Digital Trust in Action: ETDA’s Key Priorities for 2027
The Electronic Transactions Development Agency (ETDA) has set out its key priorities for 2027, signaling a significant transition in the development of Thailand’s digital regulatory environment. While much of ETDA’s work in recent years has focused on building regulatory frameworks, technical standards and trusted digital infrastructure, the emphasis for 2027 is increasingly on putting those mechanisms into actual use.
ETDA describes its evolving role as a “Co-Creation Regulator & Facilitator” reflecting an approach that combines regulation with collaboration, experimentation and facilitation. Its 2027 agenda focuses on four principal areas: Digital ID and verifiable digital credentials, AI governance, digital transformation of SMEs, and stronger oversight of digital platform services. The common thread is a shift from establishing digital trust frameworks to demonstrating how those frameworks work in practice.
Digital ID: from proving identity to proving rights and authority:
Digital ID has become one of the most developed components of Thailand’s digital infrastructure. ETDA reports that 28 Digital ID service licenses have been issued, while 1,797 government e-services were connected to Digital ID as of June 2026. Accumulated user accounts reached approximately 162.63 million. Digital ID is already being used across government services involving matters such as taxation, healthcare entitlements and household registration.
The next stage goes beyond simply establishing that a person is who they claim to be. ETDA is moving toward an ecosystem in which individuals and organizations can digitally prove particular facts, qualifications, rights or authority through Verifiable Credentials (VCs).
Initial use cases include digital academic transcripts and caregiver services, where digital credentials can be used to establish a relationship between a vulnerable person and a caregiver. ETDA has also been exploring interoperability for cross-border transactions. The objective is therefore progressively moving from electronic identification toward reusable and independently verifiable digital credentials.
In 2027, ETDA plans to further develop the VC ecosystem, including assessment mechanisms for service providers and a VC Trusted List. Another important initiative is the proposed pilot of a national identification card in VC format in cooperation with relevant government agencies.
The model could materially change the conventional practice of repeatedly submitting copies of identification documents. Instead of disclosing an entire document, VC technology may allow a person to disclose only the information required for a particular transaction. This could make digital transactions more efficient while supporting data minimization and reducing unnecessary circulation of copies of identity documents.
ETDA also plans to promote a Digital Document Wallet, allowing individuals to access and use digital documents electronically, and to expand Digital ID infrastructure to support additional user groups, including foreign nationals.
Of particular relevance to businesses is the Integrated Document Signing Platform (IDSP). Having undergone sandbox testing, the platform is intended to support verification of corporate authority and execution of documents between organizations. If adopted more broadly, infrastructure of this kind could simplify one of the persistent practical issues in electronic contracting: verifying not merely the identity of the individual signing a document, but whether that individual has authority to bind the relevant legal entity.
The implications extend beyond electronic signatures. Businesses may increasingly need systems capable of receiving and verifying digital credentials for customer onboarding, employee qualifications, corporate authorization, contractual documentation and other transactions. Digital identity is consequently developing from a standalone authentication mechanism into part of the infrastructure underlying digital commerce.
AI governance: moving from principles into the sandbox
AI governance is another area where ETDA intends to move from frameworks toward practical implementation.
ETDA has developed draft AI legislation together with more than 12 guidelines, toolkits and related governance materials. AI governance initiatives have been implemented across four major sectors—education, the justice system, government and financial services—covering more than 140 organizations. ETDA has also provided AI governance training across government and reports reaching more than 120,000 users through its AI-related knowledge initiatives.
The next stage centers on the AI Governance Practice Center (AIGPC) and the AI Governance Sandbox.
The AIGPC is expected to operate as a central platform bringing together government agencies, AI developers, businesses and experts. Rather than treating AI governance primarily as a collection of abstract principles, the sandbox approach allows governance requirements to be tested against actual AI systems and use cases.
ETDA has identified several areas requiring particular attention because of their potential risk, including education, children and vulnerable groups, and the justice system. Sandbox testing is expected to examine issues such as risk management, privacy, transparency and compliance with applicable laws. The results may subsequently inform sector-specific guidelines and proposals for regulatory measures. ETDA also intends to develop testing criteria for multilingual AI safety. (ETDA)
This direction is significant for organizations developing or deploying AI. The central compliance question is increasingly likely to move from whether an organization has adopted general AI principles to whether it can demonstrate that those principles are implemented in practice.
Organizations using AI should therefore consider governance mechanisms that document matters such as the purpose and scope of an AI system, risk classification, data governance, privacy implications, human oversight, transparency, testing and monitoring, accountability and procedures for responding when the system produces inappropriate or harmful outcomes.
For higher-risk AI applications, governance documentation may become particularly important. The sandbox model also indicates that regulatory expectations may evolve through testing and practical experience rather than solely through prescriptive legislation.
SMEs Growth: from adopting technology to demonstrating growth
ETDA’s third priority approaches digital trust from an economic development perspective. The objective is to move SMEs from being merely “digitally ready” toward achieving measurable growth through technology.
Thailand’s Digital Maturity Index has indicated that many SMEs remain at the “Digital Follower” level. ETDA’s response has been to develop a model that first assesses the particular digital maturity and operational gaps of a business and then connects that business with appropriate technology, expertise and financing.
The SMEs Growth program has operated across four regions and 16 provinces. ETDA reports participation by 1,697 SMEs and 138 digital providers, with 108 successful business matches. The program generated an estimated THB 689.5 million in combined economic and social impact, of which approximately THB 530.6 million was attributed to SMEs and THB 158.9 million to digital providers.
An important development arising from the program is the SMEs Profile, essentially a development map intended to help businesses understand their current position, identify operational gaps and select appropriate technology and support mechanisms. The approach recognizes that different SMEs face different constraints: one business may require technology, another personnel or skills, while another may require financing or specialist advice.
