Full submission text available here. Read on below for a summary.
Safe Innovation as Infrastructure: Making AI Assurance and Resilience Integral to Hong Kong’s First Five-Year Plan
257KB ∙ PDF file
This document contains the full text of our submission in response to the HK Government's Five-Year Plan consultation document.
Hong Kong is implementing a five-year plan for the first time in its history.
What is a five-year plan? It is a planning instrument China borrowed from the Soviet Union in the 1950s. The first one ran from 1953 to 1957 and was built around heavy industry and collectivised agriculture. Seventy years later the form has survived while the content has changed almost beyond recognition. A modern plan sets national priorities, growth targets and technology objectives for a five-year cycle, and governments at every level below write their own plans to match it. The PRC’s National People’s Congress approved the National 15th Five-Year Plan, covering 2026 to 2030, in March 2026.
Hong Kong has never produced one of its own before. The HK government’s stated reason for starting now is to align the city’s development with national strategy, and it describes the exercise as a vital step in exercising executive-led governance, deepening reforms and enhancing governance efficacy.
The HK government’s Constitutional and Mainland Affairs Bureau put a draft out for public comment in June and closed the consultation on 14 August. We read the consultation in full to see what it implied for AI safety, and filed a submission.
The Plan is organised into six Parts.
Part 1 — Land and new districts. Hong Kong is among the most crowded places on earth, and the built-up areas around Victoria Harbour have almost no room left to expand into. This Part sets out the government’s planned response to it. The Northern Metropolis is a new district along the Shenzhen border, planned to hold housing, universities, technology firms and medical research, easing the land shortage while putting research and industry next to each other and close enough to Shenzhen for the two cities to work as a single innovation cluster. It would contain a University Town, and Hetao, a science park straddling the boundary and developed jointly with Shenzhen.
Part 2 — Finance and professional services. Finance is the centrepiece of Hong Kong’s economy, and this Part is dedicated to defending and extending that position. It covers Hong Kong’s standing as an international financial centre, its ambitions in asset management, insurance and risk management, and the professional services that make all of it work, including law, arbitration, accounting, and testing and certification.
Part 3 — Industry and technology. Hong Kong leans heavily on services and has a narrow industrial base, and the Plan states that research coming out of its universities too rarely reaches the companies that could use it. This Part sets out to close that gap, and it contains the Plan’s only substantial passage on AI. That passage is built around the AI+ Initiative, which is a mainland Chinese programme. The Central People’s Government announced it at the “two sessions”, the pair of national meetings held in Beijing each March at which the National People’s Congress and the Chinese People’s Political Consultative Conference set the year’s political agenda, and a detailed action plan for implementing it followed in August 2025. The AI+ Initiative’s purpose is to get AI adopted into 90% of China’s economy by 2030. The Hong Kong governmment has committed to deepening that programme locally, which means running a national initiative through Hong Kong’s own universities, regulators and financial sector, under the separate legal and regulatory system Hong Kong operates.
Part 4 — People. This Part covers the public services people rely on, including education, healthcare, housing, social welfare, labour and elderly care, with the stated goal of raising living standards. AI appears here mainly in the context of healthcare, where the Plan wants electronic health records across the whole system and what it calls “smart healthcare”, meaning AI used in areas like diagnosis, triage and clinical support.
Part 5 — Regional and global links. This Part points in two directions. Looking inward toward the mainland, it commits Hong Kong to deeper integration with the Greater Bay Area, the cluster of Hong Kong, Macao and nine cities in Guangdong that Beijing treats as one economic region. A recurring theme is “soft connectivity”, by which the Plan means aligning the rules on either side of the boundary, so that a licence, a standard or a professional qualification recognised in Hong Kong is recognised in Guangdong too (Bridges and railways are the “hard” kind of connectivity). Looking outward, the Plan asks Hong Kong to help Chinese standards win acceptance internationally, and to assemble capital, projects, talent, technology and professional services for Belt and Road co-operation, China’s programme of infrastructure and investment partnerships across Asia, Africa and Europe.
Part 6 — Resilience and security. This Part covers how the city copes when things go wrong, meaning public safety, cybersecurity, emergency planning, and the machinery through which government departments assess risk and prepare for it. The hazards it has in mind are mostly physical ones, typhoons and floods and public-order emergencies. Mentions of smart city infrastructure and autonomous vehicles also appear here.
The Plan carries weight because government departments will use it to justify their budgets over the next five years. A capability the text names is easier to fund than one it leaves out.
The government has not waited for the Plan to be finished before building. In September 2025 the Legislative Council approved HK$1 billion to establish the Hong Kong Artificial Intelligence Research and Development Institute (AIRDI), which the funding paper describes as the main driver for promoting AI development in Hong Kong. Its remit includes setting AI standards, promoting interoperability between systems, and providing AI safety assessment and compliance consulting. A 14-member board was appointed in March 2026, and the institute should be fully operational before the end of the year.
The Plan’s substantive commitment on AI is a single sentence in Part 3:
“Deepen the implementation of the AI+ Initiative, accelerate the transformation of AI R&D outcomes and development of application scenarios, promote the deep integration of AI across various industries, and refine the framework for AI and data governance.”
Almost all of that sentence concerns speed and diffusion — getting AI into more industries and getting it there faster. Governance occupies the last seven words, which promise to refine a framework without saying what refining it would involve. Refining it would presumably require the ability to evaluate an AI system, test it, and learn from it when it fails. The Plan mentions none of those.
