On Friday 17 July 2026, two of us from the We’re Humans team, Tacha and Eve, spent the evening at the Pullman Pattaya Hotel G for the AustCham Thailand Eastern Seaboard (ESB) Members Briefing on PDPA and AI governance. The seminar, jointly hosted by AustCham Thailand and BDO, tackled one of the most pressing questions facing businesses today: how to stay compliant with Thailand’s data protection law while adopting AI responsibly. Here is what we learned about PDPA and AI governance readiness, along with the practical steps every organisation can take now.
What PDPA and AI governance readiness actually means
PDPA and AI governance readiness means demonstrating that your organisation both complies with Thailand’s Personal Data Protection Act (PDPA) and governs its AI systems responsibly with clear privacy notices, up-to-date records of processing, documented risk assessments, and controls spanning the entire AI lifecycle. The single biggest message of the briefing was that these are no longer two separate tasks. The moment you use AI to process personal data, your data privacy readiness and your AI risk readiness become the same project.
Why PDPA compliance and AI governance now go together
We’re Humans work with corporate clients across IT support, cybersecurity, IT solutions, and digital marketing. Data protection and AI governance sit right at the centre of that work. As we prepare to launch new products not only in Thailand but in markets around the world where data privacy and AI accountability are non-negotiable, staying ahead of Thailand’s PDPA guidance and its emerging AI regulation is how we keep our advice accurate and our own systems compliant. For a business handling customer data, the same logic applies: AI adoption without governance is a compliance risk waiting to surface.
Inside the seminar: PDPA data privacy readiness meets AI governance.
The session was led by two specialists from BDO Thailand: Netinat Rattanapanya, Advisory Director, and Sneha Chawla, Manager, Tax and Legal. Together they connected the strategic and practical sides of AI governance and PDPA compliance.
Netinat set the strategic frame on the principles of Responsible AI, and how international standards such as the OECD AI Principles, the NIST AI Risk Management Framework (AI RMF), and ISO/IEC 42001 map onto Thailand’s regulatory direction. We were walked through the most common risks businesses run when AI is left unmanaged, the EU AI Act as a reference point, Thailand’s draft AI legislation, and the sector-specific regulators that will shape enforcement here.
Sneha made it concrete for PDPA. She covered how to update Privacy Notices for AI, introduced an AI Project Intake Form, showed how to integrate AI systems into Records of Processing Activities (ROPA), and laid out an AI governance checklist that spans the full AI lifecycle hands-on guidance a business can act on immediately.
“AI is a flaw multiplier”: the core lesson on AI risk readiness.
If one idea summed up the evening, it was this: AI is a flaw multiplier. AI does not remove the weak spots in your existing controls; it magnifies them. Point an AI system at messy data, unclear ownership, or a shaky privacy posture, and you don’t get automation; you get your problems at scale, faster.
The companion message was just as memorable: standards first, regulation follows. The advice was not to wait for Thailand’s AI law to be finalised before acting. Organisations that begin aligning to ISO/IEC 42001 and the NIST AI RMF now will be ready when the law lands and better protected in the meantime.
Your PDPA & AI governance readiness checklist: four practical tools
One reason the seminar was so valuable is that it handed over usable tools, not just theory. These four form a practical PDPA and AI governance readiness checklist any Thai business can start using this week.
1. Privacy Notice six items to update
When you use AI to process customer data, your privacy notice needs to say so. Disclose that AI is involved, whether automated decision-making takes place, which AI or LLM provider you use, what type of data is processed, whether there is a channel to request human review of outputs, and the data subject’s rights.
2. AI Project Intake Form: five questions
Before any new AI project starts, answer five questions: what is the purpose; does it involve personal data; what is the impact on people’s rights; what is the scope of the service provider (will data be used for further training or transferred overseas); and is there human review of the output. It is a simple gate that stops risky projects before they begin.
3. Records of Processing Activities (ROPA)
When an AI system processes personal data, update your ROPA with the name of the AI system, the dataset, the purpose, the legal basis, data recipients and cross-border transfers, the retention period, the DPIA status, and who is responsible for the review.
4. AI Governance Control Checklist: Five stages
The most comprehensive tool covers the entire AI lifecycle in five stages: Design & Intake, Silo & Store, Process & Use, Explain & Trust, and Monitor & Retire. Each stage carries its own controls — risk classification, AI-DPIA, bias and fairness testing, human-in-the-loop review, and eventual retirement of the system.
AI governance standards: ISO/IEC 42001, NIST AI RMF and the EU AI Act
For businesses wondering where to start, the standards referenced throughout the briefing give a clear map. ISO/IEC 42001 provides a certifiable AI management system; the NIST AI Risk Management Framework offers a practical, risk-based method for identifying and mitigating AI harms; the OECD AI Principles set the baseline for values; and the EU AI Act shows where risk-based regulation is heading globally. Adopting these now is the fastest route to PDPA and AI governance readiness before Thailand’s own AI law takes effect.
Networking at the Joint Chambers ESB Sundowners
After the seminar, the Joint Chambers ESB Sundowners brought together members from seven chambers of commerce, with BDO Thailand and WHA Group as sponsors. We talked with people from manufacturing, logistics, hospitality, technology, legal, education, energy, and human resources, as well as decision-makers from across the Eastern Seaboard.
It was also a chance to share our own news: We’re Humans recently won an AI award in the UK. That sparked genuine conversations about our AI products and digital solutions and introduced our team to new contacts who wanted to learn more about what we do.
What PDPA and AI governance readiness means for your business
The takeaway for Thai businesses and for any organisation launching AI-enabled products into privacy-conscious markets is that PDPA compliance and AI governance are now one conversation. The checklists above are a strong starting point, and the “standards first” mindset means you can begin today rather than waiting for the law’s final wording.
This is exactly the work we do at We’re Humans. From cybersecurity and IT solutions to advising on PDPA-aligned processes and responsible AI adoption, we help businesses get ready before regulation forces the issue. If your organisation is mapping its own PDPA and AI governance readiness or preparing to take AI products to market at home and abroad, we would be glad to talk.
Talk to the We’re Humans team about your PDPA and AI governance readiness.
Frequently asked questions
What is PDPA and AI governance readiness?
It is the combined state of complying with Thailand’s Personal Data Protection Act (PDPA) while governing AI systems responsibly, covering privacy notices, records of processing, risk assessments, and controls across the full AI lifecycle.
Does Thailand have an AI law yet?
Not yet in force. Thailand has draft AI legislation in progress. Experts recommend aligning with international standards such as ISO/IEC 42001 and the NIST AI RMF, now the principle of “standards first, regulation follows.”
Which standards should businesses follow for AI governance?
The most referenced are the OECD AI Principles, the NIST AI Risk Management Framework, and ISO/IEC 42001, with the EU AI Act as a benchmark for risk-based regulation.
How do you update a privacy notice for AI under PDPA?
Disclose that AI is involved, whether automated decision-making occurs, which AI or LLM provider is used, what data is processed, how to request human review of outputs, and the data subject’s rights.
Ready to get your business PDPA- and AI-governance-ready? Tacha and Eve on our sales team are your first point of contact. Tell them what you need, and they’ll connect you with the right specialists at We’re Humans, from cybersecurity and IT solutions to web development and responsible AI.
Tacha: 081 576 4688
[email protected]
Eve: 095 052 2536
[email protected]