Technology is changing the facts lawyers work with. CyberCode.ph helps you find the legal questions.
A client wants to use AI to review documents. An employee uploads confidential records to a chatbot. A disputed message becomes evidence. A business asks who owns an AI-generated logo. These problems cross familiar subjects: privacy, contracts, intellectual property, criminal law, evidence and professional responsibility.
CyberCode.ph brings those subjects together through Philippine AI and technology law guides, topic hubs and practical resources. For practising lawyers, it offers a starting point for issue spotting and further research. For law students and Bar candidates, it offers a way to connect legal rules to digital fact patterns and organise a focused review.
Start with a question, follow the relevant pillar, and open the underlying authority. Use the AI law tracker when reviewing instrument status and the Bar review hub when planning study. These materials support legal research and study; the official authorities and examination instructions remain the reference points.
A practical route for lawyers and Bar candidates
For practising lawyers: start with the client’s activity, the people affected, the information involved and the outcome sought. Move from the relevant pillar to a specific guide, then check the primary authority and the evidence. Record unresolved questions before giving advice or approving a workflow.
For Bar candidates: use the Bar review hub to organise a topic session. Read the rule, identify its elements and exceptions, and apply it to a short factual problem. Cross-check coverage against Supreme Court Bar Matters for your examination year. This article does not represent that every technology topic is examinable.
For keeping research current: record the instrument number, issuing body, date, effectivity and later amendments or decisions. Distinguish a statute from an implementing rule, advisory, judgment, proposal or commentary. Check the page’s review date and its sources before reusing an answer. CyberCode’s editorial policy and corrections policy explain where to start if a source needs review.
Explore CyberCode’s legal and technology pillars
Choose the closest subject first, then follow the related pillar when the facts overlap.
1. AI and Emerging Technology
Start with the legal questions behind generative AI, automated decisions, deepfakes and business adoption. Use the AI law tracker to distinguish instruments and their status, then follow the business compliance collection when advising an organisation. Continue with Data Privacy.
2. Data Privacy
Review personal information, lawful processing, sensitive data, data subject rights and the responsibilities of controllers and processors. Connect the legal analysis to a worked privacy impact assessment and the evidence needed to approve or hold an AI project. Continue with Business Compliance.
3. Cybercrime
Explore digital wrongdoing, complaint routes and the elements that distinguish a criminal allegation from a privacy or contractual dispute. Useful for issue spotting, client intake and deciding what evidence to preserve before choosing a remedy. Continue with Technology Law.
4. Cybersecurity
Connect technical incidents to legal questions about prevention, access, organisational responsibility and response. Follow the practical guides on account compromise, data leakage and vendor security when translating legal duties into operating controls. Continue with Data Privacy.
5. Technology Law
Explore the legal treatment of digital transactions, technology services and electronic records. Use this pillar to connect contract analysis and evidence questions with the facts of how a system actually works. Continue with Cybercrime.
6. Business Compliance
Move from identifying a legal duty to assigning an owner, documenting a decision and keeping evidence. A useful companion for in-house counsel, advisers and teams implementing privacy, security and AI controls. Continue with the five-step AI collection.
7. Digital Transformation
Review the business and governance questions raised by adopting digital systems. Start here when a client is changing workflows, then use the privacy, technology law and security pillars to examine the legal consequences. Continue with Technology Law.
8. Intellectual Property
Find the route into copyright, ownership, licensing and other IP questions affecting technology. Separate rights in the material supplied to an AI system from rights in the output and from the vendor’s contractual promises. Continue with AI-Generated Works.
9. Trademark
Review brand protection, registration and enforcement questions. Use this pillar when AI generates a name, logo or marketing asset: a usable output still needs a separate review of conflicting brand rights. Continue with Intellectual Property.
10. AI-Generated Works
Focus on authorship, human contribution, copyright and the commercial use of AI-assisted material. Read alongside the broader IP pillar and the AI vendor contract guide to distinguish statutory rights from contractual permissions. Continue with Trademark.
Review companion: Bar Exam Reviewer brings cybercrime, data privacy and electronic evidence into a study route. For a wider reading list, explore all guides and research resources.
