Israel - AI Regulation and Ethics

Israel’s Policy on Artificial Intelligence Regulation and Ethics (Ministry of Innovation, Science and Technology and Ministry of Justice) - 'Responsible Innovation' AI policy

Israel

RAI-IL-NA-IAIEMXX-2023
Adopted(Adopted)
PolicyGovernance and OversightRisk Management
Export PDF

Published in December 2023 by the Israeli Ministry of Innovation, Science and Technology together with the Ministry of Justice, the 'Responsible Innovation' policy sets principled, sectoral, risk-based guidance for AI development and use in Israel. It emphasizes a human-centric approach, international alignment, sectoral regulation led by relevant regulators, and pragmatic tools such as sandboxes and soft regulation rather than immediate broad horizontal legislation.

Summary

In December 2023 the Israeli Ministry of Innovation, Science and Technology and the Ministry of Justice (Consulting and Legislation Department) published a national policy document entitled 'Policy, Regulation and Ethics Principles in the Field of Artificial Intelligence' that frames Israel’s AI approach around the concept of 'Responsible Innovation.' The policy is expressly intended as a strategic guidance document for government ministries, sectoral regulators and the private sector, rather than as binding statutory rules. It sets out six regulatory principles and six ethical principles broadly aligned with major international frameworks (notably the OECD recommendations) and emphasizes: (1) a sectoral/regulator-led approach where each sector’s regulator determines fit-for-purpose rules based on concrete needs; (2) international interoperability to reduce cross-border regulatory friction; (3) a risk-based approach where regulatory intensity is calibrated to the type and context of risk; (4) incremental regulatory development coupled with regulatory experimentation (e.g., sandboxes and pilot projects); (5) prioritizing enabling or 'soft' regulatory tools (standards, non-binding principles) where feasible; and (6) stakeholder involvement in rulemaking. The ethical principles include human-centric AI and respect for fundamental rights, non-discrimination and equality, transparency and notice, reliability and safety across the AI lifecycle, responsibility and accountability of developers/operators, and promoting innovation for social welfare. Practical proposals in the document include establishment of a government-level knowledge and coordination center (an AI policy coordination center or governmental focal point), guidance to sectoral regulators to adopt risk-management processes, encouragement of impact assessments (privacy and rights impact methodologies), promotion of explainability and human oversight for systems affecting rights, and the use of regulatory sandboxes to enable safe experimentation. The policy identifies seven core challenges for private-sector AI — discrimination, human oversight, explainability, disclosure of AI interactions, safety, accountability and privacy — and recommends practical measures (standards, guidance, pilot testing) rather than immediate cross-cutting legislation. Because the policy is guidance-oriented it does not itself create new criminal or administrative penalties; enforcement and sanctions remain within the competences of existing sectoral regulators and of Israel’s data-protection framework (the Privacy Protection Authority under the Protection of Privacy Law), which has since been modernized through an amendment passed in 2024 that increases enforcement powers and comes into effect later. The policy also directs coordination for international engagement and alignment with leading frameworks, and recommends periodic reassessment of whether economy-wide/horizontal legislation is necessary as technologies and risks evolve. Overall, the document seeks to balance Israel’s innovation leadership goals with human-rights protection and regulatory preparedness by promoting harmonized, evidence-based, sector-led regulation and practical governance tools.

Full article

Read full text ↗

Overview

The Israeli government’s AI policy document, published in December 2023 by the Ministry of Innovation, Science and Technology in cooperation with the Ministry of Justice, defines a national approach titled "Responsible Innovation." The policy frames AI governance as a balance between stimulating innovation and upholding human rights and rule-of-law values. It prioritizes sectoral, risk-based regulation implemented by the sector-specific regulator, supported by a government-level knowledge and coordination center, and aligned where possible with leading international frameworks. The document is presented as guidance rather than binding law and explicitly favors incremental / experimental regulatory tools (e.g., sandboxes, pilot projects) and soft regulation (standards, non-binding principles), while instructing regulators to apply rigorous risk-management procedures for high-impact uses. The original government publication is available from the State of Israel publication repository and related ministry communications. For the official text (Hebrew PDF) see Policy, Regulation and Ethics Principles in the Field of Artificial Intelligence (Ministry of Innovation & Ministry of Justice, Dec 2023) and an English summary and commentary is available through ministry and sectoral press coverage including the Ministry’s synthetic descriptions and public commentary by legal and industry experts.

Definitions

The policy uses broadly applied definitions consistent with international practice. Key terms include "AI-based systems" (systems that use algorithms, models or statistical procedures to perform tasks that would otherwise require human cognitive capability), "developer" (entity designing or training models), "operator" (entity deploying or using AI systems), "user" (end-user of an AI-powered service), and "public-impact AI" (systems whose operation has material effects on individual rights, public safety, or societal functions). The document explicitly references the OECD's approach to definitions and notes that sectoral regulators may adopt more granular definitions tailored to specific fields (finance, health, infrastructure). The policy also distinguishes between lifecycle phases (design, training, deployment, monitoring) to emphasize obligations across the AI lifecycle.

