Thailand's AI governance architecture is still forming. A draft Royal Decree on Business Operations That Use Artificial Intelligence Systems has circulated under the Electronic Transactions Development Agency (ETDA) since roughly 2022 and remains under active revision, proposing a risk-tiered oversight model that echoes the EU AI Act in structure. It has not been enacted. What is enforceable today is Thailand's existing data protection statute, the Personal Data Protection Act B.E. 2562 (2019), which already reaches any AI system processing personal data of individuals in Thailand. For operators, the practical task in 2026 is separating the binding obligation that exists now from the AI-specific framework that is still being written.

Key takeaways

  • Thailand has no enacted cross-sector AI statute as of August 2026. The draft Royal Decree on Business Operations That Use Artificial Intelligence Systems, developed under ETDA, remains a draft instrument that has circulated since around 2022 and continued through revision cycles into 2025 and 2026.
  • The Personal Data Protection Act B.E. 2562 (2019), Thailand's PDPA, is the binding obligation in force today. It applies to any AI system that processes personal data of individuals in Thailand, and it is enforced by the Personal Data Protection Committee (PDPC).
  • ETDA's AI Governance Guideline is voluntary best-practice guidance, not law. It is the practical reference document for operators who want to prepare ahead of the Royal Decree's eventual finalisation.
  • The National AI Strategy and Action Plan 2022-2027, overseen by the Ministry of Digital Economy and Society (MDES), sets the policy direction that ETDA's instruments are built to implement, but the strategy itself does not create enforceable operator obligations.
  • The draft Royal Decree's structure is directionally similar to the EU AI Act, proposing risk-tiered obligations, but the two regimes are at very different legal stages: one is binding regulation already generating compliance activity, the other is still a draft.

The current state: a policy direction, not yet a statute

Thailand's AI governance landscape sits at an earlier legal stage than several of its Southeast Asian neighbours. Where Singapore has published voluntary frameworks alongside binding sector guidance, and Malaysia has combined voluntary principles with binding supervisory guidance from Bank Negara Malaysia, Thailand's AI-specific instrument remains in draft form. For a regional view of how Thailand fits alongside Singapore, Malaysia, China, and other Asia-Pacific jurisdictions, see our Asia-Pacific AI governance landscape overview, which this article does not repeat but treats as the regional companion piece.

What exists in Thailand today is a three-layer structure. The first layer is policy: the National AI Strategy and Action Plan 2022-2027, overseen by the Ministry of Digital Economy and Society (MDES), setting the government's stated direction for AI adoption, talent development, and governance across the seven-year period. The second layer is guidance: the AI Governance Guideline published by the Electronic Transactions Development Agency (ETDA), a voluntary document translating the strategy's governance ambitions into practical recommendations. The third layer is the draft regulatory instrument itself, the Royal Decree on Business Operations That Use Artificial Intelligence Systems, which would, if and when enacted, convert parts of this guidance into binding law. Underneath all three sits the one instrument already binding regardless of AI-specific developments: the Personal Data Protection Act B.E. 2562 (2019), which reaches any AI system processing personal data of individuals in Thailand today. This is the layer operators should treat as the compliance floor.

The draft Royal Decree on Business Operations That Use Artificial Intelligence Systems

ETDA has been developing a draft Royal Decree specifically addressing AI business operations since approximately 2022. Draft versions have circulated for public and stakeholder consultation, and the instrument has continued to be revised through 2025 and into 2026 without reaching final enactment. It has not been confirmed as in force, and operators should not treat any obligations described in draft versions as currently binding.

What is publicly known about the draft's direction is that it proposes a risk-tiered approach to AI oversight, broadly similar in spirit to the structure adopted by the EU AI Act. Rather than applying a single uniform obligation to all AI systems, the draft is understood to distinguish between AI applications based on their potential for harm, with higher-risk applications facing more substantial obligations around documentation and oversight, and lower-risk applications facing lighter expectations. The scope contemplated is understood to extend to businesses operating AI systems in or into Thailand, placing it in the same extraterritorial family as the PDPA and the EU AI Act: obligations attaching based on where the AI system's effects land, not solely where the operating business is incorporated.

