The 'Responsibility Gap' Left in AI Policy: Decoding Agile Governance and the Time Lag in Redress from Government AI Meetings
The social implementation of generative AI is progressing at an unprecedented speed.
The Japanese government has set a policy to become the 'world's most AI-friendly country for development and utilization' and is actively investing budget into this goal.
To avoid hindering innovation, Japan's AI policy has chosen agile governance centered on soft law, such as guidelines and principles, while minimizing strict legal regulations (hard law).
As a result, institutional design is being advanced with an emphasis on 'flexibility'.
It is also described as a Japanese-style model where 'we first respond with existing laws and supplement the parts that cannot be covered with new frameworks'.
However, while reading government meeting materials and minutes, something was bothering me.
How is responsibility positioned, and can victim redress be agile?
In this article, I will first organize the policy review process based on published minutes and policy materials to see how discussions on AI institutional design have been built up. Next, considering the reality of damages, I will think about the time lag between agile governance and victim redress.
1. AI Strategy Council and AI System Study Group
Discussions on institutional design surrounding generative AI have been centered on the Cabinet Office's AI Strategy Council and the AI System Study Group since May 2023.
These deliberations involve not only the administration but also university researchers, relevant associations, companies (such as NEC and Sakura Internet), and lawyers supporting these companies as members, with the balance between innovation and addressing technical risks treated as a central theme.
In addition, direct hearings have been conducted with companies involved in AI research, development, and social implementation (such as ABEJA, Preferred Networks, Benesse Corporation, NTT, Yamato Transport, Google Asia Pacific, and Facebook Japan).
2. Flow of Deliberations in Government Meetings: Organizing Responses via Existing Laws
(1) AI Strategy Council (2nd and 9th meetings): Premises of deliberation and confirmation of existing systems
At the 2nd AI Strategy Council (May 26, 2023), discussions were held on the utilization of AI and responses to risks while organizing the relationship with existing legal systems.
Subsequently, in the materials for the 9th meeting (May 22, 2024), existing systems such as the Civil Code, Penal Code, Copyright Act, Act on the Protection of Personal Information, and the Provider Liability Limitation Act (currently the Information Distribution Platform Countermeasures Act) were cited as responses to problems caused by AI.
First, the institutional basic stance in Japan's AI policy was demonstrated, which is to confirm the applicability of these systems.
(2) AI System Study Group (2nd to 5th meetings): Application to individual fields and combinations
This direction can also be confirmed in the discussions of the AI System Study Group established in August 2024.
At the 2nd AI System Study Group (August 23, 2024), it was recorded that as long as AI use is incorporated into corporate activities, it is important to respond using existing laws according to business characteristics.
At the following 3rd meeting (September 10, 2024), the opinion was expressed that instead of immediately establishing comprehensive AI regulations, individual field regulations, soft law, and existing laws should be combined.
Furthermore, at the 4th meeting (September 12, 2024), the view emerged that existing laws could handle certain new AI risks, and at the 5th meeting (December 26, 2024), it was organized that foundational services such as medical devices, autonomous driving, and critical infrastructure should be addressed under existing laws and guideline frameworks.
(3) Joint Meetings and the 'Interim Summary': Clarifying the Japanese Model
At the joint meeting of the AI Strategy Council (11th) and the AI System Study Group (1st) on August 2, 2024, the dual goals of promoting innovation and ensuring AI safety and risk management were identified as key policy issues.
Here, too, the premise is the idea of considering responses based on existing systems rather than immediately introducing new comprehensive regulations.
From these discussions, the 'Interim Summary' decided in February 2025 was reached, which explicitly stated that responses to personal information, copyright, and false or misleading information are premised on the use of existing laws.
(4) Minority Opinions and Corporate Views
During the course of the meetings, some committee members and others repeatedly raised issues concerning victim redress and accountability.
