Thailand - AI Ethics Guideline (2022)

NSTDA AI Ethics Guideline

Thailand

RAI-TH-NA-NSTAIET-2022
Effective: March 1, 2022
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementSafety, Testing, and Evaluation
Export PDF

The NSTDA AI Ethics Guideline is a non‑binding national framework issued in 2022 to orient research, development and deployment of AI in Thailand. It emphasises trustworthy AI through governance, privacy, transparency, fairness and safety across the AI lifecycle and aligns Thailand’s public research agencies with international ethics standards.

Summary

The NSTDA AI Ethics Guideline (issued in 2022) is a soft‑law framework created under the auspices of the National Science and Technology Development Agency (NSTDA) and related national actors to provide concrete ethical principles and practical recommendations for research institutions, developers, service providers and government agencies in Thailand. The Guideline situates AI development within Thailand’s National AI Strategy and National AI Action Plan, emphasising five core objectives: promote socially beneficial AI, protect fundamental rights, ensure safety and robustness, secure privacy and data protection, and operate with transparency and accountability.

The document is descriptive and prescriptive rather than regulatory: it sets principles, suggested processes, and implementation tools rather than new statutory obligations or criminal penalties. Key normative areas covered include governance and institutional roles (institutional oversight, governance bodies, cross‑agency coordination), risk assessment and lifecycle risk management (early risk screening, categorisation of impacts), testing, validation and evaluation practices (benchmarks, reproducibility, safety testing), data governance and privacy (PDPA compliance, provenance, consent practices), fairness and non‑discrimination (bias detection, representative data, impact mitigation), explainability and transparency (meaningful disclosure to affected individuals and decision‑makers), cybersecurity and model integrity (access controls, monitoring, patching), documentation and recordkeeping (model cards, data sheets, audit trails), and oversight and human‑in‑the‑loop requirements for high‑impact uses.

The Guideline explicitly flags several high‑risk application domains—healthcare, finance, public administration and law enforcement—and recommends heightened procedural safeguards and external review for those domains. It also encourages alignment with international instruments such as the UNESCO Recommendation on the Ethics of Artificial Intelligence, OECD AI principles and relevant sectoral standards. Because the Guideline is non‑binding, enforcement primarily occurs through institutional policy adoption, procurement conditions, funding terms, and sectoral regulators (for example, health regulators or financial supervisors) where statutory rules apply.

Practically, the Guideline lists a set of operational requirements and tools: governance structures (AI ethics committees, designated data protection officers/AI stewards), mandatory risk assessments for project approval, testing and evaluation protocols, minimum documentation standards (model cards, data provenance logs), disclosure templates for users, and incident reporting processes. It also recommends capacity‑building, public consultation, and iterative review of the Guideline itself. The NSTDA’s role is described as facilitator, standard‑setter for publicly funded research, and provider of technical guidance and tooling; regulatory enforcement remains with line ministries and sectoral regulators where existing law applies, notably the Personal Data Protection Act (PDPA).

In sum, the NSTDA AI Ethics Guideline functions as a national, research‑agency driven framework to operationalise ethical AI principles across Thailand’s research, innovation and public sectors, encouraging adoption through funding, procurement and collaborative governance rather than through new statutory sanctions.

Full article

Read full text ↗

Overview

The NSTDA AI Ethics Guideline is a national, agency‑led ethics framework published in 2022 to guide AI research, development and deployment across Thailand’s public research institutions, government projects and industry partnerships. The Guideline sets out ethical principles and operational recommendations covering governance, risk management, transparency, privacy and safety. It is intended as a practical, implementable document that complements Thailand’s National AI Strategy and related national initiatives: key official texts and supporting materials are hosted by NSTDA and by the Ministry of Digital Economy and Society (DES). For the full national principles document widely used in Thailand see the published national guideline (Digital Thailand - AI Ethics Guideline) available as a public PDF: Digital Thailand - AI Ethics Principle & Guideline (PDF), and NSTDA materials discussing implementation and the National AI Action Plan: NSTDA – National AI Action Plan (2022–2027). The Guideline is non‑binding and designed to be applied through internal governance, funding terms and sectoral policy rather than as a stand‑alone statutory instrument.

Definitions

The Guideline defines key terms to ensure shared understanding across stakeholders. "AI system" is used to mean software and/or hardware systems that perform tasks commonly associated with human intelligence by processing data via algorithms, machine learning models or other automated reasoning techniques. "Developer" and "provider" refer to entities that design, train, deploy or deliver AI systems; "user" refers to organisations or individuals operating AI systems in production; "affected person" denotes individuals or groups materially impacted by AI decisions. The document also defines ‘‘risk’’ in lifecycle terms—likelihood and severity of harm—distinguishing between operational safety risks, rights‑based harms (privacy, discrimination), and societal risks (disinformation, systemic bias). Finally, it articulates procedural definitions: "model card" (summary documentation for model behaviour), "data sheet" (dataset provenance and characteristics), and "human oversight" (roles and checkpoints ensuring non‑automated final authority where required).

