The Hiroshima Process International Code of Conduct for Organizations Developing Advanced AI Systems is a voluntary, non-binding code of conduct adopted by the G7 on 30 October 2023 under Japan's 2023 G7 Presidency. It sets out 11 Actions for organisations developing the most advanced AI systems, and was the first G7-level AI code of conduct. It is paired with a companion set of 11 Hiroshima Process International Guiding Principles, and is monitored by the OECD.
| Field | Detail |
|---|---|
| Full title | Hiroshima Process International Code of Conduct for Organizations Developing Advanced AI Systems |
| Enacting body | G7 (Canada, France, Germany, Italy, Japan, UK, US) + EU, under Japan's 2023 G7 Presidency |
| Date | 30 October 2023 (adopted) |
| Legal status | Voluntary, risk-based, "living" guidance; non-binding |
| Scope | Organisations developing "the most advanced AI systems," including foundation models and generative AI, across the AI lifecycle |
Status and timeline
The Code was adopted on 30 October 2023, four days before the Bletchley Declaration. It built on the OECD AI Principles (2019), and was issued alongside the 11 Hiroshima Process International Guiding Principles. Under Italy's 2024 G7 Presidency the framework was extended with a Reporting Framework. The OECD monitors organisations' adherence; this monitoring consists of reporting rather than enforcement.
Scope and definitions
The Code applies to organisations developing "the most advanced AI systems," a category that includes foundation models and generative AI, and covers the AI lifecycle. It is described as voluntary, risk-based, and "living" guidance, meaning it is intended to be updated over time. It carries no enforcement mechanism.
Key provisions: the 11 Actions
Action 1 — Risk Assessment and Mitigation Across the Lifecycle
Diverse testing (red-teaming), dataset/process/decision traceability, and secure-environment testing at multiple checkpoints. The Action gives particular attention to CBRN risks (chemical, biological, radiological, nuclear); offensive cyber capabilities; health and safety; self-replicating or self-proliferating models; societal, bias, and discrimination risks; threats to democratic values and human rights; and systemic, cascading risks.
Action 2 — Post-Deployment Vulnerability and Misuse Management
Monitor emerging risks; support third-party discovery (bug bounties); maintain incident documentation; and pursue cross-organisation collaboration.
Action 3 — Public Transparency Reporting
Publish capabilities, limitations, appropriate and inappropriate use, evaluations, risk assessments, bias analysis, privacy implications, and red-teaming results, in a clear and regularly updated form.
Action 4 — Responsible Information Sharing and Incident Reporting
Share evaluations, security and safety risks, dangerous capabilities (intended or unintended), and attempted circumvention, while protecting intellectual property and sensitive information.
Action 5 — AI Governance and Risk Management Policies
Accountability mechanisms; lifecycle risk frameworks; privacy policies; and staff training.
Action 6 — Security Controls
Physical security; cybersecurity; insider-threat safeguards; secured model weights and datasets; access limits on unreleased models; and vulnerability management.
Action 7 — Content Authentication and Provenance
Watermarking, detection APIs, provenance tools (C2PA-style), and labels and disclaimers.
Action 8 — Prioritized Research on Risk Mitigation
Research on democratic values, human rights, child protection, intellectual property, privacy, bias, and disinformation, as well as environmental and resource impacts.
Action 9 — Address Global Challenges
Climate, global health, and education. Support for the UN Sustainable Development Goals, digital-literacy initiatives, and public-interest AI.
Action 10 — International Technical Standards
Contribute to standards for watermarking, testing, content authentication, cybersecurity, and AI-vs-non-AI content frameworks.
Action 11 — Data Input Measures and Protections
Training-data quality; privacy-preserving techniques; preventing sensitive-data leakage; and respecting copyright.
Lineage and interoperation
The Code built on the OECD AI Principles (2019) and accompanies the 11 Hiroshima Process Guiding Principles. It was extended under Italy's 2024 G7 Presidency with a Reporting Framework and is monitored by the OECD. The EU AI Act's GPAI Code of Practice cross-references it; see EU General-Purpose AI Code of Practice (Final Version, 2025).
Comparison with other approaches
Compared with the Bletchley Declaration (November 2023), the Bletchley text consists of state-to-state resolutions (3 commitments), whereas Hiroshima is organisation-facing guidance (11 Actions); the two are complementary. The Seoul Commitments (May 2024) are narrower, with 8 commitments and 16 signing companies, and introduce an "intolerable risk threshold" and "don't deploy" language not present in Hiroshima; Seoul refines a narrower scope while Hiroshima spans broader ground. The Singapore MGF Gen AI (May 2024) sets out nine dimensions that map closely to Hiroshima's 11 Actions with a generative-AI lens. The EU GPAI Code of Practice (2025) is binding-in-effect for the EU market, whereas Hiroshima is globally voluntary; the GPAI Code cites Hiroshima as an interoperability partner.
Limitations and unresolved questions
Action 7 qualifies its watermarking and provenance expectations with "where technically feasible," reflecting that provenance remains technically difficult; the question is unresolved. Action 1 names self-replicating models explicitly, a frontier-autonomy concern later addressed in mechanisms such as the Anthropic RSP and the OpenAI Preparedness Framework. The Code carries no enforcement mechanism, and OECD monitoring is reporting rather than enforcement.
Relationships
- depends-on: OECD — Assessing Potential Future AI Risks, Benefits, and Policy Imperatives (OECD AI Principles lineage)
- supports: AI Safety Cases and Frameworks
- related: The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), Frontier AI Safety Commitments (Seoul, 2024), EU General-Purpose AI Code of Practice (Final Version, 2025), Singapore Model AI Governance Framework for Generative AI (2024), EU AI Act (Regulation 2024/1689), Managing Advanced Cyber Risks in Frontier AI Frameworks, AI Biosecurity, G7 (Group of Seven)