Hong Kong will appoint a dedicated artificial intelligence regulator and could rewrite its laws to go after deepfake scams, Chief Executive John Lee announced in his annual Policy Address to the Legislative Council on 16 September 2026.
According to Hong Kong Free Press’s coverage of the address, the government will create a new post — Commissioner for AI — under the Digital Policy Office. The role is described as a high-level civil service position whose job is to help bureaus combat the use of AI in criminal activities. On the deepfake front, Lee said the Law Reform Commission’s cybercrime subcommittee will seek public views on how to tackle deepfake scams, and the government will consider drawing up further legislation depending on what that consultation finds.
Nothing in the announcement names a start date for the commissioner, and the deepfake work is framed as a study first and a bill later. But the direction is clear: Hong Kong is moving from warning about AI misuse to building an enforcement structure for it.
A first for Hong Kong and China
No dedicated AI regulator post currently exists in Hong Kong or on the Chinese mainland, which makes this the first appointment of its kind in Greater China — at least as reported so far. It puts Hong Kong ahead of its own neighbours on institutional design, if not yet on enforceable rules. The city’s Privacy Commissioner for Personal Data has been warning since March 2026 that deepfakes are increasingly used in scams globally, including in Hong Kong, and the Policy Address explicitly ties the new commissioner’s crime-fighting brief to that trend.
The model Hong Kong is reaching for will be familiar to anyone tracking global AI governance. Singapore’s leaders made the same comparison this week, with Senior Minister Josephine Teo suggesting advanced AI may eventually need aviation-style safety regulation to earn public trust — a sector-specific regulator rather than a single omnibus law. Our earlier coverage of the Sydney Dialogue documented the same pattern across the Indo-Pacific: jurisdictions that sat out the first wave of AI rule-making are now building the institutions for the second one. Hong Kong Free Press’s companion coverage details the same-day announcement of an “AI City Brain” task force led by the Chief Secretary, an urban-management AI drawing on CCTV, transport and emergency-monitoring data — with Lee publicly promising it will not tap personal data.
Deepfakes: the scam problem comes first
The Law Reform Commission consultation targets deepfake scams — the synthetic-video confidence tricks that have already cost companies in the region real money. The most famous local case remains the 2024 Arup deepfake video-conference fraud, in which a Hong Kong finance employee transferred roughly HK$200 million (about NZ$43 million) to scammers using an AI-generated video call of the company’s chief financial officer and other colleagues.
That episode predated any dedicated deepfake statute in Hong Kong. The proposed legislation, two years on, would close part of that gap — though the Policy Address language stops short of promising a bill, saying only that further legislation “will be considered” after public consultation.
Elsewhere the enforcement gap is being closed the hard way. In New York, the Manhattan District Attorney’s Office seized twelve celebrity deepfake websites on 14 September in what WIRED describes as the largest takedown of explicit deepfake sites to date, involving around 1,200 mostly female victims. And Minnesota became the first US state to ban AI nudification apps outright, a reminder that sub-national governments are no longer waiting for national frameworks. The European Union’s AI Office has been forced to defend its own enforcement capability after a hacking spree tested whether its AI Act machinery works in practice. Hong Kong’s proposal sits in that widening lane: targeted, enforcement-focused rules aimed at the uses of AI that are already costing people money and reputations.
The other half of the address: AI adoption
The regulatory measures are only part of the story. Lee used the same address to push AI adoption across government-backed industries — the Tourism Board will put AI-generated travel recommendations on its website, the public broadcaster RTHK will use AI in production, and the existing “AI for All” initiative will host more than 200 training activities to promote responsible AI use. The government also plans an “AI City Brain” for urban management, following the model Alibaba pioneered in Hangzhou a decade ago and which has since spread through mainland Chinese cities.
That twin framing — build the industry, regulate the harms — mirrors how jurisdictions across Asia are now handling AI. Singapore pairs its safety-case work with aggressive adoption incentives. Australia’s government is weighing copyright changes that would give AI companies default access to published content in exchange for high-level deals with rights-holder groups — a fight our Sydney Dialogue coverage placed at the centre of the country’s AI strategy, and one that has divided its creative sector. Hong Kong is choosing a narrower path: appoint a regulator for the harms, promote the technology everywhere else.
What happens next
The Law Reform Commission’s public consultation on deepfake scams is the concrete next step; anyone wanting to shape the eventual rules can respond once the consultation opens. The Commissioner for AI appointment itself has no announced timeline, and it is worth remembering that Policy Addresses are declarations of intent — the actual legislation, the actual appointee, and the actual powers all remain to be seen. What changed this week is that Hong Kong now has a named institutional owner for AI harms, which is more than most of the region had on Monday.
FAQ
What is Hong Kong’s Commissioner for AI? A new high-level civil service post announced in the 2026 Policy Address on 16 September, sitting under the Digital Policy Office. Its stated role is to assist government bureaus in combating the use of AI in criminal activities. No appointee or start date has been announced yet.
Is Hong Kong banning deepfakes? Not yet. The government will consider further legislation after the Law Reform Commission’s cybercrime subcommittee consults the public on tackling deepfake scams. Any actual ban or offence would come from legislation that does not yet exist.
Has Hong Kong dealt with deepfake crime before? The most cited case is the 2024 Arup video-call fraud, in which an employee transferred about HK$200 million after a video conference in which the chief financial officer and other staff were AI-generated fakes. The city’s privacy watchdog has warned since March 2026 that deepfakes are increasingly used in scams globally, including in Hong Kong.
How does Hong Kong’s move compare with other jurisdictions? It is the first dedicated AI regulator post announced in Hong Kong or China. Singapore’s government has discussed aviation-style safety regulation for advanced AI, New York has begun seizing deepfake websites under existing criminal law, and the EU runs a central AI Office under its AI Act — each jurisdiction reaching for a different mix of dedicated regulator and existing law.
— CJ Murden, editor of Singularity.Kiwi. Former digital technologies teacher, author of AI-focused books. Writing with a New Zealand focus.