กฎหมาย AI ของไทยกำลังจะมา — องค์กรขนาดกลางต้องเตรียมอะไรจริง ๆ (ฉบับคนไม่ใช่นักกฎหมาย)Thailand's AI Law Is Coming — What a Mid-Sized Organisation Actually Needs to Prepare, Without a Law Degree
อัปเดตล่าสุด 2026-09-16Last updated 2026-09-16
สิ่งที่กฎหมายจะขอดู คือสิ่งที่องค์กรที่ใช้ AI อย่างรับผิดชอบควรมีอยู่แล้ว — ถ้ายังไม่มี วันนี้คือวันที่ถูกที่สุดที่จะเริ่มWhat the law will ask to see is what a responsible organisation should already have in place — and if you do not have it yet, today is the cheapest day to start.
เรื่องมักเริ่มจากผู้บริหารอ่านข่าวเรื่องกฎหมาย AI มาสักชิ้น แล้วส่งต่อมาให้ฝ่ายบุคคลหรือฝ่ายไอทีว่า "เตรียมองค์กรให้พร้อมรับกฎหมายนี้หน่อย" คนที่รับโจทย์ไปเปิดหาในกูเกิล เจอข่าวประกาศจากหน่วยงานต่าง ๆ บทวิเคราะห์จากที่ปรึกษากฎหมาย และโพสต์ที่พูดถึงมาตรานั้นมาตรานี้ที่ยังร่างไม่เสร็จด้วยซ้ำ ทุกหน้าเขียนถึงคนที่รู้กฎหมายอยู่แล้ว ไม่มีหน้าไหนบอกตรง ๆ ว่าวันจันทร์นี้ต้องเดินไปคุยกับใคร ต้องถามอะไร และต้องแก้อะไรก่อนIt usually starts with management reading a news story about an AI law and passing it down to HR or IT with "get us ready for this." Whoever picks it up searches online and finds announcements, law-firm briefings, and posts arguing over article numbers in a draft that is not even finished. Every page is written for someone who already knows the law. None of them says plainly who to go talk to this Monday, what to ask, and what to fix first.
หน้านี้ไม่พูดถึงชื่อหน่วยงาน ไม่อ้างมาตรา ไม่เดาวันบังคับใช้ เพราะเรื่องพวกนี้ยังไม่นิ่งและอาจเปลี่ยนได้จนถึงวันสุดท้าย สิ่งที่หน้านี้ทำแทนคือพาไล่ดูว่าองค์กรของคุณกำลังใช้ AI ที่ไหนบ้างจริง ๆ แม้แต่ที่ไม่เป็นทางการ จุดไหนที่กระทบสิทธิ์หรือโอกาสของคนควรมีคนรับผิดชอบชัดเจน และมีอะไรที่ควรวางไว้ตั้งแต่วันนี้โดยไม่ต้องรอให้ร่างกฎหมายเสร็จก่อน เพราะไม่ว่าฉบับสุดท้ายจะหน้าตาแบบไหน องค์กรที่มีพื้นฐานห้าข้อนี้อยู่แล้วจะไม่ต้องวิ่งหาคำตอบตอนกฎหมายประกาศจริงThis page does not name any agency, cite any article number, or guess an effective date — those things are unsettled and could still change up to the final text. What it does instead is walk through where your organisation is actually using AI, including unofficially, which of those uses touch a person's rights or opportunities and need a clear owner, and what is worth putting in place today without waiting for the draft to finish. Whatever the final text looks like, an organisation with these five basics already in place will not be scrambling for answers the day it is announced.
สรุปสั้นTL;DR
ร่างกฎหมาย AI ของไทยยังไม่นิ่งทั้งรายละเอียดและกำหนดเวลา แต่แนวทางกว้าง ๆ ของร่างที่เผยแพร่แล้วเดินตามทิศทางสากล คือแบ่งการใช้งานตามระดับความเสี่ยง จำกัดการใช้บางประเภท เพิ่มภาระหน้าที่ให้การใช้งานความเสี่ยงสูง และขอความโปร่งใสเมื่อเนื้อหาที่ AI สร้างอาจทำให้คนเข้าใจผิด หน้านี้ไม่เดาวันบังคับใช้และไม่อ้างชื่อหน่วยงานหรือมาตราใด แต่พาองค์กรของคุณทำสิ่งที่ทำได้จริงตอนนี้ คือสำรวจว่า AI ถูกใช้ที่ไหนบ้าง ระบุจุดที่กระทบสิทธิ์หรือโอกาสของคน ตั้งเจ้าของที่รับผิดชอบชัดเจน และวางนโยบายที่มีคนดูแลจริง พร้อมแบบสำรวจการใช้ AI ที่ก๊อปไปใช้ได้ทันทีและตารางเทียบสามท่าทีThailand's draft AI law is unsettled in both detail and timing, but the broad direction of the drafts published so far follows the international pattern — classifying uses by risk level, restricting certain uses, adding duties for high-risk uses, and asking for transparency where AI-generated content could mislead. This page does not guess an effective date and does not name any agency or article. Instead it walks your organisation through what is actually doable now: inventorying where AI is used, identifying the uses that touch a person's rights or opportunities, naming a clear owner for each, and putting a policy in place that someone actually maintains — with a copyable AI-use inventory template and a table comparing three postures.
