Skip to main content
v2026.11,858 entries · CC-BY 4.0

G7 Hiroshima AI Process: the Code of Conduct and the HAIP Reporting Framework

The G7 Hiroshima AI Process produced two things that get confused: a voluntary International Code of Conduct with eleven actions, issued by G7 Leaders on 30 October 2023, and the OECD-hosted HAIP Reporting Framework, a seven-section questionnaire organisations file in public. Version 2.0 launched 28 May 2026 with role-based routing and closed questions; reports filed by 30 September 2026 feed the next analytical review. Nothing is verified, and a draft scoring system was rejected by participants.

Written and maintained by CASRAI Editorial Board

Last updated

The G7 Hiroshima AI Process produced two separate things that are constantly confused: a voluntary International Code of Conduct for Organizations Developing Advanced AI Systems, issued by G7 Leaders on 30 October 2023, and a questionnaire the OECD built four years later so organisations could say, in public and in a common format, what they actually do about each of the Code’s eleven actions. The Code is the norm. The HAIP Reporting Framework is the disclosure vehicle. Version 2.0 of that framework launched on 28 May 2026 in Paris, and the deadline to be included in the next analytical review is 30 September 2026. Nothing in either document is binding, nobody verifies a submitted answer, and the OECD says so on the portal itself. In NIKOLAI’s vocabulary, a HAIP report is a self-attestation with no External Review record standing behind it — which is the single most important thing to understand before citing one.

The two artefacts, kept apart

Almost every summary of the Hiroshima AI Process collapses the Code and the Framework into one thing. They were produced by different bodies, at different times, for different purposes, and they behave differently when you try to rely on them.

  International Code of Conduct HAIP Reporting Framework
What it is A list of eleven voluntary actions organisations developing advanced AI are asked to take A structured questionnaire organisations complete and publish, mapped to those actions
Issued by G7 Leaders, under Japan’s 2023 G7 Presidency The OECD, on a mandate finalised under Italy’s 2024 G7 Presidency
Date 30 October 2023; folded into the Hiroshima AI Process Comprehensive Policy Framework agreed by G7 Digital and Tech Ministers in December 2023 v1.0 launched February 2025; v2.0 launched 28 May 2026
Legal force None. Voluntary guidance. None. Voluntary participation.
Who checks Nobody Nobody. The OECD publishes what is submitted.
Where it lives MOFA and Soumu document archives; mirrored by the European Commission The OECD.AI transparency portal, one public report per organisation

The distinction matters because the Code has no reporting obligation attached to it and the Framework has no compliance meaning attached to it. An organisation can follow the Code and never file. An organisation can file a thorough report and still be describing aspirations. The portal carries an explicit warning to that effect: participation “is voluntary and does not constitute compliance with, or equivalence to, other frameworks, whose scope and expectations may vary.”

The eleven actions of the Code of Conduct

The Code asks organisations to follow its actions “in a manner that is commensurate to the risks,” across the design, development, deployment and use of advanced AI systems — the most capable foundation models and generative AI systems. Condensed, the eleven are:

  1. Identify, evaluate and mitigate risks across the lifecycle, including before and throughout deployment and placement on the market.
  2. Identify and mitigate vulnerabilities, incidents and patterns of misuse after deployment, once systems are in the field.
  3. Publicly report capabilities, limitations, and domains of appropriate and inappropriate use — the provision that model cards and system cards nominally answer.
  4. Work towards responsible information sharing and incident reporting among developers, governments, civil society and academia.
  5. Develop, implement and disclose AI governance and risk management policies grounded in a risk-based approach, including privacy policies and mitigation measures.
  6. Invest in and implement robust security controls — physical security, cybersecurity and insider-threat safeguards across the lifecycle.
  7. Develop and deploy content authentication and provenance mechanisms such as watermarking, where technically feasible.
  8. Prioritise research to mitigate societal, safety and security risks.
  9. Prioritise development of AI addressing the world’s greatest challenges, such as the climate crisis, global health and education.
  10. Advance the development and adoption of international technical standards.
  11. Implement appropriate data input measures and protections for personal data and intellectual property.

