Indonesia - Ethical Guidelines for AI

Concept Draft of Ethical Guidelines for AI

Konsep Pedoman Etika Kecerdasan Artifisial

Indonesia

RAI-ID-NA-KPEKAXX-2025
Draft(Being written or scoped)
GuidelineGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

The Ministry of Communication and Digital (Komdigi) published a Concept Draft of Ethical Guidelines for Artificial Intelligence (Konsep Pedoman Etika Kecerdasan Artifisial) for public consultation in August 2025, intended to complement Ministerial Circular No. 9/2023 and to inform a future Presidential regulation. The draft sets out ethical values, governance expectations, risk-based categorization for AI use, and procedural guidance for oversight, documentation, and stakeholder engagement. Komdigi announcement (Aug 8, 2025).

Summary

Background and purpose: In August 2025 the Ministry of Communication and Digital (Komdigi) released a Concept Draft of Ethical Guidelines for Artificial Intelligence (Konsep Pedoman Etika Kecerdasan Artifisial) together with a White Paper (Buku Putih Peta Jalan Kecerdasan Artifisial Nasional) for public consultation. The purpose of the concept draft is to strengthen ethical governance for AI in Indonesia, build on the non-binding Ministerial Circular No. 9 Year 2023 on AI ethics, and inform downstream binding regulation such as a proposed Presidential Regulation (Perpres). The public consultation process was opened on 8 August 2025 and later extended through 29 August 2025. Komdigi announcement (Aug 8, 2025); extension notice (Aug 22, 2025). Structure and approach: The draft adopts a values-led, risk-based framework. It identifies core ethical principles (inclusivity, human-centredness, transparency, accountability, data protection and security) and proposes institutional responsibilities, procedural requirements for risk assessment and classification of high-risk applications, documentation and record-keeping obligations, transparency and disclosure measures for users, and expectations for safety testing and monitoring. The draft is intended to operate alongside Indonesia’s Personal Data Protection Law (Law No. 27 of 2022) and existing electronic system regulations, aligning ethical expectations with legal obligations. See Ministerial SE No. 9/2023 for the starting ethical baseline. SE No.9/2023 (Komdigi JDIH). Key measures and expectations: The draft emphasizes: (1) risk assessment and classification of AI systems (identifying high-risk categories such as biometric identification, public administration, critical infrastructure and law enforcement uses); (2) human oversight and meaningful human-in-loop requirements for high-risk functions; (3) documentation and model cards/data provenance requirements for developers and deployers; (4) transparency/disclosure to end-users about AI-generated content and automated decision-making; (5) privacy-by-design and alignment with PDP Law obligations; (6) cybersecurity and model security measures; (7) conformity processes and potential registration or notification of high-risk systems; and (8) monitoring, market surveillance and incident reporting to regulators. The draft also signals possible administrative measures and sanctions to be further specified in implementing regulations and a proposed Perpres. Komdigi (Aug 8, 2025). Process and next steps: Komdigi received public comments through August 2025 and subsequently submitted an initiative for a draft Presidential Regulation related to AI governance in early September 2025. The Concept Draft is therefore currently under review and may be incorporated or modified in forthcoming binding instruments. Media reporting and official press releases document the consultation and the plan to advance from draft guidance to Perpres. ANTARA (Sep 5, 2025). Intended audience: The draft targets AI developers, deployers, platform operators, public and private electronic system operators (PSEs), sectoral regulators, and civil society. It is intended both as an ethical baseline and as a practical roadmap for compliance, oversight, and harmonization with sectoral laws such as the Personal Data Protection Law and ITE frameworks. The draft remains a framework and is not yet legally binding; implementation details, thresholds, and sanctions will be determined in future regulations.

Full article

Read full text ↗

Overview

The Konsep Pedoman Etika Kecerdasan Artifisial is a concept draft published by the Ministry of Communication and Digital (Komdigi) in August 2025 for public consultation. It accompanies a national AI White Paper (‘Buku Putih Peta Jalan Kecerdasan Artifisial Nasional’) and is presented as a values-driven, risk-based framework intended to guide the development, deployment, and governance of AI across public and private sectors in Indonesia. The draft builds on the foundation set by Ministerial Circular/SE No.9 of 2023 on AI ethics and signals the Ministry’s intention to move from guidance toward a binding Presidential regulation. The public consultation opened on 8 August 2025 and was extended to 29 August 2025 to gather broader stakeholder input. Extension notice.

