You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 26, 2025

The IP Puzzle of AI-Generated Songs: Protection, Responsibility, and the Future of Music Law

AI-generated songs are now making waves in Vietnam on platforms like TikTok, with tracks such as “Say mot doi vi em” quickly gaining popularity and sparking widespread attention. This phenomenon raises a host of legal and ethical questions: Who is the author of these songs? Can they be protected by copyright? Who is responsible if there is an infringement? These questions are becoming increasingly urgent as AI music becomes more mainstream in Vietnam.

Copyright Protection for AI-Generated Music in Vietnam

Under current Vietnamese law, copyright protection is reserved for works that bear the mark of human creativity. The 2022 amendments to Vietnam’s Intellectual Property Law reaffirm that only works created by humans are eligible for copyright. In practice, if a human meaningfully contributes to the creative process—by providing prompts, making selections, editing, or arranging—their contribution may be protected. However, if a song is generated entirely by AI without significant human input, it is unlikely to qualify for copyright protection.

When an AI-generated song does not qualify for copyright protection, the question arises as to whether the person who writes the prompts, edits, or compiles the work can still be considered the owner of an asset under the Vietnamese Civil Code. According to Article 105 of the Civil Code 2015, assets include objects, money, valuable papers, and property rights. While AI-generated music that is not protected by copyright is not considered money or valuable papers, it may be regarded as an object (in the form of a digital file or recording) or as a property right if it can be possessed, used, transferred, or exploited for value.

Use of AI-Generated Works Without Copyright Protection

If a song is not protected by copyright, does that mean anyone can use it freely? Not necessarily. The absence of copyright does not mean the work is entirely free of restrictions. Terms of service from AI platforms may limit commercial use, require attribution, or impose licensing fees. Other rights may also apply. The person who creates, edits, or compiles the AI-generated work may establish civil ownership over the digital file or recording as a type of digital asset, provided that the creation and use of the asset are lawful and do not infringe on others’ rights. This ownership is not the same as copyright, but it allows the owner to possess, use, and dispose of the asset within the limits of the law and any relevant agreements.

Additionally, laws against unfair competition, impersonation, or violations of personal rights (such as voice, name, or image) may still be relevant.

Voice Cloning and Related Risks

One particularly thorny issue is voice cloning. In Vietnam, performers’ rights protect both live performances and recorded voices. More importantly, copying or imitating a singer’s voice can primarily infringe upon the moral rights and personal rights of individuals as recognized under the Civil Code, which increasingly treats voice as a personal identifier. The main legal risk is the violation of moral rights, such as the right to protect the integrity and authenticity of one’s voice and the right to be recognized as the owner of that voice.

Best practices include obtaining written consent from the person whose voice is used, labeling content as “AI voice,” and avoiding any suggestion that the artist participated in or endorsed the work.

Similarity to Existing Works

Another significant risk arises when AI-generated music or lyrics resemble existing works. The standard for infringement is “substantial similarity” and access to the original. If an AI creates a segment that is sufficiently similar to a prior work, using that segment in a new recording or arrangement may constitute infringement. The fact that the AI was trained on large datasets does not exempt the output from scrutiny. Even if the input data was lawfully obtained, the output must still avoid copying protected material. Defenses such as coincidence, common style, or minor excerpts are assessed on a case-by-case basis, often requiring expert analysis.

Responsibility and benefit-sharing in the AI music ecosystem are complex. Users who prompt, select, edit, or publish AI-generated music are directly responsible for the outputs they release or exploit. AI platforms may also bear responsibility if they provide infringing tools or models, or fail to remove infringing content. Those who invest in, release, or commercially exploit AI-generated music may profit under contract, but they also assume corresponding legal risks, including compensation, takedown, or recall obligations.

Practical Recommendations for Creators and Publishers

For creators and publishers, several practical recommendations emerge. It is important to document the human role in the creative process, demonstrating selection and editing to support claims of authorship.

