Hong Kong has not enacted a horizontal AI statute and has no near-term legislative timetable to do so. That does not mean AI deployment in Hong Kong is unregulated. It means the binding obligations sit inside existing law and sector supervision rather than a single AI-specific regulation: the Personal Data (Privacy) Ordinance for any AI system touching personal data, ethics guidance from the Privacy Commissioner for Personal Data that shapes how that ordinance is interpreted, and circulars from the Hong Kong Monetary Authority and the Securities and Futures Commission for AI used in regulated financial services. This guide sets out what actually binds an operator in Hong Kong today, what remains guidance rather than law, and how the whole picture compares to the EU AI Act.
Key takeaways
- Hong Kong has no enacted, horizontal AI statute in 2026. Binding AI-relevant obligations run through the Personal Data (Privacy) Ordinance, Cap. 486, and sector-specific supervisory guidance rather than a single AI law.
- The Privacy Commissioner for Personal Data published a Guidance on the Ethical Development and Use of Artificial Intelligence in August 2021, setting seven ethical principles that shape how the PCPD interprets and enforces the Ordinance against AI-driven data processing, even though the guidance itself is not directly binding.
- The Hong Kong Monetary Authority and the Securities and Futures Commission have each issued AI-specific guidance for their regulated populations, covering consumer protection in AI-assisted decisions, generative AI governance, and senior management accountability, enforced through their existing supervisory powers.
- Hong Kong's model is sectoral and principles-based, closer in structure to Taiwan's draft Basic Act and Switzerland's supervisory-circular approach than to the EU AI Act's single harmonised regulation with mandatory conformity assessment and turnover-based penalties.
- An operator with an EU AI Act compliance programme will, in most respects, exceed what Hong Kong's current framework requires, but Hong Kong's data protection and financial-sector AI expectations are actively enforced and should be treated as a current compliance floor, not an aspiration.
Background: why Hong Kong has chosen a sectoral model
Hong Kong's regulatory tradition favours principles-based supervision delivered through existing sectoral regulators rather than new omnibus statutes, a pattern visible across its approach to data protection, financial technology, and now artificial intelligence. Rather than legislating a single AI statute that would need to define risk tiers, conformity procedures, and a new supervisory authority from scratch, Hong Kong has directed its existing regulators, principally the Office of the Privacy Commissioner for Personal Data (PCPD), the Hong Kong Monetary Authority (HKMA), and the Securities and Futures Commission (SFC), to issue AI-specific guidance within the scope of the powers they already hold. The Hong Kong government's Digital Policy Office has separately published guidance for the public sector's own use of generative AI, reflecting the same instinct: adapt existing structures rather than legislate a new one.
This approach produces a regulatory picture that looks lighter than the EU AI Act on paper, because there is no single statute an operator can point to as "the AI law." It does not mean Hong Kong is a light-touch jurisdiction in practice. The PCPD, HKMA, and SFC each have real enforcement powers under their existing legislative mandates, and each has shown a willingness to apply those powers to AI-specific conduct.
The binding floor: the Personal Data (Privacy) Ordinance
The most consequential binding statute for AI operators in Hong Kong is the Personal Data (Privacy) Ordinance, Cap. 486 (PDPO), first enacted in 1995 and amended several times since, including significant anti-doxxing amendments in 2021. The PDPO applies to any collection, holding, processing, or use of personal data by a data user in Hong Kong, and its application does not turn on whether the processing is performed by a human employee or an AI system. Its six data protection principles cover the purpose and manner of collection, data accuracy and retention, the use of data, data security, openness about data policies, and an individual's right of access and correction.
For an AI operator, the practical implication is direct: any customer-facing or employment-facing AI agent that processes personal data of individuals in Hong Kong is already subject to a binding, enforceable statute regardless of whether a dedicated AI law is ever passed. The PCPD investigates complaints, can issue enforcement notices, and non-compliance with an enforcement notice is a criminal offence under the Ordinance. Operators should treat PDPO compliance, not the PCPD's non-binding AI ethics guidance, as the current legal floor, with the ethics guidance functioning as the interpretive lens the PCPD applies when an AI-related complaint reaches it.
The PCPD's ethical AI guidance and how it is actually used
In August 2021, the PCPD published its Guidance on the Ethical Development and Use of Artificial Intelligence, setting out seven core principles: accountability, human oversight, transparency and interpretability, data privacy, fairness, beneficial AI, and reliability, robustness and security. The guidance recommends organisations establish an AI strategy, conduct risk assessments before deployment, and maintain human oversight proportionate to the AI system's risk. It is explicitly framed as guidance rather than binding law, and it does not create standalone offences or penalties.
