guideline · Effective Jan 1, 2025
TH regulates AI through Draft Principles for AI Legislation (Draft Principles of the AI Law).
Draft Principles for AI Legislation (Draft Principles of the AI Law) · effective 2025
Updated 60 days ago · 3 sources · confidence: medium
Overview
Thailand’s approach to artificial intelligence regulation is characterized by a rapid evolution from foundational ethics to a structured, risk-based statutory framework. Initially guided by the 'Digital Thailand – AI Ethics Guideline' and the 'National AI Strategy and Action Plan (2022–2027),' the Thai government has moved toward formalizing oversight through the Electronic Transactions Development Agency (ETDA) and the Ministry of Digital Economy and Society (MDES). The overarching philosophy seeks to balance the promotion of a digital economy with the necessity of protecting fundamental rights, public safety, and national security. This 'dual-track' strategy involves creating a supportive environment for AI innovation—evidenced by the establishment of regulatory sandboxes—while simultaneously preparing a horizontal AI law that imposes mandatory duties on high-risk systems. The government's 'Thailand 4.0' policy identifies AI as a critical engine for growth, targeting key sectors such as smart agriculture, high-value medical services, and digital government. By 2027, the national strategy aims to have trained over 30,000 AI professionals and supported hundreds of local AI startups, all while maintaining a governance framework that ensures these technologies are developed and deployed responsibly. This commitment to 'Trustworthy AI' is not merely a domestic goal but a strategic positioning to make Thailand a regional leader in the ASEAN digital economy. As of 2025, Thailand has consolidated its regulatory efforts into the 'Draft Principles of the AI Law.' This instrument serves as the blueprint for a forthcoming primary Act that will harmonize AI governance across all sectors. The maturity of Thailand's AI landscape is reflected in its institutional readiness, particularly the creation of the AI Governance Center (AIGC) within the ETDA, which provides technical standards and readiness assessments for both public and private entities. The regulatory environment is also heavily influenced by Thailand’s existing digital laws, most notably the Personal Data Protection Act (PDPA), which provides the legal baseline for data processing in AI training and deployment. By aligning with international standards such as the OECD AI Principles and the EU AI Act, Thailand aims to position itself as a regional leader in 'Trustworthy AI' within the ASEAN community. The ongoing development of the National AI Service Platform further illustrates the government's role as both a regulator and an enabler, providing shared infrastructure for AI research while enforcing strict ethical standards for any system that interacts with the public.
Regulatory approach
Thailand’s regulatory architecture is currently shifting from a sectoral and guideline-based model to a horizontal, risk-based framework. Historically, governance was managed through 'soft law' instruments like the 2022 AI Ethics Guidelines, which provided non-binding recommendations for developers and providers. However, the 2025 Draft Principles of the AI Law introduce a more prescriptive, risk-based architecture. This approach classifies AI systems into specific risk buckets: 'Prohibited-risk AI' (uses that are banned due to unacceptable threats to safety or rights, such as social scoring or subliminal manipulation) and 'High-risk AI' (permitted only under strict governance and transparency duties). Lower-risk systems are generally subject to minimal transparency requirements, ensuring that the regulatory burden remains proportionate to the potential harm. This classification system is designed to be dynamic, allowing the ETDA to update the list of high-risk applications as technology evolves and new use cases emerge in the market. This horizontal approach is complemented by sectoral oversight. While the ETDA acts as the central coordinating body, sectoral regulators such as the Bank of Thailand (BOT) and the Securities and Exchange Commission (SEC) retain the authority to issue domain-specific rules. For instance, the BOT’s 2025 'Guiding Principles for AI Risk Management' specifically targets financial institutions, focusing on the 'FEAT' principles (Fairness, Ethics, Accountability, and Transparency). This hybrid model ensures that while there is a national baseline for AI safety, specialized industries can implement more granular controls tailored to their unique operational risks. Furthermore, the use of regulatory sandboxes allows the government to test new regulations in a controlled environment, providing 'safe harbor' protections for innovators while gathering data to inform future subordinate legislation. These sandboxes are particularly active in the fintech and healthtech sectors, where the balance between rapid innovation and consumer protection is most delicate. The ETDA's 'AI Innovation Testing Center' serves as the primary venue for these experiments, offering participants access to technical expertise and regulatory guidance in exchange for transparency and data sharing. The governance of AI in Thailand is a multi-layered system led by the Ministry of Digital Economy and Society (MDES) and its operational