We are getting more and more enquiries from companies with manufacturing sites in Thailand and Vietnam asking how they should approach generative AI adoption at their overseas subsidiaries. What makes it hard is that the regulations, the maturity of everyday usage, and the working languages are all different from one site to the next. If head office hands down a single uniform rule set, the local teams end up unable to use anything. If head office leaves it to each site, control disappears. In this article we first look at what actually differs between Thailand and Vietnam using published data, then set out the failure patterns that show up when head office drives a rollout across several sites, a roadmap that runs from a shared platform through to governance design, and the regulatory points that matter site by site.
Generative AI adoption varies widely from one overseas site to the next
When you start thinking about a multi-site rollout, the first thing to do is not to compare tools. It is to understand the environment each of your sites actually sits in. Even within ASEAN, the situation around generative AI differs considerably from country to country. And those differences cannot be explained along a single axis of countries that are ahead and countries that are behind.

Even inside Japan, size-based gaps are hidden behind the average
Before thinking about gaps between sites, it helps to look at the domestic picture, because the structure becomes easier to see. According to the survey on corporate trends regarding generative AI (March 2026) published by Teikoku Databank on 14 May 2026, 34.5% of companies overall were using generative AI. Within that figure, 4.4% answered that they use it heavily and 30.2% answered that they use it somewhat (the components do not add up exactly to the overall figure because of rounding). The survey covered 23,349 companies and obtained valid responses from 10,312 of them.
What deserves attention is what sits behind that 34.5% average. Broken down by company size, large enterprises were at 46.5%, mid-sized companies at 32.4%, and small companies at 28.0%, so there is a clear gap by scale. Cut by headcount, the gap widens further. Companies with more than 1,000 employees were at 63.6%, those with 301 to 1,000 employees at 51.9%, and those with 5 or fewer employees at 29.6%. In other words, the usage rate differs by more than a factor of two between companies with more than 1,000 employees and those with 5 or fewer.
The reason these numbers connect to the overseas story is that a group of subsidiaries is, in practical terms, a collection of organisations of very different sizes. A structure with several hundred people at the Japanese head office, a little over a hundred at the Thai site and a few dozen at the Vietnamese site is entirely common. If a domestic survey shows this much variation by size, it is natural to assume that the same kind of gap exists between head office and the overseas sites, and between the overseas sites themselves. In practice, when a head office IT department feels that the company is doing rather well with generative AI, that impression comes from the largest organisation in the group, and it often does not match how the sites experience it.
If you build a rollout plan by looking only at the average, that gap disappears from view. What you need to establish first when designing a rollout is not the company-wide average but the distribution across sites.
Thailand is investment-led, with regulation still taking shape
Next, Thailand. What stands out there is the movement of capital. According to figures published by the Thailand Board of Investment (BOI) on 23 July 2026, investment applications in the first half of 2026 totalled $43.6bn, roughly 1.47 trillion baht, across 1,299 projects. That is a 37% increase year on year.
The largest sector within that total was digital and AI infrastructure, accounting for $33bn, roughly 1.12 trillion baht. That means the great majority of first-half application value was concentrated in this one area. With investment flowing into data centres and cloud infrastructure, it is a fact that the foundation for running AI workloads in Thailand is thickening rapidly.
On the regulatory side, however, the shape is not yet fixed. Thailand’s Electronic Transactions Development Agency (ETDA) released a draft AI Act on 9 July 2026 and ran a public consultation until 14 August 2026. The draft is described as risk-based regulation resembling the EU AI Act, including provisions for extraterritorial application. As of late August 2026, however, the law has not yet been enacted. It remains at draft stage.
For country-specific implementation steps inside Thailand, our guide to AI implementation in Thailand covers the topic from a single-country perspective. This article instead looks at where Thailand sits once you line several sites up alongside each other.
In short, Thailand is a place where investment and physical infrastructure have moved first and the legal framework is trying to catch up. From a head office point of view, that reads as a site where the regulatory constraints are loose today but the conditions may well change in the near future. Unless you put records in place now that show what is being used and how, you will end up reconstructing that history retroactively once the law is enacted.