Governance and Institutional Framework

The Guideline prescribes a multi‑layered governance approach: internal governance (organisational AI oversight boards and AI ethics committees), technical governance (standards for testing, documentation and monitoring), and national coordination (cross‑agency working groups). It positions NSTDA as a convenor and capacity provider that issues technical guidance and templates, while line ministries retain sectoral regulatory authority. Specific governance measures recommended include the appointment of responsible officers (AI stewards or ethics officers), mandated project approval gates tied to risk assessments, requirements for external review of high‑impact systems, and mechanisms for transparent procurement that include ethics compliance as a term of grant funding. The Guideline also calls for collaboration across NSTDA centres — including NECTEC and other research units — and coordination with the Ministry of Digital Economy and Society and the PDPA enforcement body. For implementation resources and national coordination references see NSTDA’s programme pages and national planning documents: NSTDA and Ministry of Digital Economy and Society.

Key Focus Areas

The Guideline identifies several priority areas for practical attention. Risk management: mandatory risk screening during project inception, tiering of AI systems by potential harm, and routine risk reassessment. Safety, testing and evaluation: requirements for pre‑deployment testing, benchmarking, stress testing and continuous monitoring, plus protocols for model retraining and rollback. Transparency and disclosure: policies for meaningful user disclosure, model cards, and documentation for decisions affecting individuals. Data protection and privacy: explicit alignment with Thailand’s Personal Data Protection Act (PDPA), requirements for data minimisation, anonymisation where feasible, provenance records and consent management standards. Fairness and non‑discrimination: mandated bias testing, representative datasets, impact mitigation measures and mechanisms for stakeholder engagement with vulnerable groups. Cybersecurity and model security: access controls, provenance verification, adversarial robustness testing and incident response procedures. Accountability and documentation: enforced recordkeeping, audit trails, and obligations for tracing responsibility through procurement chains. The Guideline also emphasises capacity building—training programmes for engineers, ethics awareness for managers, and public engagement to build trust.

Implementation Framework

The Guideline provides an operational roadmap rather than a single enforcement pathway. It recommends a staged implementation model: (1) Adoption — organisations adopt the Guideline via internal policies, procurement and grant conditions; (2) Integration — embed risk management and documentation into project lifecycles; (3) Oversight — establish ethics committees and reporting mechanisms; (4) External validation — seek third‑party evaluation for high‑risk systems; (5) Continuous improvement — periodic review and public reporting. NSTDA is recommended to publish templates (model cards, risk assessment checklists, test plans), run sandboxes for high‑risk systems and offer technical assistance. Procurement and funding are key levers: NSTDA may require conformity with Guideline checkpoints as a condition for research grants and infrastructure access. The framework also recommends interoperable technical standards and alignment with international benchmarks to facilitate cross‑border research and procurement.

Monitoring and Evaluation

Monitoring focuses on process and outcome metrics: compliance with required documentation, results of independent testing, reported incidents and mitigation actions, and periodic audits of deployed systems. The Guideline encourages public reporting of high‑level compliance indicators and the creation of an incident registry for serious harms. Evaluation is both formative (to improve the Guideline and tooling) and summative (to assess how effectively harms are prevented). NSTDA and partner agencies are advised to adopt metrics capturing model performance drift, privacy incidents, appeal rates, and stakeholder complaints. The Guideline also recommends periodic external evaluations and stakeholder consultations to ensure the guidance remains responsive to technological change.

Penalties, Liability, and Appeals

Because the Guideline is non‑binding, it does not itself create statutory penalties. Instead it creates conditional obligations through funding, procurement and institutional policy: failure to meet Guideline requirements may result in administrative consequences (suspension of funding, project de‑listing, contract remedies) and escalation to sectoral regulators where applicable. The Guideline delineates liability exposure under existing legal regimes (for example PDPA breaches, consumer protection law, professional negligence or sectoral licencing rules). It recommends establishing internal appeal procedures and external review pathways for affected individuals, and encourages organisations to maintain remediation and redress processes compatible with national law and practice.

Relationship to Other Instruments

The Guideline is explicitly complementary to existing national instruments. It references the Personal Data Protection Act (PDPA) as the primary legal instrument for privacy compliance and maps Guideline obligations to PDPA requirements. It is intended to operate in concert with the National AI Strategy and the National AI Action Plan (2022–2027) which set broader policy goals, and with sectoral statutes (health, finance, transport) that may impose additional technical or licencing obligations. The Guideline also draws on international instruments—OECD AI principles, ISO/IEC standards and the UNESCO Recommendation—so organisations implementing the Guideline can better align with global best practice while satisfying local law.

