AI regulation in Israel is evolving rapidly, moving from voluntary guidelines toward a more structured, risk-based framework that affects technology companies, startups, and multinational operators alike. Israel has not yet enacted a single comprehensive AI statute, but a dense web of existing laws, sector-specific directives, and government policy documents already governs how AI systems may be developed, deployed, and audited in the country. This guide explains the current regulatory landscape, the key authorities involved, recent policy developments, and the practical compliance steps that businesses operating in Israel should take now.
The current state of ai regulation israel: no single AI act, but real obligations
Israel';s approach to AI regulation is deliberately non-prescriptive at the statutory level. Rather than passing a dedicated AI Act equivalent to the European Union';s framework, the Israeli government has chosen to apply existing legislation to AI use cases while issuing sector-specific guidance and voluntary standards. This does not mean the environment is permissive - it means that compliance requires mapping AI activities against multiple overlapping legal instruments.
The primary legislative instruments that apply to AI systems in Israel include:
- The Privacy Protection Law (5741-1981) and its regulations, which govern automated data processing and profiling.
- The Prohibition on Discrimination in Products, Services and Entry into Places of Entertainment and Public Places Law (5761-2000), which applies to algorithmic decision-making that affects protected groups.
- The Consumer Protection Law (5741-1981), which the Consumer Protection and Fair Trade Authority has begun applying to AI-generated content and automated commercial recommendations.
- Sector-specific directives from the Bank of Israel, the Capital Market Authority, and the Ministry of Health, each of which has issued guidance on AI use within its regulated domain.
In practice, a company deploying an AI-based credit scoring tool must satisfy both the Bank of Israel';s model risk management circulars and the Privacy Protection Authority';s requirements on automated decision-making. These obligations exist today, regardless of whether a dedicated AI law is in force.
The Israeli government';s AI policy framework and the innovation authority';s role
The Israeli government has published a National AI Policy that sets out guiding principles for responsible AI development. The policy, coordinated through the Prime Minister';s Office and the Israel Innovation Authority, emphasises Israel';s ambition to remain a global AI hub while managing systemic risks. The framework is explicitly innovation-friendly: it prioritises regulatory sandboxes, voluntary adoption of standards, and international interoperability over prescriptive rules.
The Israel Innovation Authority plays a central role in shaping the practical environment for AI businesses. It funds AI research and development programmes, operates regulatory sandbox mechanisms that allow companies to test AI products under relaxed conditions, and coordinates with international bodies including the OECD on AI governance standards. Companies accepted into sandbox programmes receive temporary exemptions from certain regulatory requirements in exchange for sharing data and insights with regulators.
The National Cyber Directorate has also issued guidance on AI security, focusing on adversarial attacks, model poisoning, and supply chain risks in AI systems. For companies operating critical infrastructure or handling sensitive government data, compliance with these cybersecurity directives is mandatory rather than advisory.
A non-obvious requirement is that companies participating in government procurement must now demonstrate alignment with the government';s responsible AI principles as part of tender evaluation criteria. This applies even where the underlying AI system is not the primary subject of the procurement contract.
Sector-specific AI regulation: finance, health, and critical infrastructure
The most developed AI regulatory requirements in Israel exist at the sector level. Three sectors - financial services, healthcare, and critical infrastructure - have received the most detailed regulatory attention.
Financial services. The Bank of Israel has issued supervisory guidance requiring banks and licensed financial institutions to apply model risk management frameworks to all AI and machine learning models used in credit decisions, fraud detection, and customer segmentation. The guidance draws on international standards, including the Basel Committee';s principles on model risk. Institutions must document model development, validate models independently, and maintain audit trails. The Capital Market Authority has issued parallel requirements for insurance companies and pension fund managers using algorithmic tools.
Healthcare. The Ministry of Health regulates AI-based medical devices through the Medical Devices Law and its implementing regulations, which align with the EU';s Medical Device Regulation classification approach. AI software that performs diagnostic or therapeutic functions is classified as a medical device and must receive Ministry of Health approval before deployment. The approval process involves clinical evidence review and, for higher-risk devices, a conformity assessment by an approved body. In practice, this process takes several months to over a year depending on the risk class of the device.
