You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 15, 2025

Thailand Resumes Development of AI Regulatory Framework

Thailand’s Electronic Transactions Development Agency (ETDA) held an explanatory session on the draft principles and regulatory approaches of the country’s planned artificial intelligence (AI) law on May 2, 2025. This came after a lull of two years following the initial release of draft legislation on AI.

In the session, the ETDA explained that the earlier drafts were modeled after the EU’s legal framework for AI, but given the evolving Thai legal and technological landscape, it is now necessary to revisit and refine the drafts to ensure they remain relevant and effective in the local context. To aid in this process, the ETDA will accept public comments on the draft principles of the AI law until June 9, 2025.

Based on gap analysis and a comparative study of how different countries have addressed AI issues, the ETDA’s draft AI law principles are structured into five key areas. These are described below.

1. Risk-Based Requirements

The draft principles outline a set of approaches that the legislation will take toward mitigating risk:

Delegation of powers to enforcement agency or sectoral regulators

The primary legislation will not directly specify a list of prohibited risks or high-risk types of AI. Instead, it will empower an enforcement agency or relevant sectoral regulators to determine and issue such lists. This approach allows regulators in each specific industry to assess the necessity of risk classifications within their respective sectors, based on the principle that sectoral regulators are best positioned to understand the specific risks in their domains. These regulators are expected to issue subordinate legislation in alignment with the overall framework. Meanwhile, the central enforcement agency will coordinate oversight across sectors and cover areas not under the jurisdiction of any specific regulator.

Duties of high-risk AI providers

Providers of AI deemed by the enforcement agency or sectoral regulators to be high-risk will have certain additional requirements:

  • Risk management frameworks: High-risk AI providers must implement risk management systems (e.g., ISO/IEC42001:2023 or NIST Risk Management Framework). The draft principles draw a “duty of care” boundary to clarify the basis for judicial discretion and to provide a reference for government agencies in their enforcement. Failure to comply with the prescribed standards does not automatically constitute a violation; however, if such failure results in harm, the provider may bear liability for a wrongful act. The framework is designed to align with international standards and support consistency across sectors, including through secondary regulations issued by the enforcement body.
  • Local legal representatives: Offshore high-risk AI providers will be required to appoint a local representative in Thailand to ensure effective enforcement of the law for all service providers. The enforcement agency must also be notified of the appointment of a legal representative.
  • Serious incident reporting: High-risk AI providers will be required to report serious incidents to the enforcement agency.

Duties of high-risk AI deployers

Entities deploying high-risk AI must ensure human oversight of AI systems, maintain operational logs, ensure the quality of input data, and notify affected individuals in cases where the AI system may have an impact on their rights or interests. Deployers must also cooperate with investigations if AI causes harm, and may be held liable if their use falls below the standard of care expected of professionals.

2. Measures in Support of Innovation

The supportive principles—most of which can be implemented without new legislation—focus on key areas:

  • Data: Introducing exceptions to permit the use of online data for purposes such as text and data mining, similar to the EU approach, while commercial use will still be subject to rightsholder reservations.
  • Sandbox: Testing in real-world conditions will be permitted under controlled environments to ensure that regulatory design aligns with practical realities. This will require an agreement between private entities and the relevant government agency overseeing the sandbox, allowing the use of personal data originally collected for other purposes to develop AI, provided it serves the public interest. Entities operating within a sandbox and acting in good faith should not be penalized for any harm that arises during the experimental phase, in line with a safe harbor principle. However, this safe harbor will not exempt participants from civil liability for damages.

3. General Principles

Some general principles guiding the development of Thailand’s legislative approach to AI include:

  • Nondiscrimination: Prohibiting the denial of legal effect to contracts or administrative decisions made using AI.
  • AI as a tool: Affirming that all actions generated by AI must be attributable to a human, regardless of human intervention. Developers and users cannot escape liability by citing unpredictability alone.
  • Protection against unexpected actions: Establishing exceptions to protect individuals from being bound by AI-generated acts that arise from unforeseeable errors. Such expectations would apply only if the affected party could not have reasonably foreseen the AI action and the counterparty either knew or could have known.
  • Right to explanation and appeal: Granting individuals the right to understand how AI systems are developed and the ability to appeal decisions made by or with AI, potentially requiring human involvement in decision making. These rights, which are under consideration and may apply only to high-risk AI, include the right to be notified when AI is used, the right to an explanation of how AI made a decision, and the right to contest the decision.

