Hong Kong is preparing a more specific regulatory framework for artificial intelligence, with a focus on data governance, security standards and the definition of liability for damages caused by AI systems. The move combines measures announced by the government in September with a growing discussion among experts about the gaps in current rules.
Technology and law experts interviewed by South China Morning Post this Sunday (4) argued that new rules should establish minimum security requirements and clear limits of liability. The assessment comes after the government indicated that it intends to resort to legislation and specific regulatory instruments to deal with risks associated with the adoption of the technology.
The plan presented by Chief Executive John Lee foresees a risk governance strategy on seven fronts. Among them are combating the criminal use of AI, protection of minors, assessment of ethical risks, security of applications, liability for accidents involving AI products and rules for agents capable of executing tasks autonomously.
A working group led by the Department of Justice is expected to assess whether existing laws are sufficient to determine who is liable for accidents or losses caused by AI products. The government admits that the answer may involve new legislation, regulations or instruments such as codes of practice and guidelines.
Data and security take center stage in regulation
Hong Kong's initial five-year plan, valid from 2026 to 2030, also calls for a review of existing laws and measures related to AI and data risks, enforcement rules, governance standards and cybersecurity. The official guidance is to seek solutions specific and applicable to the local market, instead of simply importing a foreign regulatory model.
In practice, Hong Kong still depends mainly on existing rules, such as personal data protection legislation, complemented by guidelines for the ethical and safe use of AI. The Digital Policy Office already maintains guidelines that address issues such as data leaks, model biases, errors and information security.
Pressure for more defined rules grows along with the adoption of the technology. An inspection carried out by Hong Kong's data protection authority showed that 57 of the 60 organizations analyzed, or 95%, were already using AI in their daily operations in 2026, an increase of 15 points compared with the previous survey.
The authority itself said in September that it intends to intensify compliance checks, studies on AI use and initiatives focused on data security and cybersecurity. The government's stated goal is to form a framework that allows expanding the adoption of the technology without separating development from control mechanisms.



