Notice

NEWS

2026.09.30

News

[SAKURA Law Office | Legal Update by Managing Partner Kenshiro Michishita] Publication of “Legal Risks When Companies Deploy AI Agents — Access Controls, Human-in-the-Loop, Security and Governance (2026)”

SAKURA Law Office | Legal Update by Managing Partner Kenshiro Michishita

September 24, 2026

SAKURA Law Office | Managing Partner Kenshiro Michishita

SAKURA Law Office has published the seventh installment of the Legal Update series by Managing Partner Kenshiro Michishita, entitled “Legal Risks When Companies Deploy AI Agents — Access Controls, Human-in-the-Loop, Security and Governance (2026).”

Corporate use of generative AI is moving rapidly beyond the stage in which a system merely produces text for a human to review. AI systems are increasingly being connected to email, cloud storage, internal databases, customer relationship management platforms, development environments, accounting systems and other business tools, and are being authorized to retrieve information, plan steps and execute tasks autonomously or semi-autonomously. In this sense, AI is becoming not merely an information tool, but an operational participant in business processes.

This transition can materially increase productivity and create new business opportunities. It also changes the nature of legal risk. With a conventional generative AI system, an inaccurate answer may cause no harm if a human does not act on it. By contrast, an AI agent may send an email, modify a file, respond to a customer, deploy code, transmit data to an external service, initiate a transaction or otherwise translate an AI-generated decision directly into a corporate act.

For that reason, the most important question in deploying an AI agent is not simply how capable the underlying model is. The critical governance questions are what information the agent may access, what actions it may execute, when human approval is required, how the agent can be contained or stopped if it behaves unexpectedly, and who within the organization remains accountable for the consequences.

On July 31, 2026, the Information-technology Promotion Agency of Japan (“IPA”) published practical guidance for the safe use of generative AI and AI agents, organizing enterprise AI governance, lifecycle management, harms, AI-specific risk assessment, technical controls, operational controls and human controls within an integrated framework. IPA has also highlighted zero-trust concepts, identity controls, isolation environments and Human-in-the-Loop mechanisms as important issues in AI-agent security.

This Legal Update provides a practical overview, as of September 24, 2026, of the principal legal and governance issues that companies should consider when deploying AI agents in Japan, including access control, meaningful human oversight, personal information, trade secrets, prompt injection, external tools and connectors, memory, logging, incident response, vendor contracts and management-level AI governance.

Executive Summary
The defining legal and governance issue for enterprise AI agents is not merely what the AI “thinks,” but what the company authorizes it to do. Access rights and execution authority should be limited to what is necessary for the relevant task. Material actions — including payments, contract execution, external communications, employment decisions, deletion of important data and production-system changes — should generally remain subject to meaningful human review or approval unless the company has determined, through an appropriate risk assessment, that greater autonomy is justified. Companies should also design for AI-agent-specific risks, including prompt injection, malicious or compromised tools, excessive permissions, misdirected communications and leakage of confidential information. Logs, auditability, containment, credential revocation and incident response should be part of the control framework from the outset. An AI agent is not an independent legal actor under current Japanese law; the company must govern the agent as part of its own business process, information systems and internal-control environment.

1. What Is an AI Agent? The Critical Difference Is Execution Authority

As of September 24, 2026, Japanese law does not provide a single statutory definition of “AI agent” applicable to every context. In practice, the term is commonly used to describe a system in which a generative AI model or similar technology receives a goal or instruction, gathers external information, plans multiple steps and uses tools or other systems to complete a task autonomously or semi-autonomously.

The principal distinction from conventional generative AI is not simply the quality of the answer. An AI agent may be capable of sending email, creating or modifying files, writing to databases, invoking APIs, opening tickets, changing source code, adding calendar events and performing other operational actions. Accordingly, a legal and risk assessment of an AI agent must examine not only the model but also the systems to which it is connected, the credentials it can use, the actions it can execute, the approval workflow surrounding those actions and the mechanisms available to stop it.

The same model can present entirely different risk profiles depending on configuration. A model that drafts a proposed email presents a different level of risk from the same model connected directly to corporate systems with authority to send the email to a customer. The proper starting point is therefore not “Which AI are we using?” but “What can this AI see, and what can it do?”

