You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 2, 2026

Thailand Releases New Draft Artificial Intelligence Act

Thailand’s Electronic Transactions Development Agency (ETDA) released a new version of the draft Act on Artificial Intelligence on July 2, 2026, for a public hearing period expected to be approximately 30 days. The draft act adopts a risk-based regulatory approach modeled in part on international frameworks—particularly the EU’s AI Act—while incorporating provisions tailored to Thailand’s regulatory landscape and digital economy objectives. If enacted in its current form, the law would introduce extraterritorial obligations, a tiered risk classification system, strict liability for AI-related damages, and new transparency requirements for AI-generated content.

Scope and Extraterritorial Application

The draft act applies to AI development, deployment, or any other action affecting people in Thailand, even if the action occurs outside the country. Of note:

  • This extraterritorial reach creates compliance obligations for global AI companies whose systems impact Thai residents or consumers, even if the provider has no physical presence in Thailand.
  • Foreign AI providers serving Thai deployers or users must appoint a local coordinator or authorized representative. Depending on the type of AI system, the representative may need full authority to act on behalf of the provider without any limitation of liability.
  • Certain activities are exempt from the draft act’s oversight, including AI used by natural persons solely for personal or household activities, AI for educational research conducted by higher education institutions with ethics committee approval, research and development activities conducted prior to distribution or service provision, and other AI systems prescribed by royal decree.

Risk-Based Classification Framework

The draft act establishes a tiered risk classification system with three main categories:

  • Prohibited AI. The act outright prohibits AI systems employing cognitive-behavioral manipulation using subliminal techniques, AI systems causing unfair broad-scale discrimination from processing irrelevant data, and other categories of serious risk as determined by announcement of a forthcoming committee that will be responsible for national AI planning.
  • High-risk AI. High-risk AI systems are those designated by royal decree as affecting national security, health, environment, energy, telecommunications, transport, or public utilities.
  • Designated AI systems. A subsequent royal decree may additionally require regulator notification, registration, or licensing of certain AI systems before deployment.

Obligations for High-Risk AI System Providers and Deployers

Providers of high-risk AI must develop systems that are efficient and fit for purpose, transparent in operation, subject to meaningful human control, fair and nondiscriminatory, and aligned with foreseeable risks. The regulator may announce risk oversight guidelines covering 13 areas, including risk management, bias prevention, cybersecurity, human oversight, transparency, and complaint handling.

Deployers must implement risk management systems, follow provider instructions, assign capable oversight personnel, mitigate damage from AI-related incidents, retain operational logs for a minimum period (six months under the Thai text), and notify authorities of unforeseen risks.

Transparency Obligations for AI-Generated Content

The draft act introduces transparency requirements for content generation by AI systems:

  • Developers of AI systems capable of generating or modifying images, audio, or video must assess risks, implement mitigation measures, and embed machine-readable marks to identify AI-generated content.
  • Persons who introduce AI-generated content relating to national security, election-related content, investment credibility, food or drug properties, impersonation, or illegal acts into public systems must disclose that it is AI-generated or AI-modified content.
  • Platform providers face specific obligations, including risk assessment, providing reporting channels, verifying AI content, displaying labels, and preparing annual operational summaries.

Data Localization and Contract-Controlled AI Businesses

The draft act grants the forthcoming national AI planning committee authority over data and contracting requirements in sensitive sectors:

  • The committee may designate “contract-controlled AI businesses” applicable to services provided to government or critical infrastructure agencies, and may prescribe mandatory contract terms addressing data processing, risk management, security, modification and termination procedures, and post-termination obligations.
  • The committee may also require data processing within Thailand for AI services of national importance. This introduces uncertainty for cloud-based AI services and may require infrastructure investment in Thailand.

Strict Liability Regime

The draft act imposes joint liability for damages regardless of willful act or negligence—a strict liability standard. Defenses are limited to force majeure, the victim’s own act or omission, or compliance with an official order.

Enforcement and Penalties

The draft act establishes an enforcement framework, with escalating consequences for noncompliance:

  • The regulator may order providers and deployers to rectify insufficient measures.
  • With ministerial approval, the regulator may petition the court to order temporary service suspension, product recall, or deployment suspension.
  • If providers fail to comply, the regulator may petition the court to order ISPs to block AI system dissemination in Thailand.

Administrative fines range from THB 1 million to THB 5 million, depending on the nature of the violation.

AI Product Launches, Regulatory Sandbox, and Self-Regulation

The draft act also establishes a regulatory sandbox framework for testing AI systems in regulated sectors, data-sharing infrastructure through Thailand’s Big Data Institute (a national public organization), and frameworks for self-regulation and best practices. Compliance with self-regulatory best practices may also serve as selection criteria for government investment promotion programs.

Implementation Approach and Next Steps

There will be a phased implementation of the draft act’s measures. Core measures related to the launching of AI products take effect immediately upon publication. Risk control, supervision, and serious incident provisions take effect 180 days after publication, providing a compliance preparation window for affected businesses.

Organizations that develop, deploy, or rely on AI systems affecting persons in Thailand should begin assessing their compliance. They are also encouraged to submit comments on the draft act to the Ministry of Digital Economy and Society during the public hearing period.