Vietnam is ahead on both regulation and usage
Vietnam has moved in the opposite order. Vietnam enacted its Law on Artificial Intelligence, Law No.134/2025/QH15, on 10 December 2025, and it has already been in force since 1 March 2026. Alongside it, the Law on Digital Transformation, Law No.148/2025/QH15, has been in force since 1 July 2026. Vietnam has therefore completed national-level AI legislation ahead of Thailand.
Actual usage is ahead as well. According to estimates from the Microsoft AI Economics Institute cited in the International Labour Organization (ILO) brief “Generative AI and jobs in Viet Nam” published in April 2026, Vietnam’s generative AI usage rate rose from 21.2% in the first half of 2025 to 23.5% in the second half. Lining up ASEAN countries using the same estimates, Thailand stands at 10.7%, Indonesia at 12.7%, and the Philippines at 18.3%. Vietnam sits on the more advanced side of generative AI usage within ASEAN, while Thailand is relatively low.
The same ILO brief also estimates that 20.8% of Vietnam’s workforce, roughly 11.5 million people, are engaged in work exposed to generative AI. That figure is presented in the context of employment impact, but read from a company’s perspective it also means there is a substantial volume of work that generative AI could either replace or support.
Considerations for selecting a development partner in Vietnam are covered separately in our article on how to choose an AI development company in Vietnam. The concern of this article is what these country-level differences mean for a company operating multiple sites.
On the subject of cross-country comparison, PwC Japan also publishes ongoing survey work that lines up several countries on generative AI. How to read any individual number varies by survey, but the underlying tendency, that the degree of adoption differs by country, appears consistently across multiple studies and is worth keeping in mind.
Putting the site-by-site differences on one page
Setting the numbers so far side by side makes the difference between Thailand and Vietnam clear.
| Dimension | Thailand | Vietnam |
|---|---|---|
| National AI legislation | Draft stage. ETDA released the draft on 9 July 2026 with public consultation until 14 August. Not enacted as of late August 2026 | In force. AI Act (Law No.134/2025/QH15) enacted 10 December 2025, in force 1 March 2026 |
| Related regulatory movement | Expected to be risk-based regulation including extraterritorial application | Law on Digital Transformation (Law No.148/2025/QH15) also in force since 1 July 2026 |
| Estimated generative AI usage rate | 10.7% in the ASEAN comparison from Microsoft AI Economics Institute estimates | Rose from 21.2% in the first half of 2025 to 23.5% in the second half, per Microsoft AI Economics Institute estimates |
| AI-related infrastructure investment | Of $43.6bn in first-half 2026 investment applications, digital and AI infrastructure was the largest sector at $33bn | Not covered in this article |
| Estimated employment impact | Not covered in this article | An estimated 20.8% of the workforce, roughly 11.5 million people, are in work exposed to generative AI |
| Character from head office view | Investment-led, regulation following. Loose today but conditions may change | Regulation-led and usage-led. Requires aligning with the rules from the outset |
What we want you to take from this table is not which country is better, but that the order of events differs. In Thailand capital investment came first and regulation is still to come. In Vietnam regulatory groundwork was completed first and the usage rate is also higher. Even under the same heading of an ASEAN manufacturing site, the move head office should make is not the same.
The same structure echoes the domestic Teikoku Databank data mentioned earlier. Just as an overall average of 34.5% conceals 63.6% for companies with more than 1,000 employees sitting alongside 29.6% for those with 5 or fewer, an average that lumps all overseas sites together is of almost no use for decision-making. What head office needs to look at is the distribution across sites, and to vary the sequence and the intensity of the rollout according to that distribution.

The illustration above shows that even sites of identical size can be surrounded by institutional frameworks of very different thickness depending on the country. The site on the left is in a country where the framework is not yet settled, the site on the right is in a country where legislation is already complete, and the difference in wall thickness represents the gap in regulatory maturity between the two. This is the starting point for any company with multiple sites.
Common failures in head office-led generative AI rollouts
Once you understand the situation at each site, the problems that arise during an actual rollout are fairly predictable. Here we set out the failures we see most often at companies with multiple sites.
