The Proof Gap
A global growth fund is 3 weeks away from closing a Series C round of funding for a Jakarta-based fintech platform when the deal team poses a straightforward request: Show us your AI governance file. The company has no finalized guidelines nor policy to produce, taking the view that its existing arrangements are sufficient. The regulatory question is no longer whether Indonesia has detailed Personal Data Protection rules. Government Regulation No. 33 of 2026 (“GR 33/2026“), the principal implementing regulation for the Law No. 27 of 2022 concerning Personal Data Protection (“PDP Law”) was promulgated on 16 July 2026 and shall be effective on 16 January 2027. The more critical question is whether the company can demonstrate that its AI and data practices are sufficiently mature. That readiness will be evaluated against a framework that investors already understand and trust.
This remains the reality for many AI-enabled companies in Indonesia, though seasoned due diligence teams across the region have likely already identified and assessed it as part of their review process. The PDP Law applies to the processing of personal data by any organization operating in Indonesia and has extraterritorial effect: it also extends to processing activities conducted outside Indonesia where the legal consequences affect individuals in Indonesia or where the personal data concerns Indonesian citizens located abroad. While the law has been fully effective since 17 October 2024, the establishment of its dedicated supervisory authority remains ongoing.
In the meantime, a dedicated pair of AI Presidential Regulations (“AI Perpres”): a National AI Roadmap and a separate AI Ethics and Safety instrument reportedly built around a three-tier risk classification, has cleared inter-ministerial review and is awaiting the President’s approval. Sector-specific regulations are expected to be introduced following the finalization of the Presidential Regulation.
In January 2026, Indonesia’s Ministry of Communication and Digital Affairs (“MCDA”) confirmed that following the issuance of the AI Perpres, ministries and government agencies will be required to adopt sector-specific implementing regulations governing the use of AI within their respective domains. MCDA has reportedly prepared the first such regulation, requiring the labelling of AI-generated content, for release immediately after the Presidential Regulation is signed.
The absence of a finalized AI regime does not create a regulatory safe harbour. Instead, it creates the conditions in which transactions are delayed, valuation assumptions are challenged, and due diligence teams ask increasingly difficult questions about governance, risk, and accountability.

What’s Changed in Indonesia’s AI Governance Landscape
Measured in gross merchandise value, Indonesia’s digital economy is the largest in ASEAN, according to the World Bank’s Indonesia Economic Prospects report published in December 2025. Against this backdrop, the country’s AI governance landscape has evolved at a remarkable pace over the past 18 months.
The most significant recent development is the issuance of GR 33/2026 which operationalizes the PDP Law by translating its broad principles into detailed compliance requirements covering personal data processing, governance and accountability meausures, data protection impact assessments, breach notification procedures, cross-border data transfers, and administrative sanctions. For AI-enabled companies, the regulation is particularly noteworthy. The Elucidation expressly identifies AI, machine learning, and IoT as technologies that may be involved in high-risk personal data processing and therefore warrant enhanced regulatory scrutiny and risk assessment. For a detailed analysis of GR 33/2026, including its implications on cross-border data transfers, corporate transactions, and enforcement, see NDP’s earlier insight, Indonesia’s Personal Data Protection Law: GR 33/2026.
Until 2023, Indonesia had no meaningful AI-specific regulatory guidance beyond a non-binding circular on AI ethics that offered limited practical direction for businesses. In August 2025, MCDA released the National AI Roadmap White Paper for public consultation as a foundational policy document. Its core principles have subsequently been incorporated into a draft AI Perpres which has completed inter-ministerial coordination and is currently awaiting the President’s approval.
One point is particularly relevant for boards and investors alike. Under Indonesian law, a Presidential Regulation cannot itself impose criminal nor administrative sanctions; only legislation enacted by Parliament has that authority. As a result, even after it is signed, the AI Perpres will function primarily as a standards-setting instrument rather than a sanction regime. That does not mean AI-related legal risk is absent. In practice, liability will continue to be assessed under existing laws already in force, most notably the PDP Law and the Electronic Information and Transactions Law (“ITE Law”). Of the two, the PDP Law is likely to be the more immediate concern for organizations deploying AI systems given the central role that personal data plays in the development, training and operation of many AI applications.
