This page has been translated using TexTra by NICT. Please note that the translation may not be completely accurate.If you find any mistranslations, we appreciate your feedback on the "Request form for improving the automatic translation ".

First Advanced AI Utilization Advisory Board

Outline

For an overview of the Committee, please see Advanced AI Utilization Advisory Board .

Event Information

Date:
Thursday, September 18, 2025 from 10:00 a.m. to 12:00 p.m.
Location:
Office of the Prime Minister's Office - Online

Proceedings

  • 1. Opening
  • 2. Proceedings
    • 1. Operation of the Advanced AI Utilization Advisory Board
    • 2. Outline of Periodic Report on generative AI System by Each Ministry and Agency
    • 3. Trends in generative AI in Japan and other countries
    • 4. Candidate discussion points for the enhancement of the Guidelines for the Acquisition and Utilization of generative AI for the Evolution and Reform of Public Administration
  • 3) Closing

Data

Reference Documents

Summary of proceedings

At the beginning of the Advisory Board meeting, Mr. Mr. Kishi, Parliamentary Vice-Minister for Digital Transformation spoke on the significance of AI utilization in governments, Digital Agency's initiatives related to AI utilization, and the expected roles of the Advisory Board.

1. Explanation of the operation of the Advisory Board on Advanced AI Utilization

The secretariat explained the operation of the Advisory Board on Advanced AI Utilization using Documents 1 and 2, and explained that a member of Kadobayashi will be elected as the chairman, as agreed with the members beforehand.

There were no questions or opinions from the participants regarding the management.

2. Explanation of the outline of the periodic report of the generative AI system by each ministry and agency

The Secretariat made a report in Appendix 3 on the results of an analysis of the state of generative AI utilization by the various ministries and agencies.

The main questions and opinions of the attendees are as follows.

Nabatame Member: I would like to comment from the standpoint of the private sector in Thank you for the accurate analysis. There are two opinions. Regarding the first one, we understand that we have entered a phase where we can understand the overall structure in terms of the number of users and the form of use, and we can deepen our understanding of the purpose of using AI. The purpose may include improving operational efficiency and accuracy, as well as analyzing and classifying AI. We believe that the direction of the use of AI by the Japanese government will become clear. As an example introduced, the system for collecting clues to violations of laws and regulations was mentioned, and I think it is a wonderful initiative. While it was included for the purpose of improving the operational efficiency of ministry and agency employees, it is also considered to contribute to the purpose of improving the accuracy of laws and regulations observance. Therefore, we believe that we have entered a phase where we have been asked to sort out the intention of each and how it is related to national interests. As the second point, in a situation where the introduction of AI by the Japanese government is still in the early stages, we believe that it is necessary to consider whether to implement guardrails for cases where employees use it without permission.

Secretariat: We believe that the purpose of the introduction is related to how to measure the effect of the introduction. It is important to make effective the setting of goals, such as how much the information you have picked up will be found in violation cases. Regarding the use of AI by individuals, it is important to make the latest and most stable model available to the employees of all ministries and agencies, and to provide generative AI in a user-friendly form for each ministry and agency. We want to ensure that the use of AI is not the only purpose. It is essential to set goals and clarify the purpose.

Member YOSHINAGA: With regard to the LLM analysis, I believe that staff do not know which domestic models are available. When handling highly confidential data or sensitive information in the healthcare field, etc., the government considers that domestic models are necessary. In the future, it is necessary to actively provide information on domestic models that become available to each ministry and agency. My question is whether there were characteristics in the usage models of each ministry and agency.

Secretariat: , not only publishes the guidelines but also cooperates with CAIO, it is possible that information will be provided via CAIO. As for the characteristics of each ministry and agency, I will refrain here because it is no more than comparing the names of individual ministries and agencies. However, from the perspective of use cases, some ministries and agencies are limited to general-purpose utilization as a whole, and some ministries and agencies have stepped into utilization of Specialized Type 1 and Specialized Type 2, so there is a slight difference.

TORISAWA: The analytical axis shows the number of users, but since the ratio of active users / inactive users is not visible, I would like to see the frequency of use for accurate analysis. It is possible that they may refuse to provide information, but I think it will be more accurate analysis if they provide us with that information.

Secretariat: I think the number of users now corresponds to the number of people who can use it. We would like to consider whether we can specifically take active users etc.

Chai Shan Member: Concerning the analysis by the number of users, the type of 10,000 or more is concerned about whether it is a government agency unit or a slightly smaller organizational unit.

Secretariat: The category of more than 10,000 people will probably include the use of local related organizations.