หน้านี้เขียนให้ใครWho This Page Is For
สามคนนี้มักเป็นคนที่ต้องรับมือกับเรื่องนี้ในองค์กร ไม่ว่าจะเต็มใจหรือไม่ก็ตามThese three people usually end up handling this inside an organisation, whether they wanted to or not.
ฝ่ายบุคคลหรือแอดมินที่ถูกสั่งให้ "ทำให้องค์กรพร้อม"The HR or admin head told to "get us ready"
คุณได้รับมอบหมายให้เตรียมองค์กรรับกฎหมายที่ยังไม่ออก โดยไม่มีใครบอกว่าต้องเริ่มจากตรงไหน หน้านี้ให้จุดเริ่มต้นที่ทำได้จริงวันนี้ ไม่ใช่รายการรอข่าวประกาศYou were handed the task of preparing the organisation for a law that has not been finalised, with nobody telling you where to start. This page gives you a starting point you can act on today, not a list of things to wait on a news announcement for.
เจ้าของกิจการที่คิดว่าเรื่องนี้เกี่ยวกับบริษัทเทคโนโลยีเท่านั้นThe owner who thinks this only applies to tech companies
คุณอาจคิดว่าเพราะบริษัทไม่ได้สร้าง AI เอง เรื่องนี้จึงไม่เกี่ยวกับธุรกิจของคุณ ส่วนที่ 3 และ 4 ของหน้านี้อธิบายว่าทำไมความคิดนี้พลาดตรงไหน และทำไมการใช้เครื่องมือ AI สำเร็จรูปก็นับเป็นการใช้งานที่ต้องดูแลYou may assume that because your company does not build AI, none of this applies to you. Sections 3 and 4 below explain exactly where that assumption breaks down, and why using an off-the-shelf AI tool still counts as a use that needs governing.
หัวหน้าแผนกที่ใช้ AI ช่วยคัดคนหรือให้เครดิตอยู่แล้วThe department head already using AI for hiring, credit, or pricing
ถ้าทีมของคุณใช้ AI ช่วยคัดกรองใบสมัคร ประเมินเครดิต ตั้งราคาเฉพาะบุคคล หรือเรื่องที่เกี่ยวกับความปลอดภัย คุณคือคนที่กรอบกฎหมายนี้ใช้กับคุณมากที่สุด หน้านี้เขียนขึ้นมาเพื่อให้คุณรู้ว่าต้องตรวจอะไรก่อนใครIf your team already uses AI to screen applicants, assess credit, price individual customers, or handle anything safety-related, you are the reader this framework applies to most directly. This page tells you what to check first.
องค์กรต้องเตรียมอะไรจริง ๆWhat does an organisation actually need to prepare?
คำตอบตรงไปตรงมาคือ ไม่ต้องรอให้กฎหมายออกก่อนแล้วค่อยเริ่ม เพราะสิ่งที่กฎหมายแทบทุกฉบับในทิศทางนี้จะขอดู คือสิ่งที่องค์กรที่ใช้ AI อย่างรับผิดชอบควรมีอยู่แล้วไม่ว่ามีกฎหมายหรือไม่ ต่อไปนี้คือหกข้อที่เราเห็นว่าเป็นจุดเริ่มต้นที่ใช้ได้จริงในองค์กรที่เราอบรมThe honest answer is that you do not need to wait for the law before starting, because what nearly every framework in this direction asks to see is what a responsible AI-using organisation should already have, law or no law. The following six points are what we have seen work as a genuine starting point in the organisations we train.
หกข้อที่องค์กรควรตอบได้Six things your organisation should be able to answer
- รู้ว่า AI ถูกใช้ที่ไหนในองค์กรจริง ๆ — รวมถึงที่ใช้กันเองแบบไม่เป็นทางการ องค์กรส่วนใหญ่ที่เราคุยด้วยตอบคำถามนี้ไม่ได้ครบ เพราะแผนกต่าง ๆ ใช้เครื่องมือกันเองโดยไม่มีใครรวบรวมKnow where AI is actually being used across the organisation — including unofficial use. Most organisations we talk to cannot fully answer this, because individual teams adopt tools on their own with nobody consolidating the picture.
- แยกให้ออกว่าการใช้งานไหนกระทบสิทธิ์หรือโอกาสของคน — เช่น การจ้างงาน วินัยพนักงาน การให้เครดิต การตั้งราคาเฉพาะบุคคล หรือเรื่องที่เกี่ยวกับความปลอดภัย เพราะกรอบความเสี่ยงแทบทุกฉบับที่ใช้ในทิศทางสากลจัดการใช้งานกลุ่มนี้เป็นความเสี่ยงสูงเหมือนกันIdentify the uses that touch a person's rights or opportunities — hiring, employee discipline, credit, pricing to individuals, anything safety-related. Nearly every risk-based framework internationally treats this group of uses as high-risk.
