Japan's IP Strategy Headquarters study group has published a post-consultation revision of its comply-or-explain Principle Code on generative AI transparency and intellectual property

Japan Revises Generative AI IP Principle Code Draft. The Leveraged Years regulation briefing card.

The draft says outright that it is not a norm with legal binding force. It then asks generative AI businesses to publish their crawler identifiers, answer rights holders about specific URLs in training data, and explain in public every principle they decline to follow.

The short version

Bottom line: Not binding. The document states in terms that it is not a norm with legal binding force and does not compel disclosure of sensitive information. It operates by comply-or-explain, and it is still a draft carrying a provisional title.

Who this affects: IP litigators and in-house IP counsel advising generative AI developers, model providers and platform operators serving the Japanese market, plus rights holder organisations in publishing, music, film, manga, anime and games.

Issue date: 18 August 2026, circulated as document 1 to the 13th meeting of the study group, held 10:00 to 12:00. No adoption date or acceptance deadline is stated in the draft.

What changed: This version is expressly the public comment draft as amended. It sets out three principles, a scope section with worked examples of who falls outside it, and rules on what does not count as a valid explanation.

Analysis: The extraterritorial clause is the part with reach. A business with no head office or principal office in Japan is within scope if its system or service is provided toward Japan, and the draft says that includes but is not limited to being usable by Japanese nationals.

Primary sources: 13th meeting agenda and materials, Cabinet Secretariat · Document 1: revised draft Principle Code (PDF, Japanese) · Reference 1: worked examples of the disclosure items (PDF, Japanese)

Instrument (EN)
Principle Code on the protection of intellectual property and transparency for the appropriate use of generative AI (provisional title), draft
Authority
Study Group on Intellectual Property Rights in the AI Era, Intellectual Property Strategy Headquarters, Cabinet Secretariat and Cabinet Office
Jurisdiction
Japan, with express application to overseas businesses serving Japan
Status
Draft revised following public comment, circulated to the 13th meeting
Bindingness
None. Comply-or-explain, expressly described as not a norm with legal binding force
Stated policy basis
Act on Promotion of Research, Development and Utilisation of AI-Related Technologies, Act No. 53 of 2025
Issue date / next deadline
18 August 2026 / no deadline stated
Registry
Accepting businesses are asked to publish and notify the Cabinet Office IP Strategy Promotion Secretariat, which publishes a list and links but does not review content
Primary source
https://www.cas.go.jp/jp/seisakukaigi/titeki2/ai_kentoukai/gijisidai/dai13/index.html

The method is borrowed from corporate governance

The draft says its approach is modelled on stewardship code practice in the corporate governance field: comply or explain. A business that considers a principle inappropriate for its circumstances may decline to implement it, provided it explains the reason sufficiently.

It goes further than the usual formulation on two points. Stating that you have not built the capability to implement Principle 2 or Principle 3 is expressly insufficient as an explanation; the business must, taking its scale into account, say when that capability will be in place. And pointing to an override clause in a contract or terms of use is also insufficient; the business must explain why the clause exists.

Visibility is handled through a register. Accepting businesses are asked to publish their acceptance and their per-principle implementation or explanation on their corporate site, notify the Cabinet Office IP Strategy Promotion Secretariat in a prescribed form, and review the content at least annually. The Secretariat publishes the list and links, but expressly does not examine what is filed and does not answer third-party enquiries about it.

Principle 1: what goes on the corporate website

The first principle asks for a public summary disclosure, readable by anyone, covering both transparency and intellectual property measures.

On transparency: model name, identifier and version; provenance including past versions and revision history; architecture and design specification, including third-party licence arrangements; usage rules identifying intended and prohibited uses; and the content of the training process. On training data: the types of data used for training and validation, including data used in retrieval augmented generation, non-public datasets obtained by web crawl or from third parties, public datasets, and whether and why synthetic data was used. On crawlers: purpose, collection period, name and identifier, and whether third-party crawlers were used and which.

On intellectual property the list is operational rather than declaratory. Adopt an IP protection policy with a clear responsibility structure, review it at least annually and publish a summary. Respect access restrictions such as paywalls and machine-readable instructions such as robots.txt, publish the measures applied per user agent, and give notice when they change. Retain training logs for a period. Work to avoid crawling pirate sites. Take technical measures against infringing outputs where possible, and apply provenance techniques such as watermarking or C2PA where possible. Tell users not to use outputs they believe infringe. Maintain a contact point for rights holders, make the requirements for a request as clear as possible, and keep records of how requests were handled.

