You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 4, 2024

Comparing EU, Southeast Asia Approaches to AI Regulation

Law360

The rapid development and deployment of artificial intelligence in various industries is increasingly attracting the attention of regulators, who aim to encourage the progression of AI technologies while ensuring their responsible use.

Recent regulatory developments around the world, including in the European Union and Southeast Asia, serve as evidence of this emerging trend.

Here we shall discuss the effect of AI regulatory approaches in the  EU on Southeast Asian countries.

Approach and Action

The EU Artificial Intelligence Act has been officially adopted by EU colegislators and will enter into force 20 days after its publication in the EU Official Journal.[1]

Most of its provisions will apply two years after its entry into force.

The act establishes a harmonized EU legal framework, aiming at ensuring that AI systems placed on and utilized in the EU market are safe, have managed risks, and are aligned with EU fundamental rights and values.

Countries in Southeast Asia, predominantly governed by civil law systems, often adopt statutory frameworks similar to those in the EU when addressing new legal matters.

In the rapidly developing field of AI, Southeast Asian countries are adopting a wait-andsee approach toward global regulatory trends. This cautious stance allows them to observe and analyze international developments in AI regulation before crafting their own frameworks.

Compared to the EU, countries in Southeast Asia are generally more focused on using AI for national development. Common themes include building human resource capability, developing ecosystems and building infrastructure. Some countries emphasize governance and ethics more than others.

Over the past five years, governments across Southeast Asia have been focusing on promoting AI by implementing national policies to strengthen AI promotion and governance.

While there may be less regional integration in the approach to AI of countries in Southeast Asia, there are some efforts to create a unified stance.

In February, the Association of Southeast Asian Nations released its guide on AI governance and ethics. The guide is for policymakers and organizations in ASEAN to rely on when they design, develop and deploy AI technologies.[2]

The guide encourages regional-level initiatives, alignment within Southeast Asian nations and interoperability of AI frameworks across jurisdictions.

The EU AI Act establishes a shared supervision and enforcement regime between the EU member states’ competent authorities and the European Commission.

In turn, despite the absence in Southeast Asia of a regional governing body as strong as in the EU, many countries in the region have already established new bodies or assigned existing ones to oversee AI matters and implement national policies on AI within their jurisdiction.

Draft AI Regulations in Southeast Asia

Some countries in Southeast Asia are in the process of drafting AI-specific legislation.

Thailand, for example, is currently in the process of drafting two AI-related laws to promote and regulate AI systems:

  • The Draft AI Innovation Promotion and Support Act aims to establish an AI sandbox and contains provisions on data sharing, AI standards and certification, and risk management;[3] and
  • The Draft Royal Decree on AI System Service Business is aligned with the principles of the EU AI Act, highlighting the necessity of risk assessment, reporting specifications, and the establishment of specific steps to reduce AI risks.[4]

The rollout of the EU AI Act is expected to influence Thai authorities to make further revisions and additions to the draft legislation.

Impact of Southeast Asia AI Regulations on EU

The EU AI Act has increasing relevance to Southeast Asia materially, and how the Southeast Asian regulatory landscape unfolds will in turn have significant relevance to the EU.

First, the main obstacle for Southeast Asian countries adopting an approach similar to the EU’s AI playbook is that the region is less integrated, both as a market and as a regulatory environment.[5]

In January 2021, ASEAN adopted the ASEAN Digital Masterplan 2025, calling for a regional policy for best practice guidance on AI governance. Based on this guidance, it is apparent that most Southeast Asian governments have taken a softer and gentler approach to AI regulation compared to the EU, focusing on voluntary guidelines and codes of conduct, rather than hard law.[6]

As emerging markets, ASEAN member states are wary of affecting business confidence. Emerging markets tend to stay away from overregulation, because it could discourage innovation.

ASEAN guidelines motivate governments to foster tech talent and to upskill workforces, as well as to invest in research and development rather than to impose stringent restrictions, because of fear of reducing business opportunities.

Southeast Asian countries taking a more business-friendly approach to AI regulation can be a possible setback to the EU’s push for global coordination.[7]

In 2023, EU officials traveled across Asian countries to convince ASEAN governments to follow its lead in enforcing rules. Unlike the EU AI Act, the ASEAN AI guide asks companies to take countries’ cultural differences into consideration.

The comparatively relaxed approach of ASEAN member states may become a barrier to establishing a global standard for AI, as the EU has desired with its landmark AI legislation.

