詳細検索

[Latest in 2026] EU AI Act and Japan's Regulatory Response|5 Measures Security Personnel Should Take

Avatar
by 似里
3 min read

[Latest in 2026] EU AI Act and Japan's Regulatory Response|5 Measures Security Personnel Should Take
Translated from 日本語 • View original
似里
似里

Hello! I'm a Colorkrew infrastructure and security engineer. I was looking at Microsoft's documentation and found that the security bulletin on AI has been significantly updated. Therefore, this time, I would like to summarize the regulations on the use of AI that should be suppressed as a security officer.

Why does AI need "special" compliance responses?

AI has the characteristics of probabilistic output (answers fluctuate even with the same input), dependence on training data (inheritance of bias and privacy concerns), opacity (difficult to explain), and continuous evolution (change during operation), creating risks that are difficult to catch with traditional IT controls alone. Microsoft has established the principles of responsible AI (fairness, trust and safety, privacy and security, transparency, accountability, and inclusiveness) and a shared responsibility model, and recommends that controls be built in from the design stage. (Responsible AI - Microsoft)

About the use of AI in Japan

In Japan, the AI Law will be fully enforced in 2025, and the Cabinet Office's Artificial Intelligence Strategy Headquarters has begun to implement the AI Basic Plan and guidelines for ensuring its appropriateness. Although it is a philosophy law, transparency, risk management, and information provision practices are emphasized. (AI Law - Cabinet Office)

Overseas AI Usage

Full application of the EU:EU AI Act

Ahead of Japan, the EU has enforced stricter laws on the use of AI. The EU AI Act has been phased into effect since 2024. From August 2026 this year, high-risk requirements and other requirements will be applied in earnest, and extraterritorial application, high fines, and GPAI obligations will occur. If the law is applicable, the following measures are required. (EU Artifical Intelligence Act - EU)

  • Risk classification: Confirmation of whether or not high-risk areas such as recruitment, education, and critical infrastructure are applicable
  • GPAI Ready: Technical documentation, training data summaries, copyright compliance
  • Transparency obligations: Disclosure of information about AI service providers
  • Governance: risk management, data management, technical document management
  • Human monitoring: Human monitoring including system operation status and usage status

United States: NIST

Although there is no law enforced at the federal level in the United States, NIST has presented a policy for the use of AI. Among them, "validity and reliability", "safety", "security and resilience", "accountability and transparency", "explainability and interpretability", "enhanced privacy" and "fairness" are required.

How to respond to laws and regulations

Effective Use of Microsoft Products

In aiming for responsible use of AI, it is important to make effective use of the products provided by Microsoft. Therefore, we will introduce the use cases of various products.

  • Purview Compliance Manager: Visualize assessments and gaps with EU AI Act, ISO/IEC 42001, and NIST AI RMF templates
  • Defender for Cloud Apps+Purview: Detect, evaluate, and manage internal and external AI apps, and detect and investigate interactions with generative AI through communication and compliance
  • Azure AI Content Safety: Detects harmful content such as violence, hate, and self-harm
  • Audit, Retention, and eDiscovery: Utilize retention and audit logs, including Copilot's prompts/responses.

Using SOC Services

It is important to detect inappropriate use of AI systems, such as using Microsoft products, and to respond promptly. To achieve this, it is necessary to have a system in place that can handle the security use of AI from design to operation. If it is difficult to build such a system in-house, using an external SOC service is also an effective measure.

What Colorkrew can help You can do Colorkrew Security provides services that perform SOC operation from the above security design.

If you have any requests such as "I want to reduce the operational burden" or "I want to quickly detect cyber attacks", please feel free to contact us. Let's strengthen your company's security operations together.

Related Articles