policy · Effective Oct 27, 2024
IL regulates AI through Privacy Protection Authority guidance on AI and data protection.
Privacy Protection Authority guidance on AI and data protection · effective 2024-10-27
Updated 60 days ago · 3 sources · confidence: medium
Overview
Israel’s approach to artificial intelligence regulation is defined by its 'Responsible Innovation' philosophy, a strategy designed to maintain the nation's status as a 'Startup Nation' while establishing necessary safeguards for human rights and public safety. Unlike the European Union’s horizontal approach via the AI Act, Israel has deliberately chosen a decentralized, sectoral model. This approach is rooted in the belief that AI technology is too diverse for a single, rigid statute and that specialized regulators—such as those in finance, health, and transportation—are best positioned to understand and mitigate the specific risks within their respective domains. The maturity of Israel's AI landscape is characterized by advanced policy development and strategic government investment, spearheaded by the Ministry of Innovation, Science and Technology (MIST) and the Ministry of Justice (MOJ). The Israeli government recognizes that AI is a dual-use technology with significant implications for national security, economic growth, and social welfare. Consequently, the national strategy is not merely about restriction but about creating an environment where trustworthy AI can flourish. This involves significant public-private partnerships and a focus on building the necessary human capital and technical infrastructure to support a robust AI ecosystem. The 'Responsible Innovation' framework is designed to be dynamic, allowing for rapid adjustments as new capabilities, such as generative AI and large language models, emerge and present new challenges to existing legal structures. By early 2026, the Israeli government has shifted from foundational strategy to active implementation, focusing on the creation of a national AI Policy Coordination Center. This center serves as a knowledge hub to ensure consistency across different sectors, preventing a fragmented regulatory landscape while allowing for the flexibility required by rapid technological evolution. The overall posture remains 'enabling' rather than 'restrictive,' emphasizing ethical principles over prescriptive prohibitions.
Regulatory approach
Israel’s regulatory architecture is strictly sectoral and risk-based. The government’s 'Policy, Regulation and Ethics Principles in the Field of Artificial Intelligence,' adopted in late 2023, explicitly directs sectoral regulators to lead the rulemaking process. Under this framework, regulatory intensity is calibrated to the level of risk and the potential impact on individual rights. Low-risk applications, such as customer service chatbots, are subject to minimal oversight, while high-impact systems—such as those used for credit scoring, medical diagnosis, or autonomous vehicles—are subject to more rigorous transparency, human oversight, and documentation requirements. This risk-based triage ensures that innovation is not stifled by unnecessary administrative burdens in low-stakes environments. The framework also prioritizes 'soft law' and incremental development. Instead of immediate binding legislation, the Israeli government encourages the use of voluntary standards, ethical codes, and regulatory sandboxes. These sandboxes allow companies to test AI applications in a controlled environment with regulatory supervision, providing regulators with empirical data to inform future rules. This iterative process is designed to foster 'international interoperability,' ensuring that Israeli AI companies can easily comply with global standards like the OECD AI Principles or the EU AI Act. By avoiding a unique, Israel-specific horizontal law, the government aims to reduce cross-border regulatory friction for its robust export-oriented technology sector. The six core ethical principles guiding this approach include human-centricity, equality and non-discrimination, transparency and explainability, reliability and safety, accountability, and privacy protection. These principles are intended to be integrated into the design phase of AI systems, promoting a 'trustworthy by design' culture within the Israeli tech ecosystem. The governance of AI in Israel is a collaborative effort involving several key ministries and independent authorities. The Ministry of Innovation, Science and Technology (MIST) acts as the policy lead, responsible for the national strategy, international representation, and the coordination of the National AI Program. MIST works closely with the Ministry of Justice (MOJ), specifically the Office of Legal Counsel and Legislative Affairs, which provides the legal interpretations necessary to apply existing laws—such as torts, contracts, and administrative law—to AI-related disputes. The MOJ also ensures that any new sectoral directives align with Israel’s constitutional values and human rights protections. Enforcement is decentralized among sectoral regulators. For instance, the Bank of Israel and the Israel Securities Authority oversee AI in the financial sector, while the Ministry of Health manages AI in medical devices. However, the Privacy Protection Authority (PPA) serves as a cross-sectoral enforcer regarding the data lifecycles of AI systems. The PPA has the mandate to investigate how personal data is collected, processed, and used for algorithmic decision-making. With the establishment of the AI Policy Coordination Center, the government has created a focal point to assist these various bodies in harmonizing their approaches, sharing technical expertise, and developing common tools like risk-assessment templates and documentation standards. This center also acts as a bridge between the government and the private sector, facilitating dialogue on emerging risks and technological trends. The Israel Innovation Authority (IIA) also plays a governance role by funding AI research and development, often attaching ethical and regulatory compliance conditions to its grants, thereby influencing the behavior of early-stage startups.
