AI Policy Wiki
Dashboard

G7 Hiroshima Code of Conduct for Advanced AI (2023)

high confidence · updated 2026-06-06

Source summary of the G7 voluntary code of conduct for organisations developing advanced AI systems, adopted October 2023 as part of the Hiroshima AI Process.

The G7 Hiroshima Code of Conduct for Advanced AI is a voluntary code of conduct for organisations developing the most advanced AI systems, including foundation models and generative AI. It was adopted on 30 October 2023 under Japan's 2023 G7 Presidency as part of the Hiroshima AI Process, alongside a companion set of 11 "Hiroshima Process Guiding Principles." The Code is described as "living" (non-static) and risk-based, and applies across the AI lifecycle. The framework page is G7 Hiroshima Code of Conduct for Advanced AI (2023).

Summary of the Code

The Code comprises 11 Actions:

  1. Risk assessment and mitigation across the lifecycle, including CBRN, cyber, self-replication, societal/bias, and democratic-values risks.
  2. Post-deployment vulnerability and misuse management (bounties, incident documentation, collaboration).
  3. Public transparency reporting on capabilities, limitations, and appropriate use.
  4. Responsible information sharing and incident reporting with industry, governments, civil society, and academia.
  5. AI governance and risk management policies (accountability, privacy, training).
  6. Robust security controls (physical, cyber, insider-threat, model weights).
  7. Content authentication and provenance (watermarking, C2PA-style mechanisms).
  8. Prioritized research on risk mitigation (bias, disinformation, child protection, IP, environment).
  9. Address global challenges (climate, health, education, SDGs).
  10. International technical standards contribution and adoption.
  11. Data input measures and protections for personal data and IP.

The Code is built on the OECD AI Principles (2019). It was extended under Italy's 2024 G7 Presidency with a Reporting Framework, and is monitored by the OECD.

Key claims

The Code was the first G7-level AI code of conduct, adopted four days before the Bletchley declaration, and provided a template that the later The Bletchley Declaration (AI Safety Summit, 1–2 November 2023) and Seoul commitments built on.

Action 1 explicitly names chemical, biological, radiological, and nuclear (CBRN) risks and "self-replicating or self-proliferating models," anticipating the frontier threshold systems later set out in Anthropic's Responsible Scaling Policy (Version 3.1) and OpenAI Preparedness Framework V.2.

Action 7 calls for "reliable content authentication and provenance mechanisms, where technically feasible, such as watermarking." A comparable provenance and watermarking emphasis appears in the Singapore MGF and EU AI Act (Regulation 2024/1689).

The OECD runs the reporting framework, which serves as the practical compliance and monitoring mechanism. The Code is cross-referenced by the EU GPAI Code of Practice and forms part of the EU's argument for adequacy.

Relation to other frameworks

The Code pre-dates The Bletchley Declaration (AI Safety Summit, 1–2 November 2023) in the international framework lineage and feeds into it. It is explicitly referenced by the GPAI provisions of the EU AI Act (Regulation 2024/1689) and by the EU General-Purpose AI Code of Practice (Final Version, 2025). Its CBRN and cyber risk framing aligns with Managing Advanced Cyber Risks in Frontier AI Frameworks and AI Biosecurity, and its watermarking and provenance provisions connect to Singapore Model AI Governance Framework for Generative AI (2024).

Relationships