Using AI and Software in Thailand: Your Legal Rights and Obligations

Every business in Thailand now uses artificial intelligence and software, whether to draft documents, serve customers, analyse data, or build products. The legal questions that follow are practical and immediate: who owns what the AI produces, whether you may feed your data or someone else's content into it, what happens to your confidential information, and who pays when the technology gets something wrong.

โดย ศาสตราจารย์ เดชอุดม ไกรฤทธิ์, ฌร ไกรฤทธิ์·6 กรกฎาคม 2569·ใช้เวลาอ่าน 15 นาที

This guide answers those questions under Thai law as it stands in mid-2026. One point frames everything below: Thailand does not yet have a comprehensive AI statute in force. A draft AI Act is advancing, and the Electronic Transactions Development Agency (ETDA) released a revised draft for public consultation on 2 July 2026, but until it is enacted, the use of AI and software is governed by the laws Thailand already has: the Copyright Act, the Patent Act, the Trade Secrets Act, the Personal Data Protection Act, the Civil and Commercial Code, and others.

The bottom line: what you can do today

For the reader who wants the short version:

  • Can we use tools like ChatGPT or Copilot for work? Yes, with controls. There is no law banning business use of AI. The risks are about data, confidentiality, and who is responsible for the output, all covered below.
  • Can we use AI to draft contracts and documents? Yes, but a human must check the result and remains responsible for it. Never assume the output is correct, and for court documents, special rules apply to lawyers (see section 7).
  • Can we put customer or personal data into AI? Only with a lawful basis under the data protection law and a proper agreement with the AI provider. Do not put personal or confidential data into free, consumer-grade tools.
  • Who owns what the AI produces? Not automatically you. Purely AI-made output may not be protected at all, and work made by staff or contractors may belong to them by default. If you want to own it, put it in the contract.

Each point is explained in full below.

Contents

  1. The state of the law: no AI Act yet
  2. Who owns what AI produces
  3. Feeding content into AI: the training and prompting problem
  4. Your rights in software
  5. Protecting confidential information and trade secrets
  6. Data protection when you use AI
  7. Who is liable when AI gets it wrong
  8. Patents and AI-made inventions
  9. The coming AI Act: what to prepare for
  10. A practical checklist

1. The state of the law: no AI Act yet

A good deal of online commentary gets this wrong, so it is worth being clear: as of July 2026 there is no comprehensive Artificial Intelligence Act in force in Thailand. The unified draft Act on Artificial Intelligence was released by ETDA in a revised form on 2 July 2026 for a short public consultation. Earlier twin drafts, one promotional and one modelled on the European Union's AI Act, are being consolidated into it. None of these is law yet.

What that means in practice is that AI and software are governed today by Thailand's existing legal framework, applied to a new technology. That framework covers more than businesses often assume, and the sections below set out the parts that matter most.

2. Who owns what AI produces

The starting point is the Copyright Act B.E. 2537 (1994). (Thai statutes carry a Buddhist Era year; subtract 543 for the Gregorian year shown in brackets.) The Act protects an original work created by an "author," defined as the person who makes or creates the work. Thai law has no case squarely on artificial intelligence, but the better view, shared across the profession, is that copyright requires a human author. A work generated purely by a generative-AI tool, with no human creative contribution, most likely attracts no copyright, which means you cannot safely treat it as your protected, exclusive property. This aligns with the position taken by the United States Copyright Office, which in its 2025 report on AI confirmed that prompts alone do not make a person the author of an AI output.

Where a person genuinely directs and shapes the work, the picture changes. If a human contributes original expression, by meaningfully selecting, arranging, and editing the material so that human creativity is perceptible in the result, copyright may subsist and that person is the first owner. How much human input is enough is unsettled in Thailand, so anyone relying on AI-assisted material should keep a record of the human creative steps taken.

Once a protected work exists, ownership follows the ordinary rules, and one of them regularly catches businesses out. Under the Copyright Act, a work made by an employee in the course of employment belongs to the employee, not the employer, unless the parties agree otherwise in writing. This is the opposite of the "work made for hire" default in some other countries. A work made under a commission (a hire-of-work arrangement) belongs to the commissioner unless otherwise agreed. The lesson is simple: if you want to own what your staff or contractors create with AI, put it in the contract.

