Legal Update: Thailand Named in the White House Transshipment Report — Legal Exposure and the Government’s Response

Introduction

On 13 August 2026, the White House Office of Trade and Manufacturing Policy published a report entitled The Great Transshipment Scam (the “Report”). The Report identifies more than 40 jurisdictions said to present elevated risk of illegal transshipment of Chinese-origin goods into the United States and places Thailand in the second of three risk tiers.

The Thai Government responded within days, on 15 August 2026, confirmed that technical tariff negotiations with the United States would proceed at the end of August, and on 17 August 2026, the Department of Foreign Trade (“DFT”), Ministry of Commerce (“MOC”), set out the measures Thailand has taken on origin verification and its position on the underlying analysis.

The Report is not a legal instrument: it imposes no duty and creates no liability. Nonetheless, it consolidates a documented U.S. Government position that will inform enforcement targeting, trade remedy proceedings, and the negotiation of an Agreement on Reciprocal Trade (“ART”).

Thailand’s Classification under the Report

The Report groups the identified jurisdictions into three tiers. The first comprises diversified economies with large volumes of China-linked goods and comparatively strong customs systems, including Canada, the European Union, India, Israel, Japan, Mexico, South Korea, and Taiwan. The third comprises smaller economies said to offer specific weak-link advantages, such as low-cost labor, permissive free zones, or limited customs capacity.

Thailand is placed in the second tier, described as economies combining significant transshipment volumes with deep integration into China-linked supply chains, alongside Brazil, Indonesia, Malaysia, Turkey, and Vietnam. The Report characterizes Thailand, Vietnam, Malaysia, and Indonesia as major platforms for electronics, machinery, plastics, footwear, apparel, and components incorporating Chinese-origin inputs.

Thailand is named specifically in two contexts, and the two carry different legal weight.

The first is the Report’s “ugly sister city” analysis, which pairs foreign industrial corridors with U.S. regions producing the same goods, on the premise that work gained in one is work lost in the other. Thailand’s entry pairs the Ayutthaya–Samut Prakan corridor — linked to thermostats under HS 903210 — with the Minneapolis–St. Paul instruments sector. This is an inference drawn from trade statistics rather than a finding against any specific company, and the Report itself describes the pairings as illustrative. It nonetheless signals to U.S. Customs and Border Protection (“CBP”) which product code and geographic area warrant closer scrutiny.

The second reference concerns a decided case. The Report cites circumvention findings on solar cells and modules, in which the U.S. Department of Commerce determined that duties on Chinese goods were being evaded through final processing in Cambodia, Malaysia, Thailand, and Vietnam. Thailand therefore already has an enforcement record on this issue.

Thailand’s Response

According to MOC figures cited on 15 August 2026, approximately 72 percent of Thai product lines under Section 301 and Section 232 measures are already exempt, leaving roughly 28 percent still subject to the additional tariff. The exemptions span eight industry groups:

  • Electronic equipment and electrical machinery;
  • Machinery and components;
  • Iron and steel;
  • Articles of iron or steel;
  • Plastics and plastic products;
  • Vehicles and components;
  • Copper and copper products; and
  • Measuring, medical, and optical instruments.

Four of these groups fall under Section 232. As explained below, their inclusion reflects a distinction: goods in those categories are excluded from Section 301 to prevent double charging, rather than relieved of duty altogether.

Thailand is responding on three fronts.

Origin verification: The DFT has reported that the watch list operated jointly with CBP has been expanded from 49 items covering 194 tariff lines to 67 items covering 274 tariff lines, effective 1 June 2026. The DFT is developing an AI-assisted origin risk assessment system, has trained more than 2,000 operators on rules of origin and local content requirements, and has increased factory inspections, retrospective origin audits, and data linkage with the Customs Department, the Department of Industrial Works, and provincial commercial offices. The DFT and the Customs Department were scheduled to meet the Office of the United States Trade Representative (“USTR”) between 28 and 31 August 2026.

Negotiation: The Government confirmed on 15 August 2026 that technical tariff discussions would take place at the end of August, led by the Deputy Prime Minister and Minister of Commerce. It cited Thai private-sector investment in the United States of close to USD 20 billion as evidence of mutual economic interest, and denied reports that the negotiations were linked to any security or military arrangement.

The trade surplus: Thailand exports more to the United States than it imports, but at least 30 percent of those exports are produced by U.S. companies operating manufacturing bases in Thailand. On Thailand’s analysis, the bilateral surplus therefore measures the depth of a shared supply chain rather than a one-sided advantage, and cannot be read from the headline figure alone. It must instead be assessed together with investment flows, the location of production, and the broader scope of economic activity between the two countries.

Key Takeaways

  • The Report places Thailand in Tier 2 of a three-tier transshipment risk classification, alongside Brazil, Indonesia, Malaysia, Turkey, and Vietnam.
  • The Report is analytical rather than legal. It imposes no measure and expressly acknowledges that the trade patterns it identifies do not, by themselves, establish illegal transshipment.
  • Thailand has expanded its CBP watch list to 67 items and 274 tariff lines effective 1 June 2026, is deploying AI-assisted origin risk assessment, and met with the USTR between 28 and 31 August 2026.
  • Approximately 72 percent of Thai product lines under Section 301 and Section 232 are already exempt, with roughly 28 percent remaining exposed.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

DBD Opens Consultation on Exempting Five Business Categories from Foreign Business Licensing

Introduction

The Department of Business Development (the “DBD”) has published an announcement inviting public comments on the principles of a draft Ministerial Regulation Prescribing Businesses Not Requiring a License for the Operation of Business by Foreigners, B.E. …. (the “Draft Regulation”).

The Draft Regulation would allow foreign nationals to operate five categories of business without obtaining a license under the Foreign Business Act B.E. 2542 (1999) (the “FBA”). All five categories are already supervised by a sector regulator under specific legislation, reflecting the removal of duplicate licensing rather than the liberalization of previously unregulated activity.

Background

Section 9 of the FBA requires the Foreign Business Committee (the “Committee”) to review the restricted business categories under the lists annexed to the FBA at least once a year. Following its reviews for 2024 (B.E. 2567) and 2025 (B.E. 2568), the Committee resolved to propose removing five business activities from the restricted categories. The Committee reasoned that the businesses concerned are already supervised by specific agencies under specific laws, so removing them would reduce duplication in state oversight. It also considered that the exemptions are consistent with economic development and with the readiness of Thai operators to compete; further, because certain of the activities are provided only to affiliated companies, exempting them would reduce costs and facilitate business operations without exposing Thai operators to new competition.

Consultation

The consultation itself reflects a recent procedural change. Section 5 of the Act on Legislative Drafting and Evaluation of Law B.E. 2562 (2019) requires state agencies to conduct consultation and impact analysis before enacting any law, to disclose the results, and to take them into account at every stage of the process; this requirement applies to ministerial regulations by analogy.

On 10 March 2026 (B.E. 2569), the Cabinet approved recommendations of the Law Development Commission extending the minimum consultation period from not less than 15 days to not less than 30 days, and requiring agencies to consult on the principles of a law before it is drafted, in addition to consulting on the drafted text.

