You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 5, 2026

Vietnam Takes Major Step in AI Governance with New Guiding Decree

Vietnam’s AI regulatory framework has reached an important milestone. While the Law on Artificial Intelligence No. 134/2025/QH15 (AI Law) established the foundation for AI governance, many practical compliance requirements were left to implementing regulations.

On April 30, 2026, the government issued Decree No. 142/2026/ND-CP (Decree 142), which took effect on May 1, 2026, and provides the first detailed guidance on the implementation of the AI Law. Although an official list of high-risk AI systems is still pending from the prime minister, Decree 142 provides valuable insight into how Vietnam’s risk-based AI regulatory framework will operate in practice.

Risk Classification Framework

The AI Law adopts a risk-based approach under which AI systems are classified as high-risk, medium-risk, or low-risk. Decree 142 builds on this framework by providing detailed guidance on how these classifications are determined.

High-risk AI systems are determined based on factors such as (i) their potential impact on life, health, property, human rights, public interests, or national security; (ii) the sector in which they are deployed; and (iii) the scale of affected users or integration with critical infrastructure. The latest draft list of high-risk AI systems appears to follow these same principles.

Medium-risk AI systems generally include systems that may mislead, influence, or manipulate users, particularly where users may not realize they are interacting with AI or AI-generated content. The focus is therefore on transparency and authenticity risks rather than broader societal or safety concerns.

Low-risk AI systems are those that do not meet the criteria for either high-risk or medium-risk classification.

Importantly, Decree 142 seeks to avoid over-classification. Certain systems may fall outside the high-risk or medium-risk regimes, including internal-use systems, office-support tools, technical editing applications, certain back-end processing systems, and AI systems used in artistic, gaming, cinematic, or other creative contexts.

Providers must also review and reclassify AI systems where significant changes materially alter the system’s risk profile, where serious incidents reveal a higher level of risk, or where required by regulatory developments or competent authorities.

Key Compliance Requirements

Risk Classification Documentation and Notification of Medium- and High-Risk AI Systems

Before deployment, providers of medium-risk and high-risk AI systems must prepare risk classification dossiers containing key information regarding the system, its intended purpose, deployment context, affected users, principal input data, and applicable risk management measures.

Decree 142 limits disclosure obligations to information within the provider’s lawful access and control. Providers are generally not required to disclose source code, model parameters, raw training data, or protected confidential information. The decree also recognizes equivalent international technical documentation standards and, where an AI system uses personal data, permits a personal data processing impact assessment (DPIA) dossier prepared in accordance with personal data protection laws to replace or be integrated into the risk classification dossier, thereby reducing duplicative compliance requirements.

Providers must then notify the Ministry of Science and Technology (MST) of the risk classification results through the national AI one-stop portal before deployment. The notification follows a self-declaration model and automatically generates an AI system identification code and electronic confirmation.

Governance Requirements for High-Risk AI Systems

Decree 142 clarifies that mandatory third-party conformity certification applies only to certain categories of high-risk AI systems. For other high-risk systems, providers may conduct self-assessments or engage accredited conformity assessment organizations, while remaining responsible for the assessment results.

Providers of high-risk AI systems must also establish and maintain risk management systems addressing risk assessment, data quality, human oversight, risk mitigation measures, and ongoing reviews following significant system changes. Reassessment is required where material changes affect the original conformity assessment results.

Deployers are subject to corresponding obligations, including monitoring system performance, maintaining human oversight, implementing risk controls, and notifying providers and authorities where serious risks or incidents arise.

Transparency Requirements for All AI Systems

Transparency is a central feature of Decree 142. Providers must implement machine-readable technical markings for AI-generated or AI-modified audio, image, and video content, such as metadata, digital signatures, or other provenance verification measures. Separately, deployers making AI-generated content available to the public must provide clear notifications where such content could mislead users regarding authenticity, particularly in relation to deepfakes, simulated voices, and recreated real-world events.

The decree recognizes a number of exceptions, including certain technical edits, internal-use content, and research or testing activities. Overall, the framework adopts a dual-layer approach combining technical traceability with user-facing transparency.

Incident Reporting for All AI Systems

Decree 142 further clarifies the AI Law’s serious incident regime. Covered incidents include those involving death, serious health impacts, significant property damage, serious infringements of rights and interests, or disruptions to public services, essential services, national security, or public order.

