Thailand - AI Risk Assessment Guidelines
Draft ETDA Notification regarding AI Risk Assessment
ร่างประกาศ ETDA ว่าด้วยการประเมินความเสี่ยงของ AI
Thailand
RAI-TH-NA-DENRAXA-2023The Draft ETDA Notification regarding AI Risk Assessment (published 17 July 2023 for public consultation) proposes a standardized, risk‑based framework for identifying, measuring, and managing risks from AI systems deployed or offered to users in Thailand. It emphasizes governance, risk mapping, measurement indicators, and risk mitigation measures, and requires providers and importers to prepare risk assessment reports and documentation for ETDA review.
Summary
Background and purpose: On 17 July 2023 the Electronic Transactions Development Agency (ETDA) published a draft Notification setting out guidelines for AI Risk Assessment and opened a public consultation (closed 19 August 2023). The draft was developed to operationalize the national approach to AI governance under Thailand’s broader AI policy initiatives and to support safe deployment of AI systems by applying a risk‑based methodology. Scope and objective: The draft targets AI systems developed, imported, offered or otherwise made available to users in Thailand and focuses on systems that may materially affect individuals, public safety, social stability, or economic activity. The draft’s principal objective is to harmonize a systematic process—across governance, risk mapping, measurement and risk management—for organizations to identify and mitigate harms from AI while enabling innovation through clarity on expectations and reporting. Core elements: The draft is organized around four pillars: (1) Governance: establishing organizational accountability, roles (e.g., AI owners, risk managers), integration of AI risk processes into corporate governance and culture, and senior sign‑off; (2) Risk mapping: use‑case and cross‑sectoral profiling to identify scenarios, affected populations, input data, model characteristics, decision‑making points and operational environments; (3) Risk measurement: definition of qualitative and quantitative indicators (e.g., likelihood/impact matrices, fairness and bias metrics, safety and robustness testing metrics, data quality measures); and (4) Risk management: prioritization, mitigation plans (technical, organizational and procedural), human oversight measures, monitoring and incident response. Requirements for providers and importers: The draft requires that AI developers, deployers and importers produce documented risk assessment reports using either a use‑case approach or a cross‑sectoral profile approach. Reports must itemize potential harms, likelihood/impact assessments, mitigation measures, monitoring plans and residual risk statements. The draft also contemplates checklists and templates for ETDA review and periodic updates of the assessment. High‑risk systems and controls: While not providing an exhaustive list of high‑risk systems, the draft signals that systems which can alter human behaviour, cause physical or mental harm, or materially affect economic or social stability will attract heightened scrutiny. The draft envisages designation lists, additional duties (e.g., registration, local representative for offshore providers), and reporting obligations for serious incidents. Relationship to other instruments: The draft was prepared in the context of parallel draft instruments (e.g., Draft AI Promotion Act, draft sandbox notification) and interacts with existing data protection (PDPA), cybersecurity and sectoral rules (finance, health). Enforcement and remedies: The draft indicates ETDA review and potential administrative measures, and contemplates referral to other competent authorities where statutory penalties exist. Consultation and next steps: The draft was subject to public consultation in mid‑2023; subsequent revisions and formal adoption would depend on ETDA processes and alignment with broader national legal reform. Stakeholder impact: Developers, service providers, digital platforms, public agencies and end‑user organizations will be affected; the draft aims to balance risk mitigation with innovation support through templates, sandboxes and ETDA guidance.
Full article
Read full text ↗Overview
The Draft Notification published by the Electronic Transactions Development Agency (ETDA) on 17 July 2023 sets out a harmonized methodology for AI risk assessment to be applied by organizations that develop, import, operate, or provide access to AI systems to users in Thailand. The document proposes a four‑pillar approach—governance, risk mapping, risk measurement, and risk management—intended to be proportionate to the potential impact of the AI system. The draft was opened for public consultation (closed 19 August 2023) and is intended to work together with other national AI initiatives, including the AI sandbox and proposed promotional legislation. For background and complementary materials, see ETDA’s AI governance resources such as the AI Governance Center and Readiness tools on the ETDA website (for example, ETDA AI Readiness Assessment).
Definitions
The draft includes working definitions to support consistent application across sectors. Key defined terms commonly used in the draft are: "AI system" (software or automated decision support that performs tasks that would otherwise require human intelligence); "AI provider" (entity that develops or supplies an AI system); "AI deployer" (entity that integrates or places the AI system into operation); "use‑case" (specific context of an AI system’s operation); "risk mapping" (systematic identification of scenarios and affected stakeholders); and "high‑risk AI" (systems whose malfunction or biased operation could cause significant physical, psychological, economic or societal harm). These definitions are aligned with the draft law and international practice but may be adapted as the regulatory process advances.
