Indonesia - Draft AI Bill

Draft Bill on Artificial Intelligence

Rancangan Undang-Undang tentang Kecerdasan Buatan (Draft Bill on Artificial Intelligence)

Indonesia

RAI-ID-NA-RUTKBXX-2025
Draft(Being written or scoped)Checked 7 Sep 2026

Indonesia - Draft AI Bill is Draft in Indonesia as of 7 Sep 2026, according to setkab.go.id.

BillGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

The proposed Draft Bill on Artificial Intelligence (RUU Kecerdasan Buatan) sets out a risk-based regulatory framework and transparency rules for AI providers and deployers in Indonesia. Initiated under the Government's 2020 national strategy, it creates registration duties for high-risk AI monitored by Kominfo. The law remains in draft status.

Summary

This regulation entry collects publicly available official materials, government announcements, and contextual legislation relevant to a proposed Indonesian Draft Bill on Artificial Intelligence (RUU Kecerdasan Buatan). No single consolidated official draft text titled "Rancangan Undang-Undang tentang Kecerdasan Buatan" was published on central government legislative portals or ministries' legislative pages as of the retrieval date. Instead, Indonesia has relied on a national strategic framework (Strategi Nasional untuk Kecerdasan Artifisial 2020–2045) and multiple ministerial/agency initiatives and statements indicating the government's intent to develop a regulatory framework, complemented by planned national AI roadmap activity in 2025.

The likely objectives of a dedicated RUU AI — as derived from official strategy and ministry statements — would be to: (1) implement a risk-based regulatory approach that protects fundamental rights and public safety while fostering innovation; (2) establish governance and oversight roles across ministries, regulators, and a possible national AI authority or coordination secretariat; (3) impose obligations on providers and deployers of AI systems regarding risk assessment, transparency, data protection compliance, security, and impact testing; (4) introduce conformity assessment, registration, and market surveillance for high-risk AI systems; and (5) provide enforcement tools, administrative penalties, and liability regimes for harm resulting from AI systems. These aims align with the Government's declared priorities (healthcare, public service reform/reformasi birokrasi, talent and education, smart cities, and food security) and the 2020–2045 national strategy.

Key structural elements expected in a draft bill include: definitions and scope (covering AI systems, providers, deployers, high-risk categories), governance and institutional arrangements (lead ministry coordination, roles for Kominfo, BSSN, BRIN, Ministry of Health, and DPR oversight), risk-based classification and prohibited uses, obligations for transparency and documentation including mandatory model cards and impact assessments, data protection and privacy alignment with the Personal Data Protection Act (UU No. 27/2022), cybersecurity and model security provisions, conformity and registration regimes for high-risk systems, mechanisms for redress and liability, and enforcement/penalty powers. These anticipated features derive from Indonesia’s national strategy and public statements by Kominfo and coordinating ministries as the Government prepares a national AI roadmap.

Because no central official consolidated draft text for the RUU AI was publicly located, this entry is synthetic: it draws on official strategy documents and ministry announcements to describe the expected content, structure, scope, and key obligations that a formal Draft Bill would include if/when published by the government. Users seeking the actual legislative text should monitor the DPR/Baleg publication pages and ministerial legal portals listed in the Sources below.

Full article

Read full text ↗

Overview

The Draft Bill on Artificial Intelligence ("RUU AI") would establish a national, risk-based legal framework for the development, deployment, and oversight of AI systems across public and private sectors in Indonesia. It is intended to operationalize priorities defined in the national strategic framework "Strategi Nasional untuk Kecerdasan Artifisial 2020–2045" and to be coordinated with ministries and agencies responsible for communications, cybersecurity, research, health, and economic coordination. Official statements and government roadmaps indicate the Government planned to publish a more detailed AI roadmap during 2025 while broader strategic direction stems from the 2020–2045 national strategy. For context and ongoing public materials see the national strategy and government announcements. Setkab: International Cooperation on AI. (setkab.go.id)

Definitions

The draft would define core terms: "artificial intelligence" and "AI system" (likely as software or systems that produce outputs such as predictions, recommendations, content or decisions); "provider" (entity that develops or supplies an AI model or service); "deployer" (entity that integrates or uses the AI system in a specific context); "high-risk AI" (systems whose failure, misuse, or bias presents serious harm to health, safety, fundamental rights, or public order); and "training data". Definitions would be calibrated to align with existing Indonesian law (e.g., electronic systems law, personal data protection law) and international norms to maintain interoperability.