RELATED INSIGHTS​ 

July 10, 2025
For companies and individuals doing business in Vietnam, a common question is whether electronic signatures (e-signatures) are legally recognized under Vietnamese law. This matter is governed by Law No. 20/2023/QH15 on Electronic Transactions issued on June 22, 2023 (ETL 2023) and its guiding legal documents such as Decree No. 23/2025/ND-CP dated February 21, 2025, and Circular 06/2024/TT-BTTTT dated July 1, 2024 (Circular 06). Recognition of Validity of E-signatures in Vietnam As a general principle, the ETL 2023 confirms that an e-signature cannot be denied legal validity solely due to its electronic form. The law categorizes e-signatures into three types: Type 1: Specialized e-signatures for organizations Type 2: Public digital signatures for individuals and organizations Type 3: Specialized digital signatures for government agencies Among these types, only secure specialized e-signatures (a secure e-signature of type 1) and digital signatures (type 2) are explicitly granted the same legal validity as handwritten (wet) signatures. This distinction is particularly important in legal disputes and for transactions with government agencies. (For more details, please refer to our previous article.) Domestic e-signatures A domestic organization can choose to use secure specialized e-signatures (type 1) and/or digital signatures (type 2) while a Vietnam-based individual can choose digital signatures (type 2) for their transactions—particularly for those involving government agencies and transactions of high value and complexity which require stronger legal protection. Specialized e-signatures (type 1) can be created by the organizations themselves, and additionally must be “secure” to be explicitly recognized as having the same legal validity as handwritten signatures. For clarity, “secure” specialized e-signatures are those certified (granted a safety certificate) by the Ministry of Science and Technology (MST). (This was formerly the responsibility of the Ministry of Information and Communications, which was merged with MST under Vietnam’s 2025 administrative restructuring.) Digital signatures (type 2) are
July 9, 2025
On June 16, 2025, the National Assembly of Vietnam adopted Law No. 75/2025/QH15 amending and supplementing a number of articles of the 2012 Advertising Law, with an effective date of January 1, 2026. The amended Advertising Law was enacted to further refine the legal framework for advertising activities in the modern era. Online Advertising Under the amended Advertising Law, “online advertising” is defined to encompass not only advertising on electronic newspapers and electronic information pages (as provided under the 2012 Advertising Law) but also advertising on other electronic venues, including social media, online applications, and digital platforms with internet connection. The amended Advertising Law also imposes new requirements for online advertising, including: Identification signs: Advertisements must have clear identifiable signs in numbers, letters, symbols, images, or sounds to distinguish them from non-advertising content. Control features: For advertisements not in fixed areas, there must be easily recognizable features and icons that allow recipients to turn off the advertisement, notify the service provider of violating advertising content, and refuse to view inappropriate advertising content. Linked content: Content in the links embedded in advertisements must comply with the law. Advertising service providers and publishers must have measures to check and monitor the linked content. Advertising on social media: Organizations and enterprises providing social media services must offer users features to distinguish advertising content from other content. Signage for sponsored content: When advertising, users of social media services must use signs to differentiate advertising or sponsored content from other content they provide. In response to the above requirements for online advertising, the amended Advertising Law sets out obligations of advertisers, advertising service providers, advertising publishers, and advertising conveyors in relation to online advertising. Among these, it is notably the responsibility of individuals and organizations engaging in online advertising to prevent and remove violating
July 1, 2025
Now halfway through 2025, Thailand continues to advance in the realm of data privacy, with the ambitious goal of achieving zero data breaches. The Personal Data Protection Committee (PDPC), an independent government body established by the Personal Data Protection Act (PDPA), is taking a more proactive approach, having published several rulings and orders to enhance data protection measures and clarify compliance expectations for businesses. Here is a look back at Thailand’s data privacy developments in the first half of the year. Strengthening Law Enforcement and New Guidance for Compliance Enforcement of existing data protection laws and regulations has taken a step forward this year. Some of the specific initiatives include: Increased enforcement by the PDPC. A key trend to watch from the first half of 2025 is the PDPC’s active enforcement of the PDPA as it intensifies oversight through compliance orders and public warnings against noncompliant organizations while ramping up efforts to prevent and halt the illegal trading of personal data by actively monitoring emerging societal issues. Call center scams and cyber fraud control. Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Orders from the Expert Committee. Several orders issued by the Expert Committee under the PDPA were announced in the first half of this year. These include directives for data controllers to take corrective actions to comply with the PDPA, as well as initiatives to raise awareness of data privacy within organizations, reflecting the regulator’s focus on promoting organizational awareness and compliance. A guideline report summarizing the Expert Committee’s decisions and orders was also published to serve as a reference for compliance. Public issue monitoring. The PDPC has been taking a more proactive approach
June 27, 2025
Three American giants are actively protecting their intellectual property rights against generative AI, as two legal battles commence on both sides of the Atlantic. In the UK, Seattle-based media company Getty Images accuses UK-based Stability AI of multiple IP infringements. In the US, The Walt Disney Company and Universal Studios are teaming up against Midjourney, an AI startup, with their main ground being copyright infringement. Both cases are centered around questions legal minds have been posing since the introduction of generative AI: Is the output of generative AI an infringement? And who is ultimately responsible for the output, the platform or the user? Getty Images v. Stability AI Getty initially filed a claim in the High Court in 2023, which resulted in Stability applying for reverse summary judgment on the grounds that Getty had no real prospect of success, arguing that their operations took place outside the UK. However, the High Court judge hearing the case decided that the claims brought by Getty did have a real prospect of succeeding in court. Despite this, Stability saw a small victory when the court ruled that the representative action brought by Getty would not succeed due to the difficulties in identifying who qualified for the class. The proposed class was comprised of 50,000 rightsholders who alleged their rights were also infringed. Stability was successful in arguing that identifying these individuals would be challenging due to the unclear definition of the class. This current trial is centered around four main grounds: Copyright infringement. Getty accuses Stability of using content that Getty owns or has an exclusive license for when training their model, Stable Diffusion, resulting in the generated output containing substantial parts of that content. Getty is also alleging secondary copyright infringement, arguing that Stability is importing an article into the UK