- Insights This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
AI rules in SEA: the risks, the fines, what you need to know
If you build or deploy AI in Southeast Asia, someone has probably handed you a stack of “AI governance frameworks” and told you to comply. Most of those frameworks are voluntary and carry no penalty, but there are others that can incur hefty fines.
These mandatory frameworks range from existing data protection laws to new AI regulations, as well as industry-specific rules that you should already be familiar with.

Image credit: Ulla
Making the effort to know the difference between what’s voluntary and mandatory is key for any CTO or product lead. Confusing the two can waste precious time and money that most startups don’t have.
In my work as an applied scientist building AI systems for Southeast Asian contexts, I’ve spent years on the technical side of what regulators are now trying to govern, such as training data, model documentation, bias testing, and deployment oversight. For builders, it is important to understand what these regulations actually require so they can act on them.
What carries penalties
A lot of AI regulations, including the European Union’s AI Act and Vietnam’s AI Law, use risk-based classification systems. These have a wide reach, covering local and foreign entities engaged in AI activities.
For example, social scoring and real-time biometric identification in public spaces are categorized as prohibited in both the EU and Vietnam.
Below that is the high-risk tier, which is where most AI builders will find themselves. If your product touches on hiring, credit scoring, healthcare, education, or essential public services, treat it as high-risk by default.
The EU AI Act
Regulation 2024/1689 is a binding law that applies not only to companies inside the EU but to any provider or deployer outside the union whose AI system output is used in its jurisdiction. If your company is based in Jakarta but a client uses your tool in their Berlin office, you’re in scope just the same.
Penalties are not symbolic: up to 35 million euros (US$40.7 million) or 7% of worldwide turnover for prohibited uses, and up to 15 million euros (US$17.4 million) or 3% of worldwide turnover for high-risk non-compliance.
Vietnam’s AI Law
Law 134/2025 has flown under the radar for many builder teams operating in Southeast Asia. Vietnam’s National Assembly passed the region’s first standalone, comprehensive AI statute on December 10, 2025, and it took effect on March 1, 2026.
The law’s structure lifts much of its logic from the EU AI Act: There are prohibited, high-risk, and low-risk tiers, with separate provider and deployer obligations on high-risk systems.
Voluntary, for now
What high-risk means in practice
What to do in the next 12 months
Stay ahead in Asia’s tech landscape
This is premium content. Subscribe to read the full story.
Most AI governance frameworks that apply in Southeast Asia are voluntary, but some are mandatory. Confusing the two can cost you.
We know this is not ideal. ⌛ Sign up in 20 seconds. Cancel anytime.
Our subscriber community includes professionals from these companies:





Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.
