Philippines - AI Development Regulation (HB 7396)

House Bill No. 7396 (Artificial Intelligence Development and Regulation Act)

Philippines

RAI-PH-NA-HN7AIXX-2024
Under Review(Under Review)
BillGovernance and OversightConformity Assessment and RegistrationEnforcement and Penalties
Export PDF

House Bill No. 7396, submitted to the Philippine House of Representatives on March 1, 2023, creates a national authority to regulate public and private AI developers and deployers. It mandates registration for AI entities and establishes technical standards for high-risk applications. The measure is currently under review.

Summary

House Bill No. 7396, formally titled the 'Artificial Intelligence Development Act of the Philippines,' represents a comprehensive legislative proposal to establish the Philippines' first dedicated regulatory framework for artificial intelligence technologies. Introduced to the House of Representatives on March 1, 2023, the bill responds to growing recognition that AI's rapid development and deployment across Philippine society requires coordinated governance to maximize benefits while mitigating risks. The bill defines artificial intelligence as 'the ability of machines or computer programs that are designed to perform tasks that simulate human intelligence,' including capabilities for reasoning, learning, problem-solving, perception, and natural language processing.

The centerpiece of House Bill 7396 is creation of the Artificial Intelligence Development Authority (AIDA), a new government agency to be established under the Office of the President with broad powers and responsibilities for AI governance. AIDA would serve as the primary regulatory body coordinating national AI policy development, establishing technical and ethical standards, ensuring compliance with existing laws including the Data Privacy Act of 2012, and providing oversight of AI deployment across public and private sectors. The placement of AIDA under the Office of the President reflects the cross-cutting nature of AI technologies affecting virtually all government functions and economic sectors, necessitating high-level coordination and authority to align diverse stakeholder interests.

AIDA's proposed mandate includes multiple critical functions. First, developing and maintaining a comprehensive National AI Strategy that sets priorities, identifies opportunities, addresses challenges, and coordinates government efforts across agencies. Second, establishing regulatory standards and security requirements for AI systems deployed in high-risk applications including healthcare, financial services, critical infrastructure, law enforcement, and public administration. Third, creating licensing and certification regimes for certain categories of AI systems or providers, ensuring that entities deploying AI meet minimum competency, security, and ethical standards before market entry. Fourth, ensuring AI systems comply with existing Philippine laws, particularly the Data Privacy Act of 2012, by working with the National Privacy Commission to address AI-specific data protection challenges including algorithmic transparency, consent mechanisms for automated processing, and protection against discriminatory AI decisions.

The bill emphasizes alignment of national AI development with international standards and best practices. AIDA would be responsible for monitoring global AI governance developments, participating in international standard-setting bodies, and adapting international frameworks to Philippine context and priorities. This international engagement aims to ensure Philippine AI regulation remains interoperable with major trading partners and technology sources while protecting distinctly Philippine values, rights, and development priorities.

Data protection and privacy constitute core concerns addressed by House Bill 7396. The bill explicitly requires AI systems to comply with the Data Privacy Act of 2012, with AIDA working in coordination with the National Privacy Commission to develop AI-specific guidance on consent, transparency, data minimization, security, and accountability. The bill recognizes that AI systems processing personal data pose unique privacy risks through profiling, automated decision-making, and potential for algorithmic bias, requiring specialized regulatory attention beyond general data protection requirements.

Ethical AI development represents another foundational principle embedded in the proposed legislation. House Bill 7396 directs AIDA to establish standards promoting transparency in AI system operations, accountability for AI-generated outcomes, fairness and non-discrimination in algorithmic decision-making, protection of fundamental human rights including dignity and autonomy, and inclusive design ensuring AI benefits all Filipinos regardless of socioeconomic status, geographic location, language, or other characteristics. These ethical principles aim to prevent AI from exacerbating existing inequalities or creating new forms of discrimination and exclusion.

The bill includes provisions addressing malicious use of AI technologies. AIDA would serve as a watchdog monitoring and acting against individuals or entities exploiting AI for harmful purposes including fraud, manipulation, privacy violations, discriminatory practices, or security threats. This enforcement function would involve coordination with law enforcement agencies, regulatory bodies in specific sectors, and international partners addressing transnational AI-enabled crimes.

Business registration requirements constitute a practical implementation mechanism within House Bill 7396. Entities developing or deploying AI systems meeting specified thresholds would be required to register with AIDA, providing information about their AI capabilities, applications, data processing practices, and governance measures. This registration creates transparency regarding the AI ecosystem in the Philippines, enables targeted oversight of high-risk applications, and facilitates communication between AIDA and AI developers regarding evolving standards and requirements.

