Israel is one of the world's most concentrated technology and AI ecosystems by output per capita. It hosts hundreds of AI companies, a mature deep tech investment market, and a government that has actively promoted AI development through the Israel Innovation Authority and the Israeli National AI Program. What Israel does not have in 2026 is an AI statute. AI governance operates instead through the Privacy Protection Law, through a small number of sector instruments that reach AI models by their own terms, and through a government policy document that chose sectoral regulation over a horizontal law. For operators deploying AI in Israel or exporting AI to EU markets from Israel, the regulatory picture is distinct from any other jurisdiction covered in this series. This guide explains the architecture, the obligations that are real, and what EU regulatory exposure looks like for Israeli AI companies.
Key takeaways
- Israel has no AI statute equivalent to Regulation (EU) 2024/1689. The binding instruments that reach AI-related data processing are the Privacy Protection Law 5741-1981, amended by Amendment No. 13 with effect from 14 August 2025, and the Privacy Protection Regulations (Data Security) 5777-2017, in force since May 2018, both enforced by the Privacy Protection Authority (Reshut HaGanat HaPratiyut).
- The EU AI Act reaches Israeli companies on two routes. Article 2(1)(a) covers providers placing AI systems on the Union market irrespective of where they are established, and Article 2(1)(c) covers providers and deployers in a third country where the output produced by the AI system is used in the Union. This is the most significant compliance exposure for Israeli AI exporters in 2026.
- Israel holds an EU adequacy decision, Commission Decision 2011/61/EU of 31 January 2011, covering automated international transfers. The Commission reviewed it with ten other pre-GDPR decisions in a report of 15 January 2024 and concluded that Israel continues to provide an adequate level of protection. Adequacy is a data protection finding and says nothing about the AI Act.
- One Israeli sector instrument reaches AI models by its own terms. Bank of Israel Proper Conduct of Banking Business Directive 369, Management of Model Risk, of 21 August 2024, states that all of its provisions also apply to models that use or rely on artificial intelligence, and names bias, accountability, controls and explainability as risks to be managed.
- Israel adheres to the OECD AI Principles, adopted in 2019 and updated in May 2024, and signed the Council of Europe Framework Convention on Artificial Intelligence (CETS No. 225) on 5 September 2024. Signature is not ratification, and Israel has not ratified. Neither instrument creates a directly enforceable duty on an Israeli operator today.
The regulatory architecture: no horizontal AI law, but layered governance
Israel's regulatory architecture for AI in 2026 differs from every jurisdiction covered in this series. Unlike the EU, which operates a comprehensive horizontal regulation, unlike the UK, which operates a sector-based model with named regulator responsibilities, and unlike the US, which operates a fragmented federal plus state system, Israel operates a combination of general privacy law, banking supervision that reaches AI models by its own terms, and government policy that binds nobody in the private sector. There is no dedicated AI supervisory authority, no mandatory AI registration or notification system, and no AI-specific penalty framework.
This does not mean the governance landscape is empty. Three distinct layers apply in practice. The first is general privacy law, which is binding and enforced. The second is banking supervision, where the Bank of Israel has extended its model risk directive to AI models in terms that bind supervised banking corporations. The third is government policy, which is not binding on private operators at all: a policy document of December 2023, a national programme published in 2024, a guide for the public sector issued for consultation in 2025, and an interagency report on AI in finance published in December 2025.
The distinction between those layers matters, because the third is where most published summaries of Israeli AI regulation quietly go wrong. Policy documents that recommend, map and advise are read back as if they created duties. They did not. The December 2025 interagency report on AI in finance states the position in one line: in Israel, as of now, no legally binding definition for the term artificial intelligence has been set.
For operators assessing Israel's compliance burden in isolation, the picture is less demanding than the EU or Korea. For Israeli AI companies with EU market exposure, the dominant compliance obligation is not domestic at all: it is the EU AI Act's extraterritorial application, which applies regardless of where the AI company is incorporated.
