You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 25, 2025

Vietnam’s Digital Tech Industry Law: Building the Future of AI, Chips, and Digital Assets

Artificial intelligence (AI), semiconductors, and digital assets are considered critical drivers of Vietnam’s future economic growth and are fundamental to the nation’s digital transformation targets. These sectors form the core of Vietnam’s strategy to build a robust, globally competitive digital economy. This strategic direction gained substantial momentum with the issuance of the Law on Digital Technology Industry (DTI Law) on June 14, 2025.

The DTI Law was designed to attract investment, stimulate innovation, cultivate high-quality human resources, and ensure the responsible, secure, and sustainable growth of digital technologies like AI and digital assets, harmonizing Vietnam’s digital industry with international standards while safeguarding public interests and national security.

Several key provisions of the DTI Law took effect on July 1, 2025, and the law will become fully effective on January 1, 2026. The government is delegated to provide further necessary guidelines and details for implementation of the law.

Artificial Intelligence (AI): Principle-Driven and Risk-Based Regulations

Under the DTI Law, there are seven core principles guiding the development, provision, and use of AI which are applicable to AI developers, providers and deployers. These principles favor values-based governance over purely technical prescriptions, and include the following:

  • Taking a human-centered approach that upholds ethical values, inclusivity, flexibility, equality, and non-discrimination.
  • Ensuring transparency, accountability, and explainability, with AI systems remaining under human control.
  • Maintaining cybersecurity and system safety.
  • Adherence to data protection and privacy regulations.
  • Having the ability to control AI algorithms and models.
  • Effective risk management throughout the entire lifecycle of AI systems.
  • Compliance with consumer protection laws and other relevant legal frameworks.

AI system management follows a risk-based approach, with the law categorizing systems into high-risk, high-impact, and other groups. High-risk AI systems are those that, in certain applications, may pose significant threats or harm to individuals or the public interest while high-impact systems are designed for multi-purpose use, involving a large user base, extensive parameters, and massive data processing capabilities.

Both high-risk and high-impact systems are subject to stringent regulatory requirements, including technical requirements, transparency in data storage and disclosure, data governance, monitoring and inspection, cybersecurity, and other applicable obligations. Enterprises developing or deploying such systems should therefore begin mapping their AI inventories and preparing documented risk assessments to accelerate future compliance.

AI systems that directly interact with humans must clearly notify their users of their AI aspects. Additionally, digital technology products generated by AI, if listed in the official list issued by the Minister of Science and Technology, must carry identifiable markers detectable by either users or machines.

Semiconductors: Building a Competitive and Vertically Integrated Ecosystem

Vietnam’s semiconductor industry development is guided by four key principles:

  • Focusing on breakthrough semiconductor chip development across sectors, closely linked to the global semiconductor ecosystem (research, design, manufacturing, packaging, testing).
  • Aligning semiconductor development with the electronics industry, with a focus on specialized electronic devices in various sectors.
  • Ensuring sufficient and high-quality human resources for the semiconductor industry.
  • Promoting foreign investment and mobilizing both domestic and international resources to master semiconductor chip technology, design, and production.

The government will establish a semiconductor development strategy based on these four principles and aligned with Vietnam’s socio-economic strategies and management needs. Enterprises are encouraged to closely follow up the country’s semiconductor development strategy to identify potential opportunities for its benefits.

Digital Assets: Legally Recognized for the First Time

For the first time in Vietnamese legislation, the DTI Law recognizes digital assets as property expressed in data form and created, issued, stored, or transferred through digital technologies. The law further classifies them into: (i) virtual assets (excluding securities, digital fiat currency, and other regulated financial assets); (ii) crypto assets (excluding securities, digital fiat currency, and other regulated financial assets), and (iii) other digital assets.

The management of digital assets encompasses several aspects, including establishing and transferring ownership; regulating rights and obligations of involved parties; ensuring cybersecurity, preventing money laundering and terrorist financing; inspection and enforcement; and conditions for businesses providing services crypto asset services.

Incentives for AI and Semiconductor Industries

Vietnam’s DTI Law offers a robust package of investment incentives for projects in AI system development, AI data centers, and semiconductor chip R&D and production, including design, packaging, and testing. These projects are classified as specially prioritized investment sectors and benefit from preferential treatment in areas such as taxation, land use rights, and access to other legal benefits. The government may also provide direct financial support for infrastructure, equipment, and factory construction through local development budgets. Enterprises in these sectors are eligible for customs-related advantages to facilitate import and export activities.

Innovative startups in AI and semiconductors are similarly prioritized, qualifying for incentives under investment, tax, and land laws, and may receive direct funding for workforce training, talent acquisition, R&D, pilot production, consulting, and technology upgrades. The law introduces additional special mechanisms for the semiconductor industry, extending incentives to projects producing materials, machinery, and components that directly support chip manufacturing. Importation of used equipment for semiconductor production is allowed if it meets technical criteria set by the Ministry of Science and Technology, with enterprises required to self-certify compliance. Finally, the law provides targeted support for businesses participating in the semiconductor supply chain, further strengthening Vietnam’s position as a competitive hub for digital technology investment.

