Notice

NEWS

2026.09.30

News

Publication of “Generative AI in the Workplace: Legal Risks and AI Governance for Companies in Japan (2026)”

LEGAL UPDATE | NO. 1 | SEPTEMBER 2026

[SAKURA Law Office | Legal Update by Managing Partner Kenshiro Michishita]

SAKURA Law Office
Managing Partner Kenshiro Michishita
Tokyo, Japan | September 2026

SAKURA Law Office has published the first installment of the Legal Update series by Managing Partner Kenshiro Michishita, entitled “Generative AI in the Workplace: Legal Risks and AI Governance for Companies in Japan (2026).”

Generative AI is no longer a specialized technology used only by a limited number of advanced technology companies. ChatGPT and other generative AI tools are increasingly being incorporated into drafting, translation, research, contract review, meeting-minute preparation, marketing, software development, customer support, internal knowledge management and a wide range of other corporate functions.

More recently, the focus has begun to shift from conventional generative AI systems that respond to human prompts toward AI agents that can connect to email, cloud storage, internal databases and other systems, retrieve information, make decisions, and in some cases perform external actions autonomously.

These developments create significant opportunities for greater efficiency, sophistication and new business models. At the same time, however, they bring together legal issues that companies have traditionally managed separately, including personal information, trade secrets, copyright, contracts, information security, employment, reputation and corporate governance.

The central question for companies is therefore no longer simply whether to use generative AI. The more important question is how to determine which AI systems may be used, by whom, for what business purposes, with what categories of information, subject to what level of human review, and with what allocation of responsibility for final decisions.

This Legal Update provides a structured overview of the principal legal and governance issues that companies should consider under Japanese law as of September 2026.

Executive Summary

The use of generative AI in business is not, in itself, generally prohibited under Japanese law. The legal analysis instead depends on the data being processed, the intended use, the contractual and technical settings of the AI service, the impact of the output, and the level of human oversight. Companies should therefore adopt a risk-based governance framework that integrates data protection, confidentiality, intellectual property, contracting, cybersecurity and corporate decision-making.

1. Japan’s AI Regulatory Framework

Japan enacted the Act on the Promotion of Research and Development and Utilization of Artificial Intelligence-Related Technologies in 2025. The Act was promulgated on June 4, 2025 and entered fully into force on September 1, 2025.

Japan’s AI framework should not be understood as a comprehensive prohibition-based regime under which every corporate use of AI is subject to prior governmental approval. Rather, Japan has adopted a framework that seeks to promote AI research, development and utilization while ensuring that AI is used appropriately.

This distinction is important for businesses. The policy objective is not to prevent companies from using AI. On the contrary, the Japanese framework expressly recognizes the potential of AI to increase the efficiency and sophistication of business activities and to contribute to innovation.

At the same time, the framework recognizes that inappropriate AI development or use may create risks involving personal information, intellectual property rights and other legally protected interests. Japanese companies, and foreign companies operating in Japan, should therefore approach AI governance as a matter of responsible deployment rather than simple prohibition.

2. The AI Act Is Only One Part of the Legal Analysis

The AI Act alone does not resolve the legal issues arising from corporate use of generative AI.

On December 19, 2025, the Japanese Government adopted guidelines concerning the appropriate development and use of AI-related technologies under the AI Act. Those guidelines identify human-centricity, fairness, safety, transparency, accountability, security, privacy and personal information protection, fair competition, AI literacy and innovation as important elements, while emphasizing a risk-based approach and integrated AI governance.

On March 31, 2026, the AI Guidelines for Business were updated to Version 1.2. Those guidelines organize relevant considerations according to the roles of AI developers, AI providers and AI users. Most companies that use an external generative AI service for internal business purposes will ordinarily be acting primarily as AI users. A company that incorporates AI into a product or service offered to customers, however, may also need to consider issues more closely associated with an AI provider.

In practice, depending on the use case, Japan’s Act on the Protection of Personal Information, Copyright Act, Unfair Competition Prevention Act, contract law, tort law, employment law, sector-specific regulation and cybersecurity requirements may all apply. AI law in Japan should therefore be viewed as a cross-disciplinary legal field rather than a single statute.

3. The First Question Is What Information Is Being Put Into the AI

For many companies, the most immediate legal risk associated with generative AI is not the AI model itself. It is the information entered into it.

A company may possess many different categories of information, including customer information, employee information, résumés, health information, internal emails, source code, pricing information, product development information, board materials, M&A documents, litigation materials, customer lists and information received from business partners under confidentiality agreements.