The present exercise is therefore a first-stage consultation on principles. The text of the Draft Regulation has not yet been produced, and a further consultation on the drafted provisions is expected to follow.

The consultation period runs from 10 August 2026 to 30 September 2026 (B.E. 2569). Comments may be submitted through the Central Legal System website and the DBD website.

The Five Proposed Categories

1. Businesses related to, supporting, or necessary for securities or derivatives business

A foreign national conducting any of these activities must already be licensed by the Office of the Securities and Exchange Commission (the “SEC Office”) to operate a securities business under the securities and exchange law, or a derivatives business under the derivatives law, and must obtain the SEC Office’s approval before commencing the additional activity.

2. Aircraft maintenance services

This covers the maintenance of aircraft, aircraft major components, appliances, and aircraft parts under the air navigation law. The Air Navigation Act B.E. 2497 (1954) (the “ANA”) requires a repair station certificate, issued in three types corresponding respectively to aircraft, aircraft major components, and appliances and parts. The ANA prohibits operating a repair station without such a certificate and requires applicants to meet prescribed qualifications. The certificate is issued by the Director of the Civil Aviation Authority of Thailand (“CAAT”), which would become the single licensing authority for the activity.

3. Procuring customers to offer financial products of companies within a financial business group

Please see details of explanation in Item 4.

4. Debt collection services provided to companies within a financial business group

For categories 3 and 4, the foreign operator must itself be a company within a financial business group and may provide the relevant services only to other companies within that group. The term “financial business group” follows the Bank of Thailand (“BOT”) notification, which covers a commercial bank together with its parent company, subsidiaries at every tier, and joint ventures, whether domestic or foreign. Both activities constitute a supporting business, and where the group company is itself a commercial bank, they fall within the “other services” framework.

One qualification applies to debt collection: where collection is made from a debtor who is a natural person, the activity constitutes a debt collection business under the Debt Collection Act B.E. 2558 (2015) and must be registered in accordance with the criteria, methods, and conditions prescribed under that Act and its associated Ministerial Regulation.

5. Service business where a state enterprise is the counterparty

This category differs in nature from the others: it is not a new exemption but a correction to an existing one.

The business already appears in the Ministerial Regulation Prescribing Service Businesses Not Requiring a License for Foreigners (No. 3), B.E. 2560 (2017), which was issued when the applicable budget legislation was the Budget Procedure Act B.E. 2502 (1959) (the “2502 BPA”). The Budget Procedure Act B.E. 2561 (2018) (the “2561 BPA”) subsequently narrowed the definition of “state enterprise” by excluding limited companies and public limited companies in which state enterprises hold more than 50 percent of the capital. The transitional provision of the 2561 BPA, however, provides that references to “state enterprise” in pre-existing legislation continue to carry the meaning under the 2502 BPA.

As a result, the term used in the 2017 Ministerial Regulation still bears the older, wider meaning, which is inconsistent with the definition now in force. The DBD proposes to align the reference with the 2561 BPA, together with a transitional provision preserving the rights of foreign nationals already providing services to state enterprises under the former definition before the Draft Regulation takes effect.

Legal Significance

The exemption removes the requirement to obtain the FBL. However, a foreign national or entity relying on it must still obtain the licenses and approvals from the other agencies regulating such activities as follows:

  • SEC Office licensing and approval for the securities-related activities;
  • A CAAT repair station certificate for aircraft maintenance;
  • The BOT financial business group framework for the two financial support services; and
  • Registration under the Debt Collection Act where collection is made from natural persons.

The scope conditions are also narrow and should be read closely. Categories 3 and 4 are available only to a company within a financial business group serving other companies within the same group — a limitation expressly intended to confine the commercial reach of the exemption so that Thai operators are not affected. Category 1 is confined to management, marketing, human resources, and information technology services, and to a defined class of recipients.

For category 5, the practical question runs the other way. Because the definition of “state enterprise” has narrowed, some foreign operators currently serving state-enterprise subsidiaries may fall outside the exemption once the reference is updated. The proposed transitional provision is intended to address this, and its drafting will matter to those affected.

Key Takeaways

  • The DBD is consulting on the principles of a Draft Regulation that would exempt five business categories from FBA licensing. The proposal remains subject to the legislative process and does not yet have legal effect.
  • The proposal aims to reduce regulatory duplication in areas where specific sectoral laws and regulators already apply.
  • Comments are open until 30 September 2026. This is a principles-stage consultation, and a second consultation on the drafted text is expected before the Draft Regulation is finalized.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Government Support for Small and Medium Enterprises (SMEs): Four New Economic Working Groups

Introduction

On 10 August 2026, Ms. Suphajee Suthumpun, Deputy Prime Minister and Minister of Commerce (“MOC”), chaired the first 2026 meeting of the Sub-Committee on the Development of Trade, Tourism and the Community Economy (the “Sub-Committee”). The Sub-Committee resolved to establish four specialized working groups tasked with restructuring the Thai economy across four dimensions:

  • the creative and visitor economy;
  • high-value agriculture and food security;
  • the community economy and SMEs; and
  • international trade.

The initiative is built on a two-tier delivery model:

  • Quick Big Win (short-term): targets measurable results within 6 to 12 months, principally by reviewing and removing regulatory requirements that obstruct business. This tier is deliberately confined to measures achievable without amending primary legislation and without requiring substantial budget allocation.
  • Big Win (long-term): targets structural reform over a two-to-four-year horizon to strengthen Thailand’s international competitiveness.

For businesses — particularly SMEs — the initiative carries particular significance. The MOC has identified small operators as accounting for approximately 35 percent of total national income, and the working group dedicated to the community economy and SMEs has been given an express mandate covering the entire entrepreneurial lifecycle, from business formation through to scale-up.

The initiative also places strong emphasis on regulatory and administrative reform. In particular, the Quick Big Win framework is intended to deliver practical improvements through measures that can generally be implemented without amendments to primary legislation.

The Four Working Groups

  1. Creative Economy and Visitor Economy
    This group aims to extend the policy frame beyond conventional tourism to a broader visitor economy that includes those travelling to Thailand for education, business, and wellness purposes. Its work draws on Thailand’s cultural capital, identity, and visitor experience, and seeks to connect secondary cities and local communities to visitor spending.
  2. Agricultural Products, Food Security, and High-Value Agriculture
    This group addresses the agricultural sector across the full value chain — upstream production, midstream processing, and downstream marketing — with the goal of moving Thai agriculture toward higher-value output, linking the sector more closely to industry and investment, and reinforcing food security.
  3. Community Economy and Small and Medium Enterprises (SMEs)
    This group covers the entrepreneurial ecosystem as a whole: reducing licensing burdens, streamlining permit processes, building operator knowledge, upgrading goods and services, and promoting both scale-up and fair competition. Wholesale and retail trade is treated as a connected dimension of the same mandate. The group’s focus reflects the Government’s broader objective of improving the business environment for SMEs through practical regulatory and administrative reform.
  4. International Trade
    This group focuses on promoting a more balanced import-export position, opening new markets, increasing utilization of existing free trade agreements, and responding to geopolitical pressure and non-tariff measures. It also carries the specific objectives of increasing SMEs’ share of the export structure and reducing dependency on any single market, thereby strengthening the resilience and international competitiveness of Thai businesses.

