Thailand - AI Innovation Testing Center

Draft ETDA Notification regarding Artificial Intelligence Sandbox (AI Innovation Testing Center)

ร่างประกาศ ETDA เกี่ยวกับ Sandbox ปัญญาประดิษฐ์ (ศูนย์ทดสอบนวัตกรรม AI)

Thailand

RAI-TH-NA-DENRAXX-2023
Draft(Being written or scoped)
RegulationGovernance and OversightSafety, Testing, and EvaluationRisk Management
Export PDF

This draft ETDA Notification (March 2023) sets out the framework for an AI Innovation Testing Center (AI Sandbox) operated by the Electronic Transactions Development Agency (ETDA) to enable supervised testing of AI innovations in Thailand. It establishes application procedures, oversight powers, risk-management and reporting obligations for sandbox participants while remaining subject to further revision and final approval.

Summary

The Draft ETDA Notification regarding the Artificial Intelligence Sandbox (AI Innovation Testing Center), published for public consultation on 30 March 2023, proposes a supervised regulatory testing environment managed by the Electronic Transactions Development Agency (ETDA) to support safe development and evaluation of AI systems in Thailand. The draft creates a voluntary but structured ‘AI Innovation Testing Center’ (the Sandbox) where AI developers, AI entrepreneurs and eligible organisations can test systems under ETDA oversight, gain guidance on compliance and gather performance data prior to broader deployment. The notification outlines the scope of eligible technologies, application and approval procedures, minimum documentation and safety measures, data protection and privacy safeguards, human oversight requirements, monitoring and reporting duties, confidentiality/ intellectual property protections, and the ETDA’s authority to modify, suspend, or terminate tests.

Eligibility criteria in the draft require applicants to provide detailed project plans including technical architecture, descriptions of datasets and data flows, human-in-the-loop arrangements, user safety and consumer protection measures, risk assessments and mitigation plans, monitoring indicators, exit plans, and post-test reporting commitments. ETDA review criteria emphasize feasibility, effect on public safety and quality of life, privacy and data protection compliance under Thailand’s PDPA, and technical robustness (including cybersecurity measures and resilience against adversarial inputs). The draft also proposes that tests involving potentially high-risk AI (e.g., biometric identification, healthcare diagnostics, finance-critical decisioning, public safety systems) will be subject to stricter scrutiny and additional conditions or may only be allowed within limited sandbox tracks.

Governance provisions grant ETDA powers to set terms of participation, require amendments to test plans, demand additional safeguards, suspend or terminate tests when risks materialise, and require final reports and data necessary for evaluation. The draft foresees collaboration with sectoral regulators and other public agencies for domain-specific oversight and anticipates mechanisms for cross-agency referrals. Participants must maintain logs and documentation for audit and traceability, implement transparency measures for affected users, and carry out risk monitoring and mitigation during and after testing. The draft contemplates limited ‘safe-harbor’ arrangements to encourage innovation—if participants act in good faith under supervised conditions, ETDA may limit certain administrative sanctions for conduct strictly within the agreed test boundaries (subject to exceptions, notably for serious harm or criminal acts).

Enforcement measures in the draft include contractual remedies, administrative orders, suspension/termination of sandbox access, requirement to remediate, and referral to other authorities; civil or criminal liabilities and data-protection penalties under other applicable laws remain unaffected. The consultation phase closed on 13 April 2023 and the draft is expected to be revised in light of stakeholder input and coordinated with related initiatives including a broader Draft Artificial Intelligence Innovation Promotion Act and ETDA AI governance workstreams. Primary official materials about ETDA sandboxes and AI governance (including ETDA sandbox participation guidance and ETDA AI program pages) were used to derive this regulation entry. Because the document remained a draft in 2023, there is no stated effective date yet and final content is subject to change.