Chai Shan Member: Regarding the point that personal use raised by members must be prevented, for general-purpose type1, I think it is important to eliminate people who cannot use it. If there is something officially available, they are likely to use it. I think it is important to eliminate blank areas. To that end, I think it is necessary to break down and concretize the rules for using generative AI.

Member OKADA: We share information about the fact that we have often received consultations from ministries and agencies, local governments, and companies in Nabatame I felt that the purpose of introducing AI, which was raised by a member, is important. In all the projects shared with us, we can infer that objectives, outcome indicators, activity indicators, etc. have been set at the stage of raising budget requests. In the first place, I wonder whether outcome indicators and activity indicators have been set, and if so, what kind of criteria have been set. They are important for understanding the overall situation and for learning from the cases of other ministries and agencies, so I would like you to consider them.

Secretariat: The points you pointed out are also important for raising awareness, so we would like to consider them. We are also developing procedures for using AI. Even if it is available free of charge, it is acceptable to use it as long as it is Confidentiality class-1 information. In order to actively utilize it without imposing a burden, it is a reality that such information is often used without clearly defining performance indicators, etc. For cases where systems are developed, Digital Agency is also seeking indicators. First of all, I think it is important to have an attitude of using it without setting performance indicators, so I would like to proceed while adjusting it well.

3. Explanation of generative AI Trends in Japan and Other Countries

The Secretariat explained the trend of generative AI in Japan and other countries in Appendix 4.

The main questions and opinions of the attendees are as follows.

KITAMURA A member: We would like to add two points. Regarding AISI evaluation tools, we have released open source software, including automatic red teaming. Details are available on GitHub. Regarding the status of generative AI's introduction, there is a trend to move to generative AI based on the control of the conventional AI, as there is a need to keep a firm footing in the German market. Although an internationally established definition of agentic AI does not yet exist, based on a provisional understanding of the practical situation, for example, in Germany and other countries, specific initiatives such as audits and the use of meta-agents are underway, and it is necessary to be aware that competition for the next stage is becoming increasingly intense.

Member YOSHINAGA: On September 15, 2025, OpenAI, Duke University, and Harvard University released a report titled "How People Are Using ChatGPT." The report says that is mainly used for guidance, for information gathering like search engines, and for document creation support. Currently, the government ministries and agencies generally consider it to be classified into these three categories. In the previous report, it was mentioned that it is also used for legal system survey support, etc. However, I have experience of surveying legal systems of dozens of countries as a researcher of a think tank, and I think such surveys will not need to use think tanks in the future. However, it is necessary to closely examine the accuracy of the hallucination, and I think we need to monitor each ministry and agency to see if they are closely examining and providing information. I would like Digital Agency to closely communicate with each ministry and agency on this matter.

Secretariat: generative AI, each ministry is to establish rules for utilization, conduct training, and disseminate the points to keep in mind when using it for hallucination, etc.

KITAMURA A member: The Advisory Board also needs to cooperate with CAIO members from various ministries and agencies. In the presence of CDOs, CISOs, etc., in order to prevent excessive burdens from concentrating on the CAIO, we, the Advisory Board, as experts, would like to supplement the CAIO's practical operations by providing expert advice in a form that can be expected as a partner of the CAIO.

Nabatame Member: I would like to comment from the standpoint of the private sector in AI Basic Plan, have been extremely positive, and I believe we have been able to contribute to the beneficiaries, the people of Japan. The U.S. action plan was also released in July, and I understand that it is extremely timely. Based on this, it is important to see how dynamically the future operation can be advanced as a continuous transformation. Since the pace of change in AI may exceed our expectations, the Japanese government needs to strike a balance between risks and utilization. AI will continue to evolve in the future, but it is difficult to expect it to be completely infallible. In addition to the technical challenge of hallucination, the output created from a limited amount of AI cannot be said to be completely accurate, and I don't think it will change that there will be a need for manual corrections, so it is important for the Japanese government to continuously monitor and consider issues. I think it is also important for the efforts of each ministry and agency in the future to continuously review the imperfections of change and infallibility. In Pillar II of the U.S. Action Plan, as Promote Mature Federal Capacity for Data Incident Response, the United States is looking at realizing a society in which incidents are accepted as inevitable, but in which the benefits outweigh the risks.

Secretariat: The current GLs define the roles of each ministry and agency, as well as the roles of each agency. There is a description of monitoring in the operation, but we would like to consider enhancing the description while receiving opinions from everyone.