Governance and Institutional Framework

The policy establishes a governance architecture built on existing ministries and sectoral regulators. Primary institutional responsibilities are assigned to: the Ministry of Innovation, Science and Technology (policy leadership and international representation), the Ministry of Justice (legal advice and compatibility with existing law), sectoral regulators (rulemaking and supervision in their domains) and proposed creation of a government "knowledge and coordination center" to consolidate competence, issue guidance, and coordinate cross-sectoral issues. The document instructs regulators to adopt risk-management frameworks and to consult the coordination center on inter-sectoral matters. The policy also recommends establishing an AI Policy Coordination Center as an inter-agency focal point to collect best practices, coordinate Israel's international engagement, support capacity building, and advise regulators on harmonization. See the official publication: Policy document (Hebrew PDF) and commentary provided by the Ministry and legal scholars summarizing the architecture.

Key Focus Areas

The policy identifies seven central challenges for private-sector AI: discrimination and bias; human oversight; explainability; disclosure of AI interactions (user notice that AI is in use); safety across lifecycle; accountability by developers/operators; and privacy/data protection. To address these, the policy recommends: (1) risk-based regulatory triage that focuses regulatory attention where impact is greatest; (2) adoption of human-centred design and human-in-the-loop measures for systems affecting rights; (3) transparency obligations in the form of meaningful user notice and documentation about capabilities and limitations; (4) technical and organizational measures to mitigate bias and discrimination, including dataset documentation; (5) safety engineering and monitoring requirements for safety-critical systems; (6) accountability documentation, logging and incident reporting mechanisms; (7) data governance, security-by-design and privacy impact assessments where personal data are processed; (8) use of regulatory sandboxes and pilot projects to allow controlled experimentation; and (9) the use of standards and voluntary codes as a first step where appropriate. The policy emphasizes aligning measures with prevailing international standards and recommends periodic reassessment to determine whether additional cross-sectoral legislation is needed.

Implementation Framework

Implementation is decentralized: sectoral regulators must translate the policy principles into concrete, domain-specific rules. The policy sets a five-part toolkit for regulators: (1) risk assessment and risk-proportionate regulation; (2) regulatory experimentation (sandboxes, pilots); (3) soft-regulatory instruments (non-binding guidance, sector codes, standards); (4) targeted binding measures for high-risk, public-impact applications; and (5) capacity building via the recommended AI Policy Coordination Center. The policy calls for practical deliverables such as regulatory guidance documents, standard operating procedures for impact assessments, technical annexes on explainability and documentation, and templates for industry registries where necessary. The policy instructs regulators to consult stakeholders (industry, academia, civil society) in drafting sectoral rules and to coordinate with the Ministry of Innovation and the proposed coordination center to promote consistency and interoperability across sectors and with international frameworks.

Monitoring and Evaluation

Monitoring is organized through a two-tier model: (A) sectoral monitoring and enforcement by sector regulators responsible for supervising compliance with domain-specific rules; and (B) an overarching monitoring and coordination role for the government knowledge center to aggregate lessons learned, produce cross-sectoral reports, identify gaps, and recommend adjustments. The policy recommends regular impact and rights assessments, reporting obligations for serious incidents affecting safety or rights, and structured evaluations of sandboxes and pilot projects to inform adaptive regulation. The document also proposes periodic review cycles to evaluate whether the sectoral approach remains sufficient or whether economy-wide/horizontal legislation should be introduced.

Penalties, Liability, and Appeals

The 2023 policy itself does not create new criminal offences or a uniform penalty regime; it is a policy guidance document that leaves enforcement to sectoral regulators and to existing legal frameworks. The policy notes that binding penalties (where appropriate) would be implemented by sectoral regulators under their statutory powers and that existing statutes (notably Israel’s Protection of Privacy Law and other sector-specific statutes) continue to apply. Subsequent legal reforms to the privacy framework (Amendment to the Protection of Privacy Law enacted in 2024) strengthen the Privacy Protection Authority’s enforcement powers and potential sanctions for privacy violations; sectoral liability (tort, contract, consumer protection) remains governed by existing law. The policy therefore focuses on compliance tools and guidance rather than prescriptive sanctions, while acknowledging that regulators may impose penalties under their statutory regimes for non-compliance.

Relationship to Other Instruments

The policy expressly situates itself alongside prior government decisions and legal instruments: it implements principles drawn from Government Decision 212 (2021) and Government Decision 173 (February 24, 2023) and is intended to operationalize elements of the National AI Program. It complements the Protection of Privacy Law (and the PPA’s guidance), existing sectoral regulatory regimes (finance, health, telecom, transport), and international commitments. The policy instructs regulators to interpret and apply existing laws to AI use (for example, privacy and consumer-protection rules) and to avoid regulatory fragmentation by coordinating through the proposed AI Policy Coordination Center. For the state publication see official PDF.

