Indonesia - Draft AI Bill
Draft Bill on Artificial Intelligence
Rancangan Undang-Undang tentang Kecerdasan Buatan (Draft Bill on Artificial Intelligence)
Indonesia
RAI-ID-NA-RUTKBXX-2025Indonesia - Draft AI Bill is Draft in Indonesia as of 7 Sep 2026, according to setkab.go.id.
BillGovernance and OversightRisk ManagementConformity Assessment and RegistrationThe proposed Draft Bill on Artificial Intelligence (RUU Kecerdasan Buatan) sets out a risk-based regulatory framework and transparency rules for AI providers and deployers in Indonesia. Initiated under the Government's 2020 national strategy, it creates registration duties for high-risk AI monitored by Kominfo. The law remains in draft status.
Summary
This regulation entry collects publicly available official materials, government announcements, and contextual legislation relevant to a proposed Indonesian Draft Bill on Artificial Intelligence (RUU Kecerdasan Buatan). No single consolidated official draft text titled "Rancangan Undang-Undang tentang Kecerdasan Buatan" was published on central government legislative portals or ministries' legislative pages as of the retrieval date. Instead, Indonesia has relied on a national strategic framework (Strategi Nasional untuk Kecerdasan Artifisial 2020–2045) and multiple ministerial/agency initiatives and statements indicating the government's intent to develop a regulatory framework, complemented by planned national AI roadmap activity in 2025.
The likely objectives of a dedicated RUU AI — as derived from official strategy and ministry statements — would be to: (1) implement a risk-based regulatory approach that protects fundamental rights and public safety while fostering innovation; (2) establish governance and oversight roles across ministries, regulators, and a possible national AI authority or coordination secretariat; (3) impose obligations on providers and deployers of AI systems regarding risk assessment, transparency, data protection compliance, security, and impact testing; (4) introduce conformity assessment, registration, and market surveillance for high-risk AI systems; and (5) provide enforcement tools, administrative penalties, and liability regimes for harm resulting from AI systems. These aims align with the Government's declared priorities (healthcare, public service reform/reformasi birokrasi, talent and education, smart cities, and food security) and the 2020–2045 national strategy.
Key structural elements expected in a draft bill include: definitions and scope (covering AI systems, providers, deployers, high-risk categories), governance and institutional arrangements (lead ministry coordination, roles for Kominfo, BSSN, BRIN, Ministry of Health, and DPR oversight), risk-based classification and prohibited uses, obligations for transparency and documentation including mandatory model cards and impact assessments, data protection and privacy alignment with the Personal Data Protection Act (UU No. 27/2022), cybersecurity and model security provisions, conformity and registration regimes for high-risk systems, mechanisms for redress and liability, and enforcement/penalty powers. These anticipated features derive from Indonesia’s national strategy and public statements by Kominfo and coordinating ministries as the Government prepares a national AI roadmap.
Because no central official consolidated draft text for the RUU AI was publicly located, this entry is synthetic: it draws on official strategy documents and ministry announcements to describe the expected content, structure, scope, and key obligations that a formal Draft Bill would include if/when published by the government. Users seeking the actual legislative text should monitor the DPR/Baleg publication pages and ministerial legal portals listed in the Sources below.
Full article
Read full text ↗Overview
The Draft Bill on Artificial Intelligence ("RUU AI") would establish a national, risk-based legal framework for the development, deployment, and oversight of AI systems across public and private sectors in Indonesia. It is intended to operationalize priorities defined in the national strategic framework "Strategi Nasional untuk Kecerdasan Artifisial 2020–2045" and to be coordinated with ministries and agencies responsible for communications, cybersecurity, research, health, and economic coordination. Official statements and government roadmaps indicate the Government planned to publish a more detailed AI roadmap during 2025 while broader strategic direction stems from the 2020–2045 national strategy. For context and ongoing public materials see the national strategy and government announcements. Setkab: International Cooperation on AI. (setkab.go.id)
Definitions
The draft would define core terms: "artificial intelligence" and "AI system" (likely as software or systems that produce outputs such as predictions, recommendations, content or decisions); "provider" (entity that develops or supplies an AI model or service); "deployer" (entity that integrates or uses the AI system in a specific context); "high-risk AI" (systems whose failure, misuse, or bias presents serious harm to health, safety, fundamental rights, or public order); and "training data". Definitions would be calibrated to align with existing Indonesian law (e.g., electronic systems law, personal data protection law) and international norms to maintain interoperability.