Definitions

The draft defines key concepts in alignment with existing Indonesian instruments: ‘Artificial Intelligence / Kecerdasan Artifisial’ (programming capable of data processing, ML, NLP, neural networks), ‘Penyelenggara Sistem Elektronik (PSE)’, ‘Pelaku Usaha’ (AI programming actors), ‘High-Risk AI’ (applications with elevated potential for harm), and related technical terms such as ‘model provenance’, ‘human-in-the-loop’, and ‘adversarial robustness’. These definitions are intended to interoperate with the statutory definitions in Law No. 27/2022 on Personal Data Protection and existing electronic systems law and guidance. The draft aims to align legal and ethical terminology to reduce ambiguity across implementing agencies.

Governance and Institutional Framework

The draft places primary stewardship with the Ministry of Communication and Digital but envisages a multi-agency governance architecture involving sectoral regulators (e.g., OJK for finance, Ministry of Health for healthcare), national cybersecurity authorities (e.g., BSSN), and consumer protection bodies. It proposes a national coordination mechanism to: (1) classify high-risk systems; (2) maintain registries or notification schemes for significant AI deployment; (3) coordinate conformity assessment and market surveillance; and (4) harmonize sectoral rules to avoid regulatory fragmentation. The model is consultative and iterative — Komdigi’s consultation document and the White Paper were produced by a broad taskforce of government, academics, industry and civil society representatives to ensure cross-sectoral buy-in. Komdigi announcement.

Key Focus Areas

The draft’s focus areas include: (a) Governance & oversight (clear institutional roles, registries and inter-agency coordination); (b) Risk management (mandatory risk assessments and classification of high-risk use-cases); (c) Safety testing & evaluation (pre-deployment testing, adversarial resilience and continuous monitoring); (d) Transparency & disclosure (model cards, user notices, provenance data and AI-generated content labelling); (e) Data protection & privacy (privacy-by-design, DPIA alignment with Law No.27/2022); (f) Fundamental rights (anti-discrimination, due process protections for automated decisions); (g) Cybersecurity & model security (requirements for integrity, access controls and incident reporting); (h) Conformity assessment & registration (third-party audit pathways and potential mandatory registration for certain categories); (i) Accountability & documentation (retention of logs, audit trails and explainability records); and (j) Liability, redress & enforcement (administrative sanctions and measures to ensure remediation). Many of these areas explicitly reference or harmonize with existing instruments such as SE No.9/2023 and the PDP Law. SE No.9/2023.

Implementation Framework

Implementation in the draft is phased and risk-based. Lower-risk AI retains voluntary compliance plus baseline transparency obligations; high-risk AI triggers mandatory pre-deployment risk assessments, documentation, registration/notification, third-party conformity or testing (as defined by implementing rules), and enhanced human oversight requirements. The draft anticipates sectoral implementing rules to operationalize thresholds, technical standards, and enforcement mechanisms. It also recommends capacity building for regulators, accredited testing laboratories, and guidance documents for SMEs to reduce compliance burden while protecting public interests.

Monitoring and Evaluation

The draft outlines monitoring mechanisms including market surveillance, periodic reporting by PSEs, incident notification requirements, and performance indicators tied to safety, fairness and privacy outcomes. It envisions a national AI registry or dashboard to track high-risk systems, a complaint-handling channel for affected persons, and regular public reporting by Komdigi and partner agencies on compliance trends. Independent evaluation — including audits and public transparency reporting — is recommended to measure policy effectiveness and to feed iterative updates to the framework.

Penalties, Liability, and Appeals

As a concept draft, detailed sanctions are deferred to implementing regulations, but it enumerates possible measures: administrative fines, remedial orders (model rollback, algorithmic adjustments), suspension or blocking of services, revocation of PSE registration, and referral for criminal investigation where statutory offences are implicated (e.g., violations of PDP Law or ITE provisions). The draft also describes redress pathways for individuals including complaint mechanisms and requirements for transparent appeals procedures. Enforcement is envisaged to be proportional, risk-based and accompanied by guidance to support compliance.

Relationship to Other Instruments

The draft explicitly connects to: the Ministerial Circular/SE No.9/2023 on AI ethics; Law No.27 of 2022 on Personal Data Protection (PDP Law); existing Electronic Information and Transactions (ITE) law and implementing PSE rules; and sectoral laws (health, finance) where additional safeguards apply. The draft is positioned as a normative bridge that informs future binding instruments (including a proposed Presidential Regulation) while respecting existing statutory obligations under the PDP Law and other sectoral regimes. SE No.9/2023; Law No.27/2022 (PDP Law).

International Alignment

The Concept Draft emphasizes alignment with international best practices and soft-law instruments (e.g., OECD AI Principles, EU AI Act concepts), while calibrating to Indonesia’s legal context. It encourages interoperability (data protection, cross-border cooperation on AI safety and incident response) and proposes participation in multilateral fora to harmonize standards and avoid fragmentation, particularly for cross-border AI services and global platforms operating in Indonesia. This international orientation is intended to facilitate trade, investment, and cooperative enforcement mechanisms.

