You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 26, 2025

The IP Puzzle of AI-Generated Songs: Protection, Responsibility, and the Future of Music Law

AI-generated songs are now making waves in Vietnam on platforms like TikTok, with tracks such as “Say mot doi vi em” quickly gaining popularity and sparking widespread attention. This phenomenon raises a host of legal and ethical questions: Who is the author of these songs? Can they be protected by copyright? Who is responsible if there is an infringement? These questions are becoming increasingly urgent as AI music becomes more mainstream in Vietnam.

Copyright Protection for AI-Generated Music in Vietnam

Under current Vietnamese law, copyright protection is reserved for works that bear the mark of human creativity. The 2022 amendments to Vietnam’s Intellectual Property Law reaffirm that only works created by humans are eligible for copyright. In practice, if a human meaningfully contributes to the creative process—by providing prompts, making selections, editing, or arranging—their contribution may be protected. However, if a song is generated entirely by AI without significant human input, it is unlikely to qualify for copyright protection.

When an AI-generated song does not qualify for copyright protection, the question arises as to whether the person who writes the prompts, edits, or compiles the work can still be considered the owner of an asset under the Vietnamese Civil Code. According to Article 105 of the Civil Code 2015, assets include objects, money, valuable papers, and property rights. While AI-generated music that is not protected by copyright is not considered money or valuable papers, it may be regarded as an object (in the form of a digital file or recording) or as a property right if it can be possessed, used, transferred, or exploited for value.

Use of AI-Generated Works Without Copyright Protection

If a song is not protected by copyright, does that mean anyone can use it freely? Not necessarily. The absence of copyright does not mean the work is entirely free of restrictions. Terms of service from AI platforms may limit commercial use, require attribution, or impose licensing fees. Other rights may also apply. The person who creates, edits, or compiles the AI-generated work may establish civil ownership over the digital file or recording as a type of digital asset, provided that the creation and use of the asset are lawful and do not infringe on others’ rights. This ownership is not the same as copyright, but it allows the owner to possess, use, and dispose of the asset within the limits of the law and any relevant agreements.

Additionally, laws against unfair competition, impersonation, or violations of personal rights (such as voice, name, or image) may still be relevant.

Voice Cloning and Related Risks

One particularly thorny issue is voice cloning. In Vietnam, performers’ rights protect both live performances and recorded voices. More importantly, copying or imitating a singer’s voice can primarily infringe upon the moral rights and personal rights of individuals as recognized under the Civil Code, which increasingly treats voice as a personal identifier. The main legal risk is the violation of moral rights, such as the right to protect the integrity and authenticity of one’s voice and the right to be recognized as the owner of that voice.

Best practices include obtaining written consent from the person whose voice is used, labeling content as “AI voice,” and avoiding any suggestion that the artist participated in or endorsed the work.

Similarity to Existing Works

Another significant risk arises when AI-generated music or lyrics resemble existing works. The standard for infringement is “substantial similarity” and access to the original. If an AI creates a segment that is sufficiently similar to a prior work, using that segment in a new recording or arrangement may constitute infringement. The fact that the AI was trained on large datasets does not exempt the output from scrutiny. Even if the input data was lawfully obtained, the output must still avoid copying protected material. Defenses such as coincidence, common style, or minor excerpts are assessed on a case-by-case basis, often requiring expert analysis.

Responsibility and benefit-sharing in the AI music ecosystem are complex. Users who prompt, select, edit, or publish AI-generated music are directly responsible for the outputs they release or exploit. AI platforms may also bear responsibility if they provide infringing tools or models, or fail to remove infringing content. Those who invest in, release, or commercially exploit AI-generated music may profit under contract, but they also assume corresponding legal risks, including compensation, takedown, or recall obligations.

Practical Recommendations for Creators and Publishers

For creators and publishers, several practical recommendations emerge. It is important to document the human role in the creative process, demonstrating selection and editing to support claims of authorship.