  • Similarity checks should be conducted using melody and lyric analysis tools, and expert opinions should be sought when necessary to avoid recognizable copying.
  • Voice governance is critical: Do not clone an artist’s voice without written consent, label AI-generated voices clearly, and avoid implying artist involvement.
  • Use models and training data with clear provenance, and ensure all samples, loops, and plugins are properly licensed, keeping records to prove origin.
  • Internal contracts should allocate rights and responsibilities among authors, producers, singers, engineers, and publishers, including indemnity clauses for intellectual property claims.
  • Platform terms should be reviewed carefully for output usage rights, commercial restrictions, and labeling obligations.
  • Finally, establish procedures for receiving and responding to takedown notices promptly to minimize damage.

Legal Outlook in Vietnam

Vietnam is actively shaping its legal framework to address the rapid growth of artificial intelligence. A draft Law on Artificial Intelligence released by the Ministry of Science and Technology is scheduled to take effect on January 1, 2026. In parallel, Vietnam’s Intellectual Property Law is under review, with discussions focused on how to accommodate AI-generated content.

The current framework does not recognize AI as an author, meaning that works created solely by AI may not qualify for copyright protection unless there is identifiable human contribution. This legal gap has prompted calls for clearer definitions of authorship, ownership, and liability in the context of AI-assisted creativity. While it is still too early to predict whether Vietnam’s upcoming laws will restrict or encourage AI-generated music, the direction appears cautiously optimistic. The government is balancing innovation incentives with ethical and legal safeguards, aiming to foster responsible AI development while protecting creators and consumers.

Key IP Takeaways on AI-Generated Content

AI-generated music challenges traditional IP frameworks on three fronts: authorship and protection, risks of voice cloning and similarity to prior works, and the allocation of liability among users, platforms, and publishers.

The safest path forward is proactive: Document the creative process, clear rights diligently, and use contractual safeguards. With these measures, businesses can treat AI not as a legal hazard, but as a sustainable creative tool in Vietnam’s fast-evolving music landscape.

As Vietnam’s evolving legal landscape offers both opportunities and uncertainties, stakeholders in the music and creative industries should stay informed and engaged with these regulatory developments to navigate the future of AI-generated content.

This article first appeared in Managing Intellectual Property.

