Preface
Sasakawa Peace Foundation USA, through its US-Japan NEXT Alliance Initiative (NEXT), organized an “AI Assurance Study Trip” to Tokyo in July 2024, featuring 6 US experts in the field of Artificial Intelligence (AI), specifically AI Security and Safety. The purpose of this Study Trip was to foster networking, share information, and explore opportunities for bilateral technical research collaboration to help strengthen AI defenses, harmonize standards, and mitigate disinformation, as a supplement to multilateral efforts.
The Study Trip supports NEXT’s project called “Allied on AI Assurance: Technology to Enhance AI Security and Safety.” NEXT organized the trip in collaboration with Doug Rake of Racke Strategies & Technologies, as part of a “Japan-US Strategic Science, Technology & Innovation Initiative” (JUSSTII) activity, and with support from several Japanese partners.[1] We brought 6 senior level US AI security experts (from Department of Energy’s National Laboratories and the Department of Homeland Security) to Japan for 3 days of meetings and roundtable discussions with Japanese counterparts (government, academia, private sector), including a site visit to Japan’s AI Safety Institute. In addition, together with the University of Tokyo, Research Center for Advanced Science and Technology (RCAST)/Economic Security Research Program (ESRP) we co-hosted a public event attended by about 125 guests made up of students, researchers, private sector representatives and embassy officials from various countries.
The US delegation participants included:
For more information on the NEXT Alliance Initiative Japan Study Trip 2024, click here.
Table of Contents:
A phenomenon some call “adversarial AI” has emerged as an economic and national security concern not only in terms how it can threaten national cybersecurity efforts or AI training model integrity, but also its potential to spread disinformation and undermine democratic institutions. AI-enabled disinformation, be it through fake human accounts, automated botnets, or groups of coordinated malign actors, can exploit modern digital connectivity and flood it with discriminatory and inflammatory ideas designed to widen identity-based social gaps, erode trust in democratic governance, promote government and societal dysfunction, and even incite violence.
The US and Japan are wrestling with these challenges individually and collectively through multilateral forums such as the G7 and OECD, but bilateral networking on this topic can be an important supplement, especially when it comes to the technology behind the policy development. The US and UK signed a cooperation agreement among their AI Safety Institutes (AISI) for this purpose in April 2024. Japan launched its AISI in February 2024, and the US and Japan have begun consultations on possible cooperation and info sharing. US Secretary of Commerce Gina Raimondo in May announced the US AI Safety Institute Strategic Vision, which included an emphasis on cooperation with allies, and the US will host the first meeting of an international AISI network in November 2024. Bilateral collaboration in confronting AI-enabled disinformation and adversarial AI can be a force multiplier for investing in research to develop countermeasures and mitigation strategies, but a necessary first step is to enhance mutual understanding on the topic.
Each member of our US study trip delegation is involved in AI security research or policy making in some way, either conducting government-sponsored research, supporting government policy makers with technical expertise, or facilitating bilateral science and technology collaboration. The group’s itinerary in Japan involved a series of not-for-attribution meetings and dialogues with Japanese counterparts designed to exchange information about current work, share perspectives about challenging aspects of AI safety, and explore opportunities for bilateral collaboration. We are grateful to all the officials and experts who took the time to talk with us.
On Day One of the trip, the US delegation carried out a series of meetings with US Embassy staff, AI and economic security-related officials at Japan’s National Security Secretariat, and an extended roundtable discussion with experts in Japan’s Cabinet Office, Secretariat of Science, Technology and Innovation Policy. The meeting included officials from Japan’s Ministry of Education, Culture, Sports, Science and Technology (MEXT); Ministry of Economy, Trade & Industry (METI); Ministry of Internal Affairs and Communications (MIC); and the National center of Incident readiness and Strategy for Cybersecurity (NISC).
On Day Two, Sasakawa USA co-organized with PwC Japan a roundtable discussion involving university AI researchers and private sector representatives sharing their perspectives about AI Safety and Data Trust issues. The US delegation also made a site visit to Japan’s new AI Safety Institute and met with experts there.
On Day Three, Sasakawa USA co-organized with Japan’s National Institute of Information and Communications Technology (NICT) a roundtable discussion with national laboratory and university AI researchers sharing examples and outcomes from their AI safety and security research. They also discussed the challenge of translating lab research to real world implementation, as well as best practices in international collaboration. Afterwards, some members of the US delegation participated in the public event referenced in the Preface.
The following report combines insights and information gleaned from the study trip with subsequent archival research to sketch out the current landscape of AI Security/Safety policy making and research in the United States and Japan. It concludes with observations regarding opportunities and challenges for bilateral and “minilateral” collaboration on AI assurance.
AI-related terminology is an evolving set of labels and descriptions that is only just now becoming harmonized internationally and across different professional sectors. The US Commerce Department’s National Institute for Standards and Technology (NIST) in 2024 began collaborating with Japan’s new AI Safety Institute to create a “crosswalk” (i.e., a mapping of concepts and terms) of the NIST AI Risk Management Framework and Japan’s AI Guidelines for Business. Crosswalk 1 of this process focused on terminology and has been produced in both English and Japanese. The overall aim is to promote interoperability between US and Japanese governance frameworks.
Within the broad topic of AI governance lies a concept of Assurance, what the United Kingdom (UK) government describes in general terms as “the process of measuring, evaluating and communicating something about a system or process, documentation, a product or an organisation.” The US Department of Transportation describes AI assurance as “the techniques, activities, and processes used to evaluate and assure expected properties of AI components or AI-enabled systems” throughout their lifecycle. In its February 2024 report “Introduction to AI Assurance,” the UK’s Department of Science, Innovation and Technology describes it as the measurement, evaluation and communication of the “trustworthiness of AI systems” based on credible evidence. Trustworthy AI is an important issue not only for consumers and businesses engaged with AI, but also in terms of public safety and national security. This latter area (national security) is where our “Allied on AI Assurance” project is focused.
