What the NBTC Telecom AI Guidelines Cover
The guidelines apply to holders of telecom business licenses, but only when those licensees use AI to deliver their licensed services. In other words, the rules follow the licence, not the technology. A telecom operator that uses AI for network optimisation, fraud detection, customer chatbots, or personalised offers falls squarely within scope.
Companies without a telecom licence are not directly bound. However, many will feel the effect indirectly. Cloud vendors, model developers, and outsourced service providers that supply AI tools to licensees will need to meet the same standards through their contracts. Consequently, the telecom AI guidelines in Thailand reach well beyond the licensed operators themselves.
Who Must Pay Attention
Three groups should study the guidelines closely. First, licensed telecom operators bear primary responsibility for compliance. Second, technology vendors that sell or integrate AI for those operators will be held to the standards through service agreements. Third, investors evaluating a telecom target should treat AI governance as a due-diligence item.
The Six Core Principles for Responsible AI
At the heart of the framework sit six principles that licensees should follow whenever they deploy AI. Together, these principles translate broad ethical goals into operational expectations.
| Principle | What It Requires in Practice |
|---|---|
| Lawfulness and ethics | AI must respect privacy, dignity, and human rights. Input and output filtering should block false information, illegal activity, or content that harms people. |
| Fairness | Training data should be diverse, representative, and reliably sourced. Regular bias testing is recommended. |
| Security and privacy | Cybersecurity measures should track international standards such as ISO/IEC 27090. Personal data should be protected through encryption, anonymisation, and access controls. |
| Transparency | Licensees should explain how AI works and disclose its use to consumers in proportion to the risk involved. |
| Accountability | Responsibility for AI outcomes must be clearly assigned. Complaint and inquiry channels should stay open to consumers. |
| Reliability | AI should deliver accurate, consistent results. Robustness testing helps confirm stable operation in unexpected scenarios. |
Governance Across the AI Lifecycle
The NBTC does not stop at principles. Instead, it prescribes controls across six stages of the AI lifecycle, from first design to secure retirement. This lifecycle approach mirrors global best practice and pushes operators to build governance in from the start.
The six stages are solution design, data preparation, model building, deployment, monitoring and evaluation, and decommissioning. Within these stages, licensees are expected to apply the following controls:
- Predevelopment risk analysis before a project begins
- Due diligence on third-party AI providers
- Data quality and traceability standards
- Reliability and fairness testing before launch
- Human oversight mechanisms during operation
- Secure retirement processes that meet international standards
Above all, licensees should assign clear roles at both the policy and operational levels. A governance committee, working group, or designated officer should own AI strategy, while accountability should extend to outsourced providers named in service contracts.
Consumer Disclosure and Staff AI Literacy
The guidelines place strong emphasis on the customer relationship. When consumers interact with a chatbot or voicebot, the operator should tell them clearly that they are dealing with AI. Likewise, when an AI-driven recommendation may influence a purchase or service decision, the operator should flag it and offer a route to a human agent.
Internally, the NBTC expects operators to raise AI literacy at every level. Non-technical staff should understand how the company uses AI and where the risks lie. Meanwhile, technical teams and external developers should receive training on company policy, AI ethics, and the relevant laws.
How the Telecom AI Guidelines in Thailand Fit the Wider Legal Framework
These guidelines do not operate in isolation. Rather, they sit alongside a growing stack of Thai digital law, and licensees must read them together with existing statutes. In particular, the framework interacts with the following laws:
- The Personal Data Protection Act (PDPA), which governs how operators collect and process customer data used to train or run AI
- The Cybersecurity Act, which sets baseline security duties for critical infrastructure
- The Computer Crime Act, which addresses unlawful content and system misuse
- The NBTC’s own consumer-protection notification on privacy and telecom user rights
Looking ahead, the Electronic Transactions Development Agency (ETDA) is drafting dedicated AI governance legislation. That effort ties directly into Thailand’s draft AI Act, which will set economy-wide rules for higher-risk systems. When that law arrives, today’s voluntary guidelines are likely to foreshadow the mandatory standard. For that reason, early adopters gain a real advantage.
Practical Steps for Telecom and Technology Businesses
Foreign operators and their AI vendors should not wait for enforcement. Instead, they can act now to close the gap between current practice and the regulator’s expectations. We recommend the following steps:
- Map your AI systems. Identify every AI use case that touches a licensed telecom service.
- Stand up a governance structure. Appoint an owner and define policies at both strategic and operational levels.
- Review vendor contracts. Push the six principles and lifecycle duties down to third-party AI providers in writing.
- Build consumer disclosures. Add clear AI notices and a human-agent option to chatbots and recommendation tools.
- Train your people. Run AI-literacy programmes for both technical and non-technical staff.
For any merger or acquisition in the telecom sector, buyers should now assess a target’s AI governance maturity and data-handling practices as part of due diligence. A weak AI framework can quickly become a post-closing liability.
Frequently Asked Questions
Are the telecom AI guidelines in Thailand legally binding?
Which companies fall within the scope of the guidelines?
What are the six core AI principles the NBTC expects?
How do the guidelines relate to the PDPA and other Thai laws?
What should telecom operators do first to comply?
Preparing Your Business for AI Regulation in Thailand?
Lex Bangkok advises telecom operators, technology vendors, and international investors on AI governance, data protection, and regulatory compliance across Thailand’s fast-evolving digital economy. Our team can benchmark your operations against the NBTC framework and build a compliance structure that anticipates the coming AI law.
Schedule a Consultation