As of late 2024, House Bill 7396 remains pending in the Philippine Congress and has not been enacted into law. The bill is under consideration by relevant House committees, which are reviewing its provisions, soliciting stakeholder input from technology companies, civil society organizations, academic institutions, and government agencies, and potentially proposing amendments before the bill advances to floor debate and voting. The legislative process timeline remains uncertain, with the bill competing for attention among numerous other legislative priorities. While House Bill 7396 provides a foundational framework, its deliberately broad language leaves many specifics to be determined through implementing regulations that AIDA would develop after enactment, following multi-stakeholder consultations and international best practice reviews.

Full article

Read full text ↗

Overview

House Bill No. 7396, formally known as the 'Artificial Intelligence Development Act of the Philippines,' represents the Philippine legislature's comprehensive response to the challenges and opportunities presented by artificial intelligence technologies. Introduced to the House of Representatives on March 1, 2023, the bill establishes the first dedicated regulatory framework for AI in the Philippines, creating institutional structures, standards, and oversight mechanisms to govern AI development and deployment across all sectors. The bill's central innovation is establishment of the Artificial Intelligence Development Authority (AIDA), a new government agency under the Office of the President with broad powers to coordinate national AI policy, establish technical and ethical standards, ensure legal compliance, and oversee responsible AI deployment. The legislation responds to growing recognition that AI's transformative potential across healthcare, education, finance, governance, and virtually all aspects of Philippine society requires coordinated regulation that balances innovation and economic competitiveness with protection of rights, privacy, security, and democratic values. The bill aligns Philippine AI governance with international developments including the European Union AI Act, UNESCO's AI ethics recommendations, and OECD AI principles, while maintaining flexibility to address Philippine-specific priorities including digital divide concerns, Filipino language requirements, and developmental objectives. As of late 2024, House Bill 7396 remains pending in Congress, undergoing committee review and stakeholder consultation. The bill's deliberately framework-oriented approach leaves many implementation details to be developed through AIDA regulations following enactment, enabling adaptive governance responsive to rapid technological change. The bill is one of several AI-related legislative proposals under consideration, including bills addressing deepfakes, labor impacts, electoral integrity, and research funding, collectively forming an emerging comprehensive AI governance ecosystem for the Philippines.

Definitions

House Bill 7396 establishes precise definitions for key terms governing artificial intelligence regulation in the Philippines. Artificial Intelligence is defined as 'the ability of machines or computer programs that are designed to perform tasks that simulate human intelligence,' encompassing capabilities including reasoning and logic application, learning from experience and data, problem-solving and decision-making, perception of the environment through sensors and data inputs, natural language understanding and generation, pattern recognition and classification, and prediction and forecasting. This broad definition captures both narrow AI systems designed for specific tasks and general-purpose AI systems with diverse capabilities, ensuring comprehensive regulatory coverage as AI technologies evolve. AI System refers to any machine-based system that uses artificial intelligence to generate outputs including predictions, recommendations, decisions, or content, whether operating autonomously or with human oversight. This definition encompasses software applications, embedded systems in physical devices, cloud-based AI services, and hybrid architectures combining multiple AI components. AI Developer means any individual or entity engaged in designing, creating, training, or substantially modifying artificial intelligence systems, including software engineers, data scientists, research teams, and organizations commissioning AI development. AI Deployer refers to entities that put AI systems into use in operational environments, including businesses using AI for customer service, government agencies deploying AI for public administration, healthcare providers using AI for diagnostics, and any organization integrating AI into products or services affecting end users. High-Risk AI System (though not explicitly defined in the initial bill text, anticipated in implementing regulations) would encompass AI applications posing significant risks to health, safety, fundamental rights, or public welfare, including medical diagnostic systems, financial credit scoring, law enforcement and judicial applications, critical infrastructure management, and educational assessment. Personal Data retains its definition from the Data Privacy Act of 2012 as any information from which an individual's identity can be reasonably and directly ascertained, or when combined with other information would directly and certainly identify an individual. Algorithmic Transparency refers to the degree to which an AI system's operating logic, decision-making processes, and influencing factors can be understood and explained to affected individuals and overseers. Algorithmic Bias means systematic and repeatable errors in AI systems that create unfair outcomes, such as privileging or disadvantaging particular groups based on protected characteristics including race, gender, religion, age, disability, or socioeconomic status. Ethical AI encompasses artificial intelligence developed and deployed in accordance with principles of fairness, accountability, transparency, human rights protection, inclusivity, and social benefit maximization, as articulated in standards established by AIDA.

