ASEAN is trying to write digital trade rules at the moment the global system has stopped producing them. Negotiations on the ASEAN Digital Economy Framework Agreement (DEFA) concluded on 29 May 2026, at the Second Meeting of the 57th ASEAN Senior Economic Officials Meeting in Manila, according to Allen & Gledhill. Law-firm briefings put signing at the 49th ASEAN Summit in November 2026, and Rajah & Tann Asia reports the same target. ASEAN's economic ministers met in Manila on 19 September 2026 for the 58th ASEAN Economic Ministers' Meeting, whose adopted joint media statement has a section on electronic commerce and the digital economy. One caveat applies to everything below: we could not extract the text of that PDF, so the ministers' exact wording on signing is unconfirmed. The November target rests on the law-firm reports. Nobody outside the negotiating rooms has seen the DEFA text either, so any assessment of its details is provisional.
What is on the table
As summarised by law firms, DEFA is billed as the first comprehensive, region-wide agreement dedicated to the digital economy. It reportedly covers digital trade facilitation, cross-border data flows, digital payments and electronic transactions, online consumer protection and interoperability. It also addresses AI, fintech and source code protection. Those firms describe the data-flow commitment only as "supporting trusted cross-border data flows". That phrase could mean almost anything, and the real test is whether it comes with a workable default or a thicket of carve-outs.
The case for caution
The strongest argument for governments wary of binding digital-trade rules deserves a fair hearing. Data and code are not ordinary goods. States have legitimate interests in law-enforcement access, financial supervision, privacy and resilience, and a region with very different income levels and regulatory capacity may reasonably want room to act. The Electronic Frontier Foundation's September 2026 essay on digital sovereignty notes that in Asia, concerns about where data is held are driving much of the conversation. It also warns that sovereignty can be used to splinter access to the internet. Its recommended answer is resilience through open source, interoperability, portability and strong encryption, not walled gardens. Trade rules that ignore these concerns would be brittle, and they would probably be quietly ignored.
Why a rulebook is still better than a vacuum
That caution cuts both ways. The alternative to common rules is not neutral national discretion. It is a patchwork of localisation mandates and ad hoc levies, which falls hardest on small firms that cannot maintain a data centre or a compliance team in every market. A region of ten very different economies is exactly where a shared baseline pays off.
The global backdrop strengthens that case. At the WTO's 14th Ministerial Conference in March 2026, a proposal by 164 members to extend the moratorium on customs duties on electronic transmissions to 31 December 2030 was blocked. According to the USTR's press release, Brazil and Turkey were the two members that blocked it. USTR Ambassador Greer said they "would rather let it lapse after 28 years than do the right thing for innovation and the digital economy." That is the US government's account, and other reporting says India and some developing countries also opposed a long extension on revenue and policy-space grounds. That objection is a real one. Governments that lose tariff revenue may prefer to keep their options open. But the lapse means that, in principle, every WTO member may now consider duties on cross-border streams of software, video and data. The practical risk is that cloud and SaaS pricing across Southeast Asia becomes a bargaining chip.
A regional agreement can fill part of that gap. If DEFA members bind themselves not to impose customs duties on electronic transmissions among themselves, and I have not seen the text confirm this, the pact would offer predictability that Geneva could not. Predictability, rather than liberalisation as such, is what a start-up planning a regional launch is buying.
What to watch in the text
Three design questions will determine whether DEFA is an enabler or a headline.
- Data flows with a real default. A commitment that flows are permitted unless a government can justify a restriction as necessary and proportionate is meaningful. A commitment that says only that flows are "supported", subject to each member's laws, is not.
- Source code protection that stays narrow. Barring forced transfer of proprietary code as a condition of market access is pro-innovation. It should not become a shield against regulators auditing high-risk AI or security-critical systems under due process. The exceptions need to be drafted with that distinction in mind.
- Domestic regulatory space that is explicit, not accidental. Privacy, consumer protection and financial-stability measures should be expressly preserved. Clear exceptions make strong commitments more durable, because members are less tempted to hedge the commitments themselves.
Enforcement is a fourth question. ASEAN's record on dispute settlement is thin, and a rulebook with no credible mechanism for raising complaints can become a statement of intent.
The bottom line
DEFA should be judged by whether it commits members to open defaults while keeping narrow, transparent exceptions, not by whether it is signed on schedule. The WTO lapse makes the stakes higher. If ASEAN delivers a text with real defaults, it offers a template other regions can copy; if it delivers aspirational language, it will add to the general drift toward national discretion. Publishing the full text promptly after signing, and letting developers, civil society and businesses test the exceptions, would be the cheapest way to show that this is a trade rulebook and not a sovereignty slogan.