Vietnam's Law on Artificial Intelligence (Law No. 134/2025/QH15) has been in force since 1 March 2026. Decree 142/2026/ND-CP, which fills in the details, has applied since 1 May 2026. Decision 33/2026/QD-TTg, effective 15 August 2026, lists 46 high-risk AI systems across 6 sectors. If you provide or deploy AI in Vietnam, you must now classify every system before launch and notify the Ministry of Science and Technology of medium- and high-risk ones. You must tell users when they are talking to an AI and mark AI-generated media. Serious incidents must be reported within 72 hours or 5 working days. AI systems that were already running get until 1 March 2027, or 1 September 2027 in health, education and finance.
This guide is written for teams that build or run AI: Vietnamese companies, foreign SaaS selling into Vietnam, and buyers working with a Vietnam-based engineering partner. Every article number below was checked against the official texts published in the Government Gazette (Công báo) on congbao.chinhphu.vn. It is a practical summary, not legal advice. Confirm your own case with Vietnamese counsel.
It is Vietnam's first standalone AI law. It sets up risk-based rules for researching, developing, providing, deploying and using AI systems in Vietnam (Article 1). Three texts make up the current framework:
| Text | Issued | In force | What it does |
|---|---|---|---|
| Law on Artificial Intelligence No. 134/2025/QH15 | Passed by the National Assembly 10 Dec 2025 | 1 Mar 2026 | Risk levels, prohibited acts, transparency, incidents, high-risk duties, liability, transition |
| Decree 142/2026/ND-CP | 30 Apr 2026 | 1 May 2026 | Classification rules, risk-classification file, notification, conformity assessment, marking and labelling, incident deadlines, sandbox |
| Decision 33/2026/QD-TTg | 30 Jun 2026 | 15 Aug 2026 | The list of 46 high-risk AI systems in 6 sectors, plus transition dates for listed systems |
AI used only for national defence, security and cryptography is outside the law (Article 1(2)).
Yes, if you take part in AI activity in Vietnam, whether you are a Vietnamese or a foreign organisation (Article 2). The law defines four roles, and your obligations depend on which ones you hold (Article 3):
A typical pattern: a fintech that puts a credit-scoring model into its app under its own brand is the provider. A bank that licenses it is a deployer. The engineering firm that built it for the fintech is a developer. If you are a foreign company with a Vietnam-based engineering partner, the duties that matter most usually sit with whoever puts the system into use in Vietnam. Map the roles in your contracts.

There are three levels, and the provider classifies its own system before putting it into use (Article 9, Article 10(1); Decree 142, Article 6):
| Risk level | Definition | How you know | Main duties |
|---|---|---|---|
| High | Can cause significant harm to life, health, rights and legitimate interests, national or public interest, or national security | The system is on the Prime Minister's list (Decision 33/2026) | Classification file, notification before use, conformity assessment, risk management, logs, human oversight, transparency, incident handling |
| Medium | Can confuse, influence or manipulate users because they cannot tell they are dealing with AI or AI-generated content | Not on the high-risk list, and meets the Decree 142 Article 9 test | Classification file, notification before use, transparency, explain on request |
| Low | Everything else | Neither of the above | Explain on request if there are signs of a violation; publishing basic information is encouraged |
Decree 142 narrows the medium tier. A system is not medium-risk if it only makes technical edits that don't create new content or change identity, is an office tool whose AI nature is obvious from context, does not serve content to the public, is used for clearly fictional art, film or games, or only processes data inside a technical system without facing users (Article 9(3)). Classification applies to AI systems, not to bare models, unless the model is a component of a specific system (Article 6(2)).
Decision 33/2026/QD-TTg lists 46 systems in 6 sectors. Each entry applies only when specific conditions are met, so read the "description" column for your row, not just the title.
| Sector | Systems listed | Examples (each with conditions) |
|---|---|---|
| Education | 3 | Self-study content from uncontrolled data at large scale; automated testing and ranking of learners used as the official result; biometric or emotion monitoring of learners |
| Ethnic and religious affairs | 7 | Automated scoring or final approval of policy beneficiaries; approving, extending or cancelling registrations; stopping support for suspected fraud; inferring a person's ethnicity or religion |
| Health | 2 | AI in surgical robots that intervene directly, or act without staff confirmation at each parameter change |
| Banking | 2 | AI that creates and approves high-value transactions with no human check; AI that makes the final credit decision without independent officer approval |
| Judicial proceedings | 1 | Large-scale biometric identification at the scene, used to resolve public-interest civil cases |
| Transport | 31 | Autonomous vehicle control, signalling and dispatch, air-traffic and airport systems, drone detection |
The banking entries show how the list works. Credit scoring is not automatically high-risk. It becomes high-risk when the system makes the final approve-or-reject decision and that decision is used directly to lend or disburse without independent approval by a credit officer. Decree 142 Article 8(2) adds exclusions. A system is not proposed for the list if it only collects, cleans, classifies or translates data, if a person with authority can genuinely review and override it before the decision takes effect, if it serves only internal operations, or if its output is advisory and never the sole basis for a final decision. In practice, a well-designed human-in-the-loop step is often what keeps a system off the list.
Providers carry the design duties and deployers carry the operating duties (Law Article 14; Decree 142 Articles 12–15). For providers:
Deployers must use the system only within its classified purpose, keep data secure, keep human intervention possible, monitor for drift or misuse, and act and report if serious harm looks likely (Law Article 14(2); Decree Article 15(4)–(6)). A foreign provider of a high-risk system offered in Vietnam needs a lawful point of contact in Vietnam. If the system requires certification, it needs a commercial presence or an authorised representative (Law Article 14(6)).
These duties apply to every risk level, not only to high-risk systems:
File a preliminary report within 72 hours for incidents involving loss of life or serious harm to health, serious disruption of public or essential services, or national security. The same 72-hour limit applies to serious rights violations that are out of control. Other serious incidents get 5 working days. A full report on the remediation follows within 15 days of the preliminary one (Decree 142 Article 19). The clock starts when you have enough information to confirm an incident happened and probably came from the AI system, not when the investigation ends. Filing on time is not an admission of fault. Reports use forms AI01a (organisations) or AI01b (individuals) via the national portal. Providers and deployers must keep system logs and incident data, and a deployer must file if it cannot reach the provider.
There are three sets of dates, depending on when the system went live and whether it is on the high-risk list:
| Situation | Deadline to comply | Source |
|---|---|---|
| Any AI system in operation before 1 Mar 2026, in health, education or finance | 18 months: by 1 Sep 2027 | Law Article 35(1)(a) |
| Any AI system in operation before 1 Mar 2026, other sectors | 12 months: by 1 Mar 2027 | Law Article 35(1)(b) |
| Listed high-risk system in operation before 15 Aug 2026, health, education or finance | Before 1 Sep 2027 | Decision 33/2026 Article 4(1)(a) |
| Listed high-risk system in operation before 15 Aug 2026, other listed sectors | Before 1 Mar 2027 | Decision 33/2026 Article 4(1)(b) |
| Listed high-risk system put into operation within 6 months after 15 Aug 2026 | Before 1 Mar 2027 | Decision 33/2026 Article 4(3) |
| System that becomes high-risk because the list is amended | Up to 12 months from the amendment, with real human oversight and full logs in the meantime | Decree 142 Article 11(5) |
Systems in transition can keep operating, unless the authority finds a risk of serious harm and orders a suspension. A new system launched today gets no grace period for classification and notification. Those happen before use.

