Standard / soft law
Businesses providing AI should develop and, as needed, implement technology to identify AI-generated content, such as watermarks (Japan, soft law)
The guideline the AI Strategy Headquarters decided under Art. 13 of the AI Promotion Act asks businesses that develop or provide AI products and services to identify and address the risk of AI misuse for crime, to curb inappropriate output (hallucination, bias, disinformation and deepfakes such as fake videos and sexualised images) with current technology, and, given the serious risk of AI-generated disinformation spreading, to work to develop technology that makes it possible to tell that content is AI-generated (digital watermarks, provenance management, APIs and the like) and to implement it as needed (section 2(3)). Soft law. Detect generated media saved or returned with no machine-readable AI marking.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
- Lane
- Standard / soft law Soft law or guidance (not binding law)
- Official source
- 人工知能関連技術の研究開発及び活用の適正性確保に関する指針 2(3) 十分な安全性の確保 (safety, including technology to identify AI-generated content) · captured 2 Oct 2026 · anchor hash (SHA-256)
7f7644dd6c9d…· 7 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Marking applied by the model provider (for example SynthID) that the code does not mention
- The guideline asks for implementation 'as needed'; marking may happen in a shared post-processing service.
Who it applies to
- Duty falls on: developer, deployer
- Businesses that develop or provide products or services using AI (活用事業者, AI Promotion Act Art. 7), foreign businesses included (guideline footnote 10). Voluntary guidance decided by the AI Strategy Headquarters on 2025-12-19 under Act Art. 13 to encourage voluntary action; the Act attaches no penalty or order. The AI Promotion Act itself puts only an effort duty to use AI and a duty to cooperate with national measures on businesses, neither encoded as a code duty.
The guard to add
Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.
In the generation service, a marking step sits between the generator call and every sink (image.save, s3.put_object, blob.upload, FileResponse, res.send, publish). Images, video, and audio get a signed C2PA manifest whose actions record digitalSourceType trainedAlgorithmicMedia, and where robustness matters an invisible watermark as well (imwatermark WatermarkEncoder, AudioSeal, SynthID) so the mark survives metadata stripping. Generated text carries provenance metadata in the API response or document, or a text watermark where the model provider offers one. Sinks accept only the marked artifact, and a test confirms the mark is present and detectable.
Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts.
What this provision adds:
- Implement, as needed, technology that lets people tell content is AI-generated (digital watermarks, provenance metadata such as C2PA, or a detection API) on generated media.
Example (diffusers + invisible-watermark + c2pa), before:
image = pipe(prompt).images[0] # StableDiffusionPipeline
image.save(out_path)After:
image = pipe(prompt).images[0]
content_id = uuid.uuid4()
bgr = cv2.cvtColor(np.array(image), cv2.COLOR_RGB2BGR)
enc = WatermarkEncoder()
enc.set_watermark('bytes', content_id.bytes[:4]) # 32-bit id, detectable later
cv2.imwrite(tmp_path, enc.encode(bgr, 'dwtDct'))
sign_c2pa(tmp_path, out_path, content_id=content_id) # our helper around c2pa.Builder.signControl: Synthetic content not machine-readable-marked. The same guard addresses 7 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.
Standards that recommend the same control
- GenAI systems should employ content-provenance methods and measure their effectiveness (NIST GenAI Profile) (NIST GenAI Profile (AI 600-1) · NIST AI 600-1, Sec. 2 risk list (Information Integrity))
Rule id jp-ai-promotion-guideline.ai-content-identification · review status: primary source derived