You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 12, 2026

Thailand’s Advertising Guidelines Targeting AI-Generated Content

Thailand’s AI legislative framework took another step forward when the Office of the Consumer Protection Board (OCPB) issued a notification establishing guidelines for AI-generated advertising that may cause material misunderstanding about products or services. The notification, which is already in effect, was issued under the Consumer Protection Act B.E. 2522 (1979) and its amendments, which prohibit advertising that is unfair to consumers or may cause harm to society, including false or exaggerated statements and statements that may cause material misunderstanding about products or services.

The notification addresses emerging advertising practices, including the use of images edited using software or AI to attract consumer interest or build credibility. The OCPB noted that such advertising may result in consumers misunderstanding the essential characteristics, condition, or usage of products, which violates consumer rights and causes damage.

Key Requirements on AI-Generated or Digitally Manipulated Advertising Content

For advertisements using still images or videos created or edited with software programs or AI tools that may cause the depicted product or service to differ from the actual product sold or service provided—which may cause misunderstanding regarding the condition, quality, quantity, or other essential aspects of the products or services—advertisers and business operators must comply with the following requirements:

  • Prior authorization. Obtain approval from relevant regulatory authorities where required by law.
  • Accurate representation. Ensure that the advertised size, quantity, volume, number, or composition matches the actual product or service being sold, whether in still images or videos.
  • Mandatory AI disclosure labels. Display clear disclosures when AI or software is used to create or edit images, such as:
    • “Real image or simulation edited using AI”
    • “Photo from actual location or simulation edited using AI”
    • “Photo from actual product or edited simulation”
    • “Image created by AI”
    • “Video created by AI”
  • Clarity of disclosure. Ensure disclosures are clearly visible, audible, or readable according to the type of advertising medium.

Recommendations

Business operators should assess their current advertising practices and update internal policies to ensure compliance with these new disclosure and warning requirements. Companies should ensure that marketing contracts and creative workflows incorporate the mandatory disclosures specified in the announcement. In particular, operators that develop, use, or rely on AI systems in their marketing activities should assess their current data governance practices and oversight mechanisms. Businesses should also monitor the ongoing development of Thailand’s broader AI regulatory framework to ensure timely compliance with future requirements.

