Direct Answer: There Is No Single Mandatory Indonesia AI Risk Tier Yet

As of 24 September 2026, Indonesia does not operate one universally binding, numbered AI risk-classification system that every company must apply to every model. Instead, obligations are assembled from several sources at once: the Personal Data Protection Law (Law No. 27 of 2022), sector rules covering finance, health, telecommunications and digital services, the electronic-system registration regime administered through the Ministry of Communication and Digital, and emerging national guidance that draws on international practice. Because these instruments answer different questions, most Indonesian firms still need an internal classification method that maps each AI use case to the laws that actually touch it. The safest answer is therefore practical rather than legalistic: build a tiered internal register, map each tier to specific data and impact requirements, and re-check the mapping whenever a model, vendor or data source changes. A company that deploys a payroll-screening bot and a disaster-warning model should not treat them as the same risk category simply because both use machine learning. Classification is not about the algorithm alone; it is about the decision, the people affected, the data involved and what happens when the system is wrong. A useful working rule is that the higher the consequence of error, the heavier the required review, regardless of how simple the technology looks. Vendors claiming a certified Indonesian AI risk score should be asked which statute their method cites, because a self-assigned label has little legal weight on its own.

Also worth reading: What is AI knowledge ops for SMBs in SEA and how can Indonesian businesses implement it effectively by September 2026? · What is the state of AI workflow automation for Indonesia in 2026, and how should Indonesian businesses actually adopt it? · What is the definitive Indonesian AI regulatory compliance guide for businesses in 2026?

The Legal Drivers Behind Any Classification Scheme

Indonesia's main binding data rule is the Personal Data Protection Law, or PDP Law, which took effect on 17 October 2024 after its enactment and transition window. It distinguishes general personal data from specific personal data, and the latter category includes health records, biometric identifiers, genetic information, criminal-conviction data, children's data and financial-account information. For risk purposes, this distinction is more useful than a generic low, medium and high scale, because it tells you which consent, notice and security duties attach to a system before the model has even run a single prediction. The PDP Law also places duties on both data controllers and data processors, requires purpose limitation, and gives data subjects rights such as access to their data and correction of inaccuracies. A company running AI-based age verification, for example, should expect a classification debate not only about accuracy but also about whether identity documents are processed lawfully and whether minors' data is being handled under additional protections. The implementing regulations around the PDP Law have moved in steps rather than one clean release, so compliance teams should track official channels rather than rely on consultancy summaries. Alongside the PDP Law, sector rules matter: banks face risk-based supervision, hospitals answer to health-ministry standards, and digital platforms fall under electronic-system rules. Classification frameworks that ignore sectoral overlays tend to understate risk precisely where the stakes are highest.

Why Organisations Need a Formal Classification Even Without a National Scheme

The absence of a single national tier does not remove the need for one internally, and the reasons are practical. First, procurement teams cannot evaluate vendors without a shared vocabulary; if a supplier describes a system as medium risk, the buyer needs to know whether that means marketing text generation or credit decisioning. Second, incident response depends on prior classification: a team that has already labelled a model high risk will have escalation paths, backup controls and retention rules ready, while an unclassified system tends to be handled ad hoc after a failure. Third, classification creates an audit trail that demonstrates good faith to regulators, customers and insurers. A documented register showing that a system was assessed in March 2026, reviewed in July 2026 and re-assessed after a model update is far stronger evidence than an undocumented assurance that the tool is safe. There is also a regional trade dimension. The European Union's AI Act applies to providers placing systems on the EU market, and certain high-risk obligations tied to safety components in regulated products become applicable from 2 August 2027, with the broader schedule taking effect from 2 August 2026. Indonesian firms supplying global customers or building into EU-bound products should therefore classify against both local law and the destination regime rather than assume domestic rules are sufficient. The point of a formal scheme is speed and consistency of decision-making, not a certificate that transfers risk to a vendor.

A Practical Four-Tier Internal Method With Numeric Thresholds

A workable internal method scores impact and likelihood on a 1-to-5 scale each, multiplying them into a 1-to-25 risk score. Impact considers whether the output affects health, safety, employment, credit, education, liberty or legal rights; likelihood considers the probability of error given real operating conditions, including bad training data, distribution shift and adversarial misuse. Scores of 20 to 25 are treated as high risk and require executive approval, independent testing, a documented appeal path and a named accountable owner. Scores from 10 to 19 are medium risk and require privacy review, human oversight for consequential decisions and quarterly control checks. Scores from 5 to 9 are low risk and need documented purpose, access controls and annual review. Scores of 1 to 4 are minimal risk and are covered by standard IT and acceptable-use policies. A separate category should exist for uses the organisation refuses to deploy at all, such as fully automated termination of employment or biometric surveillance without lawful basis, regardless of calculated score. The table below shows how this scheme compares with two other common approaches used in the market.