Legal and Regulatory Context

The Quick Big Win initiative is expected to be implemented through existing legal and administrative mechanisms, including:

  • Facilitation of Licensing and Public Services Consideration Act B.E. 2569 (2026): streamlines licensing procedures and public service delivery through new administrative mechanisms, replacing and expanding the earlier framework under the Facilitation of Official Licensing Consideration Act B.E. 2558 (2015).
  • Act on Legislative Drafting and Evaluation of Law B.E. 2562 (2019): facilitates stakeholder participation in the law-making and regulatory reform process.
  • SME Promotion Act B.E. 2543 (2000): provides the institutional framework for SME development and policy coordination.

These instruments provide the legal and administrative foundation for implementing the Quick Big Win agenda, particularly in relation to licensing simplification, regulatory reform, public service efficiency, and SME development.

Key Takeaways

  • The initiative underscores the strategic importance of SMEs in driving inclusive and sustainable economic growth.
  • The Quick Big Win framework aims to deliver measurable regulatory and administrative improvements within 6 to 12 months, primarily through reforms that do not require legislative amendment.
  • The Community Economy and SMEs Working Group has been tasked with supporting businesses throughout the entrepreneurial lifecycle — from establishment and compliance to expansion and competitiveness.
  • Businesses should closely monitor developments over the next 6 to 12 months and take advantage of opportunities to raise regulatory concerns as reforms are implemented.
  • Although the initiative does not create binding legal obligations, it offers an early indication of the Government’s priorities for future economic and regulatory reform.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Cabinet Approves Draft Ministerial Regulation Introducing Per-Item Fees for DBD Data Linkage Services

On August 7, 2026, The Deputy Government Spokesperson announced that the Cabinet of Thailand (“Cabinet”) has approved in principle a draft Ministerial Regulation Prescribing Fee Rates and Fee Exemptions for Registration, Requests for Document Inspection, Requests for Certified Copies, and Other Fees Relating to Partnerships and Limited Companies B.E. …. (“Draft Regulation”), as proposed by the Ministry of Commerce (“MOC”). The Draft Regulation has been referred to and is currently under the Office of the Council of State’s review. The Cabinet also instructed the MOC to take into account comments from the Office of the National Economic and Social Development Council regarding this Draft Regulation.

Background

Members of the public and businesses can currently verify juristic person information through a data linkage between the Department of Business Development (“DBD”) computer network and the user’s own system. Under the Ministerial Regulation Prescribing Fee Rates, Fee Reductions and Fee Exemptions Relating to Partnerships and Limited Companies B.E. 2563 (2020) (the “2563 Regulation”), a fee of THB 30 is charged per data set, with each set comprising six items:

  • name of the partnership or limited company
  • director information
  • number and names of authorized directors
  • registered capital
  • head office and branch locations
  • corporate objectives

The current system does not permit partial data requests: a user seeking only a single item — for example, registered capital — must nevertheless pay THB 30 for the full data set. The MOC considers this structure an unnecessary cost burden on both the public and private sectors, an obstacle to digital government development, and inconsistent with modern business practices that call for selective data access.

The Draft Regulation therefore aims to lower data-linkage service costs for juristic person verification by the public and private sectors. It also seeks to encourage corporate transactions through reliable electronic platforms, accelerate digital transformation in government, facilitate inter-agency data integration, and enable the DBD to expand its service coverage.

Key Changes

  • Introduction of a per-item fee. A new fee of THB 5 per individual item will apply to company certificate data. Users may still request the complete data set at the existing rate of THB 30, while the installation fee for the data linkage program remains THB 3,000 per instance. This allows users to select and pay only for the items they require.
  • Removal of the expired e-Registration discount. Clause 4 of the 2563 Regulation — which granted a 50 percent reduction on certain registration fees for partnerships and limited companies filing through the electronic juristic person registration system between 1 January 2021 and 31 December 2023 — will be deleted, as the discount period has already lapsed.

Key Takeaways

  • Users of the DBD data linkage service will be able to obtain individual certificate items at THB 5 each, rather than paying THB 30 for the full six-item data set.
  • For a typical two-item request, cost will fall from THB 30 to THB 10.
  • The THB 3,000 installation fee and the THB 30 full-set option are retained; all other registration and document fees are unaffected.
  • The Draft Regulation remains subject to review by the Office of the Council of State and is not yet in force. Businesses relying on the data linkage service should monitor the Royal Gazette for the effective date.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Big Data: Thailand Approves National Strategy to Accelerate AI and Data-Driven Economy

Thailand’s Cabinet has acknowledged the draft National Big Data Strategy, establishing the country’s first comprehensive policy framework for the development and use of big data as a foundation for digital government, artificial intelligence (AI), and a data-driven economy.

The strategy is intended to provide a unified direction for government agencies to improve data management, strengthen digital infrastructure, and promote the practical use of data in both the public and private sectors.

Why the strategy matters:

Although the strategy is not legislation and does not itself impose new legal obligations, it signals the Government’s long-term policy direction. Businesses operating in Thailand—particularly technology companies, cloud service providers, AI developers, healthcare providers, financial institutions, and organizations handling government-related data—should expect increased public investment and regulatory attention in data governance and AI.

The strategy also reinforces the Government’s objective of using data as a strategic national asset to improve public administration, support economic growth, and enhance Thailand’s digital competitiveness.

Key objectives:

According to the announcement, the strategy seeks to:

  • establish an integrated national big data ecosystem;
  • improve evidence-based policy making through better use of government data;
  • support AI adoption across government and industry;
  • enhance Thailand’s digital competitiveness; and
  • promote responsible and systematic use of data.

The Government has also set measurable goals, including increasing the economic value generated from big data and positioning Thailand among the world’s leading countries in big data capability.

Four strategic pillars:

The strategy consists of four principal initiatives.

1. Building national data infrastructure

The Government plans to strengthen core digital infrastructure through initiatives such as:

  • Government Cloud;
  • Government Data Catalog; and
  • National Big Data Platform.

These projects are intended to improve interoperability and enable more effective data sharing among government agencies.

2. Expanding practical use of data

The strategy encourages wider use of data analytics to address national priorities, including:

  • healthcare;
  • tourism;
  • environmental management;
  • agriculture; and
  • trade and economic development.

This reflects the Government’s intention to move beyond data collection toward data-driven decision-making.

3. Accelerating AI adoption

A significant component of the strategy is the promotion of AI across the public and private sectors.

The Government intends to:

  • expand AI applications in government services and industry;
  • support development of Thai-language AI models; and
  • establish datasets suitable for AI development.

These initiatives may create opportunities for AI developers, cloud providers, data platform operators, and businesses offering AI-enabled solutions.

4. Developing human capital

Recognizing that technology alone is insufficient, the strategy also emphasizes workforce development by increasing the number of professionals with expertise in big data and AI.

The Government aims to significantly expand the pool of skilled personnel capable of supporting Thailand’s digital transformation.

