MONOLITH LAW OFFICE+81-3-6262-3248Weekdays 10:00-18:00 JST

MONOLITH LAW MAGAZINE

IT

Five Steps to Successful AI Adoption: Developing a Practical Internal AI Policy and Training Program

IT

Five Steps to Successful AI Adoption: Developing a Practical Internal AI Policy and Training Program

Technological advances in generative AI have the potential to fundamentally transform traditional business processes. However, many organizations face challenges not only in overcoming technical barriers, but more importantly in managing legal and ethical risks and integrating AI into their organizations. Simply distributing the latest tools across the company and leaving their use to the discretion of individual departments—a “hands-off” approach—can lead to serious incidents, such as information leaks and infringement of third-party rights. Ultimately, this approach can also hinder the organization’s overall productivity.

To sustainably benefit from AI, it is helpful to establish “living AI internal regulations” that achieve an efficient balance between technological convenience and legal safety. A phased training process based on those regulations is also crucial. This article explains five specific steps for achieving effective AI implementation, based on the latest Japanese laws, regulations, and government guidelines.

Risks of Uncontrolled Generative AI Use

When considering the implementation of generative AI, organizations often encounter the problem of “shadow IT,” in which operational use begins before the organization has established a clear policy. Because these tools are highly convenient, employees may use personal accounts for work based on their own judgment. This “let’s try it first” approach may appear to accelerate implementation in the short term, but in reality, it encourages unregulated use and accumulates significant management risks.

In particular, there are concerns that the careless input of confidential information may result in the leakage of trade secrets, that AI may generate content infringing the copyrights of others, and that inaccurate information may be communicated externally. The AI Business Operator Guidelines, published by Japan’s Ministry of Economy, Trade and Industry and Ministry of Internal Affairs and Communications in April 2024, also call on businesses using AI to assess these risks appropriately and establish the necessary governance.

Without a solid foundation of clear rules, employees cannot accurately determine what is permitted and what is prohibited. As a result, they may either hesitate to use AI creatively or unknowingly make serious mistakes.

Reference: Ministry of Internal Affairs and Communications|AI Business Operator Guidelines Page

Even if unregulated use temporarily improves organizational productivity, the costs of resolving legal problems and the loss of public trust can be immeasurable. Therefore, clearly establishing a framework for safe use at the initial stage of AI implementation does not restrict operational freedom. Rather, it provides an environment in which employees can use the technology with confidence. The purpose of this article is to clarify the specific steps for building this “safe foundation” and establishing an operational system that prevents it from becoming a mere formality.

https://monolith.law/corporate/establishment-of-ai-internal-regulations

Step 1: Define the purpose of AI Implementation and the Problem to Be Solved

Steps 1-2: Clarifying Objectives and Selecting Optimal Services

The first critical factor in determining the success of AI implementation is whether AI can be redefined as a means of solving organizational challenges, rather than making the introduction of the technology an end in itself. If the purpose of AI implementation remains vague, the resulting internal regulations may become abstract and ineffective, leading to “dead rules” that have little practical value in the workplace.

The first step should be to clearly articulate the purpose of introducing AI, including the specific challenges that it is intended to address in each department.

  • Accounting Department: Reducing administrative burdens. The primary issue is security regarding the external transmission of data.
  • Development Department: Automating code generation. Key concerns include Article 30-4 of the Japanese Copyright Act, open-source software licences, and vulnerabilities.
  • Sales and Public Relations: Creating materials and generating FAQs. The focus is on information accuracy and the risk of infringing third-party rights.

By identifying the specific challenges each department must address, the direction of rules tailored to each type of work becomes clearer.

Step 2: Select Appropriate AI Services and Review Their Terms

Next, select AI services that align with the objectives that have been defined. The current market offers a wide range of services, from general-purpose generative AI such as ChatGPT to AI specialized in fields such as law, accounting, and programming. While general-purpose AI offers the flexibility to handle a broad range of tasks, it may be less accurate in specialized fields and less suited to complying with particular regulations than specialized AI.

When selecting services, it is crucial to ensure that they comply with the organization’s security policies. The potential use of the provider’s APIs and the availability of data-protection features under plans for corporations are also important considerations. As there are often fundamental differences between free individual plans and paid business plans regarding the use of input data for training, including the availability of opt-out settings, entering into a business-plan contract should be a prerequisite for company-wide implementation.

When selecting AI services, the most important and frequently overlooked issue is the review of each vendor’s terms of use. Compared with general SaaS products, AI services tend to have complex and frequently changing conditions regarding data ownership and the use of data for training. The following five points should be verified before entering into a contract in order to minimize legal risks.

