Key takeaways

  • There is no Indonesian AI law. The ministry's own legal register, read for 2016, 2020, 2022, 2023, 2024, 2025 and 2026, lists no binding AI regulation. Any guide that hands you an Indonesian AI compliance regime is describing something that does not exist.
  • The one AI-specific instrument is Circular Letter of the Minister of Communication and Informatics No. 9 of 2023 on Artificial Intelligence Ethics, signed 19 December 2023. It is guidance, it names nine values, and it creates no enforceable duty.
  • Law No. 27 of 2022 on Personal Data Protection is the instrument that actually bites. Article 2 reaches acts outside Indonesia that affect Indonesian citizens. Article 10 gives a right to object to a decision based solely on automated processing, including profiling, where it has legal effect or significant impact.
  • Article 46 requires written notice of a personal data protection failure within 3 times 24 hours, to the data subject and to the supervisory body. Article 57 caps the administrative fine at 2 per cent of annual revenue. Article 68 sets a criminal fine of up to Rp 6 billion, and Article 70 allows up to ten times the maximum for a corporation.
  • The Electronic Information and Transactions Law, Law No. 11 of 2008 as amended by Law No. 19 of 2016 and Law No. 1 of 2024, punishes intentional distribution of false information under Article 28, with up to six years and Rp 1 billion under Article 45A. It requires intent and it says nothing about artificial intelligence.

There is no Indonesian AI law

The most useful thing this guide can tell an operator is a negative. Indonesia has not enacted an AI statute, and nothing on the books creates an Indonesian AI compliance regime with risk classes, conformity assessment, registration or AI-specific penalties.

That is not an inference from commentary. The Ministry of Communication and Digital publishes a year by year register of every legal product in its field at jdih.komdigi.go.id. Read for 2016, 2020, 2022, 2023, 2024, 2025 and 2026, the register contains no binding regulation on artificial intelligence. The 2025 list runs to forty three instruments covering spectrum, postal services, electronic system governance for child protection, functional job classes and ministry organisation. Not one concerns AI. The 2026 list to August contains a single AI item, Ministerial Decision No. 117 of 2026 of 12 March 2026, a guideline on the use and teaching of digital technology and artificial intelligence in formal, non-formal and informal education. That is a schools instrument, not an operator regime.

The ministry itself was renamed by Presidential Regulation No. 174 of 2024 of 5 November 2024, which establishes the Kementerian Komunikasi dan Digital, the Ministry of Communication and Digital, in place of the former Ministry of Communication and Informatics. Instruments issued before that date carry the old ministerial title, which is why the AI ethics circular below is a circular of the Minister of Communication and Informatics.

The one AI-specific instrument

Circular Letter of the Minister of Communication and Informatics No. 9 of 2023 on Artificial Intelligence Ethics was signed on 19 December 2023 by Minister Budi Arie Setiadi and is recorded as in force on the ministry's register. It is the only instrument in Indonesian law addressed specifically to artificial intelligence and directed at companies and electronic system operators.

Its own text describes what it is: ethical guidance, a reference for values and ethical principles, a framework for an operator's internal policy. A circular of this kind is a policy instrument, not a regulation. It carries no sanction and no supervisory mechanism. An operator that departs from it is not in breach of Indonesian law for that reason alone.

The circular names nine values for AI implementation: inclusivity, humanity, security, accessibility, transparency, credibility and accountability, personal data protection, sustainable development and environment, and intellectual property. Its legal basis section cites nine existing laws and regulations, among them the 2008 Electronic Information and Transactions Law and the 2022 Personal Data Protection Law. That citation pattern is the point. The circular does not create duties; it points at duties that already exist elsewhere.

The Personal Data Protection Law is the instrument that bites

Law No. 27 of 2022 on Personal Data Protection was enacted and promulgated on 17 October 2022 and is recorded as in force. Article 74 gave controllers and processors a maximum of two years from promulgation to bring processing into line, so the compliance transition closed on 17 October 2024. The law itself has been in force since 2022; what ended in 2024 was the grace period.

Article 2 sets the reach. The law applies to persons, public bodies and international organisations acting within Indonesian jurisdiction, and to acts performed outside Indonesia that have legal effect inside Indonesia or that affect Indonesian citizens. An operator with no Indonesian entity is inside the law if its agent processes the personal data of Indonesian users.

Four provisions matter most for an AI agent.

Objection to solely automated decisions, Article 10. A data subject has the right to object to a decision based solely on automated processing, including profiling, that produces a legal effect or has a significant impact on that subject. The provision is Article 10, not Article 25. It is a right to object, framed narrowly around solely automated decisions with legal or significant effect. An operator running credit, screening, underwriting or access decisions for Indonesian users needs a route by which a person can raise that objection and have it handled.