2. An AI Agent Is Not, Under Current Japanese Law, an Independent Legal Person

Even where an AI agent performs highly autonomous functions, current Japanese law does not generally treat the AI agent itself as an independent legal person comparable to a natural person or corporation. When a company uses an AI agent in its business, contractual, data-protection, intellectual-property, tort and other legal issues must be analyzed in relation to the company and the human and corporate actors who selected, configured, deployed and operated the system.

The statement that “the AI acted on its own” does not, by itself, sever corporate responsibility. In assessing the company’s position, it may be relevant to consider the authority granted to the agent, the supervision and containment mechanisms adopted, the foreseeability of the relevant risk and the controls implemented to address that risk.

Legal departments should therefore avoid treating AI-agent conduct as an exceptional technological event that sits outside ordinary corporate governance. The better approach is to incorporate AI agents into existing authority rules, information-governance frameworks, approval processes and internal controls.

3. Japan’s AI Framework Favors Risk-Based, End-to-End Governance

Japan’s AI Act came into force in 2025, and on December 19, 2025, the Japanese Government adopted guidelines under Article 13 concerning the appropriate development and use of AI-related technologies. Those guidelines emphasize human-centric design, fairness, safety, transparency, accountability, security, privacy and personal information, AI literacy and other principles, and promote a risk-based approach, end-to-end AI governance and agile review.

The AI Guidelines for Business Ver1.2, published on March 31, 2026, likewise organize expectations by reference to AI developers, AI providers and AI business users. A company deploying an AI agent internally will often be acting primarily as an AI business user. A company that integrates an AI agent into a service offered to customers may also need to consider responsibilities more closely associated with an AI provider.

These frameworks do not impose one uniform rule on every AI agent. Their practical significance is that governance should be proportionate to the nature and magnitude of the risk. Companies should calibrate controls by reference to the agent’s read access, execution authority, data sensitivity, external impact and the consequences of malfunction.

4. The First Governance Artifact Should Be an “Agent Authority Map”

One of the first documents that Legal, Security and IT should require when an AI agent is proposed is a concrete map of the authority granted to that agent. The company should identify what data the agent can access, what folders it can search, what APIs it can call, where it can send information, what records it can alter or delete, whether it can initiate payments or participate in contracting, and whether it has any administrative privileges.

If permissions are not understood before deployment, excessive authority may become a more significant risk than model error itself. A customer-support agent with unrestricted search access across corporate storage may retrieve sensitive materials that are irrelevant to the customer’s request. A coding agent with direct deployment rights may cause incorrect code to reach production without meaningful review.

Permission design is not intended to eliminate the benefits of AI agents. Its purpose is to ensure that, even when the agent makes a poor decision, the potential harm remains bounded by a controlled technical and legal perimeter.

5. Apply the Principle of Least Privilege to AI Agents

An AI agent should ordinarily receive only the access and execution rights necessary to perform its assigned function. IPA’s 2026 AI-security publications have highlighted the application of zero-trust concepts to agentic AI and the importance of identity and isolation controls.

In practice, companies should consider separating agents by function rather than concentrating broad rights in a single agent, separating read access from write access and preventing direct access to sensitive databases or production systems unless such access is demonstrably necessary. API keys, tokens and other credentials should be subject to lifecycle management at least as stringent as that applied to human users.

Shared credentials also create attribution problems. Where practicable, each agent should have an identifiable service identity, and the organization should retain records of permission grants, changes, suspensions and revocations.

6. Human-in-the-Loop Must Mean More Than a Formal “Approve” Button

Human-in-the-Loop is frequently invoked in discussions of AI-agent governance. A formal approval step, however, is not necessarily meaningful oversight. A human who is shown only an “Approve” button, without the information needed to assess the proposed action, may become little more than a procedural rubber stamp.

Effective human oversight requires that the reviewer be able to understand the proposed action, its basis, the relevant data and the likely consequences; that the reviewer have sufficient time and information to decide; that the reviewer be able to reject or modify the proposal; and that the organization be able to suspend the AI process where necessary.