Legal and regulatory implications:

The strategy itself does not amend Thailand’s existing legal framework, including laws governing personal data protection, cybersecurity, or digital government.

Nevertheless, it indicates that future regulatory and policy initiatives are likely to focus on:

  • enhanced government data governance;
  • improved standards for data interoperability;
  • greater integration of public-sector datasets;
  • expanded use of AI in government services; and
  • stronger digital infrastructure supporting government cloud and data-sharing initiatives.

Organizations participating in government projects or processing government-related data should therefore continue monitoring future implementing measures, technical standards, procurement requirements, and sector-specific regulations that may follow.

Looking ahead:

The National Big Data Strategy represents an important policy milestone in Thailand’s digital transformation agenda. While much of its implementation will depend on future projects, funding, and regulatory measures, the strategy demonstrates the Government’s commitment to treating data and AI as key drivers of economic development and public-sector modernization.

For businesses, the announcement suggests increasing opportunities in AI, cloud computing, digital infrastructure, and government technology, while reinforcing the importance of robust data governance and regulatory compliance.

Key takeaways:

  • Businesses involved in AI, cloud services, digital infrastructure, and government technology should monitor future implementing regulations, technical standards, and procurement initiatives arising from the strategy.
  • Thailand has adopted its first comprehensive national strategy for big data development.
  • The strategy serves as a policy framework rather than creating immediate legal obligations.
  • Four priorities include national data infrastructure, wider use of data analytics, AI adoption, and workforce development.
  • Government investment is expected to accelerate in cloud infrastructure, data platforms, and AI ecosystems.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Tightens Registration Requirements for Partnerships and Limited Companies with Foreign Participation

Nominees: A Threat to Thailand’s Economy

Nominee arrangements — in which Thai nationals hold shares or capital contributions on behalf of foreign investors — have remained a longstanding compliance concern under the Foreign Business Act B.E. 2542 (1999) (the “FBA”). The Department of Business Development (the “DBD”) has now shifted a significant part of that scrutiny to the registration stage itself.

The use of nominees is a major national concern that undermines Thailand’s economic and business security by distorting market competition, reducing tax revenue, and eroding investor confidence. Foreign operators who rely on nominees unfairly bypass statutory business restrictions, undercutting law-abiding foreign investors and overwhelming Thai small and medium-sized enterprises (SMEs) that cannot compete against superior capital and resources — ultimately contributing to job losses and business closures. Nominee structures also facilitate tax evasion, money laundering, and other illicit financial activity, which compromises state revenue collection and damages Thailand’s international reputation by exposing gaps in regulatory and legal enforcement.

For these reasons, the rigorous inspection of, and crackdown on, nominee arrangements is a critical measure to protect the country’s economic interests, ensure fair competition, and safeguard the long-term stability of the Thai economy.

Background

Initial screening at the company incorporation stage previously offered partial protection against nominee risk by verifying Thai investment capital. However, bad actors circumvented these controls through subsequent corporate amendments — transferring shares or directorships to foreign nationals only after the company had already secured initial approval.

Legal Basis

To close this loophole, the DBD issued the “Central Partnership and Company Registrar Order No. 2/2569, Prescribing the Criteria and Supporting Documents for Applications for the Registration of the Incorporation and Amendment of Partnerships and Limited Companies Where Foreign Nationals Participate in the Investment or Hold Signing Authority in Partnerships and Limited Companies” (the “Order”). The Order took effect on 1 August 2026.

The Order extends DBD oversight across the full business lifecycle — from incorporation through post-registration amendments — to prevent unauthorized structural changes, while imposing stricter documentation requirements on all relevant registration applications.

It consolidates existing requirements by repealing two earlier orders:

  1. Order No. 2/2568, dated 1 December 2025 (B.E. 2568), concerning the registration of incorporation involving foreign investment, foreign directors, or foreign authorized signatories in a legal entity; and
  2. Order No. 1/2569, dated 16 March 2026 (B.E. 2569), concerning amendment registrations admitting foreign nationals as partners or as authorized signatory directors.

According to its preamble, the Order is intended to enhance the credibility of the commercial register, to prevent the concealment or disguise of funds derived from unlawful conduct through nominee arrangements, and to deter Thai nationals from providing assistance or support to, or jointly operating a business with, foreign nationals in the nature of a nominee.

New Legal Requirements

1. Registration of Incorporation

The additional documentary requirements apply to an application for the registration of incorporation in either of the following cases:

  • a partnership or limited company in which a foreign partner or shareholder contributes, or holds, less than 50% of the capital contribution or registered capital; or
  • a limited company with no foreign shareholder, where a foreign national serves as a director authorized to sign — whether solely or jointly — so as to bind the company.

Supporting documents required at incorporation

Applicants falling within the above categories must submit a Letter of Clarification on Investment, in the form annexed to the Order, together with the following bank statements:

  • a statement of the account from which each Thai partner or shareholder made payment, covering the three months prior to the date of payment and evidencing a withdrawal or transfer consistent with the amount and date of payment;
  • a statement of the account of the managing partner or director who received the funds, evidencing receipts consistent with the amount and date of payment from each partner and shareholder; and
  • where the receiving account is also the account relied upon to evidence payment under the first item above, an additional statement covering the three months prior to the date of receipt.

The third requirement addresses situations in which the managing partner or director settles their own contribution from funds already held in the receiving account, rather than by a traceable transfer. In such cases, the source of those funds must be explained separately in the Letter of Clarification.

2. Amendment Registrations Involving Foreign Nationals

A Letter of Confirmation of Investment, also in the form annexed to the Order, must be submitted with an application to register an amendment admitting a foreign national as a partner, or appointing a foreign national as an authorized signatory director, in either of the following cases:

  • a partnership in which all partners were previously Thai nationals, or in which foreign partners held 50% or more of the capital contribution, where the amendment results in foreign partners holding less than 50% and no foreign national serving as managing partner; or
  • a limited company in which all directors authorized to bind the company were previously Thai nationals, where an amendment to the directors — or to the number or names of the directors signing to bind the company — results in a foreign national holding sole or joint signing authority.

3. Additional Requirements for Recently Incorporated Entities

Where a partnership or limited company incorporated on or after 1 August 2026 submits an amendment application of the type described above within one year of its registration as a juristic person, it must additionally submit the amendment version of the Letter of Clarification on Investment, together with a bank statement evidencing that the entity — or the managing partner or director on its behalf — received the full amount of the capital contributions or share payments called up at incorporation.

This requirement addresses the sequencing of transactions whereby an entity is incorporated with Thai partners or directors and a foreign national is introduced shortly thereafter.

Legal Significance

The Order does not introduce a new prohibition; nominee arrangements already constitute an offence under Section 36 of the FBA. Its significance instead lies in shifting the evidentiary burden to the point of registration, and in the personal declaration now required of the signatory.

