Hong Kong - Ethical AI Framework

Ethical Artificial Intelligence Framework

Hong Kong

RAI-HK-NA-ETHARIN-2021
Effective: August 18, 2021
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementData Protection and Privacy
Export PDF

The Ethical Artificial Intelligence Framework is a government-issued guidance document developed to help Hong Kong government bureaux/departments (B/Ds) and other organisations adopt AI and big data analytics responsibly. It sets out 12 ethical principles, an AI governance structure, lifecycle practices and an AI Application Impact Assessment template to identify, manage and mitigate ethical, privacy and security risks.

Summary

The Ethical Artificial Intelligence Framework (the “Framework”) was developed by Hong Kong’s Digital Policy Office (formerly Office of the Government Chief Information Officer) to provide a practical, risk-aware set of principles and operational practices for the ethical adoption of AI and big data analytics in IT projects. Although originally tailored for internal adoption by Government bureaux and departments (B/Ds), the Framework is published as a customised general reference for other organisations. The Framework consolidates: (a) twelve Ethical AI Principles (two ‘‘performance’’ principles — Transparency & Interpretability; Reliability, Robustness & Security — and ten general principles including Fairness, Human Oversight, Data Privacy, Accountability and Beneficial AI); (b) an AI governance structure that defines roles and responsibilities across executive and technical levels; (c) an AI lifecycle and practice guide addressing project strategy, planning, ecosystem, development, deployment and operation; and (d) an AI Application Impact Assessment template for systematic evaluation of potential benefits, impacts and risks. The Framework is explicitly designed to be used alongside existing legal and technical requirements in Hong Kong (notably the Personal Data (Privacy) Ordinance and PCPD guidance). It emphasises data protection, risk-based oversight, human-in-the-loop controls, documentation and stakeholder engagement, and includes appendices with glossaries, references to international standards and a dedicated generative AI annex. The Digital Policy Office has maintained and updated the Framework (amendments and versioning appear in the published PDF), with enhancements in 2023 and a further publicised Version 1.4 dated July 25, 2024. The Privacy Commissioner for Personal Data (PCPD) has also published companion guidance and a Model Personal Data Protection Framework (PCPD Guidance, Aug 18 2021; Model Framework 2024) which organisations should consult to comply with Hong Kong’s data-protection law when handling personal data in AI systems.

Full article

Read full text ↗

Overview

The Hong Kong Ethical Artificial Intelligence Framework (Ethical AI Framework) provides a structured, pragmatic approach for embedding ethical considerations into AI and big data analytics projects. Developed by the Digital Policy Office (DPO) for internal government adoption and released as a customised general reference, the Framework consolidates twelve Ethical AI Principles, an AI governance model, an AI lifecycle practice guide and an AI Application Impact Assessment template. The public PDF (Version 1.4) and quick-reference guide are published by the DPO and available as an official download: Ethical AI Framework (DPO PDF). The Framework is explicitly intended to complement sectoral rules and the Personal Data (Privacy) Ordinance (PDPO), and to be read alongside PCPD publications such as the PCPD Guidance on the Ethical Development and Use of AI (Aug 18, 2021). It emphasises a risk-based posture that balances innovation with public interest, safety and privacy protection.

Definitions

The Framework defines key terms for consistent use across government AI projects. "AI" covers analytic operations including advanced analytics, machine learning and big-data-driven models used to find correlations, make predictions or automate decisions. An "AI application" is any IT project whose actions, decisions or outputs are empowered by such AI models (examples include predictive services, automated decisioning, image analytics and generative AI features). "AI Assessment" refers to the AI Application Impact Assessment template that organisations must use to evaluate benefits, risks and mitigation measures. Other defined concepts include Ethical AI Principles (twelve high-level principles), AI Lifecycle stages (strategy, planning, development, deployment, operation), AI Governance roles (executive sponsors, CIO/IT Board, project teams, assurance teams), and data stewardship concepts aligned to the PDPO.

Governance and Institutional Framework

The Framework sets out an AI governance structure that distributes responsibilities across organisational layers. Senior leadership (e.g., CIO, IT Board) is tasked with strategy, resource allocation and escalation; programme and project teams are responsible for implementing ethical practices across the AI lifecycle; assurance teams (Project Assurance Team, central review boards) handle independent review and compliance checks; and operational teams monitor live systems for drift, security and safety incidents. The Framework recommends establishing formal AI governance committees, appointing accountable owners (e.g., AI product owners and data stewards), and maintaining defined decision gates tied to the AI Application Impact Assessment. It also prescribes linkage to enterprise risk management, security and privacy functions and recommends transparent reporting lines to enable escalation of high-risk projects for senior review (DPO Ethical AI Framework PDF).