Governance and Institutional Framework

House Bill 7396 establishes the Artificial Intelligence Development Authority (AIDA) as the central institutional pillar of Philippine AI governance. AIDA would be created as an attached agency under the Office of the President, reflecting AI's cross-cutting significance across all government functions and the need for high-level coordination authority. This placement enables AIDA to convene and coordinate actions across multiple departments and agencies, resolve inter-agency conflicts, and align AI governance with broader national development priorities articulated by the President and the National Economic and Development Authority (NEDA). AIDA's leadership structure would include an Administrator appointed by the President, subject to Commission on Appointments confirmation, supported by Deputy Administrators for key functional areas including Technology Standards, Legal and Ethical Compliance, Industry Development, and International Cooperation. The Administrator would report directly to the Executive Secretary, ensuring high-level visibility and support for AI governance initiatives. AIDA's organizational structure would include technical divisions staffed by experts in artificial intelligence, data science, cybersecurity, law, ethics, economics, and public administration, creating multi-disciplinary capacity to address AI's complex challenges. AIDA would coordinate with multiple existing agencies whose mandates intersect with AI governance. The National Privacy Commission (NPC) would remain the primary authority for data protection, with AIDA developing AI-specific interpretations and standards in coordination with NPC to address unique privacy challenges posed by machine learning, profiling, and automated decision-making. The Department of Information and Communications Technology (DICT) would coordinate on digital infrastructure essential for AI deployment, cybersecurity standards for AI systems, and government AI applications. The Department of Trade and Industry (DTI) would coordinate on AI's economic development implications, trade policy dimensions, and implementation of the National AI Strategy Roadmap. The Department of Science and Technology (DOST) would coordinate on AI research and development, ensuring AIDA's standards reflect cutting-edge research and supporting commercialization of DOST-funded AI innovations. Sectoral regulators including the Bangko Sentral ng Pilipinas (BSP) for financial AI, the Food and Drug Administration for medical AI, and the Land Transportation Office for autonomous vehicles would maintain primary authority in their domains while coordinating with AIDA on cross-cutting AI standards and risk assessments. AIDA would establish advisory bodies including a Technical Advisory Board comprising AI researchers and technologists, an Ethics Advisory Board with philosophers, human rights experts, and civil society representatives, and an Industry Advisory Board with private sector executives and startup founders. These advisory bodies would provide specialized expertise, diverse perspectives, and stakeholder input informing AIDA's policy development and standard-setting activities. AIDA's international engagement would include participation in ASEAN digital economy initiatives, collaboration with UNESCO and OECD on AI ethics and governance, engagement with ISO and IEEE standards development, and bilateral cooperation with AI regulatory authorities in major trading partners including the United States, European Union, Japan, and South Korea. This international coordination ensures Philippine AI regulation remains interoperable with global markets while adapting international best practices to local context.