Full article

Read full text ↗

Overview

The Draft ETDA Notification proposes the creation of an "AI Innovation Testing Center" (commonly referenced as an AI regulatory sandbox) run by the Electronic Transactions Development Agency (ETDA) to provide a supervised environment for testing, evaluating and refining artificial intelligence systems and services prior to general market deployment. The stated aims are to enable innovation, assess system safety and social impact, foster compliance with existing digital laws (including data protection), and to build shared technical and governance knowledge across public and private sectors. The draft was published for consultation on 30 March 2023 and the consultation period was recorded as closing on 13 April 2023; commentary and analysis of the consultation are available from public trackers and legal briefings. For programme context and established ETDA sandbox processes see the ETDA information on its Digital Service Sandbox, which the AI sandbox proposal builds on and extends. Examples and explanations of the consultation announcement are available via independent trackers and legal commentary. For the original ETDA sandbox programme: ETDA Digital Service Sandbox - ETDA. For the specific consultation event: Opened consultation on Draft ETDA Notification regarding AI Sandbox - Digital Policy Alert.

Definitions

The draft defines key terms used for the sandbox architecture. "AI Innovation" covers software/hardware that performs decision-making or problem-solving by processing data via algorithms and learning methods. "AI Entrepreneur" describes any person or legal entity that develops or offers AI-based products or services. "Testing Project" (or "Sandbox Project") is the applicant’s described test activity, including scope, duration, KPIs, datasets used, stakeholders and exit strategy. "Human Oversight" requires named persons with authority to intervene in operation or decisioning. "High-risk AI" is the label for categories with potential to cause significant physical, economic, social or rights-related harm; the draft sets higher bars for approval and monitoring for such cases. "AIGC" / "AI Governance Center" refers to the institutional unit within ETDA that will manage technical evaluations, guidance and cross-sector coordination for AI governance tasks. The draft also clarifies what constitutes the "test boundary" (the permitted scope of a sandbox trial) and "safe harbour" protections (limited administrative leniency for good-faith supervised testing within the sandbox, excluding criminal acts and severe public harm).

Governance and Institutional Framework

ETDA is assigned central responsibility for establishing the AI Innovation Testing Center, managing applications, granting permissions, supervising tests and coordinating with sectoral regulators and data-protection authorities. The draft anticipates the creation or designation of an internal AI Governance Center (AIGC) within ETDA to provide technical assessment, advisory services and monitoring. ETDA’s governance remit includes adopting participation rules, approving project plans, setting risk-mitigation conditions, and exercising powers to require plan modification, suspend or terminate tests that present unacceptable risks. The draft envisions memoranda of understanding with sectoral regulators (e.g., health, finance, telecommunications) where domain-specific regulatory oversight is needed. ETDA’s role incorporates capacity-building: publishing guidance, templates, toolkits and evaluation methodologies to promote reproducible safe-testing practices. The draft states ETDA may publish anonymised summaries of testing outcomes to inform public policy while protecting proprietary information and personal data. See ETDA’s general sandbox guidance for operational precedent at ETDA Digital Service Sandbox - ETDA and related ETDA AI program pages.

Key Focus Areas

The draft sets out substantive priorities for sandbox projects. Technical robustness and safety: applicants must present system architecture, failure modes, fallback mechanisms and cybersecurity protections. Data governance and privacy: applicants must document data provenance, consent regimes, data minimisation, anonymisation/pseudonymisation, data retention and cross-border transfer measures consistent with Thailand’s PDPA. Human oversight and explainability: projects must demonstrate human-in-the-loop controls, escalation procedures and explainability methods suitable for impacted users. Risk assessment and mitigation: comprehensive pre-test risk assessments and live monitoring plans are required; high-risk activities may require additional audits, independent testing or co-supervision. Consumer protection and redress: plans must include complaint handling, notification of affected persons (when applicable), remedies for harm and contact points. Transparency and reporting: ETDA may require public notice of tests affecting the public and periodic reporting to ETDA and designated regulators. Interoperability and standards: projects are encouraged to align with technical standards and to provide documentation that helps regulators assess conformity and reproducibility. Social impact and ethics: applicants must present an assessment of potential societal harms, biases, discrimination risks and environmental impacts. Finally, intellectual property and confidentiality: the draft balances disclosure for regulatory evaluation with protection of trade secrets where justified under defined safeguards.