Because the decree remains in draft status, this article does not describe specific compliance deadlines, risk-tier thresholds, or penalty amounts for the AI-specific instrument. Any such details reported elsewhere should be treated as provisional until ETDA and the Thai government confirm enactment and publish the final text.

The AI Governance Guideline: the practical reference point today

Separately from the draft Royal Decree, ETDA has published an AI Governance Guideline (sometimes referred to as the Guideline for Artificial Intelligence Governance) intended to guide organisations on responsible AI deployment. Unlike the Royal Decree, it is not pending legislation. It is voluntary best-practice guidance, comparable in function to Singapore's Model AI Governance Framework or Malaysia's MDEC AI Principles: a reference document organisations can adopt now, ahead of any binding requirement, to build governance maturity and produce documentation that will likely map onto the Royal Decree's eventual obligations once enacted.

For operators assessing what to actually do in Thailand in 2026, the guideline is the more actionable of the two ETDA instruments. It provides a structured basis for internal AI governance: documenting how AI systems are developed or procured, how risk is assessed, how oversight is exercised, and how outcomes are monitored. This mirrors the pattern seen in Singapore and Malaysia, where voluntary frameworks published years ahead of binding rules shaped what the eventual binding rules required in substance. The guideline does not carry statutory force and non-adoption creates no direct penalty; its practical value lies in procurement expectations, contractual due diligence, and the documentation trail it produces for eventual regulatory engagement.

The National AI Strategy and Action Plan 2022-2027

The Ministry of Digital Economy and Society oversees Thailand's National AI Strategy and Action Plan 2022-2027, the government's overarching policy document for AI adoption and governance across the seven-year period, spanning talent development, infrastructure, industry adoption, and governance. It is the policy umbrella under which ETDA's guideline and draft decree sit, but the strategy itself does not create enforceable operator obligations; its relevance is directional, signalling where binding regulation is most likely to develop first. Operators should expect Thailand's AI-specific framework to continue maturing over the remainder of the 2022-2027 period, with the Royal Decree the most likely vehicle for converting policy intent into binding law.

PDPA B.E. 2562 (2019): the binding obligation in force today

The Personal Data Protection Act B.E. 2562 (2019), Thailand's PDPA, is the operative binding law for any AI system that processes personal data of individuals in Thailand. It was closely modelled on the EU's General Data Protection Regulation and applies extraterritorially in the same manner: an organisation does not need to be incorporated in Thailand to fall within scope, only to process personal data of individuals located there.

For AI systems specifically, the PDPA's general data protection principles apply without any AI-specific carve-out. Any AI application that collects, stores, uses, or discloses personal data, whether for training, inference, personalisation, or automated decision-making, must satisfy the PDPA's requirements around lawful basis for processing, purpose limitation, data minimisation, data subject rights, and security measures. This means the absence of an enacted AI-specific statute does not leave AI deployments in Thailand unregulated: an organisation running an AI system without a PDPA-compliant legal basis, adequate data subject notice, or appropriate security controls is already exposed to enforcement risk today, regardless of how the AI Royal Decree eventually resolves.

Enforcement architecture: PDPC, ETDA, and MDES

The Personal Data Protection Committee (PDPC) is Thailand's active AI-relevant enforcer today, exercising statutory authority under the PDPA to investigate complaints, issue guidance, and take enforcement action against organisations that violate data protection obligations, including violations arising from AI systems that process personal data unlawfully.

ETDA occupies a different role: it is the body drafting the AI-specific regulatory instrument and publishing voluntary guidance, but it does not currently exercise binding enforcement authority over AI systems as such; its authority in the AI space today is developmental and advisory, pending the Royal Decree's enactment. MDES sits above both bodies as the policy sponsor of the National AI Strategy and does not itself enforce operator-level obligations. In practice: PDPC is who to worry about today for any AI system touching personal data; ETDA and MDES are who to watch for what becomes binding next. Assuming the PDPC's authority extends to AI governance questions beyond personal data would overstate the current legal position.