Enforcement & penalties
Because Israel lacks a single 'AI Act,' there are no AI-specific administrative fines. Instead, enforcement relies on the existing statutory powers of sectoral regulators and the Privacy Protection Authority. The most significant shift in enforcement occurred with the 2024 amendment to the Protection of Privacy Law. This legislation drastically increased the PPA’s ability to impose administrative fines, which can now reach millions of New Israeli Shekels (NIS) for severe violations involving large-scale data processing or sensitive personal information. These fines serve as a primary deterrent for AI developers and operators who fail to comply with transparency or data minimization requirements. Beyond financial penalties, regulators possess various administrative sanctions. Sectoral bodies can revoke licenses, issue 'cease and desist' orders, or impose specific conditions on the deployment of AI systems. For example, the Bank of Israel can prohibit the use of an automated credit-scoring model if it is found to be discriminatory or lacks sufficient explainability. Furthermore, the Israeli legal system allows for civil litigation; individuals harmed by biased or faulty AI systems can seek redress through tort law. The Ministry of Justice has signaled that it will continue to monitor whether current liability frameworks are sufficient, or if new legislation is needed to clarify the responsibility between AI developers and third-party vendors. Enforcement is also increasingly proactive; the PPA and sectoral regulators have begun conducting 'compliance audits' of high-risk AI systems, requiring companies to demonstrate that they have conducted impact assessments and implemented necessary safeguards. This shift from reactive to proactive enforcement is a key feature of the 2025-2026 regulatory landscape.
Data protection
The Protection of Privacy Law (PPL) of 1981, supplemented by the Data Security Regulations of 2017, forms the backbone of AI regulation in Israel. The law is interpreted broadly to cover the unique risks of AI, such as automated profiling and the secondary use of data. In 2022, the Privacy Protection Authority (PPA) issued specific guidance clarifying that the statutory 'duty of notification' (Section 11 of the PPL) requires controllers to inform individuals when their data is being used in automated decision-making systems. This includes explaining the logic of the system and the potential consequences of the decision, effectively creating an 'informed consent' standard for AI-driven processing. Israel maintains 'adequacy' status with the European Union, meaning its data protection standards are considered essentially equivalent to the GDPR. This status is vital for Israel’s tech economy and necessitates that the PPA closely aligns its AI-related enforcement with European trends. The 2024 legislative amendments further modernized the framework by streamlining the database registration process while simultaneously strengthening the PPA’s investigative and sanctioning powers. AI operators in Israel are expected to conduct Privacy Impact Assessments (PIAs) and implement 'Privacy by Design' principles, particularly when deploying systems that process sensitive categories of data or affect vulnerable populations. The PPA has also emphasized the importance of data minimization in AI training, encouraging the use of synthetic data and anonymization techniques to reduce privacy risks. As AI systems increasingly rely on biometric and behavioral data, the PPA is expected to issue further specific guidelines on the processing of these sensitive data categories in the context of algorithmic surveillance and identification.
Sector-specific rules
The financial sector is currently the most regulated area for AI in Israel. Following an interagency task force report in late 2024, the Bank of Israel and other financial regulators have moved toward a formal framework for AI in credit decisioning, insurance underwriting, and investment advice. These rules emphasize 'graded explainability,' where the level of explanation required for an automated decision is proportional to its impact on the consumer. For instance, a denial of credit requires a much more detailed explanation than a personalized marketing offer. The framework also mandates human-in-the-loop oversight for material financial decisions to prevent systemic risks and ensure accountability. In the healthcare sector, the Ministry of Health has established guidelines for AI-based medical devices and clinical decision-support systems. These rules focus on clinical validation, safety, and the prevention of algorithmic bias in diagnostic tools. Similarly, the transportation sector is governed by specific regulations for autonomous vehicle testing, which require rigorous safety logging and human-operator availability. Across all sectors, the government encourages the use of 'soft' regulatory tools, such as the Ministry of Justice’s 2022 opinion on copyright, which provides a legal pathway for AI companies to use copyrighted data for training purposes, provided they follow fair-use principles and avoid competing directly with the original creators' markets. This sectoral approach allows for highly tailored rules; for example, AI in employment is subject to specific labor law interpretations regarding discrimination in hiring algorithms, while AI in law enforcement is subject to stricter constitutional scrutiny regarding due process and the right to a fair trial.