KITAMURA A member: The keyword for generative AI in the future is multi-agent. In the past, "wrong answers" in the generated results were a problem, but in the future, "malfunctions" that occur in the course of cooperation of multiple AI systems, that is, unexpected behavior due to interactions between systems, will be a problem.

Chairman: Kadobayashi: multi-agent were raised, and we would like to continue discussions at the Advisory Board in the future.

4. Explanation of possible discussion points for the enhancement of the Guidelines for the Acquisition and Utilization of generative AI for the Evolution and Reform of Public Administration

The Secretariat explained the candidate issues for improvement of the guideline.

The main questions and opinions of the attendees are as follows.

Chairman: Kadobayashi: , we would like to ask the members of Naganuma.

NAGANUMA Member: Business Federation Digital Economy Promotion Committee International Strategy WG Chief. Last year, the Federation of Economic Organizations (Keidanren) participated as a member of the industrial world in a study group on AI systems. In doing so, the Japan Business Federation (Nippon Keidanren) conducted a questionnaire on AI utilization and systems, and the results are summarized here. The questionnaire was sent to AI developers, AI providers, and AI users. The point of view on the utilization of governmental AI is also included, and the study group on AI systems was also approached. I would like you to refer to what Keidanren was saying. Regarding the basic approach to the principles, "(1) Compatibility between risk response and innovation promotion" clearly specifies the allocation of responsibilities, and includes certification systems for AI products and safety measures, support measures as industrial policies, and human resource development with AI literacy. This is a part that is also reflected in the AI Act. "(2) Flexible institutional design to respond to the speed of change in technology and business" has been incorporated into the AI Act as an institutional design to respond to the speed of technology and business. "(3) Compliance with International Interoperability and International Guidelines" refers to international interoperability, and the items listed are based on compliance with international codes of conduct. As you know, it is also reflected in the AI Act. We received many comments on "(4) Governments' Views on the Appropriate Procurement and Use of AI." There is also a view that Japan should reduce its dependence on foreign suppliers. There are also calls for the clarification of responsibilities and decision-making processes, and for the establishment of a governance system within the government. We have also received calls for the strengthening of international competitiveness and the development of standards such as ISMAP. The rearing of the domestic technology is greatly desired from the industrial world. There are calls for clarifying responsibilities, making the decision-making process transparent, and building governance within the government, and I would like to deepen the discussion. Regarding the strengthening of international competitiveness, I think that what will happen specifically will be discussed later. I think the ISMAP system will also be a point of discussion later. "(5) Other opinions" also stated that it is necessary to consider certification systems, responses by industry, and consideration for small and medium-sized enterprises. In the future, we would like to have in-depth discussions on "(4) Views on Appropriate Procurement and Use of AI by Governments". This material is from one year ago, but please use it as a reference.

Yuasa: There are three opinions. The first one, which was also raised by Nabatame, is that it is well known that there is no infallibility in AI, but public opinion seems to be growing that administrative work should be perfect. It seems necessary to send a clear message that the accuracy of AI is not 100 percent. The second point is that there is a point of issue as to what to do if the government or local governments are pointed out to be illegal, but from the perspective of the government, there is a risk of being sued. Regarding the determination of high risk by the GL, we believe that it is not a risk determination that is directly linked to illegality under the Administrative Act. We believe that it is necessary to review again whether the direction is such that high risk = possibility of violation. The third point is regarding the logic on the risk axis. Considering that personal information is assumed to be used in most use cases, it may be too strict to say that high risk is imposed immediately when personal information is handled. It may become a barrier when government agencies use AI. Since the handling changes depending on whether it is Special Care-required Personal Information or not, we do not call it relaxation, but we should make the logic easy for the government to introduce.

Secretariat: We would like to deepen it while receiving opinions. I think that the part that AI is not infallible will be especially important in use cases for the public, and I would like to proceed based on showing precautions and disclaimers in writing and making them concrete.

Secretariat: As for the risk judgment logic, the current thinking is that "C. Whether or not confidential or private information has been learned" is concerned about leakage risks, and "B. The nature of work related to the use of generative AI" is to respond to civil illegalities that cause damage by creating wrong information. "A. Scope and type of users" is from the perspective of reducing risks by thoroughly implementing rules as long as users can be identified. "D. Utilization of output results that have been judged by government officials" is from the perspective of a human-in-the-loop approach and from the perspective that people are responsible for the content. Regarding the part of "C. Existence of learning, etc. of confidential information and personal information" for which opinions were received, we would like to have more concrete discussions in the future.