As of September 24, 2026, Japanese law does not impose a universal statutory Human-in-the-Loop requirement for every AI-agent use case. Nevertheless, for actions with significant or difficult-to-reverse consequences — such as payments, contract execution, public announcements, material customer notices, adverse employment decisions, deletion of important data and changes to production environments — companies should seriously consider preserving substantive human approval.

7. Which Actions May Be Autonomous, and Which Should Require Human Approval?

The degree of autonomy granted to an AI agent should reflect the significance and reversibility of the action, the financial amount involved, the effect on third parties, the impact on legal rights and obligations, and the company’s ability to detect and remediate an error.

Automated collection of public information, routine internal ticket triage and drafting of internal materials may lend themselves to greater automation. By contrast, executing customer contracts, initiating bank payments, transferring personal data to third parties, making hiring or disciplinary decisions, issuing important public statements and deploying source code into production ordinarily require stronger controls.

Companies should distinguish clearly between what an AI agent is technically capable of doing and what the organization has authorized the agent to do. Technical capability is not the same as legal or internal-control authorization.

8. When AI Agents Participate in Contracts, Payments or Other External Transactions

Where an AI agent participates in ordering, procurement, quotations, contract execution, payments or other external transactions, the company should align the agent’s authority with its internal delegation-of-authority rules and approval procedures. Because the agent’s conduct may create legal relationships or financial exposure with third parties, the organization should define who authorized the activity, the transaction types permitted, the counterparties allowed and the monetary thresholds applicable.

For automated purchasing or payment agents, practical controls may include approved-counterparty lists, monetary limits, product or service categories, transaction-frequency limits and time-of-day restrictions, with human approval required above specified thresholds.

If an agent acts on information obtained from third parties or the open web, the company must also account for the possibility that external content contains malicious instructions intended to manipulate the agent. Agents involved in contracting or payment should therefore combine controls such as treating external content as data rather than authority, restricting counterparties, setting transaction limits and applying anomaly detection.

9. Relationship to Internal Controls Under Japanese Corporate Law

When AI agents become embedded in material business processes, their governance can become a matter of enterprise risk management and internal control rather than merely an IT implementation issue. Under the Companies Act, certain companies with boards of directors are required to establish systems designed to ensure the propriety of corporate operations, and the Ordinance for Enforcement of the Companies Act addresses matters such as systems for managing the risk of loss and ensuring compliance by employees.

The introduction of an AI agent does not, by itself, mean that every deployment requires a specific board resolution or a bespoke internal-control framework. However, where an AI agent is materially involved in sales, payments, customer interactions, financial reporting, software development or management of important information, its permissions, supervision, logging, containment and incident response should be positioned within the company’s existing internal-control and risk-management structures.

Senior management does not need a count of every AI agent for its own sake. It does need visibility into which agents have material execution authority, which critical systems they can access, what sensitive data they process and what magnitude of loss they could plausibly cause.

10. AI Agents Can Expand Data-Protection Risk Under Japan’s APPI

AI agents can collect and combine information from multiple systems automatically. This can materially improve operational efficiency, but it may also increase risk under Japan’s Act on the Protection of Personal Information (“APPI”).

For example, a customer-service agent connected simultaneously to CRM data, email, purchase history and support records may aggregate personal information that was previously separated across systems. The company should consider whether such use falls within the specified purpose of use, how any external AI provider’s handling should be characterized for purposes of outsourcing, third-party provision or cross-border transfers, and whether data may be used for training or model improvement.

An AI agent may also retrieve personal information that the employee did not manually place into a prompt. Accordingly, an employee rule stating only “Do not enter personal information into AI prompts” is insufficient for agentic AI. The agent’s access permissions themselves must be reviewed from a data-protection perspective.

11. Trade Secrets and NDA-Protected Information: Focus on the Agent’s Search Scope

Where an AI agent uses enterprise search or retrieval-augmented generation (“RAG”), its search corpus may include trade secrets, M&A materials, information received under NDAs, board materials, source code and other confidential information. The key issue is not limited to whether the agent transmits information externally. The company must first ask whether the agent needed access to that information at all.

