Indonesia - Ethical Guidelines for AI
Concept Draft of Ethical Guidelines for AI
Konsep Pedoman Etika Kecerdasan Artifisial
Indonesia
RAI-ID-NA-KPEKAXX-2025The Ministry of Communication and Digital (Komdigi) published a Concept Draft of Ethical Guidelines for Artificial Intelligence (Konsep Pedoman Etika Kecerdasan Artifisial) for public consultation in August 2025, intended to complement Ministerial Circular No. 9/2023 and to inform a future Presidential regulation. The draft sets out ethical values, governance expectations, risk-based categorization for AI use, and procedural guidance for oversight, documentation, and stakeholder engagement. Komdigi announcement (Aug 8, 2025).
Summary
Full article
Read full text ↗Overview
The Konsep Pedoman Etika Kecerdasan Artifisial is a concept draft published by the Ministry of Communication and Digital (Komdigi) in August 2025 for public consultation. It accompanies a national AI White Paper (‘Buku Putih Peta Jalan Kecerdasan Artifisial Nasional’) and is presented as a values-driven, risk-based framework intended to guide the development, deployment, and governance of AI across public and private sectors in Indonesia. The draft builds on the foundation set by Ministerial Circular/SE No.9 of 2023 on AI ethics and signals the Ministry’s intention to move from guidance toward a binding Presidential regulation. The public consultation opened on 8 August 2025 and was extended to 29 August 2025 to gather broader stakeholder input. Extension notice.
Definitions
The draft defines key concepts in alignment with existing Indonesian instruments: ‘Artificial Intelligence / Kecerdasan Artifisial’ (programming capable of data processing, ML, NLP, neural networks), ‘Penyelenggara Sistem Elektronik (PSE)’, ‘Pelaku Usaha’ (AI programming actors), ‘High-Risk AI’ (applications with elevated potential for harm), and related technical terms such as ‘model provenance’, ‘human-in-the-loop’, and ‘adversarial robustness’. These definitions are intended to interoperate with the statutory definitions in Law No. 27/2022 on Personal Data Protection and existing electronic systems law and guidance. The draft aims to align legal and ethical terminology to reduce ambiguity across implementing agencies.
Governance and Institutional Framework
The draft places primary stewardship with the Ministry of Communication and Digital but envisages a multi-agency governance architecture involving sectoral regulators (e.g., OJK for finance, Ministry of Health for healthcare), national cybersecurity authorities (e.g., BSSN), and consumer protection bodies. It proposes a national coordination mechanism to: (1) classify high-risk systems; (2) maintain registries or notification schemes for significant AI deployment; (3) coordinate conformity assessment and market surveillance; and (4) harmonize sectoral rules to avoid regulatory fragmentation. The model is consultative and iterative — Komdigi’s consultation document and the White Paper were produced by a broad taskforce of government, academics, industry and civil society representatives to ensure cross-sectoral buy-in. Komdigi announcement.
Key Focus Areas
The draft’s focus areas include: (a) Governance & oversight (clear institutional roles, registries and inter-agency coordination); (b) Risk management (mandatory risk assessments and classification of high-risk use-cases); (c) Safety testing & evaluation (pre-deployment testing, adversarial resilience and continuous monitoring); (d) Transparency & disclosure (model cards, user notices, provenance data and AI-generated content labelling); (e) Data protection & privacy (privacy-by-design, DPIA alignment with Law No.27/2022); (f) Fundamental rights (anti-discrimination, due process protections for automated decisions); (g) Cybersecurity & model security (requirements for integrity, access controls and incident reporting); (h) Conformity assessment & registration (third-party audit pathways and potential mandatory registration for certain categories); (i) Accountability & documentation (retention of logs, audit trails and explainability records); and (j) Liability, redress & enforcement (administrative sanctions and measures to ensure remediation). Many of these areas explicitly reference or harmonize with existing instruments such as SE No.9/2023 and the PDP Law. SE No.9/2023.
