Editorial frame. This article observes and synthesizes published guidance from named regulators and standards bodies. It is editorial reading for compliance officers, GCs, DPOs, and boards. It is not legal or compliance advice for your specific deployment. AI governance obligations depend on your jurisdiction, sector, role (provider, deployer, importer, distributor), and the systems you operate. Engage qualified counsel and your data protection authority before acting on any structural pattern shown here.
Southeast Asia does not have one AI governance posture. It has at least three, sorted less by geography than by how far each government has moved from strategy document to testable framework. An organization deploying AI systems across Singapore, Malaysia, and Thailand encounters a documented framework with a testing toolkit in one jurisdiction and a set of named-but-unformalized instruments in the other two. Understanding where the line between binding and aspirational actually sits is the first task for any compliance officer building a regional program in 2026.
A Region at Two Speeds
The observed pattern by mid-2026 is a bifurcation. Singapore has published a sequence of frameworks: the Model AI Governance Framework second edition (2020), the Generative AI extension (2024), and, most recently, the Model AI Governance Framework for Agentic AI, Version 1.5, published 20 May 2026. Alongside these, Singapore operates an open-source testing toolkit through the AI Verify Foundation and has begun accrediting third-party test results as a cross-border trust signal. The Ministry of Digital Development and Information’s National AI Strategy 2.0, refreshed in May 2026, names “Trusted and Responsible AI” as one of three structural pillars and frames the framework family as its implementation layer.
The rest of the region has taken a softer-touch approach. Malaysia, Thailand, Indonesia, the Philippines, and Vietnam have each published strategy documents, ministerial circulars, or roadmaps that acknowledge AI risk without creating enforceable compliance obligations. This is not a story of hard regulation versus nothing. Singapore’s frameworks remain voluntary in the same technical sense as the region’s other instruments. The practical difference is maturity and testability: Singapore has built out an operational layer (testing toolkit, accreditation program, documented case studies) that the rest of the region has not yet reached.
The structure most practitioners use is to treat Singapore’s framework family as the regional ceiling and to verify each jurisdiction’s underlying data protection law as the compliance floor. That second layer matters because, across the region, AI-specific guidance is published as a supplement to existing personal data protection law rather than as a standalone AI statute. An organization already compliant with local data protection obligations has a shorter path to AI governance alignment than non-compliance would suggest.

Singapore: The Benchmark Jurisdiction
Singapore’s instrument stack has three layers. The Model AI Governance Framework second edition (2020), published jointly by the Infocomm Media Development Authority (IMDA) and the Personal Data Protection Commission (PDPC), set the original structure: four pillars covering internal governance, human oversight calibration, operations management, and stakeholder communication. It introduced three human oversight modes still referenced across the framework family: human-in-the-loop, where the AI provides recommendations only and a human retains full decisional control; human-out-of-the-loop, where no human reviews individual decisions; and human-over-the-loop, a supervisory rather than approval role.
The 2024 extension addressed the governance gap that generative and foundation models opened: hallucination, training data provenance, and supply chain opacity when an organization deploys a third-party model rather than building one. It introduced a clearer developer-versus-deployer distinction, which matters because most enterprises in the region are deployers of models built elsewhere, not developers of their own.
The Agentic AI framework, version 1.5, is the newest layer and the one with the thinnest practitioner coverage as of this writing, given its 20 May 2026 publication date. It organizes guidance around four dimensions: bounding risk before deployment using a likelihood-and-impact model, allocating accountability across a value chain that runs from model developer through platform provider to deployer, implementing technical controls at both the structural and prompt layers, and preparing end users for both external-facing and internally-integrated agent use. It documents named case studies, including a Singapore IT services deployment that used a three-tier risk classification to determine which agent actions require human approval, and a private-banking use case where an agent drafts source-of-wealth memos under mandatory human review at every decision point. Singapore’s Model AI Governance Framework for Agentic AI and the practitioner-level detail behind each of these three layers are examined at length in a companion essay on this site.
MDDI requires that regulated financial institutions treat the Monetary Authority of Singapore’s FEAT Principles (fairness, ethics, accountability, transparency, published 2018) as a sector-specific overlay. The framework is voluntary in the same sense as the others, but practitioners working in Singapore’s financial sector commonly treat FEAT as the operative floor precisely because MAS supervisory expectations reference it during incident review, even without a formal certification requirement attached.
Singapore is also the only Southeast Asian country listed as an adherent to the OECD AI Principles, the five values-based commitments (inclusive growth, human rights and fairness, transparency, resilience and safety, accountability) that the OECD updated in May 2024. The Model AI Governance Framework functions as Singapore’s operational translation of those principles, which is one reason its structure recurs in secondary commentary across the region even where other governments have not formally adopted the OECD framework themselves.