Providers and deployers must submit preliminary reports within 72 hours for urgent incidents or within five working days for other serious incidents, preserve relevant logs and data, and submit follow-up reports within 15 days. Where incident reporting obligations also arise under cybersecurity, personal data protection, or sector-specific regulations, reporting must additionally comply with those requirements.

Foreign Providers

The AI Law requires foreign providers of certain high-risk AI systems subject to mandatory conformity certification to establish a commercial presence or appoint an authorized representative in Vietnam. Decree 142 does not further clarify the scope of this requirement, leaving uncertainty regarding its application to cross-border AI services.

Other Notable Developments

Decree 142 introduces a controlled regulatory sandbox mechanism for AI systems. Depending on the risk level, deployment scope, and data involved, participants may benefit from certain regulatory flexibilities during testing while remaining subject to regulatory oversight and compliance with cybersecurity and personal data protection laws.

The decree also contains transitional provisions pending the launch of the national AI one-stop portal. However, as of the date of writing, the portal has not yet been launched and no formal alternative submission mechanism has been announced.

Outlook

Decree 142 represents a significant step toward operationalizing Vietnam’s AI Law by introducing detailed compliance obligations, governance requirements, and implementation procedures, particularly for high-risk AI systems. However, several important elements remain pending, including the prime minister’s official list of high-risk AI systems, further guidance on conformity assessment methodologies, and the launch of the national AI one-stop portal. Businesses should therefore continue monitoring forthcoming regulations and guidance to assess the practical impact of the regime on their AI-related activities in Vietnam.