Under the Letter of Confirmation of Investment, the managing partner or authorized director confirms that all partners have genuinely made and paid their capital contributions, that all shareholders have genuinely paid for their shares, and that no Thai national has provided assistance or support to, or jointly operated a business with, a foreign national in the nature of a nominee. The signatory further acknowledges the following penalties:

  • Section 36 of the FBA: imprisonment not exceeding 3 years, a fine of THB 100,000 to 1,000,000, or both;
  • Section 137 of the Criminal Code (false statements to an official): imprisonment not exceeding 6 months, a fine not exceeding THB 10,000, or both; and
  • Section 267 of the Criminal Code (causing a false entry in a public document): imprisonment not exceeding 3 years, a fine not exceeding THB 60,000, or both.

Key Takeaways

  • Existing entities are unaffected until they register a qualifying amendment, at which point the Order applies in full.
  • The Order took effect on 1 August 2026 and applies to partnerships and limited companies in which foreign participation is below 50%, and to limited companies in which a foreign national holds signing authority.
  • Documentary requirements now extend to bank statements evidencing both the payment and receipt of capital contributions and share payments, supported by a prescribed clarification letter.
  • Amendment registrations introducing a foreign partner or foreign signatory require a signed Letter of Confirmation of Investment, which carries personal criminal exposure for the signatory.
  • Entities incorporated on or after the effective date are subject to additional requirements if a qualifying amendment is registered within their first year.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Breaking Down Government Data Silos: New Rules on Inter-Agency Sharing of Personal Information

A new Royal Decree has established a legal framework requiring government agencies to share personal information under their control with other government agencies for specified electronic data-linkage purposes.

The Royal Decree on Disclosure of Personal Information Controlled by Government Agencies to Other Government Agencies B.E. 2569 (2026) (the “Royal Decree”) represents an important development in the government’s efforts to move away from fragmented, agency-specific databases toward greater interoperability of public-sector information.

The measure is intended to enable government agencies to use more complete and accurate information in policymaking, public services and targeted welfare programs, while reducing the burden on individuals of repeatedly submitting information already held by the government. The framework is also intended to contribute to greater transparency and more effective law enforcement.

Legal basis for inter-agency disclosure:

The Royal Decree is issued pursuant to Section 24(9) of the Official Information Act B.E. 2540 (1997).

Section 24 of the Official Information Act establishes, as a general rule, that a government agency may not disclose personal information under its control to another government agency or another person without the prior or contemporaneous written consent of the person concerned, subject to specified statutory exceptions.

Section 24(9) permits disclosure in other cases prescribed by Royal Decree.

The new Royal Decree uses this statutory mechanism to provide a specific legal basis for government-to-government disclosure of personal information falling within its scope. As a result, qualifying disclosure under the Royal Decree does not depend on obtaining the individual’s written consent on each occasion.

This is important because large-scale government data interoperability would be difficult to implement if each transfer of information between government agencies required separate consent from every affected individual.

From isolated databases to connected government:

The policy underlying the Royal Decree is broader than simply permitting one government agency to send information to another.

Government agencies hold significant amounts of information about individuals, but that information has traditionally been maintained within separate administrative systems. Where relevant information is distributed among different agencies, the government may not have ready access to the complete information required for policymaking, public services or welfare administration.

The Royal Decree is intended to address this fragmentation by enabling electronic linkage of personal information held across government agencies.

The stated objectives include allowing government policies and measures, government services and targeted welfare programs to be based on accurate and complete information. Greater data linkage is also intended to improve the efficiency of government services, reduce administrative burdens on the public, promote transparency and enhance the effectiveness of law enforcement.

In practical terms, the framework supports a move toward the principle that individuals should not continually be required to provide one government agency with information that is already held by another government agency where the conditions for lawful data linkage are satisfied.

Government agencies may be required to disclose information:

A significant feature of the Royal Decree is that it does not merely provide government agencies with a general permission to share personal information.

It establishes a framework under which a government agency controlling personal information must disclose that information to another government agency where the information is requested for purposes falling within the Royal Decree.

The relevant data linkage is intended to support the preparation and provision of government services and the provision of targeted welfare through electronic means.

This gives the Royal Decree practical significance beyond an ordinary exception to a confidentiality rule. It provides the legal infrastructure for systematic government data interoperability.

The receiving agency also assumes obligations:

Greater availability of government-held information is accompanied by safeguards.

A government agency requesting and receiving personal information must safeguard that information. Importantly, it may not further disclose the information to an outside person.

This restriction is an important limitation on the scope of the new regime. The Royal Decree should therefore not be understood as making personal information freely transferable simply because it has entered an interconnected government information system.

The legal authorization concerns disclosure within the framework established by the Royal Decree. Once information has been received, the recipient agency remains responsible for protecting it and complying with the restrictions applicable to its subsequent disclosure.

The required safeguards are also linked to criteria and conditions prescribed by the competent authority and cybersecurity requirements. Consequently, implementation of the Royal Decree is as much an information-governance issue as a data-access issue.

Targeted welfare and government services:

One of the clearest practical applications of government data linkage is the provision of targeted welfare.

Eligibility for government assistance may depend on information maintained by several different authorities. Without data linkage, individuals may have to obtain documents from one agency and submit them to another, while the agency administering the benefit may have difficulty independently establishing a complete picture of the applicant’s circumstances.

Electronic linkage can potentially change this process.

Where legally permitted, the administering agency may obtain relevant information directly from government data already available elsewhere. This can make eligibility assessment more accurate, reduce duplicate documentation and enable welfare programs to be directed more effectively toward intended recipients.

The same principle can apply more broadly to government services. Greater interoperability can reduce repeated requests for information and allow government agencies to make administrative decisions using more complete information.

Transparency and law enforcement:

The Royal Decree also has implications beyond welfare and administrative services.

The stated rationale includes increasing transparency within government and improving the effectiveness of law enforcement. Information that appears unremarkable when held in a single agency’s database may have greater significance when lawfully linked with information held by other agencies.

Inter-agency data linkage can therefore provide government authorities with a more complete information base for identifying inconsistencies, verifying information and carrying out their statutory functions.

This capability may be particularly relevant where investigations or enforcement activities require information held by several government bodies.

However, the Royal Decree should not be characterized as creating a general law-enforcement database or an unrestricted investigative power. Its significance lies in providing a statutory mechanism for disclosure and electronic data linkage within the scope established by the Royal Decree.

Data sharing does not mean unrestricted data use:

An important compliance point is the distinction between access to information and freedom to use or disclose that information.

The fact that one government agency is legally entitled to obtain information from another does not mean that information becomes unrestricted once transferred.

Government agencies implementing data-linkage arrangements should therefore consider controls covering at least:

  • the authority and purpose for requesting information;
  • identification of the information required;
  • authentication of requesting agencies and authorized personnel;
  • access controls within the receiving agency;
  • secure electronic transmission;
  • logging and traceability of access and transfers;
  • cybersecurity safeguards;
  • retention and management of linked information; and
  • controls preventing unauthorized onward disclosure.

These controls are particularly important because increased interoperability can increase the consequences of inadequate security. A weakness in one interconnected system may potentially expose information originating from several agencies.

Relationship with personal data protection requirements:

The Royal Decree should also be understood within the broader legal framework governing personal information.