Its practical force comes from two directions. First, the PCPD applies the guidance's principles when it exercises its existing PDPO enforcement powers over AI-driven personal data processing, meaning a company that ignored the guidance's recommended safeguards is in a materially weaker position if a PDPO complaint is investigated. Second, the guidance functions as a de facto governance benchmark that Hong Kong-based enterprises, particularly those with cross-border operations into mainland China or into markets with binding AI statutes, increasingly adopt voluntarily as a documented standard. Operators building an AI governance programme for Hong Kong should treat the seven principles as the practical specification even though the PDPO, not the guidance, is what carries statutory force.
Financial sector guidance: the HKMA and the SFC
Hong Kong's financial regulators have been the most active in issuing AI-specific expectations, consistent with the sectoral pattern. The Hong Kong Monetary Authority has issued guidance addressing consumer protection in the use of big data analytics and artificial intelligence by authorized institutions, covering fairness, transparency, and accountability in AI-assisted decisions such as credit scoring and product recommendations, and has extended its supervisory guidance into generative AI adoption, setting expectations for governance, model risk management, and data security specific to large language model deployments in banking.
The Securities and Futures Commission has issued a circular addressing the use of generative AI language models by licensed corporations, requiring senior management to remain accountable for AI-assisted research, advice, and client communications, and setting expectations for data governance, model validation, and disclosure where generative AI materially contributes to investment advice or research output given to clients. Both regulators apply these expectations through their existing supervisory and enforcement powers over authorized institutions and licensed corporations respectively, meaning non-compliance carries the same practical consequences, supervisory intervention, remediation orders, and in serious cases licence conditions, as non-compliance with any other supervisory circular.
Financial institutions and fintech operators deploying AI agents that touch credit decisions, investment research, or client advice in Hong Kong should treat HKMA and SFC guidance as a live, binding-in-practice compliance expectation today, independent of whether a horizontal AI statute is ever enacted, in the same way Singapore's MAS FEAT principles operate through existing financial supervision rather than a dedicated AI licence.
Comparison with the EU AI Act
Set against the EU AI Act, Hong Kong's position combines two features operators should hold separately. First, there is no enacted, horizontal AI statute, no risk-tiered classification system comparable to Annex III, no mandatory conformity assessment, and no turnover-based penalty regime comparable to Article 99 of Regulation (EU) 2024/1689. Second, there is already a functioning, binding data protection statute with real enforcement powers, and two of Hong Kong's most significant financial regulators are actively applying AI-specific guidance within their existing supervisory authority. The combined effect is a jurisdiction that looks less regulated than the EU on paper but is not unregulated in practice for the AI use cases carrying the most real-world risk: personal data processing and financial services decisions.
Extraterritorial reach runs asymmetrically, as it does for most non-EU jurisdictions in this network. The EU AI Act's Article 2 scope applies in full to any operator placing AI systems on the EU market or whose AI output is used in the EU, regardless of a Hong Kong operator's domestic regulatory position. There is no equivalent extraterritorial reach running from Hong Kong's current framework back toward EU-based operators. A cross-border operator's EU compliance obligations are not reduced by strong Hong Kong governance, and Hong Kong compliance obligations are not created by an operator's EU AI Act programme; the two run on separate tracks that overlap substantially in substance, particularly around data governance and human oversight, but not in legal force.
Practical implications for operators
Four steps are proportionate for an operator active in Hong Kong in 2026. First, treat PDPO compliance as the binding floor for any AI system processing personal data of individuals in Hong Kong, and confirm your data governance documentation would satisfy a PCPD enforcement notice, not just an internal privacy policy. Second, adopt the PCPD's seven ethical AI principles as your practical governance specification even though they are not directly binding, since they are what the PCPD applies when a complaint is investigated and what an increasing number of Hong Kong counterparties expect to see documented. Third, if operating in or selling into Hong Kong's financial sector, map your AI governance programme against the relevant HKMA or SFC guidance directly, since this is the most concrete, currently enforced AI-specific expectation in the jurisdiction. Fourth, where an EU AI Act or ISO/IEC 42001 governance programme already exists, use its documentation as the backbone for Hong Kong, since the substantive principles, accountability, human oversight, transparency, fairness, largely overlap even though the legal force and enforcement architecture differ.