From legal review to a documented business AI decision
The business AI compliance collection connects five practical steps. Carry the same proposed use and decision record through the route:
- Assessment: define the use, data, affected decisions and responsible owner.
- Worked PIA: map data flows, assess privacy risks and identify missing evidence.
- Vendor evidence: test assurances against documentation and record unresolved gaps.
- Contracts: translate agreed controls into clauses and schedules.
- Staff rollout: communicate approved uses, train staff and establish the incident route.
A completed checklist is not an approval. Return unresolved issues to the responsible reviewer before moving from assessment into live use.
Philippine AI law FAQ: questions for practice and review
The answers below are starting points for research. Sources linked in this introduction were checked on 3 October 2026; this is not a claim that every linked guide or every Philippine AI-related instrument has been comprehensively revalidated.
1. What does “AI law in the Philippines” cover?
It is a research topic spanning several bodies of law. Start with what the system does: personal-data processing, content creation, a transaction or alleged wrongdoing. Then identify the applicable instrument and its scope. Use the Philippine AI law tracker to organise that research.
Authority: RA 10173, Data Privacy Act; Intellectual Property Code, RA 8293; Cybercrime Prevention Act, RA 10175.
2. How do I check whether an AI proposal is already law?
Find the official instrument, enactment or issuance details, effectivity provisions and later amendments. A bill number, policy announcement or news headline alone does not establish an enforceable statutory duty. Record the date of your check beside the proposition you intend to rely on. Start with the dated instrument tracker.
3. Who regulates AI in the Philippines?
Identify the issue before identifying the regulator. The NPC administers data privacy law; its AI advisory concerns systems processing personal data. That does not make it the authority for every AI-related copyright, criminal or professional-responsibility question. Start in the AI hub and follow the relevant pillar.
Authority: RA 10173, Data Privacy Act, section 7; NPC Advisory 2024-04, section 1.
4. Does the Data Privacy Act apply to AI training and testing?
The NPC’s AI advisory covers personal-data processing in development and deployment, including training and testing. Examine the information used at each stage, rather than looking only at the final output. Continue to AI and data privacy.
Authority: NPC Advisory 2024-04, section 1.
5. Is consent always needed before using personal data in AI?
Consent is one lawful basis for ordinary personal information, not the only one. The actual purpose and necessary processing must fit an applicable basis. Sensitive personal and privileged information require separate analysis under section 13. Review the Data Privacy pillar before choosing a basis.
Authority: RA 10173, Data Privacy Act, sections 11–13.
6. Can lawyers upload client documents into a public AI tool?
Do not treat access to an AI account as permission to disclose client material. Review professional duties, privilege, data protection and the service’s retention and reuse terms first. For initial testing, use fictional material. Follow the vendor evidence pack to document the review.
Authority: Supreme Court introduction to the CPRA; RA 10173, Data Privacy Act, sections 13–15.
7. When should an AI privacy impact assessment be done?
Assess privacy risks while designing the proposed use, before exposing people’s data to an untested workflow. Revisit the assessment when purposes, data, vendors or controls change. The worked AI PIA shows how to record risks, evidence gaps and a decision to hold a project.
Authority: NPC Advisory 2024-04, section 2, privacy by design and default.
8. Is removing names enough to anonymise an AI prompt?
Not necessarily. Context and combinations of details can still identify someone. Review whether a person can be identified from the remaining material and other available information. Use the worked PIA to examine the proposed data flow, rather than assuming a redacted file is anonymous.
Authority: RA 10173, Data Privacy Act, section 3(g).
9. What if AI makes a decision affecting a person?
Examine the consequences, data quality, transparency and meaningful human oversight. The DPA includes access to information about automated processes used as the sole basis of decisions significantly affecting a data subject. Continue to automated decisions and profiling.
Authority: RA 10173, Data Privacy Act, section 16(c)(6); NPC Advisory 2024-04, section 2.
10. Can an AI vendor store data outside the Philippines?
Overseas processing does not remove the controller’s accountability. Establish the destination, recipients, safeguards and contractual responsibilities before approving the arrangement. Review the vendor evidence matrix and follow it into the contract schedules.
Authority: DPA Implementing Rules and Regulations, sections 43–45 and 50.