The Privacy Protection Law and its application to AI
Israel's Privacy Protection Law 5741-1981 is the foundational instrument governing the collection, use, storage, and transfer of personal information in Israel. The law predates the internet, but has been updated through regulations and official interpretations to address digital information processing. The Privacy Protection Regulations (Data Security) 5777-2017, which came into force in May 2018, classify databases into four risk categories, high, medium, basic, and databases managed by an individual with access for no more than three people, and scale the security duties of the controller to the category.
The Privacy Protection Authority describes its own remit as covering all entities in Israel, private, business and public, that hold or process personal digital information. An AI system that processes personal information about individuals in Israel therefore engages the Law through the ordinary route, as a database, rather than through anything AI-specific.
The most significant recent change is Amendment No. 13 to the Privacy Protection Law, which entered into force on 14 August 2025. The Authority's own Guidance No. 1/2024 describes it as establishing a new category of data types defined as data with special sensitivity, a category that affects the financial sanctions imposed for violations of the Law or the Regulations, the obligation to appoint a data protection officer, and the requirement to notify the Privacy Protection Authority regarding large and sensitive databases. An operator that structured its Israeli compliance around the old registration picture is working from a superseded map.
What the Authority has not done is publish AI-specific guidance. Its published guidelines cover the right of access, surveillance cameras, workplace surveillance, outsourcing of personal data processing, recruitment, direct mailing and foreclosure data. There is no guideline on artificial intelligence, on automated decision-making, or on web scraping. An operator looking for an Israeli regulator's view of how privacy law applies to model training will not find a published one, and should reason from the general duties in the Law and the 2017 Regulations instead.
Israel holds an EU adequacy decision. Commission Decision 2011/61/EU of 31 January 2011 found that Israel provides an adequate level of protection for personal data transferred from the European Union in relation to automated international transfers. The decision survived the move to the GDPR, and the Commission reviewed it together with ten other pre-GDPR decisions in a report of 15 January 2024, concluding that each of the eleven countries and territories continues to ensure an adequate level of protection, while recommending that Israel codify protections currently developed through sub-legislative channels and case law. Adequacy removes the need for standard contractual clauses on EU to Israel transfers. It says nothing about AI governance and does not touch the AI Act's application to Israeli providers.
Sector supervision: banking model risk, and the limits of the rest
One Israeli sector instrument reaches AI directly and by name. The Bank of Israel's Supervisor of Banks issued Proper Conduct of Banking Business Directive 369, Management of Model Risk, on 21 August 2024. Its scope provision is explicit: all the provisions of this directive also apply to models that include the use or reliance on artificial intelligence. The directive observes that AI models bring efficiency and quality gains but are liable to expose banking corporations to new risks or amplify existing ones.
The duties it creates are the ones an operator would expect from a model risk regime rather than from an AI-specific one. Banks must validate models so that they function as expected, according to the objectives and business uses for which they were designed, across conceptual soundness, ongoing monitoring and outcomes analysis. They must maintain documentation of development and validation sufficient to let someone unfamiliar with a model understand how it works, its limitations and its main assumptions. The board of directors outlines the strategy for model risk management, sets the risk appetite and approves the policy formulated by senior management.
Where the directive turns AI-specific, it names the risks rather than prescribing the method. It asks banks to address reliability and fairness of the models in terms of bias or discrimination, accountability adapted to AI models taking into account the degree and manner of human involvement, the design of controls in decision-making mechanisms based on those models, and transparency with an emphasis on the ability to explain the results achieved. It also asks that full disclosure be maintained so that the rights of those affected by the model to receive information and to appeal the results are not diminished. Models are used in credit underwriting among other activities, but the directive sets no credit-specific validation regime beyond the general one, and it does not impose a customer-facing explanation duty in the way the EU AI Act does for deployers.
