// AI Safety
The safety review comes before the purchase order.
A Japanese enterprise buyer now runs an AI governance review on the way in, and it arrives earlier than most vendors expect. The questions are narrow and they repeat: where does the model run, who checked the output, what happens when it is wrong. This page sets out the rules that actually apply in 2026, and how we hold our own work, our vendors, and our channel to them.
// What actually applies
What binds, what only asks, and what quietly changed date.
The position as of August 2026. AI governance material ages badly, so the sources sit under the grid.
Japan: the AI Promotion Act
Passed 28 May 2025, promulgated and partly in force on 4 June 2025, fully in force on 1 September 2025 once the provisions establishing the AI Strategy Headquarters took effect. It carries no fines and no bans. The single duty it places on a private company is to endeavour to cooperate with government measures. Where conduct is egregious, the state investigates and names the company. The binding force sits in the law underneath it: APPI, the Copyright Act, the Unfair Competition Prevention Act, and whatever sector law already governs the product the AI sits inside.
The AI Guidelines for Business, Ver1.2
This is the document your buyer's governance team is actually reading. METI and MIC issued Ver1.2 on 31 March 2026, and it treats Japanese AI adoption as having moved out of pilots and into production. It defines AI agents and physical AI for the first time, and it makes human judgment a design requirement rather than a nicety. Soft law, so you may deviate from it. You will be asked to explain why.
EU AI Act: the date moved
The Article 50 transparency obligations apply from 2 August 2026: disclose that a person is dealing with an AI, and label AI-generated content. The stand-alone high-risk obligations did not. The Digital Omnibus package, given final Council approval on 29 June 2026, deferred those to 2 December 2027, and to 2 August 2028 where the high-risk AI is embedded in a product that is already regulated. One narrow piece did shift: the Article 50(2) machine-readable marking duty carries four months' grace to 2 December 2026, and only for systems already on the EU market before 2 August 2026. A good deal of vendor material still quotes the original date.
ISO/IEC 42001 and the NIST AI RMF
ISO/IEC 42001 is the AI management system standard, certified by an accredited body on a three-year cycle. It is voluntary and no country mandates it. It is turning up in enterprise procurement anyway, because a certificate spares the buyer an audit they would otherwise run themselves. The NIST AI RMF is the other common reference, organised around four functions: Govern / Map / Measure / Manage.
// The review itself
Six questions, and they arrive in this order.
This is what a Japanese security and risk team puts to a vendor. Answer them before the meeting rather than during it.
Where does the model run?
Processing location, storage location, whether anything crosses a border, and whether the workload can stay in Japan. This decides how APPI applies to the deal.
Who checks the output?
Ver1.2 makes human judgment a design requirement. Show the decision points where a person sits in the flow, as an operating procedure rather than an intention.
What happens when it is wrong?
Detection, blast radius, who gets told, and how you recover. Answering that you have not thought about it becomes a finding in the review.
What guards the input?
Text retrieved from somewhere else can arrive carrying instructions. The buyer wants to know how untrusted content is handled before it reaches the model.
What guards the output?
The checks that stop personal data, secrets, or content the reader has no right to see from leaving in a reply.
What leaves with us at the end?
Data, configuration, and model artefacts. Portability sits inside the sovereignty conversation, and Japanese buyers price it.
// How we apply it
The same bar, turned on ourselves.
A safety position a firm does not apply to itself is marketing. Below is what we do, put plainly enough that you can hold us to it during an engagement.
Our own work
What we hold ourselves to
- Client data does not enter any path where a public API may train on it.
- A named person reviews every client deliverable before it leaves us, including anything an AI drafted.
- Machine-generated analysis carries its source. We do not ship a figure we cannot point at.
- We keep a record of where AI was used on an engagement, and we will show it to you on request.
The vendors we represent
What a product clears before we carry it
- Where the model and the data are processed, and whether the workload can stay in Japan.
- Which decision points accept a human check, as a product capability rather than a promise.
- How a wrong output is detected, and the route by which a customer is told.
- What leaves with the customer on exit, and the documented steps for getting it out.
Buyers, end users and resellers
What we put in front of them
- We start by asking whether the use case needs AI at all.
- Where a product does not fit, we say so. Adoption is not the assumed outcome.
- Resellers get written limits: what the product cannot do, and what they must not claim for it.
- What to monitor after go-live is part of the handover, not a later conversation.
// Where this connects
Safety is a property of the build, so it shows up across the practice.
// On the longer horizon
Two conversations, and only one of them is yours to settle.
The long-horizon argument is live and it is serious. The AI Futures Project, founded by former OpenAI researcher Daniel Kokotajlo, published AI 2027 as a forecast of what a fast capability ramp would look like, then AI 2040: Plan A as a recommendation for what should happen instead: slow the pace, force transparency, and spread the resulting power wider than a couple of companies.
We are not in a position to adjudicate a forecast, and we will not pretend otherwise. What we will say is that the design implications survive the disagreement. Do not hand a decision to a system whose reasoning you cannot inspect. Keep a place where a person can stop it. Keep a route out. Those hold whether superintelligence arrives in 2030 or never, which is what makes them worth building now.
The near conversation is the one we can help with, and it does not need the far one resolved first.
// What carries over
- No decision closes automatically if you cannot inspect how it was reached.
- Keep one place where a person can halt it.
- Grant an agent the narrowest permission the task allows.
- Build the exit at the same time as the entry.
Run the review before your buyer does.
Bring the product and the use case. We will tell you which of the six questions you can answer today, and which one stops the deal.