Governance and Institutional Framework

The bill would establish a multi-agency governance model with lead coordination by the Ministry of Communication and Digital (Kominfo) or a dedicated national AI coordination unit, supported by the National Cyber and Crypto Agency (BSSN) for cybersecurity, BRIN for research standards, Kemenkes for health-related AI, and the Ministry of Home Affairs for local government deployment. The DPR's Badan Legislasi (Baleg) and parliamentary committees would retain legislative oversight. The law would likely create mechanisms for interministerial coordination, technical advisory boards (including civil society and industry representatives), and a registration / catalogue system for high-risk AI systems to support market surveillance and transparency. See Kominfo statements and national strategy documents for roles and priorities. Kementerian Komunikasi dan Informatika (Kominfo).

Key Focus Areas

The RUU would be expected to emphasize: (1) risk-based categorization (prohibited, unacceptable, high, limited, minimal risk); (2) mandatory risk assessments and mitigation for high-risk systems; (3) requirements for transparency and human oversight (including model documentation, "model cards", and user-facing disclosures when decisions significantly affect individuals); (4) data governance and mandatory alignment with Indonesia's Personal Data Protection law; (5) cybersecurity and model security controls to prevent poisoning, leakage, or misuse; (6) conformity assessment and registration for systems that impact safety or rights; (7) sector-specific safeguards for healthcare, finance, public services and broadcasting; and (8) research and innovation safeguards enabling safe experimentation (sandbox regimes). These focus areas reflect the national strategy and Kominfo roadmap priorities. Strategi Nasional untuk Kecerdasan Artifisial 2020–2045.

Implementation Framework

Implementation would combine primary legislation with delegated regulation: ministerial regulations (Peraturan Menteri), government regulations (Peraturan Pemerintah), and sectoral technical standards. The law would empower regulators to set conformity assessment procedures, require pre-deployment safety testing for high-risk AI, define notification or registration thresholds, and mandate incident reporting and post-market monitoring. It would also foreclose certain prohibited uses (e.g., unregulated biometric mass surveillance) and outline sandbox pathways for innovators. Regulatory coordination with the Personal Data Protection Act and existing electronic systems legislation is anticipated.

Monitoring and Evaluation

Monitoring would rely on market surveillance authorities, periodic audits, mandatory reporting from providers and deployers, and public registries for high-risk systems. The law would require impact metrics (safety, fairness, transparency) and periodic public evaluation to permit updates in response to rapid technical change. A national AI observatory or registry may be used to collect usage statistics and incidents, guiding updates to the risk taxonomy and enforcement priorities.

Penalties, Liability, and Appeals

The draft would create a layered enforcement scheme: administrative sanctions (warnings, fines scaled to turnover or impact), corrective orders (recalls, suspension), civil liability provisions (for harms caused by systems), and criminal sanctions for deliberate wrongdoing where applicable (e.g., severe negligence or fraud). It would also institute appeal mechanisms and judicial review for enforcement actions. The bill would coordinate liability regimes with existing Indonesian civil and consumer protection laws.

Relationship to Other Instruments

The RUU AI would be designed to operate alongside: Law on Electronic Information and Transactions (ITE law and related government regulations), the Personal Data Protection Act (UU No. 27/2022), sectoral laws (health, finance, broadcasting), and national data governance policies such as One Data Indonesia. The draft must ensure consistency and avoid conflicts with existing statutes while providing AI-specific obligations where gaps exist. Officials have indicated AI provisions may also appear in sector-specific laws and RUU revisions (e.g., copyright, broadcasting, education).

International Alignment

Indonesia seeks to align its approach with international standards (OECD, EU AI Act principles, G20 outcomes) while advocating positions for developing countries in global fora. The national strategy and government statements emphasize international cooperation, capacity building, and alignment that preserves technological sovereignty and inclusive development. The law would therefore incorporate internationally recognized principles such as human-centric AI, proportionality, transparency, and accountability. Setkab: International Cooperation on AI. (setkab.go.id)

Implementation Timeline

MilestoneDate (if announced)
Strategic framework (STRANAS AI) published2020 (Strategic timeframe 2020–2045).
Government statements & interagency coordination on AI roadmap2024–2025 (public announcements; roadmap targeted for July 2025).
Planned national AI roadmap launch (ministerial announcement)July 2025 (Kominfo roadmap launch plan reported by press).
Draft Bill publication (official RUU text)Not publicly published as of retrieval date.