AI Safety and AI Security are directly connected to trustworthiness and the tools necessary to evaluate them. According to the US-Japan crosswalk, the two countries define AI safety and AI security slightly differently. For NIST, AI is “safe” if it does not “lead to a state in which human life, health, property, or the environment is endangered [under defined conditions].” In contrast, Japan adds a “human-centric” component including consideration for human life, body property and mind, and the environment, as well as human “safety” from disinformation.
AI Security is also linked to trustworthiness (according to both countries), as it describes AI systems “that can maintain confidentiality, integrity, and availability” through reasonable protection mechanisms that prevent unauthorized access and use. This includes protecting the development of large language models (LLMs) from data “poisoning” or tampering, designing AI systems based on early and thorough adversarial AI risk assessments, and providing sufficient cybersecurity for AI systems and services throughout their lifespan.
Interestingly, Japan’s AI Guidelines for Business add a note specifically mentioning that it is not possible to eliminate all vulnerabilities in AI systems and services, perhaps in part to reassure businesses that they won’t be subject to unreasonable liability claims if something goes wrong. At the same time, the guidelines push companies to keep up with the “current technological level.” This admission of vulnerability points to another aspect of AI Security, namely mitigation. If adversarial AI is at some point destined to spark a crisis, then nations will need tools available to help contain and reverse the damage.
There are several multilateral initiatives focused on enhancing AI safety and security. Notable among them is work carried out by the OECD through its Expert Group on AI Risk & Accountability and an Expert Group on AI Incidents, the latter of which created an automated monitor of AI incidents and hazards that now shows a moving average of AI incidents globally at around 700 every three months. For years leading up to spring 2023 the 3-month moving average never exceeded 40 incidents. This AI Incidents Monitor (AIM) is designed to help to show risk patterns and establish a collective understanding of AI hazards and their multifaceted nature, so that it can be a useful tool for trustworthy AI.
The G7 has been another important multilateral forum to enhance AI assurance, often working in coordination with the OECD. In July 2024, for example, the OECD announced a pilot program to test a reporting framework linked to the G7’s International Code of Conduct for Organizations Developing Advanced AI Systems. The program will gather information about how organizations developing advanced AI systems align with the Code of Conduct. In addition, the OECD and Global Partnership on AI (GPAI) formed an “integrated partnership” in July 2024 “bringing together all current OECD members and GPAI countries on equal footing, under the GPAI brand and on the basis of the OECD Recommendation on Artificial Intelligence.” The United Nations (UN) also contributes via its High-Level Advisory Body on AI, as do a series of global Safety Summits (involving over 25 nations) from 2023 and various networks of AI governance-focused non-governmental organizations (NGOs) and industry groups.
At the first AI Safety Summit held in the UK in 2023, the UK government (with support from 28 countries and the EU) commissioned a “state of the science report” on potential risks posed by advanced AI systems. It might be possible in the near future to create a broad multilateral process capable of producing regular science-based assessments of AI risks that can help nations respond appropriately and more collectively. Candidate models for such a process include the Intergovernmental Panel on Climate Change (IPCC) or the Intergovernmental Science-Policy Platform on Biodiversity and Ecosystem Services (IPBES). A September 2024 report by the UN Advisory Body on AI (entitled “Governing AI for Humanity”) also recommended an international scientific panel on AI, citing similar examples as relevant precedents.
In addition, during a meeting involving the US delegation and officials at Japan’s AI Safety Institute, a Japanese specialist highlighted the importance of “SC 42,” which is a short-hand way of referring to a special subcommittee that began meeting in 2018 to help the technical side of international standard setting organizations address challenges unique to AI. SC 42 supports Joint Technical Committee 1 (JTC 1) that was established by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) and has facilitated standardization globally for such technologies as smart (chip/credit) cards, biometric systems, bar codes, cloud computing services, and many others. Japan contributes to SC 42 work and then Japan AISI benefits from SC 42 output to inform domestic regulation development and the design of AI safety testbeds. Other AI-relevant standard setting organizations include the International Telecommunications Union (ITU) and the Institute of Electrical and Electronics Engineers (IEEE).
The future of AI assurance is multilateral, to be sure, and in fact during one of the US delegation’s meetings with US Embassy staff an official said that the Embassy “thinks about what we can do with Japan multilaterally about 90 percent of the time. 10 percent is bilateral.” Still, as with many other global challenges, there is a valuable role that bilateral and minilateral partnerships can play. One aspect of this role is to be a caucus within broader multilateral frameworks for pooling information and building consensus that go beyond one nation’s perspective (and set of interests) but are not as unwieldy as larger international groups. Another aspect is to combine strengths or compensate for weaknesses in terms of resources or expertise.
Members of our study trip delegation, for example, were asked in Japan by a student at the public event why the US would want to work with Japan on AI issues, when the US is such a global leader in the field. The US experts responded that Japan is still an engineering superpower in the world, and its AI skills in robotics and industrial systems in particular are world class, together with possessing a highly disciplined and rigorous academic research community for AI science and engineering. Japan is also a leader in information authentication technologies (e.g., so-called Originator Profile) that can help combat online disinformation. There are a variety of areas where US and Japanese firms and researchers can combine their strengths or complement each other to improve the speed and quality of their work as they contribute to multilateral initiatives or allied interests.
Related to this, the US and Japanese governments are investing significant sums of money in research and the development of tools to help them improve AI assurance for the sake of safe and secure AI systems. Their private sectors are investing even more, each in their own ways, and are valuable partners in this process. The US and Japanese governments are consistently numbers 1 and 3 in the world respectively in terms of the amount spent on science and engineering research and development. Japan has also been either the largest or second-largest foreign source of R&D investment in the United States since 2010.
Sharing information and ideas to create more synergy and mutual benefit from these investments is a useful bilateral activity in support of the wider common good. In these ways, being “allied on AI assurance” can be a valuable supplement to, though not a replacement for, various multilateral initiatives. One US delegation member said during the trip that “we are in a place today with AI security where we were twenty years ago with cybersecurity, and it is critical to have international partnerships in place not just for joint research and programs, but to build the information sharing infrastructure on threats and vulnerabilities that we’ll need in the future as this field evolves.” Moreover, another US member called for a greater sense of urgency in this regard, because “I have never seen in my 38-year career a faster adoption of technology while it is changing at the same time, and at the same time creating a $2 trillion economy that the world’s largest companies are chasing.”
