Indonesia's 2026 AI regulations lack safeguards against state surveillance
New presidential rules promise ethics and transparency but rely on laws already used to silence critics, raising fears AI will become a repression tool.
Indonesia plans to issue two presidential regulations on artificial intelligence in 2026 under the Prabowo administration, marking the country's first legally binding AI governance framework. One regulation addresses AI ethics, while the second establishes a national AI roadmap based on a white paper released for public consultation in August 2025.
According to Ismail, Secretary-General of the Ministry of Communication and Digital Affairs (Komdigi), the regulations aim to build a sovereign AI ecosystem focused on governance, public trust, ethics, transparency, and accountability. Yet the framework's reliance on existing Indonesian laws raises serious questions about whether it can prevent state actors from weaponizing AI against civil society.
Enforcement built on repressive foundations
The regulations depend on laws that have proven ineffective or selectively applied. Article 45A of the 2024 Electronic Information and Transaction Law and provisions in the 2008 Pornography Act could theoretically address AI misinformation and deepfake pornography. The 2022 Personal Data Protection Law requires explicit consent for data processing, which could limit unauthorized AI training on personal data.
But these laws offer little real protection. The Electronic Information and Transactions Law has been consistently wielded by Indonesia's political and economic elite to silence critics rather than combat disinformation. Despite the law's existence, deepfake images and videos proliferated during Indonesia's 2024 elections, and a sophisticated influence industry continues to operate largely unchecked.
The Personal Data Protection Law faces similar challenges. Without a strong, independent data protection authority, the law has proven ineffective. While the government is establishing such an agency, concerns persist about whether it will have sufficient autonomy to investigate state institutions accused of violations.
Surveillance infrastructure already in place
Indonesia's government has accumulated extensive biometric data through its electronic identification system since 2011. TOTM Technologies, which has access to Indonesian biometric data through its subsidiary PT International Biometric Indonesia (Interbio), won contracts worth $4.9 million and $5.4 million in 2022 to provide biometric identification and surveillance systems for law enforcement.
The Indonesian government has also purchased surveillance tools used by autocratic regimes elsewhere. While no confirmed evidence exists of these tools targeting civil society, many Indonesian academics, activists, and journalists critical of elites have allegedly experienced digital attacks. Former TOTM Technologies director Dhanie Tri Indrasto now holds positions at Interbio and PT Radika Karya Utama, a company that has procured zero-click surveillance tools for the Indonesian National Police.
Critical gaps in the framework
Komdigi's 2025 National AI Roadmap white paper identifies politics, law, and security as priority sectors but limits applications to detecting online manipulation and cyberattacks. The 2025 Draft AI Ethics Guidelines explicitly exempt AI use for "defence and national security" from monitoring and evaluation provisions, creating a potential loophole for abuse.
The framework makes no mention of protections against AI-powered state surveillance or elite-funded online influence operations. Specific risks include facial recognition technology to identify protesters and AI agents designed to mimic grassroots movements to polarize or fragment civil society.
Why it matters
Indonesia's approach to AI regulation illustrates a pattern emerging across Southeast Asia: governments adopting the language of ethical AI while building frameworks that could enable rather than constrain state power. Without independent enforcement mechanisms and explicit protections against state misuse, AI governance becomes a veneer over expanding surveillance capabilities. For multinational companies operating in Indonesia or considering AI deployments in the region, the regulatory environment offers little certainty that systems won't be co-opted for political purposes.
This analysis was first reported by Ary Hermawan, Visiting Fellow at the ISEAS – Yusof Ishak Institute, in the East Asia Forum.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call