3. Feeding content into AI: the training and prompting problem

Putting someone else's copyrighted material into an AI system, to train a model or as part of a prompt, generally involves reproducing that material, and reproduction without the owner's permission is, on its face, an infringement. In short, if you train or fine-tune a model on third-party content in Thailand, assume you need a licence.

Thailand is stricter here than several neighbours. It has no text-and-data-mining exception of the kind found in Singapore or Japan, and no broad "fair use" doctrine of the United States kind. The Copyright Act permits use only where it both avoids conflict with the owner's normal exploitation of the work and falls within a specific listed purpose, such as non-profit research, personal use, or criticism with acknowledgement. Commercial-scale training on copyrighted material is very unlikely to qualify.

One further point: "trained lawfully abroad" is not a safe harbour. Thai copyright law can still apply where the model is deployed or commercialised in the Thai market, so a foreign training process that relied on another country's data-mining exception does not automatically protect you here.

4. Your rights in software

Software is well protected in Thailand. The Copyright Act defines a "computer program" and protects it in the same way as a literary work. Protection arises automatically on creation, with no need to register, although the Department of Intellectual Property operates a voluntary recording system that can help with proof. As with all copyright, it is the expression, not the underlying idea or function, that is protected.

Most software reaches users through a licence, and Thai law enforces licences through ordinary contract principles together with the Electronic Transactions Act B.E. 2544 (2001), under which electronic acceptance is generally valid. Click-through licences and end-user agreements are usually workable, though there is little Thai case law testing how the user's assent is captured, so clear acceptance mechanics are worth getting right. Open-source licences such as the GPL or MIT operate on the same footing: they are copyright licences whose conditions bind because using the software outside those conditions becomes infringement. Their enforceability has not been tested in a Thai court, but in principle they should hold.

One area deserves particular care: the "as is," warranty-disclaimer, and limitation-of-liability clauses that appear in almost every software agreement. These are not automatically enforceable in Thailand. The Unfair Contract Terms Act B.E. 2540 (1997) allows a court to enforce such clauses only so far as they are fair and reasonable in the circumstances, and it prohibits any advance term that excludes liability for death, bodily injury, or harm to health. A blanket cap on liability may be read down by a court, especially in consumer or standard-form contracts. Vendors should draft these clauses to be defensible, and customers should not assume a supplier's disclaimer is the last word.

5. Protecting confidential information and trade secrets

The Trade Secrets Act B.E. 2545 (2002) protects commercial information that is not generally known, that has commercial value because it is secret, and that the owner keeps secret through reasonable measures. Protection is automatic, needs no registration, and lasts as long as the secrecy does.

This is where AI creates a real and underappreciated risk. If an employee pastes confidential business information, a client list, pricing model, source code, or draft strategy, into a public, consumer-grade AI tool whose terms allow the provider to retain or train on what is submitted, two things can go wrong at once. The information may cease to be "secret," and the business may be shown not to have taken the "reasonable measures" the Act requires. Either failure can forfeit trade-secret protection permanently.

The single biggest everyday exposure for most businesses is staff using free AI tools. The fix is inexpensive: a written policy on what may and may not be entered into AI, the use of enterprise AI deployments with contractual "no training, no retention" terms, and access limited to those who need it. These are also the very "reasonable measures" the Trade Secrets Act rewards.

6. Data protection when you use AI

The Personal Data Protection Act B.E. 2562 (2019), or PDPA, is fully in force and is the single most important law for most businesses using AI, because AI runs on data and much of that data is personal. The duties in this section come from the PDPA, which already binds you, not from any AI-specific law.

Before personal or customer data goes into an AI system, a business needs a lawful basis for that use. Consent is one basis, but "blanket" consent buried in old terms is unlikely to cover a new AI use; other bases such as legitimate interest require a documented balancing exercise. Special care applies to sensitive data, including health and biometric information, which as a rule needs explicit consent. The business must also have given proper notice of what it collects and why, and must re-notify individuals if it starts using their data for a new AI purpose.