Prompted in part by growing public access to AI tools such as ChatGPT and building off the US government’s development of a Blueprint for an AI Bill of Rights in late 2022, the Biden administration in 2023 launched a series of department and interagency task forces and working groups related to AI assurance including some at the Departments of Defense, Energy, Transportation, Commerce, Homeland Security, and others. These efforts all contributed to the Biden administration’s first comprehensive policy statement and government action plan for AI safety in October 2023. This “Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence” outlined new standards for AI safety and security, initiated a variety of measures to enhance users’ privacy, and instructed multiple departments and agencies to develop more detailed guidelines for ethical AI use, consumer protections, and government use of AI. The US AI Safety Institute, located within NIST at the Department of Commerce, was established following the October 2023 Executive Order.
Some of the US study trip delegation members described the content and process for implementation of the Executive Order for their Japanese counterparts during the roundtables, noting that it is giving the US government some opportunities to improve upon past data strategies. One member described the Order as “extremely comprehensive” though “perhaps overly comprehensive, if that’s possible” given its breadth and ambition in prescribing “over 100 different actions across the whole of US government.”
The Order contained eight major components, the largest of which was standards for AI safety and security. Here the focus was on “standing up and developing the implementation of repeatable mechanisms and repeatable processes to understand the risks related to AI,” especially regarding bio security, cybersecurity, national security, and critical infrastructure. Privacy issues also featured prominently, in particular evaluating and articulating data privacy risks when collecting data or using human data is involved. The Order also addressed protections for consumers, minorities (e.g., limiting the biases of AI models), workers, and others, while still trying to promote AI innovation and international engagement. The White House released a 180-day progress update for the required actions in April 2024.
Organizationally, the Executive Order sought to build upon the interagency coordination fostered by its development and established an interagency Chief AI Officer Council to guide the government’s own use of AI going forward. It also created an AI Safety and Security Board of high-profile outside experts that meets quarterly to advise the Secretary of Homeland Security and private sector stakeholders on related policy issues. The Department of Homeland Security has been working to evaluate the specific potential for AI risks in the chemical and biological space, while the Department of Energy has been focused on radiological and nuclear areas.
Figure 3.1: US Government’s AI Policy and Research Structure (simplified)

The task of defining the standards by which private sector “frontier” models could be judged “high risk” was given to NIST at the Department of Commerce, which also launched the new AI Safety Institute. This institute then worked with over 280 private AI stakeholders (e.g., companies and non-governmental organizations and associations) to create a US AI Safety Institute Consortium (AISIC) that will help the Institute “develop science-based and empirically backed guidelines and standards for AI measurement and policy.”
The stakes are high and the issues complex regarding so-called high-risk models. For those that meet the standard, the US government would insist on an ability to review the models for compliance with their standards, “pulling back the curtain” on model development, according to one US delegation member. Yet, how US officials would carry out such reviews needs to be determined, and what power they would have to compel potentially costly changes is also unclear.
While the US government and US Congress are being very deliberate in working out these details, the State of California tried moving forward with its own legislation that would require companies training large and expensive AI models (e.g., with development costs exceeding $100 million) to test for catastrophic risks, to incorporate a “kill switch” to disable the technology, if necessary, and would introduce potential legal liabilities if their tools are used for harmful purposes. The controversial bill split the AI community between avid supporters and fierce critics, and Governor Gavin Newsome eventually vetoed the bill in September 2024 while signing several smaller AI-related bills. At the federal level, a non-profit organization following the AI governance issue is tracking twenty different bills related to AI assurance introduced in the 118th Congress, but there appears little consensus on the next specific steps. Simply put, the legal environment surrounding AI assurance is in flux.
The US government has also organized interagency workshops involving outside AI assurance researchers including officials and experts from other countries such as the United Kingdom and Japan to examine risks and mitigation strategies for adversarial AI threats. They worked to define adversarial AI and counter AI, catalog various types of risks and attacks, and consider how different technologies, functions, and government missions could be affected.[2] The report concludes with a compiled list of mitigation strategies discussed regarding data preparation, model training and testing, model deployment and maintenance, and human systems interaction.
Another US delegation member provided a briefing to a bilateral roundtable of experts exploring data trust issues. Focusing heavily (but not exclusively) on data inputs for AI systems, the expert noted that there are both promotion and protection aspects to the Executive Order, in that it calls for “the development of standards and tools to help ensure that AI systems are safe, secure and trustworthy,” while also directing actions to counter an adversary’s use of AI against the United States. For both of these, he said, “it all starts with data,” and he highlighted several AI risks that are specifically linked to data trust. These include poisoning at training time, data at inference time, data security, and data calibration and provenance. With so much open-source data currently being scraped by companies for use in model training, it is extremely difficult for firms to verify what is going into their systems, how to trace it, and how to reproduce it.
The US expert argued that we need to view data as a strategic asset and a critical input for science and security, requiring “focused and dedicated effort to ensure successful execution of research and mission” (i.e., dedicated data engineers separate from the model builders themselves). This extends to lab research focused specifically on the data itself and various automated tools to enhance data accuracy, trust, and verification. This is an often-overlooked area for collaborative research between allied nations’ labs. In addition, because every organization, data, and task are different, there will not be one solution that meets all of the needs, but trust can be enhanced if the principles of underlying data governance are sound, and this is an area where harmonization across countries is not only helpful, but also necessary to some degree.
The expert explained that good data governance helps an organization understand what data it has, where it is stored, how to use it, and who can access it. It does this by outlining the policies and procedures for creating, storing, accessing, maintaining, and disposing of data. With clear and consistent procedures in place for data availability, quality, integrity, usability, and security, many potential problems can be avoided in the first place, and if a mistake or danger arises, the resolution of that problem becomes notably faster and easier. He made the case, in conclusion, that any future research collaboration between US and Japanese labs or institutes could be facilitated and strengthened greatly by building a solid bilateral (and ideally, multilateral) foundation of data governance. Moreover, even though the high-level concept of how best to approach data governance is relatively well established and understood, how that approach is executed changes frequently based on the organization, the task, and the tools that are utilizing, protecting, and often generating data.
