Skip to content
Oversight Newsroom

Insight · AI governance · Israel

Insight: AI oversight — what binds an organization that uses AI

A company that uses AI does not need a new law to be accountable. It needs to know which existing duties already reach the tools, the vendors and the data.

What is AI oversight inside a company?

AI oversight is the set of decisions that stay with people while software does the work: which tools may touch company data, who reviews what they produce, and who answers when something goes wrong. It is a management question before it is a technical one.

In Israel there is no single statute titled AI governance for private companies. What binds an organization is a layered picture, and most of the layers are older than the tools.

The vendor layer: Regulation 15

A reading of the Privacy Protection Authority's guide to Regulation 15 after Amendment 13 is that the controller assesses the risk of an outside party, specifies the service and the systems involved, and regulates the relationship in a written agreement covering permissions, oversight and termination.

Two points from the Authority's FAQ matter for any Regulation 15 AI vendor. First, an external party is a wider category than a holder of the database: it can include anyone with actual access to the database or its systems in the course of the service. Second, a vendor that stores or processes data for the controller usually also becomes a holder, and the test is what the vendor does, not what the contract calls it.

In the cloud, the FAQ keeps legal responsibility for database security with the controller. Operational responsibility is split according to the service model. The practical result: signing with a large provider does not move the accountability.

What the regulator's AI documents are, and are not

The Authority's July 2026 recommendations on AI agents address personal use by individuals. They do not regulate business processing, and an organization should not cite them as business guidance.

The April 2025 draft on applying the Privacy Protection Law to AI systems is a draft for public comment, not a final directive. The consent opinion of 25 February 2026 is a separate document on the consent principle. Reading the three as one instrument is a common mistake.

Questions a board can ask

We located no source that sets a specific duty of board oversight of AI in Israeli law, so this section offers questions rather than a standard. The questions are a way to test whether the layers above have an owner.

  • Which AI tools are in use today, including those staff adopted without a procurement process?
  • For each tool: is the vendor an external party under Regulation 15, and is there a written agreement that covers access, oversight and termination?
  • What company or personal data can reach the tool, and who decided that?
  • When AI output is relied on or sent outside the company, who checks it, and is that check recorded?
  • When would the company tell a customer, an employee or a counterparty that AI was involved, and who decides? AI disclosure is a judgment call that needs an owner.
  • If an agentic tool can act on its own, what can it do without a person approving, and how is it stopped?
  • Who reports to the board on any of this, how often, and what would trigger an out-of-cycle report?

Where the line sits

Oversight does not mean approving every action in real time. It means that the decisions listed above have a named owner, a record, and a date on which they are checked again. Software can gather the facts; a person signs the decision.

CLOAK builds source-linked research and human review into its own work, and the CIDAH regulation map behind this page is re-checked monthly.

Frequently asked questions

Is there an Israeli AI law that binds companies?

We found no single statute on AI governance for private companies. What binds a company is a set of existing duties, such as the Regulation 15 vendor rules and the controller's responsibility for database security. This is a reading of the sources and should be verified for a specific case.

Does the Privacy Protection Authority's July 2026 AI agents document apply to businesses?

It addresses personal use by individuals and does not regulate business processing. Companies should treat it as background, not as business guidance.

Who is responsible when an AI vendor holds company data in the cloud?

According to the Authority's FAQ, legal responsibility for database security remains with the controller, while operational responsibility is split by service model.

Is a vendor a holder or an external party under Regulation 15?

The categories overlap. An external party can be anyone with actual access in the course of the service, and a vendor that stores or processes data for the controller usually also becomes a holder. The test is functional, not the contract label.

Does the law require board oversight of AI?

We located no source that sets such a duty. The board questions on this page are prompts for management, not a legal standard.

Related series: AI briefings from Neeman Keynan & Co.