The Plan commits Hong Kong to a holistic approach to development and security in its guiding principles, and Part 6 states that development and safety deserve equal emphasis. The same commitment appears in government statements outside the Plan. The Chief Executive’s Policy Address, delivered annually to set out government priorities, promised in 2025 to promote AI across sectors while placing strong emphasis on safety risk prevention. In June 2026 the Innovation, Technology and Industry Bureau, which runs technology policy, told the Legislative Council that AI development must be guided by safety and driven by applications.
The government has therefore said, more than once, that AI development should be governed by safety considerations. Our submission asked for that commitment to be written into the Plan’s AI text, where at present it does not appear.
Embed safe, secure, trustworthy and accountable AI across the Plan. We asked for two changes to the Part 3 sentence provided above. The first is to state that AI will be integrated into industries and public services on a safe, secure, trustworthy and accountable basis. The second is to expand that seven-word governance promise so it names what a refined framework would contain, meaning the capacity to evaluate AI systems, test them, assure them, secure them, and learn from incidents when they occur.
Hong Kong regulators have already adopted written guidance on AI diffusion. For example, the Digital Policy Office publishes an Ethical Artificial Intelligence Framework and a generative AI guideline, which tell departments and businesses what responsible AI use looks like across system security, robustness, privacy and data management. However, guidance of that kind describes a standard. It does not create anyone able to check whether the standard is being met, and the Plan makes no commitment to building that capacity.
Our recommendation here applies across the whole Plan, and Part 6 is where it reaches furthest from familiar ground, because the resilience chapter is written for typhoons and floods. As AI is built into essential services, the same risk assessment and contingency machinery will have to handle cyber misuse, AI-enabled fraud, autonomous systems failing in ways nobody planned for, and services collapsing because an AI provider went down.
Make AIRDI’s assessment work demonstrably independent. We asked the government to settle one question about AIRDI’s structure before it opens.1
AIRDI’s funding proposal envisages two lines of business that sit awkwardly together. Under one, AIRDI would assess and certify AI systems for security and compliance. Under the other, it would sell consulting services to the companies building those systems on a fee-charging basis, and the paper anticipates AIRDI moving gradually towards self-financing partly through such fees. An organisation that advises a company on its AI system and then certifies that system invites an obvious question about whose interest the certificate serves.
We are not suggesting AIRDI would necessarily behave improperly, and certain safeguards already exist, including a government-appointed board, a designated Controlling Officer, unrestricted audit access and reporting to the legislature. However, a certificate is only useful to a third party who can see that the assessment behind it was independent. We asked for the assessment function to be separated from fee-earning advice, for assessment methodologies and conflict-of-interest arrangements to be published, and for safety measures to appear among the results AIRDI reports against. Settling this while the institute is still being designed costs far less than retrofitting it afterwards.
Build Hong Kong’s role as a bridge for AI assurance and standards. We asked the Plan to develop a role Hong Kong is unusually well placed to fill.
A company running the same AI system in Hong Kong, Shenzhen and Frankfurt has to satisfy three differently shaped sets of requirements. Mapping those requirements against each other, and training people who can apply them, is technical work that suits institutions Hong Kong already runs. Testing and certification is the industry of independent laboratories and certification bodies that examine a product or a company against a written standard and issue a certificate confirming it complies, and Hong Kong’s version of that industry is mature. The Hong Kong Accreditation Service accredits those laboratories and certification bodies, and it holds the international arrangements through which Hong Kong certificates are recognised abroad. Extending all of that to AI requires new standards and assessment criteria, a considerably smaller job than founding an institution.
Of course, certification has its limit. Checking that a company has sound governance, documentation and testing processes tells you nothing about what its AI model can actually do, including whether the model could help someone run a cyber attack. Answering such questions takes different methods, and they are research problems better suited to Hong Kong’s universities than to its certification bodies.
The argument running through all three recommendations is that assurance helps AI diffusion.
Consider a bank that wants to use a model in credit decisions. Before it can, it has to satisfy its board, its auditors, its insurer and its regulator that the model behaves predictably and that somebody is accountable when it does not. Every bank assembling that evidence on its own pays for the same work again. Common standards and shared testing methods make the evidence cheaper to produce and easier for a regulator to check, which is why Hong Kong’s financial regulators have built something along these lines. In March 2026 the four financial regulators, together with Cyberport, expanded the GenA.I. Sandbox into the GenA.I. Sandbox++, a controlled environment covering banking, securities, asset and wealth management, insurance, pensions and stored-value facilities, in which firms can test AI applications with supervisory input.
The same reasoning runs through the Plan’s ambitions in insurance and risk management. Spreading AI through financial services introduces model risk, heavy dependence on a small number of third-party providers, AI-enabled fraud, and the possibility of services failing when a provider fails. Regulators are already responding to these emerging threats. The Securities and Futures Commission has told licensed firms to manage AI model risk, validate models before approving them for use, and test performance end to end from user input to system output. A city that intends to sell risk management services to the world needs the capacity to do this work well for itself.
Hong Kong has the institutions for becoming an AI assurance capital. What it lacks is the AI-specific standards and criteria for them to work against.
The Plan is being finalised, and we will read the final version when it is published. Our full submission to the public consultation is provided at the start of this post. It sets out our reasoning at greater length, proposes specific drafting for the Part 3 and Part 6 text, and lists implementation pathways there was no room to include in a summary post.
We are field-building AI safety in Hong Kong. If you work on any of this, in testing and certification, financial services, the universities, government, or on the same questions somewhere else, write to us at info@aisafetyhk.org.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.