CheckpointsDetails to ConfirmLegal and Practical Significance
Scope of ProhibitionsWhether the generation of advice in specific fields, including medicine, law, and finance, is prohibitedTo avoid account suspension or liability risks resulting from violations of the terms
Permission for Commercial UseWhether commercial use of generated content is expressly permitted, and whether this differs by planTo ensure stable rights for use in revenue-generating activities
Intellectual Property RightsWhether the terms clearly state that copyright in generated content belongs to the userTo protect the content as the company’s own creation and enable secondary use
Use for Machine LearningWhether it is possible to opt-out of having input data used for model retrainingTo protect trade secrets and prevent leaks of confidential information
General Clauses and Governing LawThe jurisdiction, scope of indemnification, and applicable law in the event of a disputeTo ensure predictability and manage costs in the event of a dispute

In particular, clauses concerning the use of data for machine learning are directly related to the protection of trade secrets in Japan. If input data is incorporated into a vendor’s training data, there is a risk that the company’s confidential information may later be reflected in another user’s response. To receive protection as a trade secret under Japan’s Unfair Competition Prevention Act, the company must be able to demonstrate appropriate secrecy management. An environment in which data is indiscriminately used for AI training may seriously undermine that requirement.

Attention must also be paid to the governing law. Many services provided by U.S. vendors are governed by laws such as the law of the State of Delaware and may limit dispute resolution to overseas venues. For Japanese companies, this may effectively make the exercise of their rights impractical. Therefore, when using such services for critical operations, it is advisable to consider negotiating contracts that provide for Japanese law as the governing law or designate Japanese courts as the agreed jurisdiction.

Step 3: Pilot, Learn, and Improve Through a PDCA Cycle

Rushing to apply rules across the entire organization without sufficient verification can create confusion in the workplace and cause the rules to become mere formalities sooner. A trial implementation through a “small-scale rollout” is recommended, targeting specific project teams or departments with high IT literacy and a clear understanding of the issues involved.

The greatest drawback of implementing AI across the organization at once is the imposition of “one-size-fits-all rules” that disregard the diverse operational realities within the organization. Applying overly strict rules company-wide can reduce convenience in the workplace, while overly lenient rules fail to control risks. By establishing a trial period, the organization can accumulate data based on actual experience and identify the risks that arise in real workflows, as well as the guidelines that are necessary.

This period should function as a “sandbox” in which failures are permitted. Employees should be encouraged to use AI and keep a record of the prompts they enter, the outputs they receive, and any concerns that arise, such as inaccurate information caused by hallucinations, inappropriate expressions, or signs of copyright infringement. A system should then be established under which legal and information-systems personnel review those records.

To maximize the effectiveness of a small-scale start, it is useful to implement the following six-step verification workflow:

  1. Identify the target operations and prepare an “initial guideline” tailored to those operations. This initial draft should briefly set out the minimum prohibitions, such as a prohibition on entering confidential information, as well as recommended methods of use.
  2. Provide introductory training to selected members and allow them to use AI in their actual work.
  3. Collect feedback from the workplace through regular interviews, such as whether the rules are interfering with work or whether any unexpected risks have been encountered.
  4. Based on the issues identified, readjust the balance between risk and convenience and improve the guidelines.
  5. Reissue the improved guidelines and continue refining them.
  6. Develop “standard regulations” for company-wide implementation based on the insights obtained through this verification process.

By operating this PDCA cycle, rules can be transformed from top-down requirements into “living rules” that employees understand and can follow in practice.

Step 4: Scale Carefully With Department-Specific Risk Assessments

Steps 4-5: Expanding Implementation Scope and Regular Reviews

When expanding the scope of implementation based on insights obtained during the trial, it is essential to conduct individual risk assessments for each department. Uniform regulations alone cannot adequately address differences in the assets that must be protected.

  • Human Resources Department: Emphasize the prohibition on entering personally identifiable information and the transparency of automated decision-making, in accordance with Japan’s Act on the Protection of Personal Information.
  • Research and Development Department: Prioritize technical and contractual protections to prevent ideas from becoming training data for other companies.
  • Public Relations and Marketing: Focus on measures addressing similarities to trademarks and designs, as well as the risk of public backlash.

By organizing these issues and clearly categorizing tasks as “permitted,” “conditionally permitted,” or “prohibited,” employees can confidently determine the extent to which they may use AI in their work.