- ระบุได้ว่ามีคนคนหนึ่งรับผิดชอบต่อการใช้งานความเสี่ยงสูงแต่ละจุด — ไม่ใช่ "ฝ่าย" หรือ "ทีม" ลอย ๆ แต่เป็นคนที่ระบุชื่อได้และตอบคำถามแทนได้จริงเมื่อมีคนถามBe able to show a human is accountable for each high-risk use — not a vague "department" or "team," but one named person who can actually answer for it when asked.
- อธิบายให้ลูกค้าหรือพนักงานฟังได้ เมื่อ AI มีส่วนในเรื่องที่กระทบเขา — ไม่ต้องอธิบายทุกครั้งที่ AI ช่วยแค่ร่างเบื้องต้น แต่ต้องอธิบายได้เมื่อ AI มีผลจริงต่อสิ่งที่เกิดขึ้นกับเขาBe able to explain to a customer or employee when AI was involved in something that affected them — not every time AI touched a first draft, but whenever it genuinely shaped what happened to them.
- เก็บบันทึกที่ย้อนดูได้ว่า AI ทำอะไรไปบ้าง — เพียงพอให้สร้างเรื่องราวย้อนหลังได้ว่าระบบตัดสินใจหรือแนะนำอะไร บนข้อมูลอะไร และใครเป็นคนตรวจก่อนนำไปใช้จริงKeep records that let you reconstruct what the AI did — enough to trace back what it decided or recommended, on what input, and who checked it before it was acted on.
- มีนโยบายที่มีเจ้าของจริง ไม่ใช่เอกสารที่เขียนไว้แล้วไม่มีใครดูแล — ถ้ายังไม่มี อ่านต่อได้ที่ นโยบายการใช้ AI ในองค์กร ฉบับใช้ได้จริง ซึ่งให้โครงร่างนโยบาย 8 ข้อที่ก๊อปไปปรับใช้ได้ทันทีHave a policy someone actually owns — not a document written once and left unmaintained. If you do not have one yet, see An AI Use Policy Your Organisation Can Actually Apply, which gives eight ready-to-copy clauses.
ทั้งหกข้อนี้ไม่ได้อ้างอิงมาตราหรือหน่วยงานใดโดยเฉพาะ เพราะทำได้และมีประโยชน์อยู่แล้วไม่ว่าฉบับสุดท้ายของกฎหมายจะหน้าตาแบบไหนNone of these six depend on any specific article or agency — they are worth doing regardless of what the final text ends up saying.
ที่คนเข้าใจผิด กับที่เป็นจริงWhat People Get Wrong, and What Is Actually True
ความเชื่อห้าข้อนี้พบบ่อยที่สุดในห้องประชุมที่กำลังคุยเรื่องกฎหมาย AI แต่ละข้อมีเหตุผลรองรับอยู่บ้าง ไม่ใช่ความเชื่อที่ไร้สาระ เพียงแต่พลาดตรงจุดที่สำคัญที่สุดThese five beliefs come up most often in meetings discussing the AI law. Each has some reasoning behind it — none is a straw man — but each misses the point that matters most.
ความเชื่อ: ใช้กับบริษัทเทคโนโลยีเท่านั้นBelief: this only applies to technology companies
ความจริง กรอบความเสี่ยงในทิศทางสากลที่ร่างกฎหมายไทยเดินตามอยู่มองที่การใช้งาน ไม่ได้มองที่ว่าใครสร้างเครื่องมือ โรงงาน ร้านค้าปลีก หรือบริษัทประกันที่ใช้ AI ช่วยคัดกรองคนหรือให้เครดิต ก็อยู่ในข่ายเดียวกับบริษัทที่พัฒนาโมเดลขึ้นเองReality: the international-pattern risk frameworks that Thailand's draft follows look at use, not at who built the tool. A factory, a retailer, or an insurer using AI to screen applicants or assess credit falls into the same category as a company that builds its own models.
ความเชื่อ: รอกฎหมายออกก่อนค่อยทำBelief: wait for the law to be finalised before doing anything
ความจริง พื้นฐานหกข้อในส่วนที่ 3 ไม่ได้ขึ้นกับว่ากฎหมายจะออกมาหน้าตาแบบไหน การรอทำให้เสียเวลาที่ควรใช้สำรวจและจัดระเบียบภายในไปเปล่า ๆ แล้วพอกฎหมายประกาศจริงก็ต้องเร่งทำทุกอย่างพร้อมกันในเวลาสั้น ๆReality: the six basics in section 3 do not depend on what the final text says. Waiting only wastes time that could go toward internal inventory and housekeeping — and when the law is finally announced, you end up rushing everything at once in a short window.
ความเชื่อ: ใช้แค่ ChatGPT ไม่ได้สร้าง AI เอง ไม่เกี่ยวBelief: we only use ChatGPT, we don't build AI ourselves, so this doesn't apply
ความจริง กรอบเหล่านี้ว่าด้วยการใช้งาน ไม่ใช่การสร้าง การใช้เครื่องมือสำเร็จรูปช่วยคัดกรองใบสมัครงานก็คือการใช้งานหนึ่ง ไม่ว่าเครื่องมือนั้นองค์กรจะพัฒนาเองหรือซื้อบริการมาใช้Reality: these frameworks are about use, not about building. Using an off-the-shelf tool to screen job candidates is itself a use, regardless of whether the organisation built the tool or simply subscribed to it.
