From Principles to Proof: Building Robust and Reliable AI Governance in Hong Kong

Sam Wu • 6 October 2026
Sam Wu

Partner, Hong Kong


Download PDF

From Principles to Proof: Building Robust and Reliable AI Governance in Hong Kong

Technology‑driven companies are no longer judged only on what their artificial intelligence (“AI”) can do, but on whether they can prove that it is governable, auditable, and investable. While Hong Kong’s emerging AI governance framework relies on existing legal regimes on data protection, financial regulation, copyright, consumer protection and common‑law duties, it increasingly expects institutions to demonstrate responsible AI deployment through internal governance, documentation and third‑party risk management, rather than through a standalone AI statute.


This article builds on Hong Kong’s Ethical Artificial Intelligence Framework (“Ethical AI Framework”), the Hong Kong Generative Artificial Intelligence Technical and Application Guideline (“Generative AI Guideline”) and the Hong Kong Digital Policy Office’s presentation titled “AI Governance in Hong Kong – Trusted AI in Practice: Governance & Third Party Risk Management” (“Trusted AI in Practice”) to ask a practical question: what does “good AI governance” look like when a board, investor, stakeholder or regulator asks the company to show its work? The focus is not just on what the law says, but also on how boards and management teams can evidence governance, accountability and human oversight across the lifecycle of increasingly complex AI systems.


From ethical AI to provable AI


Hong Kong’s approach to AI is deliberately incremental. In early 2026, the Hong Kong government reiterated that AI would continue to be regulated mainly through existing regimes, including the Personal Data (Privacy) Ordinance, licensing and conduct requirements under the Securities and Futures Ordinance, anti‑money laundering rules and consumer protection, supplemented by non‑binding frameworks and sectoral guidance. In that setting, the focus is no longer simply on the existence of an AI policy, but on whether an organization can show that its AI use cases are subject to effective and accountable governance.


The Ethical AI Framework, originally designed for government departments and now promoted as a reference for any organization operating AI systems in Hong Kong, articulates twelve ethical principles spanning transparency, interpretability, robustness, security, fairness, human oversight, accountability, data privacy and more. The Generative AI Guideline adds a four‑tier risk classification – unacceptable, high, limited and low risk – with escalating governance expectations. Taken together, these instruments already hint at what “provable AI governance” entails: mapping use cases to risk tiers, documenting design and oversight decisions, and integrating AI into existing risk and compliance architectures.


For technology‑driven companies seeking to scale and raise capital across borders, this is not a purely local issue. Global investors increasingly apply similar lenses, whether or not the home jurisdiction has a dedicated AI statute. Companies should therefore be prepared to demonstrate that they know where AI is embedded in their operations, understand the associated risks, and have a credible governance response.


AI governance: managing model and operational risk


One of the most practical contributions of the Ethical AI Framework is the three‑lines‑of‑defence model for AI:

  1. project teams form the first line, responsible for design, risk assessment and initial mitigation; 

  2. project steering committees and assurance teams form the second line, responsible for independent review and approval; and 

  3. an information technology board or chief information officer, with external advisers where needed, forms the third line, responsible for ongoing oversight and monitoring of AI strategy and risks.


In practice, AI should be treated as a form of model risk and operational risk, rather than as a purely technical issue. That includes: 


  • setting a clear AI risk appetite, especially for high‑risk or safety‑critical systems;

  • requiring an inventory of material AI use cases, including the business owner, risk classification, and key controls;

  • insisting that high‑risk deployments such as credit scoring, trading algorithms, automated content moderation with legal implications receive explicit board or committee sign‑off;

  • clarifying who has authority to approve exceptions, for instance, greater autonomy for an agentic AI system or the use of untested models in production, etc.


A workable approach is to designate a senior executive owner for AI governance (such as the chief risk officer or a joint ownership model between business and technology) and to embed AI‑specific responsibilities into existing board committees (such as risk, audit, technology or conduct), rather than creating a standalone “AI committee” with an unclear mandate.