These categories of information are not legally identical. Some information may constitute personal information under Japanese data protection law. Some may qualify as a trade secret. Some may be subject to contractual confidentiality obligations. Some may be protected by copyright or by industry-specific rules.

A corporate AI policy should therefore classify information and determine which categories may be entered into which AI environments. The legal and security assessment should be conducted at the level of the actual service, subscription plan, technical configuration, purpose of use and type of information being processed.

4. Personal Information and Japan’s APPI

The use of personal information in generative AI systems requires particular attention under Japan’s Act on the Protection of Personal Information, commonly referred to as the APPI.

Japan’s Personal Information Protection Commission has issued specific guidance addressing the use of generative AI services. Where a business handling personal information enters personal information into a generative AI service, it must consider whether such use falls within the scope of the purpose of use identified for that personal information.

Additional issues may arise where personal data is entered into an external AI service without the individual’s consent. In particular, companies should examine whether the AI provider uses the submitted data solely to generate the requested output or whether the information may also be used for machine learning, model improvement or other purposes.

Relevant questions include whether submitted data is used for model training; how long submitted data is retained; where it is stored; whether subprocessors receive access; whether cross-border processing occurs; whether administrators can restrict user activity; whether logging and audit functions are available; and what happens to the data when the contract ends.

Japan also enacted amendments to the APPI in July 2026. Companies should distinguish carefully between provisions that are already effective and provisions that have been enacted but are not yet in force. Current compliance decisions should be based on the law presently applicable to the relevant conduct, while preparing for forthcoming changes.

5. Trade Secrets and Confidential Business Information

Not all commercially sensitive information is personal information. For many businesses, their most valuable information consists of product plans, manufacturing methods, pricing strategies, customer lists, technical information, source code, financing plans and information concerning potential acquisitions or business alliances.

Under Japan’s Unfair Competition Prevention Act, information may qualify for protection as a trade secret if the statutory requirements are satisfied, including requirements concerning secrecy management, usefulness and non-public nature.

Entering commercially sensitive information into an external AI service does not automatically mean that trade secret protection will always be lost. However, uncontrolled use of public external AI services may become relevant when evaluating whether the company has maintained an appropriate system for protecting confidential information.

Contractual obligations must also be considered separately. A non-disclosure agreement may restrict disclosure to third parties, outsourcing, use of external cloud services or cross-border processing. In such cases, entering information into an AI service may create a contractual issue even where the information does not constitute personal information.

A corporate AI policy should therefore address confidential information and trade secrets independently from personal data. A rule that merely prohibits employees from entering personal information into AI systems is not sufficient.

6. Generative AI and Copyright

Copyright questions relating to generative AI are often discussed as though they involve a single legal issue. In practice, it is important to separate the use of copyrighted works for AI development or machine learning from the creation and subsequent use of AI-generated outputs.

Japan’s Agency for Cultural Affairs has published materials discussing the relationship between generative AI and copyright under existing Japanese copyright law. For corporate users, one of the most important points is that content does not become free of copyright risk merely because it was produced by an AI system.

If an AI-generated image, text, music or other work is sufficiently similar to an existing copyrighted work and the relevant legal requirements for infringement are satisfied, ordinary copyright principles may become relevant. The risk is particularly important where AI-generated content is used externally and at scale, including in advertising, packaging, games, publishing, film or corporate branding.

At the same time, companies should not assume that every AI-generated output will necessarily be protected by copyright in the same way as a conventional human-created work. The degree of human creative contribution may become relevant. Companies planning to rely on AI-generated content as an important long-term business asset should consider not only infringement risk but also ownership, protectability and the documentation of the human creative process.

7. Hallucinations and the Need for Human Verification

Generative AI systems may provide incorrect information in highly persuasive language. This phenomenon is commonly referred to as hallucination.

AI systems may generate non-existent cases, inaccurate statutory references, fictitious academic papers, incorrect product information, false biographical information or inaccurate financial information.

When AI is used only for brainstorming or preliminary drafting, the consequences of an error may be limited. The risk changes materially when the output is used for customer communications, public statements, financial decisions, recruitment decisions, legal analysis, contractual negotiations or other important corporate decisions.

The appropriate response is not necessarily to require identical human review for every AI output. A risk-based approach is more appropriate. The more significant the decision and the greater the potential impact of an error, the stronger the human verification process should be. AI should support human decision-making in high-impact areas rather than replace responsibility for the final decision.

8. Defamation, Privacy and False Information

Generative AI can generate statements about identifiable individuals and companies, and those statements may be inaccurate.