RELATED INSIGHTS​ 

February 27, 2024
Thailand’s National Cyber Security Committee (NCSC) released three notifications under the Cybersecurity Act on January 18, 2024, setting cybersecurity-related requirements for key organizations and assets. While one of these notifications already took effect, the two most notable will take effect on January 18, 2025 (i.e., one year from their publication in the Government Gazette). These two are the NCSC Notification Re: Standards for Defining the Security Category for Data or Information Systems B.E. 2566 (2023) (“Notification on Security Category”) and the NCSC Notification Re: Minimum Standards for Data and Information Systems B.E. 2566 (2023) (“Notification on Minimum Standards”). These notifications apply to: State agencies; Supervising or regulating organizations (i.e., state organizations, private organizations, or persons designated by law to regulate or supervise the affairs of state organizations or critical information infrastructure organizations); and Critical information infrastructure organizations (i.e., organizations related to or providing national security, significant public services, banking and finance, information technologies and telecommunications, transportation and logistics, energy and public utilities, and public health). Collectively these are defined as “Organizations” under the notifications. Notification on Security Category The Notification on Security Category sets forth risk-based security classifications—or “security categories”—for Organizations’ data or information systems. For security category assessment purposes, Organizations are required to perform a self-assessment of their data or information systems based on three key security objectives: confidentiality, integrity, and availability. Each of these objectives is further categorized into three risk levels (low, medium, and high), taking into account the assessment of potential impact in the following areas: Organizations’ financial value or reputation; Organizations’ number of service users; Organizations’ ability to perform their duties; State stability or public order. The risk levels for the three objectives are determined by considering whether there are “minimal,” “severe,” or “serious severe” effects, as described below: Confidentiality (not including data classified
February 2, 2024
The pervasive global issue of illicit personal data trading has extended its reach into Vietnam, where such sensitive information is being sold at minimal costs. A 2023 report from the Ministry of Public Security revealed that over two-thirds of the Vietnamese population has fallen victim to unlawful data collection and distribution. In the past two years, authorities have pressed charges on five criminal cases involving the buying and selling of billions of items of personal data, encompassing a wide range of sensitive information such as names, phone numbers, email addresses, and more. Notably, a person’s profile can be acquired for just USD 1, while profiles of millions of business customers can be obtained for a mere USD 100. Recognizing the severity of the problem, Vietnam has made serious efforts to combat illicit personal data trading by criminal means, encompassing both the legal framework and practical implementation.   Understanding the Criminal Legal Framework Vietnam’s 2015 Criminal Code, as amended in 2017, functions as a pivotal legal instrument delineating offenses and their corresponding punishments. Under Section 2 of Chapter XXI of the Criminal Code (“Offenses Against Regulations on Information Technology and Telecommunications Networks”), individuals engaging in the illicit trading of personal data, depending on the nature of the data (e.g., information about phone number, address, or—more dangerously—bank account) and the nature of the infringing acts, may be charged under different crimes. The sanctions can include monetary fines; non-custodial reform; imprisonment; and/or prohibition from holding certain positions, practicing certain professions, or doing certain jobs. For example, for the illicit trade of private information of an individual on a computer or telecommunications network, Article 288 of the Criminal Code specifies penalties including a monetary fine of up to VND 1 billion (equivalent to around USD 41,000); non-custodial reform of up to three years;
January 30, 2024
Thailand has made its draft Platform Economy Act (the “Draft PEA”) available to relevant entities in certain industries. The Draft PEA aims to regulate and standardize digital platform service business operations and protect consumers and other stakeholders. Once the Draft PEA becomes law, the Royal Decree on the Operation of Digital Platform Service Businesses that are subject to Prior Notification B.E. 2565 (2022) and the relevant provisions under the Electronic Transactions Act B.E. 2544 (2001), as amended, will cease to have effect. The key provisions of the Draft PEA are summarized below. Definitions The definitions of the key terms under the Draft PEA are substantially similar to the definitions of the key terms under the royal decree mentioned above. According to the Draft PEA, “digital platform services” refers to the provision of electronic intermediary services that manage data to facilitate connection, through computer networks, between business users, consumers, or users, regardless of whether remuneration is charged. Exemption The Draft PEA does not apply to digital platform services (DPSs) that are regulated by specific laws and have rules guaranteeing transparency and fairness, or that follow operational standards no less stringent than those required in the Draft PEA. Nonetheless, the Electronic Transactions Development Agency (ETDA) can request or link data relating to exempted DPSs from the relevant supervisory authorities. Extraterritorial Effect Offshore DPSs with certain characteristics are also subject to the obligations under the Draft PEA and will have to appoint a coordinating person in Thailand. However, offshore DPSs will not have to establish a business in Thailand. General Responsibilities and Obligations The Draft PEA sets out the following requirements: DPSs with (1) at least THB 100 million (approx. USD 2.8 million) in annual revenue from providing the DPSs in Thailand before deducting expenses, or (2) more than 10,000 monthly users
January 24, 2024
On 17 April 2023, the Vietnamese government issued the Personal Data Protection Decree, which is set to take effect 1 July 2023 without any transitional period. The PDPD is considered to be the first comprehensive document on data protection in Vietnam. Accordingly, it provides detailed regulations on the rights of data subjects, consent requirements and requirements for data processing impact assessments and outbound transfer impact assessments. In 2024, the adoption of the Law on the Protection of Consumer Rights and the Law on Electronic Transactions will play a vital role regarding data protection. The LPCR will require traders to obtain consent to collect consumer data and establish a mechanism enabling consumers to select the information they consent to traders collecting. Consumers must also be allowed to express consent in a suitable form. For special processing purposes — such as sharing, disclosure, or transfer of personal data to third parties, and use of personal data to send advertisements and to introduce products — the LPCR requires a mechanism which enables data subjects to clearly opt in to give, or not give, their consent. This requirement is similar to procedures currently required for regulated stakeholders under the PDPD. In the same vein, the LET strictly forbids the acts of trading data to protect Vietnamese personal data. The government is anticipated to provide more details relating to data privacy guidelines after the issuance of the Draft Law on Telecommunications. Accordingly, the draft requires enterprises to provide the requisite information — such as service user’s name and address, number and location of transmitting or receiving servers, call times, IP address and other personal information supplied by the service user when entering a contract — to the relevant authority, as per a request which is made in accordance with the law. Amendments to Decree