A Japanese researcher agreed with this conclusion but added that one productive approach to help harmonize data governance could be to build data sharing infrastructure that different firms and organizations could utilize to enhance trust, rather than rely just on policies and procedures. He noted that Europe is currently developing some data sharing platforms, but he was not aware of how the US was approaching this activity. The US expert explained that within the US national lab community there exist some data-sharing platforms throughout the country, but it has been much harder to build these with entities outside this relatively closed system. Experts from both countries at the roundtable then considered possible ways to stimulate a public-private consortia that could help bridge some of these gaps (described in Section 5 of this paper).
During the course of the study trip, researchers from both countries shared insights about their current research related to AI assurance. On the US side, one researcher described her lab’s work trying to better understand how different types of AI operate in environments slightly different than those within which they were trained, applying AI in different domains and US government missions to assess real world behavior. This also gives the researchers opportunities to test different techniques for adjusting or calibrating the AI system to make it more effective and reliable for the end user. Their work cuts across various disciplines and stages of the AI life cycle, helping to draw more direct lines from design, development, testing and evaluation, and end use.
Another US researcher described his center’s work helping the US government evaluate different computer and cyber defense solutions incorporating AI that it is considering purchasing. In the process of testing their effectiveness under normal conditions, the researchers also introduced adversarial conditions and demonstrated a 68 percent success rate of penetrating state of the art AI-enabled cyber defense systems with various types of malware. The team expanded its work and began observing similar vulnerabilities in systems for identity science, biometrics, image processing, and other use cases. Their work extends beyond protecting points of entry for these systems to include potential misuse of AI tools for creating deepfakes and other types of disinformation. Their mission is not only to identify these problems, but also to help find answers that can strengthen national security.
Japan is investing heavily in AI-related technologies, driven by a combination of factors. Part of the motivation is simply a desire to not miss out on the commercial opportunities, as large US, European, and Chinese firms keep growing and spending. The market is expanding rapidly in Japan, and in 2024 several major US tech companies have announced multi-billion dollar investments in Japan (e.g., AWS at $15 billion, Microsoft at nearly $3 billion, Google Cloud at $1 billion, Oracle at $8 billion, along with smaller investments by Open AI, NVDIA, and others). The Japanese government also sees AI as an important strategic technology and would love to have a national champion (or champions) to support its national and economic security missions, rather than rely on large US firms. Japan’s NTT Corporation launched a new company in 2024 (NTT AI-CIX) to help companies incorporate AI systems across different industries to support their digital transformation. Other large players in AI include Toyota Research Institute, Fujitsu Laboratories, Softbank Robotics, Sony, NEC and Hitachi, as well as smaller start-ups such as Sakana AI, which received a significant investment from NVDIA in late 2024.
Another factor is Japan’s shrinking population, a phenomenon of the past fifteen years but accelerating to a rate of 800,000 more deaths than births in 2023. Many in Japan see AI as the only way to help sustain the economy and provide essential services in the future. US delegation members noted this contrast to the AI debate in the United States, where many policy makers worry that AI will take away too many jobs and create unemployment. In Japan, AI could provide a healthy fix to the labor market.
The challenge of AI assurance and AI safety is also on the Japanese government’s collective mind. Long thought relatively insulated from traditional disinformation campaigns due to Japan’s unique language and culture that made deceit difficult, AI is changing the game and was particularly evident in the wake of Japan’s decision in 2023 to release treated water around the Fukushima nuclear power plant into the ocean. China, in particular, has been cited as the source for a large-scale disinformation campaign that year that Japan struggled to counter. Japan’s Foreign Ministry issued press releases to counter fake news stories, but like many other governments, officials in Tokyo lack the necessary tools or infrastructure to respond quickly and systematically to AI-generated disinformation.
One countermeasure has been to invest in technology that can easily identify the disseminators of information on the internet, or so-called Originator Profile technology. Despite this seemingly adversarial experience in 2023, however, our study trip observed that officials in Japan have been less quick to adopt the term “adversarial AI” compared to their US counterparts, perhaps due to the term’s assumption of confrontation. Much work remains to better harmonize terminology and build a shared understanding within the alliance of various AI assurance concepts.
As in many other countries, Japan’s government is trying to find the right balance between promoting innovation and establishing appropriate guardrails for AI development. Its efforts began in earnest in 2016 when Japan hosted the G7 ministerial and leaders’ meetings with AI squarely on the agenda. That same year Japan’s prime minister launched an expert AI Technology Strategy Council to advise his office, although the focus at the time was mostly on the innovation-side of the equation and some ethical considerations, rather than firm guardrails.
That year coincided with Japan’s release of its 5th Science and Technology Basic Plan touting the advent of “Society 5.0,” described as “a highly integrated system of cyberspace and physical space.” AI was thought to be a foundational technology for Society 5.0, initially envisioned as “a human-centered society in which economic development and the resolution of social issues are compatible with each other” through this cyber and physical integration. However, as the potential risks of AI became more widely understood, Japan’s next 5-year Science and Technology Basic Plan in 2021 described Society 5.0 less idealistically as “a society that is sustainable and resilient against threats and unpredictable and uncertain situations, that ensures the safety and security of the people, and that [allows] individuals to realize diverse well-being.” AI assurance had become a higher priority, and similar to the US government, 2023 was a pivotal year.
Japan re-launched its AI Strategy Council in May 2023, and by August of the following year the Council had already met eleven times. 2023 also saw Japan host the G7 again and the establishment of the “Hiroshima AI Process,” which led to G7 agreement on a “Comprehensive Policy Framework for AI” by December. The Framework consists of multiple elements including (1) the OECD’s Report towards a G7 Common Understanding on Generative AI, (2) International Guiding Principles, (3) International Code of Conduct, and (4) project-based cooperation on AI. The stated purpose of the Framework is “to promote safe, secure, and trustworthy AI worldwide.” Japan’s METI and MIC also released the first draft of their “AI Guidelines for Business” that December so that companies and other stakeholders could provide comment. The final version (1.0) was published in April 2024.
