How Do Philippine Laws Regulate AI Development?
Introduction
Artificial intelligence development in the Philippines increasingly depends on large datasets, software code, creative works, personal information, and automated decision-making systems. For local technology startups, the principal legal concern is whether data and content may be collected, copied, processed, used for model training, or incorporated into an AI product.
Philippine law does not presently provide a single statute dedicated exclusively to artificial intelligence. Instead, AI development is governed by existing laws on copyright, data privacy, cybersecurity, intellectual property, and, in some cases, sector-specific regulation. The principal statutes affecting AI training and deployment are the Intellectual Property Code of the Philippines and the Data Privacy Act of 2012, supplemented by recent guidance from the National Privacy Commission and the Supreme Court.
What Philippine Laws Apply to AI Systems?
AI systems may process several legally distinct categories of material. These include personal information, sensitive personal information, copyrighted text and images, computer programs, databases, confidential business information, and user-generated content.
The applicable legal analysis depends on the nature of the material, the purpose of the processing, the identity of the person controlling the data, and the manner in which the AI system is trained or deployed.
| AI activity | Potential legal concern |
|---|---|
| Collecting personal information for model training | Lawful basis, transparency, data-subject rights, and security obligations under R.A. No. 10173 |
| Copying books, photographs, music, software, or other creative works | Copyright ownership, reproduction, communication to the public, and possible exceptions under R.A. No. 8293 |
| Using a third-party AI platform | Controller-processor allocation, outsourcing, confidentiality, and accountability |
| Deploying automated recommendations or decisions | Transparency, human review, fairness, contestability, and possible sector-specific duties |
How Does the Data Privacy Act Govern AI Training?
The Data Privacy Act of 2012 applies when an AI system processes personal information or sensitive personal information. This includes processing undertaken during the development, training, testing, and deployment of the system, as confirmed by NPC Advisory No. 2024-04 (2024).
The law is technology-neutral. A startup cannot avoid the Data Privacy Act merely because personal information is processed through machine learning, a large language model, a recommendation engine, or another automated system.
Who Is Responsible for AI Data Processing?
A startup is generally a personal information controller when it determines the purposes and means of processing personal information for its AI product. A service provider that processes personal information on the startup’s instructions may act as a personal information processor.
The distinction depends on actual control and functions, not merely on the wording of a contract. A controller remains accountable for processing undertaken by its processor, including outsourced training, hosting, annotation, analytics, or model-evaluation activities.
Under NPC Advisory No. 2024-04, a personal information controller remains accountable for the actions of its personal information processor when AI-related processing is subcontracted or outsourced. Accountability also extends to the outcomes and consequences of processing involving personal data.
What Lawful Basis Is Required for AI Training?
Before processing personal information for AI development, the controller must determine the appropriate lawful basis under Sections 12 and 13 of R.A. No. 10173. The lawful basis must be established before the relevant processing occurs, including the collection, preparation, training, testing, and deployment stages.
Consent is not the only possible lawful basis, but it must not be treated as automatically unnecessary merely because the data was obtained from the internet or another publicly accessible source. Public availability does not remove the protection given by the Data Privacy Act. The NPC expressly states that publicly available personal data remains protected and must still be processed under an appropriate lawful basis and the general privacy principles.
In addition, Section 12 provides that processing must not be otherwise prohibited by law. Thus, a claimed privacy-law basis cannot automatically authorize the use or disclosure of material protected by another law, including copyright. This limitation was recognized in NPC 24-006, HCN v. DBO (2025).
What Transparency Duties Apply to AI Systems?
When personal data is used to develop or deploy an AI system, the controller must provide information that is accessible, concrete, understandable, and presented in plain language. The explanation should address, as applicable:
- the nature, purpose, and extent of the processing;
- the factors and inputs considered by the AI system;
- the risks associated with the processing;
- the expected outputs of the system;
- the possible effects on data subjects; and
- available dispute or review mechanisms.
