On August 25, 2026, Hong Kong’s Office of the Privacy Commissioner for Personal Data issued guidance on protecting personal data privacy in the use of agentic AI, translating data minimization, retention, least privilege, auditability, and human oversight into more concrete deployment and operating controls for AI agents. On the same day, Japan’s Intellectual Property Strategy Headquarters published a principle-code on intellectual property protection and transparency for the appropriate use of generative AI, using a “comply or explain” mechanism to encourage model developers and providers to disclose information on training data, models, and IP-protection measures, creating a new soft-law framework for generative AI training transparency and copyright governance. From August 25 to 28, 2026, Korea promulgated and brought into effect most provisions of the amended Act on the Promotion of Artificial Intelligence and Data-Based Administration and its Enforcement Decree, bringing AI accountability officers, service inventories, data-quality requirements, and ethics into public-sector governance while further specifying impact assessment, logging, performance validation, and incident-response mechanisms that will take effect in 2027. On August 26, 2026, Singapore’s Ministry of Law and Intellectual Property Office launched a public consultation on AI and the intellectual property regime, bringing lawful use of training data, infringement by generated outputs, and allocation of responsibility among developers, deployers, and end users into policy review. On August 27 and 28, 2026, China issued a series of national AI standards covering agents, retrieval-augmented generation, cloud inference deployment toolchains, computing platforms, and open-source model platforms, providing a more unified technical baseline for enterprise AI system design, testing, procurement, and acceptance.
On August 25, 2026, Hong Kong’s Office of the Privacy Commissioner for Personal Data (PCPD) published the non-binding guidance Protecting Personal Data Privacy in the Use of Agentic AI, providing practical recommendations for organizations using agentic AI to process personal data. The guidance focuses on data minimization, purpose limitation, data retention, system permissions, security auditing, risk assessment, and human oversight, and supplements the PCPD’s 2024 Artificial Intelligence: Model Personal Data Protection Framework. The guidance itself does not create statutory obligations independent of the Personal Data (Privacy) Ordinance (PDPO); rather, it explains how organizations can apply existing personal-data protection requirements in agentic AI scenarios.
Compared with earlier governance documents aimed mainly at general AI systems, this guidance addresses the additional risks that arise once agentic AI gains access to systems and can autonomously execute tasks. The PCPD organizes the relevant controls into nine recommendations: apply data minimization at the point of data collection and clearly segregate the information and systems an agent may access; explain in privacy notices how agentic AI processes personal data, control changes in purpose, and set maximum retention periods for personal data stored in conversation histories, caches, and long-term memory; carefully manage plugins and skills from a system-security perspective; grant only the minimum permissions required to complete the task while maintaining traceability and auditability; test system security and reliability before deployment; conduct ongoing privacy risk assessments during operation; and apply human-in-the-loop oversight to decisions that may significantly affect individuals. The guidance also calls on organizations to define internal governance responsibilities and use contractual arrangements to control data retention and security by external service providers. The PCPD additionally provides a security checklist covering the assessment, preparation, deployment, use, and decommissioning stages.
What enterprises actually need to adjust is not merely the wording of privacy policies, but the agent’s operating permissions and the lifecycle of the data it touches. Conventional generative AI generally returns content after an employee actively enters information. An agent, by contrast, can continuously read email, calendars, customer systems, or business databases and can directly use tools to schedule appointments, send messages, or even make payments. Once long-term memory is enabled, the same personal data may continue to reside in conversation history, caches, or memory layers. Enterprises therefore need to break down “what an employee can access” into the more precise question of which data and tools an agent can access for a particular task, and at what point it must stop and wait for human approval. For example, the fact that a customer-service agent can read support tickets and draft replies does not mean it needs permission to modify customer master records, download full transaction histories, or send attachments to external email addresses. Agent logs should also record more than the final answer; they should make tool calls, data access, and key actions traceable, otherwise it will be difficult to identify where an error, unauthorized action, or personal-data breach occurred. For long-term memory, deletion and retention rules also need to propagate into the agent’s conversations, caches, and memory stores rather than being applied only to the original record in a business database. These are deployment implications derived from the PCPD’s recommendations; the guidance does not prescribe a uniform log schema, permission model, or retention period.
