You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 25, 2025

Setting the Ground Rules: The Importance of Implementing Internal GenAI Policies

Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption.

The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight.

For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues.

The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks.

Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully.

Risks of GenAI Use

The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant:

  • Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training. Further, employees may share confidential organization or client information without realizing the implications, increasing the risk of unintentional data leakage and unauthorized disclosure—especially since it can be difficult for organizations to know which GenAI tools employees are using and what types of information they are sharing.
  • Data protection and regulatory compliance: The evolving legal landscape regulating AI creates compliance challenges across multiple jurisdictions. Organizations must navigate complex data protection laws like Thailand’s Personal Data Protection Act (PDPA) and Vietnam’s Personal Data Protection Decree (PDPD), each with different compliance requirements. In the absence of AI-specific legislation, sector-specific regulations also add additional complexity, while unclear regulatory guidance often leaves organizations operating in legal uncertainty, particularly when using AI for decision-making that impacts individuals or when deploying AI systems that interact directly with customers.
  • Intellectual property risks: AI-generated content raises yet-to-be-answered questions about ownership, originality, and copyright infringement. Additionally, proprietary information shared with GenAI tools can be inadvertently incorporated into model training data, potentially compromising trade secrets or violating confidentiality agreements.
  • Governance and accountability: Disjointed and unregulated or inadequately governed GenAI adoption creates oversight gaps, making it difficult to track usage, assign responsibility for outputs, or respond to incidents. In addition, traditional approval processes may not account for AI-assisted work, creating quality control issues.

Developing an Internal GenAI Policy

Forward-thinking organizations across Southeast Asia are establishing internal policies that provide clear direction for both approved and unapproved AI use. These policies form the cornerstone of responsible AI adoption in these organizations by balancing innovation with effective risk management.

An effective AI policy functions as both a protective framework and an enablement tool. Rather than simply listing restrictions, the most effective policies provide practical guidance that empowers employees to leverage AI capabilities while maintaining organizational standards. This approach requires addressing several critical components when developing an AI policy, including, among others:

  • Policy scope: Effective AI policies begin with a clear articulation of their purpose, defining exactly which AI tools and use cases are governed by the policy, including distinguishing between enterprise-approved solutions and general AI tools in the market.
  • Access and authorization: Organizations should define user tiers and access levels, specifying which roles are permitted to use specific AI tools and under what circumstances. This includes establishing approval processes for new AI tool adoption and creating exceptions for specialized use cases.
  • Data governance and privacy protection: As GenAI tools may process personal information, policies must establish strict protocols for data handling. This encompasses defining what types of data can be shared with AI systems and ensuring compliance with regional privacy regulations such as Thailand’s PDPA or Vietnam’s PDPD.
  • Accountability and verification: Policies should also assign internal accountability for AI-generated content and outputs. It is important to establish appropriate review protocols based on the type of AI-assisted work, along with guidelines for transparently disclosing when and how AI was used, especially in client-facing materials or critical decision-making, which may require human validation.
  • Monitoring and incident response: Effective policies establish clear procedures for tracking AI usage, identifying potential misuse or unacceptable output, and responding to security incidents, policy violations, and AI-related incidents such as hallucinations or biased outputs. This includes defining escalation procedures and reporting mechanisms.
  • Vendor management: As organizations increasingly rely on third-party AI services, policies must address vendor evaluation criteria, contract requirements, and ongoing performance monitoring to ensure external AI providers meet legal obligations, data protection requirements, and operational expectations related to security, accountability, and transparency.

Given the rapid pace of AI development, policies should include review cycles, update mechanisms, and processes for incorporating new regulatory requirements or technological capabilities. They should also provide a framework for assessing emerging technologies and adapting policy coverage to reflect evolving risks and capabilities.

Finally, organizations should hold comprehensive education and training sessions to ensure that employees understand both the capabilities and limitations of AI tools, recognize potential risks, and follow organizational policies when using AI in their work.

Proactive Implementation

The GenAI revolution isn’t waiting for businesses to catch up—it’s already here, integrated into daily workflows. Organizations can either proactively implement robust governance frameworks to safely harness AI’s immense potential or risk falling behind in an increasingly complex and fast-moving landscape.

By establishing clear guidelines, accountability structures, and effective risk management protocols, organizations can confidently leverage AI capabilities to encourage innovation while maintaining oversight and minimizing risks. This approach not only builds stakeholder trust and ensures regulatory compliance but also encourages greater AI adoption and transparency among employees. With well-designed guardrails in place, employees can confidently and responsibly integrate GenAI into their work.

Ultimately, organizations that strike the right balance between innovation and responsibility will be best positioned to lead in the GenAI era.

