EU AI Act คืออะไรและทำไมเกี่ยวกับไทย
EU AI Act หรือ Regulation (EU) 2024/1689 ผ่านสภายุโรปเมื่อ 13 มี.ค. 2024 มีผล 1 ส.ค. 2024 และบังคับใช้ทยอยตามมาตรา 113 จุดสำคัญที่ไทยมักมองข้ามคือ Art. 2(1)(c): กฎหมายครอบคลุม ‘providers and deployers established in third countries where the output produced by the AI system is used in the Union’
หมายความว่า สำนักกฎหมายไทยที่ใช้ AI ร่างสัญญา สรุปคดี หรือทำ due diligence ส่งให้ลูกค้าใน EU — อยู่ในขอบเขต ต้องปฏิบัติตาม transparency obligations เหมือนผู้ให้บริการ EU
Risk-based classification 4 ระดับ
AI Act ใช้ pyramid model:
- Unacceptable risk (Art. 5) — ห้ามเด็ดขาด: social scoring, real-time biometric ID ในที่สาธารณะ, emotion recognition ในที่ทำงาน/โรงเรียน
- High-risk (Annex III) — credit scoring, recruitment, law enforcement, migration — ต้อง CE marking + EU database registration + technical documentation
- Limited risk (Art. 50) — chatbots, deepfake, AI-generated content ต้อง disclosure ‘this is AI-generated’
- Minimal risk — spam filter, AI ใน video game — voluntary code of conduct
GPAI (General-Purpose AI) Models
GPT-4, Claude, Gemini จัดเป็น GPAI ตาม Art. 51 · ผู้ให้บริการต้องเปิดเผย training data summary, copyright compliance policy และ technical documentation
Systemic risk GPAI (compute ≥ 10^25 FLOPs) เพิ่ม model evaluation + adversarial testing + incident reporting ต่อ AI Office
ผลกระทบต่อสำนักกฎหมายไทย
3 use case ที่กระทบบ่อย:
- ใช้ AI สรุปคดี/ร่างสัญญาให้ลูกค้า EU → Limited risk → ต้องแจ้งลูกค้าว่าใช้ AI + human review
- ใช้ AI screen ผู้สมัครงาน (recruitment) → High-risk → ต้อง impact assessment + bias testing
- ขาย legal-tech SaaS ใน EU → ต้องประเมิน risk tier + CE conformity (ถ้า high-risk)
Compliance checklist สำหรับสำนักกฎหมายไทย
NYC Legal แนะนำ 7 ขั้นตอน:
- 1) AI inventory — ระบุทุก AI tool ที่ใช้ + ลูกค้าที่ผลลัพธ์ไปถึง EU
- 2) Risk classification ตาม Annex III + Art. 5
- 3) Engagement letter เพิ่ม AI disclosure clause + opt-out
- 4) Human-in-the-loop policy — ทนายต้อง review ทุก AI output ก่อนส่งลูกค้า
- 5) Vendor due diligence — ตรวจว่า GPAI provider compliant
- 6) Data Processing Agreement (DPA) update รวม AI processing
- 7) Staff training + incident response plan
Penalty regime
Art. 99 กำหนด 3 tier ค่าปรับ: €35M หรือ 7% turnover (prohibited AI) · €15M หรือ 3% (high-risk violations) · €7.5M หรือ 1% (incorrect information ต่อ authority) — เข้มกว่า GDPR ที่สูงสุด 4%
Member states มีอำนาจบังคับใช้ผ่าน National Competent Authority ที่แต่งตั้งภายใน 2 ส.ค. 2025







