Lexguard AI logo
Lexguard AI logo

AI in Hong Kong Has Moved from Experimentation to Executive Accountability

An executive summary of the PCPD’s 2026 AI compliance findings, highlighting the key trends, remaining governance gaps, and the practical actions senior executives should take to manage AI risk responsibly.

Lewis Ho

Artificial intelligence is no longer a pilot project sitting at the edge of the enterprise. In Hong Kong, it is fast becoming part of core operations, from customer service and marketing to compliance, risk management and administration. That is the clearest signal from the Hong Kong Privacy Commissioner for Personal Data’s latest compliance checks on 60 organisations, published on 19 May 2026.

For senior executives, the message is straightforward: AI adoption is accelerating, regulatory expectations are maturing, and governance can no longer be delegated solely to IT or innovation teams.

The good news is that the Privacy Commissioner found no contravention of the Personal Data (Privacy) Ordinance (PDPO) among the organisations reviewed. But that should not be read as a green light for complacency. Instead, it reflects something more important: regulators now expect organisations to use AI with structure, discipline and board-level oversight.

This is especially relevant for Hong Kong businesses that also operate in Mainland China. As we have noted before, a purely Hong Kong-focused AI framework is often too narrow. For many organisations, executive decision-making now needs to account not only for the PDPO, but also for Mainland-facing rules on data governance, algorithmic systems, cross-border data flows and AI deployment practices.


What the 2026 findings tell executives

The headline figure is striking: 95% of the 60 organisations reviewed were already using AI in day-to-day operations, up from 80% in 2025. Nearly four in five had been using AI for more than a year, and about half were using three or more AI systems.

This matters because AI has clearly crossed a threshold. It is no longer an isolated tool used by a few functions. It is becoming operational infrastructure.

The Commissioner’s findings also show where AI is being used most often:

  • administrative support

  • customer service

  • research and development

  • marketing

  • compliance and risk management

That pattern should catch the attention of the C-suite. These are not marginal use cases. They are functions that influence customer interactions, internal efficiency, control environments and business decision-making.

Privacy risk is becoming more targeted — but not necessarily smaller

Among the organisations using AI, 42% collected and/or used personal data through AI systems. Interestingly, this is lower than in 2025, suggesting that some organisations may be becoming more selective about where personal data is introduced into AI workflows.

There are encouraging signs in the report:

  • 100% of organisations collecting or using personal data through AI provided Personal Information Collection Statements.

  • 100% implemented security measures such as access controls, encryption, penetration testing and anonymisation.

  • Only 29% retained personal data collected through AI systems, a sharp drop from around 79% in 2025.

  • 63% used anonymised or pseudonymised data.

  • 33% used privacy-enhancing techniques such as synthetic data and federated learning.

These figures suggest that many organisations are becoming more thoughtful about data minimisation, retention discipline and technical safeguards.

But there is a second reading that boards should not miss: the governance challenge is becoming more complex, not less.

As AI becomes more embedded, the risk is no longer limited to whether personal data is collected. It extends to how data flows through prompts, models, plugins, logs, analytics environments, third-party tools and increasingly, agentic systems. Executive teams should therefore resist the temptation to interpret lower data retention figures as lower risk overall.


The governance gap is no longer about awareness — it is about execution

One of the most useful aspects of the Commissioner’s findings is that they reveal where mature organisations are differentiating themselves.

Among the organisations using AI with personal data:

  • 96% tested AI systems before implementation for reliability, robustness and fairness

  • 79% conducted privacy impact assessments before implementation

  • 79% adopted a human-in-the-loop oversight approach

  • 92% had data breach response plans

  • 63% conducted regular internal audits and/or independent assessments

  • 79% established AI governance structures

  • 83% provided AI-related training to employees

  • 90% of those training programmes covered AI-related privacy risks

The findings also expose where leadership attention may be uneven. Only 50% had formulated AI-related policies, and only 54% had held board-level discussions on AI use. For senior executives, that is the real warning sign.

In other words, organisations are deploying controls, but not all of them have fully embedded AI into formal enterprise governance. That creates a familiar kind of risk: technology adoption moving faster than management systems.

Why senior executives should care now

For boards and executive committees, the issue is no longer whether AI creates opportunity. That is already settled. The question is whether the organisation can scale AI without scaling unmanaged risk.

The Commissioner’s latest recommendations point to a governance model that is increasingly aligned with what boards should already expect in other high-impact areas: clear accountability, risk assessment, documented policies, training, incident readiness, auditability and stakeholder transparency.

From a leadership perspective, five implications stand out.

1. AI must be treated as an enterprise risk issue

AI should sit alongside cybersecurity, privacy, operational resilience and third-party risk — not beneath them. If the board is not receiving regular reporting on AI use, risk tiering and controls, governance is likely lagging adoption.

2. Employee use of generative AI is now a policy issue, not a personal productivity choice

All organisations reviewed that collected and/or used personal data through AI systems allowed employees to use generative AI at work. Yet only 71% had specific internal policies or guidelines. That gap is material. In practice, many of the greatest risks arise not from enterprise-approved systems, but from everyday use by employees who may upload confidential, personal or commercially sensitive data into external tools.

3. Human oversight remains a regulatory expectation

The strong prevalence of the human-in-the-loop model is significant. It suggests that regulators continue to view meaningful human review as a core safeguard, especially where AI affects individuals or processes personal data. For executives, this means efficiency goals must be balanced against accountability and intervention capability.