Chairman: Kadobayashi: Technology is evolving with respect to confidential data, with Named Entity Recognition and other technologies enabling the automatic masking of personal data, while privacy-enhancing technologies (PETs) that protect confidential data are evolving. Technology is evolving with respect to confidential data, with Named Entity Recognition and other technologies enabling the automatic masking of personal data, while privacy-enhancing technologies (AI) that protect confidential data are evolving.

Secretariat: In relation to this, the review of the Act on the Protection of Personal Information has become a point of discussion at the next Diet session, and I would like to pay close attention to trends.

Chairman: Kadobayashi: With regard to "A. Scope and type of users," it is important for the government to present guidelines to industry.

TORISAWA: I would like to make a few comments. With regard to the check sheet for procurements, I think it is very difficult to express and secure the point that AI is not infallible in this sheet. It seems to be impossible to realize Requirement 19: "The output from the generative AI system should not contain harmful biases and should not contain unjustifiable discrimination." Whether it means that the output that can reject an answer is 100 percent or 90 percent is not commonly understood as the former, but this is also impossible at present and will be almost impossible in the future. The description of the examples of measures is also problematic, and it is said that there is a mechanism in which generative AI can refuse to answer. It is not possible to identify personal names 100 percent accurately and completely. In procurement, if the benchmark data is open, it is considered that amateurs will read this description about AI, but how to write "possessing technology" is also difficult for the supplier side. One idea is to use benchmark results to show that there is no bias, but in evaluation by benchmark tests, if the benchmark data is open, it is considered that it will be difficult to score in that case. How to write it is important. I think the same applies to Requirement 27 "AI accessed by the generative AI system is maintained in appropriate condition". AI

Secretariat: generative AI is not infallible into the check sheet. We are not requiring that it is basically infallible, but the essence is that we are taking risk mitigation measures against it. However, we believe that it is necessary to review the specific expressions from the viewpoint of what you pointed out. We will encourage the secretariat to confirm, but we will continue to receive opinions from all members and make improvements.

KITAMURA A member: AISI is just one of the evaluation methods, and it is not an absolute evaluation. AI does not have any geographical boundaries, and when we look at the difficulties of cross-border regulations, the Royal Institution of AI in the UK believes that in Europe, data-management and data-access issues, such as how much information is disclosed and how little is disclosed, will be the areas of competition among countries in the future. The currency of AI is data, so the idea is that data-access will be the area of regulation. Looking at the limits of control of quality models, there is a growing view that the main battlefield will shift to data.

Secretariat: 's Guidelines for Procuring and Utilizing generative AI, AI policies will likely be on the agenda in the future.

Chairman: Kadobayashi: knows no borders. However, with the spread of the Internet, privacy laws and regulations have been gradually introduced. The same trend is expected for AI. It is important for the Japanese government to present guidelines regarding data, such as whether or not administrative documents can be studied. In the administration, it is also important to address biases in thought.

KITAMURA A member: 's generative AI initiatives are also being seen in the private sector. Even in Germany, the Japanese benchmark was being watched.

Member YOSHINAGA: I have four opinions. First, since specific risks have not yet been identified, there is room for consideration of the flow chart. What kind of risks actually exist should be learned from the ministries and agencies, and the risk judgment sheet should be revised after brainstorming within the advisory board. Second, there was the case of child abuse protection in Mie Prefecture, which may have been discussed separately in the guidelines of the local government. There was the case of child abuse protection in Mie Prefecture, which may have been discussed separately in the guidelines of the AI. It is also difficult to judge whether or not it should have been judged as high risk at a protection rate of 39%. The operation rules of the AI, such as such criteria, should also be considered. Third, I would like to know how the governmental organizations of other countries use generative AI. For example, if there are cases where governmental organizations use AI in the U.S., the U.K., Singapore, etc., please present them from the next time on. Fourth, regarding the structure of the guideline, in the attachment, there are classifications of mandatory reference and recommendation, but wouldn't it be easier to use if the order was changed from mandatory to recommendation? Also, in the attachment, I thought it would be easier to use if it is clearly indicated whether it is mandatory or not.

Secretariat: I would like to deepen discussions while indicating the direction based on today's opinions. I have heard that the AI on the protection of child abuse utilized deep learning. Regarding the order of the attachments, the current situation is to number them in the order in which they appear in the main text, but we would like to consider it.

Chairman: Kadobayashi: I think each ministry and agency and the administration have their own jurisdiction. Regarding child abuse, I think it is under the jurisdiction of the Child and Family Agency. I think we should promote it while cooperating with each other.