Implementation Timeline

MilestoneDateNotes
Public consultation opened2025-08-08Komdigi announcement
Consultation extended (deadline)2025-08-29Extension notice
Submission of Perpres initiative2025-09-05ANTARA report
Expected harmonization & draftingQ3–Q4 2025 (target)Subject to inter-agency process and stakeholder input

Sources and References

SourceType
Kementerian Komunikasi dan Digital: Konsultasi Publik Buku Putih Peta Jalan KA Nasional dan Konsep Pedoman Etika Kecerdasan Artifisial (Aug 8, 2025)Primary Source
Kementerian Komunikasi dan Digital: Perpanjangan Waktu Konsultasi Publik (Aug 22, 2025)Primary Source
JDIH Komdigi: SE No.9/2023 on AI Ethics (Dec 19, 2023)Primary Source
ANTARA: Komdigi submitted Perpres initiative (Sep 5, 2025)Primary Source (press)

Requirements for a company

What an organisation has to do under Indonesia - Ethical Guidelines for AI, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.

Must do

12
  • Perform Data Protection Impact Assessments aligned with Law No. 27/2022.Providers and operators of AI systems processing personal data.
  • Implement privacy-by-design principles when developing and deploying AI systems.Providers and operators of AI systems processing personal data.
  • Conduct pre-deployment risk assessments and classify the AI system's risk level.Providers and operators of AI systems.
  • Maintain comprehensive model documentation, data provenance, logs, and audit trails.Providers and operators of AI systems.
  • Define and implement human-in-the-loop controls for high-risk AI system functions.Providers and operators of high-risk AI systems.
  • Conduct pre-deployment safety testing and continuous monitoring of AI systems.Providers and operators of AI systems.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Adopt values-based policies consistent with the draft's ethical principles.All AI developers and operators.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Indonesia - Ethical Guidelines for AI, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers and operators of AI systems processing personal data.Perform Data Protection Impact Assessments aligned with Law No. 27/2022.
Data protection & privacy (privacy-by-design, DPIA alignment with Law No.27/2022)
Before deploymentKey Focus Areas (e)Critical
2Providers and operators of AI systems processing personal data.Implement privacy-by-design principles when developing and deploying AI systems.
Data protection & privacy (privacy-by-design, DPIA alignment with Law No.27/2022)
During developmentKey Focus Areas (e)Critical
3Providers and operators of AI systems.Conduct pre-deployment risk assessments and classify the AI system's risk level.
mandatory risk assessments and classification of high-risk use-cases
Before deploymentKey Focus Areas (b)Important
4Providers and operators of AI systems.Maintain comprehensive model documentation, data provenance, logs, and audit trails.
retention of logs, audit trails and explainability records
Before deployment and continuousKey Focus Areas (i)Important
5Providers and operators of high-risk AI systems.Define and implement human-in-the-loop controls for high-risk AI system functions.
enhanced human oversight requirements
Before deployment and continuousImplementation FrameworkImportant
6Providers and operators of AI systems.Conduct pre-deployment safety testing and continuous monitoring of AI systems.
pre-deployment testing, adversarial resilience and continuous monitoring
Before deployment and continuousKey Focus Areas (c)Important
7Providers and operators of AI systems.Implement cybersecurity requirements for AI systems, including integrity, access controls, and incident reporting.
requirements for integrity, access controls and incident reporting
Before deployment and continuousKey Focus Areas (g)Important
8Providers and operators of AI systems.Provide transparency through model cards, user notices, and labelling of AI-generated content.
Transparency & disclosure (model cards, user notices, provenance data and AI-generated content labelling)
Before deployment and continuousKey Focus Areas (d)Important
9Providers and operators of AI systems.Ensure AI systems uphold fundamental rights, including anti-discrimination and due process protections.
Fundamental rights (anti-discrimination, due process protections for automated decisions)
During development and continuousKey Focus Areas (f)Important
10Providers and operators of AI systems.Notify authorities of incidents related to AI system performance, safety, or security.
incident notification requirements
Immediately upon discoveryMonitoring and EvaluationImportant
11Providers and operators of high-risk AI systems.Register or notify significant AI deployments with the national coordination mechanism.
maintain registries or notification schemes for significant AI deployment
Before deploymentGovernance and Institutional FrameworkImportant
12Providers and operators of high-risk AI systems.Undergo third-party conformity assessment or testing for certain categories of AI systems.
third-party audit pathways and potential mandatory registration for certain categories
Before deploymentKey Focus Areas (h)Important
13All AI developers and operators.Adopt values-based policies consistent with the draft's ethical principles.
Adopt values-based policies consistent with the draft (inclusivity, transparency, accountability)
OverviewRecommended

© Regulations.AI · updated on 13-Jun-2026