On August 18, 2026, the study group on intellectual property rights in the AI era, under Japan's Intellectual Property Strategy Headquarters, took up a revised version of the "Principle Code" for generative AI transparency and IP protection. The code is voluntary. It would apply to Japanese firms and to foreign providers whose systems operate in Japan, and it works on a comply-or-explain basis: a company that does not follow a principle is expected to say why. The government formally adopted the code on August 25, as Adnkronos reports.
What the code asks for
The expectations are practical. Providers should honor paywalls and robots.txt, avoid known pirate sites, keep training logs, use safeguards such as watermarking, set up contact points for rights holders, and disclose model and training-data information. The Cabinet Secretariat publishes the code text and a companion document of concrete examples. The December 2025 draft, as described by Baker McKenzie, covers developers, service providers and the businesses that support them, so responsibility is spread across the AI value chain rather than placed on one actor.
The strongest case for the code
Rights holders have a serious argument. Japan's Copyright Act permits information analysis, including model training, without prior authorization, and that flexibility is a reason many developers treat Japan as hospitable. But permissive law paired with opaque practice leaves creators unable to tell whether their work was used, whether a crawler ignored a paywall, or whom to contact. Per Baker McKenzie's review of the consultation, rights holders asked for "stronger and more meaningful transparency" and better traceability. Without some disclosure mechanism, the political pressure to reopen the copyright exception itself grows. A transparency code is a cheaper answer than amending the law.
Why the design is right
The code follows Japan's existing soft-law approach. The AI Promotion Act was enacted on March 15, 2025 and took effect on July 1, 2025. It sets principles and government support instead of penalties. The Principle Code fits that pattern, and three features are worth defending.
- It targets conduct that is already norm-violating. Respecting robots.txt, not circumventing paywalls and steering clear of known pirate sites are baseline expectations that responsible developers already meet. Codifying them costs compliant firms little and gives rights holders a benchmark.
- Comply-or-explain is proportionate. A company can depart from a principle if it explains the departure publicly. That is far lighter than the fixed obligations and penalty regimes of the EU AI Act, which the draft drew on for inspiration. It lets a small model developer or an open-source project explain a different practice instead of being shut out.
- Disclosure disciplines the market. Public statements let customers, publishers and licensing counterparties compare providers. Reputation, not fines, does the enforcing.
Where the risks are
The consultation drew more than 2,000 responses from businesses, industry groups and rights holders, according to Baker McKenzie. Industry's concerns were feasibility, confidentiality and competitiveness: detailed disclosure could expose proprietary information, and it is technically hard to identify every item in a web-scale training corpus. Those worries are legitimate. Three deserve attention as the code is put into practice.
- Voluntary can drift into de facto mandatory. If public procurement, subsidies or ministry guidance begin to require acceptance of the code, comply-or-explain becomes comply-or-lose-the-contract. The safeguard is to keep acceptance genuinely optional and to say so in official documents.
- Disclosure granularity matters. Summary-level information, such as data categories, collection periods and crawling methods, serves accountability. Item-by-item inventories would be costly, invite litigation and reveal competitive know-how without helping creators much. Regulators should define the reporting template narrowly.
- Foreign providers create an uneven field. A code covering overseas providers whose systems operate in Japan is sensible in principle. But voluntary acceptance by domestic firms alone, with foreign providers free to decline, could produce the competitive imbalance Baker McKenzie flags. Equal treatment in how explanations are judged is essential, and so is restraint in assuming that a non-accepting foreign firm is a rule-breaker.
How this compares abroad
Other jurisdictions are testing harder tools. The EU's AI Act imposes binding transparency duties on general-purpose model providers. In the United States, California's governor has issued an executive order on AI, which the Electronic Frontier Foundation has answered with a call for a thoughtful debate about actual harms. Japan's route is different: publish expectations, ask for public explanations and let practice develop before deciding whether law is needed. That sequencing is what evidence-based regulation looks like. It leaves room to tighten later if the record shows widespread non-disclosure, and it avoids locking in requirements before anyone knows what is technically feasible.
What to watch
Three tests will show whether the code works. First, the operating rules: the reporting format, the timetable and who reviews explanations. Second, uptake: whether the major domestic and foreign providers accept the code and publish meaningful statements instead of boilerplate. Third, whether the government resists using it as a backdoor requirement. If the answers are favorable, Japan will have shown that transparency and permissive training law can coexist without a licensing regime or penalty schedule. If the code hardens into item-level disclosure with implicit penalties, it will lose what makes it attractive: a light-touch standard that rights holders can rely on and developers can meet.