  • Similarity checks should be conducted using melody and lyric analysis tools, and expert opinions should be sought when necessary to avoid recognizable copying.
  • Voice governance is critical: Do not clone an artist’s voice without written consent, label AI-generated voices clearly, and avoid implying artist involvement.
  • Use models and training data with clear provenance, and ensure all samples, loops, and plugins are properly licensed, keeping records to prove origin.
  • Internal contracts should allocate rights and responsibilities among authors, producers, singers, engineers, and publishers, including indemnity clauses for intellectual property claims.
  • Platform terms should be reviewed carefully for output usage rights, commercial restrictions, and labeling obligations.
  • Finally, establish procedures for receiving and responding to takedown notices promptly to minimize damage.

Legal Outlook in Vietnam

Vietnam is actively shaping its legal framework to address the rapid growth of artificial intelligence. A draft Law on Artificial Intelligence released by the Ministry of Science and Technology is scheduled to take effect on January 1, 2026. In parallel, Vietnam’s Intellectual Property Law is under review, with discussions focused on how to accommodate AI-generated content.

The current framework does not recognize AI as an author, meaning that works created solely by AI may not qualify for copyright protection unless there is identifiable human contribution. This legal gap has prompted calls for clearer definitions of authorship, ownership, and liability in the context of AI-assisted creativity. While it is still too early to predict whether Vietnam’s upcoming laws will restrict or encourage AI-generated music, the direction appears cautiously optimistic. The government is balancing innovation incentives with ethical and legal safeguards, aiming to foster responsible AI development while protecting creators and consumers.

Key IP Takeaways on AI-Generated Content

AI-generated music challenges traditional IP frameworks on three fronts: authorship and protection, risks of voice cloning and similarity to prior works, and the allocation of liability among users, platforms, and publishers.

The safest path forward is proactive: Document the creative process, clear rights diligently, and use contractual safeguards. With these measures, businesses can treat AI not as a legal hazard, but as a sustainable creative tool in Vietnam’s fast-evolving music landscape.

As Vietnam’s evolving legal landscape offers both opportunities and uncertainties, stakeholders in the music and creative industries should stay informed and engaged with these regulatory developments to navigate the future of AI-generated content.

This article first appeared in Managing Intellectual Property.

