New AI laws should target data governance and safety to build confidence: experts

Leopold Chen約 12 分鐘閱讀

站內可閱讀至 (台北時間)

本站保存版本
字級

Hong Kong should enact laws on data governance and underlying safety standards to ensure the responsible use of artificial intelligence (AI), experts have said, as the government pledged to tackle disputes or crimes involving the technology’s application with tailored legislation.

They also said that legislation was needed to define liability boundaries, which could bolster business and public confidence in expanding its adoption.

Chief Executive John Lee Ka-chiu said in his recent policy address that authorities would study new legislation to tackle cyber-enabled crimes. A working group led by the Department of Justice would review whether existing laws were adequate in addressing liability issues arising from accidents or damage caused by AI products, he added.

Police have identified AI as one of the five major cyber threats in 2026, with the force recording cases in which suspects used AI-generated materials for scams or fabricated identity cards with deepfakes to set up bank accounts for money laundering.

Innovation and technology sector lawmaker Duncan Chiu said Hong Kong’s legislation should focus on underlying data security, as it would be difficult for laws to catch up with the rapid evolution of individual AI applications.

“AI can only work with the presence of underlying data, and therefore enhancing data governance is the most fundamental,” he said, pointing to mainland China’s Data Security Law as a reference for Hong Kong.

The law established a tiered data protection system, requiring authorities to implement differentiated management and protection measures based on the importance and sensitivity of the data, while each central ministry and regional government shall also establish tailored measures on data under its purview.

Mainland authorities implemented their national standard on data classification and grading in 2024, breaking it down into three categories: core, important and general. Regulators across various sectors, including banking, automotive, industry and information technology and ecology, have introduced their respective data security standards accordingly.

Chiu added that data governance would be a complex issue with various levels of sensitivity and different use scenarios, making the involvement of industry members indispensable.

“While the government can come up with a broader framework, different industries should also have their respective detailed governance guidelines,” he said.

Leonard Chan Tik-yuen, founding chairman of the Hong Kong Innovative Technology Development Association, said that while the city had in place detailed AI application guidelines, their deterrent effect was insufficient to ensure responsible use.

“The industry hopes that there could be legislation to support the healthy development of AI and prevent crimes,” he said.

Echoing Chiu’s remarks, Chan said the law should not target individual AI functions and should instead focus on digital literacy, underlying data security standards and users’ auditing requirements.

He also suggested that Hong Kong introduce a “safe harbour” system, in which the liabilities of users in data breaches could be mitigated if they followed stringent requirements on disclosure, auditing and risk control, so as to offer incentives for them to follow.

“In this case, companies would know where the red line lies and would be encouraged to comply with such requirements,” he said, adding that clearer laws would especially benefit small and medium-sized enterprises, which usually lacked resources for costly legal consultancy.

Secretary for Justice Paul Lam Ting-kwok earlier said that while existing laws in the city could address AI-related crimes, the review aimed to formulate more targeted legislation to keep pace with rapid technological advancement and handle cases more effectively.

He admitted that legislation could fall behind technological advancement, but expected that Hong Kong’s AI laws would be “forward-looking” to cover foreseeable risks.

Legislator Priscilla Leung Mei-fun, who is also a law professor, said Hong Kong currently lacked codified laws to govern the technology, and disputes arising from AI use were mainly subject to common law principles and precedents, which might not be well-known among the general public.

“In fact, even without a codified ordinance, for any problems, troubles, accidents, or harm that an AI has caused to particular individuals or particular materials, goods or properties, the user of the AI has to be ultimately liable,” she said.

Deepfakes have remained a prevailing concern in Hong Kong after a male student at the University of Hong Kong allegedly used his female classmates’ photos to produce intimate pictures using the technology and stored them on his own laptop last year.

The male student did not face any criminal accusations as current laws only govern the distribution and publication of indecent and obscene materials instead of production and possession.

On regulating deepfake risks, justice minister Lam said late last month that the Law Reform Commission was deliberating whether the production of such materials should be criminalised, as the body would also need to strike a balance with personal freedom.

Both lawmakers Chiu and Leung agreed that criminalising unauthorised deepfake production and possession should be considered.

“Other than indecent or intimate materials, deepfakes could also damage others’ reputations by using their faces to say terrible things,” Chiu said. “Once circulated, this can cause severe stress or emotional distress.”