Its immediate statutory basis is the Official Information Act, and it establishes a specific mechanism permitting inter-agency disclosure that would otherwise be subject to the restrictions in Section 24 of that Act.

However, the existence of a statutory basis for disclosure should not automatically be equated with unlimited authority to process the information for any subsequent purpose.

Government agencies participating in data-linkage arrangements should therefore identify the legal authority supporting each stage of the information lifecycle—including collection, disclosure, receipt, use, retention, security and any subsequent disclosure—and consider other applicable personal data protection and cybersecurity requirements.

The distinction is particularly important as government systems become increasingly interconnected. Legal authority to receive information is only one component of lawful and responsible data governance.

A significant step toward data-driven government:

The Royal Decree represents a structural change in the management of government-held personal information.

The traditional model in which each government agency maintains its own information and individuals repeatedly provide substantially the same information to different authorities is increasingly being replaced by a model based on controlled interoperability.

If implemented effectively, the new framework should enable government agencies to make greater use of information already available within the public sector, improve the accuracy of public services and welfare programs, and reduce unnecessary administrative burdens on individuals.

The corresponding challenge is governance.

The more effectively government information systems are connected, the more important it becomes to ensure that access is authorized, purposes are properly defined, information is adequately protected and subsequent disclosure remains controlled.

The Royal Decree therefore represents not simply an expansion of government access to data, but a move toward a more integrated model of public-sector data governance.

Key Takeaways:

  • The Royal Decree marks an important shift from government data held in separate institutional silos toward controlled, interoperable public-sector data infrastructure.
  • The Royal Decree establishes a statutory mechanism for the disclosure of personal information between government agencies for qualifying electronic data-linkage purposes.
  • Its legal basis is Section 24(9) of the Official Information Act, which allows exceptions to the general restriction on disclosure of government-controlled personal information without written consent.
  • The framework goes beyond merely permitting voluntary data sharing and supports systematic interoperability between government information systems.
  • A government agency receiving information under the framework must safeguard the information and is restricted from further disclosure to an outside person.
  • The framework is intended to support more accurate policymaking, more efficient government services and targeted welfare, reduced administrative burdens on the public, greater transparency and more effective law enforcement.
  • Government agencies should not treat authorization to receive information as unrestricted authority to use or further disclose it. Purpose limitation, access controls, cybersecurity and information governance remain central to implementation.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

From Voluntary Guidance to Legal Accountability: The Changing Rules for Digital Platforms

Digital platform regulation is entering a new phase. Recent developments indicate a shift from a framework centered largely on registration, disclosure, and risk management toward a more substantive model addressing platform conduct, seller accountability, fee transparency, and potentially the allocation of liability between platforms and businesses operating through them.

Two developments illustrate this direction particularly well. The first is the proposed Digital Platform Economy Act, which is being developed as a broader statutory framework for the platform economy. The second is the Electronic Transactions Development Agency (ETDA) Guideline on Transparency and Fairness in Digital Platform Service Fees, which establishes voluntary best practices for the disclosure and adjustment of platform fees. Although the guideline is not mandatory and the proposed Act has not yet been enacted, considered together they provide a useful indication of the regulatory principles increasingly shaping oversight of digital platforms: transparency, fairness, accountability, and greater protection for users and consumers.

A New Regulatory Framework for Digital Platforms:

Digital platform services are currently regulated under the Royal Decree on the Operation of Digital Platform Service Businesses that are Subject to Prior Notification. The existing regime establishes notification requirements and imposes various obligations depending on the nature, size, and risk profile of a platform. The proposed Digital Platform Economy Act would represent a significant further development. The government has accelerated work on the legislation, with the current policy timetable contemplating submission to the Cabinet before the draft proceeds to Parliament. As the legislation remains under development, however, both its provisions and legislative timetable remain subject to change.

The emerging framework indicates several areas that platform operators should monitor closely. These include registration and disclosure of information concerning platform operations and revenue, as well as measures intended to give regulators greater visibility over businesses participating in the platform economy. Territorial scope will be particularly important for multinational businesses, since a platform providing services into the local market may potentially become subject to regulatory requirements even where the operator does not have a conventional physical presence in the jurisdiction.

Another important area concerns businesses and individuals offering goods or services through platforms. The regulatory direction increasingly places platforms in the position of gatekeepers rather than merely passive intermediaries. Existing regulatory measures already require certain platforms to obtain and verify seller information and implement risk-management measures concerning goods and services offered through their systems. The proposed legislation appears likely to develop this approach further, making seller onboarding, identity verification, record keeping, monitoring, and enforcement increasingly important compliance functions rather than merely commercial processes.

The Emerging Question of Platform Liability:

Perhaps the most significant issue to monitor is the extent to which a platform may bear responsibility for harm arising from transactions conducted through its service. Platform operators have traditionally characterized themselves as intermediaries connecting independent sellers with customers, and their terms and conditions commonly distinguish the platform from the seller responsible for the underlying goods or services.

The proposed regulatory approach may reduce the practical significance of that distinction. Discussions surrounding the Digital Platform Economy Act contemplate circumstances in which platforms could bear joint responsibility for consumer harm, particularly where the platform fails to perform duties imposed on it. The precise scope of any liability will depend on the final statutory language, including the conduct that triggers liability, available defenses, and the relationship between the new regime and existing consumer protection laws.

If enacted broadly, such liability could materially alter the allocation of risk in the platform economy. Seller verification and monitoring would no longer be viewed simply as regulatory procedures; they could become directly relevant to a platform’s financial exposure when consumers suffer loss. Contractual provisions placing responsibility on sellers, including indemnities, may remain important but would not necessarily protect a platform from independent statutory liability. Platform operators should therefore monitor the liability provisions particularly closely as the draft progresses.

Fee Transparency and Fairness:

While the proposed Act represents the potential development of mandatory statutory obligations, ETDA has adopted a softer regulatory approach to another significant platform issue: fees. Its Guideline on Transparency and Fairness in Digital Platform Service Fees is intended as voluntary best practice rather than direct price regulation. The guideline does not prescribe maximum commissions or other charges. Instead, it focuses on whether users can understand what they are being charged, what services they receive in return, and how changes to those charges are made.

Platforms are encouraged to present fee information clearly and in an accessible manner, including an explanation of individual fee items, the services or benefits associated with them, and the basis or method used to calculate the charges. This is particularly relevant where the actual cost of participating on a platform extends beyond a headline commission and may include advertising, promotional, affiliate, payment-related, or other service fees. The regulatory concern is therefore not simply whether a particular commission is high or low, but whether users can reasonably determine and evaluate the overall economic cost of using the platform.

The guideline also addresses changes to platform fees. It recommends that users receive at least 15 days’ advance notice of fee changes, together with information concerning the reason for the change, its scope and potential impact, and channels for inquiries or feedback. The guideline also contemplates a consultation process in connection with fee changes. Platforms should therefore distinguish between merely notifying users that a fee will change and maintaining a process that reflects the broader principles of transparency, consultation, and fairness contemplated by the guideline.