Sources and References

SourceType
Setkab: Kerja Sama Internasional untuk Mendukung Pemanfaatan dan Pengembangan AI di IndonesiaPrimary Source
Strategi Nasional untuk Kecerdasan Artifisial 2020–2045 (STRANAS KA)Primary Source
Kompas: Government to launch AI roadmap July 2025Official press coverage
Kementerian Komunikasi dan Informatika (Kominfo) official announcementsPrimary Source

Requirements for a company

What an organisation has to do under Indonesia - Draft AI Bill, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.

Must do

14
  • Avoid prohibited uses of AI, such as unregulated biometric mass surveillance.All entities developing or deploying AI systems.
  • Conduct mandatory risk assessments for high-risk AI systems.Providers and deployers of high-risk AI systems.
  • Implement mitigation measures for identified risks in high-risk AI systems.Providers and deployers of high-risk AI systems.
  • Ensure AI systems comply with Indonesia's Personal Data Protection law.Providers and deployers of AI systems.
  • Implement cybersecurity and model security controls for AI systems.Providers and deployers of AI systems.
  • Undergo conformity assessment for AI systems impacting safety or rights.Providers of AI systems impacting safety or rights.
  • +8 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Indonesia - Draft AI Bill, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1All entities developing or deploying AI systems.Avoid prohibited uses of AI, such as unregulated biometric mass surveillance.
“foreclose certain prohibited uses (e.g., unregulated biometric mass surveillance)”
—Implementation FrameworkCritical
2Providers and deployers of high-risk AI systems.Conduct mandatory risk assessments for high-risk AI systems.
“mandatory risk assessments and mitigation for high-risk systems”
Before placing on marketKey Focus AreasCritical
3Providers and deployers of high-risk AI systems.Implement mitigation measures for identified risks in high-risk AI systems.
“mandatory risk assessments and mitigation for high-risk systems”
Before placing on marketKey Focus AreasCritical
4Providers and deployers of AI systems.Ensure AI systems comply with Indonesia's Personal Data Protection law.
“data governance and mandatory alignment with Indonesia's Personal Data Protection law”
—Key Focus AreasCritical
5Providers and deployers of AI systems.Implement cybersecurity and model security controls for AI systems.
“cybersecurity and model security controls to prevent poisoning, leakage, or misuse”
Before placing on marketKey Focus AreasCritical
6Providers of AI systems impacting safety or rights.Undergo conformity assessment for AI systems impacting safety or rights.
“conformity assessment and registration for systems that impact safety or rights”
Before placing on marketKey Focus AreasCritical
7Providers of high-risk AI systems.Conduct pre-deployment safety testing for high-risk AI systems.
“require pre-deployment safety testing for high-risk AI”
Before placing on marketImplementation FrameworkCritical
8Providers and deployers of AI systems.Report incidents and adverse outcomes for AI systems.
“mandate incident reporting and post-market monitoring”
—Implementation FrameworkCritical
9Providers and deployers of high-risk AI systems.Register high-risk AI systems in the national registry.
“a registration / catalogue system for high-risk AI systems to support market surveillance”
Before placing on marketGovernance and Institutional FrameworkCritical
10Deployers of AI systems.Provide user-facing disclosures when AI decisions significantly affect individuals.
“user-facing disclosures when decisions significantly affect individuals”
—Key Focus AreasCritical
11Providers of AI systems.Provide model documentation, including 'model cards', for AI systems.
“model documentation, 'model cards', and user-facing disclosures”
Before placing on marketKey Focus AreasImportant
12Deployers of AI systems.Ensure human oversight for AI systems.
“requirements for transparency and human oversight”
—Key Focus AreasImportant
13Providers and deployers of AI systems.Perform post-market monitoring for AI systems.
“mandate incident reporting and post-market monitoring”
—Implementation FrameworkImportant
14Providers and deployers of AI systems.Provide mandatory reports to authorities.
“mandatory reporting from providers and deployers”
—Monitoring and EvaluationImportant

© Regulations.AI · updated on 20 Sep 2026 · reviewed against official sources on 7 Sep 2026 using Gemini 3.6 Flash