You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 13, 2026

Is Vietnam Pioneering the Legal Framework for AI and IP?

Managing Intellectual Property

Vietnam’s Law on Intellectual Property (IP Law) has undergone continuous amendment in recent years, with the latest amendment issued at the end of 2025. Among the amended and supplemented provisions, the regulation that has perhaps attracted the most attention is a provision relating to the use of protected IP objects by artificial intelligence (AI) systems.

Specifically, Article 7 of the 2025 IP Law introduces a completely new Clause 5, which reads in full as follows:

“Organizations and individuals are permitted to use texts and data relating to intellectual property objects that have been lawfully published, and which the public is allowed to access, for the purposes of scientific research, experimentation, and training of artificial intelligence systems, provided that such use will not unreasonably affect the legitimate rights and interests of the authors and intellectual property rights holders in accordance with this Law.

With respect to texts and data that are objects protected by copyright and related rights, the use of the texts and data as set forth herein must also be in accordance with the regulations of the Government.”

Analyzing this newly added provision in the context of how it was conceived, as well as the challenges that still lie ahead, can provide some interesting insights.

From Aspirations to Flight in Science and Technology

From the end of 2024 and throughout 2025—the 50th anniversary of the country’s reunification—Vietnam witnessed numerous sweeping changes in many areas, including legislative development. It could be said that no sessions of the National Assembly have ever adopted as many laws, resolutions, and major policies as this one. The aspirations of the highest-level leadership have been concretized into major law and policy projects, which were drafted, developed, and passed at record speed.

All of this was aimed at building a foundation for Vietnam to achieve breakthrough development, with an expected GDP growth rate of up to 10% per year over the next decade. As a key driver of this growth, science and technology were given special attention, and the legal framework in this sector, including IP law, was urgently developed and amended.

Vietnam has not been hesitant to introduce new regulations, unprecedented even in developed countries, and established the relationship between IP and AI with these goals in mind.

Caution in Building the Legal Framework

In this context, the question of whether the relationship between IP and AI should be incorporated into the amended 2025 IP Law became a topic of attention and debate from the outset, with two distinct approaches.

Legal scholars and practicing lawyers tended to be cautious about the idea of incorporating regulations governing the relationship between IP and AI into law, especially provisions relating to the use of protected IP objects by AI systems. Legal practitioners favored a more prudent approach, hoping that Vietnam would not move too hastily and would instead take time to observe and evaluate advanced legislative models worldwide. However, significant momentum came from upper leadership and the technology sector, who sought a legal corridor providing the most favorable conditions for tech companies to develop.

Even the tech companies themselves could not converge upon one consistent approach. Content-producing companies, whose rights and interests are closely tied to the control of the use of their works, tended to have the view that the use of protected IP objects must be subject to prior authorization by the rights holders. Meanwhile, the companies whose business models rely heavily on access to data welcomed and actively promoted a trend allowing them to freely use such objects even if they were protected by IP law.

Ultimately, the form of the provision that was adopted partially reflects the prevailing influence of the tech companies, as the 2025 IP Law officially introduced a principle allowing AI systems to “use texts and data relating to intellectual property objects … provided that such use will not unreasonably affect the legitimate rights and interests of authors and intellectual property right holders.”

However, caution continues to be reflected in the final sentence of Article 7.5, which adds the key clause that “With respect to texts and data that are objects protected by copyright and related rights, the use […] must also be in accordance with the regulations of the Government.”

Thus, the current regulation chosen by Vietnam could be deemed to be both open and closed. It is open in that it clearly sets out the principle that AI systems can use protected IP objects without prior consent from the right holders. However, the use of objects protected by the specific form of copyright and related rights—the form of IP protection most likely to apply to online content accessed by AI systems—will be implemented in accordance with regulations yet to be issued, which could close off certain avenues in the future. For now, pending the issuance of such regulations, AI systems can enjoy the rights already recognized.

Vietnam’s legal provisions in this area appear to be of a pioneering nature. However, only time will tell if this is truly the case.

This article first appeared in Managing Intellectual Property.