If an AI system generates false allegations concerning criminal conduct, misconduct, professional history or other sensitive matters, and a company republishes or relies upon those allegations, defamation, privacy, reputational harm and other legal issues may arise.

The fact that a statement was originally generated by an AI system does not necessarily eliminate the responsibility of the person or company that chose to use or publish it.

This issue requires particular caution where AI is used for background checks, competitor research, recruitment, due diligence or public-facing content. Adverse information concerning a person or company should not ordinarily be treated as reliable solely because an AI system produced it. Where the information may materially affect another person’s rights or a significant business decision, the underlying source should be verified.

9. AI Contracts: Follow the Data

Contractual review is a critical part of corporate AI governance. Japan’s Ministry of Economy, Trade and Industry has published an AI contract checklist addressing issues arising when businesses use or develop AI systems.

When reviewing an AI service agreement, companies should consider how input data may be used; whether inputs may be used for training or model improvement; ownership and permitted use of outputs; allocation of intellectual property infringement risk; representations and warranties; indemnification; limitations of liability; data retention and deletion; security; subprocessors; cross-border transfers; incident notification; audit rights; logging; changes to terms; termination; and governing law and dispute resolution.

Companies should also recognize that different versions of a service offered under the same brand may have materially different contractual and technical conditions. A free consumer account, an enterprise account and an API-based implementation may not involve the same treatment of data.

Accordingly, the correct legal question is not simply whether a particular AI service is safe. The better question is whether the specific service, under the specific contract and configuration, is appropriate for the specific corporate use case and category of information.

10. AI Agents Create a Different Level of Risk

The development of AI agents materially changes the risk profile of enterprise AI. A conventional generative AI system generally responds to a user prompt. An AI agent may be connected to email, cloud storage, calendars, internal databases and external systems, and may be authorized to take actions rather than merely generate text.

An agent with excessive access rights may retrieve information it should not access. It may send a message to the wrong recipient, alter or delete files, or take action based on inaccurate information. It may also be exposed to prompt-injection attacks or other attempts to manipulate its behavior through external content.

Companies deploying AI agents should therefore apply the principle of least privilege. An AI agent should receive no broader access than is necessary to perform its defined function.

For actions that are difficult to reverse or that may materially affect third parties — including payments, contract execution, customer communications, deletion of important data and employment decisions — human approval should generally remain part of the process.

11. Shadow AI Is a Governance Issue

A company may believe that it has not adopted generative AI while employees are already using public AI services through personal accounts. This is often referred to as shadow AI.

Shadow AI is problematic because the company may have no visibility into which services are being used, what information is being submitted or whether business data is being retained externally.

A simple internal announcement stating that AI is prohibited may not eliminate this risk. A prohibition that is not supported by training, technical controls, monitoring and realistic alternatives may simply drive AI use outside the company’s formal governance structure.

In some organizations, providing employees with an approved enterprise AI environment may therefore reduce rather than increase overall information-management risk. The appropriate approach depends on the company’s business, data and risk profile.

12. What Should an Internal Generative AI Policy Cover?

An effective generative AI policy should not be merely a list of prohibited acts. It should create an operational framework that employees can actually follow.

The policy should define its scope, including whether it applies only to standalone generative AI tools or also to AI features embedded in ordinary SaaS products, AI agents and privately owned devices used for work. The company should then identify approved AI services and specify what categories of information may be processed in each approved environment.

For example, a company might permit routine use with publicly available information, allow ordinary internal information only within an approved enterprise environment, and require specific approval before personal data, highly confidential information, M&A information or third-party confidential information can be processed.

The company should also specify the level of review required before AI-generated content may be used. A draft used internally for brainstorming does not require the same review as a legal notice, customer communication, public announcement, advertisement or employment decision. High-risk use cases should be identified in advance and made subject to mandatory human review and approval.

Finally, the company should establish an incident-reporting process. Employees who accidentally submit confidential information should know whom to contact immediately. Early notification may allow the company to seek deletion, preserve logs, disable access and assess whether further legal or technical action is required.

13. AI Governance Should Be a Continuing Management Process

AI governance should not end when a company publishes an internal AI policy. AI technology, service terms, regulatory guidance and corporate use cases continue to change. Governance must therefore operate as an ongoing management process.

Depending on the size and complexity of the organization, this process may include a corporate AI policy, an approved-tools register, classification of AI use cases, legal and contractual review, privacy review, security review, employee training, incident response, periodic monitoring and management reporting.

Legal, IT, cybersecurity, privacy, HR, internal audit, business teams and senior management should not address AI independently from one another. The most effective governance structures connect these functions.