Governance and Institutional Framework
The draft places primary responsibility on AI providers and deployers to implement governance arrangements that support risk‑based oversight. This includes senior management accountability, designated roles (e.g., AI risk manager or coordinator), risk committees, and documented internal policies and processes. The ETDA is identified as the lead coordinating agency for technical guidance and review; ETDA’s AI Governance Center (AIGC) and other designated units are expected to publish checklists, templates and advisory materials. The institutional arrangements also contemplate coordination with sectoral supervisors (for example, banking, health, telecommunications) and other regulators for cross‑referrals. The draft contemplates that ETDA will maintain an updated set of guidance documents and may publish lists of AI systems subject to enhanced monitoring. For institutional resources and ETDA’s broader AI governance work see ETDA publications and AIGC resources.
Key Focus Areas
The draft centers on a set of operational requirements that map to identifiable harms. First, governance: organizations must document roles, escalation paths, and training for personnel involved in AI lifecycle activities. Second, risk mapping: organizations must identify scenarios where the AI system acts on or influences individuals, the types of input and training data, the data provenance, third‑party dependencies (e.g., pre‑trained models, APIs), and potential failure modes. Third, risk measurement: the draft asks for explicit measures and indicators—both qualitative (scenario narratives and likelihood/impact scoring) and quantitative (accuracy metrics, bias/fairness measurements, robustness tests, availability metrics, false positive/negative rates). Fourth, risk management: organizations must produce prioritized mitigation plans, detect/monitor residual risk, implement human oversight where necessary, and define incident reporting and remediation procedures. The draft also addresses data quality controls, provenance and access control measures, maintenance of model cards and documentation, and lifecycle update governance (including retraining and monitoring after deployment).
Implementation Framework
The draft expresses flexibility in methodology but establishes minimum content for risk assessment deliverables. Providers may adopt a use‑case approach (detailed assessment per distinct application) or a cross‑sectoral profiling approach (where many similar use cases share a common profile). Required deliverables include: (a) a risk assessment report describing scenarios, affected stakeholders, harm types, likelihood/impact scoring and residual risk; (b) a mitigation and monitoring plan specifying technical and organizational measures; (c) evidence of validation, testing and safety evaluation (e.g., test results, test sets); and (d) a documentation package including model description, data lineage, performance metrics and a human oversight plan. The draft signals ETDA will publish checklists and templates to promote consistent submissions and to reduce compliance costs for smaller providers. Organizations are expected to incorporate continuous monitoring and to update assessments when material changes occur.
Monitoring and Evaluation
Monitoring requirements described by the draft emphasize continuous and post‑deployment surveillance. Organizations must implement monitoring systems that capture model drift, performance degradation, bias emergence and evidence of real‑world harms. The draft recommends logging and traceability mechanisms—operational logs, decision records and data versioning—to facilitate audits and incident investigations. ETDA envisages periodic reporting and may conduct targeted audits or request documentation during supervisory reviews. The draft encourages use of metrics and KPIs to evaluate mitigation effectiveness and to inform revision cycles. ETDA also proposes to collect aggregate readiness data to refine sectoral guidance.
Penalties, Liability, and Appeals
While the draft focuses primarily on assessment and management obligations, it contemplates enforcement mechanisms administered by ETDA and coordination with other authorities. Proposed administrative measures can include corrective directions, requirements to suspend or limit deployment, registration or reporting requirements, and referrals to sectoral agencies for statutory sanctions. The draft anticipates liability may be pursued under existing legal regimes (consumer protection, data protection, civil liability) where harm occurs, and that failure to perform required risk assessments could be an evidentiary factor in civil or administrative proceedings. The draft also includes procedural elements for appeals or responses to ETDA findings to ensure due process for affected organizations.
Relationship to Other Instruments
The draft is intended to operate alongside a suite of complementary instruments: the Draft Artificial Intelligence Innovation Promotion Act (policy and promotional measures), the Draft ETDA Notification on AI Sandbox (testing and experimentation exemptions), Thailand’s Personal Data Protection Act (PDPA), sector‑specific rules (e.g., Bank of Thailand and Ministry of Public Health guidance), and the Royal Decree on Digital Platform Services. The draft explicitly cross‑references responsibilities under data protection and cybersecurity laws and envisages cooperation mechanisms for enforcement and technical assistance. It also seeks to avoid duplication by allowing documentation used for other sectoral compliance programs to satisfy ETDA requirements where appropriate.
International Alignment
The draft draws on international best practice and references standards and frameworks such as the EU AI Act principles, ISO/IEC guidance on AI risk management (including ISO/IEC 42001 family), and NIST risk management recommendations as non‑binding exemplars. ETDA signals an intent to maintain interoperability with global approaches to avoid fragmentation while tailoring requirements to Thailand’s legal and institutional context. The draft also anticipates special treatment for cross‑border provision of AI services, requiring local representation and notification for some offshore providers to ensure accountability for users in Thailand.