Read as a list, actions 1 through 7 are risk and security obligations and actions 8 through 11 are investment and ecosystem commitments. That split explains a lot about the reports that come back: the second half is straightforward to describe and impossible to falsify, so it is where submissions tend to be longest.

What the Reporting Framework asks

The questionnaire is organised into seven sections carrying roughly 39 items in total — between two and eight questions per section:

  1. Risk identification and evaluation — how the organisation classifies risk, identifies and evaluates it, and conducts testing.
  2. Risk management and information security — data quality, intellectual property and privacy protection, and AI-specific information security practices.
  3. Transparency reporting on advanced AI systems — reports, technical documentation and disclosure practices.
  4. Organisational governance, incident management and transparency — governance structures, staff training, and AI incident response processes.
  5. Content authentication and provenance mechanisms — how users are informed that content is AI-generated.
  6. Research and investment to advance AI safety.
  7. Advancing human and global interests — digital literacy, human-centric AI, and beneficial applications.

The mapping back to the Code is loose rather than one-to-one: seven sections against eleven actions means several actions share a section and one section (transparency) covers a single action at length. Anyone building a crosswalk from a HAIP report to another framework has to do that reconciliation by hand.

Version 2.0: what actually changed

The OECD launched version 2.0 on 28 May 2026 at an event organised by Tech7, on the margins of the G7 Digital and Tech Ministerial Meeting under France’s G7 Presidency in Paris. It was refined through a pilot involving organisations from seven countries — model developers, application developers and deployers across the value chain — plus input from individual experts. More than 50 organisations pledged to complete a report using it.

Four changes are substantive rather than cosmetic:

  • Role-based routing. v1.0 implicitly assumed the respondent was a frontier model developer. v2.0 sorts respondents by role — model developer, application developer, deployer — and routes each to the questions relevant to that role. This is the change that makes the framework usable by an organisation that trains nothing and deploys a vendor’s model.
  • Closed questions replace open prose. Most of v1.0’s open-ended questions become checkboxes and yes/no questions with conditional follow-ups; free text survives mainly in sub-questions. This is the direct answer to the comparability problem documented below, and it comes at a real cost — v1.0’s free text captured nuance that a checkbox cannot.
  • New and previously buried topics. v2.0 adds explicit coverage of agentic AI and agent-to-agent interaction, scaling mitigations with model capability, systemic risk thresholds and indicators, AI safety institute involvement in third-party testing, fundamental rights, vulnerable populations, confidential reporting channels, and AI-specific threats.
  • Borrowed vocabulary. v2.0 adopts terminology from the NIST AI Risk Management Framework, ISO/IEC 42001 and the EU’s General-Purpose AI Code of Practice, and links out to the OECD.AI Catalogue of Tools and Metrics — so answers are at least phrased in terms other frameworks recognise.

Organisations are encouraged to submit under the revised framework by 30 September 2026 to be included in the next planned analytical review. Submission itself is on a rolling basis; the deadline governs inclusion in the analysis, not the ability to file.

Who has actually reported, and how many

The participation number is quoted inconsistently, including across the OECD’s own pages, and the discrepancy is worth stating plainly rather than picking a favourite figure:

Source Count As of
OECD.AI early-insights post 19 organisations submitted February to April 2025
OECD.AI “ten insights” analysis 20 organisations in the first cycle Published April 2025
Brookings review 24 submissions, up from 19 in May Late November 2025
OECD.AI transparency overview 25 reports in the initial round 2025 analysis
OECD v2.0 launch More than 50 organisations pledged 28 May 2026

The counts differ because they measure different things at different cut-offs: reports versus organisations, first-batch versus cumulative, submitted versus published versus pledged. None of them is wrong. All of them get cited as “the number of HAIP participants,” which is how a range of 19 to more than 50 ends up in circulation for the same programme. If you need a figure, name the source and the date with it.