Each site spins up its own separate tools
This is the most common one by far. Before head office issues any policy, each site starts using free tiers or services contracted out of departmental budgets. The Thai site picks a service that is popular locally, the Vietnamese site picks one the development team is comfortable with, and head office picks a different one because Japanese-language support matters. That is how the split happens.
What makes this state of affairs troublesome is that the cost of consolidating later is far larger than people expect. Because the teams have already woven these tools into their workflows, any attempt to standardise triggers resistance along the lines of having something taken away that was working. Prompts, configurations and practical know-how have also accumulated separately per service, so switching causes a temporary drop in productivity on the ground.
More often than not, while head office assumes nothing has started yet, the sites are already running. You can infer this from the usage data cited earlier. In an environment such as Vietnam, where the usage rate has climbed to 23.5%, you get closer to reality by assuming that employees are already touching generative AI as individuals.
Cross-border data flows and security get pushed to the back
The next most common pattern is that all the discussion goes into how to use the tools, and where the data is actually being sent is examined only afterwards. With generative AI services, which country’s servers process the information you enter depends on the form of usage. For an overseas subsidiary, local personal data protection law and contractual constraints on handling business data both come into play.
In a country such as Vietnam, where the AI Act and the Law on Digital Transformation are already in force, discovering later that the requirements were not in fact met means a large amount of rework. Even in a country such as Thailand, where the law is still at draft stage, the fact that the draft is being debated in the direction of risk-based regulation with extraterritorial application means it is safer to design on the assumption that conditions will change once it is enacted.
From the point of view of the people doing the work, this examination looks like a nuisance. But deferring it produces the most wasteful possible outcome, where a pilot delivers good results and then legal stops the project just before company-wide rollout.
Operating rules written for a Japanese context are simply handed down
Head office writes a generative AI usage policy, translates it into English, and distributes it to the sites. The sequence sounds natural, but on its own it often fails to work.
There are three reasons. First, the policy is written on the assumption of Japanese law and internal Japanese company systems, so it does not show how each item maps to local regulation. Second, it is built mainly around a list of prohibitions, so a reader cannot work out what they are actually allowed to do. Third, the subtle parts of the judgement criteria fall away during translation.
The third point in particular is easy to miss. Suppose the policy says not to enter confidential information. Where the line falls on what counts as confidential is obvious at a Japanese head office, and that shared sense simply does not travel. The person at the site cannot make the call, so they swing to one of two extremes, either not using the tool because it is unclear, or using it without worrying about it.
How to write a generative AI usage policy in the first place is covered in our article on building a generative AI usage policy. When rolling one out to overseas sites, though, you need to think in terms of rebuilding it as a local edition rather than translating it.
The pilot is run only at head office
Effectiveness is verified in a head office department, the results look good, and the project is then rolled out horizontally to the sites. This sequence is another common way to fail.
Head office work comes with Japanese-language documentation already in place, staff with comparatively high IT literacy, and established access to internal systems. Results produced in that environment do not reproduce in the environment at a local site. At a local site the documents in play are a mix of Thai or Vietnamese with English and Japanese, the state of internal systems is different, and staff backgrounds are more varied.
When you take head office pilot results to a site and present them, the local reception is that it only worked because it was head office work. Once that is how it lands, the rollout becomes difficult.
Effectiveness metrics differ from site to site
If each site measures results its own way, head office loses any view of the whole. One site reports hours saved, another reports the number of users, another reports the number of processes where the tool has been introduced. When that happens, sites cannot be compared and you cannot judge where additional investment should go.
Aligning the metrics is not about grading the sites, it is about enabling head office to make investment decisions. Unless you share that purpose up front, the local reading will be that they are being monitored.
The local IT team is left out of the process
When the head office IT department leads, the site’s own IT staff can end up outside the loop right up until implementation. In actual operation, though, account management, troubleshooting and answering questions from the shop floor all fall to the local IT staff.
If operations are handed over to them without their having understood the intent behind the design, they cannot answer questions, and as a result usage does not spread. At some sites there are only one or two IT staff, and how well that single person understands the system determines the adoption rate for the entire site.