arm, the Electronic Transactions Development Agency (ETDA). The ETDA is the primary coordinating regulator, responsible for drafting AI-specific standards, managing the national AI registry, and overseeing the AI Governance Center (AIGC). The AIGC serves as a technical hub, providing tools for risk assessment and helping organizations align their AI systems with national ethics and safety standards. Under the 2025 Draft Principles, the ETDA is expected to gain expanded powers to issue administrative orders, such as cease-and-desist notices for non-compliant high-risk systems. The agency also operates the 'AI Clinic,' a consultation service that helps SMEs understand their compliance obligations under the PDPA and the emerging AI laws. In addition to the ETDA, the National Science and Technology Development Agency (NSTDA) and the National Electronics and Computer Technology Center (NECTEC) play critical roles in the technical and research aspects of AI governance. They act as the secretariat for the National AI Committee, which is chaired by the Prime Minister. This committee provides high-level political steering and ensures that AI initiatives are integrated across various ministries, including Health, Agriculture, and Education. For data-related enforcement, the Personal Data Protection Committee (PDPC) remains the sole authority for investigating breaches of privacy during AI lifecycles, possessing the power to impose significant administrative and criminal penalties. The PDPC often collaborates with the ETDA to ensure that data protection standards are embedded into the technical requirements for AI systems, particularly regarding the use of biometric data and large-scale profiling.
Enforcement & penalties
Enforcement mechanisms for AI in Thailand currently rely on a combination of existing digital statutes and proposed administrative sanctions under the new Draft Principles. Under the Personal Data Protection Act (PDPA), which is already in force, organizations found in violation of data processing rules—such as using personal data for AI training without a lawful basis—can face administrative fines of up to 5 million THB. Furthermore, the PDPA allows for civil liability with punitive damages and criminal penalties, including imprisonment for up to one year for serious breaches involving sensitive data. These existing penalties serve as the primary deterrent for AI-related harms involving personal information. The PDPC has already begun taking a more active role in auditing companies that use automated systems for customer profiling and credit scoring. The 2025 Draft Principles of the AI Law propose a new suite of enforcement tools specifically for AI systems. These include the power for regulators to issue administrative orders to remove or block access to prohibited AI systems and the seizure of physical items embedding non-compliant AI. The draft also envisions a system of administrative fines for failing to register high-risk systems or for neglecting mandatory documentation duties, such as maintaining model cards and risk assessment reports. While the exact fine amounts for AI-specific violations are to be determined in subordinate regulations, the framework emphasizes a corrective approach, allowing regulators to instruct providers to remediate risks before escalating to financial penalties. For the most severe violations, such as the deployment of prohibited AI that causes widespread public harm, the law may allow for the revocation of business licenses and permanent bans on operating digital services in Thailand.
Data protection
The Personal Data Protection Act B.E. 2562 (2019) (PDPA) is the cornerstone of Thailand’s data protection framework and applies directly to the AI lifecycle. All AI developers and providers operating in Thailand must identify a lawful basis for processing personal data, whether for training, testing, or deployment. While consent is a common basis, the PDPA also allows for processing based on legitimate interests or scientific research, provided that adequate safeguards are in place. The law requires strict data minimization and purpose limitation, meaning that data collected for one purpose cannot be used for AI training without ensuring the new use is compatible or obtaining fresh consent. This has led to a growing emphasis on 'Privacy-Enhancing Technologies' (PETs) within the Thai AI community, as developers seek ways to train models without accessing raw personal data. For AI systems, the PDPA imposes significant accountability requirements, including the obligation to conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities. Organizations must also appoint a Data Protection Officer (DPO) if their core activities involve large-scale monitoring or processing of sensitive data, such as biometrics or health records often used in AI. Furthermore, the PDPA regulates cross-border data transfers, which is critical for Thai entities using offshore cloud services or foreign-hosted AI models. These transfers are only permitted to jurisdictions with adequate data protection standards or through PDPC-approved mechanisms, such as Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs). The PDPC is also working on specific guidelines for 'AI Data Governance,' which will provide more clarity on how to handle data bias and ensure the representativeness of training sets under the existing legal framework.
