Thailand's new central-bank guideline says banks and payment firms should own the decisions their AI makes
Most of the AI-in-finance rulebook is written in English by regulators in London, Washington, and Brussels. Thailand's is not, and that is why it is worth reading. On 12 September 2025 the Bank of Thailand released a Thai-language policy guideline that tells banks and payment companies something blunt: if your AI system makes a call, or a person leans on its output to make one, the firm is expected to answer for the result. It is short, principles-based, non-binding, and it lands the accountability on the board and senior management. Because it is published only in Thai, it rarely shows up in the roundups, so here is a source-checked read of what it says.
Key facts
- Instrument
- Bank of Thailand Policy Guidelines on Risk Management for the Use of Artificial Intelligence Systems (แนวนโยบายธนาคารแห่งประเทศไทย เรื่อง การบริหารจัดการความเสี่ยงของการใช้งานระบบปัญญาประดิษฐ์).
- Issuer
- Bank of Thailand (ธนาคารแห่งประเทศไทย), IT Risk Regulation and Examination Department, Payment Systems Policy and Financial Consumer Protection Group.
- Date
- 12 September 2025 (12 กันยายน 2568), following a public consultation in June 2025.
- Who is covered
- Financial institutions and specialized financial institutions under the Financial Institutions Business Act, plus regulated payment system operators and payment service providers under the Payment Systems Act.
- Status and consequence
- Supervisory policy guideline, not a penalty-bearing regulation. It supplements binding IT-risk, data-governance, third-party-risk, and market-conduct rules. Firms must still comply with laws such as the Personal Data Protection Act.
What the guidelines expect
The guideline sets four governing principles and then two operating sections. The four principles read as the spine of the document. First, the financial service provider is accountable for how its AI system works, including any decision that relies on the system's output. Second, the provider governs AI use in line with a generally accepted responsible-AI standard, named in the text as FEAT, for fairness, ethics, accountability, and transparency. Third, the provider manages risk across the full AI lifecycle so the system stays secure, accurate, and reliable, with results that can be controlled and explained. Fourth, the provider treats customers transparently and fairly.
Here is the operative accountability line, in the original and in plain English:
ผู้ให้บริการทางการเงินมีความรับผิดชอบต่อการทำงานของระบบ AI รวมถึงการตัดสินใจที่อ้างอิงจากผลลัพธ์ของระบบ AI
"The financial service provider is accountable for the operation of the AI system, including decisions made in reliance on the outputs of the AI system." (English gloss of the Bank of Thailand text.)
From there the guideline splits into two parts. Part 1, governance, wants clear board and senior-management responsibility, an approved AI-use policy that is reviewed regularly, oversight assigned across all three lines of defense, and staff trained well enough not to over-rely on AI output. It also asks firms to consider keeping a person in the decision, either as a human in the loop or a human over the loop, for high-impact uses such as loan approvals, account opening, and deposit or transfer approvals. And when AI talks to customers in place of a human, the firm should tell the customer that and offer a route to a real person.
Part 2, development and security, is where the technical expectations sit. Firms are asked to control data quality before training, restrict what data the model can reach, and protect sensitive and personal data with methods the text names directly, including data masking, hashing, and input sanitization. On models, the guideline calls for evaluation metrics, testing before and after deployment against unseen data and edge cases, retrieval-augmented generation and prompt engineering to reduce hallucination in generative AI, and documentation so people can explain a model's inputs, outputs, and parameters. On cyber threats it names the attack types it cares about, including prompt injection, model inversion, data poisoning, and adversarial attacks, and it points firms at international references such as the OWASP Top 10 for Large Language Model Applications and MITRE ATLAS.
Who is covered
Scope is set in Section 3 and repeated in the definitions. The guideline reaches financial institutions and specialized financial institutions regulated under the Financial Institutions Business Act, and it reaches regulated payment system operators and payment service providers under the Payment Systems Act. In practice that is the commercial banks, the state-backed specialized institutions such as the housing and agricultural banks, and the licensed payment and e-money players.
Two scope points matter for anyone building on top of a vendor model. The Bank of Thailand's own appended FAQ states the principles apply whether the AI is developed in house or procured from a third party, and it gives an in-house generative AI chatbot as an example that still counts. Separately, the definition deliberately excludes rules-based automation: robotic process automation, condition-matching systems, and automated scripts are not treated as AI systems under this guideline, because a human sets their steps in advance.
Effective dates and status
The guideline carries a single date, 12 September 2025, and no phased implementation calendar. That is consistent with its nature. This is a naeo nayobai, a policy guideline that states supervisory expectations, not a notification carrying its own penalty schedule. It was preceded by a formal public consultation in June 2025, and the final text folds in an appended question-and-answer section that clarifies scope and definitions.
Because it is guidance, the pressure it creates is supervisory rather than punitive. It plugs into rules the Bank of Thailand already enforces and names them: IT risk, third-party risk, data governance, and market conduct. A firm that ignores the AI guideline is not fined for that alone, but the same expectations surface through those binding regimes and through examination.