Japan is creating a whole-of-government approach to AI policy making and resource allocation, seeking to play a major role in international rule making and facilitate prompt, flexible responses to potential AI risks and opportunities involving diverse stakeholders. While the eight-person AI Strategy Council sits conceptually at the top of this process, the primary “control tower” is a group within the Cabinet Office’s Council for Science, Technology and Innovation (CSTI), drawn from different ministries and led by a Director General assigned to be the overall AI coordinator (see the simplified org chart below).
Figure 4.1: Japanese Government’s AI Policy and Research Structure (simplified)

*Other ministries take part in the “AI Strategic Team” in an ad-hoc manner
In this way, the different competent ministries (and associated research labs and funding agencies) continue leading AI strategy development and implementation within their areas of expertise and jurisdiction, but they do so under a coherent national strategic framework. They also benefit from information sharing and create synergies and efficiencies as AI policies are continuously evaluated and updated. According to a hand-out provided by the Cabinet Office, for example, while the fiscal year 2024 AI-related budget was just about $800 million, a supplemental budget that year was roughly $2.1 billion, with about three-quarters of it going to strengthening AI development capabilities by securing computational resources, expanding data centers, and supporting research and development. A smaller amount of funds was allocated to the promotion of AI use and a little bit (~$7 million) for responding to risk.
Japan’s AI Safety Institute is funded through METI and operates within METI’s Information-technology Promotion Agency (IPA), although it cooperates with all of Japan’s AI-related ministries and national laboratories. At the time of our study trip to Tokyo, Japan AISI was comprised of about 25 technical staff, half of whom work there full-time and include specialists seconded from the private sector. Japan AISI describes its role not as an R&D organization but as a “hub for AI Safety in Japan,” promoting information sharing and collaboration among relevant companies and organizations, supporting the government by conducting surveys examining evaluation methods, and creating standards. It is also a conduit for international collaboration (including overseeing the translation into Japanese of certain foreign risk frameworks and guidelines), and its overall mission is to “create an environment where anyone can safely implement and develop AI.” Subsequent discussion in the study trip meeting with Japan AISI revealed a possible opportunity for US-Japan collaboration in the testbed development area (described in Section 5 of this paper).
Japan AISI also coordinates closely with Japanese companies, but one Japan AISI representative noted that a near-term priority is the development of an AI industry consortia in Japan with whom Japan AISI could collaborate more closely. The process has been slowed by cumbersome procedures designed to ensure inclusiveness, fairness, and transparency when these public-private bodies are assembled, he said. This process also includes the involvement of relevant Japanese research laboratories such as RIKEN, AIST and NICT.
In addition, NICT has collaborated with the Global Partnership on AI to establish in July 2024 a GPAI Tokyo Expert Support Center (ESC) within NICT to provide operational and administrative support for studies and projects conducted by GPAI experts. This move coincided with GPAI and the OECD’s step to form an integrated partnership on AI governance, so there is some consolidation of effort taking place in this area, and Japan is investing to stay closely engaged. Specifically, a “core mission” of the Tokyo ESC is to support GPAI’s Generative AI Workforce (SAFE) project, what GPAI considers its first “transversal” Working Group project.
The SAFE project plans to network with various GPAI working groups to: 1) map the initiatives and private companies developing technology solutions on service-led generative AI solutions (such as AI audit and anti-disinformation technology); 2) assess the effectiveness and feasibility of these initiatives and liaise with them; and 3) disseminate these proposed solutions to GPAI member countries and beyond. According to materials prepared by Tokyo ESC and GPAI, the SAFE project will proceed on three tracks, namely technical safety of LLMs (i.e., establishing an industry certification), data governance on LLMs (i.e., update of the taxonomy), and identifying both exogenous and endogenous factors regarding the safety of artificial general intelligence. NICT is also planning to host a Tokyo Innovation Workshop around the late spring or summer of 2025.
NICT also has its own AI assurance research agenda underway, focusing on three areas in particular: 1) optimizing AI through secure data linkages; 2) “cheapfake” detection; and 3) AI-generated content detection. The first area recognizes that most data sets are not aggregated, and various techniques (e.g., encryption and anonymization) are needed to help integrate diverse datasets without compromising privacy. Federated learning can also be used to train models across decentralized data sources. NICT is also leveraging deep learning techniques for improved detection accuracy for cheapfakes (i.e., made with easily accessible non-AI based editing tools), as well as AI-generated media or “deepfakes.”
As for other research laboratories in Japan, RIKEN highlighted to the US delegation one of its projects on the potential benefits and risks of personal AI systems, which could become a primary means of citizens’ interface with government, health, and commercial services in the future. Designed and regulated effectively, personal AI can help block online manipulation and aggregate personal data with each user, decentralizing data management and limiting the scope of so-called surveillance capitalism and the “attention economy.” Still, because personal AI users themselves will find it difficult to evaluate the accuracy or objectivity of these systems, understanding the design and regulating personal AI carefully will be important for AI assurance, if these systems do indeed become a primary filter for each individual’s social and commercial interaction.
For its part, AIST has for several years been supporting AI bridging cloud infrastructure so that a wider range of firms have access to top-quality deep learning speeds. It has also created a machine learning quality management testbed and conducts research by simulating different types of data poisoning and inversion attacks. To help bridge the gap between lab research and commercial applications, AIST created a company called AIST Solutions in 2023. The firm can provide advice and expertise on intellectual property licensing, product testing, marketing strategies, and other services so that laboratory breakthroughs can translate more readily into commercial success.
Echoing the call mentioned earlier for a greater sense of urgency for AI assurance, a US researcher said that “governments are trying to catch up and companies are racing to outcompete each other, and what I feel is being left in the middle are practical measures to ensure that the technology being deployed is safe, reliable, and secure.” He added that “we know that these models can be fooled, that we have not solved cybersecurity vulnerabilities, and yet we are rapidly embedding it in commercial and financial applications.”