Transfer outside Indonesia, Article 56. A controller may transfer personal data to a controller or processor outside the jurisdiction of the Republic of Indonesia in accordance with the conditions set by the law. The relevant article is 56 alone. Article 57 is administrative sanctions and Articles 58 onward establish the supervisory body, so the range sometimes quoted as Articles 56 to 58 is not a transfer regime.

Lawful basis and transparency, Articles 20 and 21. Article 20 requires a processing basis: explicit consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a public task, or other legitimate interests balanced against the rights of the subject. Article 21 requires that, where processing rests on consent, the controller informs the subject of the lawfulness of processing, the purposes, the types of data, the retention period, the details collected, the duration of processing and the subject's rights. An agent that infers attributes users were never told about has a problem under Article 21 before it has one anywhere else.

Breach notification, Article 46. Where a personal data protection failure occurs, the controller must give written notice within 3 times 24 hours, to the data subject and to the supervisory body. Seventy two hours, not fourteen days. That is the same window as the GDPR gives for notifying a supervisory authority, and Indonesia additionally puts the data subject inside the same window. An operator that has built its incident process around the European timetable already has the clock right; what it needs to add is simultaneous notice to affected individuals.

On penalties, Article 57 paragraph 3 caps the administrative fine at 2 per cent of annual revenue or annual receipts, measured against the variable of the violation. On the criminal side, Article 67 sets fines of up to Rp 5 billion, Rp 4 billion and Rp 5 billion across its three offences, and Article 68 sets a fine of up to Rp 6 billion for falsifying personal data. Article 70 provides that where an offence is committed by a corporation the fine may be up to ten times the maximum for the offence, with additional penalties available including forfeiture of assets, suspension of business and dissolution.

Article 58 places supervision with a body established by the President and responsible to the President. It is not a directorate of the ministry, and the guide previously said otherwise. Operators should note the distinction because it determines who any breach notice under Article 46 is addressed to.

The Electronic Information and Transactions Law

The Electronic Information and Transactions Law is Law No. 11 of 2008, amended first by Law No. 19 of 2016 of 25 November 2016 and then by Law No. 1 of 2024 of 2 January 2024, the second amendment. The second amendment is in force from the date of its promulgation.

Article 28 creates three offences, each requiring intent. Paragraph 1 covers a person who intentionally distributes or transmits electronic information or documents containing a false or misleading notice that causes material loss to consumers in an electronic transaction. Paragraph 2 covers a person who intentionally and without right distributes content that incites or influences others so as to produce hatred or hostility toward an individual or group on grounds of race, nationality, ethnicity, colour, religion, belief, sex, mental disability or physical disability. Paragraph 3 covers a person who intentionally spreads information known to contain a false notice that causes unrest in society. Article 45A sets the penalty for each at up to six years imprisonment and a fine of up to Rp 1 billion.

Two corrections follow for AI operators. First, Law No. 1 of 2024 does not mention artificial intelligence, machine generation or automated content anywhere in its text. There is no Indonesian provision that extends content liability to machine-produced output as such. Second, every Article 28 offence turns on intent, and paragraph 1 is confined to consumer material loss in an electronic transaction. An agent that produces an inaccurate answer is not, without more, inside Article 28. The realistic exposure is an operator that knowingly deploys a system to push false commercial claims, which is a decision a person makes, not an accident a model has.

Civil liability sits outside the statute and follows ordinary Indonesian tort principles, requiring the claimant to show harm, causation and fault.

Electronic system operator registration

Operators serving Indonesian users through an online service sit inside the electronic system operator regime rather than any AI regime. Ministerial Regulation of the Minister of Communication and Informatics No. 5 of 2020 of 16 November 2020 governs private scope electronic system operators, and Ministerial Regulation No. 20 of 2016 of 1 December 2016 governs the protection of personal data in electronic systems. Ministerial Regulation No. 5 of 2025 of 18 March 2025 covers public scope operators and does not apply to commercial deployments.

An AI agent delivered as an online service is an electronic system. The obligations that attach to it are registration and platform obligations of general application, and they do not change because the system uses a model.

What could not be verified

Three claims that circulate widely could not be confirmed at any official source, and this guide no longer carries them.

No Presidential Regulation No. 24 of 2023 adopting a National AI Strategy could be read at peraturan.go.id, jdihn.go.id, jdih.setneg.go.id, peraturan.bpk.go.id or any working ministry register. The ministry's own 2023 register lists Presidential Regulation No. 22 of 2023 on the ministry and no AI instrument. Operators should not plan against a strategy document whose existence cannot be established.

