You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 2, 2026

Thailand Releases New Draft Artificial Intelligence Act

Thailand’s Electronic Transactions Development Agency (ETDA) released a new version of the draft Act on Artificial Intelligence on July 2, 2026, for a public hearing period expected to be approximately 30 days. The draft act adopts a risk-based regulatory approach modeled in part on international frameworks—particularly the EU’s AI Act—while incorporating provisions tailored to Thailand’s regulatory landscape and digital economy objectives. If enacted in its current form, the law would introduce extraterritorial obligations, a tiered risk classification system, strict liability for AI-related damages, and new transparency requirements for AI-generated content.

Scope and Extraterritorial Application

The draft act applies to AI development, deployment, or any other action affecting people in Thailand, even if the action occurs outside the country. Of note:

  • This extraterritorial reach creates compliance obligations for global AI companies whose systems impact Thai residents or consumers, even if the provider has no physical presence in Thailand.
  • Foreign AI providers serving Thai deployers or users must appoint a local coordinator or authorized representative. Depending on the type of AI system, the representative may need full authority to act on behalf of the provider without any limitation of liability.
  • Certain activities are exempt from the draft act’s oversight, including AI used by natural persons solely for personal or household activities, AI for educational research conducted by higher education institutions with ethics committee approval, research and development activities conducted prior to distribution or service provision, and other AI systems prescribed by royal decree.

Risk-Based Classification Framework

The draft act establishes a tiered risk classification system with three main categories:

  • Prohibited AI. The act outright prohibits AI systems employing cognitive-behavioral manipulation using subliminal techniques, AI systems causing unfair broad-scale discrimination from processing irrelevant data, and other categories of serious risk as determined by announcement of a forthcoming committee that will be responsible for national AI planning.
  • High-risk AI. High-risk AI systems are those designated by royal decree as affecting national security, health, environment, energy, telecommunications, transport, or public utilities.
  • Designated AI systems. A subsequent royal decree may additionally require regulator notification, registration, or licensing of certain AI systems before deployment.

Obligations for High-Risk AI System Providers and Deployers

Providers of high-risk AI must develop systems that are efficient and fit for purpose, transparent in operation, subject to meaningful human control, fair and nondiscriminatory, and aligned with foreseeable risks. The regulator may announce risk oversight guidelines covering 13 areas, including risk management, bias prevention, cybersecurity, human oversight, transparency, and complaint handling.

Deployers must implement risk management systems, follow provider instructions, assign capable oversight personnel, mitigate damage from AI-related incidents, retain operational logs for a minimum period (six months under the Thai text), and notify authorities of unforeseen risks.

Transparency Obligations for AI-Generated Content

The draft act introduces transparency requirements for content generation by AI systems:

  • Developers of AI systems capable of generating or modifying images, audio, or video must assess risks, implement mitigation measures, and embed machine-readable marks to identify AI-generated content.
  • Persons who introduce AI-generated content relating to national security, election-related content, investment credibility, food or drug properties, impersonation, or illegal acts into public systems must disclose that it is AI-generated or AI-modified content.
  • Platform providers face specific obligations, including risk assessment, providing reporting channels, verifying AI content, displaying labels, and preparing annual operational summaries.

Data Localization and Contract-Controlled AI Businesses

The draft act grants the forthcoming national AI planning committee authority over data and contracting requirements in sensitive sectors:

  • The committee may designate “contract-controlled AI businesses” applicable to services provided to government or critical infrastructure agencies, and may prescribe mandatory contract terms addressing data processing, risk management, security, modification and termination procedures, and post-termination obligations.
  • The committee may also require data processing within Thailand for AI services of national importance. This introduces uncertainty for cloud-based AI services and may require infrastructure investment in Thailand.

Strict Liability Regime

The draft act imposes joint liability for damages regardless of willful act or negligence—a strict liability standard. Defenses are limited to force majeure, the victim’s own act or omission, or compliance with an official order.

Enforcement and Penalties

The draft act establishes an enforcement framework, with escalating consequences for noncompliance:

  • The regulator may order providers and deployers to rectify insufficient measures.
  • With ministerial approval, the regulator may petition the court to order temporary service suspension, product recall, or deployment suspension.
  • If providers fail to comply, the regulator may petition the court to order ISPs to block AI system dissemination in Thailand.

Administrative fines range from THB 1 million to THB 5 million, depending on the nature of the violation.

AI Product Launches, Regulatory Sandbox, and Self-Regulation

The draft act also establishes a regulatory sandbox framework for testing AI systems in regulated sectors, data-sharing infrastructure through Thailand’s Big Data Institute (a national public organization), and frameworks for self-regulation and best practices. Compliance with self-regulatory best practices may also serve as selection criteria for government investment promotion programs.

Implementation Approach and Next Steps

There will be a phased implementation of the draft act’s measures. Core measures related to the launching of AI products take effect immediately upon publication. Risk control, supervision, and serious incident provisions take effect 180 days after publication, providing a compliance preparation window for affected businesses.

Organizations that develop, deploy, or rely on AI systems affecting persons in Thailand should begin assessing their compliance. They are also encouraged to submit comments on the draft act to the Ministry of Digital Economy and Society during the public hearing period.

