You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 15, 2025

Thailand Prepares Startup Promotion Act to Unlock Fundraising and Support

Thailand is taking steps to energize its startup scene by drafting the Startup Promotion Law. This draft law aims to remove obstacles, open new funding opportunities, and provide coordinated government support. The goal is to make it easier for Thailand-based startups to grow and compete on a global stage.

Why Is This Law Needed?

For many years, Thai startups have operated under traditional company law frameworks that were not designed with high-growth businesses or with fundraising opportunities in mind. Restrictions on issuing bonds, offering shares to outside investors, and repurchasing shares for employee incentive programs made it challenging for emerging companies to access capital and accelerate their growth. The draft Startup Promotion Act seeks to remove these obstacles and foster a more competitive, entrepreneur-friendly environment in Thailand.

Who’s in Charge?

Two main organizations will oversee the startup ecosystem:

  • Startup Promotion Committee: This group, to be appointed by the National Science, Research, and Innovation Policy Council, will set national strategies, policies, and budget; design promotional campaign and incentives; and propose further legislative amendments to promote startups.
  • National Innovation Agency (NIA): Under the draft act, the NIA will be the main contact for startups and will serve as the secretariat office of the Startup Promotion Committee, coordinating data, advising startups, maintaining the public registry, and providing funding and investment (grants, repayable grants, loans, and equity) under committee criteria and, where applicable, cabinet approval.

What Startups Are Eligible for Benefits?

To be officially recognized and access benefits, a company must:

  • Be a private limited company less than 10 years old at the time of application. Existing companies that already exceed the 10-year threshold may still apply for startup statues within one year of the law’s enactment, as long as they otherwise still qualify for the new regime.
  • Have average annual revenue not exceeding THB 300 million over the past three years (with possible adjustments for different sectors).
  • Never have declared dividends before.
  • Not be controlled by another company, unless the parent is also a certified startup or a university spinoff focused on commercializing research.

Application Process

Applications must be submitted online to the NIA, and applicants must certify the accuracy of all information provided. Once approved, the company’s name will be published by the NIA on a list categorized by business sector.

Labor Requirement

Within two years of certification, startups must employ a minimum number of qualified Thai workers, as specified by the Startup Promotion Committee.

What Are the Main Benefits for Eligible Startups?

Certified startups will receive special privileges for five years. For categories designated as deep‑tech, the committee may extend the term for a total of up to ten years.

Flexible Corporate Financing

  • Startups can publicly offer shares and issue corporate bonds, which are currently restricted under Thai law.
  • They can allocate new shares to outside investors in addition to existing shareholders.
  • Debt can be converted into equity, making it easier to use modern investment tools like convertible notes.
  • Preferred shares can be converted into ordinary shares.
  • Startups can buy back up to 20% of their own shares as treasury stock. Buybacks are allowed for financial management, fulfilling investment agreements, or acquiring shares from dissenting shareholders. Treasury shares can be used for employee stock option programs (ESOPs) or future investment allocations.

Government Support Measures

  • Tax incentives: Access to tax benefits designed to support startup growth.
  • Immigration benefits: Facilitation under existing immigration and foreign-worker laws; the committee may propose categories of qualified foreign experts and high-skill personnel for certified startups.
  • Government procurement: Where suitable, agencies will treat certified startups’ goods and services as items the state intends to promote under the Public Procurement and Supplies Administration Act.
  • Intellectual property support: Assistance with IP registration and protection.
  • Investment incentives: Eligibility for incentives under the Board of Investment (BOI), Eastern Economic Corridor (EEC), and other competitiveness enhancement initiatives.

The draft law requires the relevant government agencies to assist certified startups in accessing these applicable benefits. The NIA will coordinate information, request documents, and serve as a hub connecting startups to tax, immigration, procurement, IP, BOI/EEC, and other authorities.

How Is Compliance Enforced?