Hong Kong’s new guidance continues a policy path moving gradually from “general AI governance” toward “controls for specific use scenarios.” In 2024, the PCPD published its Artificial Intelligence: Model Personal Data Protection Framework, setting out an organization-level framework across AI strategy and governance, risk assessment and human oversight, model customization and system management, and stakeholder communication. Its 2025 Checklist on Guidelines for the Use of Generative AI by Employees further translated governance into questions such as which tools employees may use, what data they may enter, how outputs should be verified, and how AI incidents should be reported. A compliance review of 60 organizations conducted in May 2026 then showed that around 79% of organizations collecting or using personal data through AI had adopted human-in-the-loop oversight. The August guidance moves the focus another step—from “how humans use generative AI” to “how agents with autonomous action capabilities obtain and use permissions.” More notably, the PCPD expressly states that it referred to the July 2026 Cybersecurity Standards Practice Guide—Security Guidelines for the Deployment and Use of Intelligent Agents issued by the Secretariat of China’s National Cybersecurity Standardization Technical Committee, which already organizes agent security across assessment, preparation, deployment, use, and decommissioning. The UK National Cyber Security Centre’s interim guidance on agentic AI, published on August 20, similarly emphasizes sandboxing, logging and auditing, real-time oversight, attribution of actions, and emergency shutdown from a cyber-security perspective. The legal foundations and governance objectives differ, but the technical controls increasingly converge: the more autonomous an agent becomes, the more governance depends on permission boundaries, operational visibility, and the ability for humans to intervene—not merely on reviewing model outputs.
On August 25, 2026, Japan’s Intellectual Property Strategy Headquarters published the non-binding soft-law document Principle-Code for Protection of Intellectual Property and Transparency for the Appropriate Use of Generative AI, establishing a “comply or explain” mechanism for generative AI developers and providers on transparency and intellectual-property protection. The Japanese government has made clear that the code carries no penalties. Its role is not to create new statutory IP obligations, but to ask participating businesses either to implement the relevant principles or publicly explain why they do not.
The code divides transparency into two layers: proactive disclosure and case-specific inquiry. Principle 1 calls on businesses to disclose an overview of the model, training process, and training data, together with information on the implementation of intellectual-property protection measures; Principles 2 and 3 create routes, subject to specified conditions, for rights holders alleging infringement and users of generative AI to make inquiries about training data. Public information may include, for example, the model name and version, types of data and collection methods, use of web crawlers, traceability arrangements, and whether the business respects access restrictions, avoids scraping piracy sites, retains training records, and implements measures to reduce infringing outputs. Participants are also expected to publish their acceptance and implementation status on their own websites and notify the Intellectual Property Strategy Promotion Secretariat of the Cabinet Office. However, the government publication also notes that the formal launch date for the notification mechanism will be announced separately.
For enterprises that train generative AI models themselves or provide generative AI products to the Japanese public, the first change is that “can the model be explained?” becomes a governance question in its own right, rather than focusing solely on whether outputs infringe IP. If an enterprise chooses to participate in the code, it needs to prepare information on model versions, the sources of training and validation data, crawler policies, methods for recognizing rights reservations, training records, and contact channels for rights holders, while deciding which information can be disclosed and which should be addressed through “explain” rather than disclosure because of trade-secret or security concerns. For enterprises building applications on third-party foundation models, another practical question is whether upstream model suppliers can provide enough information for downstream organizations to meet their own disclosure and inquiry-response commitments. If an enterprise cannot confirm the underlying model’s data sources, crawling arrangements, or rights-protection measures, it may be difficult to answer customers or rights holders independently. The soft-law framework can therefore also be translated into model-procurement conditions—for example, requiring suppliers to explain their training-data transparency policies, copyright controls, inquiry-response mechanisms, and recordkeeping capabilities. Importantly, the code does not turn these measures into a uniform statutory audit format, nor does it grant rights holders a new compulsory right to disclosure. Declining to participate in the code also cannot be equated automatically with unlawful conduct.
