A narrow, dated note on Hong Kong instruments relevant to AI-agent oversight. Each entry names the instrument's exact status and addressees. Guidance, supervisory circulars and legislation are different things, and this note keeps them apart.
These pages describe the product and cite public instruments. They are not legal advice, not a certification, and not a statement that any instrument applies to your organisation. The official source is authoritative; applicability questions belong to your advisers.
Instruments, by status
| Instrument | Status | What it addresses |
|---|---|---|
| Personal Data (Privacy) Ordinance (Cap. 486) | Binding law. | Personal data handling, including by AI systems. Using AAES does not discharge the data user's duties; other parties' obligations depend on their roles. |
| Artificial Intelligence: Model Personal Data Protection Framework · PCPD | Voluntary framework, published 11 June 2024. The Model Framework is voluntary and is not an approved code of practice under the PDPO. | AI strategy and governance with named accountability, risk assessment and human oversight, model lifecycle management, stakeholder engagement. |
| 2026 compliance checks · PCPD | Supervisory activity; findings published 19 May 2026. The third annual round covered 60 organisations across 15 sectors and identified no PDPO contraventions. | Examined AI use and personal-data privacy in practice, including implementation of the Model Framework and the GenAI employee checklist. The checks were not agentic-AI-specific tests. |
| Protecting Personal Data Privacy in the Use of Agentic AI · PCPD | Guidance, published 25 August 2026. Supplements the 2024 Model Framework; not law. | Five privacy risks of AI agents with system access (extensive access, system vulnerabilities, vulnerable plugins, function creep, multi-agent risks), with nine recommendations and a security checklist under the PDPO. |
| Circular on use of generative AI language models · SFC, 12 November 2024 | Supervisory circular. Addressed to licensed corporations, not legislation, and not addressed to organisations outside SFC supervision. | Four areas: senior-management responsibility, AI model risk management, cybersecurity and data risk management, third-party provider risk management. |
What AAES records may contribute
| Expectation | AAES contribution | Capability status |
|---|---|---|
| Named accountability (PCPD Model Framework; SFC senior-management responsibility) | Every registered agent has a named accountable manager, a configured association rather than a statutory appointment; approvals are attributable to a named person; agent identities cannot act as approvers through the supported AAES approval path. | Implemented. |
| Human oversight of consequential actions (PCPD guidance; SFC circular) | Actions the operator registers as irreversible (a registration classification, not an independent assessment of effects) require approval by an authorized person, bound to one intent and the exact payload, with expiry. An approval record does not by itself show the approver had adequate information, time or practical power to intervene. | Implemented. |
| Records an internal audit can review (PCPD internal-audit recommendation) | Sealed, hash-chained decision records with offline integrity verification by the client's own reviewer. | Implemented. An independently controlled witness can be configured separately; that is not an external assessment, and the default deployment has none. |
AAES decision records may support review of access and approval controls. They do not establish lawful processing, model fairness, suitability, or compliance with any instrument as a whole.
Within the configured trust model, integrity verification checks the exported records; it does not establish that every action was recorded, that an external action succeeded, or that recorded assertions are true. Approval records do not by themselves establish meaningful human oversight. Enforcement depends on control of the credential path, and actions bypassing AAES are not recorded.
Residual responsibility and explicit gaps
- The client remains the regulated entity. Whether the SFC circular or a PCPD instrument applies to you is your adviser's question, not this page's.
- Work outside AAES is invisible to AAES. Records cover actions routed through AAES; they say nothing about actions on bypass paths.
- No independent certification or assessment of AAES exists. No SOC 2 report, no penetration test.
- Status changes. Instruments are updated; re-check the primary source before relying on the status shown here.
Bring the instruments your risk team cites to a scoped evaluation.
Related pages:
This note: https://aaes.ai/library/jurisdictions/hong-kong.html
Singapore note: https://aaes.ai/library/jurisdictions/singapore.html
Trust model: https://aaes.ai/library/trust-model.html
Scope an evaluation: https://aaes.ai/contact.html?ref=library-evaluation
