NBTC Issues AI Governance Guidelines for Telecom Licensees
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has issued new guidelines setting out its expectations for the responsible use of artificial intelligence (AI) by telecommunications licensees. Although the guidelines are not legally binding, they establish a comprehensive risk-based framework for AI governance and provide a clear indication of the regulatory standards that the NBTC expects telecom operators to adopt when deploying AI in the provision of telecommunications services.
The guidelines reflect the increasing regulatory focus on AI governance and complement existing legal obligations relating to cybersecurity, personal data protection, and telecommunications. They also align with broader national efforts to develop a comprehensive AI regulatory framework.
Scope of the Guidelines:
The guidelines apply to holders of telecommunications business licenses under Thailand’s telecommunications licensing regime, but only in relation to AI systems used to provide licensed telecommunications services.
Organizations that are not telecommunications licensees are not directly subject to the guidelines. Nevertheless, AI developers, technology vendors, cloud service providers, and outsourced service providers may be indirectly affected because telecommunications licensees are expected to exercise oversight over third-party AI solutions used in their operations. As a result, contractual obligations and vendor due diligence are likely to become increasingly important for suppliers serving the telecommunications sector.
The guidelines should be considered alongside existing legal requirements, including the Personal Data Protection Act, the Cybersecurity Act, the Computer Crime Act, and the NBTC Notification on the Protection of Telecommunications Service Users’ Rights in relation to personal data, privacy, and the freedom of telecommunications. They also complement the broader AI legislation currently under development by the Electronic Transactions Development Agency (ETDA).
Strengthening AI Governance:
A central feature of the guidelines is the expectation that AI governance should extend beyond technical implementation and become an organizational responsibility.
Telecommunications licensees are encouraged to establish governance structures at both the policy and operational levels, such as AI committees, working groups, or designated responsible officers. These governance bodies should oversee AI strategy, establish internal policies, supervise risk management, and define accountability throughout the AI lifecycle.
The guidelines also emphasize that responsibilities should be clearly assigned not only to internal personnel but also to third-party AI solution providers and outsourced service providers. Licensees are expected to ensure that contractual arrangements clearly define each party’s obligations regarding AI governance, risk management, and regulatory compliance.
A Principles-Based Approach to Responsible AI:
Rather than prescribing detailed technical requirements, the guidelines adopt a principles-based approach centered on six core expectations.
First, AI systems should comply with applicable laws, ethical principles, and internationally recognized standards. AI should respect privacy, human dignity, and fundamental rights, and organizations should consider implementing appropriate safeguards, including content filtering, to reduce the risk of generating harmful or unlawful outputs.
Second, AI systems should operate fairly. This includes using representative and reliable training data, assessing potential bias, and taking appropriate measures to mitigate discriminatory outcomes.
Third, cybersecurity and privacy protections should be integrated into AI systems. The guidelines encourage the adoption of internationally recognized security standards and recommend technical safeguards such as encryption, anonymization, and access controls to protect personal data and system integrity.
Fourth, organizations should promote transparency by maintaining documentation regarding AI design, development, and operation, while providing consumers with appropriate information about how AI systems influence decisions or recommendations.
Fifth, accountability should be clearly established throughout the organization. Internal policies should define responsibility for AI outcomes, while consumers should have accessible channels to submit inquiries or complaints regarding AI-enabled services.
Finally, AI systems should be reliable and robust. The guidelines recommend testing AI models to ensure that they produce accurate and consistent results, including under unexpected operating conditions.
Governance Throughout the AI Lifecycle:
The guidelines emphasize that AI governance should be integrated throughout the entire AI lifecycle rather than focusing solely on deployment.
Licensees are expected to conduct risk assessments before development begins, evaluate the capabilities and reliability of third-party AI providers, and maintain appropriate standards for data quality and traceability. Before deployment, AI systems should undergo testing for reliability, fairness, and operational performance.
Once AI systems are operational, organizations should continuously monitor performance, maintain appropriate human oversight, and periodically evaluate whether AI systems continue to operate as intended. The guidelines also address the retirement of AI systems, encouraging secure decommissioning processes that protect data and maintain appropriate records throughout the system’s lifecycle.
This lifecycle-based approach reflects the growing international trend toward continuous AI governance rather than one-time compliance assessments.
Consumer Transparency and Organizational Readiness:
Consumer protection is another significant feature of the guidelines.
Telecommunications licensees are encouraged to notify consumers when they are interacting with AI systems, such as chatbots or voicebots. Where AI-generated recommendations may influence consumer decisions, organizations should provide appropriate disclosures and allow consumers to request assistance from a human representative where appropriate. Effective feedback and complaint mechanisms should also be maintained.
Internally, the guidelines recognize that responsible AI governance requires organization-wide awareness. Licensees are therefore encouraged to provide AI-related training across all levels of the organization. Employees who use AI systems should understand the associated legal and operational risks, while technical personnel and external developers should receive training on organizational AI policies, ethical principles, and applicable regulatory requirements.
Practical Implications:
Although the guidelines do not create new legal obligations, they provide valuable insight into the NBTC’s regulatory expectations and are likely to influence future regulatory supervision and industry best practices.
Telecommunications licensees should consider reviewing their existing AI governance frameworks to determine whether governance responsibilities are clearly assigned and appropriately documented. Organizations should also evaluate AI risk management procedures, update contracts with AI vendors and outsourced service providers, assess consumer disclosure mechanisms, and ensure that staff receive appropriate AI governance training.
The guidelines may also have implications for corporate transactions involving telecommunications businesses. As AI becomes increasingly integrated into telecommunications operations, AI governance maturity, data governance practices, and vendor oversight may become important considerations during legal and regulatory due diligence.
Key Takeaways:
- Telecommunications licensees should review their governance frameworks, contractual arrangements, AI risk management processes, consumer disclosure practices, and staff training programs to align with the NBTC’s expectations.
- The NBTC’s AI guidelines establish a comprehensive risk-based governance framework for telecommunications licensees and provide a clear indication of the regulator’s expectations for responsible AI deployment.
- Although nonbinding, the guidelines are likely to influence regulatory supervision and industry best practices within Thailand’s telecommunications sector.
- AI governance is expected to extend throughout the entire AI lifecycle, encompassing organizational governance, risk management, vendor oversight, cybersecurity, consumer protection, and ongoing monitoring.
Author: Panisa Suwanmatajarn, Managing Partner.
Other Articles
- Consumer Enforcement Intensifies for EV Businesses as Complaint Cases Rise and Labeling Expectations Increase
- TCCT Establishes Two Subcommittees to Strengthen Trade Competition Oversight
- Thailand Revises Visa Exemption Scheme: Shorter Stay Periods and a New Country-Based Category System
- Managing Regulatory Due Diligence for Cross-Border Investors in Financial and Digital Asset Businesses
- BOT: Bank of Thailand Introduces Stricter Rules on Large Cash Transactions to Combat Illicit Flows
- Anti-Bribery: Digital Government Data Integration Raises Compliance Expectations


