You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 25, 2025

Setting the Ground Rules: The Importance of Implementing Internal GenAI Policies

Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption.

The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight.

For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues.

The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks.

Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully.

Risks of GenAI Use

The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant:

  • Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training. Further, employees may share confidential organization or client information without realizing the implications, increasing the risk of unintentional data leakage and unauthorized disclosure—especially since it can be difficult for organizations to know which GenAI tools employees are using and what types of information they are sharing.
  • Data protection and regulatory compliance: The evolving legal landscape regulating AI creates compliance challenges across multiple jurisdictions. Organizations must navigate complex data protection laws like Thailand’s Personal Data Protection Act (PDPA) and Vietnam’s Personal Data Protection Decree (PDPD), each with different compliance requirements. In the absence of AI-specific legislation, sector-specific regulations also add additional complexity, while unclear regulatory guidance often leaves organizations operating in legal uncertainty, particularly when using AI for decision-making that impacts individuals or when deploying AI systems that interact directly with customers.
  • Intellectual property risks: AI-generated content raises yet-to-be-answered questions about ownership, originality, and copyright infringement. Additionally, proprietary information shared with GenAI tools can be inadvertently incorporated into model training data, potentially compromising trade secrets or violating confidentiality agreements.
  • Governance and accountability: Disjointed and unregulated or inadequately governed GenAI adoption creates oversight gaps, making it difficult to track usage, assign responsibility for outputs, or respond to incidents. In addition, traditional approval processes may not account for AI-assisted work, creating quality control issues.

Developing an Internal GenAI Policy

Forward-thinking organizations across Southeast Asia are establishing internal policies that provide clear direction for both approved and unapproved AI use. These policies form the cornerstone of responsible AI adoption in these organizations by balancing innovation with effective risk management.

An effective AI policy functions as both a protective framework and an enablement tool. Rather than simply listing restrictions, the most effective policies provide practical guidance that empowers employees to leverage AI capabilities while maintaining organizational standards. This approach requires addressing several critical components when developing an AI policy, including, among others:

  • Policy scope: Effective AI policies begin with a clear articulation of their purpose, defining exactly which AI tools and use cases are governed by the policy, including distinguishing between enterprise-approved solutions and general AI tools in the market.
  • Access and authorization: Organizations should define user tiers and access levels, specifying which roles are permitted to use specific AI tools and under what circumstances. This includes establishing approval processes for new AI tool adoption and creating exceptions for specialized use cases.
  • Data governance and privacy protection: As GenAI tools may process personal information, policies must establish strict protocols for data handling. This encompasses defining what types of data can be shared with AI systems and ensuring compliance with regional privacy regulations such as Thailand’s PDPA or Vietnam’s PDPD.
  • Accountability and verification: Policies should also assign internal accountability for AI-generated content and outputs. It is important to establish appropriate review protocols based on the type of AI-assisted work, along with guidelines for transparently disclosing when and how AI was used, especially in client-facing materials or critical decision-making, which may require human validation.
  • Monitoring and incident response: Effective policies establish clear procedures for tracking AI usage, identifying potential misuse or unacceptable output, and responding to security incidents, policy violations, and AI-related incidents such as hallucinations or biased outputs. This includes defining escalation procedures and reporting mechanisms.
  • Vendor management: As organizations increasingly rely on third-party AI services, policies must address vendor evaluation criteria, contract requirements, and ongoing performance monitoring to ensure external AI providers meet legal obligations, data protection requirements, and operational expectations related to security, accountability, and transparency.

Given the rapid pace of AI development, policies should include review cycles, update mechanisms, and processes for incorporating new regulatory requirements or technological capabilities. They should also provide a framework for assessing emerging technologies and adapting policy coverage to reflect evolving risks and capabilities.

Finally, organizations should hold comprehensive education and training sessions to ensure that employees understand both the capabilities and limitations of AI tools, recognize potential risks, and follow organizational policies when using AI in their work.

Proactive Implementation

The GenAI revolution isn’t waiting for businesses to catch up—it’s already here, integrated into daily workflows. Organizations can either proactively implement robust governance frameworks to safely harness AI’s immense potential or risk falling behind in an increasingly complex and fast-moving landscape.

By establishing clear guidelines, accountability structures, and effective risk management protocols, organizations can confidently leverage AI capabilities to encourage innovation while maintaining oversight and minimizing risks. This approach not only builds stakeholder trust and ensures regulatory compliance but also encourages greater AI adoption and transparency among employees. With well-designed guardrails in place, employees can confidently and responsibly integrate GenAI into their work.

Ultimately, organizations that strike the right balance between innovation and responsibility will be best positioned to lead in the GenAI era.