A generic statement that data may be used to “improve services” may be inadequate where the actual purpose is to train a model, create user profiles, generate predictions, or make recommendations affecting individuals. The privacy notice should identify the relevant purposes with sufficient clarity.
Can Data Subjects Object to AI Training?
Yes. Controllers should maintain effective mechanisms, or reasonable alternative measures, for the exercise of data-subject rights before, during, and after AI development and deployment.
NPC Advisory No. 2024-04 specifically identifies the rights to object, rectification, and erasure or blocking. The fact that personal data has already been incorporated into a dataset does not automatically make a request unreasonable. If a request cannot be fully implemented, the controller should explain why and adopt measures that achieve the intended effect as far as possible.
For example, a startup may need procedures for identifying records incorporated into training datasets, restricting future use, correcting source data, deleting or isolating records, retraining a model where appropriate, or applying technical controls to prevent continued use.
How Does Copyright Law Affect AI Training?
The Intellectual Property Code of the Philippines, R.A. No. 8293, protects original intellectual creations in the literary and artistic domain from the moment of creation. The statutory protection covers legally protected works and the rights granted by the statute; it does not extend to every idea, fact, procedure, system, method of operation, concept, principle, or discovery.
The Supreme Court has emphasized that copyright is a statutory right whose scope is defined by law. In Philippine Home Cable Holdings, Inc. v. Filipino Society of Composers, Authors & Publishers, Inc., G.R. No. 188933, 2023, the Court discussed the statutory nature of copyright and the protection afforded to original literary and artistic works.
For AI developers, the principal issue is whether the acts involved in collecting and preparing training material constitute reproduction, adaptation, distribution, communication to the public, or another act reserved to the copyright owner. The answer may depend on the work, the method of copying, the license, the purpose, the amount used, and whether a statutory exception applies.
Are Facts and Ideas Protected by Copyright?
Facts, ideas, procedures, systems, methods of operation, concepts, principles, and discoveries are generally not protected as such. However, the particular expression of those matters may be protected.
For example, a news event may not itself be copyrightable, but a broadcaster’s recorded footage, script, graphics, or other expressive presentation may be protected. In ABS-CBN Corporation v. Gozon, et al., G.R. No. 195956, 2015, the Supreme Court distinguished news events from the protected expression of news.
This distinction matters in model training. A dataset containing factual information is not necessarily equivalent to a dataset containing copyrighted articles, photographs, illustrations, recordings, software code, or other expressive works. Developers should identify the protected expression and not assume that factual content makes the entire source lawful to copy.
Does AI Training Automatically Qualify as Fair Use?
No automatic safe harbor for AI training should be assumed. The legality of copying copyrighted material for training must be evaluated under the Intellectual Property Code, any applicable license, and the specific circumstances of the use.
Relevant considerations may include the purpose and character of the use, the nature of the copyrighted work, the amount and substantiality of the portion used, and the effect of the use on the potential market. Commercial exploitation, systematic copying, use of highly creative works, and outputs that substitute for the original may increase legal risk.
Conversely, the analysis may differ where the developer uses material under a clear license, uses public-domain works, relies on facts rather than protected expression, obtains permission from rights holders, or uses a limited and technically necessary portion for a permitted purpose. These factors are not automatic defenses and must be assessed against the actual implementation.
Can AI Outputs Infringe Copyright?
Yes, an AI output may create copyright risk even when the developer did not manually copy the work. Risk may arise when the output substantially reproduces protected expression, imitates a protected work in a way that implicates the owner’s rights, or is generated through a system designed to reproduce memorized training material.
The developer, platform operator, and user may have different levels of responsibility depending on their control, knowledge, contractual arrangements, and participation in the creation or distribution of the output. Corporate officers are not automatically criminally liable merely because an infringement occurred; active participation and the statutory requirements for liability must still be established.
What Governance Duties Apply to AI Used by the Judiciary?
The Supreme Court’s Proposed Governance Framework on the Use of Human-Centered Augmented Intelligence in the Judiciary, A.M. No. 25-11-28-SC (2026) is directed to the Judiciary, not generally to all private startups. It nevertheless illustrates the direction of Philippine institutional policy on responsible AI use.