Governance and Institutional Framework
The bill would establish a multi-agency governance model with lead coordination by the Ministry of Communication and Digital (Kominfo) or a dedicated national AI coordination unit, supported by the National Cyber and Crypto Agency (BSSN) for cybersecurity, BRIN for research standards, Kemenkes for health-related AI, and the Ministry of Home Affairs for local government deployment. The DPR's Badan Legislasi (Baleg) and parliamentary committees would retain legislative oversight. The law would likely create mechanisms for interministerial coordination, technical advisory boards (including civil society and industry representatives), and a registration / catalogue system for high-risk AI systems to support market surveillance and transparency. See Kominfo statements and national strategy documents for roles and priorities. Kementerian Komunikasi dan Informatika (Kominfo).
Key Focus Areas
The RUU would be expected to emphasize: (1) risk-based categorization (prohibited, unacceptable, high, limited, minimal risk); (2) mandatory risk assessments and mitigation for high-risk systems; (3) requirements for transparency and human oversight (including model documentation, "model cards", and user-facing disclosures when decisions significantly affect individuals); (4) data governance and mandatory alignment with Indonesia's Personal Data Protection law; (5) cybersecurity and model security controls to prevent poisoning, leakage, or misuse; (6) conformity assessment and registration for systems that impact safety or rights; (7) sector-specific safeguards for healthcare, finance, public services and broadcasting; and (8) research and innovation safeguards enabling safe experimentation (sandbox regimes). These focus areas reflect the national strategy and Kominfo roadmap priorities. Strategi Nasional untuk Kecerdasan Artifisial 2020–2045.
Implementation Framework
Implementation would combine primary legislation with delegated regulation: ministerial regulations (Peraturan Menteri), government regulations (Peraturan Pemerintah), and sectoral technical standards. The law would empower regulators to set conformity assessment procedures, require pre-deployment safety testing for high-risk AI, define notification or registration thresholds, and mandate incident reporting and post-market monitoring. It would also foreclose certain prohibited uses (e.g., unregulated biometric mass surveillance) and outline sandbox pathways for innovators. Regulatory coordination with the Personal Data Protection Act and existing electronic systems legislation is anticipated.
Monitoring and Evaluation
Monitoring would rely on market surveillance authorities, periodic audits, mandatory reporting from providers and deployers, and public registries for high-risk systems. The law would require impact metrics (safety, fairness, transparency) and periodic public evaluation to permit updates in response to rapid technical change. A national AI observatory or registry may be used to collect usage statistics and incidents, guiding updates to the risk taxonomy and enforcement priorities.
Penalties, Liability, and Appeals
The draft would create a layered enforcement scheme: administrative sanctions (warnings, fines scaled to turnover or impact), corrective orders (recalls, suspension), civil liability provisions (for harms caused by systems), and criminal sanctions for deliberate wrongdoing where applicable (e.g., severe negligence or fraud). It would also institute appeal mechanisms and judicial review for enforcement actions. The bill would coordinate liability regimes with existing Indonesian civil and consumer protection laws.
Relationship to Other Instruments
The RUU AI would be designed to operate alongside: Law on Electronic Information and Transactions (ITE law and related government regulations), the Personal Data Protection Act (UU No. 27/2022), sectoral laws (health, finance, broadcasting), and national data governance policies such as One Data Indonesia. The draft must ensure consistency and avoid conflicts with existing statutes while providing AI-specific obligations where gaps exist. Officials have indicated AI provisions may also appear in sector-specific laws and RUU revisions (e.g., copyright, broadcasting, education).
International Alignment
Indonesia seeks to align its approach with international standards (OECD, EU AI Act principles, G20 outcomes) while advocating positions for developing countries in global fora. The national strategy and government statements emphasize international cooperation, capacity building, and alignment that preserves technological sovereignty and inclusive development. The law would therefore incorporate internationally recognized principles such as human-centric AI, proportionality, transparency, and accountability. Setkab: International Cooperation on AI. (setkab.go.id)
Implementation Timeline
| Milestone | Date (if announced) |
|---|---|
| Strategic framework (STRANAS AI) published | 2020 (Strategic timeframe 2020–2045). |
| Government statements & interagency coordination on AI roadmap | 2024–2025 (public announcements; roadmap targeted for July 2025). |
| Planned national AI roadmap launch (ministerial announcement) | July 2025 (Kominfo roadmap launch plan reported by press). |
| Draft Bill publication (official RUU text) | Not publicly published as of retrieval date. |
Sources and References
| Source | Type |
|---|---|
| Setkab: Kerja Sama Internasional untuk Mendukung Pemanfaatan dan Pengembangan AI di Indonesia | Primary Source |
| Strategi Nasional untuk Kecerdasan Artifisial 2020–2045 (STRANAS KA) | Primary Source |
| Kompas: Government to launch AI roadmap July 2025 | Official press coverage |
| Kementerian Komunikasi dan Informatika (Kominfo) official announcements | Primary Source |
Requirements for a company
What an organisation has to do under Indonesia - Draft AI Bill, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.
