Part of the AI Regulation News hub.
Japan's AI Safety Institute has published a v1.0 guide setting out nine perspectives for evaluating the safety of AI robots that share physical space with people
Most AI safety guidance stops at the model. This one starts where the model meets a person in a corridor, and its most quoted line will be the disclaimer.
Bottom line: Not binding. This is a guide published by a working group of Japan's AI Safety Institute, not a regulation and not a standard. The guide says in its own text that it does not guarantee safety, legal conformity, performance or quality for any specific use or environment, and that operators must run their own risk assessment.
Who this affects: Engineering leads and product owners at robot makers, robot system integrators and component suppliers in Japan, and the AI developers and AI providers named in the METI and MIC AI Business Operator Guidelines. Deployers are addressed only indirectly.
Issue date: 23 July 2026, printed on the cover of the PDF. No deadline attaches. The document is described as a living document that will be revised as AI technology and society change.
What changed: There is now a Japanese-government-affiliated reference text for evaluating AI robots specifically, organised as three risk types, a four-factor causal frame, and nine evaluation perspectives, derived from safety experiments on two named use cases.
Analysis: The nine perspectives are the deliverable, but the scoping paragraph is the part that will date fastest. The guide deliberately limits itself to text LLMs, image recognition and speech recognition, and says vision-language-action models and robot foundation models are deferred to a later edition. That is the class of system most vendors are now selling.
Primary sources: AISI announcement page (JA) · Guide v1.0, full PDF (JA)
- Instrument (EN)
- AI Robotics Safety Evaluation Perspectives Guide, version 1.0 (working translation of the Japanese title)
- Authority
- AI Safety Institute (AISI Japan), Business Demonstration Working Group, Robotics Sub-Working Group
- Jurisdiction
- Japan; the document is published in Japanese only
- Status
- Published version 1.0; described as a living document intended for periodic revision
- Bindingness
- Non-binding guidance. The text expressly disclaims any guarantee of safety, legal conformity, performance or quality
- Issue date / next deadline
- 23 July 2026; no deadline. Companion volumes are announced but not yet published
- Scope of AI covered
- Text-based large language models, image recognition AI and speech recognition AI. Vision-language-action models and robot foundation models are named as future scope
- Companion documents
- A demonstration test report and an evaluation methods explainer are announced as separate volumes, provisionally covering a cafe transport robot, a remotely operated autonomous mobile robot, and SafeML risk analysis
- Primary source
- https://aisi.go.jp/output/output_information/260723/
Nine perspectives, and what each one is asking
Chapter 4 is the operative part. It lists nine evaluation perspectives: physical safety, operational reasonableness, stability, appropriate human intervention, privacy protection, explainability, verifiability, validity of recognition and judgment, and appropriateness of interaction.
Four of those nine have no equivalent in classical machine safety. Appropriateness of interaction and validity of recognition and judgment exist because the machine now decides things. Explainability and verifiability exist because someone will later have to reconstruct why it decided them.
The guide is candid that these perspectives were not derived from first principles. They were extracted from safety evaluation experiments run on real hardware for two use cases, and the document says so.
Three risk types, and the psychological one is not decoration
Chapter 3 sorts harm into physical, psychological and social risk, and then offers a four-factor analytical frame in which AI, the robot, the human and society each contribute. The three types are described as interacting rather than as separate buckets.
Psychological risk gets concrete treatment in the use case table. For a restaurant transport robot, the guide asks whether the ordering conversation gives the customer a sense of unease or intimidation. That is a design requirement written as a safety requirement, and it is not something an ISO 12100 hazard analysis would surface.
Physical items stay recognisable: indoor movement, passing people in corridors, obstacle avoidance, prevention of tipping and collision, and safe design for the possibility of a child approaching carelessly.
The remote delivery case is really a case about who is in charge
The second use case is an operator remotely monitoring several small delivery robots inside a test facility and on public roads, intervening as needed. The guide flags communication delay and communication loss, situational awareness support for the remote operator, and control authority management.
Then it makes the point that matters for anyone drafting a contract. Because remote operation is combined with AI autonomy, the timing of operator intervention becomes complicated, so allocation of responsibility among diverse stakeholders, transparency of the AI's decisions, log capture and explainability all become important evaluation perspectives.