Two features of the PDPA regularly surprise businesses. It contains no general right against solely automated decisions equivalent to the European rule, so protections around AI-driven decisions currently rest on guidance rather than a hard statutory right. And cross-border transfer remains difficult: the Act's "adequate destination" route has never become usable, because the regulator has not published a list of adequate countries, so transfers abroad, including to a foreign AI provider's servers, must rely on approved safeguards such as standard contractual clauses or binding corporate rules. The frameworks for binding corporate rules and a new data-protection certification, or Trust Mark, both became operational during 2025 and 2026, giving businesses more workable options than before.

Enforcement is now real. The Personal Data Protection Committee runs a proactive inspection unit, informally known as "Eagle Eye," that investigates without waiting for a complaint. In late 2025 it ordered a global iris-scanning operation to stop and to delete the biometric data of well over a million people. A wave of fines in 2025 reached into the millions of baht and, notably, fell on data processors as well as controllers, with the absence of a data protection officer a recurring aggravating factor. The Committee has also issued a draft guideline specifically on personal data protection in the development and use of AI, which, although still in draft, shows the standard it expects.

Before feeding personal data into any AI system, a business should therefore: fix and record a lawful basis; screen for sensitive data; give or update the required notice; assess the risk where the use is significant; sign an agreement that bars the vendor from using the data to train its own models; complete the cross-border check; issue a staff policy on public AI tools; and be ready to handle individuals' requests and to report a breach without undue delay and, where feasible, within seventy-two hours.

7. Who is liable when AI gets it wrong

When an AI system produces a harmful or wrong result, Thai law has no dedicated AI-liability statute yet, so responsibility is worked out through existing routes.

The primary route is tort under the Civil and Commercial Code (section 420): a person who, wilfully or negligently and unlawfully, causes damage to another must compensate for it. A business that relies carelessly on an AI output, or a developer whose system is negligently designed, can be liable, though proving causation against an opaque system is difficult. An employer is jointly liable (section 425) for an employee's wrongdoing in the course of employment, so a firm can be answerable for its staff's negligent use of AI.

Two further regimes may apply, and both are unsettled at their edges. The Code's provision on liability for dangerous things driven by mechanical power (section 437) has been suggested as a route for physically hazardous AI such as autonomous vehicles, but its extension to purely intangible software is untested. The Product Liability Act B.E. 2551 (2008) imposes strict, joint liability on business operators for unsafe products, and a "product" is a manufactured or imported movable good. Tangible AI, such as a robot, drone, or AI-enabled medical device, may well fall within it; pure software or a cloud AI service probably does not, defaulting back to general tort. No Thai court has yet resolved this.

Contract allocates liability too, but only within limits. As noted above, a supplier's disclaimer or liability cap is enforceable only so far as fair and reasonable, and cannot exclude liability for personal injury.

Finally, professionals remain personally responsible for their use of AI. This is now explicit for lawyers: the Civil Court has issued directions on the use of AI in preparing court documents that require the accuracy of AI-assisted work to be verified, the use of AI to be disclosed, and the filing lawyer to take responsibility for it. A doctor who relies on an AI tool is judged by the ordinary standard of care and professional-conduct rules; delegating a judgment to software does not transfer the liability for it.

8. Patents and AI-made inventions

Two questions arise. First, can an AI be named as the inventor of a patent? No Thai authority has decided the point, but the better view is that Thailand, like almost every other country to have considered it, would require the inventor to be a natural person, because the Patent Act frames the inventor as someone with the right to be named and, for employee inventions, rights to remuneration.

Second, are AI-related and software inventions patentable at all? The Patent Act excludes computer programs "as such," together with scientific and mathematical rules, from patent protection. But the Department of Intellectual Property's examination guidelines recognise that an invention which uses software to achieve a genuine technical effect, solving a technical problem, can fall outside that exclusion and be patentable. The outcome turns on how the invention is described and claimed, which is the work of a patent specialist.

9. The coming AI Act: what to prepare for

The draft Act on Artificial Intelligence, in its revised form released for consultation on 2 July 2026, would move Thailand to a risk-based system influenced by the European Union's AI Act. It is expected to prohibit certain uses outright, to designate categories of "high-risk" AI subject to strict controls, and to require some AI to be registered before deployment. Its reach would be extraterritorial, applying to AI that affects people in Thailand even where the provider sits abroad, with foreign providers required to appoint a local representative.