Step 5: Establish a Governance Process for Periodic Review

The environment surrounding generative AI is evolving rapidly in terms of technology, legal regulation, and social ethics. As a result, internal policies may become outdated within only a few months. Incorporating a mechanism for regular review into the operational framework is key to achieving effective governance

Specifically, the results of operational monitoring should be reviewed and the validity of the policies reassessed on a quarterly or semi-annual basis. During the review, it is important to examine whether there are any inconsistencies with the latest guidance issued by the government, including the Cabinet Office and the Ministry of Economy, Trade and Industry; whether there have been new court decisions concerning copyright in AI-generated content; and whether the terms of the AI services in use have changed.

Moreover, regular reviews should not be limited to the legal and IT departments. Establishing a review meeting that includes representatives from the workplace will help identify practical issues and prevent policies from becoming ineffective. When policies are updated as a result of a review, it is important to promptly communicate the changes and the reasons for them to all employees and provide further training where necessary. By continuing this cycle, the AI literacy of the entire organization can remain up to date.

Key Elements of Internal AI Policies for Effective Workplace Implementation

Effective internal AI regulations should not merely be a list of prohibitions. They must serve as a guide for employees when they are unsure how to proceed and function as a legal safeguard for the organization. The following four pillars should be included.

Clarifying Objectives and Scope to Build Consensus

At the beginning of the regulations, clearly state the objectives of introducing AI and the value the company aims to create. This sends a positive message encouraging employees to use AI while also providing a basis for preventing inappropriate use.

The scope of application should be clearly defined to include not only full-time employees, but also contract employees, temporary staff, and external contractors. In particular, when external contractors use AI to deliver work products, it is necessary to clarify at the contractual level where responsibility for quality control and rights management lies.

Mandating workplace education and strengthening legal protection

Simply distributing or posting internal regulations is not sufficient to fulfil supervisory responsibilities. Establish a system under which education and training on AI use are mandatory, and grant access to AI services only to employees who have completed the training. Proper management of training records is essential as evidence that the company provided appropriate supervision and education if an employee violates the rules and causes an incident.

Training should cover not only technical matters, such as prompt engineering, but also the nature of hallucinations, considerations under the copyright law, and specific examples of confidentiality obligations, using practical examples.

Specifying Permitted Services and Eradicating Shadow IT

Clearly state that only “approved services,” which the company has verified as secure and for which it has entered into appropriate contracts, may be used for business purposes. This helps systematically eliminate shadow IT involving personal accounts. In addition, by clarifying the application and approval process for new services or plugins, the company can respond flexibly to workplace needs while maintaining controlled implementation. As a risk-management measure, it is generally prudent to prohibit the use of free versions and limit use to corporate plans under which data is not used for training.

Proper Exercise of Monitoring and Audit Authority

To ensure appropriate operations within the organization, the regulations should state that the company has the authority to record and review employee prompts and output results and to conduct audits where necessary. This not only deters inappropriate use, but also plays an important role in investigating causes and limiting damage after an incident, such as an information leak. However, when monitoring is conducted, employees should be informed in advance of its purpose and scope in order to ensure transparency, which is vital to maintaining employee trust.

It is also important to consider how these provisions will be integrated with existing work rules, confidentiality agreements, and IT-use policies. While establishing AI-specific regulations, legal consistency should be ensured by linking them to existing rules so that serious violations may be subject to disciplinary measures under the work rules.

Conclusion: Establishing Internal AI Regulations to Maximize AI’s True Potential

To make AI a powerful organizational asset, the most important factors are not the budget for implementing the latest models, but rather the human management capabilities and organizational governance needed to use them effectively.

The five steps explained in this article are all essential for creating “living rules” that are embedded in the workplace. While a hands-off implementation may lead to temporary efficiency gains, sustainable growth depends on a genuine commitment to continuously balancing legal safety and convenience under Japanese law.

Legal services provided by our firm

Monolith Law Office has extensive experience in both IT, particularly internet-related matters, and law. AI business activities involve numerous legal risks, making support from lawyers familiar with AI-related legal issues indispensable. Through a team of lawyers and engineers with expertise in AI, the firm provides advanced legal support for businesses using technologies such as ChatGPT. Our services include contract drafting, assessing the legality of business models, protecting intellectual property rights, addressing privacy issues, and establishing internal AI regulations.

Managing Attorney: Toki Kawase

The Editor in Chief: Managing Attorney: Toki Kawase

An expert in IT-related legal affairs in Japan who established MONOLITH LAW OFFICE and serves as its managing attorney. Formerly an IT engineer, he has been involved in the management of IT companies. Served as legal counsel to more than 100 companies, ranging from top-tier organizations to seed-stage Startups.

Return to Top