The Framework requires AI use to remain human-centered and consistent with the Constitution, human rights, privacy, data protection, fairness, nondiscrimination, and social justice. It treats AI as a support or augmentation tool rather than a replacement for human judgment.
It further provides that human control must remain paramount. AI outputs must be reviewed and approved by human beings, and the user remains personally responsible for the output and its consequences. An AI tool cannot become the sole or determinative basis for an adjudicatory outcome.
Although this Framework does not automatically impose the same duties on every private startup, its principles are relevant when designing systems intended for government, courts, regulated industries, or decisions affecting rights and significant interests.
What Does the NPC Require for Automated Decisions?
Where AI processing significantly affects data subjects, startups should provide meaningful human intervention and a means to contest or review the result. A purely automated decision that materially affects a person presents greater privacy, fairness, explainability, and accountability risks than an internal tool used only for administrative assistance.
At a minimum, the organization should identify the decision being automated, the data and factors used, the consequences of the decision, the available review process, and the person or office responsible for resolving disputes.
What Records Should an AI Startup Maintain?
A responsible AI compliance file should contain, at a minimum:
- the sources and categories of training data;
- the legal basis and purpose for processing personal data;
- licenses, permissions, or other rights supporting the use of copyrighted material;
- contracts with annotators, cloud providers, model vendors, and other processors;
- privacy notices, data-subject request procedures, and security measures;
- testing results concerning accuracy, bias, privacy, and harmful outputs; and
- records of human review, incident response, and model changes.
Documentation is particularly important because the controller remains accountable for the processing and its consequences. A startup that cannot identify its data sources or explain its processing may face difficulty demonstrating compliance, responding to complaints, or defending its use of data.
Common Compliance Scenarios
Using Publicly Available Websites
Public accessibility does not by itself eliminate privacy or copyright obligations. Personal data remains protected under the Data Privacy Act, while articles, photographs, software, and other expressive material may remain protected by copyright.
Using Customer Data to Improve a Model
The startup should determine whether the original purpose and lawful basis cover model training. It should also assess whether the training use is compatible with the disclosed purpose, whether notice must be updated, and whether customers may object or request deletion.
Purchasing a Third-Party Dataset
Purchasing data does not transfer legal responsibility automatically. The startup should verify the seller’s authority, the source and quality of the data, applicable licenses, privacy representations, security controls, and procedures for responding to data-subject requests.
Deploying an AI Hiring Tool
A hiring system may process personal information and produce decisions with significant effects on applicants. The operator should provide transparency, test for discriminatory or inaccurate results, preserve human review, and maintain a meaningful process for correction and challenge.
Recommended Steps for Philippine Tech Startups
- Map the data. Identify personal information, sensitive personal information, copyrighted works, confidential information, software, and publicly sourced material.
- Classify the legal role. Determine whether the startup is acting as a personal information controller, processor, or both in different operations.
- Document the lawful basis. Record the basis under Sections 12 and 13 of R.A. No. 10173 before training or deployment.
- Review intellectual property rights. Confirm whether the data is licensed, public domain, factual, user-owned, or otherwise lawfully available for copying and processing.
- Build user rights into the system. Create procedures for objection, correction, erasure or blocking, access, review, and dispute resolution.
- Maintain human oversight. Do not allow high-impact outputs to operate without accountable human review.
- Monitor the model. Test for privacy leakage, bias, inaccurate outputs, memorization, security vulnerabilities, and harmful effects after deployment.
Conclusion
Philippine law currently regulates AI through existing legal duties rather than through one comprehensive AI statute. For local startups, the most immediate obligations arise from the Data Privacy Act when personal data is processed and from the Intellectual Property Code when copyrighted material is copied, transformed, distributed, communicated, or reflected in an AI system’s outputs.
The safest approach is to treat AI development as a documented legal process. Startups should identify the data used, establish a lawful basis, verify copyright permissions, protect data-subject rights, preserve human accountability, and maintain records showing how the system was trained and deployed.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

