Indonesia Advances Sweeping Cybersecurity Reform, Expands AI Oversight

Indonesia Advances Sweeping Cybersecurity Reform, Expands AI Oversight
Photo: unsplash.com 02.07.2026 500

The proposed legislation would establish a powerful new national cybersecurity authority.

Indonesian lawmakers have begun deliberating a sweeping Cybersecurity and Cyber Resilience Bill that would establish a powerful national cybersecurity authority, strengthen government oversight of critical information infrastructure, and introduce new regulatory requirements for artificial intelligence (AI) and digital products.

The bill, submitted by the government to the relevant parliamentary commission, would create a comprehensive statutory cybersecurity framework governing both public- and private-sector operators. Operators of critical information infrastructure would be required to comply with nationally prescribed cybersecurity standards, conduct regular risk assessments and independent security audits, implement business continuity and recovery plans, and submit periodic reports to the regulator.

The proposal would establish a National Cybersecurity Agency reporting directly to the president. The agency would be responsible for setting cybersecurity standards, supervising infrastructure operators, coordinating cyber incident response, and overseeing nationwide compliance with cybersecurity requirements.

The authority would also be empowered to request information from infrastructure operators, investigate cyber incidents, conduct cybersecurity operations, and filter online content deemed to constitute cyber threats or cyberattacks.

Under the bill, operators of critical information infrastructure would be required to notify the authority within 72 hours of detecting a cyber incident. The agency would have the power to assess whether reported incidents pose risks of escalating into a national cyber crisis. The proposal would also introduce mandatory annual cybersecurity audits for critical infrastructure operators, with regulators authorized to publish monitoring results to improve transparency.

A separate section of the bill introduces new cybersecurity requirements for digital products and AI. Digital products would be classified into low-, medium-, and high-risk categories, with medium- and high-risk products required to undergo government assessment before entering the market. Manufacturers would also be required to identify product vulnerabilities, provide security updates, and disclose patched vulnerabilities.

AI systems would be required to comply with ethical principles covering transparency, accountability, personal data protection, intellectual property rights, inclusivity, and sustainable development. Developers would also be required to notify the National Cybersecurity Agency when developing or deploying AI systems. Operators of critical infrastructure would only be permitted to use digital products that comply with the bill's cybersecurity requirements, while the agency would be authorized to supervise the use of AI within critical infrastructure environments.

Industry representatives broadly welcomed the proposal to strengthen Indonesia's national cybersecurity governance but urged lawmakers to clarify how the new authority would interact with existing government institutions, including the National Cyber and Crypto Agency (BSSN), intelligence agencies, and the national police.

Industry experts also warned that concentrating regulatory, supervisory, certification, audit, and enforcement powers within a single institution could create conflicts of interest and legal uncertainty for businesses. They further called for stronger safeguards governing government access to internet traffic, safe-harbor protections for incident reporting, and closer alignment of the bill with Indonesia's Personal Data Protection Law.

Source: MLex

digital markets  Indonesia 

Share with friends

Related content