Risk is particularly acute where the agent can search beyond the requesting user’s own access rights, where a shared index collapses information barriers that should remain separate, or where an external AI provider can retain or use retrieved content for training or other secondary purposes.

Companies should verify that existing information classifications and access restrictions remain effective after AI-agent deployment. The introduction of AI should not silently override Need-to-Know principles or access limitations imposed by NDAs.

12. Prompt Injection Can Turn “Bad Answers” into Unauthorized Actions

Prompt injection is a significant security threat in generative AI. Where an AI agent reads websites, email, documents or other external content, malicious instructions embedded in that content may attempt to redirect the agent away from the user’s intended objective.

With a conventional chat system, a successful attack may result only in an inappropriate answer. With an AI agent that has tool-execution authority, the consequences can include disclosure of confidential information, modification of files, API calls, misuse of credentials or other operational actions.

AI-agent architecture should therefore combine multiple controls: separation of external content from authoritative instructions, restrictions on available tools, human approval for sensitive actions, limits on outbound destinations, sandboxing and monitoring of inputs and outputs. Companies should not assume that a single filter or system prompt is sufficient to provide security.

13. External Tools, Plugins and MCP Connections Are Part of the Supply Chain

AI agents may rely on numerous external tools, plugins, APIs or other mechanisms that connect the model to third-party services. Model Context Protocol (“MCP”) and similar approaches are increasingly used to connect AI systems to external tools and data sources.

From a legal and security perspective, it is not sufficient to diligence only the model provider. The company should also assess the tools the agent can invoke, the operators of those tools, subprocessors, authentication methods, data accessed, data destinations and the scope of permissions. These components are part of the AI-agent supply chain.

If an external tool is compromised, or a malicious tool is introduced, the AI agent may treat it as a legitimate capability. Approved-tool allowlists, authenticity checks, version management and rapid deactivation procedures can therefore be important controls.

14. Agent Memory Creates a New Information-Governance Layer

AI agents may retain prior conversations, user preferences, task history or information retrieved from external systems and reuse that information in future tasks. Memory can improve usability, but it also creates legal and governance questions concerning what is retained, for how long, for whose benefit and for what future purposes.

Companies should consider what information may be written to memory, retention periods, segregation by user or organization, deletion mechanisms, administrative review, treatment of former employees and transferred personnel, and deletion at contract termination.

If an AI agent stores incorrect information in long-term memory, the error may be repeatedly reused in later decisions. Where material facts are retained, companies should consider mechanisms for accuracy review and correction.

15. Logging Is the Foundation of Accountability and Post-Incident Reconstruction

When an AI agent performs operational actions, the company should be able to reconstruct why the action occurred. A simple chat transcript may not be sufficient.

Depending on risk, relevant logs may include the user’s instruction, key information consulted by the AI, tool calls, actions executed, service accounts or credentials used, outbound destinations, human approvals or rejections, timestamps, and the model and material configuration versions in use at the time.

Logs themselves may contain large volumes of personal information or confidential material. Logging is therefore not automatically a security benefit. Purpose, access, retention, integrity protection and deletion must also be governed.

16. Design the Ability to Stop and Contain the Agent

The more capable the AI agent, the more important it becomes to prepare for immediate containment when behavior is abnormal. Companies should have practical means to stop execution, revoke API tokens and other credentials, block network communications, and place affected systems into read-only or isolated states where appropriate.

The expression “kill switch” is sometimes used, but a single stop button may not be sufficient. Even if the AI service is disabled, previously issued credentials or automated workflows may continue to function unless they are separately revoked or contained.

Incident-response procedures should therefore address agent suspension, credential revocation, system isolation, log preservation, scope assessment, deletion requests, stakeholder communications and evaluation of any regulatory reporting or notification obligations.

17. Initial Response to Misdelivery, Deletion or Unauthorized Modification by an AI Agent

When an AI-agent incident occurs, damage containment and evidence preservation should ordinarily take priority over immediate debates about ultimate responsibility. The company should identify recipients, affected data, actions executed, timestamps, accounts used, external systems involved and relevant logs, and suspend the agent or related credentials where necessary.