No OJK regulation on artificial intelligence could be found. The OJK regulation directory at ojk.go.id is readable but its filters run through server postbacks that cannot be driven from outside a browser, so the 2024 series could not be enumerated at source. Nothing in the directory listing served to us concerns AI. The previously published claim of an OJK Regulation No. 11 of 2024 establishing a four tier AI risk framework with a Rp 15 billion penalty is withdrawn in full. A financial institution deploying AI in Indonesia should check the OJK directory directly rather than rely on any secondary description, including this one.

BSSN Regulation No. 4 of 2021 could not be read. Both bssn.go.id and jdih.bssn.go.id refuse automated requests with an HTTP 403 response, and no other official domain carried the text. The previously published description of a three category classification of electronic systems with penetration testing duties is withdrawn.

Comparison with the EU AI Act

The contrast is stark rather than subtle. The EU AI Act, Regulation (EU) 2024/1689, is a binding risk-tiered regime with prohibitions, defined high-risk categories, conformity obligations and, under Article 99, penalties of EUR 35 million or 7 per cent of worldwide annual turnover for the Article 5 prohibited practices, EUR 15 million or 3 per cent for other operator obligations, and EUR 7.5 million or 1 per cent for incorrect, incomplete or misleading information, whichever is higher, with lower figures for SMEs and start-ups. Those penalties are enforced by national market surveillance authorities. The AI Office holds the separate general purpose AI regime under Article 101, with a ceiling of EUR 15 million or 3 per cent.

The Digital Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744. Annex III high-risk obligations now apply from 2 December 2027 and Annex I from 2 August 2028. The Article 5 prohibitions, the Article 50 transparency duties, the general purpose AI obligations and the Article 4 AI literacy duty were not deferred and have applied since 2 August 2026.

Indonesia has no counterpart to any of that. What it has are general duties that catch some of the same conduct: an objection right over solely automated decisions, a transfer rule, a transparency duty, a breach clock, and an intent-based content offence. An operator holding EU AI Act documentation is not thereby Indonesian compliant, and equally is not far from it, because the Indonesian duties are narrower and mostly data protection duties in form.

For a full cross-jurisdiction comparison, see the US, EU and UK liability comparison and the Singapore AI Governance Framework guide on this site. For EU AI Act operator obligations in detail, see the Article 26 deployer obligations guide on the EU Regulatory Desk.

Penalties that are actually on the statute book

The table below carries only figures read at the ministry's own legal register. It contains no AI-specific penalty, because Indonesian law provides none.

Instrument Administrative penalty Criminal exposure Source article
Law No. 27 of 2022, personal data protection Up to 2 per cent of annual revenue or annual receipts Fines up to Rp 6 billion, and up to ten times that maximum where the offender is a corporation Articles 57, 67, 68 and 70
Law No. 11 of 2008 as amended by Law No. 1 of 2024, electronic information None provided in the Article 28 and 45A provisions Up to 6 years imprisonment and a fine up to Rp 1 billion, intent required Articles 28 and 45A
Circular Letter No. 9 of 2023, AI ethics None None Advisory instrument, no sanction provision

Practical steps for operators entering the Indonesian market

First, treat this as a data protection exercise, not an AI compliance exercise. If the agent touches the personal data of Indonesian users, Law No. 27 of 2022 applies through Article 2 whether or not the operator has an Indonesian entity. Map the data flows, establish the Article 20 basis for each, and write the Article 21 disclosures so they actually cover inference and profiling.

Second, set the breach clock to 3 times 24 hours and make it dual-track. Article 46 requires written notice to both the data subject and the supervisory body inside the same window. A process that notifies a regulator first and individuals weeks later does not satisfy it.

Third, build the Article 10 objection route. It needs to be reachable by an ordinary user, in Bahasa Indonesia, and it needs to lead somewhere: a decision that can be revisited by a person.

Fourth, hold the transfer question honestly. Article 56 governs transfer outside Indonesian jurisdiction. Most AI infrastructure serving Indonesian users is offshore, so most operators are making a transfer and need to be able to say on what basis.

Fifth, do not build an Indonesian AI governance programme against a rulebook that does not exist. The nine values in Circular Letter No. 9 of 2023 are a reasonable statement of expectation and cost little to adopt, but they are not law, and no Indonesian regulator can currently be satisfied or offended by an AI risk classification. For the insurance and risk management implications of deploying into a jurisdiction whose exposure runs through data protection and content law rather than an AI act, see agentinsured.eu.