What it does NOT do
The guideline is narrow on purpose, and reading it as more than it is will get you in trouble.
- It does not impose fines or set a penalty schedule. It is guidance, not a sanctioning notification.
- It does not license, register, or pre-approve AI systems. There is no approval gate to clear before deployment.
- It does not ban any AI use case, including generative AI or automated decisions, provided the risk is managed and, where impactful, a human stays involved.
- It does not override the law. The appended FAQ is explicit that firms must still comply strictly with related law, naming personal-data-protection and intellectual-property law.
- It does not reach beyond regulated finance. Non-financial firms and unregulated fintechs sit outside its scope.
- It does not cover rules-based automation such as RPA or condition-matching scripts, which fall outside the AI definition.
How it compares: Bank of Thailand vs MAS vs HKMA
Thailand is not writing on a blank page. Its two better-known neighbors set the template years earlier, and the Bank of Thailand's choice to cite FEAT by name is a direct nod to Singapore. Here is how the three Asian AI-in-finance regimes line up.
| Feature | Bank of Thailand (BoT) | Monetary Authority of Singapore (MAS) | Hong Kong Monetary Authority (HKMA) |
|---|---|---|---|
| Core instrument | AI Risk Management Guidelines, 12 Sep 2025 | FEAT Principles, Nov 2018, plus the Veritas toolkit | High-level Principles on AI, Nov 2019, plus later GenAI circulars |
| Legal force | Policy guideline, supervisory expectation | Principles and guidance, supervisory expectation | Circular-based guidance, supervisory expectation |
| Guiding values | Fairness, ethics, accountability, transparency (FEAT) | Fairness, ethics, accountability, transparency (FEAT) | Governance, accountability, fairness, transparency, data protection |
| Board accountability | Explicit, board and senior management own AI decisions | Expected via internal governance and the FEAT accountability pillar | Explicit, board and senior management remain responsible |
| Human oversight | Human in the loop or human over the loop for high-impact uses | Human involvement expected for material decisions | Human oversight and ability to intervene expected |
| Generative AI | Named directly, with hallucination controls and RAG | Addressed in later MAS papers and the Veritas work | Addressed in dedicated 2024 GenAI guidance |
The pattern across all three is the same. None is a hard statute with fines attached. Each is a supervisory expectation that boards ignore at their peril, enforced through examination and the binding rules it sits beside. Thailand's contribution is not novelty. It is that a fourth Asian regulator has put the same accountability and human-oversight expectations in writing.
Practical steps for a covered firm
If you run risk or technology at a Thai bank or payment company, the guideline maps to a short list you can start on now.
- Write down the board and senior-management responsibilities for AI, and set a stated risk appetite the AI program has to live inside.
- Approve an AI-use policy, tie it to the responsible-AI or FEAT baseline, and schedule regular reviews so it keeps pace with the technology.
- Build an inventory of AI use cases and flag the high-impact ones, credit approval, account opening, and payment approvals, for human in the loop or human over the loop oversight.
- Stand up data-quality checks before training and access controls that stop models reaching data they do not need, with masking, hashing, and input sanitization for sensitive data.
- Define evaluation metrics, test models before and after go-live against unseen data and edge cases, and add hallucination controls for any generative AI.
- Red-team against prompt injection, model inversion, data poisoning, and adversarial attacks, tracking new threats against the OWASP LLM Top 10 and MITRE ATLAS.
- Disclose to customers when they are talking to AI, and give them a way to reach a person.
Primary sources and further reading
- Bank of Thailand, AI risk-management policy guideline, Thai PDF: bot.or.th (25680178.pdf)
- Bank of Thailand, public consultation on the draft guideline, 12 June 2025: bot.or.th public hearing
- Related tracker: our AI Regulation News hub with the full by-jurisdiction index.
- Regional context: the Asia-Pacific section for the MAS and HKMA entries.
- By jurisdiction: browse the jurisdiction matrix.
FAQ
Are the Bank of Thailand AI guidelines legally binding?
No. The document is a policy guideline that sets supervisory expectations rather than a penalty-bearing regulation. It supplements binding rules the Bank of Thailand already enforces on IT risk, data governance, third-party risk, and market conduct, and providers must still comply with the law, including the Personal Data Protection Act.
Who has to follow the guidelines?
Financial institutions and specialized financial institutions under the Financial Institutions Business Act, plus regulated payment system operators and payment service providers under the Payment Systems Act.
Do the guidelines apply if a firm only uses off-the-shelf AI like a chatbot?
Yes. The Bank of Thailand's own FAQ says the principles apply whether the AI system is built in house or procured from a third party, including a generative AI chatbot used inside the firm.
What is the FEAT principle referenced in the guidelines?
FEAT stands for fairness, ethics, accountability, and transparency. It is the responsible-AI baseline the Bank of Thailand cites, and it echoes the framework Singapore's regulator published in 2018.