Risk‑based classification: turning frameworks into internal policy


The Generative AI Guideline’s four‑tier risk classification is conceptually simple but powerful when translated into internal policy. It distinguishes between unacceptable uses (envisaged as prohibited), high‑risk uses (requiring conformity assessments, human‑in‑the‑loop mechanisms and real‑time monitoring), limited‑risk cases (emphasizing self‑assessment and transparency) and low‑risk applications (eligible for lighter‑touch self‑certification).


To translate this risk-based framework into practice, organizations should at least take the following steps:


  • Define criteria that matter in the organization’s context: These typically include the impact on individuals’ rights and interests, financial or safety consequences, the sensitivity of the data involved, the scale of deployment, and the degree of automation. For example, an internal code assistant may be classified as limited‑risk, whereas an AI‑driven loan approval engine affecting retail customers would likely be high‑risk.

  • Create a use‑case register and classification workflow: New AI projects should be logged with a description of the business purpose, data sources, model type (including reliance on third‑party or foundation models), intended users, and preliminary risk classification. Changes to existing systems such as expanding scope, adding new data sources or increasing autonomy should trigger reassessment.

  • Integrate assessments with existing data protection impact assessments or fair‑risk impact assessments: Extending those templates to include AI‑specific questions on bias, explainability, robustness, and human oversight can reduce duplication and make AI governance feel like an evolution of existing practice, not a parallel bureaucracy.
Making AI governance auditable: documentation, logs and human override


If governance is to be credible, it must be auditable. The Hong Kong frameworks already hint at this by emphasizing project documentation and mapping of use cases against risk tiers and governance dimensions. For governance, assurance and accountability purposes, however, the necessary evidence base is more specific.


At a minimum, organizations should be able to produce:


  • a system and use‑case inventory showing where AI is used, who owns it, and how it is classified;

  • data lineage and training‑data documentation setting out key data sources, the purpose of data use, major preprocessing steps, and known limitations or exclusions;

  • model versioning and change logs capturing when models were trained, finetuned or replaced, what changed, and who approved it;

  • human oversight and override records documenting when humans reviewed or overrode AI outputs in high‑risk contexts, and how frequently such interventions occur.


For agentic AI and copilots that operate in semi‑autonomous ways, the challenge is to capture enough information to reconstruct significant decisions without overwhelming users. Practical approaches include:


  • logging prompts and outputs for high‑risk workflows (for example, automated drafting of customer communications or trading strategies), with appropriate access controls and retention policies;

  • requiring users to categorize the context (for example, “draft only, human review required” versus “system‑initiated action with human confirmation”) so that the applicable human review requirements are clear;

  • implementing procedures for promptly suspending, disabling or reverting AI systems when incidents occur, while maintaining appropriate records and corresponding audit trails.


These governance records are not only useful for internal audit and compliance, but also become critical evidence in regulatory investigations, disputes and post‑transaction reviews, where applicable.


Data governance, intellectual property (“IP”) and third‑party model risk


The 2026 “Trusted AI in Practice” materials place particular emphasis on third‑party AI risk, urging organizations to treat AI vendors, model providers and other external partners as integral parts of their risk profile. This reflects the reality for many technology‑driven businesses: core AI capabilities increasingly depend on cloud infrastructure, foundation models and APIs controlled by others.


From a governance and accountability perspective, boards, investors and relevant stakeholders should expect to see:


  • Clear mapping of dependencies: Which external models and services are used in critical workflows? Where are they hosted? What jurisdictions and regulatory regimes are involved?

  • Contractual clarity on IP and data: Who owns fine‑tuned models, derivative works and output? What rights does the provider have to use customer data to improve its own models? What happens to the model and training data if the relationship terminates?

  • Security and content‑risk controls: Are there contractual commitments on security standards, content filtering, and response times for vulnerabilities or harmful outputs?

