4-tier risk classification
- Unacceptable (Art. 5): social scoring, real-time biometric ID public, emotion recognition workplace — banned
- High-risk (Annex III): legal AI ที่ช่วย judiciary, immigration decision, employment screening · ต้อง CE + DPIA + human oversight
- Limited (Art. 50): chatbot, deepfake, AI-generated content · ต้อง disclosure (mark watermark)
- Minimal: spam filter, AI ใน game · ไม่มี obligation
ผลกระทบกับ NYC Legal scope
Translation memory + AI assist (DeepL, ChatGPT): Limited risk → ต้อง disclose ลูกค้า EU
Legal research AI (Harvey, Lexis+AI): Limited risk · ทนายยัง accountable เนื้อหา
Document automation (Notary AI template): Limited risk · ต้อง human review
AI ใน immigration advisory: ถ้าใช้ตัดสินใจ visa eligibility = High-risk · ต้อง CE marking
Voice cloning ใน video consultation: ต้อง mark deepfake ตาม Art. 50
Compliance checklist สำหรับ Thai legal firm ที่บริการ EU
- 1. AI inventory: list tool ทั้งหมด + classify risk tier
- 2. Transparency notice: เพิ่มในเว็บไซต์ + retainer letter (EU client) — disclose AI use
- 3. Human-in-the-loop: ทุก output AI ต้อง qualified lawyer review + sign-off
- 4. Data governance: training data lawful · ไม่ใช้ client confidential train public model
- 5. Incident log: track AI error/hallucination · breach notification ถ้ากระทบ EU client
- 6. Vendor due diligence: ตรวจ GPAI provider compliance (OpenAI, Anthropic publish compliance summary)
- 7. Training: ทนาย/staff อบรม AI literacy (Art. 4 — บังคับ Feb 2025)
ไทย — ETDA AI Governance Guideline
ETDA Guideline 2566 (voluntary): risk-based approach คล้าย EU แต่ไม่มี penalty
PDPC AI Guideline 2566: AI ที่ process personal data ต้องผ่าน DPIA + transparency
ร่าง พ.ร.บ.AI ไทย (สำนักงานพัฒนาธุรกรรมฯ): อยู่ใน public hearing 2025 · คาดบังคับ 2027
Best practice: ใช้ EU AI Act เป็น benchmark แม้กฎหมายไทยยังไม่บังคับ · future-proof






