日本語 Get in touch
All articles

Governance

If your staff use AI, the AI Guidelines for Business are about you

Japan's AI Guidelines for Business reached version 1.2 on 31 March 2026. They name three roles, developer, provider and user, and ten principles. Most companies assume they apply to vendors. The moment an employee uses a model in their work, the company is an AI user under the guidelines, and the user has obligations too.

Published 3 min read

The AI Guidelines for Business are Japan's main statement on how companies should handle AI. The Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry publish them jointly. Version 1.0 came out on 19 April 2024, 1.1 on 28 March 2025, and 1.2 on 31 March 2026.

They are not law. They are the reference that regulators, large customers and, increasingly, procurement teams point to when they ask "how do you manage AI". If you sell to a big Japanese company in 2026, expect to be asked.

Three roles, and you are one of them

The guidelines sort every organisation into three roles: AI developer, AI provider and AI user. Most managers read that list and stop at the first two. Their company does not train models or sell AI products, so the document is somebody else's.

It is not. An AI user in the guidelines is any organisation that uses an AI system in its business. A sales team drafting proposals with a chatbot is an AI user. A back office extracting data from PDFs with a model is an AI user. A customer service desk with an AI assistant in front of it is an AI user. That is most companies in Japan by now, whether or not anyone decided it.

The ten principles

The common guiding principles run to ten: human centric, safety, fairness, privacy protection, security, transparency, accountability, education and literacy, fair competition, and innovation.

Read them as a user rather than a developer and they become practical questions. Who inside the company is accountable when the model is wrong. Which decisions is it allowed to influence and which are reserved for a person. What goes into it and what must never go into it. Who has been taught to use it, and how do you know they were.

Those are design questions. Every one of them is answered in the interface, the workflow and the internal rulebook, or it is not answered at all.

What changed in 1.2

The FY2025 update summary is explicit about why the document moved. AI agents and physical AI are now written in, with definitions, benefits, risks and points to watch. The description of risk moved towards a risk based approach. The role definitions were clarified. And the summary records the committee's own view that the guidelines had grown long, and that municipalities and small businesses who are only now starting on AI governance need to be able to use them too.

That last point is the useful one. Our reading of it: the ministries expect small companies to have a written policy on this too, and they know it cannot be a hundred pages.

What a policy looks like

For most companies we work with, it fits on a few pages. Which tools are approved. What data can and cannot go into them. Which outputs need a human sign off before they reach a customer. Who owns the rules, and when they get reviewed. Plus one half day of training per department so the rules are understood rather than filed.

We write that alongside the product, because a rulebook that arrives after the rollout gets ignored. Started before the first pilot, a first version of the policy and the training plan takes about a week. If you already have a pilot running and no policy, that is the week to schedule now.

Sources

  1. MIC and METI, AI Guidelines for Business, version history and documents (1.0 on 19 April 2024, 1.1 on 28 March 2025, 1.2 on 31 March 2026)
  2. MIC and METI, Summary of the FY2025 update to the AI Guidelines for Business (12 March 2026)

Recognise the problem

We design, build and hand over the layer that turns a stalled AI pilot into something people actually use. Tell us where you are stuck.

Get in touch