Adopt

AI Agent Governance: Japan's AI Guidelines for Business and Internal Rules

・ Employee Store Operations

Summary

AI agent governance is easier to build on top of national guidelines. This article reads the parts of the AI Guidelines for Business (version 1.2), published by Japan's Ministry of Internal Affairs and Communications (MIC) and Ministry of Economy, Trade and Industry (METI), that apply to companies using AI, and turns them into internal rule items and an operating process.

This article was checked against public materials from MIC, METI and the Cabinet Office of Japan on October 2, 2026. The guidelines are updated over time. Before relying on them, check the latest version through the sources at the end.

AI agent governance is the set of rules and management structures that let you keep using AI agents safely. AI agents act on their own across a wide range, such as sending email or changing data. That is why you need to decide in advance who allows what, and what gets recorded.

What the AI Guidelines for Business are

The AI Guidelines for Business are guidance for businesses that handle AI, compiled by MIC and METI. The first version was issued in April 2024. The latest, version 1.2, was published on March 31, 2026.

The main text describes itself as non-binding soft law. It is not a law with penalties for noncompliance. It is guidance for businesses to follow voluntarily.

On the legislative side, the Act on the Promotion of Research, Development and Utilization of AI-Related Technologies (Japan's AI Act) was promulgated on June 4, 2025. According to the Cabinet Office, it fully took effect on September 1 of the same year. The main text of the guidelines lists this act as part of its background.

The guidelines merged three earlier documents: MIC's “Draft AI R&D Guidelines for International Discussions” and “AI Utilization Guidelines,” and METI's “Governance Guidelines for Implementation of AI Principles.” Businesses now refer to this single set of guidelines instead of those three.

In March 2026, MIC and METI also published a draft handbook on using the AI Guidelines for Business. It is aimed at businesses just starting to build AI governance. A chatbot that answers questions about the guidelines was released the same month. If you want one document to start with, you can read this handbook before the main text.

What version 1.2 adds on AI agents

Version 1.2 adds a definition of AI agents. In the guidelines, an AI agent is an AI system that senses its environment and acts autonomously to achieve a specific goal. A MIC document summarizing the update says the following points were added for businesses that use AI.

  • Because AI agents act autonomously, regular review of operation history and reporting become important
  • Where output could cause serious impact or harm, decisions should follow a mechanism that keeps a human in the loop
  • To limit damage from unintended data leaks, keep the data handled to a minimum

Where to read it

The main text, appendix, checklist and worksheets for version 1.2 are published on MIC's page. METI's page lists older versions up to 1.1. To find the latest version, start from MIC's page.

What is expected of businesses that use AI

The guidelines divide businesses involved with AI into three roles: AI developers, AI providers and AI business users. One company can hold more than one role.

The three roles in the guidelines

AI developer

  • Develops AI systems
  • Handles model training and validation

AI provider

  • Offers services with AI built in
  • Supports how users operate them

AI business user

  • Uses AI in its business
  • Uses it within the scope the provider intended

Summarized from the definitions in the AI Guidelines for Business, version 1.2

A company that buys an AI agent and uses it internally is an AI business user. The side that builds and delivers it is closer to an AI provider or AI developer. When you write internal rules, decide first which role your company holds. That narrows down which chapters you need to read.

Part 5 of the main text lists what matters for AI business users. Here is a short summary of the items that lead into internal rules.

  • Follow the usage precautions set by the provider and use the AI within the intended scope
  • Check that it works as expected
  • Input accurate data, and up-to-date data where needed
  • Take care not to input personal or confidential information inappropriately
  • When output informs an evaluation of a person, tell that person and be able to explain it
  • Keep the documents received from the provider and follow the service terms

The appendix section for AI business users also lists information worth getting from the provider. When you buy an AI agent, confirm these four points with the provider and you will have the material for your internal rules.

  • The proper purpose of the AI and how to use it
  • The benefits and risks that follow from the AI's nature and how it is used
  • How and how often to check usage, and what happens if you do not
  • When and how the AI is updated and inspected

What to put in your internal rules

The main text names agile governance as the way to run AI governance. Instead of writing a fixed procedure once and stopping there, you keep cycling from analysis to evaluation.

How agile governance cycles
  1. 1Environment and risk analysisLook at benefits, risks and changes in the external environment
  2. 2Goal settingDecide on direction, such as an AI policy
  3. 3System designBuild the management mechanisms that reach the goal
  4. 4OperationRun things with the mechanisms you decided on
  5. 5EvaluationCheck whether they work and fix them

Based on “E. Building AI Governance” in the main text of the AI Guidelines for Business, version 1.2

Following this cycle, the items for your internal rules can be organized as follows.

