Flow AI Co., Ltd. ข้อมูลการติดต่อ, แผนที่และเส้นทาง,แบบฟอร์มการติดต่อ,เวลาเปิดและปิด, การบริการ,การให้คะแนนความพอใจในการบริการ,รูปภาพทั้งหมด,วิดีโอทั้งหมดและข่าวสารจาก Flow AI Co., Ltd., 111 Spaces Ratchathewi Building, Ratchathewi.

Earlier, I explored a simple but important question:Does Thailand need an AI Act?The short article could only touch the ...
03/09/2026

Earlier, I explored a simple but important question:
Does Thailand need an AI Act?

The short article could only touch the surface.

In this expanded episode, I revisit the question from a broader governance perspective — not only whether legislation is needed, but how law, governance, compliance, controls, accountability, and responsible innovation fit together.

The episode also explores why an AI Act should not be viewed as the entire answer to AI governance, but as one component of a wider governance architecture.

🎧 Watch the full episode:

Thailand is accelerating AI adoption — but how should AI be governe...

From Compliance Claims to Verifiable EvidenceOrganizations often say that they comply with policies, contractual obligat...
31/08/2026

From Compliance Claims to Verifiable Evidence

Organizations often say that they comply with policies, contractual obligations, regulatory requirements, or internal controls.

But increasingly, another question matters:

Can they demonstrate it?

This was another reflection from the “Certification as a Trusted Mechanism for Cross-border Data Transfers” session at IAPP Asia Forum 2026 in Singapore.

The session discussed certification as one mechanism for demonstrating compliance, including the role of independent assessment.

What stood out to me was a broader governance principle that extends well beyond certification itself:

Compliance becomes more credible when it can be supported by evidence.

For organizations using AI, cloud services and external technology providers, written policies and contractual commitments are important. But effective governance also depends on whether organizations can show that expected controls are actually operating.

That evidence might include monitoring records, approval logs, audit trails, risk assessments and vendor reviews showing how controls work in practice.

Independent certification can provide one form of external assurance. Under the GDPR, certification is a voluntary accountability mechanism, and the EDPB has approved Europrivacy certification criteria as a European Data Protection Seal that can be used as a transfer tool under Articles 42 and 46 GDPR.

But certification is not the larger point.

The larger point is the shift from:

“We have a policy.”

to

“We can show how the policy is implemented, monitored and evidenced.”

For AI governance and compliance, this distinction will increasingly matter.

Because trust is difficult to build from commitments alone.

It becomes stronger when organizations can demonstrate how those commitments operate in practice.

Contracts Alone May Not Be Enough for Cross-Border Data GovernanceWhen organizations rely on external technology provide...
27/08/2026

Contracts Alone May Not Be Enough for Cross-Border Data Governance

When organizations rely on external technology providers, one of the first questions Legal may ask is whether the right contractual safeguards are in place.

That question matters. But it may not be the last one.

This was another reflection from the “Certification as a Trusted Mechanism for Cross-border Data Transfers” session at IAPP Asia Forum 2026 in Singapore.

The session compared different GDPR mechanisms for international data transfers, including Standard Contractual Clauses, Binding Corporate Rules, Codes of Conduct and certification.

What stood out to me was a broader governance distinction:

A contract can establish obligations. It does not, by itself, demonstrate that those obligations are being carried out effectively.

For organizations using AI, cloud services or other external technology providers, this distinction matters.

A contract may define what a provider is required to do. But governance and compliance also need to ask what happens operationally:

Are the agreed controls actually implemented, and can the organization obtain evidence of that?

Are responsibilities clear across providers and subprocessors?

If the technology, processing arrangement or data flow changes, who is expected to detect it and respond?

Under the GDPR, contractual clauses remain an established mechanism for providing appropriate safeguards for certain international transfers. Certification can also play a role under the regulatory framework.

The point is therefore not that contracts are unimportant, or that one mechanism is inherently superior to another.

It is that documented obligations and effective controls are not the same thing.

For cross-border AI and data governance, organizations may need both:

legal mechanisms that define responsibilities and governance processes that provide confidence those responsibilities are actually being performed.

Because good governance does not end when the contract is signed.

Cross-Border AI Is Also a Data Governance ProblemWhen organizations adopt AI services, the discussion often begins with ...
24/08/2026

Cross-Border AI Is Also a Data Governance Problem

When organizations adopt AI services, the discussion often begins with capability:

What can the system do? How accurate is it? How much value can it create?

But another question deserves equal attention:

Where does the data go?

