You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 9, 2026

A Closer Look at Vietnam’s New AI Law: What It Means for AI Businesses

Vietnam has taken a decisive step into the global artificial intelligence regulatory landscape with the promulgation of the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law), adopted on December 10, 2025, and effective from March 1, 2026. As one of the earliest comprehensive, standalone AI statutes in Southeast Asia, the AI Law signals Vietnam’s ambition to position itself as both an innovation-friendly and governance-conscious AI market.

In doing so, the legislature has also streamlined Vietnam’s AI regulatory architecture. The AI Law repeals most AI-related provisions previously embedded in the Law on Digital Technology Industry No. 71/2025/QH15, consolidating AI governance under a single, unified legal framework. This structural move underscores an intent to provide greater regulatory clarity and coherence for businesses operating across the AI value chain.

Against this backdrop, the key question for AI developers, providers, deployers, and governance teams is how the new risk-based framework will shape compliance expectations, operational decisions, and governance design in practice. This article examines the new AI Law through that practical lens, focusing on what it means for AI businesses operating in or into Vietnam.

Scope of Application

The AI Law applies broadly to Vietnamese organizations and individuals, as well as foreign entities that participate in AI-related activities within Vietnam. The law expressly excludes AI activities conducted solely for national defense, security, and cryptography purposes.

A defining feature of the AI Law is that it regulates by role, not by industry. It distinguishes between:

  • Developers, who design, build, train, test, or fine-tune AI models and have direct control over the technical methods, training data, or model parameters;
  • Providers, who place AI systems on the market or put them into use under their own names;
  • Deployers, who use AI systems under their control in professional, commercial, or service-provision activities;
  • Users, who interact with AI systems or rely on their outputs; and
  • Affected persons, whose lawful rights or interests, life, health, property, reputation, or opportunity to access services are directly or indirectly impacted by the deployment of, or by the outputs generated by, AI systems.

From a practical perspective, this role-based structure is critical. An organization may play multiple roles across different AI systems, or even within the same system. Where contractual roles do not align with regulatory roles under the AI Law, businesses may face unexpected compliance exposure or risk failing to fully meet their statutory obligations. As a result, role identification is the first governance decision any AI-related business must make under the AI Law.

Risk-Based Classification as the First Compliance Gate

At the core of the AI Law is a risk-based regulatory model. In particular, AI systems are classified as either high-risk, medium-risk, or low-risk, as defined below:

  • High-risk: May cause significant harm to life, health, or the lawful rights and interests of organizations or individuals, as well as to national interests, public interests, or national security. Given this broad definition, the prime minister is tasked to issue a list specifying which AI systems are classified as high-risk. Accordingly, only the systems included in this list will be subject to the strictest regulatory requirements applicable to high-risk AI (details of which will be discussed further below).
  • Medium-risk: May have the potential to confuse, influence, or manipulate users due to users being unable to recognize that the interacting entity is an AI system or that the content is generated by such a system.
  • Low-risk: All remaining systems.

This classification is essentially the gateway to compliance, since it determines whether obligations such as notification, conformity assessment, and other ongoing governance obligations apply. While Vietnam’s AI Law is broadly aligned with the EU AI Act in adopting a risk-based regulatory philosophy, its framework is structurally simpler. Unlike the EU AI Act, which embeds outright prohibitions within a four-tier risk taxonomy, Vietnam addresses prohibited AI practices separately and applies its three-tier classification only to AI systems that are otherwise lawful. From a governance perspective, this reduces classification ambiguity and supports more predictable enforcement.

Under the AI Law, providers bear the formal responsibility for self-classifying AI systems before they are put into use. Deployers inherit this classification but must reassess it if they materially modify the system or change how it is used.

For medium- and high-risk systems, providers must additionally prepare a risk classification dossier, and notify the Ministry of Science and Technology (MST) through the national AI portal before deployment.

Governance of AI Systems Based on Risk Levels

Governance of High-Risk AI Systems

Being classified as high-risk (included in the list of high-risk AI systems to be announced by the prime minister) has significant operational and governance implications. The AI Law imposes a lifecycle-wide governance framework that directly affects product design, deployment decisions, internal controls, and regulatory engagement. In particular:

Transparency obligation: Transparency under the AI Law is a user-facing operational obligation, not merely a documentation requirement. Providers must ensure that users can recognize when they are interacting with an AI system, and that AI-generated audio, images, and videos are appropriately marked in accordance with government standards. Deployers have corresponding duties when AI-generated or AI-edited content is made public, including clear disclosure and visible labeling where such content may cause confusion or involve simulation or impersonation. In practice, this requires transparency to be embedded into product design, user interfaces, content workflows, and public communications throughout the AI system’s lifecycle.