4. AI incident response must evolve beyond traditional data breach playbooks

The report shows progress here, but only 41% specifically addressed AI-related incidents in their breach response plans. Traditional cyber incident plans may not be enough for AI failures involving hallucinated outputs, misclassification, improper automated decisions, model drift, prompt leakage or unsafe agentic actions.

5. Hong Kong-only governance may be too narrow for many groups

For companies with Mainland operations, customers, staff, data or infrastructure, AI governance should be designed with a cross-border lens. The operational reality is that an AI tool approved in Hong Kong may trigger additional scrutiny once deployed across the broader group. Executive teams should therefore assess not only whether AI complies locally, but also whether it creates Mainland-related data, transfer, algorithmic or service-governance implications.


The rise of agentic AI raises the stakes further

One notable feature of the Commissioner’s recommendations is the explicit warning to use agentic AI prudently. It signals where regulatory attention is heading. Apart from generating content, agentic AI systemsan take actions, call tools, chain decisions and operate with varying degrees of autonomy. That changes the risk profile substantially. The concern is no longer only what the model says, but what it can access, trigger, disclose or execute.

For executive teams, this means agentic AI should not be deployed under the same approval logic as a basic chatbot or drafting assistant. It requires tighter access control, stronger permissions design, controlled integrations, enhanced monitoring and a clear understanding of what the system is authorised to do.

What “good” now looks like

Based on the Commissioner’s findings, leading organisations are starting to converge around a more mature model of AI governance. In practical terms, that model includes:

  • an AI governance structure with named accountability

  • clear internal rules for employee use of generative AI

  • privacy impact assessments and broader risk assessments before deployment

  • data minimisation and disciplined retention practices

  • strong technical controls, including encryption, access controls and testing

  • meaningful human oversight for higher-risk use cases

  • AI-specific incident response planning

  • regular audit or independent review

  • staff training that includes privacy and misuse risks

  • ongoing communication with stakeholders

In many sectors, the organisations that can demonstrate responsible AI use will be better placed to win confidence, satisfy counterparties and move faster when regulators, investors or business partners ask the obvious next question: show us your controls.


A boardroom agenda for the next 90 days

For senior executives who want to respond pragmatically, the following agenda is a strong starting point:

1. Establish or refresh the AI inventory

Identify where AI is being used across the business, including unofficial employee use, embedded vendor tools and cross-border deployments. Learn more about where to start with here.

2. Classify AI use cases by risk

Separate low-risk productivity tools from high-impact systems involving personal data, customer interaction, decision support, HR, compliance or autonomous action. Learn more about Risk Tiering System.

3. Review employee use of generative AI

If internal guidelines do not exist or are too generic, update them now. Include rules on confidentiality, personal data, prompts, outputs, approval requirements and prohibited uses. Learn more about Employee AI Policy.

4. Test governance against agentic AI

Review whether current controls are suitable for tools that can retrieve data, take actions or operate across systems. Learn more about stress testing AI systems here.

5. Update incident response plans

Ensure AI-related scenarios are covered explicitly, including output errors, prompt leakage, unauthorised access, unsafe automation and third-party model failures.

6. Put AI on the board agenda

If AI has not been discussed recently at board or executive committee level, that is itself a governance issue. The latest PCPD findings make clear that AI is now a matter of strategic oversight.

7. Assess Mainland exposure

For Hong Kong groups with Mainland touchpoints, conduct a structured review of whether current AI use cases involve Mainland data, users, operations or transfers. Learn more about China's PIPL here.


The strategic takeaway

The Privacy Commissioner’s 2026 exercise sends a clear signal to the market. Hong Kong is not resisting AI adoption; it is encouraging responsible adoption. That distinction matters.

For business leaders, the path forward is not to slow innovation. It is to govern it with enough precision that the organisation can scale confidently, withstand scrutiny and avoid preventable mistakes.

The next phase of AI leadership will not belong to the companies that simply deploy the most tools. It will belong to those that can show regulators, customers, employees and investors that their AI use is intentional, controlled and board-ready.

At Lexguard, we believe that is where executive attention should now be focused: not on whether AI is coming, but on whether your governance model is ready for the version of AI your business is already using.


How Lexguard can help

Lexguard advises organisations on building practical AI governance frameworks that align innovation with privacy, regulatory and operational risk management. For Hong Kong businesses, particularly those with Mainland-facing operations, that means helping leadership teams move from fragmented AI use to a defensible governance model covering:

  • AI strategy and accountability

  • PDPO-aligned privacy governance

  • employee generative AI policies

  • risk assessments and impact assessments

  • vendor and procurement controls

  • incident response planning

  • cross-border and Mainland-related risk analysis

  • board and executive reporting frameworks

Learn more about our AI Governance Training for Boards and Employees here.

FAQ

1. Why is AI governance now a board-level issue in Hong Kong?

AI is now being used across core business functions such as customer service, administration, marketing, research, and compliance. As adoption increases, the issue is no longer just about technology deployment. It has become a matter of risk management, accountability, privacy, and operational oversight, which requires attention from senior leadership and boards.

2. What did the PCPD’s 2026 compliance checks show about AI use?

The PCPD found that AI adoption among reviewed organisations is widespread and becoming more structured. Many organisations are using AI in daily operations, carrying out privacy impact assessments, applying human oversight, strengthening security controls, and providing employee training. At the same time, the findings suggest that some organisations still need to strengthen internal policies and board-level oversight.

3. What should organisations do next to strengthen AI governance?

Organisations should start by identifying where AI is being used across the business, especially in areas involving personal data or higher-risk decisions. They should also put in place clear internal policies, assign accountability, maintain human oversight where needed, update incident response plans, and review any Hong Kong and Mainland China cross-border implications.