You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 15, 2025

Thailand Resumes Development of AI Regulatory Framework

Thailand’s Electronic Transactions Development Agency (ETDA) held an explanatory session on the draft principles and regulatory approaches of the country’s planned artificial intelligence (AI) law on May 2, 2025. This came after a lull of two years following the initial release of draft legislation on AI.

In the session, the ETDA explained that the earlier drafts were modeled after the EU’s legal framework for AI, but given the evolving Thai legal and technological landscape, it is now necessary to revisit and refine the drafts to ensure they remain relevant and effective in the local context. To aid in this process, the ETDA will accept public comments on the draft principles of the AI law until June 9, 2025.

Based on gap analysis and a comparative study of how different countries have addressed AI issues, the ETDA’s draft AI law principles are structured into five key areas. These are described below.

1. Risk-Based Requirements

The draft principles outline a set of approaches that the legislation will take toward mitigating risk:

Delegation of powers to enforcement agency or sectoral regulators

The primary legislation will not directly specify a list of prohibited risks or high-risk types of AI. Instead, it will empower an enforcement agency or relevant sectoral regulators to determine and issue such lists. This approach allows regulators in each specific industry to assess the necessity of risk classifications within their respective sectors, based on the principle that sectoral regulators are best positioned to understand the specific risks in their domains. These regulators are expected to issue subordinate legislation in alignment with the overall framework. Meanwhile, the central enforcement agency will coordinate oversight across sectors and cover areas not under the jurisdiction of any specific regulator.

Duties of high-risk AI providers

Providers of AI deemed by the enforcement agency or sectoral regulators to be high-risk will have certain additional requirements:

  • Risk management frameworks: High-risk AI providers must implement risk management systems (e.g., ISO/IEC42001:2023 or NIST Risk Management Framework). The draft principles draw a “duty of care” boundary to clarify the basis for judicial discretion and to provide a reference for government agencies in their enforcement. Failure to comply with the prescribed standards does not automatically constitute a violation; however, if such failure results in harm, the provider may bear liability for a wrongful act. The framework is designed to align with international standards and support consistency across sectors, including through secondary regulations issued by the enforcement body.
  • Local legal representatives: Offshore high-risk AI providers will be required to appoint a local representative in Thailand to ensure effective enforcement of the law for all service providers. The enforcement agency must also be notified of the appointment of a legal representative.
  • Serious incident reporting: High-risk AI providers will be required to report serious incidents to the enforcement agency.

Duties of high-risk AI deployers

Entities deploying high-risk AI must ensure human oversight of AI systems, maintain operational logs, ensure the quality of input data, and notify affected individuals in cases where the AI system may have an impact on their rights or interests. Deployers must also cooperate with investigations if AI causes harm, and may be held liable if their use falls below the standard of care expected of professionals.

2. Measures in Support of Innovation

The supportive principles—most of which can be implemented without new legislation—focus on key areas:

  • Data: Introducing exceptions to permit the use of online data for purposes such as text and data mining, similar to the EU approach, while commercial use will still be subject to rightsholder reservations.
  • Sandbox: Testing in real-world conditions will be permitted under controlled environments to ensure that regulatory design aligns with practical realities. This will require an agreement between private entities and the relevant government agency overseeing the sandbox, allowing the use of personal data originally collected for other purposes to develop AI, provided it serves the public interest. Entities operating within a sandbox and acting in good faith should not be penalized for any harm that arises during the experimental phase, in line with a safe harbor principle. However, this safe harbor will not exempt participants from civil liability for damages.

3. General Principles

Some general principles guiding the development of Thailand’s legislative approach to AI include:

  • Nondiscrimination: Prohibiting the denial of legal effect to contracts or administrative decisions made using AI.
  • AI as a tool: Affirming that all actions generated by AI must be attributable to a human, regardless of human intervention. Developers and users cannot escape liability by citing unpredictability alone.
  • Protection against unexpected actions: Establishing exceptions to protect individuals from being bound by AI-generated acts that arise from unforeseeable errors. Such expectations would apply only if the affected party could not have reasonably foreseen the AI action and the counterparty either knew or could have known.
  • Right to explanation and appeal: Granting individuals the right to understand how AI systems are developed and the ability to appeal decisions made by or with AI, potentially requiring human involvement in decision making. These rights, which are under consideration and may apply only to high-risk AI, include the right to be notified when AI is used, the right to an explanation of how AI made a decision, and the right to contest the decision.

4. Regulator

The current proposal does not call for the establishment of a new regulator; instead, it designates the existing AI Governance Center (AIGC) under the ETDA to oversee the implementation of the law. The AIGC’s roles include conducting research and development on AI governance, providing guidance to organizations on AI adoption, and supporting pilot projects and regulatory sandboxes. Additional responsibilities include monitoring global trends, compiling national AI-readiness data, and developing cooperative mechanisms both domestically and internationally.

5. Legal Enforcement

The draft AI law empowers the enforcement agency and relevant sectoral regulators to jointly issue administrative orders requiring AI providers or deployers to cease the provision or use of prohibited or high-risk AI. If such parties fail to comply and the AI service is hosted on a digital platform, authorities may order the platform provider to remove or block access to the service. For prohibited AI embedded in physical products, enforcement may extend to seizure of the items, including through entry into premises. If the noncompliant AI service is hosted outside digital platforms or a platform fails to comply, the regulators may coordinate with the Ministry of Digital Economy and Society to order internet service providers to block access within Thailand.