Violations lead to administrative fines or criminal liability depending on severity, plus civil compensation for damage (Article 29). The enacted law does not set fine amounts. It delegates administrative sanctions to a Government decree (Article 29(5)), and Decree 142 does not contain them. Earlier drafts, as reported in Vietnamese media, proposed a maximum of VND 2 billion and a percentage of revenue, but those figures are not in the law as passed. Two liability rules already apply. If a high-risk system causes damage even though it was operated correctly, the deployer compensates the injured party first and can then claim from the provider or developer if their contract allows (Article 29(2)). If a third party hacks the system, that party is liable, but a provider or deployer whose negligence allowed it shares liability (Article 29(4)). Authorities can also order reclassification, suspension or withdrawal of a system (Articles 10(6), 12(3)).
If you already build to the EU AI Act, most of the engineering carries over. Both are risk-based, both require disclosure for chatbots and AI-generated media, and both expect human oversight, logs and documentation for high-risk systems. Three differences matter in Vietnam. High-risk status comes from a closed national list of 46 named systems with detailed conditions. Medium-risk systems must also be notified to a national portal before use. And serious incidents have fixed 72-hour and 5-working-day reporting clocks. Keep one control set and map it to both regimes, rather than running two compliance projects.

We are a Hanoi-based engineering studio that builds AI for regulated industries, so these controls are part of our normal design work. We are not a law firm, and we work alongside your counsel.
Yes. Any AI system that interacts directly with people must be designed so users know they are talking to an AI (Article 11(1)). If users could be misled about that, the system is likely medium-risk, which means a classification file and notification before use.
No. Notification is required for medium- and high-risk systems. For low-risk systems, publishing basic information is encouraged but not required (Article 10(3)).
No. The law and Decree 142 say explanations and classification files do not require source code, detailed algorithms, parameters, raw training data or trade secrets (Law Article 14(1)(e); Decree Articles 12(4) and 16(4)).
Only in some cases. A foreign provider of a high-risk system offered in Vietnam needs a lawful point of contact there. If that system must be certified before use, it needs a commercial presence or an authorised representative (Article 14(6)).
Machine-readable marking is mandatory for AI-generated audio, images and video, not for text, unless another law says otherwise (Decree 142 Article 17(1)). Deployers still have to disclose AI-generated text that could mislead people about real events or people.
Yes. The law sets up a controlled testing mechanism, and its results can support recognition of conformity or a reduction of obligations (Article 21). Decree 142 Chapter IV sets out the levels, procedure and reporting.
BeevR is a senior, founder-led software and AI studio in Hanoi, Vietnam. We work at a fixed price per phase, you own the code and IP from day one, and we build compliant software for healthcare, fintech and other regulated industries. If you are building or reworking an AI system that has to meet Vietnam's AI Law, HIPAA or PCI DSS, tell us what you're building.