Implementation Framework
Implementation in the draft is phased and risk-based. Lower-risk AI retains voluntary compliance plus baseline transparency obligations; high-risk AI triggers mandatory pre-deployment risk assessments, documentation, registration/notification, third-party conformity or testing (as defined by implementing rules), and enhanced human oversight requirements. The draft anticipates sectoral implementing rules to operationalize thresholds, technical standards, and enforcement mechanisms. It also recommends capacity building for regulators, accredited testing laboratories, and guidance documents for SMEs to reduce compliance burden while protecting public interests.
Monitoring and Evaluation
The draft outlines monitoring mechanisms including market surveillance, periodic reporting by PSEs, incident notification requirements, and performance indicators tied to safety, fairness and privacy outcomes. It envisions a national AI registry or dashboard to track high-risk systems, a complaint-handling channel for affected persons, and regular public reporting by Komdigi and partner agencies on compliance trends. Independent evaluation — including audits and public transparency reporting — is recommended to measure policy effectiveness and to feed iterative updates to the framework.
Penalties, Liability, and Appeals
As a concept draft, detailed sanctions are deferred to implementing regulations, but it enumerates possible measures: administrative fines, remedial orders (model rollback, algorithmic adjustments), suspension or blocking of services, revocation of PSE registration, and referral for criminal investigation where statutory offences are implicated (e.g., violations of PDP Law or ITE provisions). The draft also describes redress pathways for individuals including complaint mechanisms and requirements for transparent appeals procedures. Enforcement is envisaged to be proportional, risk-based and accompanied by guidance to support compliance.
Relationship to Other Instruments
The draft explicitly connects to: the Ministerial Circular/SE No.9/2023 on AI ethics; Law No.27 of 2022 on Personal Data Protection (PDP Law); existing Electronic Information and Transactions (ITE) law and implementing PSE rules; and sectoral laws (health, finance) where additional safeguards apply. The draft is positioned as a normative bridge that informs future binding instruments (including a proposed Presidential Regulation) while respecting existing statutory obligations under the PDP Law and other sectoral regimes. SE No.9/2023; Law No.27/2022 (PDP Law).
International Alignment
The Concept Draft emphasizes alignment with international best practices and soft-law instruments (e.g., OECD AI Principles, EU AI Act concepts), while calibrating to Indonesia’s legal context. It encourages interoperability (data protection, cross-border cooperation on AI safety and incident response) and proposes participation in multilateral fora to harmonize standards and avoid fragmentation, particularly for cross-border AI services and global platforms operating in Indonesia. This international orientation is intended to facilitate trade, investment, and cooperative enforcement mechanisms.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Public consultation opened | 2025-08-08 | Komdigi announcement |
| Consultation extended (deadline) | 2025-08-29 | Extension notice |
| Submission of Perpres initiative | 2025-09-05 | ANTARA report |
| Expected harmonization & drafting | Q3–Q4 2025 (target) | Subject to inter-agency process and stakeholder input |
Sources and References
Requirements for a company
What an organisation has to do under Indonesia - Ethical Guidelines for AI, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.
Must do
12- Perform Data Protection Impact Assessments aligned with Law No. 27/2022.Providers and operators of AI systems processing personal data.
- Implement privacy-by-design principles when developing and deploying AI systems.Providers and operators of AI systems processing personal data.
- Conduct pre-deployment risk assessments and classify the AI system's risk level.Providers and operators of AI systems.
- Maintain comprehensive model documentation, data provenance, logs, and audit trails.Providers and operators of AI systems.
- Define and implement human-in-the-loop controls for high-risk AI system functions.Providers and operators of high-risk AI systems.
- Conduct pre-deployment safety testing and continuous monitoring of AI systems.Providers and operators of AI systems.
- +6 more in the table below
Must not do
0Nothing in this category.
Should do
1- Adopt values-based policies consistent with the draft's ethical principles.All AI developers and operators.
Should not do
0Nothing in this category.