One Indonesia-specific development warrants close attention: MCDA’s National AI Roadmap White Paper proposes the establishment of a sovereign AI fund under the oversight of Danantara, Indonesia’s sovereign wealth fund. The proposed fund is expected to operate through a public-private financing model, supported by fiscal incentives aimed at catalysing domestic AI investment. For investors, the proposal provides a clear indication of the government’s strategic commitment to strengthening Indonesia’s AI ecosystem including infrastructure, research capabilities and talent development, well before formal AI-specific legislation comes into force.
Two further developments are also worth noting. First, Ministry of Law Regulation No. 5 of 2026 on Trademark Registration is modernizing online IP enforcement framework, with parallel amendments proposed to the Copyright Bill are expected to address the treatment of AI-generated works. Secondly, National Cyber and Crypto Agency (“BSSN”), requires operators of critical digital infrastructure to report cyber incidents within 24 hours.
Regulatory status snapshot
| Instrument | Status (mid-2026) | What it means for a deal |
|---|---|---|
| PDP Law | Binding since 17 October 2024 | Binding exposure notwithstanding AI-specific rules |
| GR 33/2026 | Promulgated 16 July 2026; effective 16 January 2027 | Detailed operational readiness obligations with a fixed compliance timetable |
| PDP Authority (Lembaga PDP) | GR 33/2026 provides the institutional framework; establishment of the dedicated PDP Institution remains pending | Detailed operational rules now exist, but the enforcement architecture is not yet fully operational. MCDA continues to supervise in the interim |
| AI Perpres | Cleared inter-ministerial review, awaiting signature | Sets standards, not penalties. Sector specific rules to follow post signing |
| BSSN cyber incident rules | In force | 24-hour reporting duty for critical infrastructure operators |
| Sovereign AI Fund (Danantara) | Proposed, targeted for 2027–2029 launch | Signals future state-backed AI investment priority |
AI Governance in Indonesia: Why It Matters
For a domestic compliance officer, an incomplete AI guideline or policy may be perceived as a signal to hold off from taking action. For an investor or acquirer evaluating an Indonesian target, the same situation may be interpreted differently.
Diligence expectations have already expanded. AI and data governance are now standard areas of inquiry in technology due diligence exercises involving Indonesian targets, despite the absence of AI-specific law. In practice, investors are not waiting for a dedicated AI law before assessing AI-related risks. They are already scrutinizing governance structures, asking who is accountable for AI risk, what data is used to train and operate AI systems, and how the company detects, escalates, and remediates AI-related incidents when they arise.
GR 33/2026 further clarifies the obligations of parties that control or process personal data in the context of corporate transactions. As a result, AI governance and data protection due diligence should be addressed at the outset of transaction planning and structuring, rather than being deferred until signing or closing.
Representations become more difficult to negotiate. Regulatory uncertainty can complicate warranty negotiations where parts of the legal framework remain under development. When negotiating a standard compliance with laws representation, both sellers and buyers require a shared understanding of which obligations are currently binding and which remain prospective. Existing laws such as the PDP Law, the ITE Law, and applicable sector-specific regulations can be assessed against established legal requirements, whereas the proposed AI regime remains subject to finalization. Ambiguity at this stage can easily become a source of disagreement once a claim arises.
Governance gaps ultimately affect both valuation and deal timing. A target that is unable to produce basic evidence of AI governance is likely to face more intensive due diligence, extended transaction timelines, and increased pressure on valuation. These concerns are no longer confined to preliminary diligence questionnaires. They are increasingly reflected in transaction terms themselves, including through escrow arrangements or indemnity provisions designed to address future regulatory developments. Once such protections are embedded in a term sheet, they can be difficult to negotiate away.
Regulator scrutiny is unlikely to be purely prospective. Once the PDP Institution becomes operational and GR 33/2026 comes into force on 16 January 2027, regulators will be in a stronger position to scrutinize and enforce compliance in relation to conduct that occurred prior to the full implementation of the personal data protection framework. In particular, organizations may be asked to demonstrate how they managed AI and data-related risks during the intervening period, especially where existing obligations under the PDP Law or other applicable legislation were already engaged. Companies that treated regulatory uncertainty as a reason for inaction may find themselves having to justify that inaction retrospectively. Those that established and documented governance measures in advance are likely to be in a stronger position.
International benchmarks are already filling the gap. In the absence of a finalized domestic AI framework, investors and cross-border counterparties frequently refer to the ASEAN Guide on AI Governance and Ethics, adopted by ASEAN member states in February 2024, as a practical benchmark for responsible AI governance in the region. A company that can demonstrate alignment with these regional principles provides an investment committee in Singapore, Hong Kong, and other financial centres with a tangible basis for evaluating governance maturity, even before Indonesia’s own AI regime is formally in place.
