Clients ask this question in almost the same words: do we need to comply with a Hong Kong AI law? The honest answer is that there is no single AI statute today. What exists is a set of obligations that arrive by different routes — and most organisations are already subject to at least one of them.
The five things that actually apply
| Instrument | Issued by | Status |
|---|---|---|
| Model Personal Data Protection Framework | PCPD, 11 June 2024 | Voluntary guidance |
| Checklist on Generative AI by Employees | PCPD, 31 March 2025 | Voluntary guidance |
| Circular on GenAI in customer-facing applications | HKMA, 19 August 2024 | Supervisory expectation |
| Circular on generative AI language models | SFC, 12 November 2024 | Supervisory expectation |
| Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap. 653 | HKSAR, in force 1 January 2026 | Mandatory |
Only the last of these is a statute, and it is not an AI law — it is a computer system security law. But if you are a designated critical infrastructure operator, or you supply one, it will drive your AI governance work whether you planned for it or not.
What this means for you
If you process personal data through AI, the PDPO already applies. If you are an authorised institution or a licensed corporation, HKMA and SFC expectations apply now. If you are a designated critical-infrastructure operator, Cap. 653 is mandatory. For everyone else, the trigger is usually commercial: a client questionnaire, an RFP, or a group audit.
What clients actually ask for
In practice the demand is not for a legal opinion. It is for three artefacts: an inventory of the AI systems in use, a risk and impact assessment for each, and a policy that tells staff what they may and may not do. Those three documents answer most questionnaires and most board questions.
Where organisations get caught out
- Shadow AI: staff using tools nobody approved, with client data pasted into them.
- Vendor claims: assuming a supplier's terms transfer the risk to the supplier.
- No record: an assessment was done once, in a meeting, and cannot be produced.
- Wrong scope: governing the model but not the workflow it sits inside.
Where to start
Start with the inventory. You cannot assess, govern or evidence what you have not written down. It is usually a two-week exercise, and it produces a document that is immediately useful.