Sector-specific rules
Sectoral regulation in Thailand is most advanced in the financial services industry. The Bank of Thailand (BOT) issued the 'Guiding Principles for Artificial Intelligence Risk Management' in 2025, which applies to all financial institutions and payment service providers. These guidelines require boards and senior management to take direct responsibility for AI risks and ensure that systems are 'FEAT-aligned' (Fair, Ethical, Accountable, and Transparent). The BOT specifically mandates that financial AI systems include mechanisms for human review, especially when AI outputs materially affect consumer rights or credit decisions. It also sets rigorous standards for 'agentic AI' and generative models to prevent hallucinations and financial instability. Financial institutions must also report any significant AI-related incidents to the BOT within a specified timeframe, ensuring a high level of transparency in the banking sector. Other sectors are governed through targeted guidelines and the 'high-risk' designations found in the 2025 Draft Principles. In healthcare, AI systems used for diagnostics or medical decision support are identified as high-risk, requiring enhanced clinical validation and human oversight. The Ministry of Public Health is currently developing a specialized framework for 'Digital Health AI' that will align with the ETDA's standards while addressing the unique safety requirements of medical practice. Public administration and law enforcement are also subject to heightened scrutiny, particularly regarding the use of biometric identification and automated decision-making in public services. While these sectors do not yet have standalone 'AI Acts,' they are required to follow the ETDA’s risk assessment methodologies and the NSTDA’s ethics guidelines for research and development, ensuring a consistent level of safety across the public sector. The SEC is also exploring rules for AI in algorithmic trading to prevent market manipulation and ensure fair access for all investors.
International alignment
Thailand has explicitly aligned its AI regulatory trajectory with international norms to facilitate cross-border digital trade and ensure its AI ecosystem is globally competitive. The 2025 Draft Principles of the AI Law are heavily influenced by the European Union’s AI Act, particularly the adoption of a risk-based classification system and the focus on 'prohibited' versus 'high-risk' use cases. This alignment is intended to reduce compliance friction for Thai companies operating in international markets and for foreign providers entering the Thai market. Thailand also actively participates in ASEAN-level discussions on AI governance, contributing to the development of the ASEAN Guide on AI Governance and Ethics, which seeks to harmonize digital standards across the ten member states. This regional cooperation is seen as vital for creating a unified digital market that can compete with other global tech hubs. Beyond the EU model, Thailand’s guidelines frequently reference the OECD Principles on Artificial Intelligence and the UNESCO Recommendation on the Ethics of AI. The 2022 National AI Ethics Guidelines were designed to bridge these international standards with local legal requirements, such as the PDPA. By adopting globally recognized technical standards—such as ISO/IEC 42001 for AI Management Systems and the NIST AI Risk Management Framework—Thailand ensures that its domestic requirements for documentation, transparency, and robustness are interoperable with those of its major trading partners. This commitment to international alignment is a core component of the National AI Strategy's goal to build a 'trustworthy' national AI infrastructure. The government also engages in bilateral 'Digital Economy Partnership Agreements' (DEPAs) that include specific provisions on AI cooperation, data flows, and ethical standards, further solidifying its place in the global digital landscape.
