Hong Kong Generative AI Governance Guideline (2025)
Tags: Regulatory, Frameworks
TL;DR
- HKSAR’s Digital Policy Office commissioned HKGAI to publish a practical governance and implementation guide for generative AI.
- Sets out risk tiers, five governance dimensions, lifecycle controls, and role-specific duties for developers, providers, and users.
Why it matters for HK marketers: This is the reference playbook your AI marketing workflows must align with to stay compliant and protect brand trust in Hong Kong.
Scope and authorship
- Owner: Digital Policy Office (DPO) of the HKSAR Government.
- Authoring body: Hong Kong Generative AI Research and Development Center (HKGAI), established under InnoHK funding.
- Audience: Technology Developers, Service Providers, Service Users.
- Update cadence: DPO will review tech and applications and update the Guideline regularly.
What it covers
- Technical limits and risks: Hallucination, bias, black-box opacity, weak reasoning, input sensitivity, and data integrity issues.
- Service-derived risks: Content safety, fabrication of rumours, model jailbreaking, data leaks.
- Lifecycle + oversight: 4 stages (planning, development, deployment, usage) and proportional human oversight.
- Governance structures: Four-tier risk classification, five governance dimensions, and key principles (compliance, transparency, accuracy, fairness, practicality).
- Role matrix: Duties for developers (ethical build, safeguards), providers (privacy, accountability), users (verification, control).
Risk and compliance architecture
- Four-tier risk framework: Unacceptable (prohibited), High (conformity + HITL + monitoring), Limited (transparency, opt-outs, audits), Low (self-certification).
- Privacy and IP: Anchored to HK laws including PDPO (Cap. 486); stresses lawful basis, data minimisation, and IP respect across training and outputs.
- Traceability: Irremovable watermarks/embedded codes for high-risk content (deepfakes, ID documents, financial materials).
Implementation expectations
- Data governance: Validation, versioning, audits; enhanced controls in sensitive sectors; transparent data source disclosures where feasible.
- Reliability controls: RAG for factual grounding; provider-side fact-check tools; content labelling.
- Service operations: Secure deployment choices (cloud/on-prem/on-device), access control, interoperability (open APIs, secure data-sharing).
- User data: Logging only with consent; encryption/desensitisation in transit and storage.
Version 1.1, published December 2025.
4-tier risk classification system defined.
3 stakeholder categories specified (Developers, Service Providers, Service Users).
So what for marketers
Codify this Guideline into your AI policy and vendor SLAs now; classify every AI use case by risk tier and implement the required controls before scaling campaigns.
---
Additional content from market data:
TL;DR
- v1.1 technical/application guideline underpins marketing safeguards on training controls, rights clearance, provenance, and watermarking.
- Used for step‑by‑step checks on IP, data handling, retention/deletion, and preservation of content credentials.
Why it matters for HK marketers: It provides actionable, HK‑specific implementation details for compliant generative AI production and delivery.
Practical Controls Highlighted
- Training/retention: use enterprise environments with model training disabled where required; document retention and deletion.
- Rights and licences: confirm permission for logos, music, talent, voice/face likeness, and other identifiable attributes; define duration, territory, media, transformations, and revocation.
- Provenance: retain content credentials/metadata (e.g., C2PA), platform labels, generation records, and asset IDs; avoid stripping metadata in editing/distribution.
- Watermarking: apply persistent watermarking/provenance mechanisms for higher‑risk synthetic media.
Embedded in Playbook Workflows
- Appears in compliance checks (vendor terms, training disablement, overseas processing) and disclosure/provenance preservation steps pre‑launch.
So what for marketers
Bake these guideline requirements into creative and media SOPs and vendor contracts; run a pre‑launch provenance and rights checklist for all synthetic assets.
Sources:- HK_Generative_AI_Technical_and_Application_Guideline_en.pdf
- market data
← Back to Knowledge Base