Beyond banking, the picture is thinner than most summaries suggest. An interagency taskforce on AI in finance, whose participants included the Ministry of Justice, the Ministry of Finance, the Banking Supervision Department, the Capital Market, Insurance and Savings Authority, the Israel Securities Authority and the Competition Authority, published its final report in December 2025. The report does not announce new binding rules. It identifies the key areas for which the need to update regulation should be examined, naming model risk management, explainability, and notification and disclosure, and it declines to propose detailed prescriptive regulation at this stage. For insurance, pensions and provident funds, there is no published AI circular from the Capital Market, Insurance and Savings Authority to comply with. For health, the Ministry of Health publishes its director general circulars in Hebrew only and no AI circular could be read at source, so an operator in Israeli health technology should obtain the applicable circular directly from the Ministry rather than rely on any secondary description of it, this one included.
The policy layer: what the government has actually published
The document that sets Israel's regulatory direction is not a statute and does not pretend to be one. In December 2023 the Ministry of Innovation, Science and Technology, working with the Office of Legal Counsel and Legislative Affairs at the Ministry of Justice, published Responsible Innovation: Israel's Policy on Artificial Intelligence Regulation and Ethics. It recommends empowering sector-specific regulators, fostering international interoperability, adopting a risk-based approach, encouraging incremental development, using soft regulation and promoting multistakeholder cooperation, and it proposes an inter-agency body to advise sectoral regulators. On the central question it is unambiguous: this approach is favoured over the adoption of broad horizontal legislation, though the need for horizontal legislation should be assessed periodically, as the challenges evolve and experience is accumulated.
The industrial arm sits separately. The Israeli National AI Program, described by the Israel Innovation Authority as a collaborative, holistic and cross-ministerial effort to secure Israel's long-term leadership in AI, published its 2024 programme document in November 2024, with Dr Ziv Katzir as director of the national policy and Prof Yoav Shoham heading the scientific advisory committee. Its stated aim is to balance technological advancement with ethical, human-centric and safe practices. It is a capability programme, not a compliance regime.
The most recent addition is aimed at the state itself, not at industry. In June 2025 the Israel National Digital Agency, with the Ministry of Justice and the AI Policy and Regulation Center at the Ministry of Innovation, Science and Technology, issued for public consultation a Guide to Risk Management and Responsible Use of Artificial Intelligence Tools in the Public Sector, open for comment until 31 July 2025. It is designed for public sector bodies looking to incorporate AI in their operations and in the processes they manage. It does not bind private operators.
Internationally, Israel adheres to the OECD AI Principles, adopted in 2019 and updated in May 2024, and it signed the Council of Europe Framework Convention on Artificial Intelligence (CETS No. 225) on 5 September 2024, the day the treaty opened for signature at Vilnius. Israel has not ratified it. As of 17 August 2026 the Convention carried twenty signatures without ratification and a single ratification, by the European Union on 15 May 2026. For an operator, the practical reading is that neither instrument is a source of enforceable duty in Israel today, and that a signature is a statement of direction rather than a commencement date.
For private sector operators, then, the policy layer creates no binding compliance obligations. Its relevance is in three places: government procurement of AI systems, where alignment may become a qualification criterion; eligibility for Israel Innovation Authority support, where responsible AI commitments may be assessed; and commercial due diligence, where enterprise customers and investors increasingly ask which voluntary framework a supplier follows. It functions much as Australia's Voluntary AI Safety Standard does, as the government's position on good practice with no enforcement machinery behind it.
The EU AI Act and Israeli operators: extraterritorial exposure
The single most significant AI regulatory obligation for Israeli AI companies in 2026 is not domestic. It is the EU AI Act's extraterritorial application to Israeli providers whose AI systems are placed on the Union market, and to Israeli providers and deployers whose system output is used in the Union.
Article 2(1)(a) of Regulation (EU) 2024/1689 applies the regulation to providers placing on the market or putting into service AI systems, or placing on the market general purpose AI models, in the Union, irrespective of whether those providers are established or located within the Union or in a third country. Article 2(1)(c) reaches further: it covers providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union. The second route is the one Israeli operators tend to miss, because it does not depend on selling anything into Europe. It depends on where the output lands. The obligations that follow for providers include technical documentation under Article 11, transparency and provision of information to deployers under Article 13, post-market monitoring under Article 72, and reporting of serious incidents under Article 73.