The code is a further concretization of Japan’s systematic discussion, beginning in 2024, of how AI and intellectual-property rules should interact and how transparency should work in practice. The 2024 interim report of the Study Group on Intellectual Property Rights in the AI Era mainly mapped lawful use of training data, technical measures, and actions expected of relevant stakeholders. In December 2025, the Japanese government released a draft principle-code for public comment, with consultation closing on January 26, 2026. The 2026 Intellectual Property Strategic Program 2026 then expressly called for finalization of the code, which was reviewed at the 13th meeting of the study group on August 18 and formally published on August 25. Compared with the EU, both systems place training-data transparency and copyright governance at the model-provider level, but their legal paths differ significantly. Article 53 of the EU AI Act already requires GPAI model providers to adopt a copyright policy and publish a sufficiently detailed summary of the content used for training, while the General-Purpose AI Code of Practice primarily helps companies demonstrate compliance with mandatory legal obligations. Japan’s principle-code, by contrast, remains soft law and creates external visibility through public participation status and “comply or explain.” The enterprise deployment difference is therefore concrete: the same model entering both the EU and Japan first needs to identify mandatory minimum legal obligations in the EU, while in Japan the provider must additionally decide whether to participate in the principle-code and how to organize IP and training-data governance information that can be explained externally.
On August 25, 2026, Korea promulgated an amended Presidential Decree under the Act on the Promotion of Artificial Intelligence and Data-Based Administration (provisional translation; 인공지능 및 데이터 기반 행정 활성화에 관한 법률 시행령). On August 28, most provisions of the amended Act on the Promotion of Artificial Intelligence and Data-Based Administration (provisional translation; 인공지능 및 데이터 기반 행정 활성화에 관한 법률) and its Enforcement Decree took effect, bringing AI use into the administrative-governance systems of central administrative agencies, local governments, and other public institutions. One timing distinction is critical: although the public-sector AI impact-assessment and related risk-management regime has been specified in the new Enforcement Decree, the relevant provisions of the Act and Decree will not take effect until February 28, 2027.
The provisions effective from August 28 first address basic public-sector governance questions: “who is responsible, what AI is being used, and how is it managed?” The law requires public institutions to make clear that final authority and responsibility remain with the institution when AI is used in policymaking and decision-making, and to designate an officer responsible for AI and data-based administration. Institutions must also manage the types and purposes of AI services they provide and the data used, and submit this information to the Ministry of the Interior and Safety so the government can compile an annual service inventory. Public institutions are also required to provide AI training for personnel, ensure appropriate quality of training data, and establish AI-use ethics standards reflecting fairness, transparency, accountability, and safety. The Enforcement Decree further specifies the dimensions of the impact assessment that will begin in 2027, including decision transparency, performance and reliability of results, bias in data and algorithms, and impacts on fundamental rights.
More important for AI suppliers to prepare for is the risk-management structure under Article 29 that has already been published but is not yet applicable. From February 28, 2027, systems subject to a public-sector AI impact assessment will require a corresponding risk-management plan covering the AI-use structure, the responsible person and a log-management plan, procedures for validating performance and safety, procedures for detecting and responding to errors, bias, and security incidents, standards for suspending or restricting operations and protecting users, and procedures for complaints, objections, and remedies. The direct statutory duty falls on public institutions, not on every ordinary enterprise supplying AI to the Korean market. But vendors providing models, agents, decision-support systems, or generative AI to governments, schools, and public institutions are likely to be asked for corresponding technical evidence during procurement and acceptance. In practice, preparation will focus on model-version and intended-use descriptions, training-data and bias testing, operational logs, incident detection, human shutdown mechanisms, and interfaces supporting objections or appeals—not merely a high-level “responsible AI policy.” This is a deployment mapping derived from the statutory evaluation and risk-management items; the current text does not prescribe a uniform logging schema, fixed retention period, or specific technical architecture.
The reform does not create a public-sector AI regime that is completely parallel to Korea’s general AI regulation. Rather, it connects the public sector to an existing national AI governance framework. The legislation originally centered on “data-based administration.” Only after the February 27, 2026 amendment did AI formally enter the law’s title, definitions, allocation of responsibilities, and public-service framework, with most of the new provisions scheduled to take effect on August 28. At the same time, Korea’s Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trustworthiness (provisional translation; 인공지능 발전과 신뢰 기반 조성 등에 관한 기본법) took effect on January 22, 2026 and imposes general requirements on operators of high-impact AI around risk management, explanation, human oversight, and documentation. The two regimes are also linked: if a system that a public institution plans to adopt has already undergone a high-impact AI impact assessment under the AI Framework Act, the public-sector impact assessment may be waived after consultation with the Minister of the Interior and Safety. The resulting structure is therefore “general-market AI rules + additional public-sector governance”, not two fully duplicative assessment systems. For enterprises serving Korea’s public sector, the practical task is to identify what evidence the same system must provide under the general high-impact AI rules and what additional evidence is required in a public-procurement context.