ความเชื่อ: ทำ PDPA แล้ว เท่ากับพร้อมBelief: we've done our PDPA groundwork, so we're ready
ความจริง ถูกบางส่วน งานด้าน PDPA คือกฎหมายคุ้มครองข้อมูลส่วนบุคคล ช่วยได้จริงเพราะทำให้องค์กรรู้อยู่แล้วว่าเก็บข้อมูลอะไรและใครเข้าถึงได้ แต่ PDPA คุ้มครองข้อมูล ไม่ได้ครอบคลุมการตัดสินใจ องค์กรที่ทำ PDPA ครบแล้วยังต้องกลับมาไล่ดูว่า AI ตัวไหนกำลังตัดสินใจหรือช่วยตัดสินใจแทนคนอยู่บ้างReality: partly right. PDPA groundwork — Thailand's personal data protection law — genuinely helps, because it means the organisation already knows what data it holds and who can access it. But PDPA covers data, not decisions. An organisation with PDPA fully in place still needs to go back and map which AI systems are making or shaping decisions about people.
ความเชื่อ: ต้องจ้างที่ปรึกษาราคาแพงถึงจะพร้อมBelief: you need to hire expensive consultants before you can be ready
ความจริง พื้นฐานห้าข้อที่ส่วนที่ 5 พูดถึง เป็นงานทำความสะอาดบ้านภายในที่ทีมเดิมทำเองได้ในหนึ่งบ่ายวัน ไม่ต้องจ้างใคร ที่ปรึกษาหรือทนายความมีประโยชน์มากที่สุดเมื่อระบุได้แล้วว่าการใช้งานจุดไหนเป็นความเสี่ยงสูงจริง แล้วต้องการความเห็นเฉพาะจุดสำหรับกรณีนั้น ไม่ใช่ตั้งแต่วันแรกReality: the five basics in section 5 are internal housekeeping an existing team can do in one afternoon, no hiring required. A consultant or lawyer is most useful once you have already identified a genuinely high-risk use and need a specific opinion on that case — not from day one.
เริ่มเตรียมองค์กรได้วันนี้ — 5 ขั้นตอนStart Preparing Today — 5 Steps
ห้าขั้นตอนนี้ทำได้เองโดยไม่ต้องจ้างใคร งานสองขั้นแรกทำได้ในบ่ายเดียว ถ้าทำครบทั้งห้าข้อ คุณจะมีภาพชัดว่า AI ถูกใช้ที่ไหนบ้างในองค์กร และรู้ว่าจุดไหนต้องดูแลเป็นพิเศษ ไม่ใช่แค่รอฟังข่าวThese five steps can be done in-house without hiring anyone — the first two fit into a single afternoon. Complete all five and you will have a clear picture of where AI is used across your organisation and which points need extra care, instead of just waiting for news.
สำรวจการใช้ AI ทั้งองค์กรในหนึ่งบ่ายวันInventory AI use across the organisation in one afternoon
ถามทุกแผนกตรง ๆ ว่าใช้เครื่องมือ AI อะไรอยู่บ้าง รวมถึงที่ใช้กันเองแบบไม่เป็นทางการ ใช้แบบสำรวจในส่วนที่ 6 เป็นจุดเริ่มต้นAsk every department directly what AI tools they actually use, including unofficial ones. Use the template in section 6 below as your starting point.
ติดป้ายแต่ละรายการว่ากระทบคนหรือไม่Tag each use by whether it affects a person
ใช้แบบทดสอบสี่คำถามในส่วนที่ 6 ตรวจแต่ละรายการในตาราง ว่ากระทบงาน เงิน ความปลอดภัย หรือสิทธิ์ทางกฎหมายของใครบ้างหรือไม่Run every row through the four-question test in section 6 — does it affect someone's job, money, safety, or legal position.
ตั้งชื่อเจ้าของรายบุคคลสำหรับทุกการใช้งานความเสี่ยงสูงName an owner per high-risk use
ทุกแถวที่ติดป้ายว่ากระทบคน ต้องมีชื่อพนักงานหนึ่งคนกำกับไว้ในช่อง "ใครรับผิดชอบ" ไม่ใช่ชื่อแผนกEvery row tagged as affecting a person needs one named employee in the "who is accountable" column — not a department name.
เขียนหนึ่งย่อหน้าอธิบายว่ามนุษย์ตรวจการใช้งานความเสี่ยงสูงแต่ละจุดอย่างไรWrite one paragraph per high-risk use explaining how a human checks it
ไม่ต้องยาว แค่พอให้คนนอกอ่านแล้วเข้าใจว่าก่อนผลจาก AI จะถูกนำไปใช้จริง มีขั้นตอนตรวจของมนุษย์ตรงไหนบ้างIt does not need to be long — just enough that an outsider reading it understands where the human check happens before the AI's output is acted on.
ตั้งวันทบทวนที่ชัดเจนSet a review date
ทั้งเครื่องมือ AI ที่องค์กรใช้และร่างกฎหมายเองเปลี่ยนเร็วตลอดเวลา แบบสำรวจที่ทำวันนี้ต้องมีวันกลับมาอัปเดตที่แน่นอน ไม่ใช่ทำครั้งเดียวแล้วเก็บเข้าลิ้นชักBoth the AI tools your organisation uses and the draft law itself keep changing. Today's inventory needs a firm date to be revisited — not a one-off exercise filed away and forgotten.