For example, from the perspective of consumer protection, voices have been raised pointing out that 'many consultations are being received regarding investment fraud in SNS advertisements using AI and purchases made without realizing a site was fake,' and that 'legal regulations and redress measures for fraudulent activities are necessary,' and 'strict legal regulations are needed for fraudulent consumer troubles, prioritizing consumer interests.'
Regarding misinformation and social disruption, the seriousness of the situation where 'everyone has gained the power to disrupt society' was pointed out, and opinions were expressed that 'it is necessary to promote active measures and implementation, such as platform operators developing verification technology and labeling content.'
Furthermore, mentioning the risk of AI evaluating and screening people in corporate recruitment activities, a warning was issued that 'there is a strong opinion, especially in Europe, that evaluating people by machines is contrary to human dignity, and how accuracy is guaranteed becomes a point of discussion.'
In addition, at the 4th AI System Study Group, external expert Professor Osamu Sudo of Chuo University's Faculty of Global Informatics pointed out that 'clear responsibility provisions for damage caused by AI are necessary,' and also noted the need for detailed responsibility settings according to the AI lifecycle (developers, implementers, users, etc.) and industry-specific guidelines.
On the other hand, opinions from a business perspective have been raised one after another by companies.
First, as a strong concern, voices were raised such as 'regulation of large-scale generative AI will also hinder innovation,' 'excessive regulation itself is a risk, and it is a problem to be able to design only within constraints,' and 'AI development should not be hindered based only on vague anxiety or speculation.'
Furthermore, regarding the necessity of new regulations, the recognition that it can be handled by current laws was shown, with comments such as 'since AI utilization is embedded in business activities, it is important to respond to existing laws according to business characteristics,' 'there are no specific examples that cannot be followed by existing legal systems, and I do not recognize it as a social problem,' and 'I think existing laws can handle new AI risks. If there is enforcement power, there is no need to increase exceptions.'
As for future approaches, the majority of opinions sought flexible responses centered on soft law, such as 'a whitelist type with a preventive aspect has high concerns of becoming excessive regulation, so legal regulation should be a blacklist type based on cases,' 'it is best to use individual regulations for individual fields and a combination of soft law and existing laws, rather than AI regulation,' and 'now is the stage for the public and private sectors to work together to respond based on guidelines and create best practices.'
Committee members also widely supported the approach of first applying and enforcing existing laws (individual laws) and supplementing the missing parts.
From this, it can be evaluated that the final direction of the interim summary settled on the modest expression that 'the government will develop guidelines and encourage voluntary responses by businesses.'
(5) Reflection in the AI Act and the Artificial Intelligence Basic Plan
The discussions organized in these meetings are reflected in policy documents such as the 'Act on the Promotion of Research and Development and Utilization of Artificial Intelligence-Related Technologies' (AI Act) enacted in May 2025, the 'Guidelines for Ensuring the Appropriateness of Research and Development and Utilization of Artificial Intelligence-Related Technologies' of December of the same year, and the 'Artificial Intelligence Basic Plan.'
The AI Act has no penalties and remained a framework that encourages 'compliance with guidelines' by businesses.
Furthermore, even in the latest Basic Plan for Artificial Intelligence decided by the Cabinet in December 2025, the issue of civil liability—specifically who should be held responsible—remained limited to a future-oriented statement that 'the nature and scope of civil liability in cases of accidents or damages arising from the use of AI will be examined'.
3. The Reality of Damage Caused by Generative AI
Here, I will organize the recent damage caused by generative AI in Japan based on public materials from the National Police Agency's Cyber Police Bureau and the Financial Services Agency, as well as media reports.
First, 2024 was characterized by the fact that the misuse of generative AI emerged as actual criminal cases.
In May 2024, the Metropolitan Police Department arrested a suspect on charges of creating a malicious program with file-destruction capabilities using generative AI in March 2023 (violation of the Act on Prohibition of Unauthorized Computer Access). It became clear that the misuse of generative AI is not an abstract risk, but a real problem being prosecuted within Japan.
