AI Governance
We build governance frameworks to manage the risks that come with using AI — copyright infringement, inappropriate input or leakage of personal and confidential information, erroneous output, bias — from AI usage guidelines through to training and monitoring.
Coverage Areas (Examples)
AI governance requires attention to many dimensions. We provide comprehensive support from regulatory compliance to internal framework development.
AI Risk Assessment
We assess and manage AI risks — hallucination, bias, vendor exposure — designing controls that keep risk manageable while preserving the business value of AI.
Examples: AI usage risk assessment / Hallucination & error output risk management / Detecting and correcting bias & discriminatory output / Third-party AI vendor risk evaluation
Internal Policy & Rules
We design internal AI rules — usage guidelines, approval flows — concrete enough for employees to use AI with confidence, because rules that do not fit how the work is actually done tend to stop being followed.
Examples: Generative AI usage guidelines / Prohibited uses, permitted scope & procedures / Data input / output handling rules / AI usage request & approval procedure
Regulatory Compliance
We support compliance with the laws that AI use engages — personal data protection, copyright, and sector-specific rules — tracking how the regulations and guidelines develop and translating that into concrete action for your business.
Examples: Personal data protection & privacy / Copyright & IP risk management / Sector-specific regulations (finance, healthcare) / Overseas regulation (EU AI Act and similar)
Monitoring & Governance
We build ongoing AI governance — monitoring, incident response, review committees — designed as systems that keep running, not documents that sit still.
Examples: AI usage monitoring framework / Incident response procedures / Internal training & awareness programs / AI review committee setup
Legal Support for AI Development
We handle the legal side of AI development and procurement — contracts, training-data rights — integrated with governance design in a single engagement.
Examples: AI development & procurement contract review / Training data rights & license clearance / Terms of service & allocation of responsibility / Copyrightability, ownership & third-party infringement risk for AI output
How We Work
We offer a graduated path: executive training, a single policy or spot consultation, a package that bundles the full policy set with training, and ongoing advisory. You can start at any stage and move on to the next.
Learn first
Executive training
Leadership and back-office teams asking where to begin now that staff are already using ChatGPT
Scope
- Executive training (90 minutes, lecture format): the statutes that apply, shown in the text of the law, and the situations that typically arise once a company starts using AI, worked through with concrete examples. Delivered on a per-company basis; training alone is also available.
Fee
Training is quoted individually based on scale.
Settle one question
Spot consultation or a single policy
Companies with a concrete question or a single policy to draft
Scope
- Consultation on a specific question, with a written memo
- Drafting of one policy — usage guidelines, or whichever single document you need first
Fee
Billed on a time basis. A policy drafted here carries over as the foundation if you later move to the package or ongoing advisory.
Get the full set
Generative AI Governance Package
Mid-sized companies and IT firms that want usage assessment, rules, structure, and training in one engagement
Scope
- Usage assessment and risk mapping (industry- and usage-specific risk evaluation, vendor review of AI services in use)
- The full policy set: a core policy, plus usage guidelines, data handling standards, a request-and-approval process, and incident response procedures
- One 90-minute executive training session (lecture format); training for general staff or for developers can be added as an option
- Work plan and deliverables list, provided at kickoff
Fee
The package is undertaken for a fixed fee, confirmed at kickoff based on the scale of AI use and sector regulation. Typical duration is about two months.
Keep it running
AI & Systems Legal Advisory
Companies operating the rules they have built, and IT firms with a steady flow of AI contracts and product questions. If you already have your policies in place, you can engage us here directly without going through the package.
Scope
- A monthly memo on the points that matter, limited to developments that affect your business
- Quarterly review of regulatory developments (personal data protection, copyright, the AI Business Operator Guidelines, the EU AI Act)
- Annual revision of the policy set
- Review of AI-related contracts (development, procurement, terms of service, data provision)
Fee
Billed as a fixed monthly retainer.
Our Strengths
Practitioners with Hands-On AI Experience
Attorneys and CPAs with hands-on AI and data science experience design governance that reflects technical realities — not theoretical frameworks that fail in practice.
Keeping Pace with Rules and Guidelines
We track the fast-moving landscape of AI regulation, centred on the ministry guidelines and the government AI strategy in Japan, and extending to overseas rules such as the EU AI Act where they reach your business. Governance frameworks are designed so that they can be revised as the rules and the technology change.
Building Governance That Actually Works
We go beyond drafting policies—designing training, approval flows, and monitoring so that governance actually runs. We tailor every framework to your industry, scale, and AI usage patterns.
FAQ
Q. Our employees have started using ChatGPT for work. Where should we begin?
Start by establishing the facts — which departments are using it, for what — and identifying the risks. The policy decision follows, and there is more than one defensible answer: blocking access from company devices entirely, permitting only specified tools, or setting conditions by use case. What is appropriate depends on your business and the nature of the information involved. We support the full path from assessment through to the policy decision and the internal guidelines that implement it.
Q. Do we need to comply with overseas AI regulations such as the EU AI Act?
Application of the EU AI Act does not turn simply on whether you have an office or customers in the EU. What matters is whether you place an AI system or general-purpose AI model on the EU market, whether an AI system is used within the EU, and whether output generated outside the EU is used within it. Obligations also differ according to whether you act as a provider, a deployer, or in another role. We establish whether the Act applies and which role you occupy, then set out the requirements that follow — prohibited practices, high-risk AI, transparency obligations, and the rules on general-purpose AI models.
Q. Is Personal Information Protection Act compliance required for AI usage?
Where personal information is used for AI training, fine-tuning, or inference, the purpose of use, security control measures, and notice or publication to the individual all need to be considered. Where personal data is entered into an external AI service, you need to establish whether the provider handles that data, whether input is used for training, and how long and where it is retained — and from that, whether the arrangement is outsourcing, provision to a third party, or provision to a third party in a foreign country. We review the terms of service, the settings, and the data flow, and support the response that fits how the service is actually used.
Q. Can we develop our own AI governance framework in-house?
Guidelines have been published by METI, MIC, and the Cabinet Office, making a degree of in-house development possible. However, legal interpretation, industry-specific risk assessment, and keeping pace with regulatory changes are areas where specialist support is valuable. We also offer an advisory role to assist with your own internal development process.
Q. We are providing an AI-powered product or service — how should we map the legal risks?
Key areas to address include: (1) copyright, licensing, and the lawfulness of personal data processing for training and reference data; (2) quality control, human review, terms of use, and allocation of responsibility to contain erroneous output; (3) alignment with the sector legislation and supervisory guidelines that apply; and (4) potential applicability of overseas regulation such as the EU AI Act. Our attorneys, with hands-on AI development experience, work through the technical mechanism and the intended use, and put the contracts, terms of service, and internal operations in place together.
Q. We have created an AI usage policy, but how can we verify that it is actually being followed?
Establishing a post-policy monitoring framework is critical. Effective measures include collecting AI usage logs with periodic reviews, confirming how the request and approval procedure is being operated, collecting and feeding back on violation cases, and running regular training and awareness activities. We provide post-policy operational support and periodic reviews.
Get in Touch
We will listen to your concerns and propose the most suitable service. Initial contact creates no contractual obligation.
Contact Us