Who must do what
The obligations under Indonesia - Ethical Guidelines for AI, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers and operators of AI systems processing personal data. | Perform Data Protection Impact Assessments aligned with Law No. 27/2022. “Data protection & privacy (privacy-by-design, DPIA alignment with Law No.27/2022)” | Before deployment | Key Focus Areas (e) | Critical |
| 2 | Providers and operators of AI systems processing personal data. | Implement privacy-by-design principles when developing and deploying AI systems. “Data protection & privacy (privacy-by-design, DPIA alignment with Law No.27/2022)” | During development | Key Focus Areas (e) | Critical |
| 3 | Providers and operators of AI systems. | Conduct pre-deployment risk assessments and classify the AI system's risk level. “mandatory risk assessments and classification of high-risk use-cases” | Before deployment | Key Focus Areas (b) | Important |
| 4 | Providers and operators of AI systems. | Maintain comprehensive model documentation, data provenance, logs, and audit trails. “retention of logs, audit trails and explainability records” | Before deployment and continuous | Key Focus Areas (i) | Important |
| 5 | Providers and operators of high-risk AI systems. | Define and implement human-in-the-loop controls for high-risk AI system functions. “enhanced human oversight requirements” | Before deployment and continuous | Implementation Framework | Important |
| 6 | Providers and operators of AI systems. | Conduct pre-deployment safety testing and continuous monitoring of AI systems. “pre-deployment testing, adversarial resilience and continuous monitoring” | Before deployment and continuous | Key Focus Areas (c) | Important |
| 7 | Providers and operators of AI systems. | Implement cybersecurity requirements for AI systems, including integrity, access controls, and incident reporting. “requirements for integrity, access controls and incident reporting” | Before deployment and continuous | Key Focus Areas (g) | Important |
| 8 | Providers and operators of AI systems. | Provide transparency through model cards, user notices, and labelling of AI-generated content. “Transparency & disclosure (model cards, user notices, provenance data and AI-generated content labelling)” | Before deployment and continuous | Key Focus Areas (d) | Important |
| 9 | Providers and operators of AI systems. | Ensure AI systems uphold fundamental rights, including anti-discrimination and due process protections. “Fundamental rights (anti-discrimination, due process protections for automated decisions)” | During development and continuous | Key Focus Areas (f) | Important |
| 10 | Providers and operators of AI systems. | Notify authorities of incidents related to AI system performance, safety, or security. “incident notification requirements” | Immediately upon discovery | Monitoring and Evaluation | Important |
| 11 | Providers and operators of high-risk AI systems. | Register or notify significant AI deployments with the national coordination mechanism. “maintain registries or notification schemes for significant AI deployment” | Before deployment | Governance and Institutional Framework | Important |
| 12 | Providers and operators of high-risk AI systems. | Undergo third-party conformity assessment or testing for certain categories of AI systems. “third-party audit pathways and potential mandatory registration for certain categories” | Before deployment | Key Focus Areas (h) | Important |
| 13 | All AI developers and operators. | Adopt values-based policies consistent with the draft's ethical principles. “Adopt values-based policies consistent with the draft (inclusivity, transparency, accountability)” | — | Overview | Recommended |
Related Regulations
Rancangan Peraturan Presiden tentang Kecerdasan Buatan (Draft Presidential Regulation on Artificial Intelligence)
Indonesia95% similar
Buku Putih Peta Jalan Kecerdasan Artifisial Nasional (White Paper / Roadmap for National AI)
Indonesia94% similar
Panduan Kode Etik Kecerdasan Buatan yang Bertanggung Jawab dan Terpercaya di Industri Teknologi Finansial (OJK & Associations' AI Code of Ethics for Fintech)
Indonesia93% similar
Rancangan Undang-Undang tentang Kecerdasan Buatan (Draft Bill on Artificial Intelligence)
Indonesia93% similar
Indonesia AI Regulation Overview
Indonesia91% similar
© Regulations.AI · updated on 13-Jun-2026