For a comparison of a similarly sectoral, principles-based approach, see the Singapore AI governance guide. For the mainland Chinese framework Hong Kong operates alongside under a distinct legal system, see the China CAC generative AI measures guide. For the EU deployer obligations that remain the highest-stringency benchmark against which any sectoral regime is measured, see the Article 26 deployer obligations guide on agentliability.eu.
Related reading
For the wider Asia-Pacific regional context this guide sits within, see Asia-Pacific AI governance in 2026. For a jurisdiction with a similarly principles-first, sectoral posture, see the Switzerland AI governance guide. For the global status tracker that places Hong Kong alongside every other jurisdiction covered in this network, see the Global AI Regulation Status Tracker 2026.
Frequently asked questions
Does Hong Kong have a dedicated AI law in 2026?
No. Hong Kong has not enacted a horizontal AI-specific statute comparable to the EU AI Act. AI-relevant obligations instead run through the Personal Data (Privacy) Ordinance, Cap. 486, enforced by the Privacy Commissioner for Personal Data, plus non-binding ethical guidance from the same regulator and sector-specific circulars from the Hong Kong Monetary Authority and the Securities and Futures Commission. Hong Kong's approach is principles-based and sectoral rather than a single risk-tiered regulation.
What did the Privacy Commissioner for Personal Data publish on AI?
The PCPD published its Guidance on the Ethical Development and Use of Artificial Intelligence in August 2021, setting out seven ethical principles for organisations developing or using AI: accountability, human oversight, transparency and interpretability, data privacy, fairness, beneficial AI, and reliability, robustness and security. The guidance is not legally binding in itself, but it sets the interpretive baseline the PCPD applies when it investigates a complaint that AI-driven personal data processing breached the Personal Data (Privacy) Ordinance.
Do Hong Kong's financial regulators have AI-specific requirements?
Yes, applied through existing supervisory powers rather than a new licence. The Hong Kong Monetary Authority has issued guidance addressing the use of AI and big data analytics by authorized institutions, including consumer protection expectations for AI-assisted decisions, and has extended this into guiding principles for generative AI adoption in banking. The Securities and Futures Commission issued a circular addressing the use of generative AI language models by licensed corporations, covering governance, data security and senior management accountability for AI-assisted advice and research.
How does Hong Kong's approach compare to the EU AI Act?
Hong Kong has chosen a sectoral, principles-based model: existing regulators apply AI-specific guidance within their own supervisory powers rather than a single horizontal statute with a risk-tiered classification system, mandatory conformity assessment, and a turnover-based penalty regime. This is structurally closer to the United Kingdom's original sectoral approach than to the EU AI Act. An operator with an EU AI Act compliance programme will, in most respects, exceed what Hong Kong's current framework requires, though Hong Kong's data protection and financial-sector AI expectations are actively enforced and should not be treated as aspirational.
Does the Personal Data (Privacy) Ordinance apply to AI systems in Hong Kong?
Yes. The Personal Data (Privacy) Ordinance, Cap. 486, applies to any collection, holding, processing or use of personal data by data users in Hong Kong, including personal data processed by an AI system. Its six data protection principles, covering collection purpose and manner, accuracy and retention, use, security, openness, and access and correction, apply to AI-driven processing in the same way they apply to any other processing activity. This is the current binding floor for AI governance in Hong Kong, independent of whether a dedicated AI statute is ever enacted.
References
- Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD). Guidance on the Ethical Development and Use of Artificial Intelligence, published August 2021.
- Personal Data (Privacy) Ordinance, Cap. 486 (Hong Kong), enacted 1995, substantially amended including the 2021 anti-doxxing amendments. Six data protection principles governing collection, accuracy, use, security, openness, and access.
- Hong Kong Monetary Authority (HKMA). Guidance on consumer protection in respect of the use of big data analytics and artificial intelligence by authorized institutions, and supervisory guidance on generative AI adoption in banking.
- Securities and Futures Commission (SFC), Hong Kong. Circular on the use of generative AI language models by licensed corporations, covering governance, data security, and senior management accountability.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), for comparison, including Article 2 (extraterritorial scope), Articles 9 to 17 (high-risk obligations), Article 26 (deployer obligations), and Article 99 (penalties).
- Hong Kong Government Digital Policy Office. Guidance on the use of generative AI within the Hong Kong public sector.