Penalties: what applies now versus what remains undetermined

The PDPA establishes Thailand's current, operative penalty structure for AI-related liability exposure, since it is the binding statute already in force. The Act provides for administrative fines for non-compliance with its data protection obligations, and separately provides for criminal liability in cases involving unlawful disclosure or use of sensitive personal data that causes damage to a data subject. This gives the PDPC meaningful enforcement authority over any AI deployment that mishandles personal data, and it is the liability exposure operators should be actively managing today.

This article does not state specific Baht fine amounts, because operators should confirm current figures directly against the Act and PDPC enforcement notices rather than a secondary source, and because enforcement amounts can be revised through subordinate regulation. What matters for planning is the qualitative structure: the PDPA combines administrative and, in serious cases, criminal exposure, and that exposure is real and enforceable now. By contrast, the penalty structure for the draft AI Royal Decree remains entirely undetermined, because the instrument has not been enacted. Operators building a compliance budget for Thailand in 2026 should allocate resource to PDPA compliance as the confirmed, present-day obligation, and treat AI Royal Decree readiness as a forward-looking governance investment rather than a penalty-avoidance exercise with a known cost.

Comparison with the EU AI Act

For readers already familiar with the EU AI Act through our EU-focused coverage, the comparison with Thailand's position is useful precisely because of the stage difference. The EU AI Act (Regulation (EU) 2024/1689) is binding cross-sector legislation with direct effect across member states and explicit extraterritorial reach: it applies based on where an AI system's outputs have effect, not where the provider or deployer is incorporated, and it already carries mandatory conformity assessment obligations for high-risk systems along with substantial fines for prohibited uses.

Thailand's draft Royal Decree is structurally aspirational toward a similar model, proposing risk-tiering broadly comparable in spirit, with extraterritorial scope following a similar logic to both the EU Act and Thailand's own PDPA. But structural similarity in a draft does not equate to binding force. The EU AI Act is already generating documentation, conformity assessment, and market surveillance activity across the EU; Thailand's equivalent is still a policy document moving through internal government process.

The enforceable overlap between the two jurisdictions today runs through data protection law rather than AI-specific law. Thailand's PDPA was built on the GDPR template, so an organisation with a mature GDPR compliance programme is typically well positioned to meet most PDPA requirements with targeted local adjustments, though the two remain legally independent obligations requiring separate review rather than automatic equivalence. Organisations already tracking EU AI Act obligations for other markets should treat Thailand today as a PDPA compliance question layered with voluntary ETDA guideline alignment, not as a second EU AI Act-equivalent programme, since that programme does not yet exist in binding form.

Practical guidance for operators deploying AI into Thailand now

Given the draft-stage uncertainty around the AI-specific framework, the following priorities reflect a sensible operator posture as of August 2026.

Treat PDPA compliance as the immediate, non-negotiable obligation. Any AI system processing personal data of individuals in Thailand needs a documented lawful basis, adequate data subject notice, and appropriate security controls, regardless of what happens with the AI Royal Decree. This is the enforceable floor today, and the PDPC's enforcement authority is active now.

Adopt the ETDA AI Governance Guideline voluntarily as a forward positioning move. Governance documentation aligned with the guideline now, covering AI risk assessment, oversight structures, and monitoring processes, produces evidence that will likely map onto the Royal Decree's eventual requirements once enacted, reducing the compliance lift when that transition happens.

Monitor ETDA and MDES communications directly rather than relying on secondary summaries of the draft decree, since the instrument is still being revised and figures reported second-hand may not hold.

Do not assume Thailand readiness from EU AI Act compliance alone. The structural logic is similar, but the Thai framework is not yet binding and the PDPA is a separate legal instrument from GDPR requiring its own review.

Build AI liability risk assessment around the actual exposure, not the anticipated one. Today's real liability driver in Thailand is PDPA-related data protection risk arising from AI systems, not AI-specific regulatory risk, since the latter instrument is not yet in force. Broader analysis of how AI liability insurance markets are pricing this kind of jurisdictional uncertainty is available in the global AI liability insurance market map published on agentinsured.eu.

For organisations comparing Thailand against other Southeast Asian markets with more developed AI governance architecture, our Singapore AI governance guide and Malaysia AI governance guide provide useful comparison points for jurisdictions further along the voluntary-to-binding transition that Thailand is currently navigating.