The Framework: Govern, Prove, Scale
Responding to this gap does not require a complex framework, but it does require a deliberate one. A prudent approach is to address it through three progressive stages: Govern, Prove, and Scale. Each stage lays the foundation for the next. Skipping a stage weakens the overall governance framework and diminishes the quality of the evidence available to investors, regulators, and due diligence teams.

Govern
Effective AI governance begins with accountability, not documentation. Every AI system currently in use should have a clearly identified owner and that owner should be an individual rather than a function or department. Depending on the organization, the responsibility may sit with a Chief Risk Officer, Head of AI Risk, or the chair of a governance committee. Once accountability is established, each AI use case should be assessed and classified according to its risk profile.
High-risk AI applications require a clear point of human intervention. There should be an identifiable decision-maker with the authority to pause, review or override the system before an error or adverse outcome affects customers or regulators. The oversight mechanism does not need to be complex, but it should be clearly documented, consistently applied and subject to periodic review. In regulated sectors, responsibility is most effectively assigned to an individual who possesses a strong understanding of both the regulatory framework and the underlying technology, rather than expertise in only one of those areas.
Where AI systems involve the processing of personal data, the designated AI owner should work closely with the company’s privacy or PDP compliance team to ensure that AI governance and data protection requirements are addressed in a coordinated manner. Companies should also assess whether their activities trigger the obligation to appoint a Data Protection Officer (DPO) under GR 33/2026.
What this means for an investor: this is typically among the first diligence requests. Investors are not looking for a philosophy statement. They want to see a clearly identified owner, a documented governance framework, and evidence that the company has taken concrete decisions on AI risk management and accountability.
Prove
Governance without evidence is merely an aspiration. Proving it requires building a documented record before it is requested, not attempting to reconstruct one afterwards.
For any AI system that processes personal data, the starting point is to identify and document the legal basis for that processing, followed by a Data Protection Impact Assessment (DPIA)-style assessment of its potential impacts and risks.
Organizations should also maintain incident registers, breach logs and documentation sufficient to demonstrate compliance with the applicable reporting and notification obligations under the PDP Law and BSSN requirements.
In addition, contracts with third-party AI vendors should incorporate minimum governance standard, accountability obligations and audit rights, rather than relying exclusively on the vendors’ own internal controls.
Following the issuance of GR 33/2026, four categories of documentation have become particularly material for AI-enabled companies.
- First, a record of processing activities for each material AI system.
- Second, data protection impact assessments, which GR 33/2026’s Elucidation expressly identifies AI, machine learning, and IoT.
- Third, cross-border data transfer documentation, given that AI services, cloud infrastructure, and model vendors commonly involve offshore processing.
- Fourth, breach and incident response procedures aligned with both personal data breach notification requirements and, where applicable, BSSN incident-management obligations.
Perfection is not the goal. Consistency, traceability and contemporaneous record-keeping are far more important than elaborate processes. Even a simple spreadsheet can be effective if it is consistently maintained, properly documented and readily retrievable when needed.
What this means for an investor: this is the evidence trail diligence teams look for. A company that have it ready demonstrate governance.
Scale
This is where the framework demonstrates its value to an international audience. A governance file developed through the Govern and Prove stages serve as tangible evidence that the company is not only compliant but investable.
At a minimum, the governance file should contain:
- A board-approved AI governance policy.
- An AI systems register with documented risk classifications.
- A record of processing activities for each material AI system.
- DPIAs or equivalent AI impact assessments, where appropriate.
- Records of AI-related incidents, breaches and remediation actions.
- Documentation of governance obligations and audit rights in third-party AI vendor contracts.
- Cross-border data transfer assessments and safeguards documentation.
- DPO or accountable privacy-function designation, where applicable.
- Records of periodic board or governance committee’s oversight of of AI and data-related risk.
Following the issuance of GR 33/2026, the governance file should demonstrate not only responsible AI oversight, but also the company’s readiness to comply with the PDP regime’s requirements that strengthen AI-enabled data processing.

In practice, this may take the form of a single, well-organized folder within the data room labeled “AI and Data Governance,” containing each document in a clearly structured format with ownership and review dates readily identifiable.