For misdirected communications, the company may need to request deletion by recipients or external providers and assess the nature of any personal data or confidential information disclosed. For unintended deletion or modification, the company should examine restoration from backups or version histories and immediately restrict the agent’s ability to repeat the action.

Overwriting settings or logs during recovery can compromise the subsequent investigation. Legal and technical teams should therefore coordinate remediation and evidence preservation from the beginning.

18. AI Agents in Recruitment, Employment Decisions and Other High-Impact Contexts

Using AI agents to screen candidates, assess employees, determine assignments, support disciplinary action or influence other employment decisions requires greater caution than ordinary productivity automation. Decisions may be based on incomplete or biased data and may materially affect individual rights and interests.

The company should distinguish between using AI to generate recommendations or scores and automating the final decision solely on the basis of those outputs. For significant employment decisions, human reviewers should be able to examine the criteria, source information and reliability of the AI output and take account of relevant exceptions or context.

Employment data may also include sensitive or highly confidential information. Agent access to such data should be strictly limited to what is necessary for the relevant role.

19. Customer-Facing AI Agents Need Clear Boundaries Between Explanation and Authority

Where a customer-facing AI agent can not only answer questions but also process reservations, order changes, refunds or other transactions, the company should define clearly which matters can be completed through the AI interaction and which must be escalated to a human.

If customers may reasonably understand the AI’s response as an official corporate position or contractual commitment, an incorrect answer can become more than a quality-control issue. It may lead to customer disputes, disclosure issues or contractual consequences. For pricing, warranties, refunds, cancellation rights and other material matters, the agent should rely on approved sources and escalate matters outside defined authority limits.

The degree to which the company should disclose the use of AI will depend on the industry, use case, applicable regulation and reasonable expectations of transparency. In high-impact settings where a customer would reasonably expect human judgment, the roles of AI and human personnel and the available escalation path should be clear.

20. Contract Issues with AI-Agent Vendors

When an AI agent is procured from an external provider, the contract should address execution authority and tooling in addition to the issues ordinarily considered in generative AI agreements. Companies should review how input and retrieved data may be used, training rights, retention, subprocessors, cross-border processing, security, logging, incident notice, limitation of liability and indemnification, and should also determine how responsibility is allocated for actions executed by the agent.

Where the provider changes the model or agent functionality over time, the customer should consider whether material changes could expand execution scope or alter behavior without meaningful notice. Provisions concerning material-change notifications, deprecation of prior versions, transition periods and suspension or alternative solutions may become important.

For agents integrated deeply into company-specific workflows, generally applicable online terms may be insufficient. A DPA, SLA, security addendum, negotiated agreement or statement of work may be necessary to establish the customer’s required controls, auditability and operational boundaries.

21. Do Not Give Production Authority During the PoC Merely for Convenience

In a proof-of-concept phase, project teams may seek access to production data or production systems because realistic conditions make performance easier to evaluate. The need for a realistic test does not justify granting unnecessary production authority.

Where feasible, companies should use masked or anonymized data, sandbox environments, read-only rights and test accounts, while limiting the agent’s executable actions during evaluation.

When moving to production, the organization should not simply carry forward temporary PoC settings. Production permissions, logging, monitoring, approval workflows, credentials, failure handling and contractual protections should be reviewed separately.

22. Multi-Agent Systems Require Visibility into Chains of Authority and Responsibility

Where multiple AI agents collaborate on a task, the processing path may become materially more complex than in a single-agent system. The company should understand which agent retrieves information, which performs analysis, which decides the next step and which executes the external action.

If one agent produces an incorrect premise and a second agent relies on it to perform an action, identifying the origin of the incident can become difficult. Agent-to-agent communications should therefore be logged in proportion to risk, and for significant actions the organization should identify the final executing agent and the relevant human or corporate approver.

Agents also should not automatically trust one another without boundaries. An attack or malfunction in one agent can propagate through the system if trust is unconstrained. Each agent should have a defined trust boundary and only the permissions necessary for its role.

23. Use of AI Agents Across Multiple Jurisdictions

Global organizations deploying AI agents in multiple countries must consider not only Japanese law but also local data-protection laws, AI regulation, employment law, consumer law, export controls and other applicable requirements.

