Thailand's public hearing on the Electronic Transactions Development Agency's (ETDA) draft Artificial Intelligence Act closed on 14 August 2026. The most consequential provision is the liability clause. It makes providers and deployers jointly liable for AI-related damage "regardless of willful act or negligence," and leaves only three defences: force majeure, the victim's own act or omission, and compliance with an official order, as summarised by Tilleke & Gibbins and Baker McKenzie. Industry groups objected that unlimited strict liability would deter deployment. ETDA has signalled the clause may change. As of early October, no Cabinet or Parliament stage has been reported.
The strongest case for strict liability
Regulators have a serious argument. AI systems are opaque, and a injured person usually cannot see the training data, the model weights or the deployment choices that caused the harm. Requiring a claimant to prove negligence against a foreign developer, in a Thai court, may mean no remedy at all. Joint liability also lets the victim sue whichever party is easiest to reach, and leaves the provider and deployer to apportion fault between themselves. Thailand has also accepted this logic before.
Thailand already has a strict-liability regime, and it has limits
The Product Liability Act B.E. 2551 (2008), which took effect in February 2009, introduced strict liability into Thai law for unsafe goods. Before it, injured consumers had to prove wilful or negligent conduct under the Civil and Commercial Code. An unofficial English translation of the Act was prepared by officials of the Office of the Consumer Protection Board. According to Price Sanond's analysis, the claimant must show only that the damage came from a product in ordinary use or storage. The defendant then has to show the product was not unsafe, that the claimant knew of the danger, or that the claimant ignored instructions.
The AI draft goes further than that model in three ways.
- Defences. The product-liability regime lets a defendant argue the product was not unsafe. The AI draft, as reported, has no equivalent. A provider that did everything a careful developer could do still pays.
- Time. The product-liability regime has a built-in endpoint. Claims must be filed within three years of the injured person knowing of the injury and the responsible operator, or ten years from sale, whichever is earlier. A model is retrained, fine-tuned and redeployed continuously, so "sale" is not a natural anchor, and the draft's reported text gives no comparable stop.
- Chain of control. A defective toothpaste or appliance leaves the manufacturer's hands. An AI model is configured by a deployer, prompted by a user and fed data by third parties. Joint liability without a causation filter makes the original developer insurer of everything downstream.
What the draft risks
The draft is broad. It applies to developers, providers, deployers and platform operators, including offshore entities, and sorts systems into four tiers: prohibited, high-risk, licensed, and transparency-only (deepfakes, chatbots, generative AI), per Baker McKenzie. Tilleke reports administrative fines of THB 1 million to THB 5 million, plus enforcement powers that escalate to blocking AI systems in Thailand. Foreign providers must appoint local representatives who may carry wide liability exposure.
Stacked together, these create a cost that cannot be priced. Fines are capped, but civil liability under the draft is not. An insurer cannot underwrite a risk with no ceiling, no fault standard and no time limit. The likely result is rational withdrawal. Foreign model providers would geo-fence Thai users or decline to offer enterprise features, and local start-ups would be reluctant to build on any foundation model. The policy would then fail its own aim, because Thai victims would be protected from AI by not having access to it. Hospitals, banks and small businesses that would benefit from deployment bear that cost.
There is also an enforcement mismatch. The same draft already gives ETDA recall, suspension and blocking powers, and a licensing tier for the riskiest systems. Where a regulator controls market entry, ex-ante controls do the work of deterrence. Layering uncapped no-fault liability on top of them punishes compliant firms twice.
A proportionate alternative
The goal of making victims whole can be met without the same design. Four changes would do most of the work:
- Tier the standard. Keep strict liability for the high-risk tier that the draft itself defines, where the harm is foreseeable and insurable. Use a presumption of fault, which the defendant can rebut, for everything else.
- Add a compliance defence. A provider that met the Act's own risk-control, documentation and testing duties should have a defence. Otherwise those duties, which apply 180 days after enactment per Tilleke, carry no legal weight.
- Allocate by control. Liability should follow who configured, trained or operated the system for the specific harm, with a right of contribution between the parties, rather than automatic joint liability for all.
- Set limits. Borrow the Product Liability Act's long-stop period, and consider per-claim or insurance-linked caps for lower tiers.
The broader lesson matches what EFF argued this August in the copyright context: legal systems should avoid rewriting settled doctrine out of panic over a new technology. Thailand has a tested strict-liability regime and a regulator with real powers. The draft should use both, in proportion.
What to watch
ETDA has not published a revised text. Whether the final bill keeps the "regardless of intent or negligence" language, adds a compliance defence, or caps exposure will decide whether Thailand becomes a place where AI is deployed under clear rules or one where the largest providers quietly stay out. ETDA has run AI-governance consultations since at least 2022, per its emerging-technologies page, so it knows how to fold in feedback. The Cabinet and Parliament stages are still ahead.