In the wake of more relaxed rules in Southeast Asia, the EU AI Act has received pushback from the business community. Over 160 business executives have signed a letter warning that this legislation could affect the EU’s competitiveness, investment and innovation.[8]

Southeast Asian policymakers will be observing the impact on the EU’s digital economy of the EU AI Act. Since Southeast Asia’s AI policies are more relaxed, this could attract more investor funding globally and from the EU specifically, especially for innovation such as AI sandboxes, research and data centers.

In 2020, Southeast Asia and the EU agreed to become strategic partners, and the EU pledged €10 billion ($10.7 billion) for connectivity projects in the region, agreeing to a digital agreement with Singapore and to an energy partnership with Vietnam.[9]

Southeast Asia is projected to reap a $950 billion increase in regional total gross domestic product from the influx of AI-related businesses.[10] Additionally, Southeast Asia remains a viable AI hub for European companies looking to diversify their AI-related product manufacturing.

While EU companies may face increased burdens due to the need to maintain higher standards to comply with the EU AI Act, this situation might have a silver lining. As noted, many Southeast Asian countries are closely observing the EU’s approach and are likely to adopt similar AI regulations into their national laws in the next few years.

If this occurs, EU companies that are already in compliance with the stringent requirements of the EU AI Act will likely find it easier to adapt to the new AI regulations in Southeast Asian countries. This early compliance could give them a competitive advantage in Southeast Asian markets.

Conclusion

Both the EU and Southeast Asian countries have established bodies to oversee AI matters. While the EU has officially adopted the EU AI Act, many Southeast Asian countries have only enacted national strategies and guidelines, with some drafting their national AI legislation. Overall, there is strong support from Southeast Asian governments for AI use, backed by policies promoting such use.

The legislative journey of the EU AI Act has drawn significant global interest. The act, as the first comprehensive legal framework for AI worldwide, is prompting other jurisdictions to develop their own AI policies and laws.

It is expected that much like the way the General Data Protection Regulation has significantly influenced data protection laws across the globe, the EU AI Act will have a major impact on AI laws worldwide. As the GDPR set a global standard for data protection, the EU AI Act could become the international norm for AI governance.

Southeast Asia’s current relaxed regulatory landscape aims to attract Big Tech investments. Southeast Asian countries may follow the EU approach, but will likely await the EU AI Act’s full implementation for practical insights into AI regulation.

Businesses should monitor AI regulatory developments in the EU and Southeast Asia, assess their products and processes, and revise their compliance strategies accordingly.

 

Anne-Gabrielle Haie is a partner at Steptoe LLP.

Nop Chitranukroh is a partner at Tilleke & Gibbins International Ltd.

Steptoe associate Maria Avramidou and Tilleke & Gibbins associate Rada Lamsam contributed to this article.

 

[1]  Proposal for a Regulation of the European Parliament and of the Council laying down harmonized rules on Artificial Intelligence (EU Artificial Intelligence Act) And Amending Certain Union Legislative Acts (COM/2021/206 final): https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=celex%3A52021PC0206; Press release of the Council of the EU on the adoption of the EU AI Act: https://www.consilium.europa.eu/en/press/press-releases/2024/05/21/artificialintelligence-ai-act-council-gives-final-green-light-to-the-first-worldwide-rules-on-ai/.

[2]  ASEAN Guide on AI Governance and Ethics: https://asean.org/wpcontent/uploads/2024/02/ASEAN-Guide-on-AI-Governance-andEthics_beautified_201223_v2.pdf.

[3]  Draft AI Innovation Promotion and Support Act (Only available in Thai).

[4]  Draft Royal Decree on AI System Service Business: https://bact.cc/f/2022/10/202210-draft-service-business-that-use-airegulation-hearing-chula-onde.pdf (Only available in Thai).

[5]  https://eastasiaforum.org/2021/07/14/is-the-eus-ai-legislation-a-good-fit-for-asean.

[6]  AI regulations: What can the EU learn from Asia? https://www.dw.com/en/airegulations-what-can-the-eu-learn-from-asia/a-68203709.

[7]  Reuters, “Exclusive: Southeast Asia eyes hands-off AI rules, defying EU ambitions”: https://www.reuters.com/technology/southeast-asia-eyes-hands-off-airules-defying-eu-ambitions-2023-10-11/.

[8]  DW, AI regulations: What can the EU learn from Asia?: https://www.dw.com/en/airegulations-what-can-the-eu-learn-from-asia/a-68203709.

[9]  GIS Reports Online, The future of Europe’s Southeast Asia engagement: https://www.gisreportsonline.com/r/eu-asean/; East Asia Forum, Charting the future of Southeast Asian AI governance: https://eastasiaforum.org/2024/05/21/charting-the-future-of-southeastasian-ai-governance/.