This was one of my reflections after attending the “Certification as a Trusted Mechanism for Cross-border Data Transfers” session at IAPP Asia Forum 2026 in Singapore.

The session focused on certification and international data-transfer mechanisms under the GDPR. It reinforced a broader governance point for me: when AI relies on external platforms, cloud infrastructure, model providers or subprocessors, organizations may create data flows across entities and jurisdictions that are not visible from the AI use case alone.

That matters because AI governance cannot stop at model performance or responsible-use principles.

Organizations also need visibility into what data enters the system, who receives it, where it may be processed, and which third parties are involved. That visibility can then inform contractual requirements, compliance controls and the evidence needed to demonstrate that those controls are working.

Under the GDPR, transfers of personal data to third countries are subject to specific legal requirements. Certification can also play a role as a voluntary compliance mechanism, and in 2026 the EDPB considered Europrivacy certification criteria for use as a transfer tool under Articles 42 and 46.

But the larger lesson is not about choosing one mechanism over another.

It is that cross-border AI governance starts with visibility.

Before asking whether an AI system is compliant, organizations may first need to map the data flows behind it.

Because when AI crosses borders, governance must follow the data — not just the technology.

Human Review Is Not an Effective AI Control by Default“There is a human in the loop.”That statement may sound reassuring...
14/08/2026

Human Review Is Not an Effective AI Control by Default

“There is a human in the loop.”

That statement may sound reassuring. But from a compliance perspective, it tells us very little about whether the control is actually effective.

Consider a simple example.

An AI system recommends rejecting a customer’s credit application. A staff member is required to review the recommendation before the decision becomes final.

The reviewer is technically involved. But what if they have only a short time to assess each case, see only a risk score rather than enough information to evaluate the recommendation, and need managerial approval to override the outcome?

The process includes human review. But does it provide meaningful human oversight?

That distinction matters.

A person appearing somewhere in the workflow is not enough. Meaningful oversight requires the reviewer to have sufficient information, competence, time, authority, and clear escalation pathways to exercise independent judgment.

The reviewer must be able to challenge the AI output rather than simply confirm it.

Organizations should also consider automation bias. If employees routinely defer to AI recommendations because the system is perceived as more accurate, objective, or authoritative, the formal ability to override may have little practical value.

But there is another layer.

Even meaningful human oversight should not automatically be treated as an effective operational control. Organizations still need evidence that the control works in practice.

→ Do reviewers actually challenge questionable outputs?

→ Are overrides and escalations documented?

→ Are recurring issues identified and addressed?

→ Are reviewers trained and periodically assessed?

→ Does monitoring show that the control is working as intended?

This leads to an important distinction:

Human review asks: Is a person involved?

Meaningful human oversight asks:

Can that person exercise real judgment and intervene?

Control effectiveness asks: Does that intervention actually manage the intended risk?

For boards, executives, Compliance, Risk, Internal Audit, and AI leaders, the question should therefore go beyond whether a “human in the loop” exists.

The more important question is whether human oversight is properly designed, adequately resourced, consistently performed, documented, monitored, and tested.

Because “human in the loop” describes a workflow.

It does not, by itself, prove that an effective AI control exists.

AI Compliance Starts Before the Prompt Is SentBefore an AI system generates an answer, a compliance decision may already...
12/08/2026

AI Compliance Starts Before the Prompt Is Sent

Before an AI system generates an answer, a compliance decision may already have been made.

Someone decided what information to give the system. That decision deserves more attention.

A recent U.S. federal court decision illustrates why.

In United States v. Heppner, a criminal defendant used the public version of Claude while preparing materials relating to an ongoing criminal investigation. Some of the information entered into the system had come from discussions with his lawyers.

The court held that 31 AI-related documents were protected by neither attorney-client privilege nor the work-product doctrine. The decision was fact-specific. It does not mean that using AI automatically destroys legal privilege.

But it highlights a broader compliance issue:

A prompt can also be an information-handling decision.

The question is not only:

“Is this information confidential?”

A broader question may be:

“Am I authorized to give this information to this AI system?”

That authorization may depend on more than internal policy. It may also involve legal duties, contractual restrictions, professional obligations, the terms governing the AI system, and the safeguards surrounding its use.

The question becomes particularly important when AI use involves:
→ Confidential business information
→ Personal or customer data
→ Trade secrets and proprietary material
→ Legally privileged information
→ Credentials and security-sensitive information
→ Information subject to contractual restrictions

This does not mean these categories can never be used with AI.

The answer may depend on the AI system, deployment model, purpose, contractual terms, security controls, organizational policy, and applicable law.

That is why an approved-tools list alone is not enough.