A roadmap for rolling out generative AI to overseas sites
With those failure patterns in mind, here is the order we recommend actually working through. We break it into four stages.
Step 1 Decide the shared platform first
The first thing to do is neither a pilot nor policy drafting. It is deciding the platform that all sites will share. If you get the order wrong and wait for pilot results before picking a tool, individual adoption will have progressed at each site in the meantime.
When choosing a shared platform, the conditions to look at come before any richness of features.
First, head office must be able to see usage logs. If you cannot see who is using how much, you can measure neither rollout progress nor results. Second, the location of data processing and the retention policy must be explicit in the contract. You will certainly need this later for regulatory compliance. Third, the platform must handle the working languages of the sites. In an environment mixing Thai, Vietnamese, English and Japanese, check in advance how far it holds up in practice. Fourth, adding and removing accounts must be possible centrally from head office. At sites with high staff turnover, this administrative cost accumulates.
Rather than hunting for something feature-perfect, deciding early on something that satisfies these four points and pushing it through all sites will, in the end, make the rollout faster.
Step 2 Pick a pilot site and run it locally
Once the shared platform is settled, run the pilot at a site rather than at head office. What matters here is which site you choose.
Three criteria work well for the selection. First, the local IT staff need a reasonable level of understanding and motivation. If that is weak, head office ends up permanently attached to the project. Second, the target process needs to exist in common at other sites too. Producing results in a process unique to that one site gives you nothing to roll out. Third, choose the country on the stricter regulatory side. Carrying an operating model built in a loose environment into a strict one causes more rework than taking a model built under strict conditions and extending it to a looser environment.
On that third criterion, choosing Vietnam as the pilot site, where the AI Act is already in force, is a defensible decision. Because the constraints are explicit, the line on what you may and may not do settles quickly. Conversely, running the pilot in Thailand while regulation is still at draft stage leaves open the possibility that conditions change on enactment and the design has to be redone.
Keep the scope of the pilot narrow and limited to specific processes. Rather than trying to produce a company-wide effect, prioritise reaching a state where local staff can say, about one or two processes, that this genuinely made things easier.
Step 3 Design governance as shared rules plus local discretion
Governance design runs in parallel with the pilot. The central idea here is not to bind everything with head office rules.
Draw the line first between what head office decides in common and what is left to the sites. Distribute a policy while that line remains vague and the sites will either be unable to make decisions, sending a flood of questions to head office, or quietly drift into their own arrangements.
| Area | Decided centrally by head office | Decided locally by the site |
|---|---|---|
| Tools and platform | Approved list of services, contract and billing point of contact | Departmental distribution and priority within the site |
| Data handling | Classification criteria for what may be entered, definition of confidential | Additional personal data restrictions under local law |
| Records and audit | Log retention policy, reporting format and frequency | Point of contact when local authorities require explanation |
| Training | Shared materials and a minimum level of attainment | Language, delivery format, addition of local examples |
| Business application | Explicit list of prohibited uses | Recommended uses and mapping to local processes |
The left column covers the parts where variation between sites destroys control. The right column covers the parts where variation between sites is only natural. If head office reaches into the right column, operations stop working. If you delegate the left column to the sites, control collapses.
The item people struggle with most when drawing this line is the classification criteria for what may be entered. It belongs in the head office column, but showing only abstract principles leaves it unusable locally. To make it work in practice, you need to list the types of document actually exchanged at that site and show, as concrete examples, where each one falls in the classification. This work does not reach the required precision unless it is done together with local staff.
Step 4 Widen the rollout and make it stick
Once the pilot shows traction, extend it to the other sites. What works at this stage is not the numbers, but the explanation given by the local staff themselves.
The same content lands differently depending on whether it is presented by someone from head office or by a local colleague from the pilot site. When the message shifts from “we are doing this because head office says so” to “apparently it genuinely made life easier at the site next door”, the pace of the rollout picks up. Setting up a forum where staff at different sites can talk to each other directly also reduces the volume of individual support head office has to provide.