RELATED INSIGHTS​ 

January 6, 2026
On December 30, 2025, Thailand’s Electronic Transactions Development Agency (ETDA) notified digital marketplace operators of a consolidated list of “high‑risk products” that are subject to strict monitoring on digital platforms. The list was jointly prepared by the Thai Industrial Standards Institute (TISI) and the Food and Drug Administration (FDA) to guide platform compliance in the initial phase of implementation of the Electronic Transaction Committee’s Notification on Other Measures for Marketplace for Goods with Specific Characteristics under Section 18(2) of the 2022 Royal Decree on Digital Platform Businesses Requiring Notification B.E.2568 (2025). The notice is addressed to operators of digital platform services that function as product marketplaces with specific characteristics laid out in the notification. The ETDA states that the TISI and the FDA are closely monitoring the high‑risk product categories on digital platforms, and the published list serves as the baseline reference for platform screening during the initial phase of the notification’s implementation. High‑Risk Product List The list aggregates categories of products that are illegal to sell online or are otherwise tightly regulated under Thai law, with an emphasis on health-related products, controlled substances, medical devices, and a wide range of industrial products that require certification or compliance with specified Thai Industrial Standards, as detailed below. Prohibited and tightly controlled health products. This includes all categories of modern medicines subject to control other than general household remedies; all categories of controlled herbal products except for over-the-counter herbal products; narcotics; psychotropic substances; and medical devices requiring use in medical facilities or a physician’s prescription. Selected industrial products requiring heightened controls. The list highlights dozens of TISI-regulated items commonly sold online. Examples include pacifiers, rice cookers, electrical wire, food wrap film, crayons, washing machines and dryers, air conditioners, electric cookers and air fryers, water heaters, microwave ovens, LED luminaires, hair dryers
January 5, 2026
On December 31, 2025, the government of Vietnam promulgated Decree No. 356/2025/ND-CP detailing and guiding the implementation of the new Personal Data Protection Law (PDPL) that was issued in June 2025. The new decree, like the PDPL, entered into force on January 1, 2026, with the previous Decree No. 13/2023/ND-CP on personal data protection ceasing effect on the same day. Some key points of the new decree include the following: Comprehensive lists of basic and sensitive personal data are provided, which will require companies to review again their existing documents and data type classification to ensure compliance. New timelines are established for responding to specific data subject requests. These timelines are more reasonable and longer than the previous 72-hour requirements. Additional consent guidelines are provided, prohibiting default consent or ambiguous instructions that confuse data subjects about giving or withholding consent. Mandatory content for data transfer agreements/clauses in particular cases is provided. This covers, among other things, (i) the legal basis for the transfer of personal data; (ii) responsibilities for personal data protection during the transfer and processing of personal data; (iii) responsibilities for ensuring the exercise of the rights of personal data subjects; and (iv) responsibilities for coordination and compliance of the parties in cases where violations of personal data protection regulations are detected. The qualifications and responsibilities of data protection officers (DPOs) and data protection departments include, among others, having been trained and fostered in legal knowledge and professional skills regarding personal data protection. There are no specific provisions governing the qualifications or requirements for organizations that provide data protection training or education. New mandatory templates and requirements are provided in relation to data processing impact assessment and data transfer impact assessment, and for cases in which companies need to re-submit assessments to the regulator. Stricter requirements are
December 30, 2025
On December 17, 2025, Laos’ Ministry of Industry and Commerce (MOIC) issued a notice introducing a new digital system that allows e-commerce businesses to obtain required certificates and licenses through an online, application-based platform. Notice No. 3988, which will take effect on February 1, 2026, introduces the E-Trust platform, a downloadable application that allows e-commerce businesses to remotely obtain acknowledgement certificates and business operating licenses. New Digital Registration Options Under the previous framework established by the Decree on E-commerce (2021), businesses were required to complete registration exclusively through paper-based submissions. The new system now offers businesses two registration options: Traditional paper-based process at the Division of E-commerce Management within the MOIC; or Electronic registration and renewal through the E-Trust platform. This change is expected to streamline procedures, reduce administrative burdens, and enhance accessibility for businesses operating outside Vientiane. The E-Trust platform facilitates compliance for both individuals and legal entities required to submit applications and renewals for required certificates and licenses. The development is particularly beneficial for businesses located in remote provinces, as it eliminates the need for physical travel and significantly accelerates processing times. Compliance Requirements and Penalties Businesses must obtain or renew the required certificates and licenses to avoid sanctions under the Decision on Fines and Other Measures for Violation of the Decree and Regulations on E-commerce (No. 2828/MOIC, dated November 11, 2025). Penalties for noncompliance may include monetary fines and other enforcement measures.
December 26, 2025
Thailand has granted ride-sharing platforms additional time to comply with new regulatory requirements, extending the compliance deadline to March 31, 2026 (replacing the previous deadline of October 2, 2025). The postponement was made official on December 18, 2025, when Thailand’s Electronic Transactions Development Agency (ETDA) published the second Notification Regarding Supervision of Ride-Hailing Platforms Classified as High-Impact Digital Platform Services under the Royal Decree on Digital Platform Service Businesses. The notification provides additional time for ride-sharing platforms and drivers to transition to full regulatory compliance. The extension replaces the effective date provision of the earlier notification and applies specifically to ride-hailing activities. Background The postponement responds to feedback from operators and driver groups regarding challenges converting private vehicles into legally registered public vehicles, including complex registration procedures, high compliance costs, and operational delays. The Department of Land Transport (DLT) is concurrently reforming its vehicle registration and driver verification processes to streamline operations. Given these issues, the Electronic Transactions Committee has deferred enforcement to provide an adjustment period for operators and drivers to meet compliance requirements. Ongoing Obligations While the effective date has been deferred, the substantive obligations imposed on ride-sharing platforms remain fully intact. Operators must continue preparing to comply with the additional duties applicable to high-impact digital platform services, beyond the general requirements under the digital platform services framework. Operators are expected to use the extended transition period to finalize operational and compliance readiness ahead of enforcement on March 31, 2026. Key focus areas include: Integration with DLT vehicle-registration systems Deployment of robust driver and passenger identity verification mechanisms Updates to platform terms of service, driver-onboarding standards, and internal operational policies Preparation for ETDA reporting obligations and future audit and review processes Next Steps While the postponement replaces the previous effective date with the new March 31, 2026,