Critical infrastructure. Operators of critical infrastructure - including energy, water, telecommunications, and transportation - are subject to cybersecurity obligations under the Cyber Defence Regulations that explicitly address AI-driven control systems. The National Cyber Directorate may require operators to conduct AI-specific risk assessments and to notify the Directorate of significant AI-related incidents.
A common mistake made by foreign companies entering Israel is assuming that CE marking or FDA clearance for an AI medical device automatically satisfies Israeli requirements. Israel has its own approval pathway, and while it may accept foreign conformity assessments as supporting evidence, a separate Israeli registration is required.
Privacy, data protection, and automated decision-making under Israeli law
The Privacy Protection Authority (PPA) is the primary regulator for data-related aspects of AI in Israel. The PPA has published position papers and enforcement guidance that directly address AI and automated decision-making, even in the absence of dedicated AI legislation.
Under the Privacy Protection Law and the Privacy Protection Regulations (Data Security) of 5777-2017, any organisation that processes personal data using automated systems must implement appropriate security measures, maintain a database registry where required, and obtain valid consent or establish another lawful basis for processing. The PPA has clarified that profiling, scoring, and automated decisions that produce legal or similarly significant effects on individuals require heightened transparency and, in some cases, a right to human review.
The PPA has signalled its intention to align Israeli data protection standards more closely with the GDPR, and draft amendments to the Privacy Protection Law have been circulating. These proposed amendments would introduce explicit provisions on automated decision-making, data portability, and stronger enforcement powers for the PPA, including the ability to impose substantial administrative fines. Companies that have already aligned their AI data practices with GDPR requirements will find the transition relatively manageable, but those relying on older Israeli compliance frameworks should audit their AI data pipelines now.
In practice, founders should consider that the PPA has become increasingly active in investigating AI-related complaints. Enforcement actions have targeted companies using AI for employee monitoring, customer profiling, and biometric data processing without adequate legal basis or transparency.
If your organisation is deploying AI systems that process personal data of Israeli residents, we recommend a structured legal review of your data flows and automated decision logic. Contact info@vlolawfirm.com - we can help structure the setup correctly the first time.
Recent developments and the path toward a more structured AI framework
Several significant developments have shaped the AI regulatory environment in Israel in recent periods.
The government has published a draft framework for high-risk AI systems that mirrors, in broad terms, the risk-based tiering approach of the EU AI Act. Under this draft, AI systems used in employment decisions, access to essential services, law enforcement, and critical infrastructure would face enhanced transparency, documentation, and human oversight requirements. The draft has not yet been enacted as binding law, but regulators in the relevant sectors are already applying its principles informally.
Israel has also signed cooperation agreements with the European Union on digital and technology matters, which include commitments to align AI governance approaches over time. For companies operating in both markets, this convergence is practically significant: building compliance systems that satisfy EU AI Act requirements will increasingly satisfy Israeli expectations as well, though the two frameworks are not yet identical.
The Israeli Standards Institute (SII) has adopted several international AI standards, including ISO/IEC 42001 on AI management systems. While adoption of these standards is currently voluntary, regulators in financial services and healthcare have begun referencing them in supervisory guidance. Companies that implement ISO/IEC 42001-aligned AI governance programmes are better positioned in regulatory examinations and procurement evaluations.
Many underestimate the speed at which informal regulatory expectations can harden into enforceable requirements in Israel. Sector regulators have a history of issuing guidance that is treated as binding in practice, even before formal rulemaking is complete. Companies that wait for a final AI statute before building compliance programmes risk being caught unprepared.
Practical compliance steps for businesses operating AI systems in Israel
Building a compliant AI operation in Israel requires action across several dimensions simultaneously. The absence of a single AI statute does not simplify compliance - it requires mapping obligations across multiple regulators and legal instruments.
The core compliance steps for most AI-deploying businesses include:
- Conducting an AI inventory that identifies all AI systems in use, their risk level, the data they process, and the decisions they influence.
- Mapping each system against applicable sector regulations, the Privacy Protection Law, and the government';s responsible AI principles.
- Implementing model documentation and audit trail practices that satisfy both the PPA';s data security requirements and any sector-specific model risk management guidance.
