The adoption of AI in the financial and insurance industries is growing rapidly. Today, AI is widely used in areas such as risk analysis, loan approval processes, and automated customer service systems.
While AI helps organizations work faster and more efficiently, it also introduces new risks that businesses must carefully manage. These include inaccurate outputs, biased decision-making, and improper use of data.
As a result, regulatory authorities in Thailand have begun introducing AI governance guidelines to ensure that AI is used in a safe, transparent, and auditable manner. The two key regulators involved are the Bank of Thailand (BOT) and the Office of Insurance Commission (OIC).
Overview of AI Regulation in Thailand
Thailand does not yet have a specific standalone AI law. Instead, AI is governed through a risk-based guideline approach.
The core principle is not to prohibit AI usage, but to ensure that risks are properly managed according to the importance and impact of each use case.
The two main regulatory bodies are:
- BOT (Bank of Thailand) → oversees banking and financial services
- OIC (Office of Insurance Commission) → oversees the insurance sector
Both aim to ensure that AI is used effectively while remaining safe, fair, and trustworthy for consumers.
Guidelines from the Bank of Thailand (BOT)
The Bank of Thailand has issued an AI Risk Management Policy to encourage responsible use of AI within financial institutions.
A key foundation of this policy is the concept of Responsible AI, which consists of four main principles:
- Fairness
- Ethics
- Accountability
- Transparency
This reflects the idea that AI is not just an automated system, but something that organizations must be accountable for in terms of its outcomes and decisions.
Key AI Risk Areas Highlighted by BOT
1. Data Risk
Organizations must ensure that data used in AI systems is high-quality, secure, and protected from leakage or misuse.
2. Model Risk
AI models must be continuously tested and monitored to reduce errors, including issues such as inaccurate outputs or AI hallucination.
3. Cybersecurity Risk
Organizations must protect AI systems from modern cyber threats such as prompt injection and data poisoning, which may manipulate system behavior.
Guidelines from the Office of Insurance Commission (OIC)
On the insurance side, the OIC has introduced AI governance guidelines to balance innovation with consumer protection. The main goal is to ensure that AI is used responsibly, transparently, and in a way that can be audited and explained.
Key Principles from OIC
- Clear AI governance structure and accountability
- Strong system security and robustness
- Ability to explain AI-driven decisions
- Protection against unfair treatment and bias
Human-in-the-Loop for High-Risk AI
The OIC clearly emphasizes that high-risk AI applications must include human oversight in decision-making.
This applies to use cases such as:
- Insurance underwriting
- Premium calculation
- Claims assessment
In these cases, humans must remain involved in the final decision process to prevent unfair or incorrect outcomes.
Comparison: BOT vs OIC AI Guidelines
| Aspect | BOT (Bank of Thailand) | OIC (Insurance Commission) |
| Scope | Banking & financial services | Insurance industry |
| Core Focus | Responsible AI & risk management | AI governance & consumer protection |
| Key Concern | Model and cyber risks | Fairness and transparency |
| Explainability | Required | Clearly required |
| Human oversight | Required in critical use cases | Mandatory in high-risk decisions |
| Objective | Financial system stability | Consumer protection and fairness |
Conclusion
The guidelines from both the Bank of Thailand and the Office of Insurance Commission clearly show that AI in financial services is no longer viewed as just a technological tool. Instead, it is now considered a systemic risk that requires proper governance and control.
Organizations adopting AI must therefore focus on:
- Risk management frameworks
- System transparency and explainability
- Human oversight in critical decisions
If your organization is adopting AI in financial or insurance operations, implementing a proper AI governance framework from the beginning is essential to align with regulatory expectations from both BOT and OIC.
Designing AI systems with proper safeguards such as AI monitoring, guardrails, and human-in-the-loop processes can significantly reduce risk and ensure long-term, safe adoption of AI.
If you need guidance on implementing enterprise AI systems or AI governance frameworks, feel free to contact AppMan for expert consultation.


TH