Hong Kong authorities and experts have called for new legislation addressing data governance and safety standards to manage the responsible use of artificial intelligence (AI), amid increasing concerns over cyber-enabled crimes involving the technology.
In his recent policy address, Chief Executive John Lee Ka-chiu announced plans to examine tailored laws aimed at tackling crimes and disputes linked to AI applications. A working group under the Department of Justice has been established to review the adequacy of existing legal frameworks, particularly concerning liability issues from accidents or damages related to AI products.
Law enforcement agencies have identified AI as one of the top five cyber threats anticipated in 2026. Police records show cases where suspects used AI-generated materials for scams, including the creation of fraudulent identity cards using deepfake technology to open bank accounts for money laundering purposes.
Lawmaker Duncan Chiu, representing the innovation and technology sector, emphasized the need for legislation to focus on data security rather than specific AI functions. “AI can only work with the presence of underlying data, and therefore enhancing data governance is fundamental,” he said, pointing to mainland China’s Data Security Law as a potential model. That law institutes a tiered system of data protection, requiring government bodies to implement differentiated management based on data sensitivity, along with tailored regional measures.
Chiu noted the complexities in regulating data due to varying levels of sensitivity and diverse use cases, suggesting that industry involvement is crucial in developing detailed governance guidelines within a broader governmental framework.
Leonard Chan Tik-yuen, founding chairman of the Hong Kong Innovative Technology Development Association, agreed that existing AI application guidelines lack sufficient deterrence. He advocated for legislation that supports AI’s healthy development and crime prevention, focusing on digital literacy, data security standards, and user auditing rather than regulating discrete AI functionalities.
Legal perspectives highlight the current gaps in Hong Kong’s regulatory landscape. Legislator and law professor Priscilla Leung Mei-fun observed that AI-related disputes are presently governed by common law principles and precedents, which may not be widely understood by the public. She stressed that users remain ultimately liable for any harm caused by AI, even in the absence of codified statutes.
Concerns over deepfake technology have persisted following a case last year in which a University of Hong Kong student allegedly used classmates’ photos to create intimate images stored on his laptop. No criminal charges were brought due to laws focusing on the distribution and publication of indecent materials, but not on their production or possession.
Addressing the regulatory challenges posed by deepfakes, Secretary for Justice Paul Lam Ting-kwok said the Law Reform Commission is considering whether criminalizing the production of such materials is appropriate, while seeking to balance enforcement with safeguarding personal freedoms.
