The most useful word at AI World 2026 is not “AI.” It is the verb that follows it. Scan a website. Read a fax. Build a kintone app. Draft a security questionnaire. Turn a PowerPoint deck into a narrated training video. Check a prospective business partner. Search company documents. Translate a manual. These are the jobs Japanese vendors have brought to Makuhari Messe.

The show, held July 22–24 in halls 4–7, places AI World beside DX General Expo and Business Innovation Japan. Its own program is divided into business reform, development technology, talent, and security and governance. That architecture already gives away the market’s direction. The model is rarely the product. The product is a bounded piece of work wrapped around a model, company data, permissions, an interface and someone who remains accountable.

This report examined the official 2026 exhibitor catalog and product descriptions, then compared the commercial language with Japan’s longer history of artificial intelligence, digital transformation and AI governance. It did not independently test every system on the floor. Product capabilities, adoption numbers and performance claims below are vendor-supplied unless otherwise stated. “Actually selling” therefore means a named product, service, demonstration or implementation offer—not a Japan.co.jp endorsement that it performs as advertised.

July 22–24AI World 2026 Summer Tokyo at Makuhari Messe
4 zonesBusiness reform, development, talent, and security/governance
< 50%Share of Japanese respondents taking a positive step toward generative AI in IPA’s 2025 survey
¥50,000/monthPublished starting price for two unusually transparent catalog offers
1982–1992Core decade of Japan’s Fifth Generation Computer Systems project
¥54 billionApproximate public investment in that 11-year knowledge-computing program

The Catalog Answer: Narrow Work, Not Artificial General Intelligence

The sharpest contrast at the exhibition is between the language of autonomy and the modesty of the tasks. “Agent” can suggest a tireless digital employee making plans and acting across a company. Most sellable offers are closer to supervised workflow software: retrieve evidence, transform a document, suggest a next step, write a first draft, call an approved tool, and wait for a person.

That is not a criticism. Narrowness is often what makes enterprise AI purchasable. A chief information officer can define success for invoice extraction, vulnerability scanning or minutes: accuracy, time, exceptions and cost. “Transform the enterprise” has no comparable test.

Japanese sellerNamed offerWhat the buyer is actually buyingEvidence and caveat
BaseconnectRiskdogAn AI agent for corporate identity, credit and compliance screening, with continuing monitoring and alerts.The catalog lists 5.4 million companies, 150 million risk records from 4,000 sources, and a ¥50,000 monthly starting price. Those coverage and speed claims are the vendor’s.
J-StreamEQ Presentation Cloud + EquipmediaPowerPoint-to-narrated-video generation, followed by controlled hosting, viewing restrictions and analytics.The catalog says secure distribution begins at ¥50,000 per month and offers a 30-day trial. Multilingual support is described as planned.
SherLOCKAI red teaming, guardrails and governance platformTesting hostile prompts and failure paths, filtering model inputs and outputs, and organizing AI risk controls.A security service and governance layer—not a guarantee that an underlying model is safe.
AI Security LabAeyeScanAI- and RPA-assisted website vulnerability scanning from setup and crawling through reporting.The booth offers a generative-AI scanning demonstration. Buyers still need scope, false-positive and remediation evidence.
route-Droute-D AI data entryOCR and learning workflows that convert PDF and fax forms used in manufacturing and distribution into structured data.A live booth demonstration addresses one of Japan’s least glamorous but most persistent interfaces: paper entering a digital process.
User LocalUser Local ChatAIA fixed-price corporate generative-AI environment with RAG over internal documents, minutes and other agent functions.The company advertises no extra fee tied to character count or choice of LLM. Fixed pricing does not remove implementation, data-preparation or governance cost.
HelpfeelFAQ, Agent Mode, Analytics and SupportIntent-based search, conversational answers, analysis of customer and employee voices, and AI-assisted ticket management.Helpfeel claims its FAQ can cut inquiries by as much as 70%. The catalog does not provide an independent benchmark or a common baseline.
Dentsu SokenSecurateDrafting answers to customer security questionnaires by reusing prior answers and displaying evidence and a confidence score.A strong example of a constrained agent: it prepares and cites; security professionals remain responsible for the representation.
JSOLICHI-GEKIAutomatic creation of multilingual videos and translated materials from Japanese documents or video.The offer sells localization workflow, not a new foundation model. Terminology review still matters in safety, legal and technical content.
NovelWorksRexin AI for kintone + FLASH AIAutomatic kintone application construction from transcripts and improvement notes, plus live rapid prototyping.The vendor promises a two-hour interview-and-build session and hands over a custom system without charge. That is a prototype offer, not proof of production readiness.
UNCHAINNEURONCapturing the content and rationale of management decisions so strategy and execution can remain aligned.The difficult question is whether tacit judgment is captured accurately—or merely converted into a tidy but incomplete summary.
RimoRimo VoiceTranscription, speaker recognition and summarized minutes from recorded meetings.The listing says a one-hour recording can become minutes in about ten minutes. Accuracy by acoustic setting and specialized vocabulary is not stated.
Sales GoGoCoo!A sales-data foundation that organizes customers, deals and activity history so AI can analyze and recommend from cleaner records.It sells the prerequisite for an agent: usable data. An AI recommendation cannot repair missing or strategically distorted sales records.
FairtechAEO Hub, cross-sell AI and custom agentsMeasurement of visibility in AI search, account matching from business-card lists and catalogs, and contract agent development.The AEO product is labeled a beta beginning July 22; results should be treated as experimental until repeatable lift is shown.

