The guidelines do not create a separate AI licensing regime. Their importance lies in showing how the regulator expects existing telecommunications responsibilities to extend into the use of AI.
A telecommunications operator may obtain an AI system from a global vendor, deploy it through a regional platform and rely on an outsourced team to support it. What the operator cannot outsource is its relationship with the Thai regulator. If the system affects a licensed service, the Thai licensee remains the party expected to understand what it does, what data it uses, what risks it creates and who can intervene when something goes wrong.
That is the practical significance of the Guidelines on the Use of Artificial Intelligence for Telecommunications Services, published by the Office of the National Broadcasting and Telecommunications Commission on 2 July 2026.
The guidelines are non-binding. They do not themselves create a new AI licence, standalone legal obligations or a separate penalty regime. Their significance is practical: they show how the regulator expects licensees to understand and manage AI within an existing licensing relationship. Existing licence conditions and obligations under telecommunications, data-protection, cybersecurity and other applicable laws remain binding.
The Scope Is Specific
The guidelines apply to telecommunications licensees using AI to provide licensed telecommunications services. They do not purport to regulate every use of AI within a telecom group.
An AI tool used only to summarize internal meeting notes does not raise the same sector-regulatory questions as a system that adjusts network parameters, detects suspicious traffic, recommends customer packages or communicates through a chatbot. Other laws and internal controls may still apply, but the latter uses sit much closer to the purpose of the guidelines.
The guidelines sit within a wider Thai policy process. The Electronic Transactions Development Agency, or ETDA, is separately developing broader AI legislation. The NBTC document addresses responsible AI use in licensed telecommunications, an example of the sector deployment discussed in Regulating AI Without Illusions.
The Guidelines Begin with How AI Is Actually Used
The guidelines identify uses already relevant to telecommunications: managing network capacity, reducing energy use, predicting equipment failure, improving customer service, detecting fraud, operating chatbots and recommending services.
An AI system that moves network resources in response to demand may improve service, but a wrong decision could affect network availability across an area. A chatbot can answer routine questions, but it can also invent a package or give an inaccurate answer about a customer’s rights. A system that detects suspicious messages may prevent fraud, but overbroad detection could block legitimate communications.
The relevant question is therefore not whether an operator “uses AI.” That description is too general to carry much regulatory meaning. The better questions are what decision the system makes, what happens if it is wrong, how quickly the error can spread and whether a person can detect and correct it.
Six Principles, Applied According to Risk
The guidelines identify six ethical principles that licensees should adapt to the context, risks and effects of the particular AI use. They are not six identical or mandatory controls for every system.
- Consistency with laws, ethics and international standards, including respect for privacy, dignity, freedom and human rights.
- Fairness, including representative data and testing for unreasonable bias or discrimination.
- Security and privacy, including protection against cyber threats, misuse and inappropriate processing of personal or sensitive data.
- Transparency, including understandable disclosure, appropriate explainability, traceability and sufficient records.
- Accountability, including clearly assigned responsibility and accessible channels for questions and complaints.
- Reliability, including acceptable accuracy, consistency and robustness under unexpected conditions.
The operator still has to translate the principles into controls for the actual use. Fairness means something different for a package-recommendation system than for network energy optimization. Customer transparency also differs from the technical records needed to investigate a failure.
Existing Regulatory Responsibility Follows the Technology
The guidelines contemplate governance at both policy and operational levels, with clear internal responsibility, continuing assessment of performance and compliance, and personnel with knowledge appropriate to their roles.
This does not require every operator to create a standalone AI department. A smaller licensee using a customer-service tool may adopt a simpler structure than a mobile operator using AI to adjust network operations. Governance should fit the use and risk.
It should still be clear who approved the system, who understands its limits, who receives reports of failures and who can stop or change its operation. A policy that states ethical principles but leaves those questions unanswered will offer little help during an incident.
The guidelines also call for role-appropriate AI literacy. Employees using AI should understand its risks and proper use. Those developing, operating or maintaining it need deeper knowledge of the operator’s policies, ethical principles and applicable law.
As discussed in Beyond the Thai Partner: Control and Accountability in Thai Telecommunications Licensing, a licensee may rely on foreign technology, cloud infrastructure and specialized suppliers. It nevertheless needs sufficient information, contractual rights and operational authority to answer for the regulated service.
A Vendor Can Supply the System, but Not the Licensee’s Accountability
Most operators will use general-purpose models, telecom-specific applications, cloud services or network-vendor tools. The guidelines therefore treat third-party management as a risk in its own right. A licensee should assess the provider, define contractual responsibilities, address service levels and personal-data processing, set performance measures and obtain enough information to assess suitability for the intended use.
