
By Hafiz Noer, Fellow at the Center for Digital Society Universitas Gadjah Mada, and M. Irfan Dwi Putra, Fellow at the Center for Digital Society Universitas Gadjah Mada
At a glance
- Regulatory Consolidation: Indonesia enters 2026 focusing on reinforcing existing digital policies, notably through pending Presidential Regulations on a National AI Roadmap and AI Ethics.
- Infrastructure Expansion: To support its booming digital economy, the country is aggressively expanding its data centre capacity, aiming to reach 1.65 GW by the end of 2026.
- A Balanced Governance Model: Rather than adopting the strict, sanctions-heavy approach of the EU AI Act, Indonesia is championing a flexible, risk-based framework tailored to the unique economic realities of emerging markets.
Share this insight
Indonesia’s technology governance and regulatory landscape entered 2026 in a state of consolidation. Building on the policy and regulatory foundations laid in 2025, this year is characterised by the reinforcement of existing commitments rather than the charting of new ones—exemplified by the anticipated enactment of Indonesia’s National AI Roadmap and AI Ethics into Presidential Regulations.
However, this shift should not be mistaken for stagnation. Significant incremental developments are underway to strengthen these commitments. This article explores Indonesia’s recent AI trajectory across three dimensions: updates to policy and regulation; complementary infrastructure and institutional initiatives; and how Indonesia’s framework positions the country within both the Southeast Asian and global AI governance landscapes.
Upcoming AI Regulations, Policy Priorities and Copyright Reform
Within the anticipated umbrella of two Presidential Regulations on the National AI Roadmap and AI Ethics, Indonesia is pursuing a compliance-by-design approach. This strategy integrates ethical principles and a risk-based lens directly into AI development and deployment, rather than treating them as external add-ons.
- The National AI Roadmap: Sets out strategic policy directions to develop the national AI ecosystem.
- The AI Ethics Draft: Focuses on an AI risk classification system modelled on the EU AI Act. It outlines the roles, responsibilities, risk mitigation strategies, and self-assessment obligations for developers, individual users, corporations, and government bodies alike.
Indonesia aims to adopt AI to support key government policy priorities, including the rollout of social aid and the national free meals program. Specifically, AI will be deployed to design local menus, monitor pantry hygiene, and determine cash transfer eligibility for low-income households.
While two Presidential Regulation drafts have been prepared to support this public sector AI adoption, both remain pending as of mid-2026 due to prolonged inter-ministerial coordination and stakeholder consultations. This delay leaves Indonesia temporarily without a legally binding, overarching AI framework.
For now, AI governance defaults to a patchwork of sector-specific ministerial regulations, private-sector guidelines, and fragmented existing legislation, such as the Electronic Information and Transactions (EIT) Law and the Personal Data Protection (PDP) Law. However, should alignment among government entities progress without further delays, both foundational regulations are expected to be enacted by the end of 2026.
Concurrently, recognising that AI—particularly Generative AI—is deeply intertwined with copyright issues, Indonesia is amending its Copyright Law. This amendment addresses the intersection of intellectual property and AI in two primary areas: the use of copyrighted works as training data for AI systems, and the copyright status of works created with AI assistance. These changes aim to provide legal certainty for AI training data through clear licensing requirements, while clarifying the limits of copyright protection for AI-assisted creations.
Data Centre Expansion and Institutional Consolidation
Beyond the regulatory track, Indonesia is investing heavily in the physical and institutional frameworks required to sustain long-term AI development. As the largest digital economy in the region, the country is advancing several key initiatives to support e-commerce, the financial technology sector, and integrated public service delivery:
1. Scaling National Data Capacity
Indonesia currently hosts 196 data centre facilities. As the largest digital economy in the region, these facilities are vital to supporting e-commerce operations, the financial technology sector, and integrated public service delivery via GovTech initiatives.
However, driven by the rapid adoption of AI prompting and accelerating online commerce, the country urgently requires both expanded capacity and more functionally diverse infrastructure. To meet this demand, the government aims to nearly triple its current data centre capacity from 600 MW to 1.65 GW by the end of 2026.
2. Anchoring Digital Hubs in Special Economic Zones (SEZs)
Rather than distributing infrastructure evenly across the archipelago, the government is concentrating development within SEZs capable of anchoring regional digital ecosystems.
- Nongsa Digital Park: Located in Batam—just a 40-minute ferry ride from Singapore—Nongsa has emerged as a strategic hotspot for data centre investment. It offers a cost-effective alternative for operators as Singapore tightens its own data centre regulations and faces supply-side constraints.