4. Regulator

The current proposal does not call for the establishment of a new regulator; instead, it designates the existing AI Governance Center (AIGC) under the ETDA to oversee the implementation of the law. The AIGC’s roles include conducting research and development on AI governance, providing guidance to organizations on AI adoption, and supporting pilot projects and regulatory sandboxes. Additional responsibilities include monitoring global trends, compiling national AI-readiness data, and developing cooperative mechanisms both domestically and internationally.

5. Legal Enforcement

The draft AI law empowers the enforcement agency and relevant sectoral regulators to jointly issue administrative orders requiring AI providers or deployers to cease the provision or use of prohibited or high-risk AI. If such parties fail to comply and the AI service is hosted on a digital platform, authorities may order the platform provider to remove or block access to the service. For prohibited AI embedded in physical products, enforcement may extend to seizure of the items, including through entry into premises. If the noncompliant AI service is hosted outside digital platforms or a platform fails to comply, the regulators may coordinate with the Ministry of Digital Economy and Society to order internet service providers to block access within Thailand.

Status and Outlook

The ETDA will take the comments into consideration as part of the legislative revision process. After reviewing the draft legislation based on the feedback received in this round, a revised version of the draft law will be published for another public hearing.

Business operators should review the proposed principles of the draft AI law and submit their comments, if any, to the ETDA. They should also start monitoring the development of this law to ensure timely compliance. In particular, operators that develop, use, or rely on high-risk AI systems should begin assessing their current risk management structures, data governance practices, and human oversight mechanisms.

