Indonesia algorithmic accountability

Indonesia's AI Rules Are Right to Stay Flexible, but a Presidential Decree Cannot Carry Enforcement Alone

Komdigi's pending AI roadmap and ethics decrees favour proportionate governance. The Jakarta Post is right that enforcement still needs statutory footing.

Indonesia's AI Governance Stack People of Internet Research · Indonesia 9 Ethics values in Circular 9/2023 Voluntary guidance, not binding ru… 16 Jan 2027 GR 33/2026 effective date Six months after its 16 July 2026 … 30M won Korea AI labelling fine cap The model Komdigi says it will fol… peopleofinternet.com
Indonesia's AI Governance Stack People of Internet Research · Indonesia 9 Ethics values in Circular 9/2023 16 Jan 2027 GR 33/2026 effective date 30M won Korea AI labelling fine c… peopleofinternet.com

Key Takeaways

Indonesia's Communication and Digital Ministry (Komdigi) has finalised drafts of two presidential regulations, a National AI Roadmap and an AI Ethics Framework. Both await President Prabowo Subianto's signature, and I could not confirm a signing date, so they should be treated as pending. On 21 September 2026 the Jakarta Post's editorial board argued that executive decrees alone cannot govern a technology this consequential and that Parliament should pass a statute. It pointed to biased automated lending decisions, deepfakes and voice-cloning scams. Komdigi describes its own approach as flexible, proportionate and 'compliance-by-design', explicitly not an EU AI Act-style regime.

The strongest case for a statute

The editorial's argument deserves a fair hearing. A presidential regulation (Perpres) binds the executive branch, but it cannot create new criminal offences or private rights of action. Reporting on the drafts has made the same point: because the AI instrument is a presidential regulation rather than a law, penalties for AI misuse can only refer to existing laws such as the ITE Law and the PDP Law. Heru Sutadi of the Indonesian ICT Institute told reporters that Indonesia ideally needs its own dedicated AI law. A harmed borrower or a deepfake scam victim wants a remedy they can enforce, and a roadmap does not give them one.

Why the flexible approach is still defensible

The alternative is a comprehensive, EU-style statute drafted before Indonesia's regulators have the capacity to run one. Komdigi chose to start with ethics, safety and security as foundations, with ministries then writing sector-specific rules. Minister Meutya Hafid said the drafts were prepared in 2025 and that she hoped the President would prioritise signing them in 2026. She also said Indonesia would follow the approach of South Korea, whose Basic AI Act took effect on 22 January 2026. That law's penalties for unlabelled AI content are modest, with fines of up to 30 million won.

This matters because a sector-by-sector approach lets a lending regulator tune rules for credit scoring and a platform regulator tune rules for synthetic media. A horizontal statute written now would have to guess which of those use cases deserves the heaviest obligations. Heavy ex-ante obligations also tend to land hardest on smaller domestic developers, who cannot absorb conformity-assessment costs the way global incumbents can.

The accountability gap is already partly covered, on paper

The editorial's central worry is that nobody can be held to account for algorithmic harm. That is true in practice, but Indonesia has more law on the books than the debate suggests. Article 10 of the 2022 Personal Data Protection Law (Law 27/2022) gives people the right to object to decisions based solely on automated processing, including profiling, that have legal consequences or a significant impact. That describes an automated loan rejection closely. Article 10(2) left the mechanics to a government regulation, and that regulation was slow to arrive.

Government Regulation 33/2026 was enacted on 16 July 2026 and takes effect on 16 January 2027. According to law-firm analysis, Article 120 treats decisions on access to products, services, opportunities or benefits as having legal or significant effects, and Article 121 requires impact assessments before such processing begins. In other words, the lending-bias scenario the Jakarta Post raises is the one the data-protection regime now targets most directly. The gap is not an absence of rules. It is that this regime has not yet started operating.

What the pending decrees should do

The policy question is therefore narrower than 'decree or statute'. A better test is whether the AI instruments plug into laws that already carry sanctions, and whether they are clear enough for firms to follow. Three suggestions follow.

Where the editorial and the ministry can agree

The Jakarta Post is right that decrees cannot carry a whole accountability regime, and Komdigi is right that Indonesia should not import a heavy statute wholesale. The workable middle is to sequence the work. First, make the PDP regime operate from January 2027. Second, let the AI roadmap coordinate ministries. Third, move to a targeted AI statute only where evidence shows existing law is failing, for example if regulators cannot resolve automated-lending complaints. That keeps room for innovation now while holding open a path to legislation when the evidence calls for it.

Sources & Citations

  1. Antara: Kominfo issues AI ethics guidance via Circular Letter 9/2023
  2. Law 27/2022 on Personal Data Protection (statute text, Article 10)
  3. Indonesia Business Post: Communications Minister on AI regulation in 2026
  4. Asia News Network: AI rules pushed to 2026
  5. HLC: Indonesia's PDP implementing regulation (GR 33/2026)