Geographically, the first cohort was concentrated: the Brookings review counted nine submissions from Japan, seven from the United States, and two each from Canada and Germany. By size, eighteen were large enterprises and three were micro-enterprises. Named filers include Amazon, Anthropic, Google, Microsoft, OpenAI and Salesforce alongside Fujitsu, Hitachi, KDDI, NEC, Preferred Networks, Rakuten and SoftBank — a roster in which the Japanese contingent is as prominent as the US frontier labs, which is unusual among AI transparency regimes and a direct legacy of the process starting under Japan’s G7 Presidency.

The comparability problem, and why scoring was rejected

The first reporting cycle surfaced a structural problem that no amount of goodwill fixes. Submissions ranged from 9 to 60 pages. About a third answered by hyperlinking to external material rather than responding in the form. Thirteen organisations reported company-wide while ten used a hybrid scope; eight answered from a developer perspective and six from a deployer perspective. Most responses were high-level and hard to verify, describing governance processes without distinguishing what is implemented from what is planned, and rarely offering metrics such as error rates or benchmark results. Large companies paradoxically supplied less direct detail, curating transparency through their own documentation ecosystems instead.

The obvious remedy is to score the reports. The OECD tried it. Following interviews with 11 of the first 19 participating organisations and a multistakeholder meeting in Tokyo in June 2025, researchers presented a draft scoring system — and several participants strongly objected, arguing that simplistic rankings would distort incentives, discourage participation, and shift the focus from transparency to performance signalling.

That objection is the fault line running through every voluntary disclosure regime: the thing that would make reports comparable is the same thing that would make organisations stop filing them. v2.0’s move to closed questions is an attempt to get comparability structurally, at the form level, without imposing a score. Whether that works is the open question of the next analytical review.

A related finding cuts against the cynical read. Participants consistently reported that preparing the report was as valuable as publishing it — it forced internal coordination, clarified who owned which control, and surfaced governance gaps. That is a real benefit, but it is a benefit to the filer, not to a reader trying to assess the filer.

How HAIP relates to the instruments that do bind

HAIP sits in a crowded field, and its position in that field is specific: it is the only international framework in which an organisation reports on its own practices against a G7-agreed norm, in public, in a common form.

  • Versus the OECD AI Principles: the Principles are an OECD Council Recommendation addressed to governments; HAIP’s Code is addressed to organisations. Same institution hosting the machinery, different addressee.
  • Versus the EU AI Act GPAI Code of Practice: the GPAI Code is a route to demonstrating compliance with a binding regulation; HAIP is not a route to compliance with anything, as the portal disclaimer states. The two use overlapping vocabulary by design, so a HAIP answer can be reused as input to EU AI Act documentation — but never as evidence of it.
  • Versus the Seoul Frontier AI Safety Commitments: Seoul asked frontier developers to publish safety frameworks; HAIP asks a broader population to answer a common questionnaire. Seoul produces documents in each signatory’s own format; HAIP produces filled forms.
  • Versus the Council of Europe AI treaty: a binding international instrument on states. HAIP binds nobody and reaches organisations directly.

For a wider map of which instruments have teeth and which do not, see AI regulations around the world.

What a research administration office can do with this

Universities and research institutes rarely train advanced AI systems, so the Code’s developer-facing actions do not describe them. Two things nonetheless make HAIP directly useful to a research administration function.

Vendor due diligence for research computing. HAIP reports are free, public, structured disclosures of a vendor’s AI governance, security controls, incident response and content-provenance practices, written by the vendor against a fixed set of questions. For a research computing office evaluating whether to route institutional research data through a model provider, that is a better starting point than a marketing page and cheaper than a bespoke questionnaire. The caveat is the one running through this page: nothing in a HAIP report is verified, so it tells you what a vendor is willing to assert in public, which is useful precisely because it is on the record. Pair it with the structured approach in assessing third-party AI vendor risk.