Incident management: The AI Law treats incident management as a collective obligation across the AI value chain. Developers, providers, deployers, and users are all required to ensure the safety, security, and reliability of AI systems, and to promptly detect and address incidents that may cause harm to individuals, property, data, or social order. Where a serious incident occurs, developers and providers must take immediate technical measures to remedy the issue, including suspending or recalling the system if necessary, and notify the competent authorities through the national one-stop AI portal. Deployers and users, in turn, are required to record, report, and cooperate in incident handling and remediation.

From a governance perspective, this framework requires organizations to establish clear internal incident thresholds, reporting and escalation procedures, and cross-functional coordination between technical, legal, and compliance teams, as well as operational readiness to suspend or withdraw AI systems when mandated by regulators.

Conformity assessment: High-risk AI systems are subject to mandatory conformity assessment before being put into use and upon any significant modification during operation. Depending on whether a system falls within the prime minister-issued list of systems requiring prior certification, conformity assessment may take the form of third-party certification by a registered or recognized assessment body if certification is mandatory, or self-assessment (or outsourced assessment) by the provider if certification is not mandatory. A positive conformity assessment is a legal precondition for deployment, and providers are required to maintain conformity and publicly disclose relevant information on an ongoing basis.

Local presence for foreign providers: Foreign providers supplying high-risk AI systems in Vietnam are required to establish a lawful local contact point in Vietnam. When a high-risk system falls within the category subject to mandatory conformity certification prior to deployment, the provider must additionally establish a commercial presence or appoint an authorized representative in Vietnam.

Lifecycle governance obligations: Beyond these headline requirements, high-risk systems are subject to continuous risk management, data governance controls, technical documentation, human oversight, and regulatory cooperation obligations. For deployers, this translates into stricter limits on how systems may be used, monitored, and scaled beyond their original purpose.

Governance of Medium-Risk and Low-Risk AI Systems

Under the AI Law, medium-risk AI systems are governed primarily through transparency and accountability mechanisms rather than ex ante conformity assessment and certification (if applicable). Providers and deployers must comply with the transparency requirements mentioned above and be prepared to explain, upon request by competent authorities, the system’s purpose, functional operation, key input data, and risk management measures, without being required to disclose source code, detailed algorithms, or trade secrets. Deployers also bear responsibility for explaining system operation, risk controls, incident handling, and protection of affected persons’ lawful rights.

Low-risk AI systems, by contrast, are subject to a largely post hoc oversight model. Providers and deployers are only required to account for such systems when there are indications of legal violations or adverse impacts on lawful rights or interests, while users remain free to use low-risk systems for lawful purposes at their own responsibility.

From a governance perspective, this lighter regulatory approach does not eliminate the need for internal controls. Organizations deploying medium- and low-risk AI systems should still maintain basic documentation, transparency mechanisms, and internal escalation pathways to respond efficiently if regulatory scrutiny or incidents arise, and are encouraged to apply relevant technical standards on a voluntary basis.

Other Notable Features of the AI Law

The AI Law establishes a sandbox mechanism for AI, under which testing results may be used by authorities to recognize conformity assessment results or adjust applicable obligations.

Vietnam will adopt a National AI Strategy issued by the prime minister and subject to periodic review at least every three years or upon significant technological or market developments.

The AI Law introduces a National AI Ethics Framework to guide the development of standards, technical regulations, sector-specific guidance, and incentive policies for safe, trustworthy, and responsible AI, with voluntary application encouraged.

Violators of the AI Law and other relevant legal provisions related to AI, depending on the nature, severity, and consequences of the violation, will be subject to administrative sanctions or criminal liability. If damage occurs, they must compensate according to civil law provisions.

Outlook

While the AI Law represents a significant milestone in Vietnam’s digital regulatory development, it is best understood as a framework law rather than a fully exhaustive regulatory regime. Many key compliance elements, including detailed risk classification criteria, transparency and labeling requirements, incident reporting thresholds, conformity assessment procedures, and local presence obligations for foreign providers, are to be provided in subordinate implementing regulations.

At the time of writing, the competent authorities have not announced a specific timeline for the issuance of these implementing decrees and guidance. As a result, the full scope of practical compliance obligations and enforcement in respect of the foregoing obligations, especially for providers and deployers of high-risk AI systems, will only become clear as secondary legislation and regulatory guidance are issued.

Regardless, businesses developing, providing, or deploying AI systems in or into Vietnam should begin compliance planning at an early stage, rather than waiting for implementing decrees or enforcement actions. Early preparation will be particularly important for organizations operating complex AI supply chains or deploying systems that may fall within higher risk categories.