แบบสำรวจการใช้ AI ในองค์กร — ก๊อปไปใช้ได้ทันทีThe AI-Use Inventory — Copy It Right Now
ตารางด้านล่างนี้คือแบบสำรวจที่คัดลอกไปวางในสเปรดชีตของคุณได้ทันที แจกไปให้ทุกหัวหน้าแผนกกรอกแถวของตัวเอง เราใส่ตัวอย่างสี่แถวไว้ให้ดูว่ากรอกแบบไหน คัดลอกและปรับให้ตรงกับงานจริงขององค์กรคุณคือสิ่งที่หน้านี้ตั้งใจให้ทำThe table below is a template you can paste straight into your own spreadsheet. Hand it to every department head to fill in their own rows. We have pre-filled four example rows to show how it works — copying and adapting it to your own real work is exactly what this section is for.
| งาน/แผนกTask / department | เครื่องมือTool | ใช้ทำอะไรWhat it's used for | กระทบสิทธิ์หรือโอกาสของบุคคลไหมAffects a person's rights or opportunities? | ใครตรวจWho checks it | ใครรับผิดชอบWho is accountable |
|---|---|---|---|---|---|
| คัดกรองใบสมัครงาน / ฝ่ายบุคคลRésumé screening / HR | เครื่องมือสรุปเรซูเม่สำเร็จรูปOff-the-shelf résumé summariser | สรุปประวัติผู้สมัครก่อนส่งให้หัวหน้างานอ่านSummarises candidate history before it reaches the hiring manager | ใช่ — กระทบโอกาสได้งานYes — affects a job opportunity | หัวหน้างานที่จ้าง อ่านประวัติเต็มก่อนตัดสินHiring manager reads the full résumé before deciding | หัวหน้าฝ่ายบุคคลHead of HR |
| ตั้งราคาเสนอลูกค้ารายบุคคล / ฝ่ายขายIndividual customer pricing / Sales | โมเดลแนะนำราคาภายในInternal price-recommendation model | แนะนำส่วนลดตามประวัติการซื้อของลูกค้าแต่ละรายSuggests a discount based on each customer's purchase history | ใช่ — กระทบราคาที่บุคคลนั้นต้องจ่ายYes — affects the price that specific person pays | หัวหน้าฝ่ายขายอนุมัติก่อนเสนอราคาจริงSales manager approves before the quote is sent | หัวหน้าฝ่ายขายHead of Sales |
| ร่างโพสต์การตลาด / ฝ่ายการตลาดMarketing copy drafts / Marketing | แชตบอตช่วยเขียนทั่วไปGeneral-purpose writing chatbot | ร่างแรกของโพสต์และคำบรรยายภาพFirst drafts of posts and captions | ไม่ — เป็นแค่ร่างที่คนแก้เองก่อนเผยแพร่No — just a draft a person edits before publishing | เจ้าของโพสต์ตรวจก่อนกดเผยแพร่ทุกครั้งPost owner reviews before every publish | หัวหน้าฝ่ายการตลาดHead of Marketing |
| ตรวจจับความผิดปกติหน้างาน / โรงงานAnomaly detection on the floor / Plant | ระบบเซ็นเซอร์แจ้งเตือนอัตโนมัติAutomated sensor-alert system | แจ้งเตือนเมื่อค่าที่วัดได้ผิดปกติจากช่วงปกติFlags readings that fall outside the normal range | ใช่ — เกี่ยวข้องกับความปลอดภัยหน้างานYes — safety-related on the floor | หัวหน้ากะตรวจสอบทุกครั้งที่มีการแจ้งเตือนShift supervisor checks every alert | หัวหน้าฝ่ายความปลอดภัยHead of Safety |
แบบทดสอบสี่คำถามว่าอะไรคือ "ความเสี่ยงสูง"The four-question test for "high-risk"
ถ้าตอบ "ใช่" ข้อใดข้อหนึ่งด้านล่าง ให้ติดป้ายรายการนั้นว่ากระทบคน และต้องมีเจ้าของรับผิดชอบชัดเจนตามขั้นตอนที่ 3 ในส่วนก่อนหน้าIf the answer to any one of these is yes, tag that row as affecting a person, and it needs a clear accountable owner per step 3 above.
- การใช้งานนี้กระทบงานของใครไหม เช่น การจ้าง การเลื่อนตำแหน่ง หรือวินัยพนักงานDoes it affect someone's job — hiring, promotion, or discipline?
- การใช้งานนี้กระทบเงินของใครไหม เช่น เครดิต ราคาเฉพาะบุคคล หรือการอนุมัติวงเงินDoes it affect someone's money — credit, individual pricing, or a loan approval?
- การใช้งานนี้เกี่ยวกับความปลอดภัยของคนไหม ไม่ว่าจะเป็นพนักงานหรือลูกค้าIs it related to someone's safety — staff or customer?
- การใช้งานนี้กระทบสถานะทางกฎหมายของใครไหม เช่น สิทธิ์ในสัญญาหรือการเข้าถึงบริการDoes it affect someone's legal position — contract rights or access to a service?