International Alignment

The policy commits Israel to international interoperability: regulators should align, when possible, with leading international frameworks (for example OECD recommendations, EU developments and other advanced jurisdictions) to reduce cross-border friction and to facilitate trade and research collaboration. The document calls for active Israeli participation in international fora, and for the national coordination center to serve as Israel’s focal point in international technical and policy cooperation. The policy’s preference for a risk-based, sectoral approach is framed as flexible to allow alignment with multiple international obligations while preserving Israel’s innovation ecosystem. The policy has been published alongside Israel’s increasing international engagement on AI safeguards and subsequent participation in global treaties and multilateral initiatives.

Implementation Timeline

MilestoneTarget Date / Status
Public consultation launched (draft)Nov 2022 (public comment period)
Policy publication (final)2023-12-14 (published)
Establish government knowledge/coordination center (proposal)2024–2025 (phased implementation; center creation recommended)
Sectoral rulemaking guided by policy2024 onward (regulators to adopt risk-based measures)
Privacy law amendment increasing PPA powers2024 (Amendment passed; enforcement effective dates set by statute)
Ongoing monitoring & periodic reviewAnnual to biennial reviews recommended

Sources and References

SourceType
Policy, Regulation and Ethics Principles in the Field of Artificial Intelligence (Ministry of Innovation & Ministry of Justice, Dec 2023) - official publication (Hebrew)Primary Source
Ministry of Innovation, Science & Technology — press and program pages (English summaries and related AI program materials)Primary / Official commentary
Digital Watch Observatory — summary and analysisSecondary Analysis
Baker McKenzie — legal briefing on Israel AI policy (summary)Secondary Analysis

Requirements for a company

What an organisation has to do under Israel - AI Regulation and Ethics, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.

Must do

8
  • Conduct privacy impact assessments and implement data protection measures.Developers and operators of AI systems processing personal data.
  • Implement structured risk assessments and document mitigation measures for AI systems.Developers and operators of AI systems, especially public-impact AI.
  • Design human-in-the-loop controls and human-centered design for systems affecting rights.Developers and operators of public-impact AI systems.
  • Provide meaningful user notice and documentation about AI system capabilities and limitations.Developers and operators of AI systems.
  • Implement technical and organizational measures to mitigate bias and discrimination, including dataset documentation.Developers and operators of AI systems.
  • Adopt safety engineering, testing, and post-deployment monitoring for safety-critical AI systems.Developers and operators of safety-critical AI systems.
  • +2 more in the table below

Must not do

0

Nothing in this category.

Should do

2
  • Engage in regulatory sandboxes and pilot projects where appropriate for controlled experimentation.Developers and operators of AI systems.
  • Align AI system measures with prevailing international standards and frameworks where possible.Developers and operators of AI systems.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Israel - AI Regulation and Ethics, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Developers and operators of AI systems processing personal data.Conduct privacy impact assessments and implement data protection measures.
data governance, security-by-design and privacy impact assessments where personal data are processed
Key Focus AreasCritical
2Developers and operators of AI systems, especially public-impact AI.Implement structured risk assessments and document mitigation measures for AI systems.
Implement structured risk assessments and document mitigations
Key Focus AreasImportant
3Developers and operators of public-impact AI systems.Design human-in-the-loop controls and human-centered design for systems affecting rights.
adoption of human-centred design and human-in-the-loop measures for systems affecting rights
Key Focus AreasImportant
4Developers and operators of AI systems.Provide meaningful user notice and documentation about AI system capabilities and limitations.
transparency obligations in the form of meaningful user notice and documentation about capabilities and limitations
Key Focus AreasImportant
5Developers and operators of AI systems.Implement technical and organizational measures to mitigate bias and discrimination, including dataset documentation.
technical and organizational measures to mitigate bias and discrimination, including dataset documentation
Key Focus AreasImportant
6Developers and operators of safety-critical AI systems.Adopt safety engineering, testing, and post-deployment monitoring for safety-critical AI systems.
safety engineering and monitoring requirements for safety-critical systems
Key Focus AreasImportant
7Developers and operators of AI systems.Maintain accountability documentation, logging, versioning, and incident records for AI systems.
accountability documentation, logging and incident reporting mechanisms
Key Focus AreasImportant
8Developers and operators of AI systems.Report serious incidents affecting safety or rights to the relevant sectoral regulator.
reporting obligations for serious incidents affecting safety or rights
Monitoring and EvaluationImportant
9Developers and operators of AI systems.Engage in regulatory sandboxes and pilot projects where appropriate for controlled experimentation.
use of regulatory sandboxes and pilot projects to allow controlled experimentation
Key Focus AreasRecommended
10Developers and operators of AI systems.Align AI system measures with prevailing international standards and frameworks where possible.
aligning measures with prevailing international standards
Key Focus AreasRecommended

© Regulations.AI · updated on 13-Jun-2026