Implementation Framework

Participation is voluntary and requires submission of a detailed application package to ETDA including the project plan, risk assessment, data inventories, technical and organisational safeguards, monitoring metrics, user communication plans and exit strategies. ETDA has defined procedural timelines in the draft for initial completeness checks, substantive review, decision and execution of a participation agreement. The draft proposes time-bound trial windows with potential extensions upon justification. Participants are required to execute a written agreement with ETDA that sets test boundaries, permitted user classes, reporting cadence, audit rights and liability allocation. ETDA may require participant insurance or financial guarantees for projects with potential for material harm. Testing often occurs in staged phases (internal, limited public, expanded public), with ETDA permitting progression only after meeting agreed success criteria. ETDA reserves the right to require independent technical audits and to impose corrective measures or additional safeguards at any stage of the test. The draft also contemplates cooperation with research institutions and independent evaluators for evidence-based assessment of outcomes; see analysis at Thailand's Draft Laws for AI - Lexel.

Monitoring and Evaluation

During testing, participants must implement continuous monitoring, maintain audit logs and submit interim reports. ETDA may request live access to monitoring dashboards, anonymised logs and incident reports. KPIs and safety indicators must be measured against pre-defined thresholds; breaching thresholds triggers predefined escalation, pausing or rollback protocols. ETDA will maintain records of outcomes to inform subsequent regulatory guidance and may publish aggregated findings. The draft foresees periodic compliance reviews, post-test evaluation reports and an evidence repository to support standard-setting and future conformity assessment frameworks. For the consultation timeline and public hearing details see the public tracker of the consultation event: Opened consultation on Draft ETDA Notification regarding AI Sandbox - Digital Policy Alert.

Penalties, Liability, and Appeals

The draft distinguishes sandbox administrative enforcement from liabilities under other laws. ETDA’s sanctions under the draft are administrative: corrective orders, modification requirements, suspension or termination of sandbox participation, public notices and potential referral to sectoral regulators. The draft contemplates limited safe-harbor protections for good-faith participation but excludes immunity for criminal conduct, wilful negligence or serious harm. Civil liability and data-protection penalties under the Personal Data Protection Act (PDPA) and other statutes are unaffected. Participants have a defined right to seek administrative review or file appeals against ETDA decisions within prescribed timelines. ETDA may retain the right to require remediation and compensation mechanisms in cases where sandbox tests cause harm to individuals or public interests.

Relationship to Other Instruments

The draft is designed to operate alongside Thailand’s existing digital regime: the Electronic Transactions Act, the Personal Data Protection Act (PDPA), sectoral laws (health, finance, telecommunications), and any future AI promotion/regulation acts. It is intentionally a subordinate administrative instrument: its scope is to provide a supervised testing pathway and is not intended to replace sectoral licensing or statutory obligations. The draft references coordination with any forthcoming national AI legislation and with ETDA’s own AI governance program. Cross-references and referrals to other competent authorities are explicitly foreseen to ensure domain-specific compliance and to avoid regulatory gaps.

International Alignment

The draft explicitly references international trends in sandboxes, regulatory testing and AI risk-based approaches (notably the EU AI Act’s sandbox concept and OECD principles). It is structured to enable interoperability with international best practices on safety testing, transparency and data governance, and anticipates cooperation with foreign regulatory sandboxes for cross-border pilots. The draft encourages adoption of international standards for technical evaluation, cybersecurity, and privacy-preserving techniques to facilitate market entry and compliance alignment. Legal commentators observed this alignment during consultation and emphasized harmonisation with global frameworks; see commentary and law firm briefings linked at Thailand's draft AI law - Norton Rose Fulbright and the ETDA programme pages.

Implementation Timeline

EventDate
Draft published for public consultation2023-03-30
Consultation period closed (public record)2023-04-13
Stakeholder review and revision phase (ETDA)2023 Q2–Q3 (indicative)
Potential coordination with Draft AI Promotion Act hearings2023–2024 (indicative)
Final issuance (if adopted)To be determined

Sources and References

SourceType
ETDA Digital Service Sandbox - ETDAPrimary Source
Opened consultation on Draft ETDA Notification regarding AI Sandbox - Digital Policy AlertSecondary/Tracking Source
Thailand's Draft Laws for AI - Lexel (legal commentary)Secondary Analysis

Requirements for a company

What an organisation has to do under Thailand - AI Innovation Testing Center, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.