Key Focus Areas

House Bill 7396 addresses six priority focus areas in AI governance. First, National AI Strategy Development: AIDA would be responsible for formulating, updating, and coordinating implementation of a comprehensive National AI Strategy articulating the Philippines' vision for AI development, identifying priority application areas delivering maximum social and economic benefit, addressing challenges including digital divide and skills gaps, establishing timelines and milestones for AI adoption across sectors, and allocating government resources and attention. This strategy would build upon and coordinate existing initiatives including the DTI-led National AI Strategy Roadmap and DOST AI research programs, creating a unified policy framework. Second, Technical and Security Standards: AIDA would establish standards governing AI system security against cyber threats and adversarial attacks; robustness and reliability ensuring consistent performance; safety in applications affecting physical systems (robotics, autonomous vehicles, industrial automation); interoperability enabling AI systems to exchange data and coordinate operations; and performance benchmarks for specific application domains. These technical standards would adapt international standards (ISO, IEEE, NIST) to Philippine context while maintaining global interoperability. Third, Ethical AI Principles and Implementation: AIDA would operationalize ethical principles through mandatory requirements for transparency in AI decision-making, particularly for high-risk applications affecting individual rights and opportunities; accountability mechanisms establishing clear responsibility for AI system outcomes and providing recourse for affected individuals; fairness requirements preventing algorithmic discrimination and bias; human oversight ensuring meaningful human control over AI systems in critical applications; and inclusive design ensuring AI benefits all Filipinos including marginalized communities, rural populations, and Filipino language speakers. AIDA would develop assessment frameworks enabling organizations to evaluate their AI systems against these principles and certify compliance. Fourth, Data Protection and Privacy: Building on the Data Privacy Act of 2012, AIDA would establish AI-specific requirements for consent mechanisms appropriate for automated processing; data minimization limiting collection and retention to what is necessary for legitimate AI purposes; purpose limitation preventing repurposing of data for AI applications beyond original collection purpose; security standards protecting training data and AI models from breaches; and rights protection enabling individuals to access, correct, object to, and understand automated decisions affecting them. AIDA would coordinate closely with the National Privacy Commission to ensure consistent interpretation and enforcement of privacy requirements in AI contexts. Fifth, Licensing and Certification: For high-risk AI systems (to be specified in implementing regulations), AIDA would establish licensing requirements obligating developers to demonstrate competence, security measures, and ethical compliance before deploying AI; certification processes for AI systems themselves, verifying they meet established standards for safety, reliability, fairness, and transparency; and registration requirements creating visibility into the Philippine AI ecosystem and enabling targeted oversight. Licensing and certification regimes would balance consumer protection and risk mitigation with avoiding excessive burden on innovation and competitiveness. Sixth, Enforcement and Malicious Use Prevention: AIDA would monitor AI deployment for violations of standards, license conditions, or laws; investigate complaints regarding harmful AI applications; coordinate with law enforcement on AI-enabled crimes including fraud, manipulation, privacy violations, and security threats; impose administrative sanctions for regulatory violations including warnings, fines, suspension of operations, and license revocation; and refer serious violations for criminal prosecution under existing laws (Cybercrime Prevention Act, Data Privacy Act, Revised Penal Code). AIDA would serve as the primary watchdog protecting Filipinos from AI harms while enabling beneficial innovation to flourish.

Implementation Framework

House Bill 7396's implementation would follow a phased approach enabling measured development of regulatory capacity and gradual compliance onboarding. Phase 1 (Months 1-12 after enactment): AIDA Establishment would include appointment of AIDA Administrator and leadership team; establishment of organizational structure and hiring of technical and administrative staff; allocation of initial budget and securing office facilities; convening of advisory boards and stakeholder working groups; and initiation of strategic planning processes for regulation development. During this phase, AIDA would focus on building organizational capacity rather than active enforcement. Phase 2 (Months 6-18): Standards and Regulations Development would involve multi-stakeholder consultations with industry, civil society, academia, and government to identify priority concerns and practical implementation approaches; drafting of implementing regulations specifying technical standards, ethical requirements, licensing procedures, and enforcement mechanisms; public comment periods enabling broad participation in regulation shaping; international coordination ensuring alignment with major trading partners; and finalization of initial regulatory package. This phase emphasizes inclusive, evidence-based regulation development incorporating diverse perspectives. Phase 3 (Months 12-24): Voluntary Compliance and Testing would establish pilot programs where willing organizations test compliance with draft regulations, providing feedback on feasibility and identifying unintended consequences; voluntary registration enabling AIDA to map the Philippine AI ecosystem and establish relationships with AI developers and deployers; guidance document publication helping organizations understand requirements and implement compliance measures; and capacity building programs including workshops, technical assistance, and online resources supporting organizations' compliance readiness. This phase builds goodwill, refines regulations based on real-world feedback, and ensures organizations have tools and knowledge needed for compliance. Phase 4 (Months 18-36): Mandatory Compliance Rollout would begin with high-risk AI applications (healthcare diagnostics, financial credit scoring, law enforcement, critical infrastructure) where stakes justify immediate oversight; gradually expand to medium-risk applications based on AIDA's capacity and industry readiness; maintain lighter-touch approaches (transparency requirements without licensing) for lower-risk applications; enforce registration requirements across all AI developers and deployers meeting specified thresholds; and activate licensing and certification regimes for designated high-risk systems. This phased approach prevents overwhelming both regulators and industry with premature obligations. Phase 5 (Year 3+): Ongoing Oversight and Adaptation includes routine monitoring of registered AI systems and licensed applications; periodic audits of high-risk AI deployers; investigation of complaints and reported incidents; enforcement actions against violations; regular review and updating of standards and regulations to reflect technological evolution, emerging risks, and international developments; publication of annual reports on the state of AI in the Philippines, compliance trends, enforcement actions, and regulatory priorities; and continued stakeholder engagement through advisory boards, public consultations, and industry partnerships. This ongoing phase establishes AIDA as a mature regulator adaptive to changing technology and societal needs.