รอดูก่อน ทำเฉพาะเมื่อกฎหมายบังคับ หรือวางพื้นฐาน 5 ข้อตอนนี้ — ต่างกันตรงไหนWait and see, act only when forced, or lay the five basics now — what is the actual difference?
สามท่าทีนี้คือสิ่งที่เราเห็นองค์กรเลือกใช้จริงเมื่อเจอกฎหมายที่ยังไม่นิ่ง ไม่มีท่าทีไหนผิดร้อยเปอร์เซ็นต์ในทุกสถานการณ์ แต่ผลที่ตามมาต่างกันชัดเจน ตารางนี้เทียบให้เห็นก่อนคุณเลือกThese are the three postures we actually see organisations take when facing an unsettled law. None is wrong in every situation, but the consequences differ sharply. This table lays them out before you choose.
| หัวข้อAspect | รอดูก่อนWait and see | ทำเฉพาะเมื่อกฎหมายบังคับAct only when the law forces it | วางพื้นฐาน 5 ข้อตอนนี้Lay the five basics now |
|---|---|---|---|
| ต้นทุนตอนนี้Cost now | แทบไม่มี นอกจากเวลาที่เสียไปกับการติดตามข่าวAlmost none, apart from time spent tracking the news | ไม่มี เพราะยังไม่ได้เริ่มทำอะไรNone — nothing has started yet | เวลาไม่กี่ชั่วโมงต่อสัปดาห์ในการสำรวจและตั้งเจ้าของA few hours a week to inventory and assign owners |
| ต้นทุนเมื่อกฎหมายบังคับCost when the law takes effect | สูง เพราะต้องเริ่มทุกอย่างจากศูนย์ในเวลาสั้น ๆHigh — everything starts from zero in a short window | สูงที่สุด เพราะต้องหาทั้งข้อมูลและคนทำพร้อมกันภายใต้แรงกดดันHighest — you must find both the data and the people to do it, all under pressure | ต่ำ เพราะพื้นฐานส่วนใหญ่วางไว้ล่วงหน้าแล้ว เหลือแค่ปรับให้ตรงรายละเอียดLow — most of the groundwork already exists; only the fine details need adjusting |
| ความเสี่ยงระหว่างรอRisk while waiting | องค์กรยังไม่รู้ว่าตัวเองใช้ AI ที่ไหนบ้าง ปัญหาอาจเกิดขึ้นก่อนกฎหมายจะออกด้วยซ้ำThe organisation still does not know where it uses AI; a problem can surface before the law even arrives | เหมือนกัน บวกความเสี่ยงที่ตัดสินใจผิดเพราะไม่เคยสำรวจการใช้งานความเสี่ยงสูงมาก่อนSame, plus the risk of a bad call because high-risk uses were never mapped in the first place | ต่ำกว่าชัดเจน เพราะรู้ตัวก่อนว่าจุดไหนต้องระวังClearly lower — you already know which points need care |
| ผลต่อความเชื่อใจของลูกค้าและพนักงานEffect on customer and employee trust | ไม่เปลี่ยนแปลง จนกว่าจะมีเหตุการณ์เกิดขึ้นจริงUnchanged, until something actually goes wrong | เสี่ยงเสียความเชื่อใจถ้าเหตุการณ์เกิดก่อนองค์กรพร้อมตอบRisks losing trust if an incident happens before the organisation can answer for it | องค์กรตอบคำถามได้ทันทีเมื่อมีคนถามว่า AI มีส่วนอย่างไรThe organisation can answer immediately when asked how AI was involved |
| เหมาะกับใครBest suited to | แทบไม่มีองค์กรที่เหมาะ เพราะพื้นฐานทำได้เองโดยไม่ต้องรอAlmost no organisation — the basics can be done without waiting | องค์กรที่ยังไม่ได้ใช้ AI ในจุดที่กระทบคนเลยจริง ๆ ในตอนนี้An organisation that genuinely has no AI touching a person's rights or opportunities right now | องค์กรที่มีคนใช้ AI ทำงานจริงอยู่แล้ว ไม่ว่าจะเป็นทางการหรือไม่Organisations where AI is already used for real work, official or not |
ขอบเขตของคำตอบนี้The Limits of What This Page Can Answer
หน้านี้เขียนขึ้นจากทิศทางกว้าง ๆ ของร่างกฎหมายที่เผยแพร่แล้ว และจากสิ่งที่เราเห็นว่าเป็นพื้นฐานที่ใช้ได้จริงในองค์กรที่เราอบรม ไม่ใช่คำวินิจฉัยทางกฎหมาย มีข้อที่คุณควรรู้ก่อนนำไปใช้This page is written from the broad direction of the drafts published so far, and from what we have seen work as genuine groundwork in the organisations we train — it is not a legal ruling. There are things you should know before you rely on it.
นี่ไม่ใช่คำแนะนำทางกฎหมาย สำหรับการใช้งานที่คุณระบุแล้วว่าเป็นความเสี่ยงสูง ควรให้ทนายความประเมินเป็นรายกรณีThis is not legal advice. For any use you have identified as high-risk, get a lawyer's view of that specific case.