On August 26, 2026, Singapore’s Ministry of Law (MinLaw) and Intellectual Property Office of Singapore (IPOS) jointly launched the Public Consultation on Artificial Intelligence and Singapore’s Intellectual Property Regime, with submissions open until 5:00 p.m. on October 22, 2026. The consultation examines the impact of generative AI on copyright and patent law. The copyright section covers infringement risks in AI training, deployment, and use, as well as the role of human creativity in AI-assisted works; the patent section addresses inventorship in AI-assisted inventions and how AI-generated technical disclosures may affect the prior-art landscape.
The document remains at the public consultation stage and did not create new mandatory AI copyright or patent obligations on August 26. The government is currently considering whether legal refinements, practical information resources, or non-legally binding technical measures may be needed. The most important structural feature of the copyright section is that it separates the model’s “input side” from its “output side.” On the training side, the consultation focuses on the computational data analysis exception (CDA exception) under Singapore’s Copyright Act 2021, asking whether its scope and application to generative AI are sufficiently clear, what constitutes lawful access, and how rights-holder safeguards and industry-led technical mechanisms should operate. On the deployment side, the consultation turns to responsibility where AI-generated output infringes copyright, directly asking how existing copyright-liability principles should apply among developers, deployers, and end users, and what technical measures can reduce output-infringement risk. It also separately discusses the extent to which human activities such as prompting, selection, and modification may demonstrate copyrightable human creativity in AI-assisted works.
For enterprises, the key point is that “permission to train” and “liability for outputs” cannot be addressed through the same copyright analysis. Singapore’s current computational data analysis regime permits reproduction of works for computational analysis when statutory conditions are met, and the law treats use of works to train computer programs as a typical example. One important condition is lawful access to the source material: content obtained by circumventing a paywall or breaching database terms of use may fail to satisfy that condition. But once a model is deployed in a product, if a chatbot, retrieval-augmented generation (RAG) system, or content-generation tool reproduces protected works, the training-stage CDA exception does not automatically cover the output. Existing IPOS materials already distinguish these two stages. Enterprises therefore need at least two separate governance workflows: when training or fine-tuning a model, record data sources, access methods, licences, and use restrictions; when deploying a third-party model, confirm how the supplier manages memorized or near-verbatim outputs and establish application-level output detection, human review, complaints handling, and takedown mechanisms. “The model was trained by the supplier” does not automatically resolve output-side copyright risk for the deployer, particularly where the enterprise changes actual generated content through RAG, system prompts, or a private knowledge base. This last point is an enterprise deployment analysis based on the consultation questions and should not be read as a final allocation of liability already determined by the Singapore government.
The consultation does not reopen a single binary question of “can copyrighted works be used to train AI?” Instead, it addresses boundaries that remain once Singapore’s computational data analysis exception is applied to generative AI. Sections 243-244 of the Copyright Act 2021 already establish a dedicated computational data analysis exception and place machine-learning-style training within its structure. The current consultation shifts attention toward lawful access, technical safeguards for rights holders, and infringement liability after models are put into use. This creates a concrete policy tension: if the training side retains a relatively clear statutory space for use while the output side continues to depend on existing infringement principles applied case by case, copyright risk changes over the AI product lifecycle. Training-data compliance cannot substitute for content controls after deployment, and safeguards implemented by developers cannot fully replace the management responsibilities of deployers and users in specific business scenarios. The Singapore government is therefore also consulting on whether it should support machine-readable and other non-legally binding technical measures to improve rights-holder protection and on how output-infringement risk can be reduced in a “proportionate and commercially viable” way. For enterprises deploying AI across regions, the issue to monitor after the consultation is not “whether Singapore will prohibit AI training,” but whether the interpretive boundaries of the existing CDA exception are further clarified and whether the responsibility chain among developers, deployers, and users is translated into more concrete law, guidance, or technical standards.
