What the PCPD did
The PCPD launched the compliance checks in January 2026. The sample was 60 organisations across sectors. The methodology was documentary review and organisational interviews focused on how AI was being used, what governance sat around it, and how personal data flowed through those systems. Results were published in May 2026.
What the PCPD found
- 95% of organisations used AI in day-to-day operations. A far higher penetration than most surveys report because this counted embedded AI features in commonly used tools, not just standalone AI systems.
- Over half used three or more AI systems. The single-tool AI story is already out of date for Hong Kong business.
- No PDPO contraventions were identified in the sample. This is the headline — and it should be read as "the sampled organisations were operating within the current framework", not "AI use in Hong Kong is uniformly compliant".
- Governance maturity was inconsistent. Organisations that used AI heavily did not always have proportionate governance.
What the PCPD recommended
Six recommendation areas. Each is worth reading as a checklist for a Hong Kong SME:
- AI governance structure. Someone accountable — not "IT" as a black box.
- Privacy Impact Assessments (PIAs) for material AI use cases involving personal data.
- AI audits. Periodic review of what the AI is actually doing in production versus what was documented.
- Staff training. Users of AI tools understand what data they can and cannot put in.
- Incident-response plans that specifically cover AI-related incidents — not the generic IT incident plan retitled.
- Controls for agentic AI. See our detailed post: PCPD\'s agentic AI alert.
How to read "no contraventions found"
This is the most misread line in the report. It does not mean AI use in Hong Kong is broadly compliant. It means the sampled 60 organisations were operating within the current PDPO framework — a framework which is materially lighter on AI-specific obligations than, for example, Singapore\'s post-July-2026 position. The PCPD\'s recommendations exist because the current absence of contraventions is a floor, not a ceiling.
A Hong Kong business that is comfortable operating at the current statutory floor should still expect the floor to rise. The recommendation list above is the direction.
What to do this quarter — the SME cut
Six PCPD recommendations map to five practical actions for a 5–30 person Hong Kong business:
- Name an AI owner. One person. Written down.
- List your AI systems. Include embedded features (CRM AI, chatbot integrations, ad-copy assistants). The PCPD\'s "over half use three or more" figure means the honest count is usually higher than the intuitive one.
- Do a lightweight PIA on the two highest-risk systems. Not every system needs a full PIA — the highest-risk ones do.
- Ten-minute staff briefing on what not to put into AI tools. Written record.
- Add an "AI-related incident" branch to your existing incident-response document. One page.
Related reading
References
- Office of the Privacy Commissioner for Personal Data (PCPD), Hong Kong — compliance checks announcement (January 2026) and results publication (May 2026) — pcpd.org.hk
- Mayer Brown, "AI in Asia mid-year checkpoint", July 2026