Indonesia is close to becoming one of the first Southeast Asian states with binding, government-wide rules for artificial intelligence. Two presidential regulations — a Perpres on AI Ethics and a Perpres on the National AI Roadmap 2026-2029 — have cleared inter-ministerial harmonization and, as of September 3, 2026, need only President Prabowo Subianto's signature to take effect, according to Communications and Digital Ministry Director General Edwin Hidayat Abdullah. An analysis published by East Asia Forum on September 4, 2026 argues that the timing of the sign-off matters less than what is missing underneath it: neither Perpres creates an independent body capable of checking how the state itself uses AI, and the data-protection law they lean on for enforcement has been unenforceable in practice since it passed.
What the Perpres Actually Do
The AI Ethics regulation sets a risk-tiered framework — defining prohibited uses, high-risk uses requiring safeguards, and general-purpose guidance across roughly ten designated sectors — while the Roadmap Perpres, developed under Presidential Decision No. 38/2025 with more than 30 ministries and agencies including Bappenas, the Finance Ministry and BRIN, sets four policy priorities: stakeholder engagement, innovation, technical and research capacity, and risk mitigation. Neither creates a regulator with subpoena power, adjudicative authority, or standing to investigate a government agency's own AI deployment. Enforcement of both instruments is designed to run through existing sectoral regulators and the PDP Law's supervisory mechanism — which is precisely where the framework's gap sits. That division of labor is a defensible, deliberate choice for a first-generation ethics framework; it simply pushes all the real enforcement weight onto a law that, for now, has no enforcer.
The Case for Moving Fast Anyway
The steelman for issuing the Perpres now, gaps and all, is real. Indonesia's AI adoption — in finance, health credentialing, e-commerce fraud screening — is already outrunning any regulatory framework, and industry has been asking for the policy certainty the roadmap promises so investment decisions aren't made in a vacuum. A risk-tiered ethics baseline, even a soft one without its own enforcement teeth, is better than the status quo of no binding national AI guidance at all. Waiting for a perfect institutional structure before publishing any AI rules would leave the fastest-moving deployments — including in law enforcement and public administration — governed by nothing, which is worse than governed imperfectly.
Four Years, No Regulator
The institutional gap is not new, and it is not small. Indonesia's Personal Data Protection Law was enacted October 17, 2022, and Article 58 requires that a dedicated supervisory institution — the Lembaga PDP — be established by presidential decree to enforce it. Article 59 gives that institution authority to set data-protection policy and mediate disputes; Article 60 gives it power to issue warnings, order processing suspended, compel deletion of data, investigate violations, and levy administrative fines capped at 2% of a violator's annual revenue under Article 57(3). None of those powers has ever been exercised, because the institution does not exist. The law's transition period ended October 2024, meaning the statute has been fully enforceable for roughly two years — but the Lembaga PDP itself still does not exist. The implementing Perpres was granted presidential-initiative permission in March 2025, cleared inter-ministerial review by September 2025, and was formally submitted to the President in May 2026; as of August 19, 2026 it remained unsigned. Enforcement in the interim sits with a ministry directorate general — the same ministry that would operate AI systems the law is supposed to constrain.
Why the Missing Regulator Is the Real Story
This is precisely the structure East Asia Forum's analysis flags as dangerous: a state that can deploy AI-enabled surveillance and administrative tools while the one body statutorily designed to hear a citizen's complaint against that same state doesn't exist. It is not a hypothetical concern. Indonesia already operates citywide CCTV networks, facial-recognition systems, and lawful-intercept infrastructure at telecom carriers, and in May 2026 the government proposed a team of assessors empowered to determine who legally counts as a human rights defender under an amendment to the 1999 Human Rights Law — a proposal Human Rights Watch called an attempt to let the government decide who is or isn't a human rights defender rather than protect all rights workers equally. Layer AI-assisted identification or moderation tooling onto that environment, and the missing regulator stops being a bureaucratic footnote.
The Fix Is Institutional, Not Rhetorical
None of this argues against Indonesia regulating AI — proportionate, risk-tiered rules are the right instrument, and the roadmap's emphasis on innovation and stakeholder input is sound policy. The argument is sequencing: an ethics Perpres that leans on the PDP Law for teeth is only as credible as the regulator that law has been waiting on since 2022. Signing the AI Perpres without also signing the Lembaga PDP regulation gives Indonesia the appearance of a modern AI governance regime while leaving the enforcement backstop — the body meant to hear complaints against state and corporate misuse alike — permanently pending. Prabowo's government can close both gaps with the stroke of the same pen it is already reaching for; doing one without the other is a governance framework built without its most load-bearing wall.