Monitoring and Evaluation

House Bill 7396 envisions comprehensive monitoring and evaluation systems ensuring effective AI governance and enabling evidence-based refinement of regulatory approaches. AI System Registration would create a central database of AI developers and deployers, AI system types and applications, sectors and industries affected, data processing practices, and governance measures implemented. This registration provides AIDA with visibility into the AI landscape, enabling risk-based prioritization of oversight efforts and identification of emerging trends. Self-Assessment and Reporting would require organizations deploying high-risk AI systems to conduct periodic self-assessments against AIDA standards, documenting compliance measures, identifying gaps, and planning remediation; submit annual reports describing AI system changes, incidents or malfunctions, and risk management updates; and notify AIDA of significant incidents including system failures, data breaches, discriminatory outcomes, or safety events. These self-reporting mechanisms enable continuous monitoring beyond AIDA's direct audit capacity. Audits and Inspections would involve AIDA conducting periodic audits of licensed AI deployers, reviewing documentation, testing system performance, interviewing personnel, and assessing compliance with technical, ethical, and legal requirements; targeted inspections triggered by complaints, reported incidents, or risk indicators; and third-party audits where AIDA accredits independent organizations to conduct compliance assessments, increasing audit coverage and bringing specialized technical expertise. Complaint and Incident Reporting mechanisms would enable individuals affected by AI systems to file complaints alleging discrimination, privacy violations, errors, or other harms; civil society organizations to submit reports on systemic AI risks or patterns of violations; and AI developers and deployers to report incidents demonstrating system vulnerabilities or failures. AIDA would investigate credible complaints, require corrective actions, and impose sanctions where appropriate. Performance Metrics tracked by AIDA would include number of AI systems registered by type and sector; licensing and certification applications submitted, approved, and denied; complaints received, investigated, and resolved; enforcement actions taken including warnings, fines, suspensions, and revocations; guidance documents published and workshops conducted; stakeholder engagement events convened; and international cooperation activities undertaken. These metrics enable assessment of AIDA's operational performance and regulatory impact. Impact Assessment would periodically evaluate AI regulation's effects on innovation rates and technology adoption, measured through surveys, investment data, and startup formation; protection of rights and prevention of harms, documented through complaint trends, incident reports, and case studies; public trust in AI technologies, measured through opinion surveys; economic impacts including costs of compliance and benefits of safe AI deployment; and international competitiveness of Philippine AI sector, benchmarked against peer countries. These impact assessments inform regulatory adjustments balancing multiple objectives. Annual Reporting would provide transparency and accountability through AIDA's publication of comprehensive annual reports to the President, Congress, and the public, documenting regulatory activities, enforcement outcomes, AI ecosystem trends, challenges encountered, and plans for the subsequent year. Legislative Review would involve Congressional oversight hearings evaluating AIDA's performance and regulatory effectiveness; periodic amendment of House Bill 7396 (once enacted) to address gaps, update definitions, or adjust AIDA's powers and resources; and sunset provisions or mandatory comprehensive reviews at specified intervals (e.g., every five years) ensuring regulation remains fit for purpose as AI technology and societal understanding evolve.