Key Focus Areas

The Framework organises operational guidance around: (1) ethical principles — Transparency & Interpretability; Reliability, Robustness & Security; Fairness; Diversity & Inclusion; Human Oversight; Lawfulness & Compliance; Data Privacy; Safety; Accountability; Beneficial AI; Cooperation & Openness; and Sustainability & Just Transition; (2) practical lifecycle practices — from project strategy and planning to development, deployment and operation; (3) AI Assessment — a structured impact-assessment template which asks targeted questions about data inputs, model development, human oversight, testing protocols, privacy impact and mitigation strategies; and (4) sectoral and technology-specific considerations such as generative AI risks (appendix dedicated to generative AI). The Framework calls out data governance and PDPO compliance as cross-cutting requirements and instructs teams to embed privacy-by-design and security-by-design measures, fairness/bias checks, and human-in-the-loop arrangements proportionate to risk.

Implementation Framework

Operationalising the Framework requires organisations to: adopt the AI Application Impact Assessment at project inception; define an enterprise AI strategy and policies; establish governance committees; assign roles (AI owners, data stewards, assurance functions); incorporate data protection and cybersecurity controls aligned with existing standards; define testing and validation regimes for models (including pre-deployment testing and post-deployment monitoring); and maintain documentation and audit trails. The Framework offers templates (AI strategy template, assessment template) and recommends integrating these steps into existing project management and IT assurance processes. It also sets recommended frequencies for reassessment (e.g., annual reviews or after major model changes) and recommends escalation criteria for projects that present substantial ethical, privacy or safety risk (DPO PDF).

Monitoring and Evaluation

Monitoring emphasises continuous model performance tracking, logging and incident response. The Framework recommends key performance indicators and operational checks (accuracy drift, fairness metrics, security incidents, data access logs) and the use of AI Assessment to trigger reviews. It encourages regular audit cycles by internal assurance or external reviewers and requires post-deployment monitoring with defined thresholds for rollback or human intervention. The Framework also recommends documentation retention, versioning of models and datasets, and publishing internal summaries to support transparency and oversight.

Penalties, Liability, and Appeals

As a set of guidance documents, the Framework itself does not create criminal penalties but points organisations to statutory obligations under Hong Kong law (notably the Personal Data (Privacy) Ordinance). Non-compliance with data protection obligations may attract enforcement actions by the Privacy Commissioner for Personal Data and any sector-specific regulator may take action within its remit. The Framework therefore positions ethical compliance as a risk-management and reputational imperative and recommends mechanisms for redress: incident reporting, root-cause analysis, remediation plans, and stakeholder communications. For legal enforcement or sanctions relating to personal data breaches, organisations are referred to the PDPO and PCPD enforcement procedures (PCPD Guidance (Aug 18, 2021)).

Relationship to Other Instruments

The Ethical AI Framework is designed to complement Hong Kong’s existing legal and policy instruments. It explicitly references the Personal Data (Privacy) Ordinance (PDPO) and PCPD publications (Guidance 2021; Model Personal Data Protection Framework 2024) and promotes alignment with international standards and mainland/overseas guidance where relevant. The Framework sits alongside sector-specific supervisory guidance (e.g., financial regulators’ AI principles) and is intended to be used with existing IT security, project management and procurement processes. The DPO version also cross-references Mainland regulations and international norms in appendices and recommends a harmonised, risk-based approach to avoid conflicts with statutory obligations (DPO PDF).

International Alignment

The Framework draws on international best practice and standards (references and examples appear in the appendices). It cites and aligns with widely recognized ethical principles (e.g., human rights-based approaches) and encourages organisations to consider international interoperability when procuring or deploying AI systems, including model provenance and cross-border data transfer implications. The DPO also updated the Framework to address generative AI and referenced relevant Mainland and international measures in its appendices to support harmonised governance for cross-jurisdictional AI deployments.