For high-risk AI systems as defined in Article 6 and Annex III of the EU AI Act, the obligations are significantly more demanding. High-risk AI used in employment, credit, insurance, medical devices, critical infrastructure, or biometric identification must undergo conformity assessment before being placed on the EU market, must comply with the risk management, data governance, accuracy, and human oversight requirements in Articles 9 through 15, and must carry CE marking issued by a notified body or through a self-declaration conformity assessment. Article 22 of the Regulation is headed authorised representatives of providers of high-risk AI systems, and a provider established outside the Union should read it early rather than late.
Timing has moved, and in the direction of more room rather than less. The Digital Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744. Annex III high-risk obligations now apply from 2 December 2027 and Annex I from 2 August 2028. The Article 5 prohibitions, the Article 50 transparency duties, the general purpose AI obligations and the Article 4 AI literacy duty were not deferred and have applied since 2 August 2026. An Israeli operator whose product is not high-risk should not read the deferral as breathing room, because the parts that already bite are the parts most likely to catch a conversational or generative product.
The practical implication for Israeli AI companies with EU revenue is that EU AI Act compliance is not optional. Under Article 99, breaches of the prohibited practices in Article 5 carry up to EUR 35 million or 7 per cent of worldwide annual turnover, whichever is higher. Breaches of other operator obligations, which is where provider and deployer duties on high-risk systems sit, carry up to EUR 15 million or 3 per cent. Supplying incorrect, incomplete or misleading information to authorities carries up to EUR 7.5 million or 1 per cent. Lower figures apply to SMEs and start-ups. Israeli export-focused AI companies should treat the EU AI Act as a product compliance requirement analogous to the CE marking requirements that already apply to medical devices and safety-critical products they export to Europe. For a full analysis of what the EU regulatory framework requires, see the EU AI Act operator obligations guide at agentliability.eu.
What Israel does not have
A jurisdiction guide is more useful when it is explicit about absence, because absence is what an operator is buying certainty about. On checks made on 17 August 2026 at the relevant Israeli official domains, there is no AI statute, no AI supervisory authority, no register of AI systems, no conformity assessment or marking regime for AI, and no AI-specific penalty tier. The Privacy Protection Authority's published guidelines do not include one on artificial intelligence, automated decision-making or web scraping. No AI circular from the Capital Market, Insurance and Savings Authority could be found at its own department page. The Israel National Cyber Directorate's landing page lists alerts, advisories and an annual report, and no AI security guidance could be read there.
Absence of published guidance is not absence of supervision, and it should not be read as licence. The Privacy Protection Authority conducts criminal investigations, administrative investigations and audits, imposes administrative fines, and holds the power to suspend or erase a database's registration. A supervised bank deploying an AI model is inside Directive 369 whether or not anyone has written an AI circular. What is missing is not enforcement capacity. It is the AI-specific rulebook that operators arriving from the European framework expect to find and do not.
Operator obligations: a summary
For an operator deploying AI in Israel, the practical compliance picture organises around three questions. First, does the AI system process personal information about people in Israel? If yes, the Privacy Protection Law applies through the database route, together with the data security duties in the 2017 Regulations at the level matching the database's risk category, and with the Amendment No. 13 changes in force since 14 August 2025, including the data protection officer obligation and the duty to notify the Authority about large and sensitive databases. Second, is the operator a supervised banking corporation, or supplying models into one? If yes, Directive 369 applies, with validation, documentation and board level ownership of model risk. Third, does the system reach the Union market, or is its output used in the Union? If yes, the EU AI Act applies regardless of Israeli domestic requirements, and for high-risk systems that means conformity assessment, CE marking and technical documentation to the EU standard.
For operators deploying AI from Israel without EU market exposure, the domestic compliance burden in 2026 is comparatively limited. Whether that window narrows is a matter of published intent rather than prediction. The December 2023 policy says the need for horizontal legislation should be assessed periodically, the December 2025 interagency report names model risk management, explainability, and notification and disclosure as the areas where the need to update regulation should be examined, and Israel's signature of CETS No. 225 in September 2024 points in the same direction without yet binding anyone. None of that is a commencement date, and an operator should not plan against one.
