You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 15, 2025

Thailand Resumes Development of AI Regulatory Framework

Thailand’s Electronic Transactions Development Agency (ETDA) held an explanatory session on the draft principles and regulatory approaches of the country’s planned artificial intelligence (AI) law on May 2, 2025. This came after a lull of two years following the initial release of draft legislation on AI.

In the session, the ETDA explained that the earlier drafts were modeled after the EU’s legal framework for AI, but given the evolving Thai legal and technological landscape, it is now necessary to revisit and refine the drafts to ensure they remain relevant and effective in the local context. To aid in this process, the ETDA will accept public comments on the draft principles of the AI law until June 9, 2025.

Based on gap analysis and a comparative study of how different countries have addressed AI issues, the ETDA’s draft AI law principles are structured into five key areas. These are described below.

1. Risk-Based Requirements

The draft principles outline a set of approaches that the legislation will take toward mitigating risk:

Delegation of powers to enforcement agency or sectoral regulators

The primary legislation will not directly specify a list of prohibited risks or high-risk types of AI. Instead, it will empower an enforcement agency or relevant sectoral regulators to determine and issue such lists. This approach allows regulators in each specific industry to assess the necessity of risk classifications within their respective sectors, based on the principle that sectoral regulators are best positioned to understand the specific risks in their domains. These regulators are expected to issue subordinate legislation in alignment with the overall framework. Meanwhile, the central enforcement agency will coordinate oversight across sectors and cover areas not under the jurisdiction of any specific regulator.

Duties of high-risk AI providers

Providers of AI deemed by the enforcement agency or sectoral regulators to be high-risk will have certain additional requirements:

  • Risk management frameworks: High-risk AI providers must implement risk management systems (e.g., ISO/IEC42001:2023 or NIST Risk Management Framework). The draft principles draw a “duty of care” boundary to clarify the basis for judicial discretion and to provide a reference for government agencies in their enforcement. Failure to comply with the prescribed standards does not automatically constitute a violation; however, if such failure results in harm, the provider may bear liability for a wrongful act. The framework is designed to align with international standards and support consistency across sectors, including through secondary regulations issued by the enforcement body.
  • Local legal representatives: Offshore high-risk AI providers will be required to appoint a local representative in Thailand to ensure effective enforcement of the law for all service providers. The enforcement agency must also be notified of the appointment of a legal representative.
  • Serious incident reporting: High-risk AI providers will be required to report serious incidents to the enforcement agency.

Duties of high-risk AI deployers

Entities deploying high-risk AI must ensure human oversight of AI systems, maintain operational logs, ensure the quality of input data, and notify affected individuals in cases where the AI system may have an impact on their rights or interests. Deployers must also cooperate with investigations if AI causes harm, and may be held liable if their use falls below the standard of care expected of professionals.

2. Measures in Support of Innovation

The supportive principles—most of which can be implemented without new legislation—focus on key areas:

  • Data: Introducing exceptions to permit the use of online data for purposes such as text and data mining, similar to the EU approach, while commercial use will still be subject to rightsholder reservations.
  • Sandbox: Testing in real-world conditions will be permitted under controlled environments to ensure that regulatory design aligns with practical realities. This will require an agreement between private entities and the relevant government agency overseeing the sandbox, allowing the use of personal data originally collected for other purposes to develop AI, provided it serves the public interest. Entities operating within a sandbox and acting in good faith should not be penalized for any harm that arises during the experimental phase, in line with a safe harbor principle. However, this safe harbor will not exempt participants from civil liability for damages.

3. General Principles

Some general principles guiding the development of Thailand’s legislative approach to AI include:

  • Nondiscrimination: Prohibiting the denial of legal effect to contracts or administrative decisions made using AI.
  • AI as a tool: Affirming that all actions generated by AI must be attributable to a human, regardless of human intervention. Developers and users cannot escape liability by citing unpredictability alone.
  • Protection against unexpected actions: Establishing exceptions to protect individuals from being bound by AI-generated acts that arise from unforeseeable errors. Such expectations would apply only if the affected party could not have reasonably foreseen the AI action and the counterparty either knew or could have known.
  • Right to explanation and appeal: Granting individuals the right to understand how AI systems are developed and the ability to appeal decisions made by or with AI, potentially requiring human involvement in decision making. These rights, which are under consideration and may apply only to high-risk AI, include the right to be notified when AI is used, the right to an explanation of how AI made a decision, and the right to contest the decision.