Align the effectiveness metrics during this adoption stage. There is no need for many of them. Number of users and frequency of use, change in time required for each target process, and qualitative reports from local staff. If those three come in from every site in the same format, you can decide where to invest next.

Why the sequence matters
There is a reason behind the order of these four stages. Deciding the shared platform first closes off the options before individual adoption spreads. Running the pilot at a site rather than head office is because head office results do not reproduce. Running governance in parallel with the pilot is because completing a policy first produces something purely theoretical, while writing it afterwards means local teams have already hardened into their own arrangements. Widening the rollout last is because trying to extend horizontally without a proven case means every site restarts the same evaluation from scratch.
Plenty of companies proceed in the reverse order, starting with policy drafting, moving through a head office pilot, and choosing the tool last. That sequence produces rework on three fronts at once. The policy does not match ground reality, the pilot results do not reproduce at the sites, and by the time you get to tool selection each site already holds its own contract.
Regulatory and language points to nail down site by site
At each stage of the roadmap you need to weave in circumstances specific to each site. Here we use Thailand and Vietnam as examples of what to check in practice.
Thailand, handling a draft AI Act alongside the PDPA
What is settled today in Thailand is the Personal Data Protection Act (PDPA). Whether entering information into a generative AI service constitutes processing of personal data, and whether it constitutes disclosure to a third party, depends on the content of the information and the contractual form of the service being used. If you handle documents containing HR information or contact details for people at business partners, this check needs to be completed first.
As for the AI Act, the draft published by ETDA on 9 July 2026 went through a public consultation that ran until 14 August 2026, and as of late August 2026 it has still not been enacted. You therefore cannot lock down concrete compliance with a Thai AI Act at this point in time.
That does not mean there is nothing to do. Since the draft is risk-based regulation resembling the EU AI Act and is being debated in a direction that includes extraterritorial application, the items likely to be required after enactment can be anticipated. Records of risk assessment per use case, an inventory of which AI is used in which process, and retention of usage logs. These three are unlikely to be wasted effort regardless of how the final text settles.
What a Thai site should be doing now is not waiting for the law to pass, but starting to build the records it will be able to submit once it does. As noted above, investment in Thailand is concentrated in digital and AI infrastructure, with $33bn of the $43.6bn in first-half 2026 investment applications going to that sector. Because the infrastructure environment will keep improving, the barrier to starting to use these tools is if anything falling. Retrofitting a record-keeping mechanism after volume has grown is hard work.
Vietnam, an AI Act already in force and the handling of personal data
In Vietnam the AI Act (Law No.134/2025/QH15) has been in force since 1 March 2026. The Law on Digital Transformation (Law No.148/2025/QH15) has likewise been in force since 1 July 2026. Unlike Thailand, this is not a case of rules yet to be decided but of rules already being applied.
For that reason, generative AI use at a Vietnamese site has to begin by confirming the requirements of local law as the precondition for any internal policy. On personal data too, Vietnam has regulation covering personal data protection, and procedures relating to cross-border transfer of data can come into play. Depending on how the generative AI service is used, this issue is engaged.
At the same time, Vietnam is ahead on actual usage. The generative AI usage rate rose from 21.2% in the first half of 2025 to 23.5% in the second half, a high level compared with Thailand at 10.7%, Indonesia at 12.7% and the Philippines at 18.3%. The ILO brief also estimates that 20.8% of the workforce, roughly 11.5 million people, are engaged in work exposed to generative AI.
The combination of settled regulation and advanced usage has advantages when viewed from head office. The criteria for what is permitted are clear, and local employees are already comfortable with generative AI. This is precisely why, as noted earlier, choosing Vietnam as the pilot site is a defensible decision.
Absorbing differences in language and IT literacy
Alongside regulation, the factor that bites hardest in practice is language. Business documents at overseas sites normally mix the local language, English and Japanese. The moment you try to have generative AI process something, that mixture becomes an input-side problem.
Summarising local-language material in Japanese, converting Japanese work instructions into the local language for distribution on the floor, having English technical documents explained in the local language. Demand for these uses is high at local sites, but the question of who verifies output quality remains. Technical terms and company-specific phrasing lose accuracy if you simply leave them to the model.
The practical way forward is to build a glossary first. Equipment names, process names, item classifications, internal job titles. Organising the translations of these per site raises the stability of the output considerably. It is unglamorous work, but whether or not you have done it makes an obvious difference to usability.
For differences in IT literacy, delegating the format of training to the sites is effective. Head office sets the shared materials and the level of attainment, and leaves delivery to the local team. Some sites suit classroom sessions, others only take it in through hands-on work on real business screens. The domestic survey also shows a tendency for smaller organisations to have lower usage rates, and at sites with few people, distributing materials alone will not move anything. Adoption tends to spread by one person becoming capable and teaching those around them, so it is more efficient to focus on creating that one person first.
A sense of costs and how to think about budget
Costs are structured differently depending on the number of sites and the number of users. Here we set out what cost categories arise as a general orientation. Because the specific amounts vary considerably with contract form and scale, please do not treat them as definitive figures.
The first category is the recurring licence cost of the generative AI service. Enterprise services are typically billed monthly per user, and consolidating contracts across sites creates room to negotiate the unit price. Contract separately per site and both the unit price and the administrative overhead go up. This is one of the reasons to decide the shared platform first.
The second is initial build cost. The scale changes depending on whether you are integrating with existing internal systems, making internal documents searchable, or embedding the tool in a workflow. If you start with a general-purpose service and no integration, initial cost can be kept low.
The third is the cost of training and adoption. This is hard to see as a number, and in practice it is the most frequently overlooked. Time from site staff, localisation of training materials, and a structure for answering questions. Cut corners here and you end up paying licence fees for something nobody uses.
The fourth is the cost of regulatory verification. Local legal review, and where necessary external advice, fall into this category. In a country such as Vietnam where the legislation is already in force, it lands in one block at the start. In a country such as Thailand where legislation may yet be enacted, it is realistic to expect it to arise again at the point of enactment.
The practical way to structure the budget is to separate the pilot stage from the rollout stage. Keep the pilot narrow in scope, with few people and a short, defined period. Building the rollout budget only after results are confirmed makes approval easier than applying for all sites at once, and limits the loss if it does not work.
One more thing that helps when you have many sites is levelling the cost through the order of the rollout. Launching all sites simultaneously concentrates the training and support load into a single moment. Working through the pilot site, then sites of similar size, and finally the smaller sites lets you reuse the head office support structure.
Frequently asked questions
Should generative AI adoption at overseas sites be head office-led or locally led?
Rather than one or the other, the realistic answer is to split by area. Approval of which services may be used, the classification criteria for what may be entered, and the format for log retention and reporting are decided centrally by head office, because variation between sites on these points destroys control. On the other hand, which processes to apply it to, what language training is delivered in and how, and what additional restrictions local law requires are left to the sites. If head office dictates business application in detail, it will not match ground reality and will go unused. The key point is to write the dividing line down at the outset so that each site knows clearly what it can decide for itself.
How do generative AI regulations differ between Thailand and Vietnam?
They are at different stages. Vietnam enacted its AI Act (Law No.134/2025/QH15) on 10 December 2025, and it has been in force since 1 March 2026. The Law on Digital Transformation (Law No.148/2025/QH15) has been in force since 1 July 2026. In other words, applicable law already exists. In Thailand, ETDA released a draft AI Act on 9 July 2026 and ran a public consultation until 14 August 2026, and as of late August 2026 it has not been enacted. The settled regulation in Thailand today therefore centres on the Personal Data Protection Act (PDPA). This difference produces a difference in approach. In Vietnam you build operations on the requirements of local law, while in Thailand you prepare in advance the records you will be able to submit after enactment.
Why do generative AI usage rates differ so much between sites?
Because the regulatory environment, the state of infrastructure and the size of the organisation are all acting at once. Microsoft AI Economics Institute estimates put Vietnam’s generative AI usage rate at 23.5% in the second half of 2025, against 10.7% for Thailand, 12.7% for Indonesia and 18.3% for the Philippines. On top of that country-level variation, differences by organisational scale compound it. In the domestic Teikoku Databank survey, the overall usage rate was 34.5%, while companies with more than 1,000 employees stood at 63.6% and those with 5 or fewer at 29.6%, a gap of more than a factor of two. Because overseas sites are often smaller than head office, the country gap and the scale gap push in the same direction. You need to check the actual situation at each site rather than judging by averages.
How should we choose the pilot site?
Narrow it down using three criteria. The local IT staff have understanding and motivation, the target process also exists in common at other sites, and the country is on the stricter regulatory side. The third is easy to overlook but important. An operating model built in an environment with explicit constraints can be carried into a looser environment, but not the other way round. On that view, choosing Vietnam, where the AI Act is already in force, as the pilot site is a defensible decision. Keep the scope narrow and prioritise reaching a state where local staff can feel the benefit in one or two processes. Aiming for company-wide results from the start makes verification take too long and the momentum drains away.
Is it enough to translate the generative AI usage policy written at head office and distribute it?
Usually not. The reasons are threefold. The policy is written on the assumption of Japanese law and internal company systems, it is built mainly around a list of prohibitions so readers cannot tell what they are allowed to do, and the subtle parts of the judgement criteria fall away in translation. In particular, a statement such as “do not enter confidential information” leaves local staff unable to judge where the line on confidential falls. To make it work in practice, you need to list the types of document actually handled at that site and show, with concrete examples, where each falls in the classification. Because this work does not reach the required precision unless it is done together with local staff, the realistic approach is to treat it as rebuilding a local edition rather than translating.
Conclusion
The first stumble in generative AI adoption at overseas sites is treating those sites as a single block. Put Thailand and Vietnam side by side and the order in which they have progressed is plainly different. Thailand is investment-led, with digital and AI infrastructure accounting for $33bn of the $43.6bn in first-half 2026 investment applications, while its AI Act reached the stage of a draft published by ETDA on 9 July 2026 and remains unenacted as of late August 2026. Vietnam is the reverse, having enacted its AI Act (Law No.134/2025/QH15) on 10 December 2025 with effect from 1 March 2026, and with the Law on Digital Transformation in force since 1 July 2026, so its regulatory groundwork was completed first. Usage is ahead too, rising from 21.2% in the first half of 2025 to 23.5% in the second half, against 10.7% for Thailand, 12.7% for Indonesia and 18.3% for the Philippines.
This difference has the same structure as the size-based gap visible domestically. The Teikoku Databank survey showed an overall usage rate of 34.5%, with large enterprises at 46.5%, mid-sized companies at 32.4%, small companies at 28.0%, and companies with more than 1,000 employees at 63.6% against 29.6% for those with 5 or fewer. Averages are not material for decisions.
In terms of approach, the sequence is to settle the shared platform first and close off the options before individual adoption spreads, run the pilot not at head office but at a site in the stricter regulatory environment, design governance with a clear line between head office commonality and local discretion, and widen the rollout on the back of a proven case. Following this avoids the rework of a policy that stays theoretical, pilot results that do not reproduce, and every site restarting the same evaluation. On costs, the practical approach is to estimate four categories separately, licences, initial build, training and adoption, and regulatory verification, and to budget the pilot and the rollout as separate items.
Circumstances differ from site to site, and that is a given. Even so, the foundation that can be standardised and the line marking what should be left to the sites can both be designed. If you can tell us your current site structure and the state of your operations, we can help you form a view on questions such as which site to start from and how far your existing internal rules can be reused. Drawing on our experience supporting ASEAN sites including Thailand and Vietnam, TOMAS TECH works between head office and the local teams from the point of putting the approach together. Feel free to reach out even at an early exploration stage, before any internal direction has been settled, through our contact page.
References
- Survey on corporate trends regarding generative AI (March 2026) – Teikoku Databank
- Thailand Secures $43.6bn 1H 2026 Investment Surge as Big Tech Bets on Digital and AI – Thailand Board of Investment
- Thailand Draft AI Act – Seven Key Implications – Baker McKenzie
- Generative AI and jobs in Viet Nam – International Labour Organization
- Generative AI survey spring 2026, six-country comparison – PwC Japan