You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 30, 2025

AI Model Training and Copyright in Thailand: Key Challenges and Potential Solutions

Artificial intelligence (AI) model training and data scraping are essential processes in the development of modern AI systems. AI model training involves using large datasets to teach machine learning algorithms to recognize patterns, make predictions, or generate new content. Data scraping refers to the automated extraction of information from websites or digital sources, often to assemble the vast datasets required for effective AI training.

As these practices become more widespread, questions about the legality of using third-party content—especially copyrighted works—have become increasingly important. In Thailand, the legal landscape for AI developers is shaped primarily by the Copyright Act, which presents unique challenges due to the absence of a fair-use exception. This article examines the copyright-related risks and legal uncertainties facing AI developers under Thailand’s current copyright law and practices, offering strategic guidance for navigating this complex environment.

Copyright Risks in AI Scraping and Training

Thailand’s Copyright Act does not provide a broad fair use or fair dealing exception, unlike some other jurisdictions, such as the United States. This absence has significant consequences for AI developers:

  • No general defense for AI training: Any use of copyrighted material for AI model training is presumed to be infringing unless a specific, narrow statutory exception applies or explicit permission is obtained from the rights holder. There is no general legal basis for using copyrighted works in AI training without authorization.
  • Increased rights clearance burden: Developers must identify and secure licenses for every copyrighted work included in their training datasets. Given the scale and diversity of data required for effective AI models, this process can be both impractical and costly.
  • Legal ambiguity and litigation risk: The lack of clear statutory guidance or case law leaves developers in a legal gray area. There is no established precedent clarifying whether certain uses of copyrighted material for AI training might be tolerated or considered trivial. This uncertainty exposes developers to potential copyright infringement claims, which could result in injunctions, damages, or even criminal penalties.
  • Chilling effect on innovation: The risk of liability and the complexity of compliance may discourage both local and foreign entities from developing or deploying AI technologies in Thailand. This could stifle innovation and limit the growth of the country’s AI sector.
  • Complications in international collaboration: AI development often involves cross-border data sharing. Models trained using data in compliance with foreign laws may still be infringing under Thai law if deployed or commercialized in Thailand, complicating international partnerships and technology transfers.

Data Scraping and Copyright Infringement

Data scraping can itself constitute copyright infringement if it involves the reproduction or extraction of protected works without authorization. In Thailand, the lack of a fair use exception heightens this risk. Even the act of copying website content for the purpose of assembling training datasets may be actionable, regardless of whether the use is commercial or noncommercial. Developers must be aware that scraping publicly accessible content does not automatically make its use lawful under Thai copyright law.

Jurisdictional Factors and Model Transfer Considerations

Thai copyright law may apply to acts committed outside Thailand if the resulting AI models are deployed, commercialized, or otherwise made available within the country.In addition, AI models trained on data in compliance with foreign laws may still be infringing under Thai law if the training data included copyrighted works not cleared for use in Thailand. This creates additional due diligence requirements for international collaborations and technology transfers.

Recommendations for AI Developers

To mitigate copyright risks, AI developers operating in or targeting the Thai market should consider the following steps:

  • Conduct comprehensive rights clearance: Identify and obtain licenses for all copyrighted works included in training datasets.
  • Review data scraping practices: Avoid unauthorized reproduction or extraction of protected works; respect website terms of service and copyright notices.
  • Implement robust record-keeping: Maintain documentation of rights clearance and compliance efforts.
  • Monitor legal developments: Stay informed about changes in Thai copyright law and any emerging guidance related to AI and data use.
  • Engage in risk assessments: Regularly evaluate legal risks associated with new datasets, model deployments, and international collaborations.

Outlook

Thailand is exploring possible regulatory reforms and policy initiatives to address challenges presented by AI and emerging technologies. Discussions include the potential for AI-specific regulations, consideration of copyright exceptions for technological uses, and possible updates to data protection laws. The direction and timing of these changes remain unclear, so stakeholders should stay informed and participate in public consultations as opportunities arise.

AI developers in Thailand face significant legal challenges due to the lack of a fair use exceptions in the Copyright Act. This increases the burden of rights clearance, heightens litigation risks, and creates uncertainty that can hinder innovation and international collaboration. Proactive copyright compliance and staying updated on legal developments are important for navigating these challenges and supporting responsible AI growth.

Although some countries, such as Singapore and Japan, have introduced text and data mining (TDM) exceptions for AI training, Thailand has not yet adopted similar measures. The industry continues to await legislative amendments or court decisions that will provide clearer guidance.

A version of this article appeared in Managing Intellectual Property.