4. Regulator

The current proposal does not call for the establishment of a new regulator; instead, it designates the existing AI Governance Center (AIGC) under the ETDA to oversee the implementation of the law. The AIGC’s roles include conducting research and development on AI governance, providing guidance to organizations on AI adoption, and supporting pilot projects and regulatory sandboxes. Additional responsibilities include monitoring global trends, compiling national AI-readiness data, and developing cooperative mechanisms both domestically and internationally.

5. Legal Enforcement

The draft AI law empowers the enforcement agency and relevant sectoral regulators to jointly issue administrative orders requiring AI providers or deployers to cease the provision or use of prohibited or high-risk AI. If such parties fail to comply and the AI service is hosted on a digital platform, authorities may order the platform provider to remove or block access to the service. For prohibited AI embedded in physical products, enforcement may extend to seizure of the items, including through entry into premises. If the noncompliant AI service is hosted outside digital platforms or a platform fails to comply, the regulators may coordinate with the Ministry of Digital Economy and Society to order internet service providers to block access within Thailand.

Status and Outlook

The ETDA will take the comments into consideration as part of the legislative revision process. After reviewing the draft legislation based on the feedback received in this round, a revised version of the draft law will be published for another public hearing.

Business operators should review the proposed principles of the draft AI law and submit their comments, if any, to the ETDA. They should also start monitoring the development of this law to ensure timely compliance. In particular, operators that develop, use, or rely on high-risk AI systems should begin assessing their current risk management structures, data governance practices, and human oversight mechanisms.