Penalties and enforcement
Enforcement of Israel's AI-relevant obligations operates through existing mechanisms rather than AI-specific penalty regimes. The Privacy Protection Authority describes its own toolkit plainly: the Registrar conducts criminal investigations, administrative investigations and audits, the Authority imposes administrative fines, and it holds the power to terminate or suspend the activities of databases by suspending or erasing their registration. Amendment No. 13 raised the stakes rather than changing the instruments, by creating the category of data with special sensitivity that feeds into the level of financial sanction for breaches of the Law or the Regulations. The specific sanction amounts are set out in the Law as amended and should be read there.
Sector enforcement runs through the supervisor rather than through an AI regulator. For banking corporations, Directive 369 sits within the Proper Conduct of Banking Business framework and is supervised by the Supervisor of Banks with the ordinary supervisory toolkit. There is no AI-specific financial penalty in Israeli law, in banking or anywhere else.
For EU AI Act breaches by Israeli companies, the penalties in Article 99 are imposed by national market surveillance authorities in the member states, not by a central body. An Israeli company with no physical EU presence but caught by the Act's extraterritorial scope faces the same penalty framework as an EU-established one, and pressure in practice arrives through market access for EU-bound products and services rather than through a summons.
How Israel's approach compares to the EU AI Act
Israel's AI governance approach in 2026 is principles-based and sector-grounded rather than horizontal and prescriptive. The contrast with the EU AI Act's structure is significant. Where the EU AI Act classifies AI systems by risk level and assigns mandatory obligations to each class, Israel applies existing law to AI use cases without classification. Where the EU AI Act requires conformity assessment and CE marking for high-risk AI, Israel has no equivalent product-approval mechanism for AI. Where the EU AI Act creates a public database of registered high-risk AI systems, Israel has no such registry.
The practical effect is that an operator moving AI into the Israeli market from an EU AI Act compliance baseline will have documentation, governance, and oversight infrastructure that substantially exceeds what Israeli domestic law requires. The documentation challenges run the other direction: an Israeli AI company attempting to enter the EU market must build EU AI Act compliance infrastructure from a baseline where no equivalent domestic requirements have created the habit of technical documentation and conformity assessment. For Israeli AI companies expanding into Europe, EU AI Act compliance is therefore the primary regulatory investment, and building it proactively rather than reactively is the commercially rational approach. For a comparison with the UK's sector-based model, see the UK AI regulation guide. For the NIST AI RMF as a voluntary governance baseline that Israeli companies can use to structure their international compliance, see the NIST AI RMF analysis.
Frequently asked questions
Does Israel have a comprehensive AI law equivalent to the EU AI Act?
No. As of August 2026 Israel has no AI statute. AI governance operates through the Privacy Protection Law 5741-1981, through Bank of Israel Directive 369 on model risk for supervised banks, and through a December 2023 government policy that states the sectoral approach is favoured over the adoption of broad horizontal legislation.
Does the EU AI Act apply to Israeli AI companies?
Yes, where the conditions for extraterritorial application are met. Article 2(1)(a) of Regulation (EU) 2024/1689 covers providers placing AI systems on the Union market irrespective of establishment, and Article 2(1)(c) covers providers and deployers located in a third country where the output produced by the AI system is used in the Union. Israeli companies serving European markets are in scope on one route or the other.
How does Israel's Privacy Protection Law apply to AI systems?
It applies through the database route rather than through anything AI-specific. The Privacy Protection Authority regulates all entities in Israel, private, business and public, that hold or process personal digital information, and the 2017 Data Security Regulations scale duties to four risk categories. Amendment No. 13 has applied since 14 August 2025. The Authority has published no guideline on artificial intelligence, automated decision-making or web scraping.
What is the Israel Innovation Authority's role in AI governance?
The Israel Innovation Authority hosts the Israeli National AI Program, a cross-ministerial effort to secure Israel's long-term leadership in AI. Its role is promotional and advisory rather than regulatory. It does not issue binding compliance requirements, conduct enforcement, or operate a registration regime for AI systems. Its relevance to operators is funding eligibility and public procurement.