ร่างกฎหมายอาจเปลี่ยนแปลงสาระสำคัญได้ก่อนประกาศใช้จริง สิ่งที่เขียนในหน้านี้คือทิศทางกว้าง ๆ ของร่างที่เผยแพร่แล้วเท่านั้น ไม่ใช่ข้อความสุดท้ายThe law is a draft and may change materially before it is finalised. What this page describes is only the broad direction of the drafts published so far, not final text.
หน่วยงานกำกับดูแลเฉพาะอุตสาหกรรมอาจมีข้อกำหนดเพิ่มเติม ที่หน้านี้ไม่อาจคาดล่วงหน้าได้ทั้งหมด ถ้าธุรกิจของคุณอยู่ภายใต้การกำกับดูแลเฉพาะทาง ควรตรวจสอบข้อกำหนดของหน่วยงานนั้นเพิ่มเติมด้วยSector regulators may add requirements this page cannot fully anticipate. If your business sits under specialised oversight, check that regulator's own requirements as well.
หน้านี้จะได้รับการอัปเดตเมื่อร่างกฎหมายนิ่งขึ้น นี่คือคำมั่นตรง ๆ ไม่ใช่แค่คำสวย เมื่อรายละเอียดและกำหนดเวลาชัดเจนขึ้น เราจะกลับมาแก้ไขเนื้อหาส่วนนี้ให้ตรงกับข้อเท็จจริงล่าสุดThis page will be updated once the text is settled. That is a plain commitment, not decoration — once the details and timing become clear, we will come back and revise this content to match the latest facts.
คำถามที่พบบ่อยFAQ
กฎหมาย AI ของไทยจะบังคับใช้เมื่อไหร่When will Thailand's AI law take effect?
ยังไม่นิ่ง และหน้านี้ตั้งใจไม่เดาวันที่ให้ เพราะร่างกฎหมายอยู่ระหว่างการพิจารณาและรายละเอียดยังเปลี่ยนได้ตลอด สิ่งที่ทำได้จริงและมีประโยชน์กว่าการนั่งรอวันประกาศคือวางพื้นฐานห้าข้อที่หน้านี้พูดถึงไว้ก่อน เพราะไม่ว่าฉบับสุดท้ายจะออกมาหน้าตาแบบไหนหรือเริ่มบังคับใช้เมื่อไหร่ องค์กรที่มีพื้นฐานนี้อยู่แล้วจะปรับตัวได้เร็วกว่ามาก แผนงานของคุณจึงควรตั้งอยู่บนพื้นฐานห้าข้อนี้ ไม่ใช่ตั้งอยู่บนวันที่ที่ยังไม่มีใครยืนยันได้It is not settled, and this page deliberately does not guess a date, because the draft is still under consideration and details keep changing. What is genuinely useful — more useful than waiting for an announcement — is laying the five basics this page covers. Whatever the final text looks like or whenever it takes effect, an organisation that already has this groundwork will adapt far faster. Plan around the five basics, not around a date nobody can confirm yet.
บริษัทเราไม่ได้ทำธุรกิจเทคโนโลยี ยังต้องสนใจไหมWe are not a technology company — do we still need to care?
ต้องสนใจ เพราะกรอบกฎหมาย AI ในทิศทางสากลที่ร่างกฎหมายไทยเดินตามอยู่นั้น มองที่การใช้งาน ไม่ได้มองที่ว่าใครเป็นคนสร้างโมเดล องค์กรที่ใช้เครื่องมือ AI สำเร็จรูปเพื่อคัดกรองใบสมัครงาน ประเมินเครดิต ตั้งราคาเฉพาะบุคคล หรือช่วยตัดสินใจเรื่องที่กระทบความปลอดภัย ก็อยู่ในข่ายการใช้งานความเสี่ยงสูงเช่นเดียวกับบริษัทเทคโนโลยี ไม่ว่าองค์กรนั้นจะขายอะไรเป็นธุรกิจหลักก็ตามYes. The international-pattern frameworks that Thailand's draft follows look at use, not at who built the model. An organisation using an off-the-shelf AI tool to screen applicants, assess credit, price individual customers, or support safety-related decisions falls into the same high-risk-use category as a technology company, regardless of what it actually sells.
เราทำ PDPA เสร็จแล้ว เท่ากับพร้อมรับกฎหมาย AI หรือยังWe've already done our PDPA work — does that mean we're ready for the AI law?
ยังไม่เท่ากับพร้อมทั้งหมด แต่ช่วยได้จริง งานด้าน PDPA เช่น การรู้ว่าองค์กรเก็บข้อมูลอะไรบ้างและมีใครเข้าถึงได้ เป็นพื้นฐานที่มีประโยชน์และทำให้เริ่มเร็วขึ้น แต่ PDPA คุ้มครองข้อมูลส่วนบุคคลเป็นหลัก ขณะที่กรอบกฎหมาย AI ในทิศทางสากลเน้นที่การตัดสินใจและผลกระทบต่อสิทธิ์หรือโอกาสของบุคคล ซึ่งเป็นคนละประเด็นกัน องค์กรที่ทำ PDPA ครบแล้วยังต้องกลับมาไล่ดูว่า AI ตัวไหนกำลังตัดสินใจแทนคนอยู่บ้างNot entirely, but it genuinely helps. PDPA work — knowing what data your organisation holds and who can access it — is useful groundwork that lets you start faster. But PDPA is chiefly about protecting personal data, while the international-pattern AI frameworks focus on decisions and their effect on a person's rights or opportunities — a different question. An organisation with PDPA fully done still needs to go back and map which AI systems are making decisions about people.