International Alignment

International alignment is a core design principle: the Guideline recommends adopting internationally recognised ethical principles and technical standards to facilitate interoperability and foreign collaboration. It cites UNESCO’s Recommendation on the Ethics of Artificial Intelligence and OECD AI principles as touchstones, and recommends mapping local evaluation and conformity processes to international norms where possible. This alignment aims to reduce friction for cross‑border research, support Thai participation in international standard setting, and increase the exportability of Thai AI solutions while safeguarding rights. Relevant international resources include UNESCO AI ethics materials and OECD/AIO initiatives available publicly: UNESCO on AI Ethics and international policy analysis such as the Asia Society regional review of AI governance and ethical guidance Asia Society – Thailand AI context.

Implementation Timeline

PhaseActivitiesIndicative timing
AdoptInstitutional adoption, appoint AI steward, adopt documentation templates0–6 months
IntegrateEmbed risk assessments, testing and model cards into project lifecycles6–18 months
AssessIndependent review for high‑risk systems, audits and reporting12–36 months
IterateGuideline review, update templates and toolingEvery 12–24 months

Sources and References

SourceType
Digital Thailand - AI Ethics Principle & Guideline (PDF)Primary Source
NSTDA – National Artificial Intelligence Action Plan for Thailand (2022–2027)Primary Source (Agency material)

Requirements for a company

What an organisation has to do under Thailand - AI Ethics Guideline (2022), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

12
  • Ensure full compliance with Thailand’s Personal Data Protection Act (PDPA).Developers, providers, and users of AI systems processing personal data.
  • Include ethics compliance as a term in grant funding and procurement.Organizations providing grant funding or procuring AI systems.
  • Appoint an AI steward or ethics officer.Organizations adopting the Guideline.
  • Establish project approval gates linked to risk assessments.Organizations developing or deploying AI systems.
  • Conduct mandatory risk screening at project inception.Developers and providers of AI systems.
  • Routinely reassess risks throughout the AI system lifecycle.Developers and providers of AI systems.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

2
  • Provide training programs for engineers and ethics awareness for managers.Organizations developing or deploying AI systems.
  • Establish an incident registry for serious harms caused by AI systems.Organizations developing or deploying AI systems.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Thailand - AI Ethics Guideline (2022), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Developers, providers, and users of AI systems processing personal data.Ensure full compliance with Thailand’s Personal Data Protection Act (PDPA).
explicit alignment with Thailand’s Personal Data Protection Act (PDPA)
Key Focus AreasCritical
2Organizations providing grant funding or procuring AI systems.Include ethics compliance as a term in grant funding and procurement.
mechanisms for transparent procurement that include ethics compliance as a term of grant funding.
Governance and Institutional FrameworkCritical
3Organizations adopting the Guideline.Appoint an AI steward or ethics officer.
Specific governance measures recommended include the appointment of responsible officers (AI stewards or ethics officers)
Before 2022-09-01Governance and Institutional FrameworkImportant
4Organizations developing or deploying AI systems.Establish project approval gates linked to risk assessments.
mandated project approval gates tied to risk assessments
Before 2023-09-01Governance and Institutional FrameworkImportant
5Developers and providers of AI systems.Conduct mandatory risk screening at project inception.
mandatory risk screening during project inception
Before 2023-09-01Key Focus AreasImportant
6Developers and providers of AI systems.Routinely reassess risks throughout the AI system lifecycle.
routine risk reassessment
Key Focus AreasImportant
7Developers and providers of AI systems.Perform pre-deployment safety and bias testing.
requirements for pre-deployment testing, benchmarking, stress testing
Before placing on marketKey Focus AreasImportant
8Developers and providers of AI systems.Maintain model cards and dataset documentation.
model cards, and documentation for decisions affecting individuals.
Before 2023-09-01Key Focus AreasImportant
9Providers of high-impact AI systems.Seek external review for high-impact AI systems.
requirements for external review of high-impact systems
Before 2025-03-01Governance and Institutional FrameworkImportant
10Developers, providers, and users of AI systems.Maintain enforced recordkeeping and audit trails for AI systems.
enforced recordkeeping, audit trails
Key Focus AreasImportant
11Organizations deploying AI systems that affect individuals.Establish internal appeal procedures for affected individuals.
recommends establishing internal appeal procedures
Penalties, Liability, and AppealsImportant
12Users of AI systems.Implement continuous monitoring for deployed AI systems.
continuous monitoring
Key Focus AreasImportant
13Organizations developing or deploying AI systems.Provide training programs for engineers and ethics awareness for managers.
training programmes for engineers, ethics awareness for managers
Key Focus AreasRecommended
14Organizations developing or deploying AI systems.Establish an incident registry for serious harms caused by AI systems.
creation of an incident registry for serious harms.
Monitoring and EvaluationRecommended

© Regulations.AI · updated on 13-Jun-2026