Malaysia and Thailand: Governance in Construction
Malaysia’s National AI Office (NAIO), operating under MyDIGITAL Corporation since the corporation’s incorporation in September 2021, documents seven deliverables. Two carry regulatory character rather than pure strategy: the AI Adoption Regulatory Framework, described on the NAIO’s own site as a “framework to promote ethical and sustainable AI adoption,” and the AI Code of Ethics, aimed at “ensuring the responsible and ethical usage of AI throughout the entire management value chain.” The AI Technology Action Plan 2026-2030 is the broader strategic anchor. None of the three has yet moved from named instrument to enforceable rule as of mid-2026, and NAIO operates through seven specialized working groups spanning technology, academia, industry, and government rather than through a single regulatory office with enforcement power.
Thailand’s Electronic Transactions Development Agency (ETDA) operates a formal AI Governance Center (AIGC) as an organizational unit under the Ministry of Digital Economy and Society, distinguishing Thailand from jurisdictions where AI governance sits as a side responsibility inside a broader digital ministry. AIGC’s current operative work includes a three-year plan for medical and public health AI, announced 25 May 2026 in partnership with Thailand’s Ministry of Public Health and National Science and Technology Development Agency. ETDA’s Data Governance Policy, aligned to Thailand’s Personal Data Protection Act, remains the binding layer beneath the AIGC’s guidance work: the pattern here matches the region generally, where the enforceable obligation traces back to data protection law rather than to a standalone AI statute.
Indonesia, the Philippines, and Vietnam: Roadmap Stage
Indonesia’s primary AI-specific instrument, Ministerial Circular (Surat Edaran) No. 9 of 2023 on AI ethics, sits below the level of a binding regulation (peraturan) in Indonesia’s administrative hierarchy. It is non-binding guidance from the Ministry of Communication and Digital, formerly Kominfo. Indonesia’s Personal Data Protection Law (UU PDP), enacted 2022, provides the underlying binding layer wherever an AI system processes personal data, which mirrors the region-wide pattern of data protection law doing the enforcement work that AI-specific instruments do not yet do.
The Philippines and Vietnam are earlier in the sequence still. The Philippines’ Department of Information and Communications Technology maintains a national AI strategy roadmap at the planning-document stage; documented AI-specific advisory work from the National Privacy Commission exists but had not, as of this research, produced a named framework comparable to Singapore’s or Malaysia’s. Vietnam’s Ministry of Science and Technology maintains a national AI research and development strategy, similarly a planning instrument rather than a governance framework. Both jurisdictions warrant close tracking over the next refresh cycle, since a roadmap-stage document is a signal of future regulatory direction, not a current compliance requirement, and that gap can close quickly once a government moves from strategy to draft instrument.
Regional Architecture and the Intergovernmental Frame
ASEAN’s Guide on AI Governance and Ethics, first circulated in draft form and consolidated in 2024, structures around seven principles: transparency and explainability, fairness and equity, safety and security, human oversight, accountability and responsibility, privacy and data governance, and inclusivity. It functions as a coordination reference for member states rather than a binding instrument on any of them, and its practical effect is to standardize vocabulary across a region where formalization timelines otherwise diverge sharply.
That vocabulary convergence extends beyond ASEAN. Governments across the region cite the OECD AI Principles and the NIST AI Risk Management Framework’s four functions (Govern, Map, Measure, Manage) as reference points in their own policy documents, even where they have not formally adopted either framework. Singapore’s AI Verify testing toolkit explicitly crosswalks against the NIST AI RMF, which matters practically for any organization operating in both Singapore and the United States: a testing regime built against one framework carries legible structure into the other, even without formal mutual recognition.
Comparative Snapshot
| Jurisdiction | Primary instrument | Binding or voluntary | Sectoral overlay |
|---|---|---|---|
| Singapore | Model AI Governance Framework (2020/2024/2026 lineage) | Voluntary, with MAS FEAT as a binding-adjacent sector overlay | Financial services (MAS FEAT) |
| Malaysia | NAIO AI Adoption Regulatory Framework, AI Code of Ethics | Named but not yet enforceable | Public sector (AI Impact Study for Government) |
| Thailand | ETDA AI Governance Center guidance | Voluntary; PDPA is the binding floor | Healthcare (2026 medical AI plan) |
| Indonesia | Surat Edaran No. 9/2023 | Non-binding ministerial circular; UU PDP is the binding floor | None named |
| Philippines | DICT national AI strategy roadmap | Planning-stage | None named |
| Vietnam | MST national AI R&D strategy | Planning-stage | None named |
The comparative read-out for a compliance officer building a regional program: build against Singapore’s framework as the ceiling for internal governance design, and verify each jurisdiction’s data protection law as the enforceable floor. The AI-specific instruments in the rest of the region are directional signals of where enforcement is heading, useful for anticipating what a Malaysian, Thai, or Indonesian regulator is likely to formalize next, but they do not yet create the kind of documented obligation that a Singapore-anchored program does.
Editorial content from Business Data Guide. Not legal, regulatory, or compliance advice. AI governance obligations depend on jurisdiction, sector, deployment context, and your role as provider, deployer, importer, or distributor. Engage qualified counsel before acting on any structural pattern shown here.