You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 5, 2026

Thai SEC Heightens Enforcement Against Cross-Border Digital Asset Platforms

Thailand’s Securities and Exchange Commission (SEC) has filed a criminal complaint against a licensed digital asset broker, its overseas trading platform, and its executives for allegedly operating an unlicensed digital asset exchange targeting Thai customers. The case marks an escalation in the SEC’s enforcement efforts against unlicensed offshore platforms that attempt to serve Thai users through local licensed entities.

Criminal Complaint

On February 20, 2026, the SEC filed a criminal complaint with the Economic Crime Suppression Division against a local licensed digital asset broker, its overseas global trading platform, and its executives. The SEC alleges that the parties violated the Digital Asset Business Emergency Decree B.E. 2561 (2018) by cooperatively operating a digital asset exchange business on a cross-border basis since 2023 without the required SEC license.

According to the SEC, the local broker promoted the overseas platform’s services to the public through Thai-language posts on social media channels, with services available exclusively to customers residing in Thailand. Access to the global platform was provided through the local broker’s website and mobile application. Customers who registered for the local broker’s services were automatically granted access to the global platform without having to undergo a separate identity verification process. The SEC also found that the local broker provided back-office system support services to the global platform.

The SEC considers these activities to constitute joint operation of an unlicensed digital asset exchange. The former executives of the local broker are being held liable as the responsible persons during the relevant period. The SEC emphasized that the complaint initiates the criminal process, and the decision to prosecute or convict the accused parties will ultimately be made by law enforcement authorities and the criminal courts.

Platform Blocking

The SEC has also coordinated with the Ministry of Digital Economy and Society to block public access to the global platform under the Emergency Decree on Measures for the Prevention and Suppression of Technology Crime (No. 2) B.E. 2568 (2025). Access is expected to be restricted beginning March 22, 2026. The SEC has cautioned current users in Thailand to take appropriate steps regarding their digital assets held on the platform before the blocking date and reiterated its warning against using the services of unlicensed digital asset operators.

Key Takeaway

This enforcement action reflects the SEC’s heightened scrutiny of unlicensed offshore digital asset platforms and demonstrates that such platforms may not rely on local licensed entities to offer cross-border trading services targeting Thai users.

RELATED INSIGHTS​ 

September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 22, 2025
On September 15, 2025, Vietnam’s Ministry of Science and Technology announced that the country will issue an updated version of its National AI Strategy (first issued in 2021) and its first-ever AI Law by the end of this year. The ministry emphasized that the AI strategy is not just a legal framework, but a commitment to embracing AI to drive Vietnam into a new era. The AI adoption plan is set as a priority of the country, and marks a significant step in shaping Vietnam’s AI governance and innovation landscape. Highlights of the plan include the following: Strategic vision. Vietnam’s ambition is to leverage AI for economic growth, social development, and global competitiveness, under the guiding principle “AI for humans – safe, autonomous, cooperative, inclusive, and sustainable.” AI as national infrastructure. The updated strategy positions AI as core national infrastructure, comparable to electricity or the internet, aiming to provide every citizen with a “personal digital assistant.” Core principles for AI legislation. The AI Law will be built around the following six core principles: Risk-based regulation Transparency and accountability Human-centric development Domestic AI autonomy AI as a driver of sustainable growth Digital sovereignty, with data, infrastructure, and AI technology being three strategic pillars Ethics and openness. A National AI Ethics Code will accompany the upcoming law, aligned with international standards but tailored to the Vietnamese context. The government emphasizes open standards and open-source development. Market development and incentives. The government plans to expand domestic AI adoption, particularly in public services and key industries. The National Technology Innovation Fund (NATIF) will allocate at least 40% of its budget to AI projects, prioritizing SMEs through vouchers for locally developed AI solutions. Background on AI Law Development Regulations on AI are found in various Vietnamese laws and regulations, notably the recently adopted Law
September 17, 2025
Thailand’s Ministry of Finance has introduced a five-year personal income tax exemption on capital gains from the disposal of cryptocurrency or digital tokens. The Ministerial Regulation No. 399, published in the Government Gazette on September 5, 2025, offers the personal income tax exemption for transfers occurring between January 1, 2025, and December 31, 2029. The ministerial regulation was enacted to promote Thailand as a global financial center and digital asset business hub while encouraging increased domestic investment in digital assets. Key Conditions The exemption, which covers capital gains from cryptocurrency and digital token disposals during the specified five-year period, applies only to individuals. Companies that trade in digital assets are not eligible for this tax exemption. With the tax holiday set to expire in 2029 (unless extended), individual traders should plan ahead for postexemption taxation to ensure full compliance with Thailand’s personal income tax requirements. Proper documentation of digital asset transactions during the exemption period will be essential for future tax compliance. For more details on this tax exemption, or on any aspect of Thailand’s tax law and regulations, please contact Saravut Krailadsiri at [email protected] or Papavarin Sarawongsuth at [email protected].
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.