That does not mean a vendor must disclose every line of source code or surrender its intellectual property. The issue is whether the licensee has enough visibility and leverage to discharge its own responsibilities.
Can it understand the system’s intended function and known limitations? Will the vendor provide enough information to investigate an error or material model change? Can the licensee intervene or suspend the relevant function without waiting for an overseas support team?
Calling the vendor an independent technology provider does not solve an operational gap.
Governance Extends Across the AI Lifecycle
The guidelines do not stop at an AI policy or procurement review. They organize governance across six lifecycle stages: solution design, data preparation, model building, deployment, monitoring and evaluation, and decommissioning.
An AI system can change without a formal contract amendment. Network conditions and customer behaviour evolve, suppliers update models and new data is introduced. Performance that appeared acceptable during testing may deteriorate after deployment.
The guidelines emphasize testing, monitoring, records, traceability and the ability to diagnose problems. For higher-impact uses, human oversight should permit intervention or suspension. The official text expressly contemplates an emergency “Kill Switch” during an emergency or serious abnormality.
That is not an instruction to place a red button beside every chatbot. It is a possible control where failure may spread quickly or cannot easily be reversed. The appropriate mechanism may instead be manual review, rollback, traffic isolation, a fallback process or suspension.
Retiring a model is not simply ending a subscription. The operator may need to address retained data, access rights, logs, integration points and residual security risks.
Customers Should Know When AI Is in the Conversation
The guidelines translate transparency into practical expectations. At the start of a chatbot or voicebot conversation, the operator should disclose that it is automated. Where AI recommends a product or package that may influence the customer’s decision, the customer should receive an appropriate warning.
The operator should also provide a reasonable option to reach a human representative, with channels for feedback, complaints and review. These are not minor interface details. They preserve informed choice and help the operator identify errors.
A customer does not need a technical account of model architecture before asking a billing question. The customer should understand that AI is being used, its relevant limitations and how to obtain human assistance.
Risks become materially different when a conversational system is designed to sustain an emotional relationship or is likely to be used by children or vulnerable persons. When the Chatbot Becomes a Friend considers that more specialized issue.
AI Governance Does Not Replace Data Protection or Cybersecurity
Telecommunications AI often depends on sensitive data: location information, call and usage records, customer interactions, device information and network telemetry.
The guidelines sit alongside Thailand’s personal data protection, cybersecurity and computer-crime laws, and NBTC measures protecting users’ personal data, privacy and freedom of communication. They do not replace those obligations.
An operator using customer data to recommend packages still needs to examine purpose and legal basis, transparency, minimization, retention and security. If data moves to an overseas model provider or regional support centre, the transfer and the parties’ roles require separate analysis under the Personal Data Protection Act. Our discussion of cross-border customer data under Thailand’s PDPA explains why the transfer mechanism, controller-processor analysis and actual data flow must be considered together.
Training data may be corrupted, models and interfaces attacked, and sensitive data exposed through outputs or logs. A tool introduced to improve network security may itself create a new route into operational systems.
Not every AI issue becomes a PDPA breach or cybersecurity incident. But AI governance cannot operate as a separate compliance silo. The operator needs one coherent account of the system, data, security controls and regulated service.
What a Proportionate Response Looks Like
The guidelines should not be read as requiring the same control structure for every operator and every use. Their risk-based approach points in the opposite direction.
A proportionate response starts with the operating reality. The licensee identifies AI connected with its services, understands its decisions or outputs, assesses possible effects and chooses controls that match them.
For a low-impact support tool used within service operations, documented approval and ordinary information-security controls may be enough. For a customer-facing chatbot, the focus may be disclosure, answer quality, escalation and complaint handling. For automated fraud detection, the operator may need to test false positives, preserve evidence and provide a route for review. For AI that can alter network configuration, technical validation, continuous monitoring, human intervention and reliable rollback become far more important.
Treating all AI as high risk would produce paperwork without judgment. Treating all AI as merely another software purchase would miss how directly some systems affect a licensed service.
The Practical Point
The NBTC guidelines are non-binding and do not create a new AI licensing regime. They state regulatory expectations within an existing licensing relationship.
A telecom licensee may use AI and rely on outside expertise. It must still understand, supervise and answer for the way AI affects its licensed service.
That is more demanding than having an AI policy, but also more practical. If the regulator asks why a system blocked a communication, offered a different package, exposed personal data or contributed to a service failure, the operator should be able to explain what happened, show how the risk was managed and identify who could act.
AI may automate the decision. It does not automate away the licence.
© 2026 Formichella & Sritawat Attorneys at Law. All rights reserved.
The comments herein are provided for discussion and informational purposes only and may not reflect the most current legal developments. Nothing contained in this publication should be relied upon as legal advice.