Thailand Is Writing Its AI Rules. Build for Them Now, Not After.
Every business we speak to wants AI somewhere in its operations. A chatbot answering customer questions. A model scoring leads or flagging risky transactions. Automated document processing in the back office. Generative AI drafting product descriptions and emails.
Until now, Thai businesses doing this have worked under voluntary guidance. That is changing. Thailand’s Draft Artificial Intelligence Act, developed by the Electronic Transactions Development Agency (ETDA) under the Ministry of Digital Economy and Society, was published for public consultation in July 2026. The consultation closed on 14 August, and officials are now working through the submissions (Thai Examiner, 29 September 2026). On 22 September, ETDA briefed AmCham Thailand’s Digital Governance Council on high-risk AI, certification, standards and regulatory sandboxes.
The law is not yet enacted, and the details may change. But the direction is clear, and for any business building AI into its systems, the time to design for it is now, while it costs a few extra decisions rather than a rebuild.
This article is general information for business and technology leaders, not legal advice.
What the draft proposes
Based on reporting of the consultation draft, the proposed framework has several features that matter to anyone building or buying AI-enabled systems.
A risk-based structure. AI uses would be classified by risk. Some uses could be prohibited outright. High-risk systems would face substantially heavier requirements, and other AI activities could require registration, notification or licensing. The approach is influenced by the EU AI Act but is not a copy.
Transparency for generative AI. Generative AI, chatbots and deepfakes could face specific transparency duties, including machine-readable indicators on prescribed AI-generated or AI-modified content.
Reach beyond Thailand. Overseas providers could fall under the law when their AI affects people in Thailand, and foreign providers of high-risk AI could be required to appoint local representatives.
Data localisation in sensitive sectors. AI used by government and critical information infrastructure could face requirements to process certain data inside Thailand.
Liability across the supply chain. Legal analyses of the draft describe strict and joint liability, meaning several participants in an AI supply chain, from model provider to application developer to the business deploying it, could face the same claim. Industry groups including the Business Software Alliance have asked for this to be changed.
Real enforcement powers. Regulators could order non-compliant AI deployments to be suspended or recalled, and in serious cases blocked in Thailand.
Sandboxes as well as rules. The draft also envisages regulatory sandboxes for controlled experimentation and a national data-sharing mechanism.
Why this is an engineering problem, not just a legal one
Most of the obligations in a law like this cannot be met with a policy document. They have to be built into the software.
If a regulator or customer asks what your AI did, why it made a decision, which data it used and who approved it, the answer has to come from your systems. If the law requires you to label AI-generated content, your platform has to know which content was generated. If liability is shared across a supply chain, you need records that show what each part of the chain did. If a high-risk use needs human oversight, your workflow has to put a human in the loop at the right point and record that they were there.
Systems that bolt AI on as an afterthought, a third-party chatbot widget here, a script calling an AI API there, usually cannot answer any of those questions. Systems designed with AI as a governed component can.
Six things to design for now
Whatever the final text says, these design choices will put you in a strong position, and most of them are good engineering anyway.
An inventory of every AI use. Know where AI is used across your platforms and processes, what it does, which model or provider powers it, and what data it touches. You cannot classify risk for systems you have not listed.
A risk classification for each use. A chatbot answering opening-hours questions is not the same as a model deciding who gets credit or which job applicant is shortlisted. Decide now which of your uses could reasonably be seen as higher risk, and give those more care.
Decision and data logging. Record inputs, outputs, model versions and key decisions for AI features, with sensible retention. Logs are what let you explain, investigate and defend what the system did.
Human oversight built into the workflow. For anything consequential, build the review step into the process, recording the reviewer, the decision, and the time, rather than relying on staff to remember to check.
Content provenance. Track which text, images and documents your systems generated or modified with AI, so labelling becomes a setting rather than a project.
Clear supplier boundaries. Document which AI providers you use, what they are responsible for, and where your data is processed. Review contracts with that in mind, especially if you serve government or critical-infrastructure clients where localisation could apply.
This connects to obligations you already have
None of this sits in isolation. Thailand’s Personal Data Protection Act (PDPA) already applies whenever AI processes personal data. Since 14 September 2026, new PDPC rules require businesses to respond to a person’s request for their data within 30 days. If your AI features copy personal data into places nobody tracks, both obligations get harder at once.
The businesses that will handle the AI Act calmly are the ones whose data is already well structured, whose systems are integrated rather than scattered, and whose AI features were designed as part of the platform rather than added around it.
How we approach it
At WereHumans we build intelligent systems, cloud and data platforms, and security and compliance into the same engagement, because in practice they are the same problem. When we add AI to a client’s platform, logging, oversight and data boundaries are part of the design from the first sprint, not a retrofit after the law passes.
We also run our own platform, UFORGE, which unifies sales, hiring and finance on a single record with compliance designed into the core. It is how we run our own business, and the clearest proof of how we think about building systems that can stand up to an audit.
A practical next step
List every place AI is used in your business today, including the tools individual staff have adopted on their own. For each one, write down what it does, what data it touches and who would notice if it got something wrong. That single page will tell you where your risk is, and it is the starting point for any conversation about getting your systems ready.
Frequently asked questions
Does Thailand have an AI law?
Not yet in force. Thailand’s Draft Artificial Intelligence Act was published for consultation in July 2026; the consultation closed on 14 August 2026, and the draft was still being processed at the end of September. Until it is enacted, voluntary guidelines and existing laws such as the PDPA apply.
Will the Thai AI law apply to small businesses?
The draft is risk-based, so obligations depend mainly on what the AI is used for rather than company size. A business deploying AI in a high-risk use could face heavier duties regardless of size. The final scope will depend on the enacted text.
Does it apply if we use AI tools from overseas providers?
The draft is reported to reach overseas providers whose AI affects people in Thailand, and to spread liability across the AI supply chain. Businesses deploying third-party AI should expect to carry some responsibility for how they use it.
What should we do before the law is final?
Inventory your AI uses, classify them by risk, add logging and human oversight to consequential decisions, track AI-generated content, and document your AI suppliers and where your data is processed. These steps are useful whatever the final text says.
Can WereHumans help us add AI to our systems responsibly?
Yes. We design and build AI features as governed parts of your platform, with logging, oversight and data boundaries built in, alongside the integration and data work that makes AI useful in the first place.
Planning to put AI into your platform? Talk to us first. Call Eve on +66 89 354 9916 or visit werehumans.com.