FeatureInternal impact-and-likelihood tiersEU AI Act mappingNIST AI RMF or ISO/IEC 42001 programme
Core questionHow bad is the consequence, and how likely is the error?Is the system prohibited, high-risk, limited-transparency or minimal?Are governance, measurement and management controls operating?
Typical outputScore from 1 to 25 plus tier labelLegal category with dated obligationsCertificate, maturity report or management-system record
Best suited forFast decisions on Indonesian deploymentsFirms selling into or sourcing from the EULarger organisations building enterprise assurance
Time to first result2 to 6 weeks for a pilot register4 to 12 weeks including legal analysis3 to 9 months for a full management system
Known limitationNo external legal authorityComplex; requires product and geography analysisProcess-focused; does not replace use-case analysis
Many organisations adopt the internal tiers first and layer the other two approaches on top, because the internal method can be completed quickly and gives immediate governance value while longer programmes mature.

How Classification Changes Across Common Indonesian Use Cases

Use cases vary sharply in risk, and the differences are easy to miss. A hospital using AI to flag abnormalities in a CT scan is a high-risk decision-support system: the output influences diagnosis, the data is specific personal data under the PDP Law, and errors can harm patients. A disaster-risk model that issues public warnings is different in form but still consequential, because inaccurate warnings erode public trust and may affect evacuation behaviour; it needs monitoring for false alarms and clear human review before mass communication. A customer-service chatbot that drafts replies without taking binding decisions is usually low or minimal risk, though it still needs training on approved data, disclosure that users are talking to an AI system, and a route to a human agent. Recruitment screening deserves at least medium to high treatment because it affects livelihoods and can encode historical bias, even when the model claims only to rank candidates. Age verification, which has attracted global attention, sits in a difficult middle: the social purpose is legitimate, but the processing of government identifiers and children's data raises data-minimisation and accuracy questions that no accuracy metric alone answers. Financial scoring, insurance pricing and credit decisions should default to high risk. The lesson across examples is that classification follows the decision, not the department that owns the model.

Common Mistakes, Alternatives and Cost Expectations

The most frequent mistake is treating a vendor questionnaire as the classification itself. Questionnaires collect information but rarely test whether the system works on Indonesian languages, local accents, informal addresses or regional data patterns. Another common error is classifying by model size, assuming a larger parameter count implies higher risk; a small rule-based scoring system that denies a loan can be more dangerous than a large content-generation model. Teams also err by classifying once at launch and never again, even though vendor upgrades, new data sources and changed use cases alter risk over time. A third error is confusing compliance evidence with compliance itself, treating a signed supplier declaration as proof of ongoing control. When an internal method is too slow, alternatives include a third-party technical audit, an independent legal classification memo, or adopting a recognised management-system standard. Costs vary widely and should be treated as ranges for budgeting, not quotes: a focused classification sprint for a handful of use cases often lands between USD 5,000 and USD 25,000, while a broader assurance programme covering testing, documentation and staff training can reach USD 25,000 to USD 100,000 or more. Certification audits under ISO/IEC 42001 typically add tens of thousands of dollars depending on scope. Cheaper options exist, but no option removes the need for someone accountable.

When to Act and a Ninety-Day Implementation Path

Action becomes urgent when any of four conditions apply: the system influences decisions about money, health, safety, education or employment; it processes specific personal data; it is offered to customers outside Indonesia; or a regulator, insurer or enterprise buyer asks for documentation. A company testing an internal chat assistant for marketing copy can usually proceed with lightweight controls, while a fintech firm piloting credit scoring should pause deployment until classification, data mapping and human review are in place. The first ninety days can follow a simple rhythm. Days 1 to 30 focus on inventory: list every AI or machine-learning use case, including spreadsheets with scoring formulas and vendor-hosted tools, and record the decision each system influences. Days 31 to 60 focus on assessment: score impact and likelihood, confirm data categories, identify the laws that apply, and assign an owner to each tier. Days 61 to 90 focus on control design: implement human-in-the-loop steps, logging, retention limits, vendor documentation requirements and incident escalation, then present the register to leadership or a board committee. After that, set a review cadence of at least twice a year and after any material model change. Firms that treat classification as a living register rather than a one-time project tend to respond faster to incidents and face fewer surprises when rules tighten.

What a Mature Programme Looks Like by Late 2026

By the end of 2026, a mature Indonesian AI risk programme should be unremarkable and operational. It has a maintained register of systems, a documented scoring method, named owners and clear approval thresholds, and it links each tier to concrete controls such as consent, data minimisation, human review, logging and deletion schedules. It also knows which laws are uncertain and says so openly, rather than presenting interpretation as settled fact, and it watches international developments such as the EU AI Act schedule and emerging regional guidance. The programme should be able to answer simple questions quickly: what does this model do, what data does it use, who can override it, how long do we keep the outputs, and what happens if it fails. If those answers require a week of investigation, the classification is not yet embedded. The realistic expectation for most Indonesian firms in 2026 is not a regulatory approval but defensible governance: a repeatable method, current evidence and an honest account of residual risk. That standard is achievable without a national scoring scheme, and it is the level of rigour that regulators, enterprise customers and insurers are already beginning to expect.