RELATED INSIGHTS​ 

April 10, 2026
As digital commerce continues to reshape consumer behavior in Thailand, the Office of the Consumer Protection Board (OCPB) has been taking steps to review and update key regulations for online platforms. The OCPB has had a particular focus on addressing the risks posed by e-marketplace businesses—from misleading product information to fraudulent online transactions. Some of the regulator’s current legislative efforts related to Thailand’s labeling regulations as well as potential changes to the country’s law on direct sales and marketing. Proposed Changes to Consumer Protection Labeling Regulations On February 24, 2026, the OCPB convened a public hearing to review the Notification of the Committee on Labels re: Specification of Goods as Controlled Label Goods B.E. 2565 (2022) and its annex issued under the Consumer Protection Act. The closed-door session, which started the OPCD’s process of seeking feedback on the proposed changes, brought together representatives from government agencies, business operators, and consumer groups. The OCPB explained that its review of the labeling regulations aims to address regulatory gaps arising from evolving commercial practices, particularly the expansion of e-commerce and cross-border transactions. Authorities highlighted recurring issues involving product information that is unclear, incomplete, or potentially misleading in digital sales channels. The proposed revisions are intended to improve consumers’ access to accurate and complete product information, ensure that label disclosures remain relevant amid the growth of e-commerce, and strengthen protections against deceptive or misleading digital advertising. The review is being undertaken pursuant to the Consumer Protection Act B.E. 2522 (1979). As part of the initiative, the OCPB signaled a potential update to the categories of “controlled label products” as well as enhanced disclosure obligations for business operators, with the broader aim of promoting greater transparency, reinforcing operator accountability, and aligning Thailand’s labeling framework with current market conditions. The OCPB secretary general emphasized that
April 9, 2026
As part of its ongoing public consultation process for the development of new practical guidelines under the Personal Data Protection Act B.E. 2562 (2019) (PDPA), Thailand’s Personal Data Protection Committee (PDPC) held a two‑day public hearing on April 1–2, 2026. The hearing followed an online questionnaire and stakeholder engagement activities conducted in March 2026 and reflects the PDPC’s continued efforts to develop guidance that aligns international regulatory standards with Thai operational realities. The public hearing provided a forum for participants from both the public and private sectors to exchange views with the PDPC on the proposed guidance so that it responds to the needs of the business community while supporting effective and balanced enforcement of the PDPA. The PDPC emphasized that the consultation process is part of a wider policy objective to build trust in the convenient, secure, and internationally aligned exchange of data. Structure of the Consultation Process According to the PDPC, the initiative to develop the draft PDPA guidelines is being implemented through three core phases: Review of international best practices. The PDPC has conducted a comparative review of data protection guidance and regulatory approaches in jurisdictions with internationally recognized standards, including Singapore, the United Kingdom, the European Union (EU), and Japan. These materials are intended to serve as a reference point for developing practical recommendations across key subject areas under the PDPA. Identification of practical issues and challenges. To ensure that the guidelines respond to real‑world compliance challenges in Thailand, the PDPC has gathered views from a broad range of stakeholders across the public sector, the private sector, and the general public. This phase included focus group discussions and questionnaires aimed at identifying areas to provide organizations with greater clarity and consistency on regulatory expectations. Preparation of draft guidelines. Insights from the comparative study and stakeholder
April 3, 2026
On March 16, 2026, Vietnam’s Ministry of Public Security released a draft version of a new Decree on the Prevention and Combating of Cybercrime and High-Tech Crime to replace the currently effective Decree 25/2014/ND-CP. In the draft, the ministry has proposed a comprehensive regulatory framework aimed at addressing violations occurring within the cybersecurity domain, including measures related to intellectual property. Acts of Online IP Infringement Article 9 of the draft decree notably introduces specific provisions addressing online intellectual property infringement, with detailed lists of acts considered to constitute infringement in the online environment. Copyright and related rights infringement includes: Uploading or sharing works, performances, sound recordings, video recordings, broadcasts, computer programs, software, research, documents, theses, or other intellectual creations on digital platforms without the consent of the rights holder. Unauthorized livestreaming of copyrighted television programs, sporting events, or artistic performances. Uploading, sharing, storing, transmitting, or providing links to infringing works or digital content via websites, social networks, applications, or digital platforms. Providing or using software, tools, devices, or access codes to circumvent technological protection measures or evade lawful control mechanisms implemented by rights holders. Using artificial intelligence (AI) tools to replicate the ideas or structure of another person’s work without significant new creativity or without proper attribution, thereby causing damage to the original author. Industrial property infringement includes: Manufacturing, trading, advertising, or distributing counterfeit goods bearing counterfeit trademarks, geographical indications, or industrial designs, as well as goods infringing industrial property rights through online platforms. Unauthorized registration, appropriation, or use of domain names, account names, or digital identifiers that create confusion regarding the rights holder or the origin of goods or services. Producing, using, or offering for sale products containing all or part of a patented invention via online platforms. Advertising or introducing products with technical features or characteristics identical
April 3, 2026
Thailand’s Securities and Exchange Commission (SEC) has established a comprehensive governance framework for the use of artificial intelligence and machine learning (AI/ML) in the capital markets. The framework provides guidance to capital market business operators on understanding the risks associated with AI/ML implementation and adopting appropriate practices to build public confidence in Thailand’s capital markets. While the guidelines are principle-based rather than prescriptive, they reflect the SEC’s expectations for responsible AI/ML governance and are likely to inform supervisory activities and industry standards going forward. Scope The framework applies to capital market business operators supervised by the SEC. This includes, for example, securities and derivatives firms, asset management companies, mutual fund and private fund managers, investment advisors and investment consultants (including robo-advisory service providers), derivatives intermediaries, and other licensed intermediaries and market operators in the Thai capital markets that deploy AI/ML in their operations. Core Principles of the Guidelines The framework is presented as a best-practice manual rather than prescriptive regulation, providing guidance that regulated entities may apply to their AI/ML governance and risk management as appropriate. While currently nonbinding, the guidelines signal the SEC’s expectations for the sector, particularly in relation to other binding SEC regulations such as those covering IT risk management and market conduct. The guidelines name four core principles for AI/ML deployment: Fairness: Design and develop AI/ML with consideration for fairness, equality, and social diversity to prevent discrimination against individuals or groups. Legal and ethical compliance: Ensure AI/ML use aligns with applicable laws, ethical standards, and organizational values and policies. Accountability: Establish clear responsibility—both internally and externally—for AI/ML activities and outcomes. Transparency: Provide adequate disclosure to users about AI/ML use, including explainability of decisions and traceability of activities. AI/ML Best Practices The guidelines prescribe best practices across four stages of the AI/ML lifecycle, as described below.