You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 2, 2026

Thailand Releases New Draft Artificial Intelligence Act

Thailand’s Electronic Transactions Development Agency (ETDA) released a new version of the draft Act on Artificial Intelligence on July 2, 2026, for a public hearing period expected to be approximately 30 days. The draft act adopts a risk-based regulatory approach modeled in part on international frameworks—particularly the EU’s AI Act—while incorporating provisions tailored to Thailand’s regulatory landscape and digital economy objectives. If enacted in its current form, the law would introduce extraterritorial obligations, a tiered risk classification system, strict liability for AI-related damages, and new transparency requirements for AI-generated content.

Scope and Extraterritorial Application

The draft act applies to AI development, deployment, or any other action affecting people in Thailand, even if the action occurs outside the country. Of note:

  • This extraterritorial reach creates compliance obligations for global AI companies whose systems impact Thai residents or consumers, even if the provider has no physical presence in Thailand.
  • Foreign AI providers serving Thai deployers or users must appoint a local coordinator or authorized representative. Depending on the type of AI system, the representative may need full authority to act on behalf of the provider without any limitation of liability.
  • Certain activities are exempt from the draft act’s oversight, including AI used by natural persons solely for personal or household activities, AI for educational research conducted by higher education institutions with ethics committee approval, research and development activities conducted prior to distribution or service provision, and other AI systems prescribed by royal decree.

Risk-Based Classification Framework

The draft act establishes a tiered risk classification system with three main categories:

  • Prohibited AI. The act outright prohibits AI systems employing cognitive-behavioral manipulation using subliminal techniques, AI systems causing unfair broad-scale discrimination from processing irrelevant data, and other categories of serious risk as determined by announcement of a forthcoming committee that will be responsible for national AI planning.
  • High-risk AI. High-risk AI systems are those designated by royal decree as affecting national security, health, environment, energy, telecommunications, transport, or public utilities.
  • Designated AI systems. A subsequent royal decree may additionally require regulator notification, registration, or licensing of certain AI systems before deployment.

Obligations for High-Risk AI System Providers and Deployers

Providers of high-risk AI must develop systems that are efficient and fit for purpose, transparent in operation, subject to meaningful human control, fair and nondiscriminatory, and aligned with foreseeable risks. The regulator may announce risk oversight guidelines covering 13 areas, including risk management, bias prevention, cybersecurity, human oversight, transparency, and complaint handling.

Deployers must implement risk management systems, follow provider instructions, assign capable oversight personnel, mitigate damage from AI-related incidents, retain operational logs for a minimum period (six months under the Thai text), and notify authorities of unforeseen risks.

Transparency Obligations for AI-Generated Content

The draft act introduces transparency requirements for content generation by AI systems:

  • Developers of AI systems capable of generating or modifying images, audio, or video must assess risks, implement mitigation measures, and embed machine-readable marks to identify AI-generated content.
  • Persons who introduce AI-generated content relating to national security, election-related content, investment credibility, food or drug properties, impersonation, or illegal acts into public systems must disclose that it is AI-generated or AI-modified content.
  • Platform providers face specific obligations, including risk assessment, providing reporting channels, verifying AI content, displaying labels, and preparing annual operational summaries.

Data Localization and Contract-Controlled AI Businesses

The draft act grants the forthcoming national AI planning committee authority over data and contracting requirements in sensitive sectors:

  • The committee may designate “contract-controlled AI businesses” applicable to services provided to government or critical infrastructure agencies, and may prescribe mandatory contract terms addressing data processing, risk management, security, modification and termination procedures, and post-termination obligations.
  • The committee may also require data processing within Thailand for AI services of national importance. This introduces uncertainty for cloud-based AI services and may require infrastructure investment in Thailand.

Strict Liability Regime

The draft act imposes joint liability for damages regardless of willful act or negligence—a strict liability standard. Defenses are limited to force majeure, the victim’s own act or omission, or compliance with an official order.

