A Comparative Analysis of Corporate Criminal Liability for AI-Based Malware: A Study of Indonesian and European Union Law

Talia Kallista Haditama, Fajar Sugianto · Indonesia Law Reform Journal · 2025

AI technology has developed rapidly and has begun to interact with various aspects of human life. In Indonesia, AI is not only widely known and used by the general public but also by corporations, including limited liability companies (PTs). As an object, AI technology can be used by humans for negative purposes, just as it can be used for positive purposes. One negative use is to create advanced malware, increasing the likelihood of cybercriminals succeeding in their attacks. Indonesia currently lacks specific regulations for AI systems, unlike the European Union. This research aims to discover the laws governing sanctions for limited liability companies that commit crimes using AI-based malware in Indonesia and the European Union, and then compare the regulations of the two countries. The results show that both countries have similar regulations regarding criminal offenses related to the use of AI-based malware, the definition of corporations, and the types of sanctions that can be imposed on limited liability companies as corporations and individuals involved. The difference lies in the European Union's regulations, which do not provide detailed provisions on sanctions like Indonesia does, but instead leave the setting of sanctions to each member state. Unlike the European Union, Indonesia also does not have specific regulations on AI, even though criminal offenses related to the use of AI-based malware are already regulated in the ITE Law, PDP Law, 2023 Criminal Code, and Copyright Law. The writing recommends, first, Indonesia sould adapt a risk-based regulatory approach which categorizes AI systems as unacceptable risk, high risk, limited risk and minimal risk. Second, enhancing corporate governance obligations for Limited Liability companies to adopt AI ethics and compliance frameworks, including AI risk audits, reporting mechanisms for misuse, and monitoring system for AI deployment

Read the paper · More papers on PaperTik