Experts urge Hong Kong to build AI rules around data security and liability

Technology and legal specialists say Hong Kong’s planned AI legislation should establish data-governance standards, audit duties and clearer liability rules rather than regulate individual applications. The government is reviewing existing laws as police report scams and forged identities involving AI-generated material.
Hong Kong experts are calling for new artificial-intelligence rules focused on data governance, safety and accountability as the government reviews whether existing laws can address technology-related crimes and disputes. Chief Executive John Lee Ka-chiu said authorities would study legislation targeting cyber-enabled crimes. A Department of Justice working group will also examine liability arising from accidents or damage caused by AI products.
Police have identified AI as one of five major cyber threats in 2026. The force has recorded cases involving AI-generated material used in scams and fabricated identity cards, including deepfakes allegedly used to establish bank accounts for money laundering. Lawmaker Duncan Chiu said legislation should concentrate on underlying data security because applications are evolving faster than lawmakers can regulate individual functions.
He pointed to mainland China’s tiered data-protection system as a possible reference and said industries should help produce detailed rules for different types of data and uses. Leonard Chan, of the Hong Kong Innovative Technology Development Association, said existing application guidelines lacked sufficient deterrent force. He supported requirements covering digital literacy, data security and user audits, and proposed a safe-harbour system for organisations that met strict disclosure, auditing and risk-control standards.
Secretary for Justice Paul Lam Ting-kwok said current laws could address AI-related crimes but that more targeted legislation might handle cases more effectively. Legislator and law professor Priscilla Leung said disputes are currently governed mainly by common-law principles, which may be unfamiliar to the public. Deepfakes remain a particular concern.
The Law Reform Commission is considering whether producing such material should become a criminal offence. Chiu and Leung said unauthorised production and possession should be considered, citing risks to privacy, reputation and emotional wellbeing.
This independently written report is based on information supplied by the named publisher. Vertrix News has not independently verified the source report.