RELATED INSIGHTS​ 

August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public
August 10, 2026
Thailand has finalized its social media KYC (“know your customer”) rules under Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers (No. 2), which was published in the Government Gazette on May 5, 2026, and will take effect on November 1, 2026. While an early draft of the notification proposed requiring social media platforms to arrange identification of every user account, the final notification is significantly more targeted, focusing on paid online advertising and advertiser identity verification. Though the regulatory initiative primarily aims to combat online fraud and technology-related crimes, it also has important consequences for intellectual property enforcement, because the verified platform records that will be generated under the new requirements can help IP rights holders to identify anonymous online infringers. Key Regulatory Mandates The notification requires social media service providers to verify the identity of advertisers before their paid advertisements are published and disseminated in Thailand through social media, regardless of whether the advertising fees come from the advertisers or third parties. Verification of an advertiser is valid for one year, after which verification would have to be performed again before the platform could publish additional paid advertisements from the advertiser. Permitted verification methods are specified under the notification. A platform may verify an advertiser by checking identity evidence and confirming the connection between the advertiser and that identity evidence, with the notification giving facial comparison against certain government-issued identity documents as an example. Alternatively, platforms may verify advertisers through a digital identity verification and authentication system with an identity-proofing assurance level not lower than the level prescribed by Thailand’s Electronic Transactions Commission. The notification further requires platforms to retain only the advertiser’s information necessary to identify the advertiser, beginning from the start of the advertising activity and for
August 10, 2026
On July 31, 2026, Thailand’s Big Data Institute (BDI) launched a public consultation on the principles of a proposed new data-sharing law, with comments accepted until August 31, 2026. If enacted, the law would establish Thailand’s first comprehensive framework for government and private-sector data sharing, creating a systematic, secure, and transparent regime to support analytics, policymaking, research, and innovation. Central Data-Sharing Platform The draft law establishes a central system for data sharing, managed by the BDI. Government agencies would be required to connect to the BDI’s Data Integration and Intelligence Platform (also referred to as D2), in accordance with the BDI’s rules and procedures. Five Dimensions of Data Sharing The draft law covers five key types of data sharing between government (G), businesses (B), and consumers (C): G2B: Private organizations may request government data specifically for research and development purposes. The BDI will assess the applicant’s data governance, security, and privacy capabilities whether such measures meet prescribed standards before forwarding the request to the relevant government agency within 90 days. Any dispute may be escalated to a newly established Data-Sharing Promotion Committee for final determination. G2G: Government agencies may request data from other agencies through the central system. The data-holding agency must respond within 90 days, taking legality, necessity, proportionality, public interest, and personal data protection into account. Disputes may be referred to the Data-Sharing Promotion Committee for adjudication. B2G: In emergency situations involving public safety, economic security, or disaster response, the Minister of Digital Economy and Society may require private entities to provide data through the central data-sharing system. Government agencies must specify the data requested, demonstrate its necessity and expected benefits, and request only data reasonably available to the data holder. Requests for personal data must be limited to the minimum amount necessary. B2C: Royal decrees may
August 10, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) recently released draft guidance on records of processing activities (ROPA) for personal data controllers and processors under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft guidance, which was presented to the public on July 7, 2026, addresses both controller records of collection, use, and disclosure of personal data and processor records of processing activities carried out on behalf of controllers. If implemented, the guidance will significantly expand organizational expectations for ROPA preparation, maintenance, and use across all sectors. Key Takeaways The draft guidance contains several important implications for organizations subject to the PDPA: ROPA reframed as a core accountability tool. The guidance elevates ROPA from an administrative record to a central accountability mechanism, connecting controller duties with recordkeeping obligations. ROPA as a source for privacy notices and governance documents. ROPA should serve as the primary source for privacy notices and align with consent management, retention schedules, DPIAs, incident response plans, and vendor contracts. Expanded scope across all activities. ROPA must cover all processing activities across the organization—including security, finance, HR, and external contractors—with correct controller or processor classification for each. Ongoing maintenance and auditability. ROPA must be updated for any change to systems, purposes, or processors, reviewed at least annually, and maintained with version control and a designated owner. Enhanced vendor, processor, and cross-border transfer requirements. Organizations must document all processors, external recipients, and cross-border transfers, specifying purposes, access scope, and destination countries. Linkage with risk assessment, DPIAs, and LIAs. ROPA should assign risk levels to each activity and identify when data protection impact assessments (DPIAs) or legitimate interests assessments (LIAs) are required, functioning as a risk-management tool. ROPA and data breach readiness. Incomplete ROPA can delay breach response and notification. Organizations should map data flows, vendors,