A boom that outran its rulebook
Thailand's data center industry has grown faster than the regulatory apparatus meant to govern it. The Board of Investment approved 42 data center projects worth roughly ฿750 billion (~$21 billion) between 2024 and 2026, according to the Thai government's Public Relations Department, spanning hyperscale investments from Google, UAE-based DAMAC Group, and Singapore's Bridge Data Centres. Until now, that boom was regulated by whatever generally applicable law happened to apply — building codes, foreign business rules, telecommunications licensing — with no single authority responsible for the sector as a whole.
On August 5, 2026, Thailand's Cabinet approved a draft Prime Minister's Office regulation establishing a national Data Center Business Policy Committee, chaired by a deputy prime minister with the ministers of Digital Economy, Interior, and Energy as vice chairs. The regulation was published in the Royal Gazette on August 13 and took effect the following day, according to Baker McKenzie's legal analysis and Thai outlet Matichon. Its job is to set binding policy frameworks across the three agencies that currently approve data centers separately — the BOI (investment promotion), the Energy Regulatory Commission (power supply), and the NBTC (telecommunications licensing) — plus oversee energy security, water allocation, fire safety, and "national data security."
The case for coordination
The steelman here is straightforward and largely correct: data centers are genuinely different from ordinary factories. They draw continuous, large-scale electricity and consume significant water for cooling, and Thailand's grid and reservoirs are not infinite. The government's own Public Relations Department reported that on July 15, 2026, the National Energy Policy Council approved new prerequisites requiring data center operators to demonstrate real investment commitment before the state expands electrical infrastructure for them, alongside mandatory water management plans — explicitly to stop residential consumers from subsidizing industrial buildout and to protect agricultural water from industrial competition. When three separate regulators (BOI, ERC, NBTC) were each approving pieces of the same project without a shared resource picture, uncoordinated overbuild was a real risk. A single body that can see the whole pipeline and set consistent rules is a legitimate response to a legitimate collective-action problem, not manufactured bureaucratic empire-building.
Where it becomes a problem
The committee's own mandate, as described in the regulation, is comparatively light-touch: it proposes standards and monitors impact, and line agencies retain approval authority. That's a defensible design — coordination without a new veto layer. The bigger risk to Thailand's investment pitch isn't the committee itself; it's a separate, parallel move by one of the three agencies it oversees. The NBTC is considering reclassifying data center services from a Type 1 telecommunications business — which permits foreign-majority ownership — to Type 3, which requires Thai-majority ownership and more extensive licensing, according to Silk Legal's analysis of the reclassification. The stated rationale is to align data centers with infrastructure operators like telecom and submarine cable companies for national-security purposes. But nearly every marquee data center investment Thailand has landed in the past two years — Google, DAMAC, Bridge Data Centres, plus Chinese, Japanese, and Indian capital — has been foreign-majority by design. A hyperscaler does not restructure its ownership stack to accommodate one market's licensing preference; it builds somewhere else. Vietnam, Malaysia, and Indonesia are all actively courting the same capital with fewer ownership strings attached.
This is where "national data security" as a stated justification deserves scrutiny rather than deference. Submarine cables and spectrum are genuinely scarce, strategic infrastructure where ownership control has an obvious rationale. A data center is a building full of racks, cooled and powered under contracts that can already be audited, taxed, and conditioned without touching the equity cap table. If the actual concern is data sovereignty, Thailand already has tools for that — data localization conditions, security certification requirements, audit rights — that don't require foreign investors to hand over control of the business itself.
The proportionate path
The new Policy Committee, taken on its own terms, is a reasonable response to a real coordination gap, and Thailand deserves credit for building resource safeguards — the July energy council measures in particular — before the grid or water tables came under acute strain, rather than after. But the committee's value depends entirely on whether it functions as a coordinating layer or becomes a second veto point stacked on top of BOI, ERC, and NBTC approvals that already run for months. And its credibility will be tested by what the NBTC does next: if Type 3 reclassification proceeds, Thailand will have built an elegant coordination mechanism for a sector it is simultaneously making harder for its actual investors to operate in. Quarterly implementation reporting to the committee, cited in Thai press coverage of the regulation, is a good instinct — it should be paired with a public sunset review of the ownership question before it becomes the story that overshadows the ฿750 billion the country has already attracted.