Penalties, Liability, and Appeals

While House Bill 7396's initial text does not specify detailed penalty structures (these would be developed in implementing regulations), the bill establishes AIDA's authority to impose administrative sanctions for violations and coordinates with existing criminal laws addressing AI misuse. Administrative Penalties anticipated in implementing regulations would include formal warnings placed on public record for minor or first-time violations where organizations demonstrate good faith efforts to comply; monetary fines scaled to violation severity and organization size, potentially ranging from PHP 100,000 to PHP 10,000,000 (approximately USD 2,000 to USD 200,000), with higher fines for large corporations and lower fines for small businesses and startups; suspension of operations for specific AI systems found to pose immediate risks pending corrective action and recertification; revocation of licenses or certifications for serious or repeated violations, prohibiting continued operation until compliance is demonstrated; and corrective action orders requiring organizations to modify AI systems, improve governance, enhance transparency, or implement bias mitigation measures. Criminal Liability would arise under existing laws when AI is used to commit crimes. Violations of the Data Privacy Act of 2012 involving unauthorized processing of personal data, particularly sensitive personal information, carry penalties including imprisonment of one to three years and fines of PHP 500,000 to PHP 4,000,000 (approximately USD 10,000 to USD 80,000). The Cybercrime Prevention Act of 2012 criminalizes computer-related fraud, identity theft, and cyberattacks, with penalties including imprisonment of six months to twelve years depending on offense severity; AI used to perpetrate these crimes would be addressed under these provisions. The Revised Penal Code addresses fraud, defamation, and other offenses that could be committed through AI systems, with traditional criminal penalties applying. AIDA would coordinate with the Department of Justice and law enforcement agencies to ensure criminal prosecution of serious AI-enabled offenses supplements administrative enforcement. Civil Liability under general Philippine tort law would enable individuals harmed by AI systems to seek damages through civil lawsuits, potentially alleging negligence in AI development or deployment, strict liability for defective products where AI is embedded in consumer goods or medical devices, breach of contract where AI service providers fail to meet agreed standards, or violation of constitutional and statutory rights including privacy, equal protection, and due process. AIDA's findings and enforcement actions could serve as evidence in civil proceedings. Director and Officer Liability provisions anticipated in implementing regulations could hold corporate executives personally liable for egregious violations involving willful misconduct, gross negligence, or deliberate circumvention of regulatory requirements, incentivizing strong corporate governance and compliance cultures. Appeals Processes would enable organizations subject to AIDA sanctions to file administrative appeals within AIDA, presenting evidence and arguments for reconsideration; appeal adverse AIDA decisions to the Office of the President or designated administrative appellate body; and ultimately seek judicial review in Philippine courts, with Court of Appeals jurisdiction over AIDA final orders and potential elevation to the Supreme Court on questions of law, constitutional rights, or regulatory authority. Due process protections ensure organizations receive notice of alleged violations, opportunities to respond and present evidence, and written decisions explaining the basis for sanctions. Whistleblower Protections anticipated in implementing regulations would shield employees who report violations within their organizations or to AIDA from retaliation, encouraging internal disclosure of compliance failures before they escalate to serious harms.

Relationship to Other Instruments

House Bill 7396 exists within and seeks to coordinate a complex ecosystem of Philippine laws, regulations, and policy frameworks relevant to AI governance. The bill explicitly requires AIDA to ensure AI systems comply with the Data Privacy Act of 2012 (Republic Act No. 10173), the Philippines' foundational data protection law. AIDA would work with the National Privacy Commission to develop AI-specific interpretations of data privacy principles including consent, purpose limitation, data minimization, accuracy, security, and accountability, addressing unique challenges posed by machine learning's data-intensive nature and algorithmic decision-making's complexity. AI applications involving cybersecurity or cybercrimes would be governed by the Cybercrime Prevention Act of 2012 (Republic Act No. 10175), with AIDA coordinating with the Cybercrime Investigation and Coordinating Center (CICC) and Department of Justice on AI-enabled offenses. Consumer protection dimensions of AI would involve coordination with the Consumer Act of the Philippines (Republic Act No. 7394) and the Department of Trade and Industry's consumer protection bureau, particularly regarding AI in products, misleading AI-generated advertising, and automated customer service. Financial AI applications would require coordination with the Bangko Sentral ng Pilipinas (BSP) under its broad authority to regulate financial institutions and payment systems, with AI used in credit scoring, fraud detection, algorithmic trading, and customer service subject to both AIDA standards and BSP-specific requirements. Healthcare AI would coordinate with Food and Drug Administration regulations governing medical devices and the Department of Health's health information system policies, with AI diagnostic tools, treatment recommendation systems, and health records management requiring multi-agency oversight. Employment AI would intersect with the Labor Code of the Philippines and Department of Labor and Employment oversight, particularly regarding AI in hiring, performance evaluation, workplace monitoring, and automation's workforce impacts—areas also addressed by pending House Bill No. 9448 (Protection of Labor Against AI Automation Act). Electoral AI use would coordinate with COMELEC Resolution No. 11064 and pending House Bill No. 10567 addressing deepfakes and AI in political campaigns. The bill supports and formalizes elements of the National AI Strategy Roadmap (NAISR) led by DTI, with AIDA institutionalizing the governance and regulatory dimensions of that strategy. Research and development aspects would coordinate with DOST's AI R&D Roadmap, ensuring AIDA standards support innovation while managing risks. House Bill 7396 also relates to other pending AI legislation including House Bill No. 9448 (Protection of Labor Against AI Automation) addressing workforce impacts, House Bill No. 7913 (AI Bill of Rights) emphasizing fundamental rights protections, House Bill No. 10567 (Regulation of AI Use in Elections) addressing electoral deepfakes, and House Bill No. 7983 (National Center for AI Research) supporting research infrastructure. These bills could be integrated into House Bill 7396 through amendments, enacted separately as complementary legislation, or consolidated into comprehensive AI legislation. Internationally, the bill aims to align with OECD AI Principles, UNESCO Recommendation on the Ethics of AI, and regulatory frameworks in major trading partners particularly the European Union AI Act, ensuring interoperability while preserving Philippine policy space for context-appropriate governance.