Senior management does not necessarily need to know how many times an employee used an AI system. It should, however, understand where AI is being used in high-impact business processes, what sensitive data is being processed, which systems have access to corporate infrastructure and where material decisions depend upon AI-generated output.

14. The SAKURA Law Office Perspective on AI Legal Practice

As generative AI becomes embedded in ordinary corporate activity, the role of legal counsel is also changing.

The role of legal counsel should not be to respond to new technology only by saying that it is prohibited or risky. At the same time, it is equally inappropriate for legal review to begin only after an AI project has already been built and launched.

Companies seeking to capture the benefits of AI while controlling risks involving personal information, confidential information, intellectual property, contracts and cybersecurity should integrate legal considerations into the design of AI projects from an early stage.

There is no single AI governance framework that is appropriate for every company. A financial institution, manufacturer, healthcare business, software company and professional services firm will not face identical risks. The appropriate governance structure must reflect the company’s business model, data, technology, regulatory environment and actual use cases.

The central legal task is therefore to understand how AI is actually being used within the organization, assess the risks of each use case, and design proportionate rules and controls that allow innovation without losing legal accountability.

15. About the Kenshiro Michishita Legal Update Series

SAKURA Law Office will continue to publish the Legal Update series on the profile page of Managing Partner Kenshiro Michishita, addressing legal developments and practical issues of significance to companies and business leaders.

The series will focus not only on explaining statutes and regulatory frameworks, but also on identifying the practical questions that corporate management, in-house legal teams and other professionals should examine in actual business situations.

Future Legal Updates are expected to address, among other themes, generative AI and data protection, generative AI and copyright, AI service agreements, internal AI policies, AI agents, M&A, cross-border transactions, Web3 and digital assets, crisis management, corporate misconduct and information governance.

In a period of rapid technological, commercial and social change, SAKURA Law Office believes that legal practice must do more than describe existing rules. It must also help businesses construct workable legal frameworks for new and evolving problems.

16. How SAKURA Law Office Can Assist

SAKURA Law Office advises companies on a broad range of legal issues arising from the adoption, development and use of generative AI and other AI systems.

Our support may include legal risk assessments before AI deployment; drafting and reviewing internal AI policies and guidelines; review and negotiation of AI service agreements and terms of use; analysis of personal data and confidential information issues; copyright and other intellectual property matters; legal structuring for AI-enabled products and services; AI-agent governance; defamation and other rights-infringement issues involving AI-generated content; and incident response following information leakage or other AI-related events.

Companies are welcome to consult us even at an early stage, before a final decision has been made to adopt a particular AI system. By understanding the proposed use case, the information to be processed, the relevant technical environment and the company’s risk profile, we can help identify the legal issues that should be addressed before implementation.

AI / Generative AI Legal Inquiries

For advice concerning the adoption of generative AI, internal AI policies, AI service agreements, personal data and data governance, trade secrets, copyright and other intellectual property rights, AI agents, AI-enabled business models, or other AI / IT legal matters, please contact SAKURA Law Office.

Corporate clients may consult us not only after a specific issue has arisen, but also regarding pre-deployment legal reviews, internal governance frameworks, policy development and ongoing AI governance support.

SAKURA Law Office

Managing Partner: Kenshiro Michishita

4F, Ark Hills South Tower, 1-4-5 Roppongi, Minato-ku, Tokyo 106-0032, Japan

TEL: +81-3-6910-0692

https://sakura-lawyers.jp/en/

Kenshiro Michishita – Profile

Disclaimer

This article provides general legal information based on laws, governmental materials and other information publicly available as of September 2026. It does not constitute legal advice or a legal conclusion concerning any specific matter. Specific matters should be assessed in light of the latest applicable law, contractual arrangements, technical environment and individual facts.

Principal Japanese Sources

• Cabinet Office – Japan AI Act

• AI Strategy Headquarters – Guidelines on Appropriate Development and Use of AI-Related Technologies

• Ministry of Economy, Trade and Industry – AI Guidelines for Business, Version 1.2

• Ministry of Economy, Trade and Industry – Checklist for Contracts Concerning AI Use and Development

• Personal Information Protection Commission – Notice Concerning the Use of Generative AI Services

• Personal Information Protection Commission – 2026 APPI Amendment

• Agency for Cultural Affairs – AI and Copyright

• Ministry of Economy, Trade and Industry – Trade Secret Management Guidelines

• Information-technology Promotion Agency, Japan – Security Guidance for Generative AI and AI Agents

NextPrev