The first half of 2026 has been an active stretch for technology policy across the Asia-Pacific, and the pace shows no sign of slowing. Five markets — Japan, Korea, India, Vietnam, and Australia — are each moving through a distinct phase of artificial intelligence (AI), data, and cybersecurity rulemaking, often on multiple fronts simultaneously.
Some governments are translating years of strategy documents into their first binding legal frameworks. Others are quietly reshaping rules already in place. None of this is happening in lockstep, and the details will ultimately determine which of the Asia-Pacific markets are best positioned to develop, deploy, and adopt AI for the benefit of their economies and societies.
BSA is working across these markets to advance privacy, security, and governance policies and practices that are aligned across the region and globally. The intention is to set clear and workable expectations that support responsible innovation and AI adoption.
Japan: Strategy Ahead of Law: Next Phase of AI Policy
Japan has sought to position itself as the most AI-friendly country in the world, pairing that ambition with a light-touch legal framework. But that’s beginning to change.
The Cabinet of Japan approved a second AI Basic Plan on July 14, revising the original from December 2025. It’s a strategy document, not law — Japan’s actual AI statute, the AI Promotion Act, remains flexible and designed to promote AI innovation. The plan also calls for Japan to pursue an “open AI sovereignty” strategy to secure strategic autonomy and indispensability and to avoid dependence on any single company or country. If Japan implements this strategy by promoting international interoperability, resilience, and trusted global partnerships, Japan will contribute to and benefit from global innovation.
For enterprise software, the sharpest live issue is training-data disclosure. Driven by Japanese rights holders pursuing licensing and compensation, the government of Japan has proposed a voluntary compliance mechanism, in which AI operators are asked to reveal the content their models were trained on. However, in reality, this functions as a de facto mandatory disclosure agreement because the government will publicly display any companies that fail to comply.
BSA has advocated that Japan’s existing copyright exception already treats AI training as non-infringing analysis. Further, we maintain that requiring detailed disclosure of training risks exposing trade secrets and creating cybersecurity vulnerabilities for malicious actors, while failing to deliver the compensation rights holders are seeking. BSA will continue to encourage Japan to realize “trustworthy AI” without discouraging investment and innovation in the AI ecosystem.
Korea: High Ambitions, Uneven Execution
Korea continues to harbor ambitions of becoming one of the world’s leading AI economies. Its AI Basic Act is now in effect, making Korea the first jurisdiction after the European Union to pass a comprehensive national AI law. However, work is already underway to adjust the AI Basic Act’s definitions and obligations to avoid unduly chilling AI innovation. In the meantime, there is a grace period in place, during which penalties for violating many of the law’s provisions are suspended.
AI and copyright remain a flash point in the policy landscape. In February 2026, Korea opted against introducing a text and data mining exception into the Copyright Act. Instead, the government issued non-binding guidelines on fair use. The guidelines do little to move the needle, as they do not deliver the predictability that a carefully designed statutory exception — of the kind adopted in Japan and Singapore — gives creators, rights holders, AI developers, and the users of AI systems.
Korea’s cloud and privacy regulations also continue to impose significant compliance burdens, especially on foreign service providers. The Cloud Security Assurance Program (CSAP) has long shut most foreign providers out of Korea’s public-sector cloud market. In April, Korea confirmed plans to make CSAP a “voluntary” private-sector certification, but requirements that have barred foreign cloud service providers (e.g., data localization, network separation, Korea-specific encryption) are likely to re-emerge in a new public-sector cloud procurement framework. On privacy, recent amendments to the Personal Information Protection Act have raised the maximum fine for serious violations from 3 to 10 percent of global turnover, while also requiring certain organizations to obtain Information Security and Personal Information Protection Management System certification.
BSA will continue to engage Korean authorities across all three fronts, advocating for internationally interoperable rules scoped to genuine risk, promoting greater legal certainty, and driving digital transformation to the benefit of Korea’s industry and society.
India: Marching Forward With AI Legislation and a Sovereign Cloud Framework
India hosted the Global AI Impact Summit in February 2026, with a focus on responsible AI, inclusive growth, and measureable impact. During the summit, BSA launched the Global Enterprise AI Adoption Agenda in the presence of BSA members and government officials from India and the United States.
In July 2026, the government of India signaled that it may now pursue dedicated AI legislation, marking a notable evolution in its AI regulatory approach. The proposed framework is expected to follow a risk-based model, creating the opportunity for India to develop a workable, internationally interoperable approach to AI governance that establishes reasonable guardrails for high-risk uses of AI while enabling investments in AI development, deployment, and adoption to flourish.