RELATED INSIGHTS​ 

July 17, 2025
On July 9, 2025, Thailand issued a notification that introduces comprehensive operational requirements for digital platform service providers operating as goods marketplaces, effective December 31, 2025 (i.e., 180 days after its publication in the Government Gazette). The regulation’s official name is Notification of the Electronic Transactions Committee Re: Other Actions for Digital Platform Service Operators in the Category of Marketplace for Goods with Specific Characteristics under Section 18(2) of the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification B.E. 2565 (2022), B.E. 2568 (2025). Scope of Application The notification applies exclusively to goods marketplace operators formally designated by the Electronic Transactions Development Agency (ETDA), which on the same day designated 19 platforms that had previously notified the ETDA of their operations. The goods requiring enhanced oversight by these operators are limited to those regulated by the Thai Food and Drug Administration (FDA) and the Thai Industrial Standards Institute (TISI). Development from Earlier Draft An earlier draft of the notification had included a requirement for offshore platforms to establish a local entity, but this requirement was removed from the final notification. Key Obligations Despite the removal of the local entity requirement, the notification imposes a range of additional obligations on designated goods marketplace operators: Transparency. Operators must implement robust transparency measures, including clear, accessible, and understandable disclosures to users in Thai. These disclosures must cover all relevant terms and conditions, comprehensive product information, and complaint management procedures. Operators must also submit an annual compliance report to the ETDA within 60 days after the end of their accounting period, including statistics on regulated goods. Business user registration and identity verification. Before permitting the sale or advertisement of regulated goods, operators must collect and verify business user information, including contact details, identification documents, registration
July 15, 2025
Thailand has established new safe harbor rules that require social media platforms to remove specified content within 24 hours of government notification. On July 5, 2025, the Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers was issued and took effect. This followed a hearing in May 2025 where only a select group of social media and online communication platform operators were invited to attend and comment on draft rules that could exempt social media platform operators from joint liability under the amended Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes in cases involving victims of technological crimes. Safe Harbor Rules The notification stipulates procedures that must be followed in order to receive the protection of the safe harbor rules. Upon being notified by the Division of Prevention and Suppression of Cybercrime, Office of the Permanent Secretary of the Ministry of Digital Economy and Society (MDES) of the presence of false or misleading information that may lead to the commission of a technological crime, social media service providers must immediately take down the specified content, with a maximum allowable turnaround time of 24 hours from the time of receiving the notification. Social media service providers are required to promptly report the outcome of each takedown to the MDES Division of Prevention and Suppression. This shift in Thailand’s regulatory approach to social media content moderation establishes clear government oversight mechanisms while providing platforms with liability protection for compliance. As the new rules took immediate effect, social media platforms need to ensure that they have adequate systems and processes in place to comply with the requirements.
July 11, 2025
Vietnam’s recent embrace of “regulatory sandboxes” reflects a deliberate policy choice to balance the need for robust oversight with an equally pressing imperative to catalyze innovation. A sandbox is a controlled, time-bound framework in which businesses may pilot emerging technologies, products, or business models under relaxed or tailor-made regulatory requirements, thereby allowing regulators to observe risks in real time while innovators validate commercial viability without bearing the full weight of the traditional compliance regime. By issuing sandbox regulations, the government of Vietnam is signaling its commitment to accelerating digital transformation, attracting investment, and developing a knowledge-based economy, all while safeguarding financial stability, consumer protection, and national security. This strategy is embodied in a suite of instruments that together establish sector-specific sandboxes: Decree No. 94/2025/ND-CP on the Regulatory Sandbox in the Banking Sector (Fintech Sandbox Decree), effective July 1, 2025. Law on Digital Technology Industry (DTI Law), effective January 1, 2026, and Law on Science, Technology and Innovation (STI Law), effective October 1, 2025. Resolution No. 222/2025/QH15 on International Financial Centers (IFC Resolution), effective September 1, 2025. In addition, a draft resolution on the pilot implementation of the crypto-asset market (Draft Crypto Pilot Resolution) is expected to introduce a dedicated sandbox for crypto-asset service providers later this year, further underscoring Vietnam’s holistic, forward-looking approach to regulating emerging technologies. Below is a brief summary of all the regulatory sandboxes, who they are open for, and what businesses are attracted. Fintech Sandbox Decree Under the Fintech Sandbox Decree, besides credit institutions and foreign bank branches, fintech companies operating in Vietnam can apply for a Certificate of Sandbox Participation issued by the State Bank of Vietnam to operate any of the following services in Vietnam: Credit scoring: A solution applicable to information technology systems of credit institutions, branches of foreign banks, and fintech
July 11, 2025
On June 10, 2025, Thailand’s Supreme Administrative Court accepted for consideration a pivotal lawsuit concerning the regulatory obligations of administrative agencies over internet-based television broadcasting services, commonly referred to as over-the-top (OTT) services. This court’s decision in the case may set important precedents for how OTT platforms are regulated, especially regarding consumer protections and advertising practices. Background A user of an OTT television application initiated legal action against the National Broadcasting and Telecommunications Commission (NBTC) and related officials, alleging that the lack of clear regulatory criteria and oversight allowed OTT operators to broadcast general television content while compelling users to view advertisements before and during programming. The plaintiff argued this constituted consumer exploitation and claimed that the responsible authorities neglected or delayed their statutory duties under the Act on the Organization to Assign Radio Frequencies and Regulate Broadcasting, Television, and Telecommunications Services B.E. 2553 (2010). Initially, the Central Administrative Court declined to accept the lawsuit. However, on appeal, the Supreme Administrative Court determined that the claim fell within its jurisdiction, noting that OTT television services—defined under section 4 of the governing act—are subject to the same regulatory framework as traditional television services, regardless of the transmission method (frequency, cable, internet, or other system). Implications for OTT Services The key implications for OTT services concern the following issues: Regulatory oversight: The court recognized that OTT television services are explicitly covered under Thailand’s broadcast regulatory regime. Regulatory agencies may be compelled to establish clear operational rules and oversight mechanisms for OTT providers. Consumer protections: The plaintiff’s claim that excessive or unavoidable in-program advertising constitutes consumer exploitation was acknowledged as a matter of public interest. This may prompt stricter advertising standards for OTT platforms. Licensing requirements: The case raises the prospect that OTT operators may be required to obtain licenses from the