A governance file of this quality is rarely assembled overnight. It is typically the product of treating the Govern and Prove phases as a continuous discipline rather than as a one-time exercise undertaken to satisfy a pre-closing condition.
Alongside the governance file, companies should consider demonstrating alignment with the ASEAN Guide on AI Governance and Ethics. For investment committees outside of Indonesia who may have limited familiarity with Indonesia’ evolving AI framework, the Guide serves as a recognized regional benchmark for responsible AI governance.
What this means for an investor: when a governance file reaches this level of maturity, it can materially change the course of a transaction. Instead of generating weeks of follow-up diligence requests, it allows investors to conduct a focused and structured review. Question around regulatory exposure become easier to assess and resolve, often resulting in a smoother process, a faster timetable, and greater confidence in valuation.
The Advantage of Moving First
Indonesia’s AI regime is evolving. While GR 33/2026 takes effect on 16 January 2027, companies’ action before that date may still come under regulatory scrutiny. Companies that spent this period to establish governance frameworks and build a defensible governance file will be better positioned when the new regime takes effect. Those that have deferred action will face a more demanding task, often under tighter timelines and increased scrutiny from regulators assessing decisions made before the framework was finalized.
For an investor or acquirer, the practical question is simple: is there a governance file that can be reviewed today, or merely a commitment to create one once the regulatory landscape is settles? The former tends to support a more efficient diligence process, greater confidence in risk allocation, and fewer unexpected issues as the transaction progresses.
That is the practical meaning of “Proof First, Scale Fast” in Indonesia’s AI landscape in 2026. Governance should be demonstrated before it is needed, not after it is requested. Companies that can evidence responsible governance are generally better placed to attract capital, navigate transactions, and scale with confidence as the regulatory framework continues to evolve.
Partner Perspective
AI governance is no longer just a compliance exercise. It is increasingly a measure of corporate maturity, resilience, and investment readiness.
As Indonesia’s regulatory framework evolves, businesses must be able to demonstrate not only how they use AI, but also how they govern it. Investors, acquirers, and regulators are increasingly focused on accountability, data governance, risk management, and evidence of compliance.
Companies that can demonstrate responsible AI governance are better positioned to manage regulatory risk, build stakeholder trust, and succeed in transactions. In today’s market, strong AI governance is becoming a competitive advantage, not just a legal requirement.
Frequently Asked Questions
The following questions address the principal legal, governance, and transaction-readiness issues for businesses deploying AI in Indonesia. They are based on the PDP Law, GR 33/2026, and the Indonesian AI regulatory landscape as of October 2026.
1. Does Indonesia have a dedicated AI law?
As of October 2026, Indonesia does not have a standalone AI law. The Government is currently developing two AI Perpres: one establishing a national AI roadmap and the other addressing AI ethics and safety. These initiatives are expected to provide policy direction and governance guidance rather than create a comprehensive enforcement regime.
However, the absence of a dedicated AI law does not mean that AI deployment is unregulated. Most notably, the PDP Law governs the collection, use, disclosure and storage of personal data while the Electronic Information and Transactions Law (ITE Law) regulates a broad range of digital activities. Depending on the sector, additional requirements may arise under the industry-specific regulations and cybersecurity rules administered by BSSN.
The most significant recent development is GR 33/2026 which was issued on 16 July 2026 and takes effect on 16 January 2027. The regulation introduces detailed operational requirements for personal data processing and is particularly relevant to AI-enabled systems that collect, use, or otherwise process personal data.
2. What is GR 33/2026, and why does it matter for AI governance in Indonesia?
GR 33/2026 is the principal implementing regulation of Indonesia’s PDP Law. It translates the PDP Law’s broad principles into detailed operational requirements covering:
- personal data processing;
- governance and accountability;
- data protection impact assessments;
- breach and incident response;
- cross-border data transfers, and
- enforcement.
The Elucidation to GR 33/2026 expressly identifies AI, machine learning, and IoT as examples of technologies that may involve high-risk personal data processing. For companies using AI, this matters because data governance is no longer merely a matter of good practice.
For a detailed analysis of GR 33/2026, see NDP’s companion article Indonesia’s Personal Data Protection Law: GR 33/2026.
3. What AI and data governance obligations apply to companies in Indonesia today?
Companies using AI to process personal data are already subject to Indonesia’s PDP Law. Existing obligations include establishing a lawful basis for processing, safeguarding personal data, responding to data subject requests, and managing personal data breaches. Depending on the nature of their activities, companies may also need to comply with the ITE Law, sector-specific regulations, and applicable cybersecurity requirements issued by BSSN.