RELATED INSIGHTS​ 

August 22, 2024
The Personal Data Protection Committee (PDPC) of Thailand’s Ministry of Digital Economy and Society (MDES) has announced the first administrative fine under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). A major private company was fined THB 7 million for noncompliance with specific PDPA requirements, resulting in the unauthorized disclosure of personal data to a call center gang (phone scam fraudsters). Key Findings of Noncompliance The PDPC determined that there were three key violations of specific requirements of the PDPA: Failure to appoint a data protection officer (DPO): Despite processing personal data for over 100,000 individuals as part of its core operations, the company did not appoint a DPO. Inadequate security measures: The company lacked the required security measures, leading to a data breach involving a call center gang, causing widespread damage. Delayed data breach notification: The company did not notify authorities of the data breach within the required timeframe and failed to address the breach promptly, making it impossible to remedy the situation. In addition to the monetary fine, the PDPC, along with the PDPA’s Expert Committee, issued a corrective order requiring the company to undertake the following actions and notify the Office of the PDPC of the relevant correction measures within seven days of receiving the order: Implement up-to-date security measures: The company must improve its current security measures to prevent future breaches and ensure that the security measures are up-to-date with changing technologies. Raise awareness of personnel: The company must provide training to relevant personnel to ensure awareness of data compliance and protection practices. This significant administrative action establishes a precedent for addressing data breaches in both governmental and commercial sectors in Thailand. It also confirms the importance of PDPA compliance, particularly the need for robust security measures, timely breach notifications, and the appointment of
August 15, 2024
On August 9, 2024, Thailand’s Electronic Transactions Development Agency (ETDA) opened a period for public feedback regarding the 2022 Royal Decree on Digital Platforms and its subregulations. To collect this feedback, the ETDA has prepared a 44-question survey on specific attributes of the royal decree and its requirements, covering issues such as the definition of digital platform services (DPSs), types of services that are subject to notification requirements, information that must be submitted annually, and the royal decree’s extraterritorial scope. Business operators that fall within the scope of the royal decree and wish to provide feedback on its effectiveness should prepare and submit the survey online to the ETDA by the end of August 2024. Royal Decree on Digital Platforms Thailand’s Royal Decree on Digital Platforms was published in the Government Gazette on December 22, 2022. It defines a DPS as any service that facilitates or mediates transactions between users through a digital platform, such as e-commerce, food delivery, ride-hailing, online travel agency, online payment provider, or social media platform. The decree requires DPS operators to notify the ETDA before commencing operations, with some limited exemptions. The decree also empowers the ETDA to issue notifications (i.e., subregulations) and guidelines for implementing the decree and to monitor and enforce compliance by DPS operators. The ETDA may impose administrative sanctions, such as warnings, fines, service suspension, or revocation of notification, for any violation of the royal decree or the ETDA’s subregulations. In-scope DPS operators should take this opportunity to provide comments to the ETDA in order to voice their opinions on the practicality of the requirements and support the regulator in shaping the requirements of the royal decree and its subregulations. For more information on this initiative from the ETDA, or on any aspect related to the Royal Decree on Digital
August 5, 2024
On June 28, 2024, Thailand’s Board of Investment (BOI) updated its list of promoted activities to include data hosting, which is listed as “Activity 8.2.4 Data Hosting Services.” Qualifying data hosting services are eligible for a corporate income tax exemption (capped) for eight years, along with other tax and nontax incentives, such as import duty exemption on imported machinery to be used in the project, the right for foreigners to own land, and work permit and visa facilitation for expats, among others. To be eligible for these BOI incentives, projects must: Provide services for leasing host servers for data storage (data hosting); Have at least two data centers located in Thailand that meet or exceed the ISO/IEC 27001 data center standards; and Have an investment amount (excluding cost of land and working capital) of at least THB 5 billion. Apart from the above specific criteria, projects also need to comply with the general BOI criteria, such as a debt-to-equity ratio no higher than 3:1, submission of a feasibility study report, and use of new machinery, among others. For more details on BOI incentives for software and data center activities, or on any aspect of investment promotion in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], or Napassorn Lertussavavivat at [email protected].
July 19, 2024
Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to How the Use of Artificial Intelligence Is Regulated in Southeast Asia, a comparative resource published by Drew Network Asia (DNA). The guide provides an accessible introduction to artificial intelligence (AI) and examines how ASEAN member states are approaching governance, regulation, and responsible deployment of AI technologies. The publication begins by outlining core AI concepts and summarizing the ASEAN Guide on AI Governance and Ethics, which reflects the region’s collective approach to promoting innovation while addressing risks. It then presents a comparative overview of nine ASEAN jurisdictions, highlighting emerging national strategies, regulatory developments, and institutional frameworks. Each country chapter responds to a consistent set of ten practical questions. These cover whether a national AI strategy has been issued; the extent to which dedicated AI laws or sectoral regulations apply; the existence of relevant judicial decisions; available guidelines and government support schemes; regulators responsible for AI oversight; approaches to liability, copyright, and data protection; and key considerations for organizations deploying AI technologies. By consolidating developments across the region, the guide serves as a useful reference for businesses exploring AI-related opportunities or compliance obligations in Southeast Asia. As regulatory approaches continue to evolve, readers seeking jurisdiction-specific advice are encouraged to contact the practitioners listed in each chapter. The full guide is available for download using the button below or directly from the DNA website.