Must do

14
  • Submit a detailed application package to ETDA for sandbox participation.AI Entrepreneurs seeking sandbox participation.
  • Execute a written agreement with ETDA defining test boundaries and participant obligations.Sandbox participants.
  • Present system architecture, failure modes, fallback mechanisms, and cybersecurity protections.AI Entrepreneurs applying to the sandbox.
  • Document data provenance, consent, minimisation, anonymisation, retention, and transfer measures consistent with PDPA.AI Entrepreneurs applying to the sandbox.
  • Demonstrate human-in-the-loop controls, escalation procedures, and explainability methods.AI Entrepreneurs applying to the sandbox.
  • Conduct comprehensive pre-test risk assessments and develop live monitoring plans.AI Entrepreneurs applying to the sandbox.
  • +8 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Adopt international standards for technical evaluation, cybersecurity, and privacy-preserving techniques.Sandbox participants.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Thailand - AI Innovation Testing Center, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1AI Entrepreneurs seeking sandbox participation.Submit a detailed application package to ETDA for sandbox participation.
Participation is voluntary and requires submission of a detailed application package to ETDA.
Before commencing testingCritical
2Sandbox participants.Execute a written agreement with ETDA defining test boundaries and participant obligations.
Participants are required to execute a written agreement with ETDA that sets test boundaries.
Before commencing testingCritical
3AI Entrepreneurs applying to the sandbox.Present system architecture, failure modes, fallback mechanisms, and cybersecurity protections.
applicants must present system architecture, failure modes, fallback mechanisms and cybersecurity protections.
Upon applicationCritical
4AI Entrepreneurs applying to the sandbox.Document data provenance, consent, minimisation, anonymisation, retention, and transfer measures consistent with PDPA.
applicants must document data provenance, consent regimes, data minimisation... consistent with Thailand’s PDPA.
Upon applicationCritical
5AI Entrepreneurs applying to the sandbox.Demonstrate human-in-the-loop controls, escalation procedures, and explainability methods.
projects must demonstrate human-in-the-loop controls, escalation procedures and explainability methods.
Upon applicationCritical
6AI Entrepreneurs applying to the sandbox.Conduct comprehensive pre-test risk assessments and develop live monitoring plans.
comprehensive pre-test risk assessments and live monitoring plans are required.
Upon applicationCritical
7AI Entrepreneurs applying to the sandbox.Include plans for complaint handling, user notification, and remedies for harm.
plans must include complaint handling, notification of affected persons (when applicable), remedies for harm.
Upon applicationCritical
8Sandbox participants.Implement continuous monitoring, maintain audit logs, and submit interim reports during testing.
participants must implement continuous monitoring, maintain audit logs and submit interim reports.
During testingCritical
9Sandbox participants.Measure KPIs against thresholds and implement escalation or rollback protocols for breaches.
KPIs and safety indicators must be measured against pre-defined thresholds; breaching thresholds triggers predefined escalation.
During testingCritical
10Sandbox participants.Provide ETDA with live access to monitoring dashboards, anonymised logs, and incident reports upon request.
ETDA may request live access to monitoring dashboards, anonymised logs and incident reports.
During testing, upon requestCritical
11Sandbox participants.Ensure testing avoids criminal conduct, wilful negligence, or serious harm to public interests.
excludes immunity for criminal conduct, wilful negligence or serious harm.
During testingCritical
12Sandbox participants with high-risk projects.Obtain insurance or financial guarantees if required by ETDA for projects with potential for material harm.
ETDA may require participant insurance or financial guarantees for projects with potential for material harm.
Before commencing testingCritical
13Sandbox participants.Comply with ETDA requirements for independent technical audits and corrective measures.
ETDA reserves the right to require independent technical audits and to impose corrective measures.
During testingCritical
14AI Entrepreneurs applying to the sandbox.Present an assessment of potential societal harms, biases, discrimination risks, and environmental impacts.
applicants must present an assessment of potential societal harms, biases, discrimination risks and environmental impacts.
Upon applicationImportant
15Sandbox participants.Adopt international standards for technical evaluation, cybersecurity, and privacy-preserving techniques.
The draft encourages adoption of international standards for technical evaluation, cybersecurity, and privacy-preserving techniques.
During testingRecommended

© Regulations.AI · updated on 13-Jun-2026