Two commercial patterns stand out. First, only a minority of catalog entries publish a price. Much of AI World remains a lead-generation market in which a booth starts a consultation, proof of concept or systems-integration engagement. Second, many exhibitors sell the work around AI—cleaning data, redesigning processes, training employees, testing security and operating systems after launch. The foundation model may come from somewhere else.

Japan’s enterprise-AI market is not primarily selling a machine mind. It is selling a new access path into old work.

What “AI Agent” Usually Means Here

A practical enterprise agent has several layers. A language or vision model interprets an instruction. Retrieval-augmented generation, or RAG, brings in approved company documents. Connectors expose a limited set of tools: search a database, create a draft, open a ticket, update a field. An orchestration layer decides the sequence. Permissions constrain whose data it may see and what it may change. Logs record the path. A person approves consequential action.

Remove the retrieval layer and the agent may confidently invent company policy. Remove permissions and it may expose a personnel file to the wrong department. Remove a transaction limit and a plausible draft can become an unauthorized commitment. Remove logs and nobody can reconstruct why a decision occurred. The conversational screen is the visible fraction; governance and integration are the product.

Four different things called an agent
  • Answering agent: finds and summarizes approved information.
  • Drafting agent: prepares a questionnaire, report, email, minutes or application for review.
  • Workflow agent: moves through defined steps and calls approved tools under limits.
  • Decision-support agent: ranks risk or recommends action but leaves legal and managerial responsibility with people.

The catalog also uses “AI employee” language for customized agents that handle calls, inquiries, documents and back-office work. That metaphor is commercially vivid and operationally dangerous. Employees have authority structures, training, judgment, duties and accountability. Software has a configuration. A responsible buyer should ask which actions are permitted, which require approval, how an error is reversed and who owns the result—not whether the demo appears human.

Private AI Is a Deployment Choice, Not a Magic Seal

Enterprise buyers in Japan repeatedly ask for “private AI.” In the strongest form, sensitive data and model execution remain inside infrastructure controlled by the customer. In other arrangements, the model is a cloud service under a contract that promises not to use prompts for training. Between those poles are virtual private clouds, dedicated instances, region restrictions and local retrieval indexes.

None is automatically private. A company must map where prompts, files, embeddings, logs, backups and administrator access travel; whether subcontractors can see them; how long each copy remains; how data is deleted; and whether the vendor can silently switch a model or hosting region. RAG reduces the need to retrain a model on company records, but it also creates a new search index containing sensitive fragments. That index needs the same access discipline as the source systems.

The booth question should therefore be specific: show the data-flow diagram and the contract clause. “Secure” and “domestic” are marketing adjectives until attached to architecture, controls, audit evidence and liability.

Why the Products Look So Japanese

The catalog’s obsession with faxes, security check sheets, meeting records, kintone, internal knowledge and multilingual manuals is not technological backwardness. It is an accurate map of organizational friction. Japanese companies often operate through long supplier chains, detailed approval procedures and decades of documents spread across paper, Excel, file servers and packaged systems. The newest model still has to pass through those interfaces.

A weak-yen economy and a shrinking labor force sharpen the demand for measurable labor savings. Yet companies cannot casually replace a control step in finance, safety, procurement or human resources. The commercially viable form is assisted automation: let software read, compare and draft; let a named person authorize. Vendors that can connect to existing systems and survive internal audit may be worth more than vendors with a marginally better benchmark score.

IPA’s DX Trends 2025 found that fewer than half of responding Japanese companies were taking a positive step toward generative AI—defined as deployed, trialing or actively considering it—versus nearly four-fifths in the United States and nearly seven-tenths in Germany. Large Japanese companies were moving from trials into full deployment, but many respondents remained interested without a plan. AI World is a commercial answer to that gap. It converts “we should use AI” into a menu of limited projects that can be budgeted.