Thus, the AI research community between the US and Japan (and with other nations) needs to help educate policy makers and the public about the technology and associated risks, and collectively we should invest more time and money in public-supported research settings to advance our ability to manage AI assurance challenges.
Evaluation frameworks and tools
One bilateral discussion during the study trip concerned the challenge of conducting accurate risk assessment and evaluating the safety of frontier LLMs, when so many details about the models are not reviewable. One US expert suggested that it might not be possible to carry out a productive risk assessment of such “black boxes” now, and yet many of these models are being deployed before governments have a chance to fully understand them. He suggested that a different risk framework might be needed, in such cases. A Japanese researcher responded, “Scientifically, I totally agree with you, but as a staff member of Japan AISI, I cannot agree with you.” He continued, “We have to make some standard and share with society, so that key safety criteria are understood better, along with best practices. It might not be ‘assurance,’ but it can help reduce risk.” Frequent bilateral engagements and collaboration in such areas can create an iterative process that helps researchers in multiple countries improve and harmonize their risk assessment and management practices, working our way to greater AI assurance.
A US researcher agreed that action is needed now to help reduce risk. He emphasized the quick adoption of practical testing frameworks for the behavior of AI systems (i.e., is it effective or not), rather than focusing on the management of data inputs. He argued that frontier models are already based on the bulk of human knowledge in multiple languages and will eventually move into a form of AI reasoning. In this case, governments will lose control over the data space for AI models and will be better served by evaluating (and regulating) outcomes.
Related to this, in their discussion with Japan AISI some US researchers suggested considering coordinated or cooperative test bed development. Making test bed tools available to AI model researchers and developers and then learning (and sharing results) from their operation can be a valuable contribution to strengthening AI assurance. The test beds themselves are likely to be created by national labs and associated funding agencies, but the AI safety institutes can provide a ready network to facilitate information sharing and complementary research design. In July 2024, for example, the US National Science Foundation (NSF) announced an initiative to invest in AI-ready test beds to allow researchers to study new AI methods and systems in secure, real-world settings.
The US Department of Energy (DOE) already has dedicated AI test beds at seven national laboratories. According to DOE, these are “computing systems of various sizes, specifically designed for research and to support rigorous, transparent, and replicable testing of hardware and software capabilities.” As Japan AISI looks to orchestrate AI test bed development in Japan, their configuration could potentially take into account existing gaps in the US or Europe and then fill those gaps with agreements on mutual sharing of important results. To be effective, this would likely require some harmonization of evaluation standards so that the results in one country’s test beds are readily understood and accepted in other countries.
Related to this, one American researcher was particularly impressed with AIST’s approach utilizing a quality management testbed and vowed to follow-up after the trip to explore collaboration opportunities. He emphasized the pressing need to develop and disseminate coherent quality standards for AI systems as soon as possible, and this will require more active international coordination of efforts to understand how the systems can fail and how to assess their vulnerabilities. In this case, the development of quality standards goes hand-in-hand with quality measurements, and this can only be accomplished through rigorous testing at scale coordinated among multiple research institutes and informed by real case studies.
The case studies are necessary to help bridge the gap between what one researcher called the “science bubble” where research takes place and policy makers making difficult decisions. The example this researcher gave referred to his time on the US government’s interagency task force for the COVID pandemic, when policy makers leveraged the science community and computing power of DOE national laboratories to better understand how the virus was likely to spread. But policy makers were not asking technical questions about transmission rates in a particular area and instead wanted clear guidance for such questions as, “should we close schools in Houston?” It will likely be similar when it comes to settling AI governance and AI assurance issues, requiring close links between experts in science and policy so that science can more effectively support decision making.
A Japanese researcher agreed the importance of creating and adjusting objective indicators to measure the complex relationship between research and development conditions and usage conditions. To achieve this, it is necessary to draw on a broad and complex range of specialized knowledge (and stakeholders) that goes beyond the boundaries of the liberal arts and sciences, supported by consistent collaboration. A key challenge highlighted by another researcher at a Japanese lab, however, is the broad scope of AI businesses, with their large-scale AI models based on vast datasets, and the continuous development, operation, and evolution of AI systems. This will require new paradigms of sustainable and accelerated multi-sector partnership between academia, government, and industry to work on these complex, real-world problems.
In addition, if one side of the AI assurance “coin” is defensive and protective, there is a flip side related to creation and development that also deserves attention. The US, Japan, and other countries are investing heavily to foster the growth of national AI innovation ecosystems by providing computing and data resources, workforce training subsidies, test beds, and other assistance. AIST described its AI Bridging Cloud Infrastructure initiative, and a US researcher described a similar undertaking (still in the early stages) whereby the NSF and several DOE labs are collaborating to provide computing and data resources to smaller public and private AI entities. Of course, a national AI innovation ecosystem will always prioritize its own nation, but private sector participants inevitably have some international dimension, and there might be times when we would want to link them to some degree to leverage an allied innovation ecosystem.
Data governance and data infrastructure
As noted earlier in this report, US and Japanese experts at one of our roundtables considered possible ways to enhance AI assurance by stimulating public-private consortia to help bridge data governance gaps existing between countries and between different industry sectors. Generally speaking, participants noted that the medical research industry is probably the farthest along in terms of either harmonizing data management rules or recognizing acceptable “equivalent” levels of control internationally, as they work to abide by different national rules. They are supported by multiple international consortia to help navigate these challenges in areas of privacy and protection. The finance industry is also advanced in these areas, particularly for “traceability,” which is important in AI fields (perhaps via hardware stamps, data stamps, blockchain, or other means). So-called reproducibility is also important, said one researcher, especially if models being developed utilize dynamic data sets, or if they need to accommodate changing rules (e.g., for an autonomous driving system to adapt to new traffic laws).
A Japanese participant wondered if there are conflicting philosophies among countries regarding how much to push for multilateral data sharing infrastructure. He said that in Europe and to some extent in Japan this is being viewed as a cooperative venture among governments and private firms (for a federated data governance model and infrastructure), but his impression is that the US and UK tend to see this in more of a competitive light, or at least that there is less of a role for government to be the catalyst.
