Territory · China · Asia

AI regulation in Hong Kong SAR

Source-linked · checked 11 Sep 2026 2 instruments · 0 binding

Overview

Hong Kong has no AI-specific statute. The Office of the Privacy Commissioner for Personal Data (PCPD) issued the Model Personal Data Protection Framework for AI (June 2024) and Guidance on Ethical Development and Use of AI (2021); the Digital Policy Office published the Ethical AI Framework for government (updated 2024) and a Generative AI Technical and Application Guideline (April 2025); the Securities and Futures Commission and Hong Kong Monetary Authority issued circulars on generative-AI use in financial services. The Personal Data (Privacy) Ordinance applies.

What is the current regulatory status?

No AI-specific law; PCPD AI frameworks and Digital Policy Office guidance; financial-regulator circulars.

Binding rules versus guidance

Binding: none recorded. Strategy or guidance: PCPD Model Personal Data Protection Framework for AI (2024); Generative AI Technical and Application Guideline (2025).

Key policy instruments

Hong Kong SAR Guidance Guidance

PCPD Model Personal Data Protection Framework for AI (2024)

Artificial Intelligence: Model Personal Data Protection Framework

Published 11 June 2024, the framework gives organisations that procure, implement and use AI systems involving personal data recommendations in four areas: AI strategy and governance (an AI governance committee, procurement due diligence), risk assessment and human oversight (a risk-based approach with levels of human involvement), customisation and implementation of AI models (data preparation, testing, security), and communication and engagement with stakeholders (transparency, explainability, opt-out, feedback). It builds on the 2021 Guidance on the Ethical Development and Use of AI.

Adopted 11 Jun 2024 Source-linked · checked 11 Sep 2026 Official source
Hong Kong SAR Guidance Guidance

Generative AI Technical and Application Guideline (2025)

Hong Kong Generative Artificial Intelligence Technical and Application Guideline

Published in April 2025, the guideline covers the technical characteristics and risks of generative AI, governance principles (safety, transparency, accountability, data protection, fairness) and practical application guidance for developers, service providers and users across the AI lifecycle, and is intended as a reference for industry and government.

Adopted 15 Apr 2025 Source-linked · checked 11 Sep 2026 Official source

Upcoming deadlines

No scheduled future dates recorded. Past milestones are listed on each policy page.

Latest changes

Applicable sectors, use cases and obligation areas

Obligation areas

How to use this information

  1. Open the official source on each instrument before relying on any date or obligation.
  2. Treat strategies and guidance as signals of coming regulation, not as binding requirements.
  3. Check data-protection, consumer, employment and sector law that applies to AI systems regardless of AI-specific instruments.

Official government and regulator sources

  1. Artificial Intelligence: Model Personal Data Protection Framework
    PCPD · 2024-06-11 · Tier 1 source
  2. Ethical Artificial Intelligence Framework
    Digital Policy Office · Tier 1 source

Follow by email

Get every dated, source-linked change to this jurisdiction in a weekly email.

Double opt-in; one-click unsubscribe in every email. Choose jurisdictions

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.