You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 2, 2026

Thailand Releases New Draft Artificial Intelligence Act

Thailand’s Electronic Transactions Development Agency (ETDA) released a new version of the draft Act on Artificial Intelligence on July 2, 2026, for a public hearing period expected to be approximately 30 days. The draft act adopts a risk-based regulatory approach modeled in part on international frameworks—particularly the EU’s AI Act—while incorporating provisions tailored to Thailand’s regulatory landscape and digital economy objectives. If enacted in its current form, the law would introduce extraterritorial obligations, a tiered risk classification system, strict liability for AI-related damages, and new transparency requirements for AI-generated content.

Scope and Extraterritorial Application

The draft act applies to AI development, deployment, or any other action affecting people in Thailand, even if the action occurs outside the country. Of note:

  • This extraterritorial reach creates compliance obligations for global AI companies whose systems impact Thai residents or consumers, even if the provider has no physical presence in Thailand.
  • Foreign AI providers serving Thai deployers or users must appoint a local coordinator or authorized representative. Depending on the type of AI system, the representative may need full authority to act on behalf of the provider without any limitation of liability.
  • Certain activities are exempt from the draft act’s oversight, including AI used by natural persons solely for personal or household activities, AI for educational research conducted by higher education institutions with ethics committee approval, research and development activities conducted prior to distribution or service provision, and other AI systems prescribed by royal decree.

Risk-Based Classification Framework

The draft act establishes a tiered risk classification system with three main categories:

  • Prohibited AI. The act outright prohibits AI systems employing cognitive-behavioral manipulation using subliminal techniques, AI systems causing unfair broad-scale discrimination from processing irrelevant data, and other categories of serious risk as determined by announcement of a forthcoming committee that will be responsible for national AI planning.
  • High-risk AI. High-risk AI systems are those designated by royal decree as affecting national security, health, environment, energy, telecommunications, transport, or public utilities.
  • Designated AI systems. A subsequent royal decree may additionally require regulator notification, registration, or licensing of certain AI systems before deployment.

Obligations for High-Risk AI System Providers and Deployers

Providers of high-risk AI must develop systems that are efficient and fit for purpose, transparent in operation, subject to meaningful human control, fair and nondiscriminatory, and aligned with foreseeable risks. The regulator may announce risk oversight guidelines covering 13 areas, including risk management, bias prevention, cybersecurity, human oversight, transparency, and complaint handling.

Deployers must implement risk management systems, follow provider instructions, assign capable oversight personnel, mitigate damage from AI-related incidents, retain operational logs for a minimum period (six months under the Thai text), and notify authorities of unforeseen risks.

Transparency Obligations for AI-Generated Content

The draft act introduces transparency requirements for content generation by AI systems:

  • Developers of AI systems capable of generating or modifying images, audio, or video must assess risks, implement mitigation measures, and embed machine-readable marks to identify AI-generated content.
  • Persons who introduce AI-generated content relating to national security, election-related content, investment credibility, food or drug properties, impersonation, or illegal acts into public systems must disclose that it is AI-generated or AI-modified content.
  • Platform providers face specific obligations, including risk assessment, providing reporting channels, verifying AI content, displaying labels, and preparing annual operational summaries.

Data Localization and Contract-Controlled AI Businesses

The draft act grants the forthcoming national AI planning committee authority over data and contracting requirements in sensitive sectors:

  • The committee may designate “contract-controlled AI businesses” applicable to services provided to government or critical infrastructure agencies, and may prescribe mandatory contract terms addressing data processing, risk management, security, modification and termination procedures, and post-termination obligations.
  • The committee may also require data processing within Thailand for AI services of national importance. This introduces uncertainty for cloud-based AI services and may require infrastructure investment in Thailand.

Strict Liability Regime

The draft act imposes joint liability for damages regardless of willful act or negligence—a strict liability standard. Defenses are limited to force majeure, the victim’s own act or omission, or compliance with an official order.

Enforcement and Penalties

The draft act establishes an enforcement framework, with escalating consequences for noncompliance:

  • The regulator may order providers and deployers to rectify insufficient measures.
  • With ministerial approval, the regulator may petition the court to order temporary service suspension, product recall, or deployment suspension.
  • If providers fail to comply, the regulator may petition the court to order ISPs to block AI system dissemination in Thailand.

Administrative fines range from THB 1 million to THB 5 million, depending on the nature of the violation.

AI Product Launches, Regulatory Sandbox, and Self-Regulation

The draft act also establishes a regulatory sandbox framework for testing AI systems in regulated sectors, data-sharing infrastructure through Thailand’s Big Data Institute (a national public organization), and frameworks for self-regulation and best practices. Compliance with self-regulatory best practices may also serve as selection criteria for government investment promotion programs.

Implementation Approach and Next Steps

There will be a phased implementation of the draft act’s measures. Core measures related to the launching of AI products take effect immediately upon publication. Risk control, supervision, and serious incident provisions take effect 180 days after publication, providing a compliance preparation window for affected businesses.

Organizations that develop, deploy, or rely on AI systems affecting persons in Thailand should begin assessing their compliance. They are also encouraged to submit comments on the draft act to the Ministry of Digital Economy and Society during the public hearing period.

