You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 15, 2023

Patenting AI Technology and Software in Southeast Asia

Southeast Asia’s remarkable growth as a destination for foreign investment—including a 42 percent increase in 2021, according to a joint ASEAN-UNCTAD report—has brought with it innovation as well as the desire to protect that innovation. Investors are increasingly seeking to patent the proprietary technology that is a crucial component of so many businesses today, and a burning question for patent applicants is whether artificial intelligence (AI) technology and software are patentable in Southeast Asia. The short answer is that it depends, as the patent laws in Southeast Asia are not uniform.

Is it Patentable?

While AI tools tend to be newer, the older and more familiar question is whether computer software is patentable, and many jurisdictions do have specific rules on this issue. Pure software, or software characterized only by source code, may not be patentable, but it can be protected under copyright laws.

AI-related software may involve complex algorithms, datasets, and training methodologies that can be challenging to disclose in a manner that satisfies the enablement requirement in practice. Algorithms, mathematical methods, and abstract ideas are often considered non-patentable subject matter in many jurisdictions. While software implementing AI may involve innovative algorithms, securing patents for algorithms alone can be challenging in some jurisdictions.

Also, the patent laws of Indonesia, Myanmar, Thailand, and Vietnam specifically list computer programs as unpatentable subject matter. However, a possible workaround would be to describe the software as connected to a tangible medium. This method could overcome an unpatentable subject matter rejection during substantive examination. Furthermore, in Indonesia, a computer program can be patentable if its characteristics (i.e., instructions) have a technical effect and function to solve a tangible or intangible problem.

The most liberal of Southeast Asia’s patent regimes—Singapore’s—even addresses AI innovations. The country has a special fast-track scheme for examining AI patent applications called Accelerated Initiative for Artificial Intelligence. Under this scheme, a patent application can be granted six months from the filing date.

Patent Drafting

Drafters of patent applications in Southeast Asia need to be aware of the patentability requirements specific to AI technology and software inventions in each Southeast Asian country. When drafting AI technology and software patent applications, one option for the drafter to keep in mind is that the description should mention the connection between the software and the tangible medium. If the software can be linked to a tangible medium, the invention could be patentable.

Even if the claims of the patent application in other regions (such as the United States) do not have to show a connection with a tangible medium, when the application enters Southeast Asia, the claims can be amended to include this connection without expanding the scope of the application if the information already exists in the description.

This means that AI technology and software could be patentable as a part of a wider patentable invention.

Prosecution Strategy

In looking to patent AI innovations—or any other tools—applicants should explore possibilities for speeding up the prosecution process. For instance, ASEAN member countries have agreed to accept one another’s examination results in a scheme called the ASEAN Patent Examination Cooperation, and many Southeast Asian countries have an agreement to accept patent examination results from another country, through arrangements referred to as “patent prosecution highways” (PPHs). Cambodia has a special agreement to validate European patents without further examination. Indonesia, Thailand, and Vietnam have a PPH with Japan. Under this PPH, patent applicants can use the examination result of a corresponding patent application in Japan that has already been granted to speed up the examination process in Indonesia, Thailand, or Vietnam. Although the examiner in the other country will still examine the application to make sure it does not violate that country’s patent laws, the examination result from Japan should help speed up the examination process.

Outlook

Patenting AI technology and software in Southeast Asia requires a nuanced approach that takes into account both existing laws and procedures, as well as new considerations that arise with the advent of cutting-edge technology. As businesses continue to innovate and create proprietary technology, it is critical to develop a comprehensive strategy for protecting these valuable assets through patents. By staying up to date with the latest developments in the field and working closely with experienced legal professionals, businesses in Southeast Asia can navigate the complex patenting process and secure the protection they need in order to maintain a competitive edge in the rapidly evolving global marketplace.