Frequently asked questions

Does Indonesia have a binding AI law?

No. The published legal register of the Ministry of Communication and Digital, read year by year from 2016 to August 2026, contains no binding regulation on artificial intelligence. The only AI-specific instruments on it are Circular Letter No. 9 of 2023 on Artificial Intelligence Ethics, which is advisory, and Ministerial Decision No. 117 of 2026 on AI in education. Duties reaching AI agents come from general law: Law No. 27 of 2022 on Personal Data Protection and Law No. 11 of 2008 as amended by Law No. 19 of 2016 and Law No. 1 of 2024.

Is Indonesia's AI ethics circular binding on operators?

No. Circular Letter No. 9 of 2023 was signed on 19 December 2023 and describes itself as ethical guidance and a reference for values and principles. It names nine values: inclusivity, humanity, security, accessibility, transparency, credibility and accountability, personal data protection, sustainable development and environment, and intellectual property. It carries no sanction. Departing from it is not in itself a breach of Indonesian law.

How does Indonesia's Personal Data Protection Law affect AI agent operators?

Law No. 27 of 2022 was promulgated on 17 October 2022, with a two-year compliance transition under Article 74 that closed on 17 October 2024. Article 2 reaches acts outside Indonesia that affect Indonesian citizens. Article 10 gives a right to object to a decision based solely on automated processing, including profiling, with legal effect or significant impact. Article 56 governs transfer outside Indonesian jurisdiction. Article 46 requires written notice of a data protection failure within 3 times 24 hours, to the data subject and the supervisory body.

What are the penalties under the Personal Data Protection Law?

Article 57 paragraph 3 caps the administrative fine at 2 per cent of annual revenue or annual receipts. Article 67 sets criminal fines of up to Rp 5 billion, Rp 4 billion and Rp 5 billion for its three offences, and Article 68 sets up to Rp 6 billion for falsifying personal data. Article 70 allows a corporation to be fined up to ten times the maximum, with forfeiture, suspension or dissolution available. Under Article 58 the supervisory body is established by the President and answers to the President.

Does Indonesia's Electronic Information and Transactions Law cover AI-generated content?

Not expressly. Law No. 1 of 2024 does not mention artificial intelligence or automated generation anywhere. Article 28 punishes intentional distribution of a false or misleading notice causing material loss to consumers in an electronic transaction, intentional incitement of hatred on protected grounds, and intentional spreading of a false notice known to cause public unrest. Article 45A sets up to six years imprisonment and a fine of up to Rp 1 billion. Intent is required in every case.

References

  1. Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi. Promulgated 17 October 2022, status berlaku. Articles 2, 10, 20, 21, 46, 56, 57, 58, 67, 68, 70 and 74. jdih.komdigi.go.id
  2. Surat Edaran Menteri Komunikasi dan Informatika Nomor 9 Tahun 2023 tentang Etika Kecerdasan Artifisial. 19 December 2023, status berlaku. jdih.komdigi.go.id
  3. Undang-Undang Nomor 1 Tahun 2024 tentang Perubahan Kedua atas Undang-Undang Nomor 11 Tahun 2008 tentang Informasi dan Transaksi Elektronik. 2 January 2024. Articles 28 and 45A. jdih.komdigi.go.id
  4. Undang-Undang Nomor 19 Tahun 2016, first amendment to Law No. 11 of 2008, 25 November 2016, and Peraturan Menteri Kominfo Nomor 20 Tahun 2016 tentang Perlindungan Data Pribadi Dalam Sistem Elektronik, 1 December 2016. Annual legal register 2016, jdih.komdigi.go.id
  5. Peraturan Menteri Kominfo Nomor 5 Tahun 2020 tentang Penyelenggara Sistem Elektronik Lingkup Privat, 16 November 2020. Annual legal register 2020, jdih.komdigi.go.id
  6. Peraturan Presiden Nomor 174 Tahun 2024 tentang Kementerian Komunikasi dan Digital, 5 November 2024. Annual legal register 2024, jdih.komdigi.go.id
  7. Annual legal registers of the Ministry of Communication and Digital for 2022, 2023, 2025 and 2026, used to establish the absence of any binding AI regulation. jdih.komdigi.go.id
  8. OJK regulation directory, consulted 17 August 2026. No AI regulation served; year filters run through server postbacks and could not be driven at source. ojk.go.id
  9. Regulation (EU) 2024/1689 (EU AI Act), Article 99 and Article 101, and Regulation (EU) 2026/1744 (Digital Omnibus), in force 27 July 2026.
  10. OECD AI Principles, OECD/LEGAL/0449, revised 3 May 2024.