Philippines Responsible AI Framework 2026: What DICT's JMC 003 Means for Your Business

For years, responsible AI in the Philippines was a matter of best intentions. Government agencies and private companies alike referenced global frameworks — the EU AI Act, the OECD AI Principles, the UNESCO Recommendation — and adapted what they could on their own terms. That era is ending.
On June 9, 2026, the Department of Information and Communications Technology (DICT) and the Civil Service Commission (CSC) jointly issued Memorandum Circular No. 003, Series of 2026 — the Philippines' first formal, principles-based framework for the ethical and responsible development, deployment, and use of artificial intelligence in the public sector. For government agencies, compliance is mandatory. For private sector companies that sell AI software, cloud platforms, or managed services to any government entity, the obligations extend to you as well.
What JMC 003 Actually Requires
JMC 003 is principles-based rather than prescriptive — it does not specify a single approved algorithm or mandate a fixed compliance checklist. Instead, it establishes a governance structure anchored in five core requirements that agencies (and their vendors) must demonstrate:
- Accountability — a named AI governance officer or committee with clear lines of responsibility for AI outcomes
- Data protection — AI systems must comply with the Data Privacy Act of 2012 and all NPC issuances, including Advisory No. 2026-01 on data scraping practices
- Transparency — affected individuals must be informed when AI is used in decisions that affect them
- Human oversight — high-stakes decisions (benefits, penalties, procurement) must include a human review layer; fully autonomous decisions in sensitive areas are not permitted
- Proportionality — AI systems must be fit for purpose; over-engineered or unnecessarily invasive solutions are discouraged
The circular was confirmed in force by Baker McKenzie's July 2026 analysis and aligns with the NICTDA's six ICT development agendas, which are themselves linked to the ITU Connect 2030 Agenda, the ASEAN Digital Masterplan 2025, and the UN SDGs.
Why the Private Sector Can't Ignore This
JMC 003 applies directly to government agencies — but agencies are expected to ensure that third-party providers supplying AI systems comply with the same standards. This is the provision that matters most to technology vendors.
If you are selling any of the following to a Philippine government agency, JMC 003 governance requirements now apply to your engagement:
- AI-assisted software (HR, finance, case management, document processing)
- Cloud platforms with embedded AI features (M365 Copilot, Google Workspace with Gemini, Azure AI services)
- Managed services that include AI-powered monitoring, analytics, or automation
- Custom AI models trained on government data
Procurement teams at agencies are beginning to include AI governance attestations in their RFP requirements. Companies that cannot demonstrate JMC 003 alignment risk being excluded from bids — regardless of price competitiveness.
Beyond procurement, the broader regulatory direction in the Philippines is toward greater accountability. The NPC, SEC, and BSP are each developing AI-specific guidance for their regulated sectors. JMC 003 is the first formal signal of where enforcement is heading.
The Philippines as a Regional AI Governance Leader
JMC 003 did not emerge in isolation. The DICT's issuance is timed deliberately with the Philippines' 2026 ASEAN Chairship and the country's hosting of the ASEAN AI Summit in September 2026 — an event that will bring together ASEAN heads, ministers, industry leaders, and development partners to advance responsible AI adoption among MSMEs.
The strategic context matters for businesses: the Philippines is positioning itself as a standard-setter, not a follower, in the region's AI governance conversation. AI adoption across ASEAN could contribute up to USD 1 trillion to the regional economy by 2030, representing 10 to 18 percent of projected GDP. With MSMEs comprising 97 percent of ASEAN enterprises, the Summit's Declaration is expected to drive AI governance requirements down to the small and medium business level over the next two to three years.
For IT vendors and cloud managed service providers, this trajectory means governance documentation that seems optional today will be a baseline expectation by 2028.
What Responsible AI Governance Looks Like in Practice
Principles-based frameworks are only useful if they translate into operational change. In practice, JMC 003 alignment for a technology vendor typically requires four things:
1. An AI inventory. Document every AI tool or model used in delivery of services to a government client — including embedded AI features in commercial software like Microsoft 365 Copilot or Google Workspace.
2. A data protection audit. Map where personal data flows through your AI systems, confirm lawful bases for processing, and verify that your data handling agreements with subprocessors are DPA-compliant. Cross-reference against your existing acceptable use policy for AI tools.
3. Transparency documentation. Prepare a plain-language description of how your AI systems make or assist in decisions — suitable for inclusion in procurement submissions and client-facing privacy notices.
4. An escalation path for AI decisions. Define which outputs from your AI systems require human review before acting. For high-stakes contexts (employee data, financial records, government benefits), no fully automated decision chain should be acceptable under JMC 003.
None of this requires rebuilding your systems. For most technology vendors, it requires documentation of what already exists — and a commitment to close any gaps before your next government engagement.
DICT's Own AI Roadmap: What It Signals
The government is not asking the private sector to do anything it is not doing itself. The DICT has announced plans to integrate AI agents across its eGovernment platforms — the national mobile superapp and PhilSys digital ID — and is partnering with Google Cloud to roll out Gemini Enterprise to more than 50,000 public officers.
At SONAI 2026 on January 30, Secretary Aguda articulated five priorities for DICT's AI agenda: building trust and good governance, strengthening digital foundations, delivering practical AI solutions for citizens, developing local talent and innovation, and promoting regional leadership. These are not aspirational statements — the Gemini rollout and JMC 003 are evidence that execution is already underway.
The government's digital economy target is to grow the ICT sector to 12 percent of GDP — a ₱354 billion boost. AI is central to that ambition. Vendors who engage with that agenda need to govern accordingly.
What to Do Now
Whether you are a cloud managed service provider, an IT reseller with professional services, or a SaaS vendor with Philippine government clients, the practical path forward is the same:
- Audit your AI footprint — list every tool, model, and AI-embedded feature in your delivery stack
- Update your privacy notices and data processing agreements to reflect AI use
- Draft an AI governance statement — one to two pages, covering accountability, oversight, transparency, and data protection alignment with the DPA and JMC 003
- Review government RFPs for AI governance language — and prepare a standard response
- Train client-facing staff on how to discuss AI governance in procurement contexts
How Technica Approaches AI Governance
Technica Solutions Inc. is a Microsoft and Google Cloud partner in the Philippines. When we design and deploy cloud environments — whether Azure, M365, or Google Workspace — we include AI governance advisory as part of every managed cloud engagement. That means helping clients inventory their AI tools, configure data access controls, set up audit logging, and document human oversight procedures — not as a compliance checkbox, but as infrastructure for sustainable AI use.
JMC 003 is the beginning of a regulatory arc that will deepen over the next three years. Companies that build governance foundations now will spend less time scrambling when the enforcement guidance arrives.
Related reading
- AI Regulation in the Philippines: What NPC and DICT Are Building
- How to Write an AI Acceptable Use Policy for Philippine Businesses
- NPC Advisory 2026-01: Data Scraping Rules and What They Mean for Your Business
- Azure Managed Services in the Philippines: What a Cloud Foundation Engagement Looks Like


