Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has published guidelines establishing a risk-based framework for the responsible use of artificial intelligence by telecom licensees. Released on July 2, 2026, the Guidelines on the Use of Artificial Intelligence for Telecommunications Services address governance structures, ethical principles, lifecycle management, and consumer protection obligations.
Scope and Legal Context
The nonbinding guidelines apply to holders of telecom business licenses under Thailand’s telecom licensing laws, but only with respect to the use of AI in providing licensed telecom services. Entities without such licenses are not directly subject to the guidelines, though they may be affected as third-party AI solution providers to licensees.
The guidelines supplement and should be read alongside existing laws, including the Cybersecurity Act, the Personal Data Protection Act (PDPA), the Computer Crime Act, and the NBTC Notification regarding Measures to Protect Telecommunications Service Users’ Rights Regarding Personal Data, Privacy Rights, and Freedom of Telecommunications, as well as forthcoming AI governance legislation being drafted by the ETDA.
AI Governance Structure
Licensees are expected to establish committees, working groups, or designated officers at both policy and operational levels to set strategic direction for AI use, formulate governance policies and tools, and oversee risk management. Roles, responsibilities, and accountability should be clearly defined for all personnel across every stage of the AI lifecycle—including for third-party AI solution providers and outsourced service providers, whose obligations should be explicitly documented in service agreements.
Core Principles
The guidelines identify six core principles that licensees should adhere to when deploying AI:
AI Lifecycle Governance
The guidelines prescribe governance measures across six stages of the AI lifecycle: solution design, data preparation, model building, deployment, monitoring and evaluation, and decommissioning. Key requirements include:
External and Internal Communications
Licensees should proactively inform consumers when they are interacting with AI systems, such as chatbots or voicebots. They should also provide warnings when AI-driven recommendations may affect consumer decisions, offer the option to switch to a human agent, and maintain feedback and complaint channels.
Internally, licensees are expected to promote AI literacy across all organizational levels. Non-IT staff should have a sufficient understanding of AI usage and associated risks, while technical staff and external personnel involved in AI development should be trained to comply with organizational policies, AI ethics, and applicable regulations.
Next Steps
Telecom licensees should assess their current AI governance structures against the guidelines’ requirements, focusing on governance committees, lifecycle policies, third-party vendor contracts, consumer disclosure mechanisms, and staff training programs. For M&A transactions in the telecom sector, AI governance maturity and data handling practices should also be incorporated into due diligence assessments.