On August 27, 2026, China’s Standardization Administration released a group of national standardization guidance documents for artificial intelligence, including GB/Z 242-2026 Artificial Intelligence—Technical Requirements for Intelligent Agents, GB/Z 253-2026 Artificial Intelligence—General Technical Requirements for Retrieval-Augmented Generation, GB/Z 254-2026 Artificial Intelligence—Technical Requirements for Toolchains for Cloud-Based Inference Deployment of Large Language Models, and GB/Z 236-2026 Artificial Intelligence—Evaluation Indicators and Methods for Retrieval-Augmented Generation Systems. These documents fall under the National Information Technology Standardization Technical Committee (TC28), are implemented by its Artificial Intelligence Subcommittee, and entered into current status on the date of publication. GB/T 48110-2026 Artificial Intelligence—Technical Requirements for Open-Source Model Platforms was issued on August 28, 2026, with implementation scheduled for December 1, 2026. The event is therefore more accurately described as a cluster of foundational AI technical standards issued across August 27-28.
The defining feature of this group is not the creation of a new regulatory approval regime for a specific model, but the establishment of a common technical language for different components of the enterprise AI stack. Agents, retrieval-augmented generation (RAG), and cloud-based inference deployment each receive separate technical requirements, while RAG also has a dedicated evaluation-indicators-and-methods standard. GB/Z 244-2026 Artificial Intelligence—Guidelines for the Construction of Office Large Model Systems and GB/Z 246-2026 Artificial Intelligence—General Technical Requirements for Computing Power Platforms, issued on the same day, extend the standardization scope to specific application systems and foundational compute platforms. The open-source model platform standard issued on August 28 further covers platform management, open-source dataset management, open-source model management, contributor services, and developer services. The official standards plan states that it applies to the planning, construction, operation, and maintenance of open-source model service platforms.
These documents should not be described as directly creating new enterprise compliance obligations for agents or RAG. GB/Z documents are national standardization guidance technical documents, while GB/T 48110-2026 is a recommended national standard. Under China’s Standardization Law, recommended standards are generally adopted voluntarily, and GB/Z documents are likewise distinct from mandatory national standards. Standards may become more concrete constraints where they are incorporated by laws or regulations, expressly adopted by an enterprise, or written into procurement contracts and project-acceptance documentation. For enterprise deployment, their more immediate role will therefore appear in technology selection and acceptance. When building an enterprise knowledge-base Q&A system, organizations can use the RAG technical requirements and evaluation standards to harmonize supplier system descriptions and testing criteria; when procuring agent products, they can use the national standard as a reference for capability testing and technical acceptance; when deploying large models in the cloud, the toolchain standard can help compare deployment support across platforms; and when using open-source model platforms, enterprises can bring management capabilities for models, datasets, contributors, and developer services into platform due diligence. The practical value of the standards is first to convert “every vendor describes AI differently” into a shared technical baseline for tendering, testing, and acceptance—not to replace data-security, algorithm-governance, or generative-AI service regulation.
This is also not China’s first move to standardize agents and large models. In May 2026, GB/Z 185.1-2026 Artificial Intelligence—Agent Interconnection—Part 1: General Architecture and related agent-interconnection standards had already been issued, addressing system architecture, identity, and interconnection among agents. On August 1, 2026, the recommended electronics-industry standard SJ/T 12121-2026 Key Technologies of Artificial Intelligence—Intelligent Agent—Technical Specification took effect. By August 27, the national level had added a neighboring cluster of standards covering agents themselves, RAG, inference toolchains, computing platforms, and office large models. Compared with the EU’s use of the AI Act to impose legal obligations by provider, deployer, and risk category, these Chinese documents currently follow more of a technical standardization pathway: first standardize how systems are described, built, and evaluated, and then allow procurement, certification, sector regulation, or enterprise self-declaration to determine which standards become binding in specific projects. For enterprises deploying across regions, “China has national standards” and “the EU has the AI Act” should therefore not be compared at the same level of legal effect. A more useful approach is to maintain one matrix for “statutory obligations” and another for “technical standards/procurement baselines,” then identify which standards have entered actual project requirements through contracts, tenders, or other mechanisms.
Cite as · AI Governance Weekly · 3 September 2026
If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.