
By Keith Detros, Programme Manager and Duong Dinh, Programme Associate, Tech for Good Institute
At a glance
- Sovereignty as the Capacity to Govern: From Thailand’s locally developed LLM and Vietnam’s data infrastructure to Singapore’s assurance-based approach, countries are pursuing different forms of AI sovereignty. The emerging consensus is that sovereignty may depend less on owning the entire AI stack and more on having the capacity to govern it.
- Safety Beyond AI-Specific Rules: As AI becomes embedded across products, services, and decisions, countries are strengthening not only AI-specific governance but also existing frameworks for cybersecurity, data protection, and consumer protection. Risk-based approaches, human oversight, and assurance are emerging as key elements of responsible adoption.
- Skilling as the Foundation for Adoption: Responsible AI adoption requires more than developing new talent. Mid-career upskilling, enterprise support, and public-sector capacity building are equally important to ensuring that workers, businesses, and governments can use AI effectively. Regional cooperation, including through ASEAN DEFA, could help turn these national priorities into shared capabilities.
Share this insight
Artificial intelligence (AI) is embedded in how people work, communicate, and make decisions in Southeast Asia. According to a 2026 report by Singapore’s Economic Development Board, nearly half of Southeast Asian companies surveyed have already moved beyond AI pilots into deployment. On the consumer side, adoption has moved just as fast. Around 79% of Southeast Asian workers reported using AI in 2025, and over two-fifths have folded these tools into both their personal and professional lives.
These statistics underscore the strong momentum of AI innovation and adoption across the region. For policymakers, the central challenge is balancing these rapid adoption rates with the corresponding risks AI may potentially bring. The Tech for Good Institute’s Evolution of Tech Governance in Southeast Asia-6 initiative has tracked how the region is navigating this evolving landscape.
In the first half of 2026, we convened six roundtables bringing together government, industry, academia, and policy researchers across Southeast Asia. Three issues emerged as top-of-mind for the region’s next phase of AI governance: sovereignty, safety, and skilling.
The Sovereignty Debate
AI sovereignty is one of the key policy areas Southeast Asia is grappling with. However, there is no consensus on what it actually means. During the discussions, AI sovereignty meant different things across different countries, or even to different stakeholders within the same country. These different versions of sovereignty come from a deeper question: How should a country control its own AI future?
In Thailand, for example, the country is making a case for sovereignty by building its own large language model. The ThaiLLM, which was launched in April 2026, focuses on nuances of the Thai language, local dialects, and unique cultural contexts. On the other hand, in Vietnam, sovereignty takes on a different form by focusing on control over data through a National Data Centre. Another version of sovereignty is in the Philippines, where the discussion is about supply chains and infrastructure, playing out through the new economic zone proposed under Pax Silica for chip manufacturing and data centres. Finally, in Singapore, it means a model built on assurance. This sovereignty-by-assurance approach focuses on resilience and audit trails rather than ownership or localisation.
The various models of sovereignty encompasses different parts of the AI tech stack. From models, data, infrastructure, and even AI governance, countries in the region are trying to ensure that they can properly shape a part of a foundational technology such as AI. However, there is a growing recognition that no single country can control the entire tech stack domestically. One of our roundtables offered a useful reframe. Rather than looking at what a country owns, sovereignty should mean the capacity to govern.
This is where a version of “managed interdependence” may need to be operationalised. Countries in Southeast Asia need to have strategic alliances and partnerships to mitigate the risks throughout the AI stack. If done properly, the domestic national interests and interoperability will not be competing pursuits, but rather an essential part of creating a resilient AI ecosystem.
The Safety Imperative
Aside from sovereignty, safety is considered as another top-of-mind issue for policymakers. As earlier noted, AI is becoming more integrated into various products, services, and decision-making processes in the region. This rapid adoption has heightened the risks associated with consumer protection, personal data, and online safety, as these threats have evolved and now operate across borders on a larger scale.
To address safety concerns, stakeholders prioritise not only introducing new laws but also updating existing ones which are core to the digital economy. While AI-specific governance measures can address issues such as risk classification, accountability, assurance, and liability, there is a trend of updating foundational laws on cybersecurity, data protection, and consumer protection to be responsive to the new realities of the AI age. Indonesia, for example, is strengthening its personal data protection framework, while Vietnam has enacted the 2025 Law on Cybersecurity in response to the rapid development and application of digital technologies, closing gaps in the country’s existing legal framework.
For AI specific laws, Malaysia focuses on trust and the ethical use of AI, signalling that safety is being treated as a condition for adoption. The same principle is expected to be reflected in the upcoming AI Governance Bill. Meanwhile, Vietnam has adopted AI Law that embedded safety considerations through a risk-based approach together with requirements of human oversight.
Singapore has taken a more operational route, releasing its Updated Model AI Governance Framework for Agentic AI in May 2026. The updated guideline includes case studies on responsible agent deployment and recommends technical and non-technical measures to mitigate risk.
The Skilling Gap
Finally, skilling keeps surfacing as the actual constraint on responsible AI adoption.
One of the key concerns comes from the Philippines, where an IMF working paper found that one-third of occupations in the country are highly exposed to AI. In addition, there were concerns that much of the conversation about skilling centres around the talent pipeline (e.g. how schools and training institutions prepare new workers). The more pressing issue, however, is who upskills the current workforce. Stakeholders noted that mid-career upskilling and reskilling and lifelong learning are key areas of focus for AI skilling.
Singapore’s approach is not just about workers either. Rather, part of the AI conversation is enterprise adoption, including that of SMEs, which make up 99% of enterprises in the country. The government’s Enterprise Compute Initiative has set aside S$150 million to pair local firms with cloud providers, giving them access to AI tools, cloud credits, and consultancy support to build a working product. A parallel National AI Impact Programme aims to move 10,000 enterprises up the AI-adoption curve.
Indonesia extends this even further, by emphasising not only individuals and enterprises, but also the regulators who will be creating policy. Public sector adoption of AI remains at an early stage, and institutional capacity is identified as one area of growth for the country. Efforts to develop a national AI talent ecosystem are already in place, such as the AI Talent Factory (AITF) – an initiative designed to support students who will become future AI practitioners through exposure to the real world environment and hands-on experience in AI engineering. At the institutional level , foundational mechanisms such as data interoperability remain limited even within single ministries, where definitions and ownership of data can vary across directorates. The ideal outcome is for capability development to run in parallel, in both the wider economy and the government agencies at the same time.
Turning National Priorities into Regional Cooperation
Sovereignty, safety, and skilling are not separate tracks of AI governance. They are the same conversation, seen from three different angles. Domestically, these priorities are deeply connected as sovereignty builds resilience, safety reinforces trust, and skilling determines whether adoption can scale.
None of these issues are contained within national borders. A large language model trained in one country can be deployed in another. A scam enabled by generative AI in one market can target victims across the region. A skills gap, including in policy implementation, in one economy limits how far the region can go, because interoperability is only as strong as its weakest link.
This is precisely where regional instruments such as the upcoming ASEAN Digital Economy Framework Agreement becomes pivotal. Due to be signed in November 2026, DEFA is another test of whether the region can capitalise on shared priorities. Building on the top-of-mind issues raised in our national roundtables, the true test for DEFA is moving beyond domestic alignment. What remains to be seen is if DEFA can help transform the issues of sovereignty, safety, and skilling from national concerns into the functional cornerstone of regional cooperation.