Enforcement and Penalties

The draft act establishes an enforcement framework, with escalating consequences for noncompliance:

  • The regulator may order providers and deployers to rectify insufficient measures.
  • With ministerial approval, the regulator may petition the court to order temporary service suspension, product recall, or deployment suspension.
  • If providers fail to comply, the regulator may petition the court to order ISPs to block AI system dissemination in Thailand.

Administrative fines range from THB 1 million to THB 5 million, depending on the nature of the violation.

AI Product Launches, Regulatory Sandbox, and Self-Regulation

The draft act also establishes a regulatory sandbox framework for testing AI systems in regulated sectors, data-sharing infrastructure through Thailand’s Big Data Institute (a national public organization), and frameworks for self-regulation and best practices. Compliance with self-regulatory best practices may also serve as selection criteria for government investment promotion programs.

Implementation Approach and Next Steps

There will be a phased implementation of the draft act’s measures. Core measures related to the launching of AI products take effect immediately upon publication. Risk control, supervision, and serious incident provisions take effect 180 days after publication, providing a compliance preparation window for affected businesses.

Organizations that develop, deploy, or rely on AI systems affecting persons in Thailand should begin assessing their compliance. They are also encouraged to submit comments on the draft act to the Ministry of Digital Economy and Society during the public hearing period.

