Tel +852 5382 0328 info@safeharbour.hk WhatsApp 繁體中文
Safe Harbour Consultants · Hong Kong & Macau Get a Quote
AI governance

Does Hong Kong have an AI law? What actually applies in 2026

Hong Kong does not have a blanket AI statute. It has voluntary privacy guidance, sectoral supervisory expectations, one mandatory ordinance for critical infrastructure, and contract clauses doing most of the work.

Clients ask this question in almost the same words: do we need to comply with a Hong Kong AI law? The honest answer is that there is no single AI statute today. What exists is a set of obligations that arrive by different routes — and most organisations are already subject to at least one of them.

The five things that actually apply

InstrumentIssued byStatus
Model Personal Data Protection FrameworkPCPD, 11 June 2024Voluntary guidance
Checklist on Generative AI by EmployeesPCPD, 31 March 2025Voluntary guidance
Circular on GenAI in customer-facing applicationsHKMA, 19 August 2024Supervisory expectation
Circular on generative AI language modelsSFC, 12 November 2024Supervisory expectation
Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap. 653HKSAR, in force 1 January 2026Mandatory

Only the last of these is a statute, and it is not an AI law — it is a computer system security law. But if you are a designated critical infrastructure operator, or you supply one, it will drive your AI governance work whether you planned for it or not.

What this means for you

If you process personal data through AI, the PDPO already applies. If you are an authorised institution or a licensed corporation, HKMA and SFC expectations apply now. If you are a designated critical-infrastructure operator, Cap. 653 is mandatory. For everyone else, the trigger is usually commercial: a client questionnaire, an RFP, or a group audit.

What clients actually ask for

In practice the demand is not for a legal opinion. It is for three artefacts: an inventory of the AI systems in use, a risk and impact assessment for each, and a policy that tells staff what they may and may not do. Those three documents answer most questionnaires and most board questions.

Where organisations get caught out

  • Shadow AI: staff using tools nobody approved, with client data pasted into them.
  • Vendor claims: assuming a supplier's terms transfer the risk to the supplier.
  • No record: an assessment was done once, in a meeting, and cannot be produced.
  • Wrong scope: governing the model but not the workflow it sits inside.

Where to start

Start with the inventory. You cannot assess, govern or evidence what you have not written down. It is usually a two-week exercise, and it produces a document that is immediately useful.

Sources
PCPD, Artificial Intelligence: Model Personal Data Protection Framework, 11 June 2024 — pcpd.org.hk
PCPD, Checklist on Guidelines for the Use of Generative AI by Employees, 31 March 2025 — pcpd.org.hk
HKMA circular, 19 August 2024 — hkma.gov.hk
SFC circular 24EC55, 12 November 2024 — apps.sfc.hk
Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap. 653 — legco.gov.hk