What's next
The most significant upcoming development in Thailand’s AI landscape is the formalization of the 'Draft Principles of the AI Law' into a primary Bill. Following the public consultation that concluded in June 2025, the ETDA and MDES are expected to submit a revised consolidated draft to the Cabinet for approval. Once approved, the Bill will move through the legislative process in Parliament. This primary law will grant the ETDA and sectoral regulators the statutory authority to issue a wide array of subordinate regulations, including the definitive lists of 'high-risk' AI applications and the specific technical standards for conformity assessments. Stakeholders should also expect the establishment of a formal 'AI Registry' where providers of high-risk systems must submit their documentation before going to market. In parallel, the government is expected to expand its 'AI Innovation Testing Center' (the AI Sandbox) to accommodate more complex generative AI and agentic AI use cases. These sandboxes will likely provide the empirical data needed to refine future rules on 'safe harbor' protections and liability. Stakeholders should also anticipate the release of more granular sectoral codes of practice, particularly in the health and telecommunications sectors, as these agencies align their existing supervisory frameworks with the new national AI law. The transition from Phase 1 to Phase 2 of the National AI Strategy (2024–2027) will also see a shift in focus from foundational infrastructure to large-scale sectoral adoption and the scaling of the National AI Service Platform. This platform is intended to provide a 'one-stop-shop' for AI resources, including datasets, computing power, and compliance tools, specifically targeted at helping Thai SMEs integrate AI into their business models safely and ethically.
guideline · Effective Jan 1, 2025
guideline · Effective Jan 1, 2025
policy · Effective Jan 1, 2023
regulation · Effective Jan 1, 2023
regulation · Effective Jan 1, 2023
regulation · Effective Jan 1, 2022
guideline · Effective Jan 1, 2022
guideline · Effective Jan 1, 2022
Sources:
policy · Effective Jan 1, 2022
act · Effective Jan 1, 2022
act · Effective Jan 1, 2019
guideline · Effective n/a
Sources:
act · Effective n/a
act · Effective n/a
First principles for AI legislation proposed by the Electronic Transactions Development Agency. The new bill will be designed to implement tiered regulation based on risk levels. High-risk AI systems will be subject to stringent measures, while general AI applications will follow best practice guidelines. Key considerations include AI accountability, algorithmic transparency, and safeguards for AI systems that may impact human rights. The use of high-risk AI systems, particularly in healthcare, finance, and government services, will require transparent oversight, specialised regulatory bodies, and adaptive governance to keep pace with technological advancements.
policy · Effective Jan 1, 2022
advisory
Primary coordinator for digital services and AI governance in Thailand.
central_coordinator
Formulates national digital policy and oversees the implementation of the National AI Strategy.
advisory
Regulates and supervises financial institutions and payment systems.
data_protection
Enforces the Personal Data Protection Act (PDPA).
central_coordinator
Technical secretariat for the National AI Committee.
Feb 11, 2026 · guideline_issued
National Cyber Security Commission releases draft guidelines on use of AI
Open source →Jan 6, 2026 · news
Thailand maps long-term semiconductor strategy, pushes toward full value chain
Open source →Aug 3, 2025 · news
2025 APEC Digital and AI Ministerial Statement
Open source →Jun 11, 2025 · guideline_issued
Thailand releases draft guidelines for managing AI risks in financial sector
Open source →May 9, 2025 · news
Thailand unveils draft AI legislation principles, open to public comment
Open source →Feb 13, 2025 · law_amended
Thailand Prime Minister indicates draft AI regulation will be completed soon
Open source →Nov 26, 2024 · guideline_issued
Thailand pushing for AI governance framework for public sector
Open source →Oct 29, 2024 · guideline_issued
Thailand issues generative AI governance guidelines for organisations
Open source →Aug 1, 2024 · law_amended
Thailand invests 1 billion baht to boost AI skills and startups
Open source →May 3, 2024 · news
Thailand forms AI committee to boost digital economy
Open source →Apr 24, 2024 · law_amended
Thailand gears up for AI regulations
Open source →Apr 9, 2024 · law_amended
Thailand Senate approves report advocating AI regulation in election campaigns
Open source →Dec 1, 2022 · news
Thailand launches AI Governance Clinic
Open source →No tracked international memberships yet
Last checked May 26, 2026