Japan Has Been Here Before—But the Machinery Changed

In 1982, Japan began the Fifth Generation Computer Systems project. Backed by the Ministry of International Trade and Industry and organized through ICOT, it sought knowledge-information processing, parallel inference machines and logic programming beyond conventional computer architecture. The Information Processing Society of Japan records roughly ¥54 billion spent over 11 years, ending in fiscal 1992.

The project did not create the universal intelligent machine its popular image implied. Its parallel symbolic work, languages and research community nevertheless mattered. The lesson is not simply that Japan “failed at AI.” It is that knowledge does not become computable merely because experts can state some rules. Real organizations contain exceptions, conflicting goals, missing data and tacit practice. The same problem now reappears behind every booth promising to capture institutional knowledge.

During the 1990s and 2000s, the AI label cooled while automation kept spreading through robots, control systems, statistical quality, enterprise software and search. Japan’s industrial strength remained physical and process-oriented. In 2016, the government’s Society 5.0 vision framed data and cyber-physical systems as a response to social problems. METI’s 2017 Connected Industries initiative made the connection of machines, people and organizations a central industrial strategy.

Then came the less glamorous DX decade: cloud migration, RPA, no-code tools, data warehouses and arguments over legacy systems. METI’s 2018 DX Report warned of a “2025 digital cliff” if opaque and aging systems continued to block change. Generative AI after 2022 did not erase that work. It made the cost of unfinished data and system modernization impossible to ignore. An agent can speak natural language, but it cannot reliably act on a process no one has mapped or a database no one trusts.

Japan’s 2025 AI Promotion Act established a national framework oriented toward research, use and coordinated risk response. In March 2026, METI and MIC issued version 1.2 of the AI Guidelines for Business, explicitly updating the living document for AI agents and physical AI and strengthening risk-based thinking. The sequence matters: Japan moved from a national symbolic-computing project, through connected industry and DX, to governed deployment of probabilistic systems embedded in work.

The Product Is Often Integration

Read the listings closely and a recurring bundle appears: assessment, process design, model selection, data preparation, agent development, employee training, monitoring and maintenance. DeNA AI Link offers support from the first “we do not know what to do” conversation through tools, solutions and product development. SMS Data Tech describes introduction, development, operation, maintenance and training. Panhouse combines training with solution and agent development. Systems integrators sell continuity more than novelty.

This is rational. A foundation model can be purchased by many firms. Competitive advantage lies in making it respect a company’s product codes, approval hierarchy, customer promises and risk tolerance. That work is slow, local and hard to show in a keynote. It is also the reason an enterprise system either lives after the pilot or dies.

Japanese vendors may have an advantage in language nuance, domestic workflows and long customer relationships. They also face a structural risk: becoming a service layer on top of foreign models and clouds, capturing implementation revenue while the platform owner captures scale and data-center economics. Model portability, open interfaces and exportable logs are therefore strategic issues as well as procurement details.

Where the Demonstration Can Mislead

A trade-show demo is an edited reality. The document is legible. The question is anticipated. The network works. The source collection is clean. A prototype created in two hours can be an excellent way to discover a requirement, but it says little about permissions, peak load, disaster recovery, integration tests, maintainability or the hundredth exception.

Vendor numbers also use different denominators. A claimed 70% reduction in inquiries may apply to a particular customer, channel or class of question. Ten-minute processing for a one-hour meeting does not state transcription error. A risk database with 150 million records does not reveal false matches, update latency or appeals. The right response is not cynicism; it is to ask for the evaluation design.

ClaimEvidence a serious buyer should requestHidden failure
“Cuts work by 70%”Baseline task, sample period, comparable users, exceptions and total review timeWork moved to a different team or quality fell
“Private AI”Data-flow diagram, retention, subprocessor list, admin access, deletion test and incident termsPrompts are private but embeddings, logs or backups are not
“Autonomous agent”Action list, monetary and data limits, approval gates, sandboxing, rollback and logsA draft crosses into an irreversible transaction
“Uses your knowledge”Source coverage, permission inheritance, citation rate, revision handling and retrieval evaluationThe agent quotes an obsolete or unauthorized document
“Production ready”Availability target, recovery plan, load test, change process, model-version policy and exit planA polished prototype depends on one engineer or one model

Security Products Have Their Own Paradox

AI World’s security zone reflects a necessary correction to the first wave of corporate chatbots. SherLOCK sells red teaming and guardrails. AeyeScan automates parts of vulnerability assessment. Dentsu Soken’s Securate uses AI to help suppliers answer security questionnaires. Each tries to make protection scale when specialists are scarce.