RELATED INSIGHTS​ 

March 27, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has publicly indicated that it is preparing a new regulatory framework for data center operators that may introduce foreign-ownership restrictions. In particular, the NBTC is considering reclassifying data center operations from a type 1 telecommunications business license to a type 3 license. If implemented, this change would subject data center operators to a significantly more stringent regulatory regime, especially in relation to foreign ownership and control. The NBTC has indicated that it intends to propose a draft framework to the NBTC board. This would be followed by a public hearing process, with a view to implementing the new rules within 2026. Under the Telecommunications Business Act B.E. 2544 (2001), as amended, telecommunications businesses operating under type 3 licenses are subject to foreign ownership restrictions, including a requirement that less than 50% of the total issued shares be held by foreign shareholders. In addition, type 3 licensees are subject to foreign dominance restrictions, which prohibit arrangements that allow foreigners to dominate the business. These foreign dominance restrictions are broad in scope and may capture various forms of direct and indirect control or influence. This includes circumstances in which a foreign national is able to influence or control the formulation of policy, management, or business operations, or the appointment of directors or senior executives. At this stage, the exact scope of the proposed rules remains unclear. Businesses with existing or planned data center operations in Thailand should therefore monitor upcoming NBTC developments in this regard and prepare for the expected public hearing process.
March 27, 2026
Vietnam’s emerging governance framework for artificial intelligence (AI) is developing through a multi-layered structure comprising three components: Policy instruments setting national priorities for AI development; Regulatory framework governing development, provision, deployment and use of AI; and Technical standards and voluntary guidelines. Policy level. At policy level, the foundation for a strategic framework for AI development and governance was laid in 2021 by the National Strategy for Research, Development and Application of AI until 2030, aimed at strengthening the national AI ecosystem and positioning Vietnam as a regional AI innovation hub. Subsequently, resolution No.57-NQ/TW (2024) identified AI as a key driver of science, technology, innovation and national digital transformation. AI was also designated as a strategic technology under decision No.1131/QD-TTg (2025) listing priority technologies across sectors. Regulatory framework. At the legislative level, the new Law on Artificial Intelligence took effect on 1 March 2026, establishing the core regulatory framework governing development, provision, deployment and use of AI systems. Controlled testing for emerging AI technologies is implemented under the Law on Science, Technology and Innovation. The AI Law is expected to be further operationalised through implementing instruments, most notably a draft decree guiding the AI Law, and draft decision of the prime minister identifying high-risk AI systems (both published in February 2026). A decision establishing priority datasets for AI development is also anticipated. Compliance obligations may also arise under sectoral regulatory regimes, including data protection, cybersecurity, banking, consumer protection, e-commerce and intellectual property, particularly where AI systems are used in automated decision-making or data-driven services. Technical standards and non-binding guidelines. Vietnam’s AI governance framework is also supported by technical standards and voluntary guidelines. A key instrument is decision No.1290/QD-BKHCN (2024), providing guidelines for responsible research and development of AI systems, and represents Vietnam’s first national AI ethics code. The Ministry of Science and Technology
March 27, 2026
In response to the rapid advancement of artificial intelligence (AI) and evolving global digital trends, Thailand has undertaken significant efforts to establish a comprehensive national policy framework aimed at fostering an AI ecosystem. This framework seeks to promote the responsible development and deployment of AI technology to enhance Thailand’s economic competitiveness and improve quality of life, with targeted implementation by 2027. In furtherance of this national AI policy, regulatory authorities have initiated efforts to develop and refine the applicable legal framework, including the drafting of Thailand’s first unified AI legislation. Pending the composing and enactment of such comprehensive legislation, sector-specific regulators have proactively issued guidelines applicable to regulated entities within their respective jurisdictions, including financial institutions, banks, insurance companies, securities and derivatives business operators, and digital asset service providers. Concurrently, cross-sectoral regulatory bodies, notably the Personal Data Protection Committee (PDPC) and the National Cyber Security Agency (NCSA), have promulgated guidelines applicable to all business operators within their regulatory purview. While unified AI legislation has not been enacted, the design, development and use of AI in Thailand in various industries is still subject to existing sector-specific legislation. National AI policy The Thai cabinet approved the Thailand National AI Strategy and Action Plan (2022-2027) in July 2022, aiming to establish an AI development and application ecosystem by 2027. The strategy is built around five pillars: Preparing social, ethical, legal and regulatory readiness for AI; Developing national infrastructure; Increasing human capability and AI education; Driving AI technology and innovation; and Promoting AI adoption in public and private sectors. The above-mentioned national AI committee, under the National Digital Economy and Society Committee (NDESC), was established in August 2022, chaired by the prime minister. Comprehensive legislation Following the national AI strategy, the government has been developing comprehensive AI legislation to govern and promote AI
March 20, 2026
Thailand’s Board of Investment (BOI) now requires data center projects to demonstrate measurable benefits for local workforce development, R&D, SME capability, and domestic supply chains to qualify for corporate income tax (CIT) exemptions. BOI Notification No. Por. 3/2569, issued on February 6, 2026, updates the requirements for projects seeking promotion under BOI category 8.2.1 (data centers). All data center projects must now submit and implement plans covering development of Thai human resources and domestic supply chain support before benefiting from any CIT exemption. Human Resources Development Plan The BOI seeks to promote local talent development beyond basic training. Plans must include the following elements: Training for data center design, construction, and operations targeting vocational students, engineering and ICT undergraduates and postgraduates, and energy and building personnel in Thailand. Joint curricula with Thai universities and technical institutes. Collaborative R&D with Thai nationals or institutions in areas including AI, resource allocation, high-performance computing, and data center hardware and systems. Thai SME upskilling in electrical and energy systems and IT services. Domestic Supply Chain Support Plan Plans must demonstrate knowledge transfer in design, construction, cooling, security, and power and water management. Projects must also include usage or installation of domestically manufactured equipment or engage specialist domestic entities. Criteria for BOI Evaluation The BOI will assess data center operators’ eligibility for CIT incentives based on two criteria: Scale requirement: Training and joint-curriculum initiatives must reach a total participants equal to at least 10 times the project headcount and run for the duration of the CIT incentive. If this threshold is not met, the applicant must also implement continuous R&D or SME skills-development plans throughout the incentive period. Substantiality test: Supply-chain plans must be substantive, meet industry standards, and show measurable development of the domestic digital and data center supply base. To ensure compliance,