Artificial intelligence is increasingly embedded in business operations across Thailand, from analytics and customer onboarding systems to credit scoring, recruitment tools, and generative AI applications. While public discussion often focuses on innovation and economic opportunity, regulatory attention has increasingly shifted toward how AI systems process personal data and influence decision-making.
On 17 February 2026, Thailand’s Personal Data Protection Committee (PDPC) released draft Guidelines on Personal Data Protection in the Development and Use of Artificial Intelligence, opening them for public consultation. The draft represents one of the clearest regulatory signals to date on how Thai authorities expect organisations to govern AI deployment within the framework of existing data protection law.
Although the guidelines are not legally binding, they provide important insight into how regulators are likely to interpret compliance obligations under the Personal Data Protection Act B.E. 2562 (2019) (PDPA) as AI adoption accelerates. Rather than introducing immediate standalone AI legislation, Thailand appears to be shaping AI governance first through interpretation of existing regulatory frameworks, particularly data protection law.
AI Governance Under Current Data Protection Regulations
Thailand does not currently regulate artificial intelligence through a dedicated or standalone AI statute. Instead, AI deployment is governed indirectly through existing legal frameworks, with the PDPA serving as the most relevant statute where AI systems process personal data.
Under the current regulatory landscape, AI is not treated as a separate legal category. Regulators assess AI systems based on what they do, particularly whether they collect, analyse, generate, or influence decisions involving personal data. Where personal data is processed, the PDPA applies in full regardless of whether processing is carried out manually, algorithmically, or through machine learning models.
This technology-neutral approach reflects Thailand’s broader regulatory philosophy of focusing on processing outcomes and risk exposure rather than the underlying technology itself. AI governance under the PDPA therefore centres on determining:
- who qualifies as the data controller when automated systems are involved;
- how personal data is used for training, inference, or decision-making;
- whether automated outputs produce legal or similarly significant effects on individuals; and
- how organisations maintain meaningful oversight over systems capable of dynamic or probabilistic outputs.
In practice, AI deployment complicates traditional compliance concepts. Organisations must assess whether input data remains identifiable, whether model training constitutes a new processing purpose requiring renewed notification or consent, and how transparency obligations can be satisfied where decision-making logic may not be fully explainable.
While this framework provides flexibility and supports innovation, it also places significant interpretative responsibility on organisations. Businesses must translate established data protection principles into operational governance controls suitable for AI systems. The PDPC’s draft AI guidelines therefore represent an important step toward clarifying how existing PDPA principles should be operationalised in AI-driven environments.
Emerging Patterns in Thailand’s Regulation of AI
While binding AI legislation has not yet been enacted, the PDPC’s draft guidelines indicate how regulators already conceptualise artificial intelligence within existing law. In particular, organisations deploying AI remain accountable as data controllers where they determine the purpose of use and select input data, while AI vendors generally act as data processors.
This allocation may change where AI providers reuse customer data for independent purposes, such as model training or fine-tuning, in which case they may be regarded as data controllers in their own right. The guidelines therefore reinforce a central regulatory message: reliance on automated technologies does not reduce organisational responsibility.
More broadly, Thailand’s regulatory trajectory suggests a gradual movement toward AI-specific governance extending beyond personal data protection. Policy development led through the Electronic Transactions Development Agency (ETDA) and ongoing legislative discussions points toward a risk-based approach, under which obligations scale according to the potential impact of an AI system on individuals or society.
For platforms and operators, this signals a potential shift from “PDPA-only” compliance toward broader algorithmic accountability. Early consultations surrounding Thailand’s future AI framework indicate possible expectations such as documented risk management processes, human oversight mechanisms, operational logging, incident reporting for high-risk systems, and greater accountability for cross-border AI service providers, potentially including local representation requirements.
Rather than establishing a single horizontal AI regulator, oversight is likely to remain integrated across existing sector regulators, reflecting Thailand’s incremental and technology-neutral approach to digital regulation.
What Businesses and AI Operators Should Watch
For AI operators, the emerging regulatory direction suggests that deploying AI does not diminish legal responsibility. Organisations using AI systems will continue to be viewed as accountable actors, particularly where automated tools influence decisions affecting individuals. Reliance on third-party platforms, external APIs, or open-source models is therefore unlikely to displace compliance obligations.
Regulators also appear to be moving toward risk-based oversight. Systems with greater real-world impact, such as automated decision-making, profiling, or large-scale analytics, can be expected to attract increased expectations around human oversight, transparency, and internal governance controls. Future regulation is therefore likely to focus less on licensing AI technology itself and more on how organisations manage algorithmic risk.
In practical terms, businesses should begin viewing AI governance as an emerging compliance function alongside data protection and cybersecurity. As Thailand’s regulatory framework continues to evolve, organisations that embed accountability, monitoring, and oversight into AI deployment will be better positioned to adapt to forthcoming regulation.
For legal advice regarding compliance, handling of data, or any other matters in Thailand’s tech sectors, please contact our Technology, Crypto, and Web3 team at [email protected].
