A Nationwide Rollout, Confirmed in One Line
On August 6, 2026, Thailand's Tourist Police Commissioner, Pol Lt Gen Saksira Pueak-am, confirmed what had been building in pilot form for months: CCOC Mobile units — command vehicles fitted with cameras that run live facial recognition and automated number-plate reading against police databases — have contributed to 914 arrests nationwide. The units sit alongside an expanded, eight-language 1155 tourist hotline and a small drone fleet, all pitched as tools to "build confidence in Thailand" for visitors (Hua Hin Today). This isn't an experimental pilot anymore. It's operational infrastructure, and it's backed by real money: in January 2025 the Royal Thai Tourist Police signed a five-year, $50-60 million partnership with Gorilla Technology to deploy AI-driven surveillance, including facial and plate recognition, across the country's major tourist destinations (Gorilla Technology).
The Case for It
Thailand's economy leans hard on tourism, and tourist-targeted crime — scams, theft, overstay fraud — is a real drag on that industry's credibility. Automated systems that cross-reference faces and plates against watchlists can catch repeat offenders and missing persons faster than officers working from memory or paper alerts, and 914 arrests is not a vanity number; it represents actual cases closed. Governments elsewhere in the region are building similar systems for the same reason. A blanket objection to using AI for policing would ignore that the technology is already producing outcomes police forces have struggled to deliver manually.
But the Exemption Doing the Work Here Is Broad
The problem isn't the technology — it's that Thailand's principal privacy law barely constrains how police use it. The Personal Data Protection Act B.E. 2562 (2019), Thailand's GDPR-style statute, treats biometric data as sensitive and normally requires explicit consent to collect or use it (Ministry of Digital Economy and Society). But the Act's public-interest and state-security carve-outs are broad and largely undefined, and government processing for those purposes falls outside much of the consent and data-subject-rights framework that binds everyone else. As Digital Rights Advisor Jean Linis-Dinco has argued, that gap gives Thai authorities "a free pass to unchecked surveillance" — and it isn't hypothetical. Facial-recognition-linked SIM registration has already been used as part of counterinsurgency monitoring of Malay Muslim communities in Yala, Pattani, and Narathiwat, and a 2022 investigation by iLaw, Digital Reach, and Citizen Lab found Pegasus spyware deployed against at least 30 government critics (Context/Thomson Reuters Foundation).
What makes the gap notable is that Thailand's privacy regulator has proven it can act decisively — just not against the state. In November 2025, the Personal Data Protection Committee ordered TIDC Worldverse (operating Tools for Humanity's World iris-scanning project) to halt operations and delete biometric records collected from 1.2 million users, after finding the company had not obtained adequate consent and was offering cryptocurrency in exchange for iris scans (Biometric Update). That's a regulator with real teeth. It simply hasn't been pointed at a nationwide police camera network that performs the same category of biometric collection at a larger scale, with no published consent basis, retention limit, or independent sign-off.
A Proportionate Middle Path Exists
The EU offers a workable template without requiring Thailand to give up the tool. The EU AI Act, Regulation (EU) 2024/1689, prohibits real-time remote biometric identification by law enforcement in public spaces by default, carving out only three narrow exceptions — searching for trafficking or abduction victims, preventing an imminent terrorist threat, or locating a suspect in a crime carrying at least a four-year sentence — and even those require prior judicial or independent administrative authorization, a fundamental-rights impact assessment, and geographic and time limits before deployment (EUR-Lex). Nothing in the public reporting on Thailand's CCOC rollout suggests any comparable authorization step exists before a camera scans a face against a police database.
What Thailand Should Actually Do
Banning facial recognition would throw away a tool that is demonstrably catching real offenders in a tourism-dependent economy that needs the credibility. The fix is narrower: require independent authorization — judicial or from an empowered oversight body — before biometric matching is used beyond a defined list of serious offenses, publish retention periods and error/false-match rates, and subject the program to the same PDPC scrutiny the regulator just applied to a private iris-scanning firm. None of that requires new legislation from scratch; Thailand's Draft Royal Decree on AI, still under consideration, is the natural vehicle. The $50-60 million already committed to this infrastructure will keep expanding with or without those guardrails. The cheaper moment to install them is now, before a Pegasus-style scandal — not a facial-recognition one — forces the retrofit.