Implementation Timeline
| Event | Date |
|---|---|
| Draft published for public consultation | 2023-07-17 |
| Public consultation closed | 2023-08-19 |
| Expected ETDA review and revision period (indicative) | 2023-Q4 to 2024-Q2 |
| Finalization and formal issuance (indicative) | Dependent on ETDA schedule |
Sources and References
| Source | Type |
|---|---|
| ETDA - AI Readiness / AIGC resources | Primary Source |
| Digital Policy Alert - Draft ETDA Notification (consultation announcement) | Secondary Source |
| Lexel - Analysis of Thailand's Draft AI Laws | Secondary Source |
Requirements for a company
What an organisation has to do under Thailand - AI Risk Assessment Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.
Must do
13- Apply the harmonized methodology for AI risk assessment.Organizations developing, importing, operating, or providing AI systems to users in Thailand.
- Implement governance arrangements supporting risk-based oversight for AI systems.AI providers and deployers.
- Establish senior management accountability for AI risk.AI providers and deployers.
- Identify scenarios, data, dependencies, and potential failure modes for AI systems.Organizations.
- Document explicit qualitative and quantitative risk measurement indicators.Organizations.
- Produce prioritized mitigation plans for identified AI risks.Organizations.
- +7 more in the table below
Must not do
0Nothing in this category.
Should do
1- Implement logging and traceability mechanisms for AI systems.Organizations.
Should not do
0Nothing in this category.
Who must do what
The obligations under Thailand - AI Risk Assessment Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Organizations developing, importing, operating, or providing AI systems to users in Thailand. | Apply the harmonized methodology for AI risk assessment. “sets out a harmonized methodology for AI risk assessment to be applied by organizations that develop, import, operate, or provide access to AI systems to users in Thailand.” | — | Overview | Critical |
| 2 | AI providers and deployers. | Implement governance arrangements supporting risk-based oversight for AI systems. “draft places primary responsibility on AI providers and deployers to implement governance arrangements that support risk‑based oversight.” | — | Governance and Institutional Framework | Critical |
| 3 | AI providers and deployers. | Establish senior management accountability for AI risk. “This includes senior management accountability, designated roles (e.g., AI risk manager or coordinator), risk committees, and documented internal policies and processes.” | — | Governance and Institutional Framework | Critical |
| 4 | Organizations. | Identify scenarios, data, dependencies, and potential failure modes for AI systems. “organizations must identify scenarios where the AI system acts on or influences individuals, the types of input and training data, the data provenance, third‑party dependencies... and potential failure modes.” | Before placing on market | Key Focus Areas | Critical |
| 5 | Organizations. | Document explicit qualitative and quantitative risk measurement indicators. “the draft asks for explicit measures and indicators—both qualitative... and quantitative...” | Before placing on market | Key Focus Areas | Critical |
| 6 | Organizations. | Produce prioritized mitigation plans for identified AI risks. “organizations must produce prioritized mitigation plans, detect/monitor residual risk, implement human oversight where necessary, and define incident reporting and remediation procedures.” | Before placing on market | Key Focus Areas | Critical |
| 7 | AI providers and deployers. | Prepare a comprehensive AI risk assessment report. “Required deliverables include: (a) a risk assessment report describing scenarios, affected stakeholders, harm types, likelihood/impact scoring and residual risk” | Before placing on market | Implementation Framework | Critical |
| 8 | Organizations. | Implement monitoring systems for model drift, performance degradation, and bias emergence. “Organizations must implement monitoring systems that capture model drift, performance degradation, bias emergence and evidence of real‑world harms.” | Before placing on market | Monitoring and Evaluation | Critical |
| 9 | AI providers and deployers. | Provide a documentation package including model description, data lineage, and performance metrics. “(d) a documentation package including model description, data lineage, performance metrics and a human oversight plan.” | Before placing on market | Implementation Framework | Critical |
| 10 | AI providers and deployers. | Document internal policies and processes for AI risk management. “documented internal policies and processes.” | — | Governance and Institutional Framework | Important |
| 11 | Organizations. | Implement human oversight for AI systems where necessary. “implement human oversight where necessary” | Before placing on market | Key Focus Areas | Important |
| 12 | Organizations. | Define incident reporting and remediation procedures for AI systems. “define incident reporting and remediation procedures.” | — | Key Focus Areas | Important |
| 13 | Organizations. | Incorporate continuous monitoring and update risk assessments when material changes occur. “Organizations are expected to incorporate continuous monitoring and to update assessments when material changes occur.” | — | Implementation Framework | Important |
| 14 | Organizations. | Implement logging and traceability mechanisms for AI systems. “The draft recommends logging and traceability mechanisms—operational logs, decision records and data versioning—to facilitate audits and incident investigations.” | — | Monitoring and Evaluation | Recommended |
Related Regulations
© Regulations.AI · updated on 13-Jun-2026