Fairness extends beyond disclosure. Platforms are encouraged to avoid unnecessary duplication of charges and to distinguish clearly between compulsory fees and charges for additional services. Optional services should correspond to genuine additional benefits rather than becoming effectively mandatory through the design or operation of the platform. The objective is not direct government control of platform pricing, but a framework in which platforms can explain how fees are determined and users can understand the true costs of participating in the platform ecosystem.

From Voluntary Guidance to Legal Accountability:

Considered separately, the proposed Digital Platform Economy Act and the fee guideline address different regulatory issues. Considered together, however, they reveal a broader trajectory. The fee guideline represents soft regulation, under which regulators articulate expectations concerning fair market conduct and encourage platforms voluntarily to incorporate those principles into their business practices. The proposed legislation points toward harder regulatory intervention, potentially involving registration, disclosure, seller verification, statutory duties, enforcement mechanisms, and greater responsibility for consumer harm.

This distinction is important for businesses. Voluntary guidance should not necessarily be treated as irrelevant simply because it does not create directly enforceable obligations. Such guidance may establish regulatory expectations concerning reasonable industry conduct, identify practices receiving regulatory scrutiny, and indicate areas in which more formal intervention could eventually follow if voluntary measures prove insufficient.

The broader development is therefore not simply an increase in the number of rules applicable to digital platforms. It reflects a gradual change in the regulatory conception of the platform itself. As platforms exercise greater control over seller admission, product visibility, payment mechanisms, fees, and transactions, regulators increasingly expect them to accept corresponding responsibilities for how those ecosystems operate.

Preparing for the Next Stage of Platform Regulation:

Platform operators need not wait for the proposed legislation to be enacted before reviewing their compliance architecture. Seller onboarding and verification procedures should be assessed to determine what information is collected, how identities and business credentials are verified, how information is updated, and what happens when inaccurate information or unlawful activity is detected. Systems should also retain sufficient records to demonstrate that verification, monitoring, complaints, and enforcement procedures have actually been followed.

Fee structures warrant similar attention. Platforms should consider whether users can readily identify the overall economic cost of using their services and whether compulsory fees, optional services, promotional charges, advertising costs, and other charges are adequately explained. Procedures for changing fees should also be reviewed against the transparency, advance-notice, and consultation principles reflected in ETDA’s guideline.

Finally, contractual arrangements with sellers should be considered together with operational compliance. If the new legislation imposes independent statutory duties on platforms, contractual provisions allocating responsibility entirely to sellers may have limited effect against claims brought directly against the platform. Indemnities, suspension rights, seller information obligations, insurance arrangements, record keeping, and mechanisms for recovering losses should therefore form part of a broader risk-management framework rather than being treated as substitutes for regulatory compliance.

Key Takeaways:

  • Digital platform regulation is moving beyond registration and disclosure toward greater operational accountability.
  • The proposed Digital Platform Economy Act may expand requirements concerning platform registration, business information, seller verification, platform conduct, and consumer protection. Its final provisions should be monitored as the legislative process progresses.
  • Potential joint liability for consumer harm may be one of the most significant developments because it could alter the traditional allocation of responsibility between platforms and independent sellers.
  • ETDA’s fee guideline remains voluntary and does not constitute direct price regulation, but it establishes regulatory expectations concerning fee transparency, fairness, advance notice, and consultation.
  • Platform operators should consider reviewing seller verification, monitoring, fee disclosures, change-management procedures, contractual risk allocation, and record-keeping systems before the new statutory framework is finalized.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

Thailand Moves Toward a Dedicated Regulatory Framework for Data Centers

Thailand may soon take a significant step toward regulating its rapidly expanding data center industry. According to recent reports, the government is preparing a Prime Minister’s Office Regulation that would establish a dedicated framework for overseeing data center operations, with particular emphasis on resource management, environmental impacts, and centralized regulatory oversight. While the proposed regulation has not yet been issued, it signals a potential shift from Thailand’s current investment-driven approach toward a more comprehensive regulatory model for the sector.

Background:

Thailand has become an increasingly attractive destination for data center investment due to strong government incentives, growing cloud adoption, and its strategic location in Southeast Asia. However, the rapid expansion of large-scale facilities has also raised concerns regarding infrastructure capacity, particularly electricity and water consumption.

According to the reported proposal, the government intends to introduce a dedicated regulatory mechanism to better coordinate oversight of the industry and manage its broader impacts on national resources.

Proposed regulatory framework:

The reported proposal indicates that the Prime Minister’s Office Regulation would establish a new committee responsible for supervising data center activities. Its responsibilities would reportedly include:

  • overseeing the overall development of the data center industry;
  • assessing the impacts of data center investments;
  • monitoring resource consumption, particularly electricity and water usage;
  • coordinating regulatory oversight among relevant government agencies; and
  • supervising approvals, permits, and compliance monitoring.

Although further details have not yet been published, the proposal suggests that the government intends to create a more centralized oversight structure than currently exists.

Addressing fragmented regulation:

At present, data center projects typically interact with multiple government agencies depending on the nature of the project. Investors may require approvals or incentives from different authorities, while utility arrangements are often negotiated separately.

The reported proposal appears intended to address this fragmented regulatory landscape by introducing a dedicated governance mechanism specifically focused on data centers.

Greater focus on infrastructure and resource management:

A notable feature of the proposal is its emphasis on resource planning.

According to the reports, the government has identified several concerns, including:

  • increasing electricity demand from large-scale data centers;
  • substantial water consumption required for cooling systems;
  • challenges in forecasting future resource demand; and
  • overlapping arrangements for water supply that may complicate national infrastructure planning.

The proposal therefore appears to reflect a policy objective of integrating data center development with broader infrastructure and environmental planning rather than regulating the industry solely from an investment perspective.

Different treatment for existing and future projects:

The reported framework would distinguish among three categories of data centers:

Existing operating facilities

Existing operators may become subject to audits or assessments focusing on matters such as resource consumption, temperature management, and noise impacts.

Approved projects under development

Projects that have already received approvals but are not yet operational may be required to comply with additional regulatory conditions before commencing operations.

Future applicants

New projects may become subject to a comprehensive regulatory regime addressing matters such as:

  • sustainable water management;
  • reserve water sources;
  • environmental impacts; and
  • measures designed to reduce adverse impacts on surrounding communities.

This tiered approach suggests that the government is seeking to avoid disrupting ongoing investments while progressively strengthening regulatory requirements for future developments.

Potential changes to location planning:

The reports also indicate that the government is considering a more strategic approach to determining where future data centers should be located.

Rather than concentrating additional facilities in existing investment hubs, policymakers are reportedly evaluating locations with stronger electricity and water infrastructure, including areas near major power generation facilities. The government has also indicated that supporting digital infrastructure, such as fiber-optic networks, could be expanded if new data center clusters are developed.

What investors should watch:

Although the proposal remains at the policy stage, investors and operators should monitor several issues as the framework develops:

  • the legal authority under which the new committee will operate;
  • whether additional licensing or approval requirements will be introduced;
  • technical standards relating to electricity, water use, and environmental impacts;
  • transitional requirements applicable to existing operators; and
  • the interaction between the new framework and existing approvals issued by sector-specific regulators.

