New regulations seek digital accountability

Thailand is entering a new era of regulations as artificial intelligence (AI), digital platforms and automated transactions become more deeply embedded in business.

The country is drafting several new laws and rules to facilitate digital transactions and step up oversight of the digital landscape, from startup promotion to AI.

Regulation is moving from supervising business documents and market behaviour to examining how the technology actually works.

Businesses will be expected to understand, explain and take responsibility for what their technology does. For companies, compliance is moving beyond policies and contracts towards the design and operation of their digital systems.

Why do trade competition rules need to be changed?

The Trade Competition Commission of Thailand (TCCT) is tightening oversight of ride-hailing and on-demand delivery platforms because existing guidelines, introduced around 2020, no longer reflect how the market operates.

Warawan Chitaroon, a TCCT commissioner, said platforms have changed significantly over the past five years. Many have expanded from individual services into super apps, covering ride-hailing, food delivery and other services.

Algorithms now play a much greater role in determining prices, allocating jobs and managing incentives, which changes what regulators need to examine, she said.

The TCCT is concerned about safety and traceability, including whether platforms properly verify drivers’ backgrounds, public transport licences and vehicle registrations. Algorithms are another vital issue, said Ms Warawan.

The commission is examining “dark patterns” that could disadvantage drivers. One example cited by officials involves a driver approaching a bonus target, only for the number of jobs offered to decline before the target is reached, noted the TCCT.

Pricing algorithms are also under scrutiny, including how prices are calculated during periods of high demand.

Detecting such practices will not be easy, said Ms Warawan, adding regulators will need technical expertise, access to platform data and properly documented evidence from affected parties.

The TCCT rejects the argument that platforms are simply neutral intermediaries. Because they can control pricing, job allocation, payments and refund conditions, the regulator believes the platforms should bear responsibility for how their marketplaces operate.

“This new draft will not add heavy costs for platforms, focusing instead on monitoring and proof of transparency,” she said.

Piyapat Tubin, competition and antitrust specialist at Kudun and Partners law firm, said traditional measures such as revenue and market share are no longer adequate to assess power in the digital market.

She described a “pyramid dominance” structure, with operating systems such as iOS and Android forming a gateway to digital systems. E-commerce, ride-hailing, online travel and streaming services operate on top of this layer.

As a result, regulators need to consider control over data, network effects and access to digital systems alongside conventional measures such as market share, said Ms Piyapat.

She said she expects a change in the trade competition law involving Section 4 (4), which states the trade competition law will not be applied to sectors with their own regulators. Removing the provision means more sectors would be governed under the general competition law framework.

The Trade Competition Act should serve as the main horizontal competition law across industries, while avoiding unnecessary regulatory overlap, said Ms Piyapat.

What are the implications of the AI Act and related frameworks?

Thailand is drafting an AI Act to encourage development and adoption while establishing rules covering risks, ethics, consumer protection and accountability.

Dhiraphol Suwanprateep, adjunct law lecturer at Bangkok University, told the Bangkok Post the common direction behind the new digital rules is greater digital accountability.

He said Thailand is moving towards a risk-based legal framework for AI. Higher- risk applications are likely to face stronger requirements for human oversight, transparency, documentation and accountability, Mr Dhiraphol said.

The priority for companies is to understand where AI is being used in the organisation, he noted. In many companies, AI may already be used in recruitment, customer service, marketing, fraud detection, credit assessment or internal decision-making without being centrally monitored.

If regulation is going to depend on risk, businesses need to know what AI systems they have, what they are being used for and whether they make or support decisions affecting individuals, he said.

Companies should identify these systems, assess their risks and determine where human oversight is needed, said Mr Dhiraphol.

Using AI supplied by an outside vendor does not necessarily transfer legal responsibility to that vendor. Contracts with AI providers should therefore address data use, confidentiality, security, intellectual property, incident reporting, audit rights and liability, he noted.

AI governance is moving from “Can we use AI?” to “Can we explain, control and take responsibility for how we use AI?” said Mr Dhiraphol.

What are the trends for digital platform service and electronic transaction regulations?

Digital platform regulation is moving beyond basic notification and reporting towards more active supervision of what happens on platforms.

“The direction is towards greater merchant and product verification, stronger complaint and notice-and-takedown mechanisms, and additional responsibilities for platforms regarded as presenting higher risks,” he said.

For platform operators, the days of simply saying “we only provide the platform” are becoming more difficult, noted Mr Dhiraphol.

“Regulators increasingly expect platforms to know who is operating on their systems, what is being sold or offered, and how complaints and illegal or unsafe products are dealt with,” he said.

This means operators need stronger merchant verification, product screening and complaint-handling systems, as well as records showing what action they took, said Mr Dhiraphol.

Changes to the Electronic Transactions Act could reshape how companies handle digital transactions. The proposed overhaul covers electronic signatures, digital identity, timestamps, automated contracting and electronic trade documents.

He said businesses should not view amendments as simply another step towards replacing paper documents with PDFs. The more important development is the possibility of end-to-end digital transactions, where identification, contracting, signature, authentication, performance and record-keeping can all take place electronically.

Businesses should therefore look at the evidence their systems produce, said Mr Dhiraphol. If a transaction is disputed several years later, can the company establish who entered into it, when it occurred, how that person was authenticated, what version of the document was agreed and whether it was subsequently altered.

Electronic signature procedures, authentication, timestamps, audit trails, access controls and document retention should be reviewed, he noted, especially if the use of reliable or certified electronic systems receives stronger evidentiary recognition.

In addition to whether an electronic process is convenient, businesses should consider whether it will produce evidence that can be relied upon in court or before a regulator, said Mr Dhiraphol.

Automated contracting raises another question. As systems and AI agents become capable of entering into transactions with limited human involvement, companies will need internal rules determining who can authorise a machine to bind the company, the limits within which the system can operate, and what happens when it enters into an unintended transaction, he noted.

For consumers, the move towards fully digital transactions creates convenience, but also raises questions about unauthorised transactions, identity theft, account takeover and proof of consent.

If a consumer says “I did not authorise this transaction”, the reliability of the authentication process, electronic signature, timestamp and audit trail may determine the dispute, said Mr Dhiraphol.

What should businesses do now?

Companies do not need to wait until every regulation is finalised before preparing. They can start by mapping their digital regulatory footprint: where AI and algorithms are being used, which automated decisions affect people, which technology providers they depend on and what evidence is available if a decision is challenged.

Contracts with AI, cloud and other technology providers should also be reviewed, particularly provisions covering access to information, audit rights, incident reporting, liability and cooperation with regulators, he said.

Businesses should preserve logs, system versions, decision records and audit trails because they may need to reconstruct what an AI system or algorithm did at a particular point in time, said Mr Dhiraphol.

Finally, responsibility inside the organisation needs to be clear as these issues cut across legal, compliance, IT, cybersecurity, data protection and product teams.

Legal teams may need to become involved much earlier in technology development. If the legal risk is embedded in an algorithm, an automated decision or the design of a platform, reviewing the terms and conditions shortly before launch will no longer be enough, he noted.

The common thread running through these changes is digital accountability.

“The regulatory focus is moving from what businesses say in their policies and contracts to what their technology actually does,” Mr Dhiraphol said.

For businesses, that means moving from compliance on paper to compliance by design, he said.

Leave a Reply

Your email address will not be published. Required fields are marked *