RELATED INSIGHTS​ 

March 5, 2026
Thailand’s Securities and Exchange Commission (SEC) has filed a criminal complaint against a licensed digital asset broker, its overseas trading platform, and its executives for allegedly operating an unlicensed digital asset exchange targeting Thai customers. The case marks an escalation in the SEC’s enforcement efforts against unlicensed offshore platforms that attempt to serve Thai users through local licensed entities. Criminal Complaint On February 20, 2026, the SEC filed a criminal complaint with the Economic Crime Suppression Division against a local licensed digital asset broker, its overseas global trading platform, and its executives. The SEC alleges that the parties violated the Digital Asset Business Emergency Decree B.E. 2561 (2018) by cooperatively operating a digital asset exchange business on a cross-border basis since 2023 without the required SEC license. According to the SEC, the local broker promoted the overseas platform’s services to the public through Thai-language posts on social media channels, with services available exclusively to customers residing in Thailand. Access to the global platform was provided through the local broker’s website and mobile application. Customers who registered for the local broker’s services were automatically granted access to the global platform without having to undergo a separate identity verification process. The SEC also found that the local broker provided back-office system support services to the global platform. The SEC considers these activities to constitute joint operation of an unlicensed digital asset exchange. The former executives of the local broker are being held liable as the responsible persons during the relevant period. The SEC emphasized that the complaint initiates the criminal process, and the decision to prosecute or convict the accused parties will ultimately be made by law enforcement authorities and the criminal courts. Platform Blocking The SEC has also coordinated with the Ministry of Digital Economy and Society to block public
February 27, 2026
The Bank of Thailand (BOT) has officially implemented a new regulatory framework supervising systemically important retail payment systems (SIRPS), effective February 21, 2026, with PromptPay being the first payment system designated as a SIRPS. Under this new set of regulations, the BOT may designate payment systems under the Payment Systems Act B.E. 2560 (2017) as SIRPSs based on quantitative and qualitative assessments. Once a system is designated as a SIRPS, the operator becomes subject to expanded supervisory obligations beyond the general requirements of the Payment Systems Act. Enhanced Supervisory Requirements SIRPS operators must comply with a heightened supervisory regime across three key areas, outlined below. 1. Governance SIRPS operators must maintain robust and transparent governance structures, including: Balanced board composition, with at least one-third of the board comprising independent directors who represent stakeholders in the system (such as payment service providers, consumers, and experts). Independent directors may serve for no more than two consecutive terms. Subcommittees to assist the board in overseeing compliance, policy implementation, and operational strategy. Clear separation between executives responsible for risk and information security and those overseeing day-to-day business operations. Risk Management and System SecuritySIRPS operators must implement comprehensive risk management frameworks, including: Clear service agreements between the SIRPS operator and its direct participants (payment service providers who connect directly to the SIRPS), defining roles and responsibilities among stakeholders. These agreements must include obligations for direct SIRPS participants to supervise any indirect participants they onboard to ensure compliance with service agreements and business rules. A business continuity plan covering both IT and non-IT aspects, with annual review. The SIRPS must target service availability comparable to international payment infrastructures, including the ability to recover operations within two hours of a disruption and to maintain scalable operational capacity. Tools and controls to monitor and manage material or
February 26, 2026
Thailand is preparing to offer new tools for intellectual property enforcement as the Electronic Transactions Development Agency (ETDA) recently released for public consultation a draft notification requiring social media platforms to verify user identities and conduct know-your-customer (KYC) checks on advertisers. The draft Notification of the Electronic Transactions Commission on Measures to Prevent Technological Crimes for Social Media Service Providers, which is to be issued under the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), as amended in 2025, primarily aims to combat online fraud and technology-related crimes. However, its new obligations also provide IP owners with valuable tools to identify anonymous infringers. Key Regulatory Mandates The draft notification imposes several verification requirements on social media platforms operating in Thailand. These requirements also strengthen IP rights holders’ ability to identify anonymous infringers, as platforms must: Verify user identities through registered phone numbers and link all accounts to verifiable identities. Conduct KYC checks on advertisers, including individuals, companies, and any third-party payers. Perform heightened identity checks for high-risk or repeat offenders before publishing advertisements. Promptly remove content flagged by the Anti-Technology Crime Division and prescreen advertisements for prohibited or high-risk content. How IP Owners Can Use This Notification for Enforcement The phone number–based verification requirement enables IP owners to work more effectively with enforcement authorities in tracing individuals or entities responsible for infringing content. The comprehensive advertiser KYC obligations, including mandatory disclosure of third-party payment sources, create a clear audit trail even when bad actors attempt to obscure their identity through intermediaries or shell accounts. This traceability is essential for pursuing damages and dismantling organized counterfeit operations. The ETDA is now considering adjustments to the draft notification after receiving comments during the public consultation period, which ended on February 2, 2026. Following finalization
February 23, 2026
On February 17, 2026, Thailand’s Personal Data Protection Committee (PDPC) released its draft Guidelines on Personal Data Protection in the Development and Use of Artificial Intelligence. The draft guidelines, which translate data controller and data processor compliance obligations under the Personal Data Protection Act (PDPA) into measures tailored to AI development and deployment, are open for public comment until February 25, 2026. At a public hearing session on the draft guidelines held on February 19, the PDPC emphasized that its approach to AI is not to hinder innovation but to develop practical guidance supporting safe deployment while ensuring data protection. Although the guidelines are not legally binding, they indicate the regulator’s expectations and the likely direction of interpretation and enforcement. Scope of Application and Role of Stakeholders The guidelines will apply to all data controllers and data processors in Thailand, and to overseas data controllers and data processors whose data processing falls within the extraterritorial scope of the PDPA. The draft guidelines distinguish the roles of parties involved in AI deployment. Users of AI who determine the purpose of use and designate the input data, and retain outputs generated by the AI, are considered data controllers. In contrast, AI model providers or system integrators that process personal data under the instructions of the data controller are generally regarded as data processors. However, if an AI model provider utilizes user data for its own purposes, such as model fine-tuning or training, it may instead be classified as a data controller. Key Obligations for AI Data Collection and Use The basic principles of data processing under the PDPA must be maintained throughout the AI implementation lifecycle, from design to decommissioning, emphasizing accountability and privacy-by-design principles. The draft guidelines also stipulate the following: Data processing agreements (DPAs) should include model training prohibitions,