The final regulatory approach will determine whether the proposed framework primarily serves as a coordination mechanism or introduces substantive compliance obligations for the industry.

Key takeaways:

  • Thailand is reportedly preparing a dedicated regulatory framework for data centers through a proposed Prime Minister’s Office Regulation.
  • The proposal reflects increasing government attention to electricity consumption, water usage, and environmental impacts associated with large-scale data center investments.
  • A new committee may be established to coordinate oversight of approvals, compliance, and resource management.
  • Existing facilities, projects under development, and future investments could become subject to different regulatory requirements.
  • Although the proposal has not yet been formally issued, investors planning data center projects in Thailand should closely monitor further regulatory developments, as they may significantly affect project planning, compliance obligations, and site selection.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles

NBTC Issues AI Governance Guidelines for Telecom Licensees

Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has issued new guidelines setting out its expectations for the responsible use of artificial intelligence (AI) by telecommunications licensees. Although the guidelines are not legally binding, they establish a comprehensive risk-based framework for AI governance and provide a clear indication of the regulatory standards that the NBTC expects telecom operators to adopt when deploying AI in the provision of telecommunications services.

The guidelines reflect the increasing regulatory focus on AI governance and complement existing legal obligations relating to cybersecurity, personal data protection, and telecommunications. They also align with broader national efforts to develop a comprehensive AI regulatory framework.

Scope of the Guidelines:

The guidelines apply to holders of telecommunications business licenses under Thailand’s telecommunications licensing regime, but only in relation to AI systems used to provide licensed telecommunications services.

Organizations that are not telecommunications licensees are not directly subject to the guidelines. Nevertheless, AI developers, technology vendors, cloud service providers, and outsourced service providers may be indirectly affected because telecommunications licensees are expected to exercise oversight over third-party AI solutions used in their operations. As a result, contractual obligations and vendor due diligence are likely to become increasingly important for suppliers serving the telecommunications sector.

The guidelines should be considered alongside existing legal requirements, including the Personal Data Protection Act, the Cybersecurity Act, the Computer Crime Act, and the NBTC Notification on the Protection of Telecommunications Service Users’ Rights in relation to personal data, privacy, and the freedom of telecommunications. They also complement the broader AI legislation currently under development by the Electronic Transactions Development Agency (ETDA).

Strengthening AI Governance:

A central feature of the guidelines is the expectation that AI governance should extend beyond technical implementation and become an organizational responsibility.

Telecommunications licensees are encouraged to establish governance structures at both the policy and operational levels, such as AI committees, working groups, or designated responsible officers. These governance bodies should oversee AI strategy, establish internal policies, supervise risk management, and define accountability throughout the AI lifecycle.

The guidelines also emphasize that responsibilities should be clearly assigned not only to internal personnel but also to third-party AI solution providers and outsourced service providers. Licensees are expected to ensure that contractual arrangements clearly define each party’s obligations regarding AI governance, risk management, and regulatory compliance.

A Principles-Based Approach to Responsible AI:

Rather than prescribing detailed technical requirements, the guidelines adopt a principles-based approach centered on six core expectations.

First, AI systems should comply with applicable laws, ethical principles, and internationally recognized standards. AI should respect privacy, human dignity, and fundamental rights, and organizations should consider implementing appropriate safeguards, including content filtering, to reduce the risk of generating harmful or unlawful outputs.

Second, AI systems should operate fairly. This includes using representative and reliable training data, assessing potential bias, and taking appropriate measures to mitigate discriminatory outcomes.

Third, cybersecurity and privacy protections should be integrated into AI systems. The guidelines encourage the adoption of internationally recognized security standards and recommend technical safeguards such as encryption, anonymization, and access controls to protect personal data and system integrity.

Fourth, organizations should promote transparency by maintaining documentation regarding AI design, development, and operation, while providing consumers with appropriate information about how AI systems influence decisions or recommendations.

Fifth, accountability should be clearly established throughout the organization. Internal policies should define responsibility for AI outcomes, while consumers should have accessible channels to submit inquiries or complaints regarding AI-enabled services.

Finally, AI systems should be reliable and robust. The guidelines recommend testing AI models to ensure that they produce accurate and consistent results, including under unexpected operating conditions.

Governance Throughout the AI Lifecycle:

The guidelines emphasize that AI governance should be integrated throughout the entire AI lifecycle rather than focusing solely on deployment.

Licensees are expected to conduct risk assessments before development begins, evaluate the capabilities and reliability of third-party AI providers, and maintain appropriate standards for data quality and traceability. Before deployment, AI systems should undergo testing for reliability, fairness, and operational performance.

Once AI systems are operational, organizations should continuously monitor performance, maintain appropriate human oversight, and periodically evaluate whether AI systems continue to operate as intended. The guidelines also address the retirement of AI systems, encouraging secure decommissioning processes that protect data and maintain appropriate records throughout the system’s lifecycle.

This lifecycle-based approach reflects the growing international trend toward continuous AI governance rather than one-time compliance assessments.

Consumer Transparency and Organizational Readiness:

Consumer protection is another significant feature of the guidelines.

Telecommunications licensees are encouraged to notify consumers when they are interacting with AI systems, such as chatbots or voicebots. Where AI-generated recommendations may influence consumer decisions, organizations should provide appropriate disclosures and allow consumers to request assistance from a human representative where appropriate. Effective feedback and complaint mechanisms should also be maintained.

Internally, the guidelines recognize that responsible AI governance requires organization-wide awareness. Licensees are therefore encouraged to provide AI-related training across all levels of the organization. Employees who use AI systems should understand the associated legal and operational risks, while technical personnel and external developers should receive training on organizational AI policies, ethical principles, and applicable regulatory requirements.

Practical Implications:

Although the guidelines do not create new legal obligations, they provide valuable insight into the NBTC’s regulatory expectations and are likely to influence future regulatory supervision and industry best practices.

Telecommunications licensees should consider reviewing their existing AI governance frameworks to determine whether governance responsibilities are clearly assigned and appropriately documented. Organizations should also evaluate AI risk management procedures, update contracts with AI vendors and outsourced service providers, assess consumer disclosure mechanisms, and ensure that staff receive appropriate AI governance training.

The guidelines may also have implications for corporate transactions involving telecommunications businesses. As AI becomes increasingly integrated into telecommunications operations, AI governance maturity, data governance practices, and vendor oversight may become important considerations during legal and regulatory due diligence.

Key Takeaways:

  • Telecommunications licensees should review their governance frameworks, contractual arrangements, AI risk management processes, consumer disclosure practices, and staff training programs to align with the NBTC’s expectations.
  • The NBTC’s AI guidelines establish a comprehensive risk-based governance framework for telecommunications licensees and provide a clear indication of the regulator’s expectations for responsible AI deployment.
  • Although nonbinding, the guidelines are likely to influence regulatory supervision and industry best practices within Thailand’s telecommunications sector.
  • AI governance is expected to extend throughout the entire AI lifecycle, encompassing organizational governance, risk management, vendor oversight, cybersecurity, consumer protection, and ongoing monitoring.

Author: Panisa Suwanmatajarn, Managing Partner.

Other Articles