- The BBK Expansion: With Nongsa approaching peak capacity, Indonesia and Singapore are now exploring the broader Batam–Bintan–Karimun (BBK) region to capture future digital hub opportunities.
3. Incentivising Regional Connectivity
To attract high-quality infrastructure investment, the Indonesian government offers targeted fiscal and non-fiscal incentives, including tax holidays, simplified permitting processes, and import duty exemptions. While Jakarta ultimately aims to reduce its network reliance on Singapore by diversifying data routes, it pragmatically acknowledges Singapore’s prime position as a regional hub. Consequently, Indonesia is actively expanding regional infrastructure by tapping into the Singapore–Johor–Riau Islands growth triangle.
4. Overhauling Public Sector Digital Governance
Institutionally, Indonesia is consolidating its public sector digital architecture. The government is currently drafting a Presidential Regulation on Digital Government to transition the country away from its legacy Electronic-Based Government System (SPBE) toward a user-centric service delivery paradigm featuring standardised public procurement systems and data interoperability.
This regulatory shift has significant implications for AI’s institutional foundation. AI systems require large volumes of standardised, interoperable data to function—a requirement that is currently difficult to meet due to fragmented initiatives across ministries. By breaking down ministerial silos and standardising how the government procures and manages technology, the Digital Government Regulation is expected to lay the technical and institutional foundations necessary to support responsible AI deployment across public service delivery.
Positioning Indonesia within Regional and Global AI Governance
Indonesia occupies a distinctive position in regional and global AI governance, deliberately steering a “middle path” that seeks to balance robust risk management with pro-innovation flexibility.
This upcoming framework marks an intentional evolution in Indonesia’s regulatory strategy, shifting away from fragmented, non-binding guidelines toward a more structured national standard:
- Convergence with the ASEAN Spirit: At the normative level, Indonesia has embraced internationally recognised frameworks, including the ASEAN Guide on AI Governance and Ethics. This orientation is reflected in the Draft Presidential Regulation on AI Ethics, which incorporates principles such as inclusivity, human-centredness, safety, accessibility, and transparency. Furthermore, Indonesia is not adopting the European approach entirely; rather than imposing stringent compliance obligations and extensive enforcement mechanisms, the proposed framework places greater emphasis on self-assessment and voluntary compliance.
- Divergence through Formalisation: The upcoming AI regulations mark a clear shift from a predominantly soft and non-binding approach, as embodied in the 2023 Circular Letter on AI Ethics. Instead, Indonesia is moving toward a more structured, risk-based framework that draws inspiration from the tiered-risk model of the EU AI Act. By aiming to enact the National AI Roadmap and AI Ethics guidelines into Presidential Regulations, Indonesia is attempting to formalise what has largely been a patchwork, sector-driven governance landscape.
This hybrid stance—integrating European risk frameworks with regional flexibility—is a calculated response to Indonesia’s current domestic realities. Imposing a highly punitive, compliance-heavy regime would be virtually impossible to execute at this stage. Indonesia’s regulatory bodies are still developing the capacity needed to oversee AI advancement, while its digital infrastructure remains concentrated in urban areas, leaving the rest of the archipelago underserved. Furthermore, understanding of how AI should be used and governed remains limited across government, business, and civil society. Compounding these challenges is Indonesia’s heavy reliance on AI tools and cloud services from foreign technology providers, which limits the reach of national jurisdiction within a global supply chain. Consequently, a strict regulatory approach risks being overly ambitious yet ultimately unenforceable.
Challenges and Recommendations
While Indonesia’s flexible “middle path” successfully shields local innovation from regulatory suffocation, this compromise leaves the state facing immediate structural and operational hurdles.
The Rapidly Widening Technology Gap
Drafted in 2025, Indonesia’s foundational regulatory frameworks—namely the National AI Roadmap and the AI Ethics Guidelines—already risk leaving a regulatory vacuum in the face of rapid technological evolution. These emerging risks demand urgent legislative attention.
Today, regulators face severe blind spots driven by a three-dimensional crisis spanning shadow autonomy, shadow identities, and shadow code. These three crises exploit interconnected layers of AI development.
At the organisational layer, shadow autonomy leaves institutions unable to adequately monitor or audit the autonomous decisions their AI agents make. At the identity layer, shadow identities result in an institutional inability to verify the entities operating these AI agents. Finally, at the code layer, the pressure to use AI-generated code to accelerate public service delivery introduces hidden security risks. Public organisations often lack visibility into the integrity of the code they produce, creating vulnerabilities ripe for exploitation.