International alignment
Israel’s AI policy is heavily influenced by international standards, particularly the OECD Recommendations on Artificial Intelligence. As a member of the OECD, Israel has committed to promoting AI that is innovative, trustworthy, and respects human rights. The 2023 'Responsible Innovation' policy explicitly cites the OECD principles as its foundation. This alignment ensures that Israeli companies can operate seamlessly in global markets and that the domestic regulatory environment remains familiar to international investors. Israel also participates in various international forums, such as the Global Partnership on AI (GPAI), to contribute to the development of global governance norms. Regarding the European Union, Israel closely monitors the implementation of the EU AI Act. While Israel has not adopted a similar horizontal law, its sectoral regulators often look to the EU’s technical standards and risk categories as a benchmark for their own directives. This 'de facto' alignment is driven by the need to maintain EU adequacy and to ensure that Israeli AI products are 'export-ready' for the European market. By maintaining a flexible but internationally-aligned framework, Israel seeks to balance its unique security and economic needs with the global movement toward standardized AI governance. This strategy also includes active participation in international standardization bodies like ISO and IEC, where Israeli experts contribute to the development of technical standards for AI safety, robustness, and transparency. The goal is to ensure that 'Made in Israel' AI is synonymous with 'Trustworthy AI' on the global stage.
What's next
The next phase of Israel’s AI regulation involves the formalization of the AI Policy Coordination Center within the Ministry of Innovation, Science and Technology. This center is expected to release a 'Risk Management Toolbox' for sectoral regulators, providing standardized templates for impact assessments and transparency reports. There is also ongoing discussion within the Ministry of Justice regarding a potential 'Framework Law' for AI. Such a law would not replace sectoral rules but would provide a statutory basis for cross-cutting issues like algorithmic discrimination, liability for autonomous systems, and the legal status of AI-generated content. Furthermore, the public consultation on the 2024 financial sector report is expected to result in binding directives from the Bank of Israel by late 2025 or early 2026. These directives will likely serve as a blueprint for other sectors, such as employment and housing, where AI-driven discrimination is a growing concern. The government is also expected to expand its investment in 'Public-Sector AI,' implementing new guidelines for the ethical use of AI in government services and administrative decision-making. As the National AI Program enters its final authorized year in 2026, a new multi-year strategy is anticipated, which will likely focus on generative AI and the security implications of large language models. This future strategy will also likely address the environmental impact of AI, promoting 'Green AI' initiatives to reduce the carbon footprint of large-scale data centers. Additionally, the government is exploring the creation of a 'National AI Ethics Committee' to provide ongoing guidance on the societal implications of emerging AI technologies, ensuring that the 'Responsible Innovation' approach remains relevant in an era of rapid technological change.
policy · Effective Oct 27, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2022
guideline · Effective Jan 1, 2022
guideline · Effective Jan 1, 2022
regulation · Effective Jan 1, 2021
regulation · Effective n/a
Sources:
policy · Effective n/a
code_of_ethics · Effective Jan 1, 2022
policy · Effective Jan 1, 2022
Sources:
code_of_ethics · Effective Jan 1, 2023
central_coordinator
Leads national AI policy, strategy coordination, and international representation.
data_protection
Oversees data protection, privacy compliance, and algorithmic transparency.
central_coordinator
Provides legal counsel, legislative drafting, and interpretation of AI liability.
enforcement
Regulates the banking and financial sector, including AI in credit and underwriting.
Jan 15, 2026 · international_agreement
Israel and US sign joint statement on AI
Open source →Dec 10, 2025 · news
US introduces Pax Silicia Initiative (with coalition of other countries)
Open source →Nov 29, 2025 · guideline_issued
UK and Israel launch new AI cooperation framework with Abraham Accords partners
Open source →Oct 18, 2025 · news
Israel appoints new AI director
Open source →Jul 16, 2025 · news
Israel publishes call for implementation of AI in government
Open source →Jul 15, 2025 · news
Israel and US to forge $200m tech hub for AI and quantum science development
Open source →Jul 14, 2025 · news
Israel launches NIS 1 million AI regulatory sandbox
Open source →May 26, 2025 · news
Israel Health Ministry consults on need for regulatory sandbox for testing AI technologies in healthcare
Open source →Apr 27, 2025 · news
Privacy Protection Authority releases guidance on AI and privacy
Open source →Nov 5, 2024 · news
Interim report on AI use in the financial sector
Open source →Oct 27, 2024 · news
Global data protection authorities issue statement on data scraping, covering AI
Open source →Sep 22, 2024 · law_amended
Israel establishes national expert forum to guide AI policy and regulation
Open source →Sep 4, 2024 · news
Israel signs Council of Europe's global treaty on AI
Open source →