Principles 2 and 3: a private disclosure channel

The second principle addresses rights holders. Where someone is actually bringing or preparing litigation, mediation or ADR over works such as film, music, theatre, literature, photography, manga, animation or computer games, or their instructed lawyer or legal representative, they may ask whether specified URLs are contained in the training or validation data, and the business answers. The URLs must be ones the business can readily access and check, and the draft says in a footnote that the channel is not meant for asking whether a particular work of your own was itself crawled.

Three conditions attach. The requester must show why they qualify, must state the purpose of the answer and undertake not to use it for anything else, and must identify the reference material and the specific reason for asking about it. Where a provider cannot answer, it names the developer of the model embedded in the service.

The third principle gives a narrower version of the same channel to someone who generated an output and then found matching content online. Here the requester must supply both the output and the prompt used to produce it, and must undertake not to use the answer for litigation, mediation or ADR. That last condition is the design decision worth noticing: the generator route is deliberately not a litigation route.

Who is outside the scope

The scope section is unusually specific about exclusions, and works through lettered examples. Subcontractors who take on only part of a build, such as data collection, preprocessing or model training, and deliver it to a developer, are not themselves developers. Nor is anyone who develops without providing to the public.

Systems built on data from a single company or a defined corporate group, and supplied only to that data provider or a limited designated circle, fall outside both definitions. So does a business whose system very rarely produces anything capable of infringing, with two examples given: outputs from which the creative expression of an existing work cannot be directly perceived, and outputs that amount only to statistical data or inference results supporting a decision.

Industry-specific systems are treated differently. A licensee that adds an industry layer on top of a general-purpose model is a covered business, but only for the part it added; compliance for the underlying general-purpose model is expected from the original developer.

What this is not

The draft is not a source of any enforceable right, and it does not require disclosure of trade secrets or of safety and security information, and it does not require disclosure of trade secrets or of safety and security information. It states that it places no limit on separate legal procedures, and it points readers to the existing tools: party enquiries under Article 163 of the Code of Civil Procedure and applications for a document production order under Article 221.

It also asks for restraint from the other side. The commentary states that a business should not be criticised outright merely because it declines to disclose part of the summary items, and that all parties should work towards orderly dialogue.

A closing provision keeps the document open. Taking into account how businesses respond, operational effectiveness and international developments, the document may be amended where necessary.

What we did not verify

We opened the 13th meeting agenda page and read the full 14-page draft Principle Code circulated as document 1, in Japanese, and confirmed the meeting date of 18 August 2026 on the agenda itself. English renderings of the draft in this article are our own translation of the Japanese text.

We did not open reference document 1, the worked examples of the summary disclosure items, or reference document 2, the extract from the Intellectual Property Promotion Plan 2026. We did not read the public comment version to diff it against this revision, so we cannot say which specific paragraphs changed. We did not read Act No. 53 of 2025.

We make no claim that the Code has been adopted, that any business has accepted it, that the notification form exists yet, or that failing to follow a principle carries any legal consequence in Japan. No official English text of this draft was located.

Key compliance takeaway

The disclosure list in Principle 1 is the part to act on, because most of it is verifiable from outside your organisation. Crawler user agents, robots.txt handling and a published rights holder contact point are all things a claimant can check before filing anything. If your model is reachable from Japan, the extraterritorial clause means the question of whether you are in scope is not answered by where you are incorporated.

Source File

https://www.cas.go.jp/jp/seisakukaigi/titeki2/ai_kentoukai/gijisidai/dai13/index.html

Open the 13th meeting agenda page at cas.go.jp and confirm the date line reading Reiwa 8, 18 August, then open document 1 and confirm three things: section 1(3) stating the document is not a norm with legal binding force, the crawler and robots.txt items in the intellectual property list under Principle 1, and the requirement in Principle 3 that a requester supply the prompt used to generate the output.

This document does not require generative AI businesses to disclose sensitive information belonging to them, being trade secrets and matters relating to safety and security, and it is not a norm having legal binding force. ยท Draft Principle Code, section 1(3), 18 August 2026, TLY translation from the Japanese

FAQ

Is the Principle Code binding on generative AI developers in Japan?

No. The draft states it is not a norm with legal binding force. It asks businesses that accept it to comply with each principle or publicly explain why they do not.

Does it apply to a company with no presence in Japan?

On the draft's own terms, yes, if the generative AI system or service is provided toward Japan. The text says this includes, but is not limited to, cases where it can be used by Japanese nationals.

What can a rights holder actually ask for?

Under Principle 2, whether specified URLs are included in the training or validation data, and where a provider cannot answer, the name of the developer of the underlying model. The requester must be pursuing or preparing legal proceedings and must specify the reason for the request.

Is saying we have not built the capability a valid explanation?

The draft says no. It treats that as insufficient, and asks the business to state when the capability will be in place, taking its own scale into account.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}