RELATED INSIGHTS​ 

March 19, 2026
Thailand’s Personal Data Protection Committee (PDPC) has launched a public consultation period to gather input for a forthcoming set of guidelines under the country’s Personal Data Protection Act (PDPA). This initiative follows the PDPC’s issuance of guidelines on consent and notification requirements in September 2022. The main consultation period, using an online questionnaire to gather feedback, runs until March 23, 2026. In addition, an interview-style online session for private-sector participants was held on March 17, and a two-day in-person event will be held on April 1–2—this is already fully booked and  walk-ins will not be accepted, but the session will be livestreamed on the PDPC’s Facebook page. The PDPC will use the public feedback to design draft guidelines that accurately reflect the operational realities of both public and private organizations, after which the guidelines will be shared with the public. Consultation Scope The PDPC has identified six priority areas for which upcoming guidance may be issued: Legal bases for processing: The online questionnaire assesses respondents’ understanding of consent requirements and seeks views on priority issues, such as explanations of the legal bases and considerations for selecting an appropriate legal basis depending on the nature of the processing activity. Security measures and data breach notification: The questionnaire examines respondents’ understanding of data breach reporting and security measure obligations. Topics proposed for inclusion in the guidelines include data breach prevention measures, incident response plans, risk assessment methods, and reporting procedures. Data protection officers: Respondents are invited to share their expectations regarding the DPO’s role and their experiences in contacting a DPO. The survey also asks respondents to identify priority issues, such as response timeframes for data subject requests and complaint procedures. Marketing and direct marketing: The online questionnaire seeks input on preferred topics for guidance, including individuals’ rights to refuse marketing
March 16, 2026
Thailand’s Securities and Exchange Commission (SEC) has broadened the definition of institutional investors, expanded the types of qualifying investments, and updated financial qualification thresholds for various investor categories through a revised notification on the definitions of institutional investors, ultra-high net worth investors, and high net worth investors. The amended framework, which came into force on March 1, 2026, adds digital asset business operators, investment planners, and investment consultants to the roster of entities recognized as institutional investors, and broadens the definition of investment to account for digital tokens. Expanded Definition of Institutional Investors Under the SEC’s revised notification, the category of institutional investors now expressly includes digital asset business operators licensed under the Royal Decree on Digital Asset Businesses B.E. 2561 (2018). This addition recognizes the growing role of digital asset platforms and service providers in Thailand’s investment ecosystem and aligns the regulatory treatment of digital markets with that of traditional markets. The definition of institutional investors now also encompasses investment planners and investment consultants approved by the SEC. Previously, only SEC-approved investment analysts held this status; the expansion covers a broader scope of professionals who possess comparable expertise and experience in evaluating investment opportunities. Broadened Investment Definition The revised framework now defines investment to mean direct or indirect investment in a wider range of assets beyond deposits. Specifically, the definition covers: Securities under the Securities and Exchange Act Derivatives under the Derivatives Act Investment tokens offered to the public Government-issued digital tokens (G-tokens) as specified in a separate SEC notification This expansion ensures that financial status assessments reflect the full spectrum of an investor’s holdings, including emerging digital assets. Updated Financial Qualification Thresholds The amended SEC notification also provides updated qualification thresholds for angel investors, ultra-high net worth investors, and high net worth investors. While the core criteria
March 13, 2026
Vietnam’s Law on Intellectual Property (IP Law) has undergone continuous amendment in recent years, with the latest amendment issued at the end of 2025. Among the amended and supplemented provisions, the regulation that has perhaps attracted the most attention is a provision relating to the use of protected IP objects by artificial intelligence (AI) systems. Specifically, Article 7 of the 2025 IP Law introduces a completely new Clause 5, which reads in full as follows: “Organizations and individuals are permitted to use texts and data relating to intellectual property objects that have been lawfully published, and which the public is allowed to access, for the purposes of scientific research, experimentation, and training of artificial intelligence systems, provided that such use will not unreasonably affect the legitimate rights and interests of the authors and intellectual property rights holders in accordance with this Law. With respect to texts and data that are objects protected by copyright and related rights, the use of the texts and data as set forth herein must also be in accordance with the regulations of the Government.” Analyzing this newly added provision in the context of how it was conceived, as well as the challenges that still lie ahead, can provide some interesting insights. From Aspirations to Flight in Science and Technology From the end of 2024 and throughout 2025—the 50th anniversary of the country’s reunification—Vietnam witnessed numerous sweeping changes in many areas, including legislative development. It could be said that no sessions of the National Assembly have ever adopted as many laws, resolutions, and major policies as this one. The aspirations of the highest-level leadership have been concretized into major law and policy projects, which were drafted, developed, and passed at record speed. All of this was aimed at building a foundation for Vietnam to achieve
March 12, 2026
Thailand’s AI legislative framework took another step forward when the Office of the Consumer Protection Board (OCPB) issued a notification establishing guidelines for AI-generated advertising that may cause material misunderstanding about products or services. The notification, which is already in effect, was issued under the Consumer Protection Act B.E. 2522 (1979) and its amendments, which prohibit advertising that is unfair to consumers or may cause harm to society, including false or exaggerated statements and statements that may cause material misunderstanding about products or services. The notification addresses emerging advertising practices, including the use of images edited using software or AI to attract consumer interest or build credibility. The OCPB noted that such advertising may result in consumers misunderstanding the essential characteristics, condition, or usage of products, which violates consumer rights and causes damage. Key Requirements on AI-Generated or Digitally Manipulated Advertising Content For advertisements using still images or videos created or edited with software programs or AI tools that may cause the depicted product or service to differ from the actual product sold or service provided—which may cause misunderstanding regarding the condition, quality, quantity, or other essential aspects of the products or services—advertisers and business operators must comply with the following requirements: Prior authorization. Obtain approval from relevant regulatory authorities where required by law. Accurate representation. Ensure that the advertised size, quantity, volume, number, or composition matches the actual product or service being sold, whether in still images or videos. Mandatory AI disclosure labels. Display clear disclosures when AI or software is used to create or edit images, such as: “Real image or simulation edited using AI” “Photo from actual location or simulation edited using AI” “Photo from actual product or edited simulation” “Image created by AI” “Video created by AI” Clarity of disclosure. Ensure disclosures are clearly visible,