- Establishing a transparency mechanism for individuals affected by automated decisions, including a process for human review where required.
- Registering databases with the PPA where the Privacy Protection Law requires it, and reviewing whether existing registrations cover AI-driven processing activities.
For companies in regulated sectors, additional steps apply. Financial institutions must integrate AI model risk management into their existing model governance frameworks and report material model changes to the Bank of Israel. Healthcare companies must initiate the Ministry of Health device registration process early, as timelines are substantial and the process requires clinical documentation that takes time to prepare.
A practical scenario: a European fintech company expanding into Israel and deploying an AI-based lending decision engine must satisfy Bank of Israel model risk guidance, register its data processing with the PPA, comply with the anti-discrimination law in its credit decisions, and align with the government';s responsible AI principles for any government-facing business. Each of these obligations has a different responsible authority and a different compliance timeline.
A second scenario: an Israeli healthtech startup developing an AI diagnostic tool for export must navigate Ministry of Health classification and approval for the Israeli market while simultaneously managing EU AI Act conformity assessment requirements for European distribution. The two processes have overlapping but not identical documentation requirements, and managing them in parallel requires careful project planning.
To discuss how these obligations apply to your specific AI deployment, contact info@vlolawfirm.com - we can assist with documents and filings across all relevant regulatory streams.
FAQ
What are the most significant legal risks for companies deploying AI in Israel today?
The most immediate risks arise from the Privacy Protection Law and sector-specific regulatory guidance rather than from a dedicated AI statute. Companies that process personal data through AI systems without adequate legal basis, transparency, or security measures face enforcement action by the Privacy Protection Authority, which has become more active in recent periods. In regulated sectors, failure to comply with model risk management requirements from the Bank of Israel or device registration requirements from the Ministry of Health can result in supervisory sanctions, including restrictions on business activities. Companies should also be aware that algorithmic decisions affecting protected groups may trigger liability under anti-discrimination legislation, which is enforced through civil litigation as well as regulatory action. Building a documented compliance programme now reduces exposure significantly.
How long does it take to achieve AI compliance in Israel, and what does it cost?
The timeline and cost depend heavily on the sector and the complexity of the AI systems involved. For a technology company outside a heavily regulated sector, a structured compliance review and implementation programme typically takes between two and four months and involves professional fees in the low to mid thousands of EUR range, depending on the scope of the AI inventory and the number of systems requiring remediation. For a financial institution or healthcare company, the timeline is longer - model risk management implementation or Ministry of Health device registration can each take six months to over a year. Costs in regulated sectors are correspondingly higher, particularly where external validation, clinical evidence preparation, or regulatory submissions are required. Companies that invest in ISO/IEC 42001-aligned governance frameworks early tend to reduce the marginal cost of future compliance as the regulatory framework develops.
Should Israeli AI companies build for EU AI Act compliance even though Israel has not adopted it?
For companies that export products or services to the European Union, or that process data of EU residents, EU AI Act compliance is already a direct legal obligation rather than a strategic choice. For companies focused exclusively on the Israeli market, the EU AI Act is not directly binding, but building toward its standards is strategically sensible for two reasons. First, Israeli regulators are explicitly converging their expectations toward the EU framework, and companies that already meet EU standards will face fewer adjustments as Israeli rules develop. Second, many Israeli AI companies have international growth ambitions, and building compliance infrastructure that satisfies EU requirements from the outset avoids costly retrofitting later. The practical approach is to use the EU AI Act';s risk classification and documentation requirements as a baseline and then layer Israeli sector-specific obligations on top.
Conclusion
Israel';s AI regulatory environment is active, multi-layered, and moving toward greater structure. Existing laws already impose real obligations on companies deploying AI systems, and sector regulators are enforcing those obligations with increasing vigour. The direction of travel is toward a more formalised, risk-based framework aligned with international standards. Companies that build robust AI governance programmes now will be better positioned as the framework matures.
VLO Law Firms advises international clients on AI regulation in Israel. We can assist with regulatory mapping, Privacy Protection Authority compliance, sector-specific AI governance frameworks, and Ministry of Health device registration. To request a consultation, contact: info@vlolawfirm.com