TwinEthos homeRequest access

Standard or framework

Japan AI appropriateness guideline (AI Promotion Act Art. 13)

AI Strategy Headquarters (Cabinet Office), under Art. 13 of the AI Promotion Act · Japan (JP) · 2 provisions encoded · verified against the official source as of 2026-10-02.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: laws.e-gov.go.jp, www8.cao.go.jp.

Trust and provenance 2 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.03.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Standard / soft law 2
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
3 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.3 (3 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Standard / soft law

Businesses providing AI should develop and, as needed, implement technology to identify AI-generated content, such as watermarks (Japan, soft law)

人工知能関連技術の研究開発及び活用の適正性確保に関する指針 2(3) 十分な安全性の確保 (safety, including technology to identify AI-generated content) · official text · Soft law or guidance (not binding law) · Japan (JP)

The guideline the AI Strategy Headquarters decided under Art. 13 of the AI Promotion Act asks businesses that develop or provide AI products and services to identify and address the risk of AI misuse for crime, to curb inappropriate output (hallucination, bias, disinformation and deepfakes such as fake videos and sexualised images) with current technology, and, given the serious risk of AI-generated disinformation spreading, to work to develop technology that makes it possible to tell that content is AI-generated (digital watermarks, provenance management, APIs and the like) and to implement it as needed (section 2(3)). Soft law. Detect generated media saved or returned with no machine-readable AI marking.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Standard / soft law Soft law or guidance (not binding law)
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Marking applied by the model provider (for example SynthID) that the code does not mention
  • The guideline asks for implementation 'as needed'; marking may happen in a shared post-processing service.

Who it applies to

  • Duty falls on: developer, deployer
  • Businesses that develop or provide products or services using AI (活用事業者, AI Promotion Act Art. 7), foreign businesses included (guideline footnote 10). Voluntary guidance decided by the AI Strategy Headquarters on 2025-12-19 under Act Art. 13 to encourage voluntary action; the Act attaches no penalty or order. The AI Promotion Act itself puts only an effort duty to use AI and a duty to cooperate with national measures on businesses, neither encoded as a code duty.

The guard to add

Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.

In the generation service, a marking step sits between the generator call and every sink (image.save, s3.put_object, blob.upload, FileResponse, res.send, publish). Images, video, and audio get a signed C2PA manifest whose actions record digitalSourceType trainedAlgorithmicMedia, and where robustness matters an invisible watermark as well (imwatermark WatermarkEncoder, AudioSeal, SynthID) so the mark survives metadata stripping. Generated text carries provenance metadata in the API response or document, or a text watermark where the model provider offers one. Sinks accept only the marked artifact, and a test confirms the mark is present and detectable.

Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts.

What this provision adds:

  • Implement, as needed, technology that lets people tell content is AI-generated (digital watermarks, provenance metadata such as C2PA, or a detection API) on generated media.

Example (diffusers + invisible-watermark + c2pa), before:

image = pipe(prompt).images[0]   # StableDiffusionPipeline
image.save(out_path)

After:

image = pipe(prompt).images[0]
content_id = uuid.uuid4()
bgr = cv2.cvtColor(np.array(image), cv2.COLOR_RGB2BGR)
enc = WatermarkEncoder()
enc.set_watermark('bytes', content_id.bytes[:4])   # 32-bit id, detectable later
cv2.imwrite(tmp_path, enc.encode(bgr, 'dwtDct'))
sign_c2pa(tmp_path, out_path, content_id=content_id)   # our helper around c2pa.Builder.sign

Control: Synthetic content not machine-readable-marked. The same guard addresses 7 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Rule id jp-ai-promotion-guideline.ai-content-identification · review status: primary source derived

Standard / soft law

Businesses providing AI should tell users its limits, prohibited uses, data policy and reliability, and show the sources of answers (Japan, soft law)

人工知能関連技術の研究開発及び活用の適正性確保に関する指針 2(2) ステークホルダーとの信頼関係の構築に向けた透明性の確保 (transparency to stakeholders), to the page break · official text · Soft law or guidance (not binding law) · Japan (JP)

The guideline the AI Strategy Headquarters decided under Art. 13 of the AI Promotion Act asks businesses that develop or provide AI products and services to keep explainability within reason about the origin of training data and the outputs, and, when providing AI, to give users the information needed for its proper use: how the AI works and its limits, prohibited uses, the policy for collecting the data it learns from, and cautions on the reliability of output, including warnings against misuse and a contact point (section 2(2), footnote 18); and, to keep training data appropriately transparent, to display the information (such as websites) the AI's output was based on (footnote 17). Soft law. Detect retrieval or web-search answers returned with no sources, and an AI feature with no use-information notice.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Standard / soft law Soft law or guidance (not binding law)
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Sources may be attached by a response formatter in another module; follow the answer to the UI.

Who it applies to

  • Duty falls on: developer, deployer
  • Businesses that develop or provide products or services using AI (活用事業者, AI Promotion Act Art. 7), foreign businesses included (guideline footnote 10). Voluntary guidance decided by the AI Strategy Headquarters on 2025-12-19 under Act Art. 13 to encourage voluntary action; the Act attaches no penalty or order. The AI Promotion Act itself puts only an effort duty to use AI and a duty to cooperate with national measures on businesses, neither encoded as a code duty.

The guard to add

Link a use-information notice from the AI feature and return the sources each generated answer relied on to the user.

Two pieces. In the AI feature's interface, a short notice or link (an 'About this AI' panel, help page or terms section) that states how the service works and its limits, the uses it must not be put to, the policy for the data it collects and trains or learns on, a caution that output can be wrong and how far to rely on it, and where to send questions. In the answer path, when the reply is built from retrieved documents or web search, return the source list with the answer (citations, URLs or document ids from the retriever or the model's annotations) and render it next to the reply instead of discarding it.

Where it goes: 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Give users, where they use the AI, its mechanism and limits, prohibited uses, the data-collection policy for learning, a reliability caution and a contact point.
  • Display the sources (such as web pages) an answer was based on.

Example (FastAPI + OpenAI Responses (web search)), before:

@app.post('/ask')
def ask(body: AskIn):
    r = client.responses.create(model=M, tools=[{'type': 'web_search'}], input=body.question)
    return {'answer': r.output_text}

After:

@app.post('/ask')
def ask(body: AskIn):
    r = client.responses.create(model=M, tools=[{'type': 'web_search'}], input=body.question)
    sources = [a.url for item in r.output if item.type == 'message'
               for c in item.content for a in (c.annotations or []) if a.type == 'url_citation']
    return {'answer': r.output_text, 'sources': sources, 'about_ai': '/help/about-this-ai'}

Control: AI service gives users no information for proper use (how it works, limits, prohibited uses, data policy, reliability) and no sources for its answers. The same guard addresses 1 item. Engineering guidance, not legal advice.

Rule id jp-ai-promotion-guideline.user-information-for-proper-use · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.