RELATED INSIGHTS​ 

January 29, 2026
Following the recent enactment of a comprehensive legal framework addressing sexual harassment, Thailand has launched a fast-track judicial process enabling victims of online sexual harassment to obtain court orders suspending and removing obscene content from the internet. On January 26, 2026, the Office of the Judiciary introduced the “Take It Down” procedure through the Court Integral Online Service (CIOS) platform, providing victims with their first direct, expedited pathway to halt the spread of online content that violates the new legal provisions against sexual harassment. This new remedy stems from section 284/4 of the Penal Code, introduced through the Act Amending the Penal Code (No. 30) B.E. 2568, which took effect on December 30, 2025. Under section 284/4, an injured person or a competent official may petition the court to suspend dissemination of violating data and remove the data from computer systems within a court-specified period. The court may also direct system controllers, service providers, or competent authorities to carry out the order and report back within 15 days. Filing through the CIOS Platform The CIOS platform serves as the primary electronic channel for these petitions. Key features include: Individuals can file online without appearing in person and may submit petitions at any time the system is available. Users must complete digital identity verification via the ThaID application to access the CIOS. Petitions under section 284/4 are limited to requests to suspend or remove violating content. Claims for monetary damages must be pursued separately, including via separate proceedings or prefiling mediation. Streamlined Review Process The submission workflow is end-to-end electronic, and the system provides step-by-step guidance. After submission, court staff review the petition before presenting it to a judge for consideration. The court may conduct an online inquiry to obtain additional information, and in-person attendance is required only if deemed
January 22, 2026
On January 20, 2026, Vietnam’s Ministry of Finance (MOF) issued Decision No. 96/QD-BTC to formally launch pilot administrative procedures for licensing crypto asset trading market services in Vietnam. The decision took immediate effect and implements the government’s pilot crypto asset market program under Resolution No. 05/2025/NQ-CP. Notably, competent authorities have now begun accepting license applications, marking the first time Vietnam has operationalized a licensing pathway for crypto trading market operators. Administrative Procedures and Applications The decision stipulates procedures for (i) granting, (ii) adjusting, and (iii) revoking licenses to provide services for organizing crypto asset trading markets. It provides detailed, step-by-step guidance for each procedure, including dossier composition, internal review stages, coordination mechanisms, and statutory timelines. These procedures apply specifically to entities seeking to organize and operate crypto asset trading markets within Vietnam’s pilot regulatory framework. The MOF is the authority responsible for reviewing and deciding on the above procedures, with the State Securities Commission acting as the receiving, coordinating, and procedural focal point. For licensing applications, the MOF will coordinate with multiple authorities, including the State Bank of Vietnam and the Ministry of Public Security, particularly in relation to anti-money laundering, cybersecurity, system safety, and risk control requirements. Applications may be submitted in person, by post, or electronically via the National Public Service Portal or the administrative procedure information system, in line with applicable regulations. Statutory processing timelines vary depending on the specific procedure and stage involved. For applications to obtain a license to organize a crypto asset trading market, the process is conducted in multiple phases: The MOF will issue an initial written response within 20 working days from receipt of a complete and valid initial dossier, following which, upon submission of the full set of required documents, the MOF will complete substantive review and issue the license
January 21, 2026
On January 16, 2026, Thailand’s Electronic Transactions Committee released for public comment a draft notification that would require social media platforms operating in Thailand to implement identity verification for all user accounts and advertisers, with enhanced scrutiny for high-risk advertising activities. If finalized in its current form, the Notification on Measures to Prevent Technology Crime for Social Media Service Providers would take effect 180 days after publication in the Government Gazette, fundamentally changing how platforms verify users and monetize advertising services. The public comment period is open through February 2, 2026. Mandatory User and Advertiser Identity Verification The draft establishes a universal requirement that all social media service providers implement identity verification measures for every user account. The draft imposes stricter verification obligations for advertisers than for general users. Before publishing any advertisement, platforms must verify the advertiser’s identity at a level sufficient to identify the advertiser, unless the advertiser has previously completed verification. Risk-Based Advertisement Verification The identification requirements for advertisers will be more stringent in the following cases: The advertiser has a history of user complaints or has previously violated the platform’s terms of service. The advertisement involves finance, investment, loans, sensitive personal data, or content flagged as potentially involving cybercrime. The advertisement specifically targets vulnerable groups, such as the elderly or other at-risk demographics. In such cases, platforms must conduct identity verification using government-issued identification documents and must confirm the accuracy, authenticity, and currency of these documents with the issuing government agencies. Alternatively, platforms may verify identity through an eligible digital identity verification and authentication system provider. Information Retention Platforms must retain specific information for each advertiser, including the name of the individual or juristic person and any representatives, government-issued identification documents such as ID cards, passports, or certificates of incorporation, and reachable contact information including
January 21, 2026
Spurred by global geopolitics and Canada’s Indo-Pacific Strategy, which aims to forge deeper ties with ASEAN, Canadian companies have been showing growing interest in Thailand and Southeast Asia in recent years. To understand the opportunities offered by the region, we sat down with Andrew Stoutley, a Toronto native and the chief operating officer of Tilleke & Gibbins, a leading Southeast Asian regional law firm with over 130 years of history in Thailand. Q: Why are Canadian companies looking at Thailand and Southeast Asia right now? A: Two reasons stand out. First, diversification has moved up the agenda. Many Canadian companies want options outside North America due to tariff volatility and policy uncertainty in the United States, as well as questions around the next Canada–United States–Mexico Agreement mandatory joint review. At the same time, the shift of global production from China to Southeast Asia is accelerating, driven by rising costs, geopolitics, and the need to avoid overreliance on a single market. As a result, Canadian companies are looking for a second production base or a regional hub, and Thailand and its neighbors are natural choices given their manufacturing depth, location, and established supply chains. Second, Canada’s own efforts in the region are gaining traction. The Indo-Pacific Strategy has led to more on-the-ground support, including larger trade missions, upgraded diplomatic posts, and new financing options. Export Development Canada (EDC) now has a presence in Bangkok, giving Canadian companies a direct line to financing and insurance in Thailand. There’s also steady progress on trade frameworks like the recently signed Canada–Indonesia Comprehensive Economic Partnership Agreement (which will come into effect pending domestic procedures), ongoing negotiations of a Canada–ASEAN FTA, and the exciting announcement about the launch of negotiations of a Canada–Thailand FTA. Together, these developments have the potential to make it much easier