RELATED INSIGHTS​ 

June 15, 2026
The surge in AI development has led to a desperate demand for large, high-quality training data. However, real-world data can be expensive to collect, difficult to access, and often subject to strict privacy and regulatory constraints. Synthetic data, which consists of artificially generated records that replicate the statistical properties of real-world data without reproducing specific individuals’ information, provides an appealing solution by generating artificial datasets at scale without relying on identifiable personal information. It combines speed, cost efficiency, and regulatory compliance, making it a sensible alternative for organizations seeking to reduce risks while maintaining data utility. When properly anonymized, synthetic datasets may fall outside the scope of laws such as the EU’s General Data Protection Regulation (GDPR) or Thailand’s Personal Data Protection Act (PDPA), reducing compliance burdens while still supporting high-quality model training. However, relying on synthetic data without rigorous legal due diligence could be a strategic mistake. It replaces one set of known risks (scraping, direct privacy liability) with a new set of complex liabilities. The narrative that synthetic data is a “silver bullet” for privacy and IP compliance is dangerous and could be misleading. While synthetic data addresses data scarcity, it also introduces new legal uncertainties. Legal counsel should anticipate downstream risks arising from compromised data sources. Models trained on unlawfully obtained data may need to be decommissioned, even if their outputs appear lawful. What is synthetic data? Synthetic data refers to artificially generated information created using AI techniques such as deep learning and generative models. Instead of copying real records, it reproduces the statistical patterns and relationships found in the original dataset. Synthetic data generally falls into three categories: Fully synthetic data – Entirely new data points generated from learned patterns. The model studies the structure of the original data and produces records that resemble real-world
June 11, 2026
Thailand’s Electronic Transactions Development Agency (ETDA) has released a revised draft Electronic Transactions Act (ETA) for public hearing from May 12, 2026, to June 15, 2026. This is not merely an amendment to certain provisions of the current ETA, but a comprehensive redrafting of the entire act. The revised draft ETA introduces several significant changes from the current framework, with practical implications for businesses operating in Thailand. Unified Coverage of Public and Private Sectors The current law segregates government transactions into a separate chapter with distinct rules. The draft ETA eliminates this division, defining “transaction” to encompass civil and commercial juristic acts as well as administrative procedures, administrative contracts, and other acts of government agencies. Enhanced E-Signature Definition The definition of “electronic signature” is broadened to expressly include biometric data and refocused on identifying the signatory and demonstrating intent regarding the content of the electronic data. Shift in Burden of Proof When a party challenges the reliability of electronic data created using a “trusted electronic method” or a method prescribed by the ETDA, the burden of proof and the cost of proving unreliability shifts to the challenger. Introduction of New Digital Method Concepts The draft ETA introduces several new digital method concepts that are not currently recognized under the existing ETA framework. These include: Electronic timestamping (e-timestamp) Electronic registered delivery Electronic company seals Electronic stamp duty compliance Electronic identity authentication and verification Electronic transferable records (electronic bills of lading, promissory notes, and similar negotiable instruments) Recognition of Automated Systems and Electronic Contracting The draft ETA expressly recognizes the legal validity and enforceability of contracts formed through automated systems, including contracts concluded entirely between automated systems or between an automated system and a person. A party may not deny the binding effect of such contracts solely because no human review
June 5, 2026
Vietnam’s AI regulatory framework has reached an important milestone. While the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law) established the foundation for AI governance, many practical compliance requirements were left to implementing regulations. On April 30, 2026, the government issued Decree No. 142/2026/ND-CP (Decree 142), which took effect on May 1, 2026, and provides the first detailed guidance on the implementation of the AI Law. Although an official list of high-risk AI systems is still pending from the prime minister, Decree 142 provides valuable insight into how Vietnam’s risk-based AI regulatory framework will operate in practice. Risk Classification Framework The AI Law adopts a risk-based approach under which AI systems are classified as high-risk, medium-risk, or low-risk. Decree 142 builds on this framework by providing detailed guidance on how these classifications are determined. High-risk AI systems are determined based on factors such as (i) their potential impact on life, health, property, human rights, public interests, or national security; (ii) the sector in which they are deployed; and (iii) the scale of affected users or integration with critical infrastructure. The latest draft list of high-risk AI systems appears to follow these same principles. Medium-risk AI systems generally include systems that may mislead, influence, or manipulate users, particularly where users may not realize they are interacting with AI or AI-generated content. The focus is therefore on transparency and authenticity risks rather than broader societal or safety concerns. Low-risk AI systems are those that do not meet the criteria for either high-risk or medium-risk classification. Importantly, Decree 142 seeks to avoid over-classification. Certain systems may fall outside the high-risk or medium-risk regimes, including internal-use systems, office-support tools, technical editing applications, certain back-end processing systems, and AI systems used in artistic, gaming, cinematic, or other creative contexts. Providers must also review and
June 5, 2026
On May 11, 2026, Thailand’s Ministry of Social Development and Human Security released a draft Child Protection Act (“CPA”) for public review. The draft CPA would completely repeal and replace the current Child Protection Act B.E. 2546 (2003). This represents the most comprehensive overhaul of Thailand’s child protection framework in over two decades, reflecting the government’s stated objective of modernizing the law to address evolving social challenges—including those arising from digital technology—and to promote greater coordination among government agencies, local authorities, and civil society. The public review period closes on June 9, 2026. Key changes introduced by the draft CPA that could have significant implications for businesses, particularly online platform providers, media companies, and entities operating child-related services in Thailand, are set out below. Expanded Definition of “Child” Under the current CPA, a “child” is defined as a person under the age of 18, excluding those who have attained legal majority through marriage. The draft CPA removes the marriage exception entirely, broadening the scope of the law’s protections to include all individuals under 18 without exception. Replacement of “Abuse” with Broader Concept of “Violence” The current CPA uses the term “abuse/cruelty,” which covers acts causing harm to a child’s liberty, body, or mind; sexual offenses against children; and using children in harmful or immoral activities. The draft CPA replaces this with the broader concept of “violence,” which encompasses any act or omission causing harm to a child’s body, mind, or development; abandonment or neglect; improper exploitation; and sexual abuse. Notably, the new definition adds developmental harm as a recognized category of injury and captures all forms of misconduct regardless of the child’s consent. New Standalone Definition of Sexual Abuse, Including Online Conduct One of the most significant additions in the draft CPA is the introduction of a standalone definition