
Indonesia remains as Southeast Asia’s largest digital economy, and its growth trajectory further underscores the necessity for effective governance of emerging technologies. The digital economy of the country is anticipated to account for 20.7% of GDP by the year 2045. The swift adoption of AI is driving this growth, with a notable increase in uptake during the mid-2020s and the emergence of generative AI applications across sectors such as commerce, finance, health, and education, though the level of integration and development varies significantly.
Sustaining growth at this scale necessitates a governance infrastructure that can effectively manage the associated risks and complexities. Multiple instruments are converging simultaneously: Indonesia’s Personal Data Protection (PDP) Law, currently in effect but dependent on secondary regulations for complete implementation; ongoing efforts regarding high-level AI regulation; and the ASEAN Digital Economy Framework Agreement (DEFA), which has recently concluded its negotiations in May 2026. In each instance, the fundamental principles of the framework are predominantly established, whereas the specific details will be outlined through implementing regulations, technical standards, and roadmaps that are currently in the development phase.
Moderators and Speakers
- Theodore Sutarto, Deputy Assistant for Digital Economy, Coordinating Ministry for Economic Affairs of the Republic of Indonesia
- Muhammad Faisal, Head of Partnerships and Investment Ecosystems, Ministry of Communication and Digital Affairs of the Republic of Indonesia
- Prayoga Wiradisuria, Director of Policy and Program, Indonesian Business Council
- Hafiz Noer, Expert, Faculty of Social and Political Science, Universitas Gadjah Mada
- Andreas Tjendra, Director of AI Innovation, Korika
- Angga Airlangga, Head of Government and Regulatory Affairs, IBM
- Citra Nasruddin, Programme Director of the Tech for Good Institute
- Keith Detros, Programme Manager, Tech for Good Institute
Key Takeaways
- Implementation should be coherent and proportionate
Indonesia’s recent initiatives in digital and AI governance have established a significant foundation. Key framework instruments are converging simultaneously: DEFA negotiations have been recently concluded, with a signing anticipated in later this year. The draft Presidential Regulation on AI is undergoing review at the presidential level, and the PDP Law is already in effect. Participants observed that although numerous framework principles are now widely accepted, the pressing challenge has transitioned to the specifics of operational detail and implementation. For DEFA, for example, negotiating it proved to be a challenging endeavour. Implementing it throughout ASEAN, particularly for members with more limited digital capabilities, is likely to be even more challenging. This will require sustained capacity-building and strategic partnerships.
In recent years, Indonesia has introduced a large volume of new regulations, while the current regulatory frameworks continue to be predominantly structured around traditional sectors. Participants emphasised that meaningful governance improvements will arise more from clear, coherent, and coordinated rules rather than from adding new legislations. The upcoming Presidential Regulation on AI is anticipated to be pivotal in offering a framework that can support sectoral and subnational regulations while minimising redundancy among ministries. For the industry, the primary request is for a framework that harmonises innovation with oversight while preventing conflicting standards across domestic, regional, and international regimes.
- Public sector capability matters as much as private sector adoption
Participants observed that interest and experimentation with AI and generative AI are spreading rapidly across Indonesia’s economy, including among enterprises, even though enterprise-grade AI deployment remains relatively limited. By contrast, public sector adoption is still at an early stage. While there are promising use cases, such as digitalisation in social services that has already generated substantial fiscal savings, government capabilities to scope AI use cases and integrate them into core workflows are still developing and remain uneven across institutions. As AI becomes more deeply embedded across the economy, participants stressed that building government capability, both to use these tools responsibly and to regulate them credibly is as important as private-sector momentum.
Institutional capacity emerged as a binding constraint. Data interoperability remains limited even within single ministries, where definitions and ownership of data can vary across directorates. Across agencies, data sharing often relies on bilateral, ad hoc arrangements rather than established protocols and taxonomies. Participants highlighted that strengthening public sector readiness will require investment not only in personnel, but also in technical expertise, clear data taxonomies and sharing standards, and structured cross-agency coordination. This serves as the foundation upon which credible public sector AI utilisation and effective regulation both rely.
- Effective governance requires practical tools and co-creation, not legislation alone
Establishing framework laws is crucial; however, it alone does not ensure effective governance. Participants stressed that translating high‑level principles into workable rules requires sustained collaboration between government, industry, technology practitioners, and research institutions. This should be integrated as an ongoing process rather than a one‑off consultation. There was strong support for engaging a broader set of stakeholders beyond the ministry-only working groups of previous years, with private sector and research institutes participating from the beginning of the design process.
Several practical instruments emerged as shared priorities. Regulatory sandboxes were highlighted as one of the efficient practical tools available, serving as ongoing, collaborative mechanisms that enable government and enterprises to jointly test use cases, manage risk, and refine rules before committing to enforceable mandates. Participants also pointed to interoperability, both within government and across borders, as well as the adoption of existing technical standards, including industrial and cryptographic standards. Throughout the discussion, emphasis was placed on the principle of proportionality where obligations should be tailored to ensure that smaller enterprises, which constitute the vast majority of the economy, are not burdened by compliance requirements intended for larger organisations