Cases of forging identity verification documents and generating obscene images using generative AI were also confirmed, and the damage began to be recognized as a complex issue extending beyond cybercrime.
By 2025, the concrete picture of the damage expanded rapidly.
In particular, the Mainichi Shimbun reported extensively that sexual deepfakes were spreading rapidly due to the ease of generation and dissemination, and that the damage was reaching not only celebrities but also ordinary women and children through the misuse of school event photos and graduation albums.
In April of the same year, a case was reported where obscene posters created with generative AI were sold on an auction site, marking the first such prosecution in the country, and cases are now emerging that are treated as criminal matters beyond mere issues of expression.
Additionally, generative AI has made it easy to create sophisticated phishing emails and impersonations; as natural-sounding Japanese emails and fake websites become more advanced, financial damage that is harder to detect than before has become a problem, and cases of suspect arrests have been confirmed.
In 2026, such damage has been more clearly positioned within statistics and crime victim policy discussions.
According to the National Police Agency, consultations regarding sexual deepfakes reached over 100 in 2024, and it was reported that they were on an upward trend in 2025 as well.
Furthermore, in February 2026, the National Police Agency released statistics stating that 'among consultations and reports of sexual deepfake damage using images of persons under 18, approximately 60% of cases involved classmates or students from the same school as the perpetrator'.
Sexual deepfakes are discussed as an infringement on personality rights and sexual dignity, and regarding child victims, it is becoming recognized as a problem that occurs within familiar relationships, such as cases where the perpetrator is a member of the same school community.
The spread of image manipulation via generative AI on social media has also drawn attention, and the damage is expanding beyond the act of generation to include issues involving distribution and re-dissemination on platforms.
In this way, it can be said that generative AI damage in Japan has materialized in three areas: malicious program creation, phishing/impersonation, and sexual deepfakes, evolving from initial prosecutions in 2024 to the expansion of damage in 2025, and the visualization of child victimization and diffusion structures in 2026.
4. Challenges for Responsibility Design
With the damage already becoming a reality, the issue of responsibility is not a future challenge, but a currently ongoing institutional issue.
In advanced technology fields such as nuclear power generation and space development, responsibility was considered from the institutional design stage before accidents occurred. The difference between generative AI and these fields is that at the time of AI institutional design, victims already exist and continue to be generated.
Ultimately, the issue of 'who takes responsibility and how, and how to provide relief to victims' in the AI field has become a structure on a separate track from the core of AI policy handled by the Cabinet Office.
At the Ministry of Economy, Trade and Industry, a separate 'Study Group on the Nature of Civil Liability in AI Utilization' was established in August 2025, and discussions have continued into 2026. Currently, public comments are being accepted for the 'Draft Guidelines on the Interpretation and Application of Civil Liability in AI Utilization' (deadline: March 19, 2026).
However, the purpose of this study group is limited to providing interpretive guidelines without changing existing concepts such as negligence or causality in civil law.
The response through existing laws is a framework that is fundamentally premised on ex-post dispute resolution and the determination of individual liability.
The time lag that arises between the 'speed of promotion' and the 'delay in redress'.
Given the overwhelming information gap (information asymmetry) between generative AI-related companies and the general public, claiming that current laws are sufficient could result in requiring the victimized public to prove the internal structure or algorithmic flaws of the AI.
In particular, compared to conventional AI, generative AI has a more advanced black-box internal structure, and the structure that makes it extremely difficult for victims to prove the cause or the responsible party is a challenge that conventional systems did not anticipate.
I believe that for Japan, in the social implementation of generative AI, designing an agile responsibility framework that reduces the burden of proof on victims and the time lag in redress, while remaining compatible with innovation, and presenting a harmonious and highly reliable institutional model to the world, could lead to Japan's strength in international rule-making.