  • Purpose: what the AI agent is used for, aligned with company policy
  • Allowed scope: the work delegated, and the systems and data it may touch
  • Information that must not be input: how personal and confidential information is handled
  • When a person checks: anything sent outside the company, and anything involving money or contracts
  • Records: who keeps operation history and input/output records, and where
  • Incident response: how to stop it, who to contact, and reporting to the provider
  • Review: when and by whom the rules and usage are checked

The checklist (Appendix 7) turns the common principles into short questions. One example asks whether you have a policy on AI governance and privacy. It is useful for spotting gaps in your own rules.

Owners and the approval flow

Rules do not run unless someone makes decisions. At minimum, assign these three roles.

  • Owner: responsible for all AI agent use and decides on rule changes
  • Business unit contact: checks day-to-day behavior and reports anything abnormal
  • Information management contact: checks how personal and confidential information is handled

Set the weight of approval by the impact of the work you delegate to the AI agent. The guidelines ask for human judgment in the loop where output could have serious impact. The breakdown below is one example of turning that idea into an internal rule.

Setting approval weight by the work delegated (example)

Where does the AI agent's output go?

Internal drafts or summaries that a person reads before useThe business unit decides on adoptionStill file a usage notice and keep records
Sent outside the company, or involves money or contractsOwner approval requiredAdd a step where a person checks before sending
Reads or writes personal or confidential informationApproval from the owner and the information management contact requiredKeep the data handled to a minimum

Make the permissions you give the AI agent subject to approval too. MIC's update summary says it added, for AI providers, that proper permission settings matter for preventing unintended operations by AI agents. How to decide permissions is covered in AI agent permission management.

Usage records and review frequency

The appendix section for AI business users says to set up log management before use. Logs include operation history and records of inputs and outputs. During use, check regularly that the AI is used within the proper scope.

The security section lists reviewing logs regularly and having a way to report abnormal operations right away. It also gives examples of first responses when security is breached.

  • Rolling back the AI system or restoring with an alternative system
  • Stopping the AI system (kill switch)
  • Disconnecting it from the network
  • Confirming what was breached and reporting to the people concerned

The guidelines do not set a review frequency in days. Your company decides. For example, the business unit checks logs weekly and the owner reviews the whole rule set quarterly. When the provider updates the AI, or a law or the terms change, review without waiting for the scheduled time.

A rule template

Here is an example that puts the items above into a one-page internal rule. Rewrite it to fit your own work.

  1. Purpose: these rules set out how the company uses AI agents safely
  2. Scope: all AI agents used in company work. Notify the owner before adoption
  3. Allowed use: limited to the work notified and the systems and data permitted
  4. Input limits: do not input personal or confidential information unless the information management contact approves
  5. Human check: a person checks anything sent outside the company, and anything involving money or contracts, before it is sent
  6. Records: keep operation history and input/output records, and the business unit checks them regularly
  7. Incidents: anyone who notices something abnormal stops use at once and reports to the owner. The owner contacts the provider
  8. Review: the owner reviews these rules regularly, and whenever the provider makes an update or laws or terms change

How to decide what information may be input is explained in Precautions for using generative AI at work, based on materials from Japan's Personal Information Protection Commission and Agency for Cultural Affairs.

Adopting an AI employee through Employee Store

Employee Store is a marketplace where companies can adopt AI agents built by developers, with a one-time purchase or a monthly plan. Each AI employee listed is published after review by Employee Store Operations.

After purchase, you can message the seller in a deal room created for each transaction. Confirm the items set in your internal rules here before adoption, such as where it runs, which accounts it uses, what records remain and how to stop it. The adoption process is summarized in How to adopt an AI agent.

  • Where the AI agent runs, and which accounts or API keys it uses
  • Which data in which systems it reads and writes
  • Where operation history and input/output records are kept
  • How to stop it if something goes wrong, and who to contact
  • Whether the provider will notify you before updating the AI

Check the deliverables in the deal room before you confirm receipt. If you confirm receipt only after your internal rule checks are done, you reduce rework after adoption.

FAQ

Are there penalties for not following the AI Guidelines for Business?
The main text describes itself as non-binding soft law. It is not a law with penalties for noncompliance. It is guidance for businesses to follow voluntarily.
Do the guidelines apply to a company that only uses AI agents?
Yes. The guidelines define businesses that use AI systems or AI services in their operations as AI business users, and Part 5 of the main text and the appendix list what matters for them.
Where can I read the latest version?
As of October 2026, the latest is version 1.2, published on March 31, 2026. The main text, appendix and checklist are available on MIC's page.

About the author

Employee Store OperationsThe operations team behind Employee Store, a marketplace for AI agents. We check tool features and pricing against official sources and list them at the end of each article. If you spot an error, please let us know via the contact form.

Sources

Ask AI

Ask AI if it fits your work.

Use your usual AI to explore what Employee Store offers and what to check before buying.

Opens an external AI service. Confirm pricing and deliverables on the listing page.