Organizations also need practical guidance explaining:

What information may be used with which AI systems, for which purposes, and under what safeguards?

Employees should not have to interpret complex privacy, confidentiality, security, contractual, and legal requirements every time they open an AI tool.

Compliance should help make those boundaries clear before the interaction happens.

Human review of AI outputs remains important. But by the time an output reaches a reviewer, one important compliance decision may already have been made.

AI compliance starts before the prompt is sent.

Source: United States v. Heppner, 25 CR. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026)

Shadow AI Is Not Just an Employee Compliance ProblemWhat if an employee uses an unapproved AI tool because the approved ...
10/08/2026

Shadow AI Is Not Just an Employee Compliance Problem

What if an employee uses an unapproved AI tool because the approved way of doing the work simply does not meet the business need?

The employee may still have violated policy. But that may not be the whole compliance diagnosis.

AI compliance requires clear ownership at the point of use. Employees have a responsibility to follow AI policies, use approved systems, protect confidential or personal information, and escalate uncertainty rather than bypass controls.

But accountability should not stop with the individual.

When Shadow AI appears, organizations should also ask why it happened.

→ Were appropriate AI tools actually available?

→ Were employees clear about what was permitted and prohibited?

→ Was the approval process practical for the speed at which the business operates?

→ Did training address real working situations rather than only high-level principles?

→ Could existing controls detect unauthorized AI use before it created greater risk?

Repeated workarounds may reveal something important about the control environment.

If employees consistently turn to unapproved tools because approved alternatives do not meet legitimate business needs, enforcement alone may address the behavior without addressing its cause.

Shadow AI can therefore be more than a risk signal. It can also be a demand signal. It may indicate that employees have identified a genuine use case for AI that the organization has not yet brought into its governed environment.

This does not excuse non-compliance. Some cases will still involve deliberate misconduct.

But mature AI compliance should examine both sides of the event:

What did the employee do?

and

What made unauthorized AI use possible, attractive, or necessary?

For boards and executives, this means treating Shadow AI not only as a disciplinary issue, but also as an opportunity to test whether approved tools, policies, training, approval processes, and monitoring still reflect operational reality.

The objective should not be to prevent every attempt to use AI. It should be to bring legitimate AI use into an environment where the organization can see it, govern it, and manage its risks.

So when Shadow AI appears, ask whether employees followed the rules.

But ask one more question:

Did we build rules, tools, and processes that employees can realistically follow?

And if not, is the real compliance problem larger than the individual incident?

Who Actually Owns AI Compliance?When something goes wrong with an AI system, who is accountable—Legal? Compliance? Or th...
07/08/2026

Who Actually Owns AI Compliance?

When something goes wrong with an AI system, who is accountable—Legal? Compliance? Or the team that deployed it?

Too often, the default answer is “Compliance.” That may seem logical. AI creates regulatory, privacy, operational, and reputational risk. But handing overall ownership to one control function creates a real governance weakness.

Legal and Compliance cannot own every operational risk created by how the business uses AI.

The function selecting, deploying, or relying on an AI system should remain accountable for the purpose of that use case, the decisions it supports, and the consequences it creates.

Front-line teams are essential here. They see how AI is actually used, where processes break, and what risks emerge in daily operations. Their role should go beyond following instructions. They should help review controls, flag weaknesses, and recommend improvements based on what they observe.

Legal, Compliance, Risk, Privacy, and Cybersecurity still play a critical role: setting requirements, challenging assumptions, and monitoring whether controls remain effective. But their oversight is only as strong as the feedback loop from the business.

This reflects the basic logic of the Three Lines Model: management owns and manages risk, oversight functions provide expertise and challenge, and Internal Audit provides independent assurance. The exact allocation should still fit each organization and each use case.

The real test is not “who is responsible for AI” in the abstract. It is whether the organization can answer, specifically:

→ Who approves the use case?

→ Who owns the operational risk?

→ Who monitors the controls?

→ Who challenges the decision?

→ Who can pause or stop the system?

AI-related failures can move faster and spread more widely than many traditional operational failures—across systems, customers, employees, and processes.

That is exactly why shared ownership, clearly defined, matters more than ever.

Good governance does not dilute responsibility. It makes responsibility explicit—and keeps relevant functions connected as the organization learns from real use.

In your organization, is this clearly defined—or does responsibility default to Compliance by habit?

An AI Policy Is Not an AI Compliance ProgramPublishing an AI policy does not mean your organization has an AI compliance...
05/08/2026

An AI Policy Is Not an AI Compliance Program

Publishing an AI policy does not mean your organization has an AI compliance program.