For businesses that use AI, the current draft points to a set of new duties: maintaining a risk-management system aligned with international standards such as ISO/IEC 42001, ensuring meaningful human oversight, keeping operational logs, reporting serious incidents, marking AI-generated content, and notifying individuals where a high-risk system may adversely affect their rights. The current draft also proposes a strict-liability model and administrative fines, though the figures have moved between drafts. Because the text is still changing, and the liability model in particular has shifted, these features are a direction of travel rather than settled law. The sensible course is to build the governance habits, human oversight, record-keeping, vendor due diligence, and incident procedures, that the draft rewards, since they are good practice under today's laws in any event.

10. A practical checklist

For any organisation using AI or software in Thailand:

  • Put ownership of AI-assisted work in writing with employees and contractors; do not rely on the default rules, which may not give the employer what it expects.
  • Assume you need a licence before training or fine-tuning a model on third-party content; there is no data-mining or broad fair-use exception here.
  • Never enter confidential or trade-secret information into a public AI tool; use enterprise tools with "no training, no retention" terms and a written internal policy for staff.
  • Before putting personal data into AI, confirm your lawful basis, screen for sensitive data, update your notices, sign a proper data-processing agreement, and complete the cross-border check.
  • Review supplier "as is" and liability-cap clauses; they may not be enforceable as written.
  • Keep a human in the loop for consequential decisions, verify AI outputs, and record that you did so; professionals remain personally liable.
  • Watch the AI Act as it progresses, and start building risk-management and record-keeping now.

How we can help

Dej-Udom & Associates advises businesses on the legal use of AI and software in Thailand: ownership and licensing of AI-assisted works and software; copyright and trade-secret protection; PDPA compliance for AI, including data-processing agreements and cross-border transfers; allocation of liability in technology contracts; patent strategy for software and AI inventions; and readiness for the coming AI Act.

Disclaimer: This guide is for general information only and does not constitute legal advice. Thai law on artificial intelligence is developing quickly, and several points discussed here are unsettled or subject to draft legislation current at July 2026. For advice on your circumstances, please contact Dej-Udom & Associates.

อ่านต่อ

กฎหมายบริษัทและการควบรวมกิจการทรัพย์สินทางปัญญาการตรวจคนเข้าเมืองและใบอนุญาตทำงาน

What the 14 July Cabinet Means for Employers of Migrant Workers and Foreign Investors in Thailand

If you employ registered Lao, Myanmar, or Vietnamese workers, the 14 July Cabinet moved to save a large part of your workforce. Some 562,068 workers could not complete passports and visas by the 31 July B.E. 2569 (2026) deadline and were weeks from losing status. The Cabinet approved a framework letting every worker registered under the 11 November B.E. 2568 (2025) resolution renew to work until 11 December B.E. 2570 (2027), with renewal applications due by 11 December 2026.

ฌร ไกรฤทธิ์·15 กรกฎาคม 2569
กฎหมายบริษัทและการควบรวมกิจการภาษีอากรทรัพย์สินทางปัญญาการตรวจคนเข้าเมืองและใบอนุญาตทำงานการดำเนินคดีและการระงับข้อพิพาท

What the 30 June Cabinet Means for Property Buyers, Landowners, and Employers in Thailand.

If you are closing a Thai home or condominium purchase right now, start here: the reduced property transfer and mortgage fees lapsed on 30 June B.E. 2569 (2026). As of today, the full 2 percent transfer fee and 1 percent mortgage fee are back, and they stay back until the renewed scheme is published in the Royal Gazette.

ศาสตราจารย์ เดชอุดม ไกรฤทธิ์·1 กรกฎาคม 2569
ทรัพย์สินทางปัญญา

Patent Protection in Thailand: What Businesses Need to Know

Patents in Thailand are governed by the Patent Act B.E. 2522 (1979), as amended up to B.E. 2542 (1999), and administered by the Department of Intellectual Property (DIP). A long-awaited amendment, to streamline examination and join the Hague system for designs, is under parliamentary consideration but is not yet law. The rules below are those currently in force.

ศาสตราจารย์ เดชอุดม ไกรฤทธิ์·22 มิถุนายน 2569