How does Israel's AI regulatory approach compare to the EU AI Act?
Israel's approach is principles-based and sector-specific without a horizontal AI statute, no AI risk classification system, no mandatory conformity assessment, and no AI-specific penalty framework. An operator meeting EU AI Act requirements will substantially exceed Israeli domestic obligations. The dominant compliance risk for Israeli AI exporters is the EU AI Act's extraterritorial application to their EU-market activities.
References
- Privacy Protection Law 5741-1981 (Israel). Primary data protection statute, enforced by the Privacy Protection Authority (Reshut HaGanat HaPratiyut), which describes its powers of criminal and administrative investigation, administrative fines and suspension or erasure of database registration at gov.il/en/departments/about/about_ppa.
- Privacy Protection Regulations (Data Security) 5777-2017, in force May 2018. Four risk categories: high, medium, basic, and databases managed by an individual with access for no more than three people. gov.il/en/pages/data_security_eng.
- Privacy Protection Authority Guidance No. 1/2024, The Role of the Board of Directors. Records that Amendment No. 13 to the Privacy Protection Law enters into force on 14 August 2025 and creates the category of data with special sensitivity, affecting financial sanctions, the data protection officer obligation and notification of large and sensitive databases. gov.il, Role_of_the_Board.pdf.
- Commission Decision 2011/61/EU of 31 January 2011 on the adequate protection of personal data by the State of Israel with regard to automated processing of personal data. eur-lex.europa.eu, CELEX 32011D0061.
- European Commission, COM(2024) 7 final, 15 January 2024, first review of the eleven adequacy decisions adopted under Directive 95/46/EC. Concludes that each of the eleven, Israel included, continues to ensure an adequate level of protection. eur-lex.europa.eu, CELEX 52024DC0007.
- Regulation (EU) 2024/1689 (EU AI Act), Articles 2(1)(a) and 2(1)(c), 6, 9 to 15, 11, 13, 22, 72, 73 and 99, and Annex III. Article headings and text as published by the European Commission AI Act Service Desk, ai-act-service-desk.ec.europa.eu.
- Regulation (EU) 2026/1744, the Digital Omnibus, in force 27 July 2026. Annex III high-risk obligations apply from 2 December 2027, Annex I from 2 August 2028. Article 5, Article 50, the general purpose AI obligations and Article 4 were not deferred.
- Bank of Israel, Supervisor of Banks, Proper Conduct of Banking Business Directive 369, Management of Model Risk, 21 August 2024. States that all provisions apply to models that use or rely on artificial intelligence. boi.org.il, 369_en.pdf.
- Responsible Innovation: Israel's Policy on Artificial Intelligence Regulation and Ethics. Ministry of Innovation, Science and Technology with the Ministry of Justice, December 2023. gov.il/en/departments/policies/ai_2023.
- Israel National AI Program 2024, published November 2024, and the Israeli National AI Program hosted by the Israel Innovation Authority at innovationisrael.org.il.
- Guide to Risk Management and Responsible Use of Artificial Intelligence Tools in the Public Sector. Israel National Digital Agency with the Ministry of Justice and the AI Policy and Regulation Center at the Ministry of Innovation, Science and Technology, public consultation draft, June 2025, comments to 31 July 2025. Applies to public sector bodies. gov.il/en/pages/ai-guide.
- AI in the Financial Sector, final report of Israel's interagency taskforce on AI in finance, December 2025. Records that no legally binding definition of artificial intelligence has been set in Israel, and names model risk management, explainability, and notification and disclosure as the areas where the need to update regulation should be examined. gov.il, AI in the Financial Sector, December 2025.
- OECD AI Principles, adopted 2019 and updated in May 2024. Israel is listed among the adherents. oecd.ai/en/ai-principles.
- Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225), opened for signature at Vilnius on 5 September 2024. Israel signed on 5 September 2024 as a non-member state and has not ratified. The European Union ratified on 15 May 2026. Chart of signatures and ratifications, status at 17 August 2026.