Skip to main content

Telecom AI Guidelines in Thailand: What the 2026 NBTC Rules Require

Thailand has taken its first concrete step toward regulating artificial intelligence in the communications sector. On 2 July 2026, the National Broadcasting and Telecommunications Commission (NBTC) released the Guidelines on the Use of Artificial Intelligence for Telecommunications Services. These telecom AI guidelines in Thailand set out a risk-based framework covering governance, ethics, lifecycle controls, and consumer protection. Although the guidelines are non-binding, they signal how the regulator expects operators to deploy AI responsibly, and they give foreign investors an early template for compliance before mandatory AI legislation arrives. They also continue a clear trend, as Thai institutions from the courts to the telecom regulator move to govern how AI is used. The full framework is published by the NBTC.

What the NBTC Telecom AI Guidelines Cover

The guidelines apply to holders of telecom business licenses, but only when those licensees use AI to deliver their licensed services. In other words, the rules follow the licence, not the technology. A telecom operator that uses AI for network optimisation, fraud detection, customer chatbots, or personalised offers falls squarely within scope.

Companies without a telecom licence are not directly bound. However, many will feel the effect indirectly. Cloud vendors, model developers, and outsourced service providers that supply AI tools to licensees will need to meet the same standards through their contracts. Consequently, the telecom AI guidelines in Thailand reach well beyond the licensed operators themselves.

Who Must Pay Attention

Three groups should study the guidelines closely. First, licensed telecom operators bear primary responsibility for compliance. Second, technology vendors that sell or integrate AI for those operators will be held to the standards through service agreements. Third, investors evaluating a telecom target should treat AI governance as a due-diligence item.

Key Takeaway: The guidelines are non-binding, yet they define the regulator’s expectations. Telecom licensees carry the compliance burden, but third-party AI providers must meet the same standards through contractual obligations. Investors should therefore fold AI governance into telecom due diligence today.

The Six Core Principles for Responsible AI

At the heart of the framework sit six principles that licensees should follow whenever they deploy AI. Together, these principles translate broad ethical goals into operational expectations.

PrincipleWhat It Requires in Practice
Lawfulness and ethicsAI must respect privacy, dignity, and human rights. Input and output filtering should block false information, illegal activity, or content that harms people.
FairnessTraining data should be diverse, representative, and reliably sourced. Regular bias testing is recommended.
Security and privacyCybersecurity measures should track international standards such as ISO/IEC 27090. Personal data should be protected through encryption, anonymisation, and access controls.
TransparencyLicensees should explain how AI works and disclose its use to consumers in proportion to the risk involved.
AccountabilityResponsibility for AI outcomes must be clearly assigned. Complaint and inquiry channels should stay open to consumers.
ReliabilityAI should deliver accurate, consistent results. Robustness testing helps confirm stable operation in unexpected scenarios.

Governance Across the AI Lifecycle

The NBTC does not stop at principles. Instead, it prescribes controls across six stages of the AI lifecycle, from first design to secure retirement. This lifecycle approach mirrors global best practice and pushes operators to build governance in from the start.

The six stages are solution design, data preparation, model building, deployment, monitoring and evaluation, and decommissioning. Within these stages, licensees are expected to apply the following controls:

  • Predevelopment risk analysis before a project begins
  • Due diligence on third-party AI providers
  • Data quality and traceability standards
  • Reliability and fairness testing before launch
  • Human oversight mechanisms during operation
  • Secure retirement processes that meet international standards

Above all, licensees should assign clear roles at both the policy and operational levels. A governance committee, working group, or designated officer should own AI strategy, while accountability should extend to outsourced providers named in service contracts.

Key Takeaway: Governance must run through the entire AI lifecycle, not just the launch. Operators that document risk analysis, vendor due diligence, human oversight, and secure decommissioning will align most closely with the regulator’s expectations.

Consumer Disclosure and Staff AI Literacy

The guidelines place strong emphasis on the customer relationship. When consumers interact with a chatbot or voicebot, the operator should tell them clearly that they are dealing with AI. Likewise, when an AI-driven recommendation may influence a purchase or service decision, the operator should flag it and offer a route to a human agent.