This multi-layered threat was starkly demonstrated in Australia’s “Robodebt” scandal, where an automated system used income-averaging calculations to determine welfare overpayments. Lacking human oversight, the system issued erroneous debt notifications to citizens with variable working hours. This scandal reflected all three crises simultaneously, underscoring the severe risks of algorithmic errors—a critical cautionary lesson for Indonesia as it aims to deploy AI for cash transfers.
These fast-evolving threats expose the limitations of Indonesia’s current legal toolkit, as neither the Electronic Information and Transactions (EIT) Law, the Personal Data Protection (PDP) Law, nor the upcoming Digital Government Regulations yet account for them. This gap, however, highlights a timely opportunity to integrate a “rolling review” mechanism. Mandating biennial or triennial assessments would ensure that existing regulatory frameworks remain responsive to upcoming threats without requiring a full legislative window for every overhaul.
2. Bureaucratic Friction and Alignment Gaps
Policy and regulatory alignment remain a profound operational challenge. As the technical regulatory lead, the Ministry of Communication and Digital Affairs bears the responsibility of streamlining AI governance, including coordinating standards, frameworks, and cross-ministerial implementations. However, this role has encountered institutional challenges as several provisions proposed under the regulation extend into areas that are traditionally regulated by other ministries and sectoral authorities. Establishing a multi-stakeholder task force consisting of ministries, private sectors, academia, media, and other relevant stakeholders, as mandated under the proposed Presidential Regulation, is therefore essential.
The urgency of this approach is further amplified by the rise of agentic AI that moves beyond simple prompt responses toward autonomous planning and execution—presents sophisticated threats, including advanced cyberespionage–that current frameworks are incapacitated to address these threats. In this context, sandbox functions as protected environments to test AI applications before deployment, and generating evidence-based inputs that regulators need to design adaptive regulations. Indonesia has already adopted sandboxes in health and financial technology sectors focusing on regulatory sandboxes for financial innovation and medical diagnosis, and technical innovation sandboxes for digital transactions. The extension of sandbox across high-risk sectors, particularly to counter agentic AI threats, would serve as a sensible path ahead.
3. Preparing AI-ready Civil Servants
In the upcoming Presidential Regulations, the Indonesian government positions AI as an enabler to accelerate its policy priorities. Achieving this ambition requires cohesive policy strategies, phased implementation, and a dedicated budget to equip civil servants with the skill sets necessary to execute priority programs with AI assistance.
Currently, upskilling programs remain sporadic. While a few ministries have initiated training programs in collaboration with global technology platforms—introducing civil servants to the logic of AI and its sectoral applications—these efforts are fragmented and insufficient. Bridging this gap requires a holistic, nationwide approach encompassing curriculum development, clear policy phases, measurable outcomes, and the integration of both practical and analytical AI skills.
Conclusion: A Blueprint for Evolving Economies
The first half of 2026 highlights Indonesia’s concerted efforts to consolidate its AI ecosystem through long-awaited umbrella legislation. The National AI Roadmap and AI Ethics Guidelines represent a major step toward formalising what has historically been a fragmented, sector-driven governance landscape.
If successfully enacted, this framework offers a unique opportunity for Indonesia to pioneer a more balanced, context-sensitive alternative to global AI governance. To date, international technology governance has been heavily shaped by Western models—most notably the EU, whose stringent approach has triggered the “Brussels Effect,” effectively forcing multinational corporations to adopt European standards globally to streamline compliance.
While these frameworks have significantly influenced international standards, they are rarely fully transferable to developing nations due to stark disparities in economic capacity, geopolitical positioning, institutional maturity, and technological readiness. By directly mitigating AI-related risks while actively encouraging innovation and digital growth, Indonesia can offer a highly practical reference blueprint for other evolving economies navigating identical challenges.
Nevertheless, the path ahead remains complex. Ratification delays, inter-ministerial coordination friction, and the relentless pace of AI risk developments collectively prove that legal instruments alone are insufficient. How successfully Indonesia navigates this consolidation phase will be carefully monitored—not just as a measure of its own digital maturity, but as a critical reference point for a Southeast Asian region still searching for its collective legal footing.
The views and recommendations expressed in this article, published in July 2026, are solely those of the authors and do not necessarily reflect the official views or position of the Tech for Good Institute.
