AI Regulation Tracker / Guidance and supervisory reports
Hong Kong's Privacy Commissioner Checks 60 Organisations on AI, Finds No Breach and Sets Agentic-AI Expectations
On May 19, 2026, Hong Kong's Office of the Privacy Commissioner for Personal Data (PCPD) published the results of a new round of compliance checks covering 60 organisations. It found that 57 of them, or 95 percent, now use AI in day-to-day operations, that about 42 percent process personal data through AI, and that no organisation contravened the Personal Data (Privacy) Ordinance. The report also set out how organisations should handle agentic AI. This is a supervisory report and guidance, not a new binding code.
One point up front, because it is easy to conflate. This is the PCPD's compliance-check report on AI and personal data, published on May 19, 2026. It is a different piece of work from the PCPD's AI regulatory sandbox. The sandbox is a supervised testing arrangement. This report is a supervisory sweep of how 60 organisations already use AI in the field. Keep them separate when you cite either one.
What the sweep found
The PCPD launched this round in January 2026, following rounds completed in 2024 and 2025, and it widened the net to include accounting, food and beverage, innovation and technology, logistics, and property management alongside the sectors it had covered before. Of the 60 organisations, 57, or 95 percent, use AI in day-to-day operations, which the regulator noted is up 15 percentage points from the 2025 round. About 79 percent had been using AI for over a year, and roughly 51 percent ran three or more AI systems. AI has moved from pilot to plumbing in this sample.
On personal data specifically, 24 of the 57 AI-using organisations, about 42 percent, collect or use personal data through AI systems, mostly in banking and finance, education, government, insurance, medical services, and similar sectors. Every one of those organisations provided a Personal Information Collection Statement before collecting, and all of them put security measures in place such as access control, encryption, penetration testing, and anonymisation. The headline compliance result is the important one. The PCPD completed the checks and identified no contravention of the PDPO during the process.
Why no breach is not the whole story
A clean result invites a shrug, and that would be a mistake. Read the report as a regulator taking careful measurements before it decides how hard to press. The Privacy Commissioner, Ms Ada C Hung Lai-ling, framed the finding around AI being integrated at an accelerating pace across sectors, which is exactly the setup a supervisor uses to justify sharper expectations later. The interesting content is in what the PCPD now asks organisations to do, not in the absence of a fine this year.
The report presses on governance basics that many organisations still treat as optional. It asks for an overall AI strategy and an internal governance structure, training for relevant staff, an AI incident response plan, internal policies covering employee use of generative AI and AI agents, documented risk and privacy impact assessments scaled to the risk level, regular internal audits, and active communication with stakeholders. None of that is new law. All of it is the kind of expectation a regulator later points to when a breach does happen.
The agentic-AI language is the signal
The part I would not skip is the guidance on agentic AI, because it is where the PCPD is clearly looking ahead. Where organisations use agentic AI to collect, use, or process personal data, the report says they should consider the nature and sensitivity of the data and grant the agent only the minimum access rights necessary to perform the task. It goes further and tells organisations to download the latest version of agentic AI from official channels, to be cautious when installing and using plugins or skills, to keep system and data security tight, and to keep assessing the risks.
That is a least-privilege posture applied to autonomous software, and it maps neatly onto controls a security-minded professional already understands. An AI agent that can act on your systems is a new kind of privileged account. Scope it narrowly, source it carefully, and watch what its plugins can reach. The PCPD is putting that expectation in writing before agents are everywhere, which is the useful early warning for anyone who will deploy them.
Why this reaches US practice
The PDPO governs Hong Kong, and this report binds no one in the United States. It reaches US professionals in two ways. If your organisation operates in Hong Kong or serves Hong Kong customers through AI that touches personal data, this is a direct read on what the regulator now expects, and the Model Framework and Generative AI Checklist are the yardsticks it is using. More broadly, the agentic-AI guidance is a clean statement of a control set that will show up in many jurisdictions. Least privilege for agents, trusted sourcing, plugin caution, and continuous risk assessment are portable disciplines. You do not need Hong Kong law to apply them, and building them now is cheaper than retrofitting them after an incident.
Questions professionals are asking
Is this the same as the PCPD AI sandbox?
No. This is the PCPD's compliance-check report on how 60 organisations use AI with personal data, published May 19, 2026. The AI regulatory sandbox is a separate, supervised testing arrangement. They are distinct pieces of work and should be cited separately.
Did any organisation break the law?
No. The PCPD completed the checks and identified no contravention of the Personal Data (Privacy) Ordinance during the process. The report is a supervisory sweep and guidance rather than an enforcement action, so it does not impose new legal obligations.
What does the PCPD say about agentic AI?
Where organisations use agentic AI to collect, use, or process personal data, the report says they should grant the agent only the minimum access rights necessary, download the latest version from official channels, be cautious with plugins or skills, maintain system and data security, and keep assessing the risks. It is a least-privilege posture for autonomous software.
Does this affect organisations outside Hong Kong?
Not as binding law. The PDPO governs Hong Kong. For others it is a benchmark. If you serve Hong Kong through AI that touches personal data, it shows current expectations, and the agentic-AI controls are portable disciplines worth adopting anywhere.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any report, statute, or requirement applies to your situation with qualified professionals in the relevant jurisdiction.