Must do
14- Avoid prohibited uses of AI, such as unregulated biometric mass surveillance.All entities developing or deploying AI systems.
- Conduct mandatory risk assessments for high-risk AI systems.Providers and deployers of high-risk AI systems.
- Implement mitigation measures for identified risks in high-risk AI systems.Providers and deployers of high-risk AI systems.
- Ensure AI systems comply with Indonesia's Personal Data Protection law.Providers and deployers of AI systems.
- Implement cybersecurity and model security controls for AI systems.Providers and deployers of AI systems.
- Undergo conformity assessment for AI systems impacting safety or rights.Providers of AI systems impacting safety or rights.
- +8 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Indonesia - Draft AI Bill, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | All entities developing or deploying AI systems. | Avoid prohibited uses of AI, such as unregulated biometric mass surveillance. “foreclose certain prohibited uses (e.g., unregulated biometric mass surveillance)” | — | Implementation Framework | Critical |
| 2 | Providers and deployers of high-risk AI systems. | Conduct mandatory risk assessments for high-risk AI systems. “mandatory risk assessments and mitigation for high-risk systems” | Before placing on market | Key Focus Areas | Critical |
| 3 | Providers and deployers of high-risk AI systems. | Implement mitigation measures for identified risks in high-risk AI systems. “mandatory risk assessments and mitigation for high-risk systems” | Before placing on market | Key Focus Areas | Critical |
| 4 | Providers and deployers of AI systems. | Ensure AI systems comply with Indonesia's Personal Data Protection law. “data governance and mandatory alignment with Indonesia's Personal Data Protection law” | — | Key Focus Areas | Critical |
| 5 | Providers and deployers of AI systems. | Implement cybersecurity and model security controls for AI systems. “cybersecurity and model security controls to prevent poisoning, leakage, or misuse” | Before placing on market | Key Focus Areas | Critical |
| 6 | Providers of AI systems impacting safety or rights. | Undergo conformity assessment for AI systems impacting safety or rights. “conformity assessment and registration for systems that impact safety or rights” | Before placing on market | Key Focus Areas | Critical |
| 7 | Providers of high-risk AI systems. | Conduct pre-deployment safety testing for high-risk AI systems. “require pre-deployment safety testing for high-risk AI” | Before placing on market | Implementation Framework | Critical |
| 8 | Providers and deployers of AI systems. | Report incidents and adverse outcomes for AI systems. “mandate incident reporting and post-market monitoring” | — | Implementation Framework | Critical |
| 9 | Providers and deployers of high-risk AI systems. | Register high-risk AI systems in the national registry. “a registration / catalogue system for high-risk AI systems to support market surveillance” | Before placing on market | Governance and Institutional Framework | Critical |
| 10 | Deployers of AI systems. | Provide user-facing disclosures when AI decisions significantly affect individuals. “user-facing disclosures when decisions significantly affect individuals” | — | Key Focus Areas | Critical |
| 11 | Providers of AI systems. | Provide model documentation, including 'model cards', for AI systems. “model documentation, 'model cards', and user-facing disclosures” | Before placing on market | Key Focus Areas | Important |
| 12 | Deployers of AI systems. | Ensure human oversight for AI systems. “requirements for transparency and human oversight” | — | Key Focus Areas | Important |
| 13 | Providers and deployers of AI systems. | Perform post-market monitoring for AI systems. “mandate incident reporting and post-market monitoring” | — | Implementation Framework | Important |
| 14 | Providers and deployers of AI systems. | Provide mandatory reports to authorities. “mandatory reporting from providers and deployers” | — | Monitoring and Evaluation | Important |
Related Regulations
More AI regulation in Indonesia
© Regulations.AI · updated on 20 Sep 2026 · reviewed against official sources on 7 Sep 2026 using Gemini 3.6 Flash