Implementation Timeline

EventDateNotes
PCPD Guidance published2021-08-18PCPD issued "Guidance on the Ethical Development and Use of AI" (primary data-protection guidance).
Framework enhanced for generative AI (amendment)2023-07-13DPO amendment history records updates to include generative AI practices.
DPO public PDF Version 1.42024-07-25DPO published Version 1.4 of the Ethical AI Framework (public PDF).

Sources and References

SourceType
Ethical Artificial Intelligence Framework (DPO PDF, Version 1.4, July 25, 2024)Primary Source
Digital Policy Office: Ethical Artificial Intelligence Framework (web page)Primary Source
PCPD: Guidance on the Ethical Development and Use of Artificial Intelligence (18 Aug 2021)Primary Source

Requirements for a company

What an organisation has to do under Hong Kong - Ethical AI Framework, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

11
  • Comply with the Personal Data (Privacy) Ordinance (PDPO).Organizations developing or using AI applications in Hong Kong.
  • Complete an AI Application Impact Assessment at project inception.Organizations developing or using AI applications.
  • Establish an AI governance structure with assigned roles and committees.Organizations developing or using AI applications.
  • Embed privacy-by-design and security-by-design measures in AI applications.Teams developing AI applications.
  • Define and implement testing and validation regimes for AI models.Organizations developing AI applications.
  • Implement post-deployment monitoring with thresholds for intervention or rollback.Operational teams of AI applications.
  • +5 more in the table below

Must not do

0

Nothing in this category.

Should do

2
  • Reassess AI applications annually or after major model changes.Organizations operating AI applications.
  • Publish internal summaries of AI systems to support transparency.Organizations operating AI applications.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Hong Kong - Ethical AI Framework, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Organizations developing or using AI applications in Hong Kong.Comply with the Personal Data (Privacy) Ordinance (PDPO).
Non-compliance with data protection obligations may attract enforcement actions by the Privacy Commissioner for Personal Data.
Critical
2Organizations developing or using AI applications.Complete an AI Application Impact Assessment at project inception.
Operationalising the Framework requires organisations to: adopt the AI Application Impact Assessment at project inception.
Before placing on marketImportant
3Organizations developing or using AI applications.Establish an AI governance structure with assigned roles and committees.
Operationalising the Framework requires organisations to... establish governance committees; assign roles (AI owners, data stewards, assurance functions).
Important
4Teams developing AI applications.Embed privacy-by-design and security-by-design measures in AI applications.
instructs teams to embed privacy-by-design and security-by-design measures, fairness/bias checks, and human-in-the-loop arrangements proportionate to risk.
Before placing on marketImportant
5Organizations developing AI applications.Define and implement testing and validation regimes for AI models.
define testing and validation regimes for models (including pre-deployment testing and post-deployment monitoring).
Before placing on marketImportant
6Operational teams of AI applications.Implement post-deployment monitoring with thresholds for intervention or rollback.
requires post-deployment monitoring with defined thresholds for rollback or human intervention.
Important
7Organizations developing and operating AI applications.Maintain comprehensive documentation and audit trails for AI systems.
maintain documentation and audit trails.
Important
8Organizations developing or using AI applications.Define an enterprise-wide AI strategy and associated policies.
Operationalising the Framework requires organisations to... define an enterprise AI strategy and policies.
Important
9Organizations developing or using AI applications.Link AI governance to existing enterprise risk management and security functions.
It also prescribes linkage to enterprise risk management, security and privacy functions.
Important
10Teams developing AI applications.Conduct fairness and bias checks proportionate to the AI system's risk.
instructs teams to embed privacy-by-design and security-by-design measures, fairness/bias checks, and human-in-the-loop arrangements proportionate to risk.
Before placing on marketImportant
11Teams developing AI applications.Establish human-in-the-loop arrangements proportionate to the AI system's risk.
instructs teams to embed privacy-by-design and security-by-design measures, fairness/bias checks, and human-in-the-loop arrangements proportionate to risk.
Before placing on marketImportant
12Organizations operating AI applications.Reassess AI applications annually or after major model changes.
It also sets recommended frequencies for reassessment (e.g., annual reviews or after major model changes).
Recommended
13Organizations operating AI applications.Publish internal summaries of AI systems to support transparency.
The Framework also recommends documentation retention, versioning of models and datasets, and publishing internal summaries to support transparency and oversight.
Recommended

© Regulations.AI · updated on 13-Jun-2026