with the issues organized in Checkpoints for AI Vendor Due Diligence and Contract Review.
Regarding logs, in addition to the collection and management of inputs, outputs and access history being listed as a matter to address at the planning stage, Basic Item 33 (verifiability) of the Procurement Checksheet requires that the development and provision process be verifiable, and gives as examples of measures the creation and management of system cards, model cards and data cards and the recording of data logs during testing. In a company's own AI agent operations as well, it is necessary to translate into contract clauses who will retain and audit execution logs and to what extent, and the review form can be prepared in correspondence with the items listed in Checkpoints for AI Agent Log Audits and Allocation of Responsibility.
Regarding the allocation of responsibility, Arrangement Item 8 of the Contract Checksheet requires that the business's obligation to respond, the provision of data for identifying the cause, and remedial measures in the event of an information security incident or a risk case specific to generative AI systems be set out in the contract in advance, and Arrangement Item 9 requires agreement on minimizing damage, identifying the cause and taking remedial measures if the expected quality is no longer met. In a company's own outsourcing agreements as well, putting into clauses how far the vendor is obligated to investigate, report and remediate when an incident occurs is an item to check that helps avoid later disputes.
Regarding security requirements, Basic Items 26 and 28 of the Procurement Checksheet require addressing vulnerabilities of the generative AI system as a whole and preventing the effects of unauthorized manipulation, as well as security measures throughout the development process. Item 27, on containment and recovery after an incident is detected, applies as a basic item for systems that require high reliability. As a checklist before introducing an AI service, adding the above perspectives of data handling, logs and allocation of responsibility to the items listed in The First Legal Checklist a Company Launching an AI Service Should Create and The First Legal Issues to Look at in the Terms of Use of Generative AI Services helps reduce gaps in the review form.
Effective Date and Moves to Watch
According to the supplementary provisions, the content of the guidelines takes effect on September 1, 2026. However, the application start date differs by item: for example, the necessary measures for the matters to be handled by the Chief AI Officer (CAIO) (6.2) are to be set out by June 30, 2026, and the AI governance framework accompanying the expansion of the scope of generative AI covered (2.2.2) applies from July 1, 2026.
As of the date of writing, the following points are unconfirmed or undecided.
- The status of formulation and publication by each ministry and agency of rules on the use of generative AI systems (based on the template in Annex 2)
- Revisions to [Annex 3] Procurement Checksheet and [Annex 4] Contract Checksheet, or publication of their track record of use
- The status of deliberations on reviewing the guidelines at the Chief AI Officer (CAIO) Liaison Meeting and the Advisory Board on Advanced AI Utilization
The draft second AI Basic Plan sets out appropriate procurement and leading adoption in the government's own procurement, and I think the status of operation of these guidelines will also attract attention as part of the progress in carrying out that plan.