RELATED INSIGHTS​ 

May 5, 2025
On April 29, 2025, the government of Vietnam promulgated Decree No. 94/2025/ND-CP with regulations on a controlled “sandbox” for innovative fintech solutions in the banking sector (Decree 94). The decree aims to promote innovation, modernize banking, and enhance financial inclusion while assessing risks and benefits of fintech solutions in a controlled testing environment. Fintech Sandbox Currently, the fintech sandbox focuses on three specific areas: Credit scoring Open API data sharing Peer-to-peer (P2P) lending Eligible participants for the fintech sandbox include: Credit institutions and foreign bank branches (except for P2P lending) Fintech companies operating in Vietnam Cross-border supply by foreign providers is not included in the sandbox framework. Eligible participants are permitted to provide fintech solutions only within the scope specified in the Certificate of Sandbox Participation issued by the State Bank of Vietnam in consultation with other ministries. P2P lending companies face specific restrictions within the fintech sandbox, including prohibitions against: Providing security for customer loans Operating as a customer (i.e., P2P lender or borrower) Providing P2P lending solutions to pawn shops The maximum sandbox period is two years, with the possibility of extension as permitted by law. The outcomes of the fintech sandbox will serve as a practical basis for authorities to develop and refine future fintech regulations. It is worth noting that participation in the sandbox does not guarantee that participants will meet relevant business and investment conditions that may be stipulated in future regulations. Decree 94 will take effect on July 1, 2025, signaling that the Vietnamese government intends to take a proactive approach to fostering fintech development. Implications Parties interested in participating in the fintech sandbox should begin preparing now to be ready to apply for a Certificate of Sandbox Participation when the decree takes effect.
May 2, 2025
Attorneys from Tilleke & Gibbins have updated the latest edition of Doing Business in Thailand, a Q&A-style guide from Thomson Reuters Practical Law that offers an overview of key legal considerations for companies operating in jurisdictions worldwide. The contribution outlines the country’s legal and regulatory framework for foreign investment and business operations and reflects the latest legislative developments. The chapter addresses the following core topics: Legal system: Structure of the courts and the codified nature of Thai law. Foreign investment: Business restrictions under the Foreign Business Act, sector-specific regulations, exchange control rules, and investment incentives. Business vehicles: Overview of partnerships, private and public limited companies, and other legal entities. Employment: Labor protections, employment contracts, foreign worker requirements, and termination procedures. Tax: Corporate and personal income tax, indirect taxes, and tax obligations for residents and non-residents. Intellectual property: Registration and enforcement of patents, trademarks, designs, and copyrights. Data protection: Key provisions of the Personal Data Protection Act and related compliance obligations. Competition law: Regulatory framework under the Trade Competition Act. Anti-bribery and corruption: Relevant legislation and enforcement mechanisms. E-commerce and digital business: Legal regime for online transactions and digital platforms. Marketing and advertising: Consumer protection laws and regulations affecting advertising and marketing practices. Product regulation and liability: Safety standards, liability regimes, and roles of enforcement authorities. Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
April 30, 2025
With a favorable crypto climate from the Trump administration in the United States, Thailand is ready for digital asset platforms and has market appetite. This article highlights the country’s regulatory initiatives supporting the growth of digital assets like crypto, stablecoins, and smart contracts, along with efforts to establish clear oversight. Bank of Thailand Sandbox Stablecoins used as a medium of payment, particularly those pegged to the Thai baht (THB) for public use, are considered as mirroring fiat currency, which violates the Currency Act B.E. 2501 (1958). These can also be classified as e-money under the Payment Systems Act B.E. 2560 (2017). The Bank of Thailand (BOT) urges issuers to engage in preconsultation prior to implementation, due to concerns about stablecoins being used in place of THB currency. Other FX- or asset-backed stablecoins are not recognized as legal tender under Thai law, and users must bear their own risks. The BOT recognizes the potential and benefits of these technologies in reducing operational costs for financial service providers and addressing the needs of financial service users. Consequently, the BOT issued a sandbox framework in June 2024. In particular, the enhanced regulatory sandbox allows nonlicensed entities to test financial innovations in controlled conditions. These tests must have a clearly defined duration (usually under one year) and involve a limited user group with an exit strategy. Several programmable payment projects—automated transactions with predefined conditions for the payment of goods and services—were piloted under this sandbox, which closed for applications in September 2024. Eight participants are planning to launch their test runs this year, some of which include asset tokenization or exchange global stablecoins in their programmable payment projects. Thai Securities and Exchange Commission Sandbox Given that digital asset businesses fall under the Royal Decree on Digital Asset Businesses B.E. 2561 (2018), supervised by
April 30, 2025
The Bank of Thailand (BOT) is accepting public comments until May 2, 2025, on three draft notifications that will institute an enhanced supervision scheme and impose additional requirements for systemically important retail payment system (SIRPS) operators to align with international standards and encourage open infrastructure and competition. The SIRPS operators will be determined by the BOT from the “designated payment system operators” under the Payment Systems Act B.E. 2560 (2017). SIRPS Designation The BOT will announce a list of payment system operators designated as SIRPS operators and thus subject to enhanced supervision. The BOT will evaluate whether the payment system operator should be deemed a SIRPS operator when it meets the criteria in either the BOT’s quantitative or qualitative assessments, which cover the following: Quantitative assessment: The payment system’s transaction values, market share, cross-border payment network scale and value, and settlement with other financial market infrastructure. Qualitative assessment: The payment system’s function as a part of the country’s payment system infrastructure, the significance of the system users’ roles in the payment services, the substitutability of the payment system, and the impact level on the public and users in the event of an emergency or system suspension. Supervision of SIRPS Business Operations SIRPS operators will be subject to heightened supervision in three areas, in addition to various BOT regulations on designated payment system supervision, as follows: Governance: SIRPS operators will be required to have a balanced board composition with an independent director and directors with varied expertise, establish subcommittees to assist the board in supervising the operator’s compliance with its policy and strategy, and have senior executives overseeing risk and technology security separately from the executives overseeing business operations. Risk management and security: SIRPS operators will be required to have comprehensive risk management to ensure system stability and security. This