August 4, 2026
.png)
Following the entry into force of the AI Act, the European Union became the first jurisdiction in the world to introduce a comprehensive legal framework governing artificial intelligence systems.
At the same time, an increasing number of countries are developing their own AI regulatory models, seeking to balance technological innovation with effective risk management. Thailand is among these jurisdictions, having introduced its Draft AI Act in 2026. While the proposed framework reflects several concepts found in the EU AI Act, it also introduces notable differences in its scope of application, risk classification, obligations imposed on AI stakeholders, and regulatory oversight mechanisms. As a result, understanding these approaches is becoming increasingly important not only for companies planning to enter the Thai market, but also for international businesses developing or deploying AI systems across multiple jurisdictions.
Until 2026, the use of artificial intelligence systems in Thailand was regulated only on a fragmented basis. Certain aspects of AI were governed by legislation on personal data protection, electronic transactions, cybersecurity, consumer protection, and sector-specific regulations. At the same time, Thailand had no single legislative act defining the legal status of AI systems, establishing uniform requirements for their development, deployment, and use, or creating a comprehensive framework for governmental oversight.
According to the Electronic Transactions Development Agency (ETDA), the rapid adoption of artificial intelligence technologies across the public sector, financial services, healthcare, education, and other industries exposed several legal and regulatory gaps. In particular, the existing legal framework did not provide a consistent approach to AI risk assessment, did not define the obligations of AI developers and users, and lacked dedicated mechanisms for regulatory oversight of high-risk AI applications. At the same time, the Thai Government emphasised that the absence of a clear regulatory framework could undermine both public trust in AI technologies and Thailand's attractiveness as an investment destination within the digital economy.
To address these challenges, ETDA developed the Draft AI Act, which is intended to become Thailand's first comprehensive legislation governing artificial intelligence. According to the Agency's official position, the primary objective of the proposed legislation is to establish a balanced AI governance framework that simultaneously promotes innovation, safeguards human rights, ensures transparency in the use of AI, and provides effective risk management. The Draft AI Act expressly adopts a risk-based approach, under which the level of regulatory oversight will depend on the potential impact of a particular AI system on human rights, freedoms, and public safety, rather than on the mere fact that artificial intelligence technology is being used.
On 2 July 2026, the Electronic Transactions Development Agency (ETDA) released a revised version of the Draft Act on Artificial Intelligence (Draft AI Act) for public consultation, Thailand's first comprehensive legislative proposal dedicated to the regulation of artificial intelligence. The public consultation period was opened for approximately 30 days, after which the draft is expected to be revised in light of stakeholders' comments and submitted for further consideration by the Cabinet and Parliament in accordance with Thailand's legislative procedure. As of today, the Draft AI Act has not yet entered into force and remains at the public consultation and revision stage.
According to ETDA, the Draft AI Act is intended to establish a unified legal framework governing the development, deployment, and use of artificial intelligence systems in Thailand. The primary objectives of the proposed legislation are to promote innovation, strengthen public trust in AI technologies, protect fundamental rights, and establish an effective system of regulatory oversight. At the same time, the Draft AI Act expressly adopts a risk-based approach, under which the intensity of regulatory requirements depends on the potential level of risk that a particular AI system may pose to life, health, safety, or fundamental human rights.
Unlike the previously fragmented regulatory landscape, the Draft AI Act introduces a comprehensive AI governance framework and establishes uniform rules applicable to all key participants in the AI ecosystem. In particular, the proposed legislation provides for:
The Draft AI Act places particular emphasis on high-risk AI systems. For such systems, it proposes specific obligations relating to risk management, human oversight, data quality, technical documentation, post-market monitoring, reporting of serious incidents, and compliance with transparency requirements. Conversely, AI systems presenting minimal risk would be subject to a significantly lighter regulatory regime, reflecting the intention to balance innovation with the protection of public interests.
Thailand’s proposed model for the regulation of artificial intelligence is based on a risk-based approach; however, it does not provide for the same level of regulatory intensity for all AI systems. The Electronic Transactions Development Agency states that applying a single universal regime to all technologies and all levels of risk is a one-size-fits-all approach would not serve Thailand’s interests, as excessively strict regulation could restrict technological development and the implementation of innovation. Instead, the scope of regulatory requirements should be determined depending on the nature of the AI system, the area in which it is used, and its potential impact on human rights, freedoms, and safety.