  • Change‑management expectations: Are providers obliged to notify material model changes, allow testing before deployment, and support rollback if issues emerge?


In Hong Kong, even in the absence of a dedicated AI statute, these concerns are anchored in existing legal duties including data protection, confidentiality, IP rights and, in regulated sectors, supervisory expectations on outsourcing and operational resilience. For cross‑border businesses, they also intersect with localization pressures and restrictions on cross‑border data flows, requiring careful structuring of data storage, access and processing to support both compliance and scalability.


Accordingly, well‑drafted AI vendor arrangements are not just legal risk mitigants. They are also persuasive evidence for investors and stakeholders that the company understands and manages its dependency on third‑party technology.


AI in Commercial Practice: Due Diligence, Disclosure and Risk Allocation 


As AI becomes central to valuations, AI‑related claims are appearing more frequently in pitch decks, offering documents, M&A teasers and investor updates. Recurring issues include broad statements about “proprietary AI models” that are, in fact, heavily dependent on standard third‑party tools; ambitious claims about accuracy, efficiency or fairness that are not supported by robust testing; and lack of clarity about rights to use training data or outputs across markets.


For companies and their boards, this raises two intertwined questions: first, whether the claims are accurate, complete and not misleading; and second, whether the company can produce evidence to substantiate them if challenged. For investors and transaction lawyers, it suggests a set of due‑diligence themes, such as:


  • How does the company define “AI” in its business model, and where does genuine differentiation lie?


  • What AI governance documentation exists (policies, inventories, testing reports, incident logs)?


  • How are high‑risk AI use cases identified and controlled?


  • What AI‑related incidents have occurred (for example, model failures, bias or discrimination allegations, data breaches) and how were they remediated?


  • What regulatory interactions, if any, have taken place in connection with AI use?


These questions can then be reflected in transaction documentation. For example, AI‑intensive deals may include warranties that:


  • AI systems have been developed and used in accordance with applicable laws, internal policies and specified frameworks (potentially referencing recognized guidelines such as the Ethical AI Framework or Generative AI Guideline as benchmarks).


  • The company has disclosed material AI incidents and regulatory investigations.


  • The company has appropriate rights to use training data, models and outputs in relevant jurisdictions.


  • No material misstatements have been made in AI‑related marketing or investor communications.


Covenants can require post‑closing remediation of identified gaps in AI governance, implementation of minimum controls, or enhanced reporting on AI‑related risks. In pre‑IPO contexts, boards may wish to anticipate evolving disclosure expectations by including narrative on AI governance, risk management and human oversight in offering documents, rather than treating AI purely as a growth story.


An “AI governance pack”


For technology‑driven companies operating in or from Hong Kong, a practical way to make AI “governable, auditable and investable” is to assemble an internal “AI governance pack” that can be adapted for investors, stakeholders, regulators or transaction counterparties. Building on the existing frameworks, such a pack might include:


  • a concise AI governance policy aligned with recognized principles and risk‑tiering;


  • an inventory of material AI systems and use cases, with risk classifications and owners;


  • summaries of key controls for high‑risk systems, including human oversight and incident‑response procedures;


  • a description of data governance and third‑party model risk management, including contractual safeguards;


  • a log of material AI‑related incidents, remediation steps and regulatory interactions; and


  • board‑level reporting slides highlighting AI risk appetite, key metrics and planned enhancements.


This is not purely a compliance exercise. The process of compiling the pack often reveals gaps in documentation, inconsistencies in practice, or misalignments between technical capabilities and external claims. Addressing those issues can improve the robustness of AI‑enabled business models and give boards, investors, stakeholders and regulators greater confidence that AI is a source of durable value rather than an unmanaged risk.