GR 33/2026, which takes effect on 16 January 2027, supplements these obligations by introducing more detailed compliance requirements. These include maintaining records of processing activities, conducting assessments for high-risk processing, implementing safeguards for cross-border data transfers, and establishing appropriate governance and accountability frameworks.
Companies that begin aligning their practices with these requirements now will be better positioned to demonstrate compliance once GR 33/2026 comes into force.
4. Why does AI governance in Indonesia matter for investors, acquirers, and deal teams?
AI and data governance have become standard areas of technology due diligence for Indonesian targets. Investors and acquirers increasingly focus on:
- who is responsible for AI-related risks;
- what data used to train and operate AI systems;
- how data is shared with vendors or transferred across borders; and
- whether the company has effective incident-response processes in place.
A target that cannot answer these questions or produce supporting documentation may face more extensive due diligence, longer timelines, valuation pressure, or stricter risk allocation mechanism including escrow arrangements and indemnities. GR 33/2026 further elevates the importance of AI and data diligence by making it relevant from the outset of deal structuring rather than only at closing. Companies that can demonstrate governance readiness early are better positioned to streamline diligence, reduce follow-up requests, and minimize valuation concerns.
5. What should an AI governance file contain for a company operating in Indonesia?
An AI governance file should provide a clear, verifiable record of how a company oversees AI systems, manages data-related risk and demonstrates compliance readiness. Based on the framework set out in this article, a robust govrnance file should include:
1. A board-approved AI governance policy.
2. An AI systems register with risk classifications.
3. Records of processing activities linked to each material AI system.
4. DPIAs or equivalent impact assessments for relevant high-risk processing.
5. Incident, breach, remediation, and escalation records.
6. AI vendor contracts showing governance obligations, information rights, and audit rights.
7. Cross-border data transfer assessments and safeguards documentation, where relevant.
8. DPO or accountable privacy function designation, where applicable.
9. Evidence of periodic board or committee oversight of AI and data risk.
The file should be kept up to date, clearly dated, and maintained in a form that can be readily reviewed by regulators, investors, or transaction counterparties.
6. What is the Govern, Prove, Scale framework for AI governance in Indonesia?
Govern, Prove, Scale is a practical three-stage framework for building AI governance in Indonesia.
- Govern establishes accountability by assigning a responsible owner for each AI system and classify systems according to their risk profile.
- Prove creates a documented evidence base through processing records, impact assessments, incident logs, and vendor oversight meausres.
- Scale organises that documentation into a governance file that can be reviewed efficiently by investors, regulators, and transcation counterparties.
The framework is designed to be built sequentially, with each stage reinforcing the next. Skipping a stage weakens both governance and the supporting evidence. This is especially relevant under GR 33/2026, which clarifies the practical measures needed to demonstrate PDP compliance from 16 January 2027.
7. What should companies do before GR 33/2026 takes effect on 16 January 2027?
Companies should start by mapping their AI systems and the personal data processesed by each system. Key implementation steps include:
- Appointing a named individual responsible for AI governance;
- establish or updating records of processing activities;
- assess whether any AI use cases involve high-risk processing that requires a DPIA noting that the Elucidation expressly identifies AI and machine learning as relevant risk indicators;
- review vendor, outsourcing and cloud service agreements for governance obligations, audit rights and cross-border data transfer arrangements; and
- test and document incident-response procedures.
Companies should also assess whether GR33/2026 triggers a requirement to appoint a data protection officer. The objective is not perfect paperworkbut a governance record that is current, verifiable, and ready for scrutiny by regulators, investors, or deal counterparties.
About Nusantara DFDL Partnership
Nusantara DFDL Partnership (NDP) is an Indonesian law firm and a member of the DFDL network, which operates across Southeast Asia. NDP advises foreign corporations, institutional investors, and Indonesian businesses across a full suite of corporate legal services, including corporate advisory, mergers and acquisitions, foreign direct investment, joint ventures, employment law, real estate, dispute resolution, restructuring, and cross-border transactions. NDP works with clients across sectors including digital infrastructure, financial services, energy, manufacturing, and property.
Disclaimer
This article is for general informational purposes only and does not constitute legal advice. Regulatory requirements in this area are subject to change. Readers should seek legal advice before taking steps to restructure, merge, transfer, dissolve, or otherwise reorganise an Indonesian entity or group.