Official ETDA materials separately identify the use of AI presenting a high level of risk as High-Risk AI. This group is expected to include, in particular, systems whose use may have a significant impact on human rights and freedoms, personal safety, or other interests protected by law. It is specifically in relation to such systems that enhanced regulatory control may be introduced, while more flexible mechanisms — guidelines, standards, codes of conduct, and other soft-law instruments — may be applied to AI presenting a lower level of risk.
At the same time, the available official materials do not indicate that Thailand has already definitively established a closed list of high-risk areas or introduced a formal four-tier classification of AI systems. At present, ETDA describes a general principle under which enhanced control should apply to the use of AI capable of causing significant harm to human rights, freedoms, safety, or dignity. Specific categories, criteria, and corresponding obligations are expected to be further detailed in the final text of the law, subordinate legislation, or acts issued by sector-specific regulators.
Although the final classification methodology has not yet been published, several principal factors likely to determine the level of regulatory intervention can be identified from ETDA’s official position.
First, the nature of the potential consequences for an individual will be assessed. The greater the potential impact of an AI solution on human rights, freedoms, safety, or dignity, the higher its regulatory risk is likely to be.
Second, the context in which the system is used will be relevant. The same technology may present different levels of risk depending on whether it is used for internal analytics, advertising, medical diagnosis, employee assessment, credit decision-making, or the provision of public services.
Third, the degree of AI autonomy and the role of human involvement in the final decision-making process will be taken into account. The level of risk will be higher where the system effectively determines the outcome without a proper possibility for human intervention, verification, or review.
Fourth, transparency, explainability, and the ability to identify a responsible person will remain important criteria. ETDA expressly notes that existing voluntary rules may be insufficient in matters relating to the transparency of AI operations, responsibility for resulting harm, and cases involving unpredictable system errors.
This approach is consistent with the previously adopted Thailand AI Ethics Guidelines, which provide for the assessment of legal, ethical, social, and human rights risks, the maintenance of human oversight, system logging, traceability of outputs, and the possibility of reviewing automated decisions.
At the level of the general concept, the Thai model is similar to the EU AI Act, as both systems are based on the principle that the regulatory burden should depend on the level of risk created by AI.
At the same time, the European model is already significantly more formalised. Regulation (EU) 2024/1689 distinguishes four levels of risk:
AI practices presenting an unacceptable risk are expressly prohibited. High-risk systems include, in particular, AI systems that are safety components of regulated products, as well as systems used in specified areas that may have a significant impact on health, safety, or fundamental rights. Specific transparency obligations are imposed on certain systems, including chatbots, deepfake solutions, and generative content.
Thailand, by contrast, does not currently reproduce this structure mechanically. ETDA’s official concept primarily focuses on high-risk uses of AI and allows for a differentiated combination of mandatory rules, sectoral regulation, and voluntary standards. The Thai model therefore appears to be more flexible and context-specific: the level of control may depend not only on the formal category of the system, but also on the relevant sector, the manner in which it is used, and the position of the competent regulator.
For businesses, this creates both an advantage and legal uncertainty. The advantage lies in the absence of an intention to apply strict requirements to all AI solutions automatically. At the same time, until the final law and subordinate classification criteria are adopted, companies may find it more difficult to determine in advance whether a particular product will be classified as high-risk and which regulator will be responsible for establishing mandatory requirements applicable to it.
For companies, the classification of AI according to its level of risk will have direct practical significance, as it will determine the scope of applicable compliance requirements.
Companies using AI to support internal processes with a limited impact on individuals will likely be able to operate primarily within the framework of voluntary standards, sectoral guidance, and general legislation governing personal data, cybersecurity, consumer protection, and electronic transactions.
By contrast, developers and operators of high-risk systems should expect enhanced requirements concerning:
ETDA also envisages a combination of hard law and soft law. This means that some requirements may be established directly by legislation. At the same time, technical and sector-specific rules may be introduced through guidelines, standards, codes of conduct, or acts of the relevant regulators. The official concept provides for sectoral authorities to be granted powers to introduce control or incentive measures promptly, taking into account the specific features of individual sectors.
For international businesses, this means that not only the AI product itself, but also the specific model of its use in Thailand will need to be assessed. For example, a general-purpose language model as a technological foundation may not be regarded as high-risk in itself; however, its integration into a medical diagnostic system, credit-scoring solution, or recruitment assessment tool may trigger the application of a significantly stricter regulatory regime.