Filing as a deployer. v2.0’s role-based routing is what makes this possible: a university that deploys advanced AI in research support, administration or teaching can answer the deployer path without pretending to be a model developer. Whether that is worth the effort depends on the institution — the filers’ own reported benefit was internal coordination and gap-finding, which maps neatly onto the work an institutional AI governance committee has to do anyway. If your institution is building that capability from scratch, the sequencing in the AI governance maturity model is the more practical starting point, and HAIP becomes a way to publish the result.

Where HAIP does not help: it carries no research security or export-control content, says nothing about human-subjects review, and is not a procurement standard. Do not let it stand in for any of those.

Where NIKOLAI fits

NIKOLAI is CASRAI’s own independent dictionary for frontier AI safety governance. It is not endorsed by the OECD, the G7, or any organisation that has filed a HAIP report, and every crosswalk row in it is a shadow mapping — CASRAI’s own reading of published material — unless that organisation has filed a Mapping Declaration saying otherwise.

The element that matters here is External Review on track N8 (transparency and review), which records an assessment performed by a party outside the model developer, with its type, scope and output. Run a HAIP report against that element and the result is clean and uncomfortable: a HAIP submission populates a great deal of an organisation’s governance record and populates no External Review at all. The OECD hosts, formats and publishes; it does not assess. That is not a criticism of the framework, which never claimed to audit — it is a reason to be precise about what a citation to a HAIP report supports. It supports “the organisation stated X in a public filing on date Y.” It does not support “the organisation does X.”

The same distinction is why the ranking proposal failed. Scoring self-attestations produces a league table of disclosure quality, not of safety practice, and participants read that risk correctly.

Frequently asked questions

Is the HAIP Reporting Framework mandatory?

No. Participation is voluntary, the underlying Code of Conduct is voluntary guidance, and the OECD portal states explicitly that participation does not constitute compliance with, or equivalence to, other frameworks.

Who can submit a HAIP report?

Under version 2.0, any organisation across the AI value chain — model developers, application developers and deployers — including small and medium enterprises. Version 1.0 was aimed at developers of advanced AI systems; broadening participation was the main purpose of the 2.0 revision.

What is the deadline?

Submission is rolling, but reports filed by 30 September 2026 are the ones included in the next planned analytical review.

Does the OECD verify what organisations report?

No. The OECD publishes submitted reports on the OECD.AI transparency portal. There is no audit, no assurance step and no third-party attestation requirement. Independent reviewers have repeatedly noted that most responses are high-level and difficult to verify.

How many organisations have filed?

It depends on the source and cut-off: 19 or 20 in the first cycle between February and April 2025, roughly 24 to 25 by late 2025, and more than 50 pledged to file under version 2.0 as of its May 2026 launch. Cite a number with its source and date attached.

Can a HAIP report be used to show EU AI Act compliance?

No. It uses overlapping vocabulary with the EU’s General-Purpose AI Code of Practice by design, so material can be reused as input, but the portal disclaimer rules out treating participation as equivalence to any other framework.

How does version 2.0 differ from version 1.0?

It routes respondents by role, replaces most open-ended questions with closed ones and conditional follow-ups, adds coverage of agentic AI, systemic risk thresholds, AI safety institute testing, fundamental rights and confidential reporting channels, and aligns vocabulary with the NIST AI RMF, ISO/IEC 42001 and the EU GPAI Code.

Is there a scoring or ranking of HAIP reports?

No. A draft scoring system was presented at a multistakeholder meeting in Tokyo in June 2025 and several participating organisations strongly objected, on the grounds that rankings would distort incentives and discourage participation.

Primary sources

Verified against these sources on 25 September 2026. Figures in this page are attributed to the source that published them; where sources disagree, the disagreement is shown rather than resolved.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about G7 Hiroshima AI Process: the Code of Conduct and the HAIP Reporting Framework

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

AI policy question? Get an answer citing the framework.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.