But automation can turn a weak control into a faster weak control. A security questionnaire is not evidence merely because AI reused a confident prior answer. An automated scanner cannot see a business-logic flaw it was not designed to exercise. A guardrail can be bypassed or can block legitimate work. These systems should raise coverage and consistency while preserving expert challenge, not manufacture a certificate of safety.

The best sign in Securate’s description is not “AI.” It is the display of evidence and confidence. Those features make a generated answer inspectable. The next step is to preserve who approved it, what policy version supported it and whether the customer’s question had the same meaning as the historical one.

The Labor Question Behind the Productivity Pitch

Every minutes generator and data-entry agent sits inside a labor relationship. If time is saved, who receives it? The worker may gain space for judgment and customers. Management may raise volume targets. A job may be redesigned or removed. Employees may be asked to correct the agent without recognition that they are performing quality control and producing training data.

Surveillance risk grows when AI scores calls, sales activity, emotion, attention or “engagement.” A useful deployment should be negotiated in plain terms: data collected, purpose, access, retention, appeal and prohibited uses. People need a way to contest a generated assessment. Productivity cannot be measured only from the employer’s dashboard.

Japan’s labor shortage makes automation economically understandable, but scarcity is not permission to make responsibility disappear. If an agent drafts a compliance judgment, rejects a customer, ranks a supplier or recommends a personnel action, a human role must be more than ceremonial. The reviewer needs time, authority and source evidence to disagree.

A Buyer’s Route Through Makuhari

The strongest purchasing method is to arrive with one difficult example from the real business: a smeared fax, a bilingual safety manual, a contradictory security questionnaire, a meeting with overlapping speakers, or a customer file the system must not reveal. Ask the vendor to run it. Then ask what failed.

Ten questions worth taking to every booth
  1. What exact task ends differently after your system is installed?
  2. Which actions can the agent take without approval?
  3. Show the sources, permissions and revision date behind an answer.
  4. Where do prompts, files, embeddings, logs and backups reside?
  5. What is the measured error rate on data like ours—not the demo set?
  6. How are model and prompt changes tested before release?
  7. What happens when the model, network or vendor is unavailable?
  8. What is the full first-year cost, including integration, review and training?
  9. Can we export our data, evaluations and audit history in usable form?
  10. Who is contractually responsible when an automated action causes loss?

Price transparency should be rewarded, but a low subscription is not a low total cost. A ¥50,000 monthly product can require data cleanup, identity integration, legal review, employee training and ongoing exception handling. Conversely, a higher implementation fee may be rational if it replaces several disconnected controls and produces measurable quality.

What AI World 2026 Really Shows

AI World does not reveal a single Japanese AI industry. It reveals at least four. Product companies package repeatable tasks. Systems integrators build custom bridges into old organizations. Training companies sell the confidence and habits required for adoption. Security and governance firms sell the right to proceed without losing control.

The catalog is broad enough that conventional SaaS, consulting, recruitment and even non-AI business services appear beside agents. That is useful evidence in itself: “AI World” is a commercial category, not a technical certification. The buyer has to do the classification the show cannot.

The deeper historical shift is still real. Japan’s 1980s AI program tried to build machines that could reason with encoded knowledge. The 2026 marketplace begins from the opposite end. It starts with a security form, a fax, a meeting, a sales record or an old manual and asks how much of that work can be made searchable, draftable and executable under control.

That is less cinematic than an autonomous digital employee. It is also closer to how technology changes an economy. The winners will not be the vendors that say “agent” most often. They will be the ones that can expose evidence, survive exceptions, respect permissions, measure quality and leave the customer able to exit.

What are Japanese companies actually selling at AI World 2026? Mostly, they are selling constrained access to institutional memory and the promise of fewer manual transitions between paper, people and software. The promise is credible where the task is narrow and the controls are visible. Everywhere else, the most intelligent action at the booth is still a human question.

Sources, method and disclosure

Japan.co.jp reviewed the official AI World 2026 event page and its dynamically rendered exhibitor catalog, filtering the catalog to AI World and recording named products, descriptions, demonstrations and disclosed prices. Catalog descriptions are supplied by exhibitors and were not independently tested. Claims such as inquiry reduction, processing speed, database coverage, adoption and satisfaction are presented as vendor claims, not audited findings. Historical and policy context was checked against official Japanese government, IPA and Information Processing Society of Japan sources.