Hong Kong’s guidance‑led, pro‑innovation approach not only gives companies flexibility in how they build such evidence, but it also places the onus on boards and advisers to define and implement credible governance in the absence of prescriptive rules. For organizations operating across borders, the same documentation can be leveraged to meet expectations under more prescriptive regimes and to demonstrate that AI systems are not only innovative, but also governable and accountable.


The way forward


For technology‑driven businesses, responsible AI governance should not be treated as a static compliance exercise or a barrier to innovation. Its practical value lies in enabling organizations to deploy AI with greater confidence: by identifying where accountability sits, testing and monitoring systems proportionately to risk, maintaining reliable records, and managing dependencies on data, infrastructure and third‑party providers. A governance framework that works in day‑to‑day operations is more likely to support informed decision‑making, prompt remediation and credible external communications when issues arise.


Hong Kong’s guidance‑led approach gives organizations flexibility to build controls appropriate to their business models and risk profiles. That flexibility, however, comes with a corresponding expectation that companies can explain and evidence the choices they have made. As AI becomes more embedded in products, operational processes and transaction value, the relevant question will increasingly be not simply whether a company uses AI, but whether it can demonstrate that its use of AI is reliable, accountable and capable of withstanding scrutiny.


The organizations that are best placed for the next stage of AI adoption will be those that translate high‑level principles into clear ownership, workable controls and reliable governance records. In doing so, they can treat AI governance not merely as a means of managing downside risk, but as an important foundation for trust, sustainable growth and long‑term enterprise value.


YYC Legal LLP is in Association with East & Concord Partners (Hong Kong) Law Firm.


This article was prepared as a contribution to the SLLS Global Thought Leadership 2026 Q3 TDG: Technology, Data and Governance edition. The full publication is available here: https://www.slls.global/upload/9-2.pdf.


This material has been prepared for general informational purposes only and is not intended to be relied upon as professional advice. Please contact us for specific advice.

Recent articles

by Rossana Chu • 25 September 2026
The Northern Metropolis has been incorporated into China's 15th Five-Year Plan, reinforcing Hong Kong’s integration into the nation’s overall development strategy.
by Rossana Chu • 28 August 2026
HKEX consistently emphasises importance of listed issuers complying with its listing rules. This article discusses several enforcement cases published by HKEX.
by Rossana Chu • 27 July 2026
This article provides commentary on the consultation launched by HKEX in March 2026 to solicit market feedback on its proposed reforms aimed at listing framework.
by Sam Wu, Beverly Fu • 20 July 2026
The HKSAR government reiterated that it will continue to regulate artificial intelligence mainly through existing regimes and concentrates on governance frameworks, guidelines and supervisory tools that guide institutions in deploying AI responsibly within the existing legal architecture.
by Valarie Fung • 13 July 2026
With heightened cryptocurrency trading and flow, related disputes are emerging with lightning speed, and Courts in HK are well equipped to deal with these disputes.
by Rossana Chu • 22 May 2026
HK regulators will implement USM in 2026, enhancing market efficiency, strengthening competitiveness, and modernising the securities market infrastructure in HK.
More articles

Recent News

12 June 2026
YYC Legal LLP is awarded in the “China Business Law Awards 2026” – international firms – as the Winner in the industry sector category of “Consumer and Retail”.
23 January 2026
We are pleased to announce that YYC Legal and Partner Rossana Chu are ranked in Chambers Greater China Region Guide 2026
16 January 2026
Rossana Chu is recognised as a Commended External Counsel in the In-House Community’s Counsel of the Year Awards 2025
28 November 2025
One of our Partners, Rossana Chu, is ranked by China Business Law Journal as one of The Visionaries (International) for 2025-26.
14 November 2025
We are pleased to announce that our Partner, Sam Wu, has been selected as a winner in both the LexisNexis® 40 UNDER 40 2025 – Asia List and the Hong Kong SAR List.
7 November 2025
We are delighted to announce that YYC Legal LLP (YYC Legal) and our lawyer have been recommended by asialaw as one of the top-performing legal firms and lawyers in Asia.
More News