However, the government of India has also issued rules requiring visible labelling of synthetically generated information (e.g., AI-generated content), which impose unreasonable burdens on creators and AI tool providers alike and fail to take advantage of more effective content authenticity tools. Furthermore, and contrary to BSA’s recommendation for a text and data mining exception, the Department for Promotion of Industry and International Trade proposed a mandatory blanketing licensing regime with revenue-based royalties for AI training. This development risks slowing AI adoption in India, including the development of Indian language AI models the government purports to support.
Meanwhile, the Ministry of Electronics and Information Technology (MeitY) is developing a Sovereign Cloud Framework to define sovereign cloud architecture, operational safeguards, and procurement approaches, with implications for how government workloads are classified and deployed. BSA is engaging with MeitY to contribute international perspectives and advocate for a risk-based, technology-neutral framework that supports security, resilience, innovation, and continued access to best-in-class digital technologies.
Vietnam: Three Data Laws, One Warning
Vietnam has been developing data governance and AI-related legislation at a very rapid pace. This includes updates to the Cybersecurity Law, implementation of the Personal Data Protection Law, enactments of the Data Law and AI Law, and a Data Security Law now in development.
BSA has long been concerned with various unique regulatory requirements related to the storage and processing of commercial and personal data under the existing legal frameworks. In Vietnam, the Data Security Law proposes a four-tier data classification system that would further limit how international firms and their enterprise customers manage data. This includes data transfer restrictions and data residency requirements and, in some cases, mandates domestic infrastructure and cryptography requirements. The approach imposes obligations on firms based on subjective or arbitrary criteria, such as data volume, rather than on objectively assessed risks related to the data workloads. This means companies offering cloud computing and other software- enabled services may be subject to data governance controls best reserved for highly sensitive data. The results are increased costs and deterred investments in digital transformation, cloud adoption, and the development and deployment of AI in Vietnam.
Instead of introducing yet another regulatory layer to Vietnam’s already complex and burdensome data governance regime, the government should use the Data Security Law to consolidate this legal and regulatory patchwork into a single coherent framework.
Australia: Attracting Investments While Building Safeguards
Australia seeks to position itself as a regional AI data center hub, offering regulatory certainty and expedited approvals to investors while managing risk through existing laws.
In this regard, Australia has chosen not to pass a standalone, economy-wide AI law. According to Australia’s National AI Plan, AI-related risks and issues will be addressed through existing laws and targeted policies.
In July 2026, Prime Minister Albanese set up a new Office of AI to coordinate AI policy across the government. Key initiatives include legislating mandatory standards for AI data centers, creating a “digital duty of care” that puts the onus on AI companies to build in safety by design, progressing a second tranche of Privacy Act reforms, and implementing a new transparency obligation for automated decision-making. While different departments are undertaking these initiatives, it is up to the Office of AI to coordinate these workstreams and ultimately present a coherent, predictable framework for business.
Australia’s approach to AI training and copyright is inconsistent with its ambition to be a data center hub. The government has categorically ruled out a text and data mining exception, with the Prime Minister insisting that AI systems cannot train on works without providing compensation. The government is now exploring licensing arrangements, which will deter AI training on Australian data in the country.
Australia’s approach to AI involves attracting investments and encouraging adoption on the one hand, while building safeguards on the other. These two objectives are not inherently in conflict, but success demands careful calibration.
The Bottom Line
Across these five markets, the common stated policy objective is to promote trusted AI, drive cloud adoption and digital transformation, and enhance sovereign control over sensitive systems in the public sector and various regulated sectors. However, the pace and diversity of approaches between countries — and frequently within them — suggest that the evolving legal and policy environments may struggle to support those objectives.
Risk-based, outcomes-oriented, and internationally interoperable rules for personal information protection, cybersecurity, and critical infrastructure protection can promote safe, secure deployments of technology that respect consumer interests. Fragmented policies imposing prescriptive and country-unique rules, on the other hand, risk raising costs, slowing the development and deployment of advanced software-enabled technologies, and failing to achieve the stated public policy objectives.
We look forward to continuing to work with these and other important jurisdictions. Our goal is to identify sensible regulatory approaches that meet these objectives while enhancing commercial and political partnerships that drive the next cycle of innovation, technology adoption, and the subsequent economic and social benefits.