RELATED INSIGHTS​ 

August 25, 2026
Thailand’s Electronic Transactions Development Agency (ETDA) is studying potential new regulatory measures for digital platform services that could significantly expand the country’s digital platform governance framework. The ETDA has already conducted one public consultation session on the proposed measures and will hold additional sessions on August 25 and September 2, 2026, covering five types of platform services under the Royal Decree on Digital Platform Services B.E. 2565 (2022). The measures under study are preliminary and may be changed based on consultation outcomes. Foundational Measures Applicable to All Platform Types Seven baseline obligations would apply across all digital platform categories: Transparency reports. Platforms must prepare and publish statistical reports on platform governance activities, including the number of content items removed or restricted and appeal outcomes, in a comparable format. Notice and action mechanism. Platforms must establish minimum standards for channels to report potentially illegal content or goods, conduct case-by-case review, provide explanations when content is removed or restricted, and maintain an internal appeals channel. Rights over automated decision-making. Users significantly affected by automated decisions are granted rights to request an explanation, request human review, and contest the decision. Service level agreements (SLAs). Platforms must publish minimum standards for response times, processing timelines, progress notifications, and remedies for incidents on the platform. Labeling of AI-generated content. Content generated or modified by AI must carry visible labels and machine-readable metadata, with exceptions for creative works that disclose AI use in a nonmisleading manner. Prohibition of dark patterns. User interface designs that deceive, coerce, or distort user decision-making are prohibited, including hiding critical information, creating false urgency, or making service cancellation unreasonably difficult. Business user fairness. Platforms must meet minimum standards for the treatment of sellers, workers, and content creators, including advance notice of term changes, explanation of account suspensions or visibility reductions,
August 20, 2026
Thailand has established a new cross-ministerial committee to oversee data center operations nationwide. On August 5, 2026, the Thai cabinet approved the Prime Minister’s Office Regulation on the Data Center Business Policy Committee, which was published in the Government Gazette on August 13, 2026, and is now in effect. The regulation reflects the government’s policy to elevate Thailand’s digital economy and promote investment in digital infrastructure and AI. The key features of the new committee are outlined below. Definition of “Data Center” Under the regulation, “data center” is defined as a building, premises, or structure that uses electronic equipment to provide services related to the collection, storage, processing, hosting, or transmission of data by electronic means to third parties that are not affiliates, as further determined by the Data Center Business Policy Committee. Committee Composition The committee will be chaired by a deputy prime minister designated by the prime minister, and will have three vice-chairs comprising the ministers of digital economy and society, interior, and energy. The committee also includes 12 ex-officio members: the permanent secretaries of finance, agriculture, natural resources, energy, interior, digital economy, industry, and commerce; the secretaries-general of the Board of Investment (BOI), Energy Regulatory Commission, National Broadcasting and Telecommunications Commission (NBTC), and National Water Resources Office; and the director of the Energy Policy and Planning Office. Up to three expert members may be appointed by the prime minister for two-year terms, renewable once. The secretary-general of the National Economic and Social Development Council (NESDC) serves as member and secretary, with up to two NESDC officials serving as assistant secretaries. Powers and Duties The committee is empowered to: Propose policies, standards, and operational frameworks for government agencies in approving, licensing, issuing investment promotion certificates, or providing services to data center operators in Thailand; Study, analyze, and
August 14, 2026
Thailand’s Office of the Insurance Commission (OIC) has issued guidelines clarifying the boundaries between permissible and prohibited activities for unlicensed individuals—including influencers, bloggers, and content creators—when communicating about insurance products on social media. The Good Practice Guidelines for Persons Not Licensed as Insurance Agents or Brokers Regarding the Dissemination of Insurance Content Through Digital Media B.E. 2569 (2026) took effect on July 24, 2026. Activities Requiring a License The guidelines reserve the following activities for licensed agents and brokers: Soliciting or facilitating insurance contracts. Providing personalized advice on product suitability. Recommending policy cancellation to purchase promoted products. Creating links that facilitate contract formation. Receiving performance-based compensation tied to policies or premiums generated. Importantly, boilerplate disclaimers such as “this is not a recommendation to buy insurance” will not shield individuals from liability if the OIC views the content as personalized advice or solicitation. Permitted Activities Unlicensed persons may present general educational content about insurance—such as explaining terminology, sharing industry statistics, reporting news, or sharing personal experiences—provided the content does not target specific individuals to purchase from specific companies. The guidelines also set out best practices for communication, including presenting information in a fair and balanced manner that covers both benefits and limitations, encouraging consumers to read policy terms and consult licensed professionals, verifying information from credible sources before dissemination, and exercising special care when the audience may include vulnerable groups such as persons aged 60 and older. Prohibited Practices Prohibited practices include fear-based marketing, creating artificial urgency, omitting material limitations, making exaggerated claims, falsely claiming professional credentials, using fake engagement mechanisms, and sharing false or misleading content. The guidelines also reinforce the prohibitions under section 83 of the Life Insurance Act B.E. 2535 and section 78 of the Non-Life Insurance Act B.E. 2535 against soliciting insurance contracts with foreign operators
August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public