International Alignment

House Bill 7396 demonstrates deliberate alignment with emerging international AI governance norms while maintaining flexibility for Philippine-specific priorities and developmental stage. The bill's establishment of a dedicated AI regulatory authority mirrors approaches in the European Union (European AI Office), United Kingdom (Foundation Model Taskforce evolving toward AI Safety Institute), and Singapore (AI Governance and Ethics Initiative), reflecting global convergence on the need for specialized institutional capacity addressing AI's unique challenges. The risk-based regulatory approach implicit in the bill—with heightened requirements for high-risk applications and lighter oversight for low-risk uses—aligns with the European Union AI Act's core architecture, facilitating regulatory interoperability and reducing compliance complexity for multinational technology companies operating across Philippines and EU markets. The bill's emphasis on ethical AI principles including transparency, accountability, fairness, and human rights protection directly reflects principles articulated in the OECD Principles on Artificial Intelligence (adopted 2019, updated 2024), to which the Philippines is a signatory as an OECD member, demonstrating commitment to international standards. The focus on ensuring AI benefits all segments of society, reduces inequalities, and respects cultural diversity aligns with UNESCO's Recommendation on the Ethics of Artificial Intelligence (adopted 2021), which emphasizes human rights, dignity, inclusion, and sustainable development as foundational AI governance values. House Bill 7396's coordination requirements between AIDA and the National Privacy Commission regarding AI data protection align with international data protection frameworks including the EU's General Data Protection Regulation (GDPR), particularly GDPR provisions on automated decision-making (Article 22), data protection by design (Article 25), and algorithmic transparency. This alignment facilitates Philippine organizations' participation in global data flows under adequacy frameworks. The bill's provisions addressing AI safety, security, and robustness reflect principles from the United States' National Institute of Standards and Technology (NIST) AI Risk Management Framework, providing common technical language and methodologies facilitating international research collaboration and technology transfer. AIDA's anticipated participation in international standards development through ISO/IEC JTC 1/SC 42 (Artificial Intelligence) and IEEE technical committees positions the Philippines to influence global technical standards while ensuring Philippine regulations remain interoperable with international practice. The bill's balance between promoting innovation and managing risks aligns with approaches in Singapore's Model AI Governance Framework and Japan's Social Principles of Human-Centric AI, emphasizing governance flexibility and multi-stakeholder engagement rather than rigid rules. House Bill 7396's framework accommodates participation in regional AI cooperation through ASEAN's digital economy initiatives, contributing to development of ASEAN AI governance frameworks and digital single market integration while respecting national sovereignty and developmental diversity. The bill's provisions regarding AI in critical infrastructure, national security, and public services align with concerns expressed in the United States' Executive Orders on AI (2023) and European Union's cybersecurity and critical infrastructure protection frameworks, enabling security cooperation with international partners. The anticipated inclusion of provisions addressing frontier AI systems and general-purpose AI in implementing regulations would align the Philippines with global efforts to govern increasingly powerful AI capabilities, including international discussions on AI safety, catastrophic risks, and existential risks convened through the UK AI Safety Summits, UN AI for Good initiatives, and multilateral AI safety research collaborations. The bill positions the Philippines as an active participant in global AI governance norm development rather than a passive recipient of externally developed standards, contributing Philippine perspectives on linguistic diversity, development priorities, disaster resilience, and democratic governance to international discussions.