The law sets out clear sanctions and other mechanisms to make sure only eligible startups benefit and that privileges are not abused:

  • Administrative fines: Fines range from THB 20,000 to THB 100,000 for violations such as unlawful public offerings of shares or bonds, holding too many treasury shares, failing to maintain a share register, or not canceling unallocated shares after a project ends. Ongoing violations can result in additional daily fines.
  • Personal liability: Directors, managers, and responsible officers can be held personally liable if a violation occurs due to their actions or inaction.
  • Annual reconfirmation: Startups must reconfirm their eligibility every year. Failure to do so, or providing false information, can result in removal from the official list and loss of benefits.
  • Oversight and monitoring: The NIA monitors compliance and may conduct checks or request more information from certified startups.

Outlook

Thailand’s Startup Promotion Law is a significant step toward modernizing business regulations and supporting local innovation. By making fundraising easier and improving access to government support, the law aims to help startups grow and compete internationally. The draft act has completed public consultation and is now progressing to Parliament, and both startups and investors should keep track of its developments.

RELATED INSIGHTS​ 

June 25, 2025
Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption. The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight. For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues. The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks. Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully. Risks of GenAI Use The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant: Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training.
June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management
June 19, 2025
Thailand’s Electronic Transactions Development Agency (ETDA) has announced plans for increased enforcement of the Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022). The ETDA outlined a comprehensive enforcement framework and review process during an online meeting with digital platform service operators on June 11, 2025. The ETDA’s enhanced enforcement approach includes systematic reviews of notification submissions, formal correction orders, and potential criminal penalties for noncompliance. Digital platform operators should immediately assess their current notification status and prepare for increased regulatory scrutiny. Review and Amendment of Previously Submitted Notification Data The ETDA will begin reviewing operation notification forms and annual reports submitted by digital platform service operators to assess each platform’s risk level and develop tailored regulatory obligations. In this comprehensive review process, the ETDA will: Examine the accuracy and completeness of submitted notification data; Request additional information as needed by phone or email; and Issue formal orders as needed requiring operators to correct or complete missing information. Operators who fail to comply with ETDA orders may face suspension of operations, revocation of their notification receipt, and public disclosure of their noncompliant status on the ETDA’s website. The ETDA will conduct follow-up workshops in July 2025 for operators whose data remains unclear or incomplete. Enforcement Framework and Penalties The ETDA outlined a three-tiered enforcement framework with escalating consequences for different types of violations, as follows: Failure to notify before commencing operations: Operators who begin services without proper notification may face criminal penalties under the Electronic Transactions Act, including up to one year of imprisonment, fines of up to THB 100,000 (approx. USD 3,070), or both. Additional consequences include suspension of operations and potential liability for company directors. Failure to correct or comply with official orders: Noncompliance with ETDA correction
June 13, 2025
In today’s digital age, cyberattacks have become a real threat to organizations worldwide. These attacks can range from phishing and malware to ransomware and distributed denial of service (DDoS) attacks. As the frequency and sophistication of these attacks increase, so does the importance of cybersecurity compliance. In the corporate world, compliance refers to the process of ensuring that a company and its employees adhere to all relevant laws, regulations, standards, and ethical practices—but it should not stop there. Compliance should also encompass asset recovery and disciplinary measures, which can both help organizations address incidents effectively and promote good governance. Cyberattacks are malicious attempts to access or damage a computer system or network, often carried out for financial gain, for political activism, or simply to cause disruption. For instance, a successful attack might involve an attacker creating an email address that closely resembles a legitimate one, perhaps by changing only one or two characters. That email address is then inserted into an existing conversation thread, making it appear as if the user with this email address was already part of the discussion. This tactic can easily deceive a recipient into believing the email was sent from a trusted source, thereby leading them to click on malicious links, provide sensitive information, or even make payments in accordance with the attacker’s request or instructions. Phishing attacks like these are particularly dangerous and can have a serious impact on the ongoing business of a corporation because they exploit the trust and familiarity established in the original email chain. Effective Mitigation Approaches Mechanisms for addressing the aftermath of a crisis provide important recourse to affected organizations, but effective compliance mechanisms can minimize the risk of such crises ever occurring. Companies should therefore prioritize preventative measures and implementation of effective crisis management schemes. Various legal