Where an AI agent can access data or systems across borders, the key issue is not limited to where the data is stored. Who can access it, from which jurisdiction, and through what technical path may also matter.

A practical global-policy architecture often separates group-wide baseline principles from jurisdiction-specific local rules, while establishing common minimum standards for permissions, high-risk actions and human approval across the organization.

24. Review AI-Agent Use Cases, Not Merely Model Names

An AI approval process that approves only a product name or model name is insufficient for agentic AI. The same platform may be low-risk when used to summarize public information and high-risk when connected to customer data with authority to issue refunds.

Where practicable, approval should be tied to a use case that combines purpose, business owner, connected systems, data categories, execution authority, human review, outbound communications and plausible harm.

The organization should also predefine which changes trigger re-review, such as a new model, a new tool, expanded permissions, additional data categories or a new external destination.

25. Govern the Agent Across Its Full Lifecycle

Governance should not end when the deployment is approved. AI agents should be managed across planning, procurement, PoC, design, production deployment, operation, modification and retirement. IPA’s 2026 guidance similarly emphasizes AI-system security across the lifecycle.

After deployment, companies should monitor usage patterns, failures, permission changes, model updates, incidents and changes to external tools, and should update controls where necessary.

At retirement, the organization should not merely switch off the agent. It should review API keys, service accounts, OAuth tokens, external-tool connections, retained data, memory, logs and backups so that unnecessary access rights do not remain active.

26. Additional Rules for AI Agents in Internal AI Policies

Even companies that already maintain a generative AI policy may need additional provisions when AI agents are introduced. Key topics include connections to external systems, access and execution rights, credential management, categories of actions permitted to run automatically, high-risk actions requiring Human-in-the-Loop approval, outbound destinations, log retention, emergency shutdown, approval of new tools and permission changes, and agent-to-agent interactions.

A policy that only governs “what employees may enter into generative AI” is not sufficient for AI agents. Because the agent can retrieve information on its own, the company must govern what the agent can access and what it can execute through both policy and technical configuration.

27. Illustrative Internal Policy Language for AI Agents

When adding AI-agent provisions to internal rules, companies may consider principles such as: “Only AI agents and connected tools approved by the Company may be used for business purposes”; “Access and execution rights granted to an AI agent must be limited to the minimum necessary for the relevant business purpose”; “High-risk actions designated by the Company may not be executed by an AI agent without required human approval”; “Connecting a new external tool, API or data source to an AI agent requires the Company’s prescribed review”; and “If abnormal behavior or a suspected information-security incident is identified, use of the agent must be suspended promptly and reported to the designated responsible function.”

The actual policy language must, however, reflect the type of AI agent, system architecture, industry, existing information-security rules and delegation-of-authority framework of the company.

28. What Senior Management Should Be Told About AI Agents

Reporting to senior management should not focus only on the number of AI agents deployed or the aggregate technology spend. Risk-oriented reporting should identify how many agents have material execution authority, which critical systems they connect to, what categories of personal or confidential information they process, which actions can occur without human approval, and what significant incidents or near misses have occurred.

For higher-risk agents, companies may also track the date of last review, the date of last permission review, material model or tool updates, and changes in external providers.

As AI agents move into core business processes, management should increasingly view them not merely as software tools, but as risk-bearing delegates within the organization’s operational framework.

29. SAKURA Law Office Perspective: The Core of AI-Agent Legal Governance

Two opposite assumptions can both be dangerous: treating AI agents as so novel that entirely new legal principles are required for every issue, and assuming that an existing generative AI policy is sufficient without modification. Many legal issues raised by AI agents remain grounded in familiar areas of corporate law, including personal information, trade secrets, contracts, intellectual property, employment, internal controls and cybersecurity.

What changes the analysis is execution authority. AI-agent governance must therefore address not only information submitted to an AI system, but also the systems the AI can access, the actions it can execute, the parties to whom it can transmit information and the degree of autonomy it is permitted to exercise.

The role of corporate legal practice is not to prevent the use of AI agents. It is to design legal and technical boundaries within which the agent can operate safely. Those boundaries become effective only when permissions, approvals, contracts, logging, security, data governance and incident response are designed as one integrated system.