In 2027, ETDA intends to expand this model, with particular attention to trade and retail, manufacturing, and tourism-related businesses. Importantly, the effectiveness of digital transformation is intended to be assessed by business outcomes, including revenue, costs, productivity, market development and competitiveness.
This represents a meaningful change in the way digital transformation is measured. The relevant question is no longer simply whether an SME has adopted digital technology, but whether the technology produces measurable improvements in the business.
For technology providers, this may similarly change expectations. Solutions that can demonstrate improvements in revenue, cost efficiency, productivity or market access are likely to be more persuasive than technology adoption for its own sake.
Digital platforms: from bringing platforms into the system to regulating conduct
The fourth priority is particularly relevant to digital platform operators.
Thailand’s digital platform services regulatory framework has already brought a substantial number of services within the regulatory system. ETDA reported that 2,133 digital platform services had submitted notifications by August 2026. The next phase is increasingly concerned with what platforms do after entering the system. (ETDA)
ETDA’s 2027 direction can broadly be understood through three regulatory mechanisms.
First, existing requirements applicable to particular categories of platforms are expected to move toward more active implementation. ETDA has specifically identified e-marketplaces and ride-sharing platforms as areas where existing rules must produce practical results.
Second, regulation is increasingly focused on preventing harm at an earlier stage. ETDA’s approach emphasizes platform mechanisms for preventing, detecting and responding to problematic activities rather than relying exclusively on intervention after harm has occurred. Content moderation and measures applicable to social media platforms form part of this broader direction.
Third, ETDA is paying greater attention to transparency and fairness in platform commercial practices. One issue is the structure and disclosure of platform fees and gross profit or “GP” charges. ETDA has acknowledged that responsibility for competition, pricing and related matters may fall within the authority of other regulators. Its approach is therefore based partly on transparency requirements and regulatory coordination rather than attempting to regulate every aspect of platform activity under a single statute. ETDA also plans to develop regulatory guidance for application marketplaces.
This illustrates an important characteristic of the emerging platform regulatory model: co-regulation and regulatory coordination.
Many problems arising on digital platforms involve conduct already regulated elsewhere. Non-compliant products, transportation services, accommodation, competition issues and online fraud may each fall within the responsibility of different authorities. ETDA’s role increasingly involves requiring platforms themselves to establish effective systems for prevention, verification, response and coordination with the competent authority.
The development of the 1212 ETDA Center reinforces this approach. ETDA describes complaint information as a form of system-level “radar”: complaints can be aggregated and analyzed to identify emerging risks and then referred to the responsible authority or used to develop preventive measures.
Platform operators should therefore expect regulatory attention to extend beyond formal notification requirements. Internal processes concerning merchant or service-provider verification, complaint handling, content governance, transparency, risk assessment, cooperation with authorities and remediation may become increasingly important aspects of operational compliance.
A broader transition from rules to implementation:
Taken together, ETDA’s four priorities reveal a broader development in Thailand’s digital regulatory policy.
The earlier stage of digital regulation necessarily concentrated on building infrastructure and establishing rules: Digital ID standards had to be created, AI governance principles developed, SMEs encouraged to adopt technology, and digital platforms brought within an identifiable regulatory framework.
The 2027 agenda ask a different question: do those systems work in practice?
For Digital ID, the question is whether trusted identity infrastructure can support reusable credentials, digital documents and corporate transactions. For AI, it is whether governance principles can be translated into controls capable of being tested against real AI systems. For SMEs, it is whether technology adoption produces measurable economic benefits. For platforms, it is whether regulatory obligations result in safer and fairer digital services.
This also explains ETDA’s characterization of itself as a Co-Creation Regulator & Facilitator. The emerging regulatory model does not rely exclusively on issuing additional rules. It combines standards, trusted lists, sandboxes, guidance, complaint data, cooperation with other regulators and collaboration with the private sector. (ETDA)
For businesses, the practical consequence is that operational readiness will become increasingly important.
Digital service providers should consider whether their architecture can accommodate verifiable credentials and trusted digital documents. Organizations deploying AI should establish governance processes capable of being documented and tested. Technology providers serving SMEs should be able to demonstrate measurable business outcomes. Digital platforms should review not only whether they fall within the regulatory regime but also whether their operational processes satisfy emerging expectations concerning transparency, safety, complaint management and risk mitigation.
The direction of travel is therefore clear: digital trust is moving from policy architecture into day-to-day digital transactions and business operations.
Key Takeaways:
- Digital ID is evolving into broader digital transaction infrastructure. Verifiable Credentials, Digital Document Wallets and corporate authorization mechanisms could change how identity, rights, qualifications and signing authority are established online.
- AI governance is becoming operational. The AIGPC and AI Governance Sandbox are expected to test governance principles against real use cases, particularly in areas presenting higher risks.
- AI users should focus on demonstrable governance. Risk assessments, privacy controls, transparency, human oversight, testing and accountability are increasingly relevant as governance moves from principles to implementation.
- SME digital transformation will be judged increasingly by results. ETDA’s approach emphasizes measurable improvements in revenue, cost, productivity, market access and competitiveness rather than technology adoption alone.
- Digital platform regulation is entering a more operational phase. Platform operators should expect increasing attention to preventive controls, transparency, content and complaint management, risk-based regulation and cooperation with other authorities.
- 2027 will be a year of implementation. Across all four priorities, ETDA’s central objective is to turn digital trust from regulatory and technical frameworks into infrastructure and practices that produce tangible results for individuals and businesses.
Author: Panisa Suwanmatajarn, Managing Partner.
Other Articles