Status and Outlook

The ETDA will take the comments into consideration as part of the legislative revision process. After reviewing the draft legislation based on the feedback received in this round, a revised version of the draft law will be published for another public hearing.

Business operators should review the proposed principles of the draft AI law and submit their comments, if any, to the ETDA. They should also start monitoring the development of this law to ensure timely compliance. In particular, operators that develop, use, or rely on high-risk AI systems should begin assessing their current risk management structures, data governance practices, and human oversight mechanisms.

RELATED INSIGHTS​ 

April 3, 2026
Thailand’s Securities and Exchange Commission (SEC) has established a comprehensive governance framework for the use of artificial intelligence and machine learning (AI/ML) in the capital markets. The framework provides guidance to capital market business operators on understanding the risks associated with AI/ML implementation and adopting appropriate practices to build public confidence in Thailand’s capital markets. While the guidelines are principle-based rather than prescriptive, they reflect the SEC’s expectations for responsible AI/ML governance and are likely to inform supervisory activities and industry standards going forward. Scope The framework applies to capital market business operators supervised by the SEC. This includes, for example, securities and derivatives firms, asset management companies, mutual fund and private fund managers, investment advisors and investment consultants (including robo-advisory service providers), derivatives intermediaries, and other licensed intermediaries and market operators in the Thai capital markets that deploy AI/ML in their operations. Core Principles of the Guidelines The framework is presented as a best-practice manual rather than prescriptive regulation, providing guidance that regulated entities may apply to their AI/ML governance and risk management as appropriate. While currently nonbinding, the guidelines signal the SEC’s expectations for the sector, particularly in relation to other binding SEC regulations such as those covering IT risk management and market conduct. The guidelines name four core principles for AI/ML deployment: Fairness: Design and develop AI/ML with consideration for fairness, equality, and social diversity to prevent discrimination against individuals or groups. Legal and ethical compliance: Ensure AI/ML use aligns with applicable laws, ethical standards, and organizational values and policies. Accountability: Establish clear responsibility—both internally and externally—for AI/ML activities and outcomes. Transparency: Provide adequate disclosure to users about AI/ML use, including explainability of decisions and traceability of activities. AI/ML Best Practices The guidelines prescribe best practices across four stages of the AI/ML lifecycle, as described below.
April 2, 2026
Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance. What Has Changed: OIC and PDPC Alignment The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers. Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible. Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors. Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels. DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on
March 30, 2026
On March 24, 2026, the Trade Competition Commission of Thailand (TCCT) published its long-anticipated Guidelines on Multi-Sided Platforms and E-Commerce Businesses in the Government Gazette, following the conclusion of a public hearing conducted last year. The guidelines entered into force on March 25, 2026, and significantly expand the application of Thai competition law to digital platform ecosystems. These rules introduce targeted restrictions on platform conduct, such as price-ranking algorithms and tying and bunding, that leverages network effects, and will have far-reaching implications across Thailand’s digital economy—affecting not only platform operators but also platform participants, including sellers, logistics providers, advertisers, and payment service providers operating on or alongside such platforms. The guidelines clarify how existing prohibitions under the Trade Competition Act B.E. 2560 (2017) (TCA)—including abuse of market dominance, cartel conduct, and unfair trade practices—apply in the context of platform-based business models. While many provisions reflect earlier draft guidelines, the final version delivers more precise definitions and clearer enforcement parameters, increasing regulatory certainty while also raising compliance expectations. Applicability The guidelines introduce core definitions that determine their coverage: Multi-sided platform: A platform that acts as an intermediary connecting two or more groups of users, enabling them to have direct interaction in order to exchange or rely on services from one another. Examples include digital platforms for trading goods or services (e-commerce), as defined below. Digital platform for trading goods or services (e-commerce): A platform that acts as an intermediary connecting the distribution, purchase, sale, or exchange of goods or services. This includes operations carried out to facilitate transactions or interactions between business operators through an electronic transaction system, regardless of whether a service fee is charged. Operator of a digital platform business for trading goods or services: A provider of digital platform services for trading goods or services, as described
March 27, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has publicly indicated that it is preparing a new regulatory framework for data center operators that may introduce foreign-ownership restrictions. In particular, the NBTC is considering reclassifying data center operations from a type 1 telecommunications business license to a type 3 license. If implemented, this change would subject data center operators to a significantly more stringent regulatory regime, especially in relation to foreign ownership and control. The NBTC has indicated that it intends to propose a draft framework to the NBTC board. This would be followed by a public hearing process, with a view to implementing the new rules within 2026. Under the Telecommunications Business Act B.E. 2544 (2001), as amended, telecommunications businesses operating under type 3 licenses are subject to foreign ownership restrictions, including a requirement that less than 50% of the total issued shares be held by foreign shareholders. In addition, type 3 licensees are subject to foreign dominance restrictions, which prohibit arrangements that allow foreigners to dominate the business. These foreign dominance restrictions are broad in scope and may capture various forms of direct and indirect control or influence. This includes circumstances in which a foreign national is able to influence or control the formulation of policy, management, or business operations, or the appointment of directors or senior executives. At this stage, the exact scope of the proposed rules remains unclear. Businesses with existing or planned data center operations in Thailand should therefore monitor upcoming NBTC developments in this regard and prepare for the expected public hearing process.