You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 19, 2024

DNA: How the Use of Artificial Intelligence Is Regulated in Southeast Asia

Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to How the Use of Artificial Intelligence Is Regulated in Southeast Asia, a comparative resource published by Drew Network Asia (DNA). The guide provides an accessible introduction to artificial intelligence (AI) and examines how ASEAN member states are approaching governance, regulation, and responsible deployment of AI technologies.

The publication begins by outlining core AI concepts and summarizing the ASEAN Guide on AI Governance and Ethics, which reflects the region’s collective approach to promoting innovation while addressing risks. It then presents a comparative overview of nine ASEAN jurisdictions, highlighting emerging national strategies, regulatory developments, and institutional frameworks.

Each country chapter responds to a consistent set of ten practical questions. These cover whether a national AI strategy has been issued; the extent to which dedicated AI laws or sectoral regulations apply; the existence of relevant judicial decisions; available guidelines and government support schemes; regulators responsible for AI oversight; approaches to liability, copyright, and data protection; and key considerations for organizations deploying AI technologies.

By consolidating developments across the region, the guide serves as a useful reference for businesses exploring AI-related opportunities or compliance obligations in Southeast Asia. As regulatory approaches continue to evolve, readers seeking jurisdiction-specific advice are encouraged to contact the practitioners listed in each chapter.

The full guide is available for download using the button below or directly from the DNA website.

RELATED INSIGHTS​ 

November 15, 2024
On November 9, 2024, the government of Vietnam promulgated Decree No. 147/2024/ND-CP on the management, provision, and use of internet services and online information (“Decree 147”). This decree supersedes the previous Decree No. 72/2013/ND-CP dated July 15, 2013, on the same topic (“Decree 72”) and its amending regulations, and will take effect on December 25, 2024. Spanning over 200 pages, with an appendix of 62 forms, Decree 147 addresses a wide range of key internet and online topics, including internet services; domain names; cross-border information provision; social network services; aggregated information websites; online game services; app store services; information content services on mobile telecom networks; responsibilities of telecom, internet, web hosting, data center, and telecom application service providers; and measures to handle illegal content. This decree is expected to have a significant impact on both onshore and offshore service providers in the respective fields, and will potentially tighten the regulatory landscape for internet services and online information provision in Vietnam. Some highlights from the new Decree 147 compared to its predecessor are detailed below. Cross-Border Information Provision Offshore service providers, including offshore social network service providers and offshore app store service providers, who provide services on a cross-border basis and either lease data storage in Vietnam or meet a threshold of 100,000 or more total visits per month from Vietnam for six consecutive months must adhere to stricter requirements than other providers. Notable obligations of these regulated cross-border providers include: Notifying the Authority of Broadcasting and Electronic Information (ABEI) of their contact information. Monitoring and removing illegal content. Storing and managing user data as required. Authenticating social network user accounts using Vietnamese mobile number or ID number. Reporting to the ABEI annually as well as on an ad hoc Handling user complaints. Only cross-border providers who have notified the
November 13, 2024
Thailand’s Electronic Transactions Committee has publicized a new draft notification detailing additional duties for specific marketplace digital platform service operators under Section 18(2) of the Royal Decree on Operation of Digital Platform Service Businesses Subject to Prior Notification B.E. 2565 (2022). The draft notification, which is open for public comments until November 30, 2024, aims to provide enhanced protection for users of “specific marketplace platforms” (defined below). Some key points of the draft notification are detailed below. Scope The draft notification applies to “marketplace digital platform services,” which refers to digital platform services that serve as an intermediary for buying or exchanging goods and provide services to facilitate sale transactions, such as providing communication systems (e.g., chat features), shopping carts, delivery arrangements, and supplemental payment processing facilitation. “Specific marketplace platforms” refers to Section 18(2) of the Royal Decree on Digital Platform Services, which covers digital platform services that pose risks to financial and commercial security, the reliability and credibility of data messaging systems, or potential harm to the public, and that have a high level of potential impact based on the criteria for assessing the impact of digital platform service operations. Key Obligations Registration. The draft notification requires the marketplace operators mentioned above to be registered as legal entities in Thailand. Terms and conditions. The draft notification details additional obligations relating to marketplace operators’ terms and conditions: In addition to existing obligations prescribed in the Royal Decree and the relevant subordinate laws, the draft notification emphasizes that the terms and conditions must be in Thai, clear, accessible, and understandable, and may include graphical elements to aid explanation. The terms and conditions must prescribe conditions relating to the sale of products subject to specific standards, such as those restricted under the Food Act, the Drugs Act, and the Industrial Product
November 11, 2024
The Vietnamese government has demonstrated a strong commitment to building a digital government, digital economy, and digital society through its recently issued national strategy on digital infrastructure. Under Decision No. 1132/QD-TTg dated October 19, 2024, on “Digital Infrastructure Strategy to 2025 with Orientation to 2030,” the government will create supportive conditions for both domestic and international businesses to invest in digital infrastructure with cybersecurity as a priority. Recognized as vital to the economy, this digital infrastructure will consist of four main components: (i) telecommunications and internet infrastructure, (ii) data infrastructure, (iii) physical-digital infrastructure, and (iv) digital utility infrastructure, including digital technology as a service. Key goals for 2025 include universal fiber optic access for households, 100% 5G coverage across all provinces and cities, deployment of at least two new international undersea fiber optic cables, establishment of AI data centers, development of green-standard data centers, and platforms for IoT, AI, big data, blockchain, and cybersecurity. By 2030, goals include fiber access with speeds of at least 1 Gbps, 5G coverage for 99% of the population, readiness for 6G trials, six additional international undersea fiber optic cables, development of a hyperscale data center, and positioning Vietnam as a digital hub. To achieve these goals, the government has outlined some core tasks, creating significant opportunities for both foreign and domestic investors: Developing telecommunications and internet infrastructure for widespread fiber optic and 5G access, while preparing for emerging technologies like 6G, Open RAN, satellite, and IpV6. Telecommunication enterprises will jointly invest in and share the use of international fiber optic cable routes to ensure efficient capacity utilization and optimize investment capital. Attracting foreign and domestic investment to establish hyperscale data centers and cloud computing services that meet global standards. Creating physical-digital infrastructure by integrating technology across key sectors such as transportation, energy, healthcare,
November 8, 2024
On October 31, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) opened a public consultation period on its draft notifications—one directed at data controllers and another at data processors—regarding exemptions from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft notification for data controllers aims to amend and revoke certain aspects of the first ROPA exemption notification issued in June 2022 and outlines the criteria for data controllers to be exempted from the obligation to prepare and maintain such records. Although it is officially titled “Notification of the Personal Data Protection Committee on Exemption from Record-Keeping Requirements for Small Business Data Controllers,” this draft notification applies to all types of exempted data controllers (see list below), and not only small businesses. The draft notification for data processors is new and does not replace any prior notification. The criteria under both draft notifications exempt certain data controllers and data processors from the obligation to maintain ROPAs, but exempted data controllers are not free from the obligation to retain information on the rejection of data subjects’ requests to exercise certain rights under the PDPA. While these criteria remain consistent with the June 2022 ROPA exemption notification, there are a few key takeaways from the notifications, as detailed below. Types of Exempted Parties The draft notification on data controllers adds condominium and housing estate juristic persons, as well as individuals, to the list of parties eligible for an exemption, while removing internet cafes from the list. The new draft notification for data processors mirrors the corresponding list in the draft notification for data controllers. The complete list of parties eligible for ROPA exemptions under the draft notifications is as follows: SMEs according to the law on