Internally, the NBTC expects operators to raise AI literacy at every level. Non-technical staff should understand how the company uses AI and where the risks lie. Meanwhile, technical teams and external developers should receive training on company policy, AI ethics, and the relevant laws.

How the Telecom AI Guidelines in Thailand Fit the Wider Legal Framework

These guidelines do not operate in isolation. Rather, they sit alongside a growing stack of Thai digital law, and licensees must read them together with existing statutes. In particular, the framework interacts with the following laws:

  • The Personal Data Protection Act (PDPA), which governs how operators collect and process customer data used to train or run AI
  • The Cybersecurity Act, which sets baseline security duties for critical infrastructure
  • The Computer Crime Act, which addresses unlawful content and system misuse
  • The NBTC’s own consumer-protection notification on privacy and telecom user rights

Looking ahead, the Electronic Transactions Development Agency (ETDA) is drafting dedicated AI governance legislation. That effort ties directly into Thailand’s draft AI Act, which will set economy-wide rules for higher-risk systems. When that law arrives, today’s voluntary guidelines are likely to foreshadow the mandatory standard. For that reason, early adopters gain a real advantage.

Key Takeaway: The telecom AI guidelines in Thailand overlap with the PDPA, the Cybersecurity Act, and the Computer Crime Act. Because the ETDA is preparing binding AI legislation, operators that build compliant governance now will adapt far more easily later.

Practical Steps for Telecom and Technology Businesses

Foreign operators and their AI vendors should not wait for enforcement. Instead, they can act now to close the gap between current practice and the regulator’s expectations. We recommend the following steps:

  • Map your AI systems. Identify every AI use case that touches a licensed telecom service.
  • Stand up a governance structure. Appoint an owner and define policies at both strategic and operational levels.
  • Review vendor contracts. Push the six principles and lifecycle duties down to third-party AI providers in writing.
  • Build consumer disclosures. Add clear AI notices and a human-agent option to chatbots and recommendation tools.
  • Train your people. Run AI-literacy programmes for both technical and non-technical staff.

For any merger or acquisition in the telecom sector, buyers should now assess a target’s AI governance maturity and data-handling practices as part of due diligence. A weak AI framework can quickly become a post-closing liability.

Frequently Asked Questions

Are the telecom AI guidelines in Thailand legally binding?
No. The NBTC issued the guidelines as a non-binding, risk-based framework. Even so, they express the regulator’s expectations, and they are widely expected to shape the binding AI legislation the ETDA is currently drafting. Treating them as a compliance baseline is the prudent course.
Which companies fall within the scope of the guidelines?
The guidelines apply to holders of telecom business licenses when they use AI to provide their licensed services. Businesses without a telecom licence are not directly covered, but AI vendors and outsourced providers to licensees will often need to comply through their service agreements.
What are the six core AI principles the NBTC expects?
The framework sets out six principles: lawfulness and ethics, fairness, security and privacy, transparency, accountability, and reliability. Each principle carries practical expectations, such as bias testing, encryption of personal data, clear consumer disclosure, and robustness testing before launch.
How do the guidelines relate to the PDPA and other Thai laws?
They are designed to be read alongside existing law, including the Personal Data Protection Act, the Cybersecurity Act, and the Computer Crime Act. Where AI processes personal data, the PDPA still governs that processing. The guidelines add AI-specific governance on top of these statutes rather than replacing them.
What should telecom operators do first to comply?
Start by mapping every AI use case tied to a licensed service, then appoint a governance owner and set policies at the strategic and operational levels. From there, update vendor contracts, add consumer AI disclosures, and roll out staff AI-literacy training. Investors should also add AI governance to telecom due diligence.

Preparing Your Business for AI Regulation in Thailand?

Lex Bangkok advises telecom operators, technology vendors, and international investors on AI governance, data protection, and regulatory compliance across Thailand’s fast-evolving digital economy. Our team can benchmark your operations against the NBTC framework and build a compliance structure that anticipates the coming AI law.

Schedule a Consultation