This participant went on to highlight that we have the Internet itself as a message-passing layer or networked social infrastructure for governance and interoperability. He wondered if it would be possible to build something similar for a data layer. A US researcher liked the idea but thought that its design should probably avoid the need to transfer large data sets en masse and instead allow for querying to access slices of relevant data. In that case, a well-crafted data interface is necessary so that it is sufficiently robust and efficient, but not in a way that would allow access to misconfigure the data (i.e., the digital equivalent of putting a library book back in the wrong place).
Issues of usage control, authentication, and accountability for how data is accessed and used would also have to be considered carefully. A Japanese participant suggested usage control specifically as a potential candidate for technical collaboration, because virtually all systems would benefit from an ability to “read” and understand operating parameters from text, rather than having to govern the operations by human code writing. In theory, this would allow the AI system to comprehend legal and operating restrictions and perform accordingly, allowing for relatively simple updates. Helping to make this feasible in the future could enhance AI assurance for all.
A US researcher asked Japanese counterparts about their work on how to handle the scalability of federated data sets (data, dissemination and access), since automated efforts to collect data for future use could become unmanageable over time. It is possible that the data ends up in some lower dimensional space as vectors that users access instead of the raw data, so he wondered if Japan was conducting research on vector storage in place of data storage.
The Japan side explained that in the federated data system it is developing, the approach is to have various entities being responsible for their own layer of data, for which the government facilitates a “gateway system” or federated mechanism to allow for broader access. Much of their research, therefore, is focused on designing an efficient gateway and providing for adequate trust certification. A Japanese researcher described the federated system as having three main layers including a functional layer (specific to each type of data such as for agriculture, factory data, traffic data, etc., which is looked after by local government or industry organizations), a national government ministerial layer, and a domain agnostic layer. The governance rules for these different layers (and even within layers) can be different, creating added complexity.
In addition, he noted that the contribution from private data sources has been relatively slow due to limited understanding of how the governance and protections will work, so reassuring these users/contributors is a priority for government. A Japanese participant added that he prefers the term “data-driven intelligence” over “artificial intelligence,” underscoring data as the crucial foundation.
Separately, a different Japanese researcher expressed the view that Japan’s comprehensive personal data protection law has proved to be overly restrictive and is disadvantaging Japanese AI developers. Interestingly, it seems that this issue is of sufficient concern in Japan that the Personal Information Protection Committee of Japan is considering amendments to the law that could relax the rules and allow organizations to use personal data for the purpose of educating generative AI without obtaining consent from the data subjects.
Meanwhile, the lack of a comprehensive personal data protection law (at the federal level) in the United States could complicate attempts to build a broad-based data sharing infrastructure. At the data level itself, there is some work currently being done at the OECD in this area under initiatives related to the concept of Data Free Flow with Trust, which Japan initially introduced in 2019. Alliance communication and coordination on this front is also important.
Best practices for international collaboration
The researchers in our study trip roundtables, and the institutions that they represent, are no strangers to international collaboration. NICT, for example, listed 36 different global partners (in Europe, Asia, North American, etc.) just for its Cybersecurity Research Institute. Most of that collaboration falls into one of four general categories: 1) joint data collection and analysis; 2) researcher exchanges; 3) annual workshops and co-organized events; and 4) joint paper writing. Other examples of US-Japan cooperation include the sharing of national capital-intensive equipment (e.g., lasers or telescopes), joint funding of research by NSF and the Japan Science and Technology Agency, and cooperatively built infrastructure for joint scientific research (e.g., in space). The United States and Japan have been collaborating in various science and technology fields since the early 1960s involving hundreds, if not thousands, of partnerships, and the government-to-government mechanisms for supporting these initiatives are starting to grow.
Still, although the basic challenges and opportunities related to international collaboration are well understood, technical collaboration related to AI assurance is in its early stages, and even if larger parent organizations in both countries are familiar with each other, the researchers and their labs that focus on AI issues might not be aware of those connections and best practices. Participants from both nations with significant experience in collaborative international science projects offered their insights to the group.
Best practices for international science collaboration are often common sense, but it is worth identifying them and factoring them into the planning and execution of joint projects. A US participant highlighted first the fact that successful collaboration takes time to invest in bilateral relationships, build trust, develop effective communication, and fully understand each other’s strengths and limitations. In a US-Japan cross-cultural and bilingual setting, communication is particularly challenging but necessary to reap the anticipated benefits of collaboration. Moreover, to avoid wasted time and resources, developing a clear understanding of what specifically is mutually beneficial about certain bilateral collaboration is critical for success. A Japanese researcher added that overcoming distance was often the primary challenge to building and sustaining effective collaboration, due in part to the difficulties it creates for communication. In this case, well-targeted researcher exchanges can help.
There are a variety of options for bilateral collaboration. One approach is to divide up a research task into two separate activities that play to each other’s strengths, and then combine the result from these different capabilities. Another option could be having one partner “red team” the results of the other partner, as is conducting similar research and then comparing the outcomes. However it is handled, an additional expected benefit from such efforts should be an improved ability to advise policy makers in both countries to make difficult alliance decisions that need scientific input. This was the case, for example, during the COVID pandemic or when assessing potential health risks and evacuation zones during the Fukushima nuclear power plant disaster in 2011 in Japan and bilateral activities were carried out for disaster relief and nuclear risk management.
At the workshops, participants identified a variety of research areas that could be good candidates for bilateral collaboration including deepfake detection technologies, originator profile technology, cybersecurity protection and malware detection technologies (understanding co-generation principles), federated cloud technologies (and the balance between cloud computing and edge computing), and the area of human-digital twins, which could corelate with some of Japan’s work on personal AI technologies.
