You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 25, 2025

Setting the Ground Rules: The Importance of Implementing Internal GenAI Policies

Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption.

The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight.

For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues.

The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks.

Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully.

Risks of GenAI Use

The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant:

  • Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training. Further, employees may share confidential organization or client information without realizing the implications, increasing the risk of unintentional data leakage and unauthorized disclosure—especially since it can be difficult for organizations to know which GenAI tools employees are using and what types of information they are sharing.
  • Data protection and regulatory compliance: The evolving legal landscape regulating AI creates compliance challenges across multiple jurisdictions. Organizations must navigate complex data protection laws like Thailand’s Personal Data Protection Act (PDPA) and Vietnam’s Personal Data Protection Decree (PDPD), each with different compliance requirements. In the absence of AI-specific legislation, sector-specific regulations also add additional complexity, while unclear regulatory guidance often leaves organizations operating in legal uncertainty, particularly when using AI for decision-making that impacts individuals or when deploying AI systems that interact directly with customers.
  • Intellectual property risks: AI-generated content raises yet-to-be-answered questions about ownership, originality, and copyright infringement. Additionally, proprietary information shared with GenAI tools can be inadvertently incorporated into model training data, potentially compromising trade secrets or violating confidentiality agreements.
  • Governance and accountability: Disjointed and unregulated or inadequately governed GenAI adoption creates oversight gaps, making it difficult to track usage, assign responsibility for outputs, or respond to incidents. In addition, traditional approval processes may not account for AI-assisted work, creating quality control issues.

Developing an Internal GenAI Policy

Forward-thinking organizations across Southeast Asia are establishing internal policies that provide clear direction for both approved and unapproved AI use. These policies form the cornerstone of responsible AI adoption in these organizations by balancing innovation with effective risk management.

An effective AI policy functions as both a protective framework and an enablement tool. Rather than simply listing restrictions, the most effective policies provide practical guidance that empowers employees to leverage AI capabilities while maintaining organizational standards. This approach requires addressing several critical components when developing an AI policy, including, among others:

  • Policy scope: Effective AI policies begin with a clear articulation of their purpose, defining exactly which AI tools and use cases are governed by the policy, including distinguishing between enterprise-approved solutions and general AI tools in the market.
  • Access and authorization: Organizations should define user tiers and access levels, specifying which roles are permitted to use specific AI tools and under what circumstances. This includes establishing approval processes for new AI tool adoption and creating exceptions for specialized use cases.
  • Data governance and privacy protection: As GenAI tools may process personal information, policies must establish strict protocols for data handling. This encompasses defining what types of data can be shared with AI systems and ensuring compliance with regional privacy regulations such as Thailand’s PDPA or Vietnam’s PDPD.
  • Accountability and verification: Policies should also assign internal accountability for AI-generated content and outputs. It is important to establish appropriate review protocols based on the type of AI-assisted work, along with guidelines for transparently disclosing when and how AI was used, especially in client-facing materials or critical decision-making, which may require human validation.
  • Monitoring and incident response: Effective policies establish clear procedures for tracking AI usage, identifying potential misuse or unacceptable output, and responding to security incidents, policy violations, and AI-related incidents such as hallucinations or biased outputs. This includes defining escalation procedures and reporting mechanisms.
  • Vendor management: As organizations increasingly rely on third-party AI services, policies must address vendor evaluation criteria, contract requirements, and ongoing performance monitoring to ensure external AI providers meet legal obligations, data protection requirements, and operational expectations related to security, accountability, and transparency.

Given the rapid pace of AI development, policies should include review cycles, update mechanisms, and processes for incorporating new regulatory requirements or technological capabilities. They should also provide a framework for assessing emerging technologies and adapting policy coverage to reflect evolving risks and capabilities.

Finally, organizations should hold comprehensive education and training sessions to ensure that employees understand both the capabilities and limitations of AI tools, recognize potential risks, and follow organizational policies when using AI in their work.

Proactive Implementation

The GenAI revolution isn’t waiting for businesses to catch up—it’s already here, integrated into daily workflows. Organizations can either proactively implement robust governance frameworks to safely harness AI’s immense potential or risk falling behind in an increasingly complex and fast-moving landscape.

By establishing clear guidelines, accountability structures, and effective risk management protocols, organizations can confidently leverage AI capabilities to encourage innovation while maintaining oversight and minimizing risks. This approach not only builds stakeholder trust and ensures regulatory compliance but also encourages greater AI adoption and transparency among employees. With well-designed guardrails in place, employees can confidently and responsibly integrate GenAI into their work.

Ultimately, organizations that strike the right balance between innovation and responsibility will be best positioned to lead in the GenAI era.