Implementation Timeline

DateMilestone
2023-03-01House Bill No. 7396 introduced in the House of Representatives
2023-2024Committee hearings, stakeholder consultations, and bill refinement
TBDHouse floor debate and voting (if approved by committee)
TBDSenate consideration and potential passage of companion bill
TBDBicameral conference committee reconciliation (if House and Senate versions differ)
TBDPresidential signing into law (if passed by Congress)
Enactment + 30 daysLaw takes effect (standard effectivity period unless otherwise specified)
Enactment + 90 daysAIDA Administrator appointment and confirmation
Enactment + 6 monthsAIDA operational establishment: hiring, office setup, advisory boards
Enactment + 12 monthsPublication of initial implementing regulations and standards for public comment
Enactment + 18 monthsFinalization of initial regulatory framework; voluntary compliance period begins
Enactment + 24 monthsMandatory registration requirements take effect
Enactment + 30 monthsLicensing and certification requirements for high-risk AI systems take effect
Enactment + 36 monthsFull regulatory framework operational; comprehensive enforcement begins
Enactment + 5 yearsComprehensive legislative review and potential amendments

Sources and References

SourceType
Philippine House of Representatives Official WebsitePrimary Source
MTF Counsel: AI Regulation Underway in CongressSecondary Source
Digital Policy Alert: HB7396 Introduction NoticeSecondary Source
OpenGov Asia: Legislative Efforts to Advance AI Governance in the PhilippinesSecondary Source

Requirements for a company

What an organisation has to do under Philippines - AI Development Regulation (HB 7396), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.

Must do

0

Nothing in this category.

Must not do

0

Nothing in this category.

Should do

8
  • Register AI systems with AIDA to ensure visibility within the national AI database.AI developers and deployers
  • Demonstrate competence, security measures, and ethical compliance to obtain necessary licensing before deploying high-risk AI systems.Developers of high-risk AI systems
  • Conduct periodic self-assessments against established AI standards to evaluate compliance and plan remediation.Organizations deploying high-risk AI systems
  • Notify AIDA promptly of any significant incidents, including system failures, data breaches, discriminatory outcomes, or safety events.Organizations deploying high-risk AI systems
  • Submit annual reports to AIDA detailing AI system changes, incidents, malfunctions, and risk management updates.Organizations deploying high-risk AI systems
  • Comply with the Data Privacy Act of 2012 by establishing appropriate consent, data minimization, and purpose limitation mechanisms.AI developers and deployers
  • +2 more in the table below

Should not do

1
  • Do not deploy AI systems that create systematic algorithmic discrimination or unfair outcomes based on protected characteristics.AI developers and deployers

Who must do what

The obligations under Philippines - AI Development Regulation (HB 7396), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1AI developers and deployersRegister AI systems with AIDA to ensure visibility within the national AI database.
AI System Registration would create a central database of AI developers and deployers
Monitoring and EvaluationRecommended
2Developers of high-risk AI systemsDemonstrate competence, security measures, and ethical compliance to obtain necessary licensing before deploying high-risk AI systems.
establishing licensing requirements obligating developers to demonstrate competence, security measures, and ethical compliance before deploying AI
Before deploymentKey Focus AreasRecommended
3Organizations deploying high-risk AI systemsConduct periodic self-assessments against established AI standards to evaluate compliance and plan remediation.
require organizations deploying high-risk AI systems to conduct periodic self-assessments against AIDA standards, documenting compliance measures
Monitoring and EvaluationRecommended
4Organizations deploying high-risk AI systemsNotify AIDA promptly of any significant incidents, including system failures, data breaches, discriminatory outcomes, or safety events.
notify AIDA of significant incidents including system failures, data breaches, discriminatory outcomes, or safety events.
Monitoring and EvaluationRecommended
5Organizations deploying high-risk AI systemsSubmit annual reports to AIDA detailing AI system changes, incidents, malfunctions, and risk management updates.
submit annual reports describing AI system changes, incidents or malfunctions, and risk management updates
Monitoring and EvaluationRecommended
6AI developers and deployersComply with the Data Privacy Act of 2012 by establishing appropriate consent, data minimization, and purpose limitation mechanisms.
explicitly requires AIDA to ensure AI systems comply with the Data Privacy Act of 2012 (Republic Act No. 10173)
Relationship to Other InstrumentsRecommended
7Deployers of critical AI systemsMaintain meaningful human oversight over AI systems operating in critical application domains.
human oversight ensuring meaningful human control over AI systems in critical applications
Key Focus AreasRecommended
8AI developers and deployersDo not deploy AI systems that create systematic algorithmic discrimination or unfair outcomes based on protected characteristics.
fairness requirements preventing algorithmic discrimination and bias
Key Focus AreasRecommended
9Deployers of high-risk AI systemsProvide clear transparency regarding AI decision-making processes and operating logic to affected individuals.
mandatory requirements for transparency in AI decision-making, particularly for high-risk applications
Key Focus AreasRecommended

© Regulations.AI · updated on 13-Jun-2026 · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash