
Indonesia has been preparing national rules for artificial intelligence since 2025. As September 2026 closes, the two regulations at the centre of that work have still not been issued, but officials describe them as nearly complete. For enterprises that build or buy AI systems in Indonesia, this is the window in which preparation is cheapest.
What is being regulated
The government is preparing two presidential regulations, known in Indonesian as Peraturan Presiden or Perpres. The first gives legal force to a National AI Roadmap covering 2026 to 2029. It sets strategic direction and priorities for developing and using AI in the country. The second is a regulation on AI ethics, which sets the boundaries for how AI may be developed, deployed and used.
Both build on earlier, non-binding work. The roadmap follows a white paper that the Ministry of Communication and Digital Affairs, known as Komdigi, released for public consultation in 2025. The ethics regulation builds on ethical guidelines the ministry had already published. The difference is that a presidential regulation is binding, and these would be the first binding AI rules of this kind in Indonesia.
Where the regulations stand
In January 2026, Minister of Communication and Digital Affairs Meutya Hafid said both documents had been drafted in 2025 and would be prioritised for President Prabowo Subianto's signature during 2026. In July, Indonesian business media reported that the roadmap and ethics rules were still being processed.
In early September, Edwin Hidayat Abdullah, Komdigi's Director General of Digital Ecosystem, was reported as saying that both regulations were in their final stage and awaiting the President's signature, with completion targeted for the end of 2026. No signing date has been announced. Timelines for these regulations have moved before, so the target should be read as an intention and not as a deadline.
A risk-based approach
According to the same September report, the ethics regulation sorts uses of AI by risk. Some uses would be prohibited. Others would be classed as high risk and allowed only under strict oversight. The remainder would be treated as lower risk. The sectors officials have named as priorities include education, healthcare, economic services and public services.
This structure will be familiar to anyone who has followed AI regulation elsewhere, where obligations scale with the potential for harm. The published reporting does not yet say exactly which uses fall into which category in Indonesia. Until the text is issued, organisations should avoid assuming that a classification used in another country will carry over unchanged.
The detail will come sector by sector
The presidential regulations are a framework. Officials have said that once they are signed, each ministry and government agency will issue its own derivative rules for AI in its sector, with Komdigi coordinating governance and the individual institutions handling technical implementation. A national coordination task force and regulatory sandboxes have also been described as part of the plan.
In practice, this means a bank, a hospital group and a retailer will not face identical requirements. Each should expect its own regulator to set the specifics. The minister has also said that the first ministerial regulation will address the labelling or watermarking of AI-generated content on digital platforms, to be issued soon after the presidential regulation takes effect.
What enterprises can do before the signature
None of the steps below depends on the final wording. They are the foundations any risk-based regime asks for, and they are good engineering practice in their own right.
- Build an inventory of AI use. List every system that uses AI, including features inside software bought from vendors, and record what each one decides or produces.
- Rank each use by its consequences. A model that drafts internal notes is different from one that influences a credit, hiring or medical decision. Put the most effort where people are most affected.
- Define human oversight for the higher-risk uses. Decide who reviews outputs, who can override them, and how those interventions are logged.
- Prepare to label AI-generated content. If your organisation publishes text, images, audio or video produced by AI, work out now how it would be marked and where in the pipeline that happens.
- Check the data underneath. Indonesia's Personal Data Protection Law already applies to personal data used to train or run AI systems, whatever the AI regulations finally say.
- Review vendor contracts. Ask suppliers how their models are tested, what data they retain, and what they will provide if a regulator asks how a decision was made.
- Name an owner. Give one person or committee responsibility for AI governance, so that new rules have somewhere to land.
Why this matters for architecture, not only for compliance
Requirements such as oversight, logging and labelling are far easier to meet when they are designed into a system than when they are added afterwards. An AI feature that records its inputs, the model version used and the human decision that followed can answer a regulator's question in minutes. One that does not may need to be rebuilt.
Organisations that treat governance as part of the architecture tend to move faster once rules arrive, because they are adjusting controls that already exist. That is the practical case for preparing now: the work is useful whether the regulations are signed next month or next year.
What to watch next
- The signing and publication of the two presidential regulations, and the final text of the risk categories.
- The first ministerial regulation, expected to cover labelling of AI-generated content.
- Sector rules from individual regulators, which will carry the operational detail.
- Any transition period, which will determine how quickly existing systems must comply.
We will update this article when the regulations are issued.
Sources
- Dua Perpres AI Tunggu Tanda Tangan Presiden Prabowo · Selular.ID(opens in a new tab)
- Indonesia prioritizes AI regulation in 2026, says Communications Minister · Indonesia Business Post(opens in a new tab)
- Indonesia prepares presidential regulations to guide AI adoption in government · GovInsider(opens in a new tab)
- Peta Jalan dan Etika AI Nasional Masih Diproses Menuju Perpres · Bisnis.com(opens in a new tab)
This briefing was prepared by the Indotek editorial desk with AI assistance, from the public sources listed above. It is general information, not legal or professional advice.
AI & Agentic AI
How Indotek can help
Preparing for AI regulation is mostly an engineering task: knowing where AI is used, and building oversight, logging and labelling into the systems themselves. That is the kind of work Indotek does.
- AI use inventory and risk review: we map where AI is used across your systems, including inside vendor software, and rank each use by its consequences.
- Governed AI systems: we design assistants and agents that act inside explicit permissions, log what they do and hand off to a person when stakes are high.
- Evaluation built in: every AI feature we build ships with an evaluation set, so quality is measured and can be shown, not assumed.
- Labelling and traceability: we add content labelling and decision records to AI pipelines, so an answer to a regulator's question already exists.