Yet many organizations unintentionally treat the two as if they were the same.

A well-written AI policy is an important foundation. It communicates expectations for the responsible use of AI. But by itself, it does not ensure those expectations are consistently translated into day-to-day operations.

In 2023, Samsung reportedly restricted the use of generative AI tools after employees uploaded confidential internal information into ChatGPT. For many organizations, the incident highlighted that AI adoption introduces operational risks—not just technology risks.

The important questions are no longer whether an AI policy exists.

They are whether the organization was prepared.

Who approved the use of the AI tool?

Had employees received appropriate guidance and training?

Were proportionate controls in place to protect sensitive information?

How would an incident be identified, escalated, investigated, and documented?

These questions distinguish an AI policy from an AI compliance program.

A policy defines expectations.

An AI compliance program provides the structures, processes, and evidence needed to demonstrate that those expectations are being put into practice.

Depending on an organization's size, industry, and AI risk profile, a practical program may include:

• Clear ownership and accountability
• An inventory of AI use cases
• Risk-based approval processes and operational controls
• Employee awareness and training
• Monitoring and periodic review
• Documentation and evidence

There is no universal blueprint. Organizations should build compliance programs that are proportionate to their business, their AI use, and the risks they face.

The objective is not to create more documentation. It is to provide leadership with confidence that AI is being used responsibly, consistently, and in line with the organization's own commitments.

From my perspective as a lawyer and former operations executive, organizations create far more value by embedding policies into everyday operations than by simply publishing them.

As AI adoption continues to grow, leaders should ask one simple question:

Do we have an AI policy or have we built an AI compliance program that actually works?

AI Governance and AI Compliance Are Not the SameAn organization may have an AI policy, an AI committee, and an approval ...
03/08/2026

AI Governance and AI Compliance Are Not the Same

An organization may have an AI policy, an AI committee, and an approval process—and still lack an effective AI compliance program.

The reason is simple: AI governance and AI compliance are closely connected, but they perform different organizational functions.

This distinction becomes more important with AI.

AI systems can be deployed quickly across business functions, produce variable outputs, rely on external providers, and increasingly influence—or execute—decisions at speed.

As a result, the distance between an approved governance principle and what actually happens in daily operations can widen rapidly.

Consider a customer-service team that receives approval to use an AI chatbot. The governance framework requires certain queries to be escalated for human review.

But no one is assigned to monitor whether the escalation rule is followed, document exceptions, or report recurring failures.

The governance decision exists. The compliance mechanism does not.

AI governance establishes direction, accountability, decision rights, risk ownership, and oversight. It determines who may approve AI use, what level of risk is acceptable, which issues require escalation, and what information should reach senior management or the board.

AI compliance translates those expectations, together with applicable obligations and internal commitments, into operational practices: policies, controls, procedures, training, monitoring, documentation, escalation, and evidence.

When governance decisions are not translated into responsibilities and controls, they may remain statements of intent. At the same time, compliance activity without clear direction and risk ownership can become fragmented, reactive, and disconnected from business decisions.

The relationship is therefore not a simple handoff.

From my operational leadership experience, compliance monitoring can expose control weaknesses, recurring incidents, and unclear responsibilities that require governance decisions.

Legal, Compliance, Risk, Privacy, Cybersecurity, and Internal Audit may advise, challenge, monitor, or provide assurance. But they should not automatically become the owners of every risk created by the business use of AI.

The business function selecting, deploying, or relying on an AI system should remain appropriately accountable for its purpose, use, outcomes, and operational risks.

For boards and executives, the practical test is straightforward:

Can the organization show who made the AI decision, who owns the resulting risk, what controls apply, how those controls are monitored, and what happens when they fail?

AI governance sets direction and accountability.

AI compliance makes those expectations operational, demonstrable, and reviewable.

Organizations need both—and they need clear business ownership to connect them.

ที่อยู่

111 Spaces Ratchathewi Building
Ratchathewi
10400

เวลาทำการ

จันทร์ 08:30 - 17:30
อังคาร 08:30 - 17:30
พุธ 08:30 - 17:30
พฤหัสบดี 08:30 - 17:30
ศุกร์ 08:30 - 17:30

เว็บไซต์

แจ้งเตือน

รับทราบข่าวสารและโปรโมชั่นของ Flow AI Co., Ltd.ผ่านทางอีเมล์ของคุณ เราจะเก็บข้อมูลของคุณเป็นความลับ คุณสามารถกดยกเลิกการติดตามได้ตลอดเวลา

ทางลัด

แชร์