ต้องจ้างที่ปรึกษาหรือทนายความก่อนถึงจะเริ่มเตรียมตัวได้ไหมDo we need to hire a consultant or lawyer before we can start preparing?
ไม่ต้อง อย่างน้อยไม่ใช่สำหรับจุดเริ่มต้น พื้นฐานห้าข้อที่หน้านี้พูดถึง เช่น การสำรวจว่า AI ถูกใช้ที่ไหนในองค์กร การตั้งเจ้าของงานที่ระบุตัวได้ และการเขียนนโยบายที่มีเจ้าของจริง ล้วนเป็นงานทำความสะอาดบ้านภายในที่ทีมงานเดิมทำเองได้โดยไม่ต้องจ้างใคร ที่ปรึกษาหรือทนายความจะมีประโยชน์มากที่สุดเมื่อคุณระบุได้แล้วว่าการใช้งานจุดไหนในองค์กรเป็นความเสี่ยงสูงจริง แล้วต้องการความเห็นเฉพาะจุดสำหรับกรณีนั้นNo, at least not to get started. The five basics this page covers — inventorying where AI is used, naming an identifiable owner per use, and writing a policy someone actually owns — are internal housekeeping an existing team can do without hiring anyone. A consultant or lawyer is most useful once you have identified a genuinely high-risk use and need a specific opinion on that case.
ใช้แค่ ChatGPT หรือเครื่องมือ AI สำเร็จรูปทั่วไป นับว่าเกี่ยวข้องกับกฎหมายนี้ไหมWe only use ChatGPT or general off-the-shelf AI tools — does that count?
นับ เพราะกรอบกฎหมาย AI ในทิศทางสากลพูดถึงการใช้งาน ไม่ได้พูดถึงว่าใครเป็นผู้สร้างเครื่องมือ องค์กรที่ใช้เครื่องมือ AI สำเร็จรูปคัดกรองใบสมัครงานหรือช่วยตัดสินใจเรื่องที่กระทบคน ก็ถือว่ากำลังใช้งาน AI ในความหมายที่ร่างกฎหมายสนใจ ไม่ต่างจากองค์กรที่พัฒนาโมเดลขึ้นมาเอง สิ่งที่ต้องเตรียมจึงไม่ใช่เรื่องเทคนิคของโมเดล แต่เป็นเรื่องว่าองค์กรใช้ผลลัพธ์จากเครื่องมือเหล่านั้นตัดสินใจเรื่องอะไรบ้างYes, it counts. The international-pattern AI frameworks are about use, not about who built the tool. An organisation using an off-the-shelf tool to screen job applicants or support a decision that affects people is using AI in the sense these drafts care about, no differently from an organisation that built its own model. What you need to prepare is not the model's technical details, but what decisions your organisation makes based on that tool's output.
อ่านต่อFurther Reading
ถ้ายังไม่มีนโยบาย AI ในองค์กร เริ่มจาก นโยบายการใช้ AI ในองค์กร ฉบับใช้ได้จริง ซึ่งให้โครงร่างนโยบาย 8 ข้อที่ก๊อปไปปรับใช้ได้ทันที ตรงกับข้อ 6 ในส่วนที่ 3 ของหน้านี้ ถ้ากังวลเรื่องผลกระทบของ AI ต่อความมั่นคงในงานของพนักงาน อ่าน AI กับอนาคตงานของคุณ และถ้าโจทย์ของคุณเน้นที่ข้อมูลรั่วมากกว่าเรื่องการเตรียมรับกฎหมาย อ่าน พนักงานเอาข้อมูลบริษัทไปใส่ AI จะรั่วไหมIf your organisation has no AI policy yet, start with An AI Use Policy Your Organisation Can Actually Apply, which gives eight ready-to-copy clauses matching point six in section 3 above. If you are weighing AI's effect on job security, see AI and the future of your job. And if your concern leans more toward data leaking than legal readiness, see If staff paste company data into AI, does it leak?
สำหรับผู้บริหารที่ต้องตัดสินใจเรื่องการกำกับดูแล AI ในภาพกว้าง เรามีคอร์ส AI for Executives และสำหรับทีมกฎหมายหรือฝ่ายที่ต้องดูแลความเสี่ยงด้านกฎระเบียบโดยเฉพาะ เรามีคอร์ส AI for LegalFor executives who need to think through AI governance at a broader level, we run an AI for Executives course, and for legal teams handling regulatory risk specifically, we run AI for Legal.
เราทำงานอบรมองค์กรด้าน AI เป็นงานหลัก ถ้าอยากคุยรายละเอียดเพิ่มเติมเกี่ยวกับการเตรียมองค์กรของคุณเอง ติดต่อเรา ได้เสมอCorporate AI training is our core work — if you would like to talk through the specifics of preparing your own organisation, feel free to get in touch.