Outlook

Although the DTI Law mainly provides a framework and policy-oriented provisions, with specific regulations still needing to be set out in future decrees and circulars, it is essential for businesses to stay ahead of emerging policy trends and regulatory directions shaping the development of Vietnam’s strategic digital technology sectors. Understanding these directions can help businesses seize investment opportunities and gain a first-mover advantage in the fast-evolving digital technology industry. Companies are also encouraged to closely monitor forthcoming guiding regulations under the DTI Law to ensure compliance and fully capitalize on investment incentives and support when rolling out their products and services in the Vietnamese market.

RELATED INSIGHTS​ 

December 11, 2025
On December 10, 2025, the National Assembly of Vietnam passed a new Cybersecurity Law, which will take effect on July 1, 2026. The new Cybersecurity Law was developed based on the consolidation of the 2018 Cybersecurity Law and the 2015 Law on Network Information Security. While the final approved version of the new Cybersecurity Law has not yet been published, according to official reports, the following notable requirements are confirmed to be included: The new Cybersecurity Law dedicates a specific article to prohibited acts related to cybersecurity, under which it strictly prohibits posting or disseminating information online that propagandizes against the Socialist Republic of Vietnam. The law also prohibits, among other things, (i) the appropriation, trading, seizure, or intentional disclosure of information classified as state secrets, work secrets, business secrets, personal secrets, family secrets, and private life; (ii) intentionally eavesdropping, recording, or filming online conversations without authorization; and (iii) the use of artificial intelligence (AI) or new technologies to conduct prohibited acts. The Ministry of Public Security (MPS) has the authority to require enterprises providing telecommunications, internet, and online services, as well as system administrators, to remove information violating cybersecurity laws from systems under their management. The MPS is also assigned responsibility for ensuring information security in cyberspace and data security, establishing mechanisms for IP address identity management, verifying digital account registration information, and issuing warnings and sharing information on cybersecurity threats. Information systems are classified into five levels (similar to the 2015 Law on Network Information Security) based on the degree of harm to national security and social order if an incident occurs. The MPS is the lead agency assisting the government in state management of cybersecurity. The Ministry of National Defense is responsible for managing military information systems, and the Government Cipher Committee manages cryptographic and cipher
December 4, 2025
Thailand has expanded the circumstances under which state agencies may bypass competitive bidding procedures to address urgent security challenges. On November 28, 2025, Thailand’s Ministry of Finance published the Ministerial Regulation Determining Cases of Procurement by Specific Method (No. 6) B.E. 2568 in the Royal Gazette, introducing a new pathway for procuring supplies and services needed to address cyber and military threats that may affect the stability of government agencies or the nation. For technology vendors, cybersecurity firms, and defense contractors, this regulatory change creates immediate opportunities to engage directly with government buyers facing urgent security challenges. New Fast-Track Category for Security Threats The regulation amends Thailand’s Public Procurement and Supplies Management Act B.E. 2560 (2017) to add a new category of procurement that qualifies for the “specific method”—a noncompetitive, direct selection process. Previously, agencies could use this expedited method only in limited circumstances, such as emergencies, cases with proprietary technology requirements, or national security operations. The new provision explicitly covers procurement of supplies related to preventing or resolving cyber or military threats that could impact the stability of a state agency or the country. This addition recognizes the urgent nature of modern security challenges, where competitive bidding timelines may leave agencies vulnerable during critical threat windows. State agencies dealing with active cyberattacks, preparing defensive measures against anticipated threats, or responding to military security concerns can now move directly to negotiate with qualified vendors rather than conducting lengthy public tender processes. Vendor Considerations Vendors offering cybersecurity solutions now have a regulatory avenue to work directly with government clients when stability concerns are present. These solutions include threat detection systems, anti-ransomware tools, incident response services, firewalls, and security consulting. Similarly, defense contractors providing military equipment or specialized security supplies can pursue direct engagement channels where traditional procurement methods would create
December 3, 2025
Thailand’s Civil Court has issued a regulation targeting the use of artificial intelligence (AI) in the preparation of pleadings and other documents submitted to the court. Effective November 17, 2025, the regulation aligns with September 2025 guidance from the president of the Supreme Court, and aims to safeguard accuracy, transparency, and public confidence in civil adjudication. The regulation applies to all parties submitting pleadings or any documents to the Civil Court that are prepared using AI tools or contain AI-generated content. It subjects AI used for these purposes to strict requirements on verification, disclosure, and accountability. Core Obligations The regulation imposes four principal obligations: Lawyers who use AI remain subject to duties of honesty, responsibility to the court, professional standards, and legal ethics, including the duty to assess the appropriateness of the AI tool for the work. Parties and lawyers must verify the accuracy and completeness of all facts, legal provisions, and citations in AI-generated content before submission. Parties and lawyers must disclose to the court any AI-generated content by clearly marking the beginning and end of the AI-generated portion with prescribed statements (see below). Additionally, a certification confirming the use of AI must be provided at the end of the pleading or document, stating that AI was used for certain portions and that the party has reviewed and certifies the accuracy of factual and legal content. Parties and lawyers bear the same full legal and ethical responsibility for AI-generated content as they do for personally authored documents; they cannot evade responsibility or avoid liability by citing AI-related errors. Likewise, parties must ensure that any AI-generated content is truthful, accurate, and unbiased. Prescribed Disclosure Language Each instance of AI-generated content must be preceded by the statement “[The following content was prepared using artificial intelligence]” and must end with “[End
November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.