RELATED INSIGHTS​ 

September 24, 2026
Vietnam is implementing and developing a broad package of regulatory reforms that could reshape how IP, data, digital platforms, and product authenticity are regulated and enforced. Several of the key measures have been led by the Ministry of Public Security in its legislative and administrative capacity, as part of a broader government effort. The core reform package consists of four key legal instruments: proposed amendments to the Criminal Code, a proposed new Data Security Law, a draft Decree on Product Identification, Authentication and Traceability, and the newly enacted Decree No. 330/2026/ND-CP. These instruments include rules on criminal enforcement, data security, electronic identification, product identification and traceability, administrative violations, and cybersecurity sanctions. Combined, these measures will affect copyright enforcement, industrial property rights, trade secrets, AI training data, product provenance, online takedowns, valuation of counterfeit goods and electronic evidence. It is worth noting that, in addition to strengthening criminal penalties for IP crimes, Vietnam’s emerging regulatory framework increasingly treats infringement, data misuse, product authentication, and platform-enabled violations as interconnected regulatory and enforcement challenges. For rights holders and foreign investors, this could mean stronger tools against counterfeiting and online infringement, but also more compliance obligations around data, traceability, AI, platform controls and government-facing reporting. Expansion of Criminal IP Enforcement Proposed amendments to Article 225 of the Criminal Code would expand criminal copyright exposure beyond reproduction and distribution to cover large-scale commercial public performance and online communication of works, phonograms and video recordings. This is important because piracy is increasingly about streaming, unauthorized communication, and platform access models rather than physical copying. Aggravated copyright infringement could be subject to up to 10 years in prison for individuals and fines of up to VND 6 billion (about USD 228,300) for commercial legal entities. The amended Article 226 would expand criminal industrial property liability beyond
September 17, 2026
Thailand’s Office of the Consumer Protection Board (OCPB) has released for public comment a draft bill to amend the Consumer Protection Act B.E. 2522 (1979), the country’s foundational consumer protection legislation. The draft amendment aims to modernize the nearly five-decade-old framework to address the rapid growth of digital commerce, online advertising, influencer marketing, and new business models. The public consultation period is open until October 10, 2026. Expanded Definitions Covering Digital Commerce The draft significantly broadens several core definitions to capture modern commercial activities: “Consumer” is expanded to include natural persons and nonprofit juristic persons who purchase or receive services, including those solicited by businesses and end users who do not directly pay for the goods or services. “Business operator” now explicitly covers advertising business operators and hired advertising persons, such as influencers and content creators. “Advertising media” is expanded to include digital platforms, social media, and social media user accounts. “Label” now encompasses electronic labels—symbols, codes, or other electronic formats displaying product information. Influencer and Advertising Disclosure Requirements In addition to these expanded definitions, “hired advertising person for selling goods or services” is a new definition covering influencers, content creators, live streamers, affiliate marketers, and virtual online media operators who receive monetary compensation or other benefits for advertising goods or services. Hired advertising persons—including influencers and content creators—must disclose to consumers that content is advertising and reveal their relationship with the business owner. Disclosure is required when the business owner employs the advertiser, pays or provides other benefits for the advertisement, or provides free or discounted products or services. These requirements apply where consumers would not otherwise know that the business has a connection to the person presenting the content. Labeling Requirements for Importers The draft introduces a clearer labeling obligation for importers of label-controlled goods, who must
September 11, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has published a new five-year master plan that will bring significant regulatory changes to the broadcasting and digital media sectors, including formal licensing requirements for internet-based audiovisual services. The Master Plan for Broadcasting and Television, 3rd Edition (B.E. 2569–2573/2026–2030) was published in the Government Gazette on September 1, 2026, and will affect OTT platforms, internet-based audiovisual service providers, and traditional broadcasters. Licensing Reform The NBTC will develop new licensing frameworks ahead of existing digital television license expirations, which are slated to occur between 2028 and 2030. This creates both uncertainty and opportunity for incumbents and new market entrants. New licensing criteria will also be developed for audiovisual services delivered over the internet, meaning previously unregulated internet-based providers may face licensing, fee, and content obligations for the first time. The plan also calls for a new law to govern converged communications services. OTT Regulation and Content Oversight The plan explicitly acknowledges and aims to lessen the regulatory asymmetry between traditional broadcasters—which are subject to licensing, fees, and content regulation—and internet-based services that currently face fewer obligations. The NBTC intends to develop regulatory frameworks to bring internet-based audiovisual services, including OTT platforms, streaming services, and user-generated content platforms, under content, consumer protection, and licensing requirements. Consumer Protection and Digital Rights The NBTC will strengthen its oversight of broadcasting, television, and telecommunications operators to ensure compliance with consumer protection and personal data protection requirements. This includes updating relevant notifications and orders and more strictly enforcing rules against practices that unfairly exploit consumers. These measures may layer NBTC-specific requirements on top of Thailand’s existing Personal Data Protection Act obligations. Stricter enforcement against practices that exploit consumers is a priority, with particular scrutiny on advertising practices. The NBTC will modernize complaint resolution processes, meaning service providers should
September 7, 2026
On September 4, 2026, Thailand’s prime minister convened the first meeting of the Data Center Business Policy Committee. The committee endorsed a draft policy framework for the data center industry and tasked four subcommittees with developing the standards that would sit beneath it, shifting away from fragmented, agency-by-agency approvals toward a unified national strategy aiming to maximize economic value while managing environmental and infrastructure concerns. Proposed Scope and Pillars of the National Data Center Policy Framework The proposed framework would cover all types of data centers, including internal or captive facilities operated within a company or its affiliates, rather than only commercial third-party providers. If adopted in this form, companies running private data centers purely for internal purposes would also become subject to regulatory oversight. Minimum safety and operational standards would be established, with uniform enforcement across all categories. The committee endorsed a draft policy framework with four key pillars: Industrial classification: Data centers exceeding 2 MW would be classified as industrial operations, which may require factory licenses and environmental impact assessments under the Factory Act. Resource pricing: Utility rates would be structured to reflect both direct and indirect costs, supporting green energy and green data center standards. Centralized screening: A centralized review would evaluate project suitability and resource allocation. Operators may be required to submit proposals through periodic “pitching” rounds, where projects are competitively assessed on their potential economic and strategic benefits to Thailand. Digital ecosystem: The framework would prioritize data sovereignty, tax incentives, and conditions promoting domestic digital businesses, AI, and cloud infrastructure. Multidimensional Evaluation Criteria and Subcommittees Four subcommittees will be established to develop standards responsible for the following dimensions: Economic: Criteria for assessing the economic viability of data center projects, for use in prioritizing data centers based on infrastructure readiness, demand type (including AI factories),