KITAMURA A member: : Now is not the time to elaborate on the relationship with ISO/IEC42001, which is the standard for AI management systems. Regarding ISO/IEC42001, I was one of the members who were also involved in the discussion, but there is no contradiction in the context of procurement. However, in Japan, we are at the stage where measures are just beginning to be taken, and I think it would be better to start taking action after the ISO/IEC42001 management system actually starts operating.

Secretariat: We would like to consider the option of making it an issue in the next fiscal year or later.

KITAMURA A member: The key point of the America's Action Plan is to achieve a full stack. However, since the opinion in the United States is divided into two, I think it is necessary for Japan to promote measures for the future.

NAGANUMA Member: Speaking from the perspective of the private sector, we assume that the private sector will take the lead in generative AI in terms of both use cases and risks, although the government will make use of the four issues. The current AI GL has a strong connection with the Procurement Business Operator GL. In the future, guidelines based on the AI Act will be established. From the perspective of maintaining consistency with governmental rules, it is conceivable that if there are too many updates, it will be difficult for users to use the system. It is necessary to see how far we can proceed with our eyes focused on the future. Cross-references with consideration of the time axis in the private sector will be important.

Nabatame Member: I would like to comment from the standpoint of the private sector in . The AI Governance Association, of which I am the representative director, has now grown to about 120 companies. The association was launched with the intention of disclosing to society the knowledge and efforts made by the private sector regarding risks. Through my activities to date, I have found that many of the risks inherent to AI, such as damage to the body, are clearly covered by the existing legal system. Regarding values that are not fully covered by the existing legal system, such as ethical, dignity, and bias, it is difficult even for private sector businesses. There are expressions of consideration for bias, ethical, and dignity in the AI check sheet, but I think it is also difficult to just check sample data. The reason is that procurement, unlike IT, involves a complex process of recognizing, understanding, and generating information, so I would like to discuss what to do to address the gap.

Chai Shan Member: It is also difficult to reduce the risk of copyright infringement to zero. When copyright infringement has occurred, the main legal effects are injunctive relief and claims for damages. Regarding injunctive relief, injunctive relief is given whether or not there is negligence. Regarding compensation for damages, negligence is required. If you can say that you have taken reasonable measures to prevent copyright infringement, you can reduce the possibility of an admission of negligence and significantly reduce the risk of damages. Regarding copyright infringement, it is possible to reduce the risk by providing certain technical guarantees, etc., but this is not something that users can do, and it is basically something that only developers can do. There are few things that users can do, but we believe it is important to evaluate risks based on the mode of use and respond to them. The Japan Deep Learning Association (JDLA) is also promoting discussions. I think it would be good if the private sector, which can take risks, promotes the use of the system, and then the government can refer to it. In addition, regarding the contract check sheet, JDLA and others are working to disclose the GL of the development contract for a system incorporating generative AI and the template of the contract.

Secretariat: : If the generation of images is included in the scope, we believe that it is required as a governmental guideline to describe the infringements of intellectual property rights by the products. It is similar to the conventional cybersecurity's argument. Control in terms of prevention and response to emergencies is important in AI as well. In the same way as AI, restrictions before use are important, but we would like to proceed while taking into account the restrictions at the time of use.

TORISAWA: In relation to the current law, there are cases where the descriptions are too vague to understand from the developer's point of view. We are concerned that the guidelines will be written taking over the ambiguity. Regarding the Special Care-required Personal Information, there is a description of the "Creed," but there is a point of view as to what the Creed is. There is a point of view as to whether the posts on SNS are the Creed. Based on the situation, it is considered difficult to incorporate them into the guidelines.

Member OKADA: We share information about the fact that we have often received consultations from ministries and agencies, local governments, and companies in in the past two years. The first point is about the utilization of personal data, in particular, whether it is acceptable to use pseudonymized information for generative AI. The second point is about the acceptance of hallucination, as has just recently been shown mathematically, the extent to which we accept the fate that hallucination always exists, and how we call attention to and raise awareness. The third point is about reviews during AI procurements, about when and how we should conduct technical reviews and user reviews during procurements and developments. The fourth point is about AI system audits, about when and how we should conduct an audit to see if there are any problems by appropriately function procured or developed generative AI services after they are put into operation.

Chairman: Kadobayashi: Those who regulate systems, those who operate systems, and those who develop systems were able to gather and have conversations. The use of fire for steel refining and automobiles has also been promoted, albeit with risks. It is important to consider how to utilize such resources. In addition, some undisclosed materials will not be disclosed based on the Operation Guidelines.

Greater Than