RELATED INSIGHTS​ 

July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 21, 2026
Thailand’s Ministry of Digital Economy and Society (MDES) published a notification establishing an expedited court-ordered takedown mechanism for online content in cases of “urgent necessity.” The notification, which was issued on July 17, 2026, under the Computer Crime Act B.E. 2550 (2007), as amended, took effect the following day. It significantly expands the categories of content subject to rapid government-initiated removal. Content Categories Subject to Takedown The notification defines “urgent necessity” (section 20, paragraph 5, of the Computer Crime Act) as circumstances where any delay in suppressing computer data may impact national security, religion, the monarchy, good morals, social culture, or public order. In this regard, it establishes four broad categories of content: Computer Crime Act offenses. National security offenses. IP and other criminal offenses, where it is contrary to public order or good morals and a competent officer has requested its suppression. Content contrary to public order or good morals, a broad residual category encompassing 14 subcategories approved by the Computer Data Screening Committee. The fourth category is the most expansive. Its 14 subcategories include: Content defaming, mocking, satirizing, or devaluing the monarchy. Online gambling advertising or facilitation. Offering illegal firearms for sale. Offering baraku (hookah) products or e-cigarettes for sale. Offering cannabis inflorescences or processed cannabis products for sale. Advertising or soliciting prostitution. Content inciting violence, hatred, or social division. Unauthorized overseas employment advertising. Offering boiled kratom juice for sale. Online sale or advertising of alcoholic beverages. Content satirizing or degrading Buddhism. Money lending at interest rates exceeding legally prescribed limits. Advertising or disseminating information about surrogacy services. Forgery of documents, cards, or official documents. Enforcement Procedure In cases of urgent necessity, a competent official assigned by the MDES permanent secretary must file a petition with supporting evidence to the court with jurisdiction, requesting an order to
July 20, 2026
On July 16, 2026, Thailand’s Personal Data Protection Committee (PDPC) published a notification in the Government Gazette establishing detailed rules governing data subjects’ right of access under section 30 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The notification will take effect 60 days after publication—mid-September 2026—giving data controllers a limited window to bring their processes into compliance. Scope The notification covers requests to access or obtain copies of personal data and requests for disclosure of the source of data collected without consent. Data subjects may exercise their rights directly or through authorized representatives. Key Requirements Important requirements set by the notification include the following: Required request channels. Controllers must provide at least two request channels: direct submission at the business location and registered mail. Electronic channels are optional but, if offered, may also be used for fulfilling requests. Request contents. Requests must be in writing or in electronic form and include the data subject’s name, the preferred access method, details of the data requested, and the requester’s signature. Controllers may request additional identifying information as needed. Identity and authority verification. Controllers may require official identity documents for verification. Authorized representatives must provide authorization documents and identity documents for both the data subject and the representative. Alternative verification methods (e.g., digital authentication) are permitted if they do not unreasonably obstruct data subjects’ rights. Review and response timelines. Controllers must review requests within 15 days. If the request is incomplete, the controller must notify the requester and allow at least 15 days to correct deficiencies. If not corrected, the request may be treated as abandoned. Once verified, controllers must fulfill requests within 30 days, extendable by another 30 days for large-volume or complex requests with notice to the requester. Methods for providing access or copies. Controllers may fulfill
July 16, 2026
Thailand’s Office of the Personal Data Protection Committee (PDPC) published a series of draft guidance documents for public consultation on July 7, 2026. Issued under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), the drafts address a range of compliance issues and offer insight into the regulator’s current enforcement priorities. This article examines two of those drafts: one on lawful bases for processing personal data, and another on marketing and direct marketing. Together, they reflect the Office of the PDPC’s evolving expectations on lawful-basis selection, accountability, and the use of personal data in marketing. Organizations operating in Thailand should assess the practical implications now, before the guidance is finalized. Lawful Bases: A Structured Selection Process The draft guidance on lawful bases introduces a systematic five-step process for selecting an appropriate lawful basis for each processing activity. Organizations are expected to: Identify the processing activity involved. Assess the appropriate lawful basis. Evaluate whether the data is necessary for the processing. Conduct a legitimate interest assessment (LIA) where applicable. Ensure transparency through privacy notices. The guidance provides practical explanations and examples for each lawful basis under section 24 of the PDPA—including archiving, research, statistics, vital interests, contractual necessity, legal obligation, public task, legitimate interests, and consent—as well as the bases applicable to sensitive personal data under section 26. The aim is to promote more consistent and accurate lawful-basis selection across public- and private-sector organizations. A recurring theme throughout the guidance is that organizations should select the lawful basis that most accurately reflects the actual purpose and circumstances of the processing activity. The guidance cautions against treating consent as a default or catch-all basis where another lawful basis is more appropriate. For processing based on legitimate interests, organizations should conduct and document an LIA. Processing involving sensitive personal data may require