11. Does a “no training” promise make a vendor safe to use?
It answers only one procurement question. Also request evidence about retention, backups, access, subprocessors, incidents and deletion. Record what is verified and what remains unresolved. The vendor decision record provides a practical structure; it is not a certification.
12. What should an AI vendor contract address?
Define permitted processing, confidentiality, reuse, security, assistance with rights and incidents, subcontractors and exit arrangements. Then address input rights, output permissions and the allocation of commercial risks. Adapt the sample AI contract clauses to the service and evidence collected.
Authority: DPA Implementing Rules and Regulations, sections 43–45. The samples also contain practical commercial drafting suggestions.
13. Who owns AI-generated text, images or code?
Separate authorship, protectable human contribution, third-party rights and contract terms. The IP Code defines an author as a natural person and protects original intellectual creations. A vendor’s output permission does not by itself resolve copyright protection or infringement. Start with AI-Generated Works.
Authority: Intellectual Property Code, RA 8293, sections 171.1, 172, 177–178.
14. Can publicly available material be used to train AI?
Public availability alone does not decide the legal question. Identify relevant copyright permissions or exceptions and, where people’s information is involved, the privacy analysis. Fair use requires a fact-specific assessment. Continue to AI training data and copyright and Data Privacy.
Authority: Intellectual Property Code, RA 8293, sections 177 and 185; NPC Advisory 2024-04, section 1.
15. Are deepfakes automatically criminal?
Analyse the conduct and the elements of the alleged offence. Synthetic media used for identity theft, forgery or fraud can raise cybercrime issues; other harms require their own legal analysis. Use the deepfake remedies guide alongside the Cybercrime pillar.
Authority: Cybercrime Prevention Act, RA 10175, section 4.
16. Are screenshots or AI-generated records automatically admissible?
No. Consider relevance, authenticity, integrity and the applicable procedural rules. Preserve originals and context; an AI summary should not replace the underlying record. Use the electronic evidence preservation guide to prepare, then assess admissibility for the particular proceeding.
Authority: Rules on Electronic Evidence (A.M. No. 01-7-01-SC, Supreme Court), especially Rules 3–5 and 11; check the rules applicable to the proceeding.
17. Can lawyers rely on AI-generated cases and citations?
Treat generated authorities as research leads. Open the actual judgment, verify the citation and holding, and check its later treatment before relying on it. This workflow supports the competence and diligence expected of counsel. Use Technology Law as a route to sources, not as a substitute for reading them.
Authority: Supreme Court introduction to the CPRA.
18. How should a firm introduce an AI usage policy?
Begin with approved tasks and tools, then explain input restrictions, human review and the reporting route. Train staff on realistic scenarios and record acknowledgment. The staff rollout pack supplies reusable materials; align them with the firm’s actual approval decisions.
19. What should happen after an accidental AI data disclosure?
Stop further exposure, report promptly through the organisation’s incident route and preserve relevant evidence securely. The responsible team must assess containment and any notification duties; not every incident meets the same notification threshold. Use the staff incident steps.
Authority: DPA Implementing Rules and Regulations, sections 38–42.
20. How should Bar candidates use AI and technology law materials?
Use the CyberCode Bar review hub for topic organisation and practice, then return to the official syllabus, prescribed coverage and cutoff for your examination. Practise identifying the issue, stating the applicable rule and applying it to facts. AI-generated answers need independent checking.
Authority: Supreme Court Bar Matters.
What’s the next step?
Choose one issue and turn your reading into a concrete result.
- Reviewing AI law? Open the AI and Emerging Technology hub, choose a question and verify the relevant instrument in the AI law tracker.
- Preparing for the Bar? Open the Bar review hub, select a topic within your official syllabus and write a short answer applying the rule to facts.
- Advising a business or law firm? Follow the five-step business AI collection and produce an assessment record showing the evidence, open issues and next reviewer.
- Handling a dispute or incident? Preserve the electronic evidence and use the Cybercrime and Data Privacy pillars to investigate the appropriate route.
Bookmark the pillar you use most. On your next visit, revisit the source and its status before carrying an earlier answer into a new matter. Start your Philippine AI and technology law review →
Sources rechecked as of: October 4, 2026