That is a liability paragraph wearing an engineering hat. If you are negotiating an integration agreement for a mixed autonomous and teleoperated fleet, it is the paragraph to put in front of counsel.
Who the guide thinks it is talking to
The stated readership is the supply side: stakeholders directly involved in developing, providing and operating AI robotics. The guide maps them onto the AI developer and AI provider roles from the AI Business Operator Guidelines version 1.2 of March 2026, while conceding that robot makers, system integrators and component makers do not map one-to-one onto those roles.
AI users, in the vocabulary of those same guidelines, are not the direct audience. The guide invites them to read it anyway.
It also positions itself against the AI Robotics Strategy published in March 2026 by the inter-ministerial liaison council, which set out demand-side and supply-side thinking. This guide takes the supply half.
Read the disclaimer before you cite the guide
Section 1.3.4 closes with a sentence that limits everything above it. The guide organises general safety evaluation perspectives for AI robotics; it does not guarantee safety, legal conformity, performance or quality in any specific use or specific environment. Operators must independently carry out risk evaluation and safety confirmation in light of their own use, environment, users, applicable law, relevant standards and contract terms.
So a vendor claim of the form conforms to the AISI robotics guide carries less than it appears to. There is no conformity assessment here, no certification body, no version-locked checklist that a purchaser can audit against.
What the document does give a buyer is a vocabulary. Nine named perspectives and four named evaluation methods, being risk and safety analysis, simulation, demonstration and post-incident analysis, are enough to write a procurement questionnaire that a supplier cannot answer with a brochure.
What we did not verify
I opened the AISI announcement page and the first fourteen pages of the 49-page guide PDF itself, which is where the cover date, the scope statement, the use case table, the readership section, the disclaimer and the full chapter and section headings sit. The nine perspective names and the four evaluation method names come from the guide's own table of contents and are confirmed by chapter 4's structure.
I did not read the body text of sections 4.1.1 to 4.2.4, so I have not seen the detailed criteria under each perspective. I did not open the AI Robotics Strategy of March 2026, the AI Business Operator Guidelines version 1.2, or the AISI Guide to Evaluation Perspectives on AI Safety version 1.10. The companion volumes are announced as forthcoming and I could not open them because they do not appear to be published yet.
I will not claim what any individual perspective requires you to test, nor that the guide contains pass or fail thresholds, nor that any English translation exists. The AISI page lists a Japanese version only, and all quotation here is my own translation from the Japanese.
Treat this as a checklist source, not a compliance standard. If you build or integrate robots that move around people in Japan, the nine perspectives are a reasonable spine for an internal safety case and an excellent spine for a supplier questionnaire. But the guide disclaims legal conformity in its own text, it covers only LLMs plus image and speech recognition, and version 1.0 explicitly defers the vision-language-action systems that the market is now buying.
Source File
https://aisi.go.jp/output/output_information/260723/
Open the guide PDF and confirm three things: the cover date reads Reiwa 8, 23 July 2026; section 4.1 lists nine numbered perspectives from physical safety through appropriateness of interaction; and the final paragraph of section 1.3.4 states that the guide does not guarantee safety, legal conformity, performance or quality for a specific use or environment.
This document organises general safety evaluation perspectives concerning AI robotics, and does not guarantee safety, legal conformity, performance or quality in a specific use or a specific environment. AI Robotics Safety Evaluation Perspectives Guide v1.0, section 1.3.4, 23 July 2026, author's translation from the Japanese
FAQ
Is this guide legally binding on robot makers in Japan?
No. It is guidance from a working group of the AI Safety Institute. The guide itself states that it does not guarantee legal conformity and that operators must carry out their own risk evaluation and safety confirmation.
Which AI systems does version 1.0 actually cover?
Text-based large language models, image recognition AI and speech recognition AI, together with the recognition, judgment, dialogue, instruction understanding and route generation functions built on them. The guide names vision-language-action models and robot foundation models as scope for a later edition.
What are the two use cases it was built from?
A goods transport robot in restaurants and similar venues that also takes voice orders while moving autonomously, and a remotely operated delivery robot where one operator supervises several small robots in a test facility and on public roads.
Is there an English version?
The AISI announcement page lists a Japanese version only. Any English rendering of the title or the text, including in this article, is a translation and not an official one.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.