Frequently asked questions

Has Thailand passed a binding AI law in 2026?

No. As of August 2026, Thailand has not enacted a cross-sector AI statute. The Electronic Transactions Development Agency (ETDA) has circulated a draft Royal Decree on Business Operations That Use Artificial Intelligence Systems since around 2022, and the draft has continued moving through review and revision cycles into 2026. It proposes a risk-tiered oversight model broadly comparable in structure to the EU AI Act, but it remains a draft regulatory instrument and has not been confirmed as enacted law. Operators should treat its obligations as directionally likely rather than final, and should not assume compliance readiness for a decree that has not yet taken legal effect.

What AI-related obligations apply to operators in Thailand today?

The binding obligation in force today is the Personal Data Protection Act B.E. 2562 (2019), Thailand's PDPA, which applies to any organisation that collects, uses, or discloses personal data of individuals in Thailand, including through AI systems, regardless of where the organisation is incorporated. Alongside the PDPA, the Electronic Transactions Development Agency has published an AI Governance Guideline setting out voluntary best-practice recommendations for responsible AI deployment. Organisations operating AI in or into Thailand should treat PDPA compliance as mandatory today and guideline alignment as the practical way to prepare for the draft Royal Decree's eventual obligations.

Who enforces AI-related rules in Thailand?

The Personal Data Protection Committee (PDPC) is the active enforcer today, exercising authority under the PDPA over any AI system that processes personal data of individuals in Thailand. The Electronic Transactions Development Agency (ETDA) is the body drafting and shaping the AI-specific regulatory instrument, the draft Royal Decree on Business Operations That Use Artificial Intelligence Systems, and has also published the AI Governance Guideline. The Ministry of Digital Economy and Society (MDES) oversees the National AI Strategy and Action Plan 2022-2027, which sets the broader policy direction that ETDA's instruments implement. Until the Royal Decree is enacted, there is no dedicated cross-sector AI regulator with independent enforcement powers over AI systems as such.

What penalties apply for AI-related violations in Thailand?

The operative penalty exposure today comes from the PDPA, not from any AI-specific statute. The PDPA establishes a structure of administrative fines for non-compliance with data protection obligations, and separately provides for criminal liability in cases involving unlawful disclosure or use of sensitive personal data that causes damage to a data subject. These penalties apply to any AI system processing personal data of individuals in Thailand, regardless of whether the AI-specific Royal Decree has been enacted. Because the draft Royal Decree has not been finalised, its penalty structure for AI-specific violations remains undetermined, and operators should not rely on any unofficial figures until the instrument is confirmed in force.

How does Thailand's approach compare with the EU AI Act?

Thailand's draft Royal Decree borrows the EU AI Act's risk-tiered structure in spirit, proposing different obligations depending on the risk profile of the AI application. But the two regimes are at different legal stages: the EU AI Act is binding regulation with direct effect and extraterritorial reach, already generating conformity assessment and documentation obligations for high-risk systems. Thailand's equivalent remains a draft instrument. Today, the enforceable overlap between the two jurisdictions runs through data protection law: Thailand's PDPA was closely modelled on GDPR, so organisations with a working GDPR compliance programme are typically most of the way toward PDPA compliance, though the two remain independent obligations requiring separate legal review.

References

  1. Electronic Transactions Development Agency (ETDA), draft Royal Decree on Business Operations That Use Artificial Intelligence Systems, draft circulated from 2022, under development through 2025 and 2026. Ministry of Digital Economy and Society, Thailand.
  2. Electronic Transactions Development Agency (ETDA), AI Governance Guideline (Guideline for Artificial Intelligence Governance). ETDA, Thailand.
  3. Ministry of Digital Economy and Society (MDES), National AI Strategy and Action Plan 2022-2027. Bangkok: MDES.
  4. Thailand, Personal Data Protection Act B.E. 2562 (2019).
  5. Personal Data Protection Committee (PDPC), enforcement notices and guidance under the Personal Data Protection Act B.E. 2562 (2019). Bangkok: PDPC.
  6. European Parliament and Council, Regulation (EU) 2024/1689 of the European Parliament and of the Council on Artificial Intelligence (AI Act), 13 June 2024. Official Journal of the European Union.