30. Frequently Asked Questions

Q1. How is an AI agent different from ordinary generative AI?

Conventional generative AI primarily produces information, while an AI agent may connect to external systems, retrieve information, plan multiple steps and execute actions such as sending email, updating files and invoking APIs. Legally, the principal additional issue is therefore execution authority.

Q2. Can an AI agent be allowed to execute contracts or make payments?

Such use is not categorically prohibited, but it can create significant legal and financial consequences. The company should align the agent’s authority with internal delegation rules, monetary limits, approved counterparties and required human approvals. High-value or exceptional transactions will generally justify stronger human oversight.

Q3. Does Human-in-the-Loop make an AI-agent system safe?

Not automatically. Human approval is useful only if the reviewer can understand the proposed action and its consequences and has a genuine ability to reject, modify or stop it. High-risk approval screens should provide sufficient information and time for meaningful review.

Q4. Can an AI agent search all internal company files?

As a general matter, unrestricted access is not recommended. The agent should receive only the permissions necessary for the relevant task, and existing user-level access controls should remain effective. Particular care is required for personal information, trade secrets and information protected by NDAs.

Q5. What is prompt injection?

Prompt injection refers to attacks or manipulative content designed to cause an AI system to follow instructions that conflict with the user’s or organization’s intended objective. Where an AI agent has tool-execution authority, prompt injection can lead not merely to a bad answer but to unauthorized data transmission or system operations.

Q6. How much logging should a company retain for AI agents?

The answer depends on risk. Relevant records may include user instructions, material reference data, tool calls, actions executed, outbound communications, human approvals, timestamps, and model or configuration versions. The company should also protect the logs themselves because they may contain personal or confidential information.

Q7. Can an existing generative AI policy cover AI agents?

The general principles may carry over, but additional controls are normally required for access rights, execution rights, credentials, Human-in-the-Loop approvals, external-tool connections, emergency suspension, logging and multi-agent coordination.

Q8. What should a company do first after an AI agent sends information to the wrong recipient?

The company should consider suspending the agent and relevant credentials, determine what was sent and to whom, preserve relevant logs, and assess containment steps such as deletion requests. It should then evaluate the data and confidentiality implications and any reporting or notification obligations.

Q9. Does deployment of an AI agent require a board resolution?

Not in every case. The appropriate governance process depends on the company’s organizational structure, the importance of the deployment, existing authority rules and the extent to which the agent is involved in material transactions, financial reporting or critical systems. Higher-impact deployments should receive appropriate management-level oversight.

Q10. Is there value in consulting counsel before an AI agent is deployed?

Yes. It is generally easier and less costly to address authority design, Human-in-the-Loop, vendor contracts, data access, trade secrets and incident response during procurement or PoC than to redesign the architecture after a problem has occurred.

31. About the Kenshiro Michishita Legal Update Series

SAKURA Law Office maintains a “Legal Update” section on the profile page of Managing Partner Kenshiro Michishita and publishes continuing analysis of legal issues affecting companies and society.

No. 1 addressed corporate use of generative AI and AI governance. No. 2 examined generative AI and Japan’s data-protection regime. No. 3 addressed generative AI and copyright. No. 4 examined trade secrets, confidential information and NDAs. No. 5 addressed key terms in AI service agreements. No. 6 examined corporate generative AI policies and internal guidelines.

This seventh installment addresses the next stage of enterprise AI adoption: the transition from AI that generates information to AI that can connect to corporate systems and execute business processes. It therefore focuses on authority controls, Human-in-the-Loop, prompt injection, external tools and connectors, logging, incident response and internal controls for AI agents.

Future Legal Updates will continue to address AI and employment, AI-enabled new businesses, defamation and false information generated by AI, M&A, international transactions, Web3 and digital assets, crisis management and other issues of practical significance in corporate law.

32. Matters on Which SAKURA Law Office Advises in Relation to AI Agents

SAKURA Law Office advises companies on the legal and governance issues arising from the procurement, PoC, production deployment and operation of AI agents.