RELATED INSIGHTS​ 

April 4, 2024
On March 18, 2024, the president of the Supreme Court of Thailand announced the establishment of a specialized Technology Crime Division within the Criminal Court of Thailand. This represents a significant commitment to cybercrime within the Thai judiciary and a step forward in Thailand’s ability to investigate cybercrime. The rise in cybercrime investigations in recent years has made it increasingly difficult for Thailand’s traditional criminal courts to consider and issue enforcement orders in support of ongoing investigations in a timely manner. The new Technology Crime Division addresses this challenge. This new division has jurisdiction over cybercrime and technology-related crime, fraud or extortion using computers, and criminal offenses relating to personal data protection laws. In addition, this new division has jurisdiction over all requests from competent law enforcement officers seeking court orders under the Computer Crimes Act B.E. 2550, the Personal Data Protection Act B.E. 2562, and the Cybersecurity Act B.E. 2562. The Technology Crime Division will have trainees and judges with expertise in technology and cybercrime—not only to facilitate expert prosecution of cybercrime but also to offer critical and time-sensitive support to law enforcement investigations of alleged cybercrime. The Technology Crime Division is not yet operational. The president of the Supreme Court is expected to announce the division’s opening date in the coming months. For more details on Thailand’s measures for dealing with cybercrime, please contact Michael Ramirez at [email protected] or Piyawat Vitooraporn at [email protected].
March 29, 2024
Thailand’s Cybersecurity Regulating Committee (CRC) released a notification under the Cybersecurity Act on February 22, 2024, setting key operational obligations for critical information infrastructure (CII) organizations. The notification takes effect on June 20, 2024. CII organizations are state or private entities that carry out services related to national security, public services, banking and finance, information technology and telecommunications, transportation and logistics, energy and public utilities, or public health. CII organizations will be identified by the National Cyber Security Committee (NCSC) and notified of their status. The key obligations of CII organizations are laid out below. Reporting to the National Cyber Security Agency (NCSA) CII organizations must provide the following to the NCSA: A list of executive and operational staff, along with emergency contacts who can be reached within 60 minutes in the event of a cyber threat. The NCSA must be notified of any updates to this list within 15 days following any changes. A list of internal departments or individuals who are the responsible persons, owners, and holders of the computer systems, along with emergency contacts who can be reached within 60 minutes in the event of a cyber threat. The NCSA must be notified of any updates to this list at least 7 days prior to any changes (or within 15 days after the change if there is a necessary reason). Policies, Guidelines, and Procedures As specified in the National Cyber Security Committee (NCSC) guidelines, CII organizations must prepare the following internal documents by June 20, 2025: Cybersecurity practice guidelines, consisting of an inspection plan, risk assessment, and incident response plan. Cybersecurity standards framework, consisting of measures for risk identification, risk prevention, threat detection and monitoring, incident responses, and resilience and recovery. CII organizations must also prepare the following: Mechanisms, procedures, and steps for monitoring and detecting
March 29, 2024
Vietnam’s Ministry of Public Security (MPS) is drafting two reports to present to the government in May 2024 to advocate for the development and adoption of a Law on Personal Data Protection. These reports include an assessment of the policy impact of the proposal to develop a personal data protection law, and an assessment of the current state of social relations related to personal data protection. Decree No. 13/2023/ND-CP on Personal Data Protection (PDPD), adopted in April 2023, became the first comprehensive legal instrument on data protection in Vietnam. When the National Assembly was debating its text and adoption in 2022 and 2023, questions were raised as to the status of this new regulation and the legality to adopt a decree before a law. In accordance with the public announcements made throughout the development of the PDPD assuring that a law would be developed at a later stage, the MPS is now advocating for the development of a Personal Data Protection Law and has drafted the two reports pursuant to the Law on the Promulgation of Legal Documents. The main arguments advanced by the MPS in the two reports are as follows: As the right to privacy is enshrined in the Constitution, any restrictions thereof must be made through a law and not a decree. The MPS is notably referring to the lawful basis for processing and limited exceptions to consent under the PDPD. This may be a sign that the MPS intends to widen the exceptions to consent under the new law. The definitions of “personal data” and “personal data protection” need to be harmonized to consolidate the regulatory framework. The MPS indicates that there are 69 legal documents directly related to “personal data protection” in Vietnam with more than 10 different definitions, while “personal information” appears in
March 28, 2024
Recently, Vietnam has witnessed a dramatic increase in cyber fraud, causing significant financial losses and posing a grave threat to both Vietnamese and foreign entities. With the increasing reliance on digital technology and the widespread adoption of online platforms, the country has become fertile ground for cybercriminals to exploit vulnerabilities and conduct various fraudulent activities. This article aims to present an overview of addressing cyber fraud in Vietnam and offers practical advice for businesses to safeguard themselves from becoming victims of such illicit activities.