Overall, participants advised a “defense in depth” approach for AI assurance, recognizing that a gap or problem could arise at some level within the system, but with sufficient depth it could be stopped at the next level or a level beyond that. One researcher likened this to Swiss cheese that might have holes at any given location but not all the way through. Still, a solid foundational layer for the technology (and its underpinning data and performance standards) is vital as AI scales out more broadly into a wider range of uses. Building consensus internationally around this foundational layer (and how to communicate when problems arise) struck some participants as an important area of collaboration. Part of this could include coordinating on data governance frameworks for AI. Mitigation techniques, promoting AI literacy, and workforce development were not discussed in detail during the trip, but they could be other good areas for bilateral collaboration.
In addition to bilateral collaboration at the individual or institutional level, a pair of government-convened committees is an important overseer of US-Japan science and technology cooperation, and they have already placed AI high on the list of policy and research priorities. The Joint High-Level Committee (JHLC) and the Joint Working-Level Committee (JWLC) on Science and Technology Cooperation were formed under the 1988 US-Japan Agreement on Cooperation in Research and Development in Science and Technology. The JHLC (and the JWLC that supports it) have a complicated history and a complex governing structure, which have contributed to its lack of ability in the past to be a strategic control tower for allied science investments, but that could be changing. Also, even if the JHLC has a limited ability to organize and manage bilateral science and technology cooperation, it does influence priorities and provides a bird’s-eye view of all allied activity from which all stakeholders can benefit.
On the US side, the JHLC is chaired by the OSTP Director but includes active participation from a variety of interested offices and departments including the National Institute of Standards and Technology (NIST), the National Oceanic and Atmospheric Administration (NOAA), the National Science Foundation (NSF), the Department of Energy (DOE), and the Department of State. The Japan side is co-chaired by the Minister of State for Science and Technology Policy, Intellectual Property Strategy, Space Policy and Economic Security, and the Minister of Education, Culture, Sports, Science and Technology (MEXT). Other participating Japanese institutions include the Cabinet Office (CSTI), Ministry of Internal Affairs and Communications (MIC), Ministry of Foreign Affairs (MOFA), and Ministry of Economy, Trade and Industry (METI). The two committees usually meet annually or slightly less often, but they are slowly becoming a more valuable means for inter-agency coordination of bilateral science and technology initiatives.
The world is in uncharted territory, as it simultaneously deploys and tries to manage some of the most complex and potentially consequential technology ever developed. It is not possible to fully understand where AI technology is headed and what its implications will be. Addressing these challenges at a global scale within a highly compressed timeframe requires the attention and efforts of all nations. As one study trip researcher described it, “although we often pursue a goal of ‘explainable AI,’ we might not achieve it. We do not have an explainable mind, and yet we have fields of psychology, psychiatry, and the like,” so there is a lot of work to be done to make sure AI will behave the way it should.
As noted early on in this report, bilateral engagement on such underlying issues can be a valuable supplement to multilateral efforts, especially when bilateral interactions are so much easier and faster to arrange compared to large multilateral forums. This study trip and report represents just an early stage of developing a practical US-Japan agenda for enhancing AI assurance, and this will be followed up with additional dialogues and analysis in the future via this initiative.
————————————————————————————————————————-
NB: Please note that this report is not a consensus document and is solely the author’s own interpretation of the insights generated by the dialogues and meetings (and via subsequent research) regarding AI assurance and the US-Japan alliance. Quotes are used to illustrate points on a not-for-attribution basis, as per agreement with all the dialogue participants. The author is solely responsible for the content of this report. Questions or comments regarding this summary can be directed to Jim Schoff at jschoff@spfusa.org
About the Author
Jim Schoff became senior director of the “US-Japan NEXT Alliance Initiative” at Sasakawa Peace Foundation USA in 2021, following nine years as senior fellow and director of the Japan Program at the Carnegie Endowment for International Peace. His research and writings focus on the nexus of traditional and economic security, as technological and geopolitical change challenge the US-Japan alliance. Prior to Carnegie, Schoff served as senior adviser for East Asia policy at the US Office of the Secretary of Defense, contributing to strategic planning and policy development for relations with Japan and the Republic of Korea. He also worked in Japan as Business Manager for a large construction and project management firm, Schal Bovis, and he was the Director of Asia-Pacific Studies at the Institute for Foreign Policy Analysis for seven years. Overall, Schoff’s career spans more than thirty-five years working in the fields of business, education, government, and the non-profit sector, all related to Japan, East Asia, and the US-Japan alliance. Some of his publications include: “Modernizing US-Japan Command & Control Relationships for New Challenges” (Sasakawa Peace Foundation USA, May 2023), “China and the New Role for Economic Security in the US-Japan Alliance” (Sasakawa Peace Foundation, April 2022), “US-Japan Technology Policy Coordination: Balancing Technonationalism with a Globalized World” (Carnegie, 2020), and Uncommon Alliance for the Common Good: The United States and Japan after the Cold War (Carnegie, 2017).
The US-Japan NEXT Alliance Initiative is a forum for bilateral dialogue, networking, and the development of joint recommendations involving a wide range of policy and technical specialists (in and out of government) to stimulate new alliance connections across foreign, security, and technology policy areas. Established by Sasakawa Peace Foundation USA with support from the Nippon Foundation, the goal is to help improve the alliance and how it serves shared interests, preparing it for emerging challenges within an increasingly complex and dynamic geostrategic environment. Launched in 2021, the Initiative includes two overlapping lines of effort: 1) Foreign & Security Policy, and 2) Technology & Innovation Connections. The Initiative is led by Sr. Director Jim Schoff.
[1] JUSSTII is an intermittent series of Track 1.5 bilateral dialogues with a mission of promoting collaborative research in cutting edge science and technology areas that are of mutual strategic importance to the US and Japan.
[2] In its report “Risks and Mitigation Strategies for Adversaria Artificial Intelligence Threats: A DHS S&T Study,” published in June 2023, the first workshop defined adversarial AI as AI-based attacks on either an AI-based system or a non AI-based system, while counter AI referred to either kind of attack on an AI-based system (only). See page 6 at https://www.dhs.gov/sites/default/files/2023-12/23_1222_st_risks_mitigation_strategies.pdf
2026 Sasakawa USA | Privacy Policy | Sitemap
Custom WordPress Design, Development & Digital Marketing by time4design