RELATED INSIGHTS​ 

August 15, 2025
More than a decade after the issuance of Decree No. 52/2013/ND-CP (as amended by Decree No. 85/2021/ND-CP; collectively, “Decree 52”), Vietnam’s legal framework for e-commerce is under growing pressure to keep pace with the evolving digital economy. While Decree 52 has provided a foundational framework, it has shown certain limitations in keeping up with issues such as counterfeit goods, intellectual property enforcement, unqualified products, and emerging models like livestream selling and affiliate marketing. To address these regulatory gaps, the Ministry of Industry and Trade (MOIT) has released the 2025 Draft E-Commerce Law (“Draft Law”) for public consultation. The Draft Law is intended to supersede the current framework under Decree 52 and establish a more detailed and comprehensive legal foundation for the regulations of e-commerce activities in Vietnam. It is currently expected to be submitted to the National Assembly for review and potential adoption during its 10th session in October 2025. In this article, we discuss the Draft Law’s most significant updates and legal developments in comparison to existing regulations, and assess the practical challenges that businesses may face in preparing for implementation in the near future. Platform Classification: Toward a More Nuanced Framework Unlike Decree 52’s simpler structure, which broadly categorized platforms into either (i) websites selling goods and services or (ii) websites providing e-commerce services, the Draft Law introduces a more detailed framework that aims to classify platforms based on their technical functions and business models. Specifically, the Draft Law introduces a four-tier classification system for e-commerce platforms, consisting of: (i) Direct Business Platforms, (ii) Intermediary Platforms, (iii) Social Networks with E-Commerce Functions, and (iv) Multi-Service Integrated Platforms. This approach reflects an effort to more accurately capture the complexity of today’s e-commerce landscape, including hybrid platforms such as TikTok Shop. While this approach reflects the growing complexity of
August 6, 2025
Thailand’s Digital Government Development Agency (DGA) has released drafts of two pivotal documents to guide Thai government agencies in adopting cloud technology and classifying data for cloud usage. These draft guidelines, open for public hearing through August 12, 2025, are part of the national “Go Cloud First” policy, which aims to accelerate digital transformation, improve efficiency, and ensure robust data security across the public sector. The new standards will have significant implications for both government agencies and cloud service providers operating in Thailand. Highlights of the draft guidelines are presented below. Government Cloud Usage Guidelines Cloud-first transformation: All government agencies are directed to prioritize cloud solutions for new IT projects, in line with the cabinet’s “Go Cloud First” policy. Cloud model selection: Agencies must assess their needs and select the most appropriate cloud deployment model—public, private, hybrid, or community cloud—based on the sensitivity of the data and operational requirements. Service types: The guidelines provide criteria for choosing between Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS), emphasizing the importance of using standard, non-customized services where possible. Cost management: Agencies are required to plan and separate cloud-related expenses, ensuring transparency and efficient budget allocation. Cloud migration: The guidelines outline the steps for migrating to the cloud and highlight the role of cloud service providers in facilitating the process, including supporting innovation and enabling smooth exit strategies. Procurement compliance: All cloud procurement must comply with public sector procurement laws and regulations. Only providers meeting government-mandated standards can be selected. Security and shared responsibility: The guidelines clarify the division of security responsibilities between cloud providers and government agencies. While providers manage infrastructure security, agencies remain responsible for data, application, and access controls. Legal framework: Agencies must comply with the Digital Government Administration Act, Cybersecurity
August 1, 2025
Thailand’s Personal Data Protection Committee (PDPC) announced to the press on August 1, 2025, that it had issued eight new administrative fines under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) in five cases of noncompliance by public and private entities. The enforcement actions reflect a growing commitment by the PDPC to penalize noncompliance across all sectors, regardless of organizational type or size. The total amount imposed to date was approximately THB 21.5 million (approx. USD 654,690), underscoring the financial risks tied to PDPA violations. The five cases—one involving a state agency and the remainder in the private sector—are summarized below. Case 1: State Agency Providing Online Services to the Public The order in this case stemmed from a cyberattack on a state agency’s web app, resulting in personal data of 200,000 data subjects being leaked to and sold on the dark web. The software developer was also found to have implemented no privacy by design, lacked an access control system, had no data breach prevention measures, and failed to conduct risk assessments or review existing security measures. Key noncompliance identified: Lack of appropriate security measures Weak password protection No risk assessment or ongoing review of security measures No data processing agreement with software developer that acted as data processor The state agency and the developer were each fined THB 153,120 (approx. USD 4,670). Case 2: Private Hospital This case involved a hospital that engaged an individual contractor to destroy patient medical record documents. However, the contractor stored the documents at their own premises, failed to follow the required destruction protocols, and ultimately used the medical records to wrap sweets, resulting in the leak of over 1,000 records during the destruction process. The contractor also failed to notify the hospital of the data breach. Although there was a
August 1, 2025
On July 30, 2025, Myanmar’s Cybersecurity Law No. 1/2025 came into effect with the State Administration Council’s issuance of Notification 113/2025. The law, which was enacted on January 1, 2025, aims to regulate various aspects of digital security and online activities. Below are some key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The Cybersecurity Law introduces two types of licenses, valid for a period of 3–10 years, for (1) cybersecurity services and (2) digital platform providers. Digital platforms with