Our work may include pre-deployment legal review, use-case and authority mapping, design of Human-in-the-Loop approval flows, drafting or revision of AI-agent policies, review of AI service agreements, DPAs, SLAs and security addenda, access design for personal information and trade secrets, RAG and enterprise-search permissions, controls for agent-enabled contracting, payments and customer interactions, legal analysis of prompt injection and related security risks, logging and audit policies, incident-response procedures, and global AI-agent policies for multinational groups.

It is not necessary for a company to have complete visibility into its current AI-agent environment before seeking advice. Where an organization has already deployed AI agents but does not yet fully understand their permissions or data access, we can begin by reviewing the system architecture, connected services, intended use cases, data categories and existing policies and then prioritize the necessary legal and governance measures.

33. Contact Us — AI Agents and AI Governance

For advice regarding AI-agent deployment, access controls, Human-in-the-Loop, AI service agreements, internal AI policies, personal information, trade secrets, RAG, external-tool integrations, cybersecurity, logging, incident response and other AI and technology matters, please contact SAKURA Law Office.

For corporate clients, our support may include PoC-stage design, pre-production review, authority matrices and approval workflows, vendor contracting, alignment with existing internal rules, management reporting and periodic post-deployment review, in addition to advice on individual legal issues.

When contacting us, noting that your inquiry concerns “AI Agents / AI Governance” will help us direct the matter to the appropriate lawyer promptly.

SAKURA Law Office
Managing Partner: Kenshiro Michishita
4F, Ark Hills South Tower, 1-4-5 Roppongi, Minato-ku, Tokyo 106-0032, Japan
Tel: +81-3-6910-0692
https://sakura-lawyers.jp/en/

Principal Japanese Sources

Cabinet Office / AI Strategy Headquarters, “Guidelines for Ensuring the Appropriate Research, Development and Utilization of Artificial Intelligence-Related Technologies” (December 19, 2025) — https://www8.cao.go.jp/cstp/ai/ai_guideline/ai_guideline.html

Ministry of Economy, Trade and Industry, “AI Guidelines for Business Ver1.2” (March 31, 2026) — https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/20260331_report.html

Information-technology Promotion Agency of Japan (IPA), practical guidance for safe use of generative AI and AI agents (July 31, 2026) — https://www.ipa.go.jp/jinzai/ics/core_human_resource/final_project/2026/ai-security.html

IPA, “AI Security Bulletin” (latest update September 7, 2026) — https://www.ipa.go.jp/digital/ai/security/ai-security-bulletin.html

IPA, AI security training materials for critical-infrastructure sectors (FY2026) — https://www.ipa.go.jp/jinzai/ics/short-pgm/ai-security/2026.html

Ministry of Economy, Trade and Industry, “Contract Checklist for AI Utilization and Development” (February 2025) — https://www.meti.go.jp/press/2024/02/20250218003/20250218003.html

Personal Information Protection Commission, “Points to Note Regarding the Use of Generative AI Services” — https://www.ppc.go.jp/news/careful_information/230602_AI_utilize_alert/

e-Gov Laws and Regulations Database, Companies Act and Ordinance for Enforcement of the Companies Act — https://laws.e-gov.go.jp/

Agency for Cultural Affairs, materials concerning AI and copyright — https://www.bunka.go.jp/seisaku/chosakuken/aiandcopyright.html

Ministry of Economy, Trade and Industry, Trade Secret Management Guidelines — https://www.meti.go.jp/policy/economy/chizai/chiteki/trade-secret.html

Written and supervised by SAKURA Law Office, Managing Partner Kenshiro Michishita

This article provides general legal information based on Japanese AI policy materials, the AI Guidelines for Business Ver1.2, IPA publications concerning generative AI, AI agents and AI security, guidance issued by the Personal Information Protection Commission, and general corporate-law practice as of September 24, 2026. The legality of a specific AI-agent deployment, contractual responsibility, required controls and internal approval procedures will depend on the company’s industry, system architecture, intended use, data processed, degree of agent autonomy, connected systems, applicable laws and contractual relationships. This article does not constitute legal advice or a legal conclusion regarding any particular matter. Specific cases should be evaluated in light of the latest laws, technical specifications and facts.

NextPrev