← Blog
Field note

Vietnam AI Law 2026: What Companies Building AI Must Do

Thien Nguyen · Oct 6, 2026

Vietnam's Law on Artificial Intelligence (Law No. 134/2025/QH15) has been in force since 1 March 2026. Decree 142/2026/ND-CP, which fills in the details, has applied since 1 May 2026. Decision 33/2026/QD-TTg, effective 15 August 2026, lists 46 high-risk AI systems across 6 sectors. If you provide or deploy AI in Vietnam, you must now classify every system before launch and notify the Ministry of Science and Technology of medium- and high-risk ones. You must tell users when they are talking to an AI and mark AI-generated media. Serious incidents must be reported within 72 hours or 5 working days. AI systems that were already running get until 1 March 2027, or 1 September 2027 in health, education and finance.

This guide is written for teams that build or run AI: Vietnamese companies, foreign SaaS selling into Vietnam, and buyers working with a Vietnam-based engineering partner. Every article number below was checked against the official texts published in the Government Gazette (Công báo) on congbao.chinhphu.vn. It is a practical summary, not legal advice. Confirm your own case with Vietnamese counsel.

What is Vietnam's AI Law and when did it take effect?

It is Vietnam's first standalone AI law. It sets up risk-based rules for researching, developing, providing, deploying and using AI systems in Vietnam (Article 1). Three texts make up the current framework:

TextIssuedIn forceWhat it does
Law on Artificial Intelligence No. 134/2025/QH15Passed by the National Assembly 10 Dec 20251 Mar 2026Risk levels, prohibited acts, transparency, incidents, high-risk duties, liability, transition
Decree 142/2026/ND-CP30 Apr 20261 May 2026Classification rules, risk-classification file, notification, conformity assessment, marking and labelling, incident deadlines, sandbox
Decision 33/2026/QD-TTg30 Jun 202615 Aug 2026The list of 46 high-risk AI systems in 6 sectors, plus transition dates for listed systems

AI used only for national defence, security and cryptography is outside the law (Article 1(2)).

Does the Vietnam AI Law apply to your company?

Yes, if you take part in AI activity in Vietnam, whether you are a Vietnamese or a foreign organisation (Article 2). The law defines four roles, and your obligations depend on which ones you hold (Article 3):

  • Developer: designs, builds, trains, tests or fine-tunes a model, algorithm or system and directly controls its methods, training data or parameters.
  • Provider: puts an AI system on the market or into use under its own name or brand, whether it built the system or a third party did. Most classification and high-risk duties fall here.
  • Deployer: uses an AI system under its control for professional, commercial or service purposes. Personal, non-commercial use is excluded.
  • User: interacts with the system directly or uses its output.

A typical pattern: a fintech that puts a credit-scoring model into its app under its own brand is the provider. A bank that licenses it is a deployer. The engineering firm that built it for the fintech is a developer. If you are a foreign company with a Vietnam-based engineering partner, the duties that matter most usually sit with whoever puts the system into use in Vietnam. Map the roles in your contracts.

Business leaders reviewing an AI system together
Business leaders reviewing an AI system together

How does the law classify AI systems by risk?

There are three levels, and the provider classifies its own system before putting it into use (Article 9, Article 10(1); Decree 142, Article 6):

Risk levelDefinitionHow you knowMain duties
HighCan cause significant harm to life, health, rights and legitimate interests, national or public interest, or national securityThe system is on the Prime Minister's list (Decision 33/2026)Classification file, notification before use, conformity assessment, risk management, logs, human oversight, transparency, incident handling
MediumCan confuse, influence or manipulate users because they cannot tell they are dealing with AI or AI-generated contentNot on the high-risk list, and meets the Decree 142 Article 9 testClassification file, notification before use, transparency, explain on request
LowEverything elseNeither of the aboveExplain on request if there are signs of a violation; publishing basic information is encouraged

Decree 142 narrows the medium tier. A system is not medium-risk if it only makes technical edits that don't create new content or change identity, is an office tool whose AI nature is obvious from context, does not serve content to the public, is used for clearly fictional art, film or games, or only processes data inside a technical system without facing users (Article 9(3)). Classification applies to AI systems, not to bare models, unless the model is a component of a specific system (Article 6(2)).

Which AI systems are high-risk under Decision 33/2026?

Decision 33/2026/QD-TTg lists 46 systems in 6 sectors. Each entry applies only when specific conditions are met, so read the "description" column for your row, not just the title.

SectorSystems listedExamples (each with conditions)
Education3Self-study content from uncontrolled data at large scale; automated testing and ranking of learners used as the official result; biometric or emotion monitoring of learners
Ethnic and religious affairs7Automated scoring or final approval of policy beneficiaries; approving, extending or cancelling registrations; stopping support for suspected fraud; inferring a person's ethnicity or religion
Health2AI in surgical robots that intervene directly, or act without staff confirmation at each parameter change
Banking2AI that creates and approves high-value transactions with no human check; AI that makes the final credit decision without independent officer approval
Judicial proceedings1Large-scale biometric identification at the scene, used to resolve public-interest civil cases
Transport31Autonomous vehicle control, signalling and dispatch, air-traffic and airport systems, drone detection

The banking entries show how the list works. Credit scoring is not automatically high-risk. It becomes high-risk when the system makes the final approve-or-reject decision and that decision is used directly to lend or disburse without independent approval by a credit officer. Decree 142 Article 8(2) adds exclusions. A system is not proposed for the list if it only collects, cleans, classifies or translates data, if a person with authority can genuinely review and override it before the decision takes effect, if it serves only internal operations, or if its output is advisory and never the sole basis for a final decision. In practice, a well-designed human-in-the-loop step is often what keeps a system off the list.

What must providers and deployers of high-risk AI do?

Providers carry the design duties and deployers carry the operating duties (Law Article 14; Decree 142 Articles 12–15). For providers:

  • Build a risk classification file before use. It covers system identity and version, purpose and functional architecture, users and affected people, main input data types and a summary of risk controls (Decree Article 12). A personal-data impact assessment can be reused as part of it.
  • Notify the Ministry of Science and Technology through the national AI one-stop portal before use. The portal issues a system ID (Decree Article 14). The same applies to medium-risk systems.
  • Pass a conformity assessment before use and again after a significant change, such as a new model, a new data source or a new integration. Systems on the "must be certified" part of the list need a registered conformity-assessment body. Other high-risk systems may self-assess (Law Article 13; Decree Article 13).
  • Run risk management: identify risks, govern training, test and evaluation data, design human oversight and intervention, and review controls when the model, data or use changes (Decree Article 15).
  • Keep technical documentation and operating logs sufficient for assessment and post-launch inspection (Law Article 14(1)(c)).
  • Explain on request at the level of purpose, functional principles and main input data. The law does not require you to disclose source code, detailed algorithms, parameters or trade secrets (Law Article 14(1)(e)).

Deployers must use the system only within its classified purpose, keep data secure, keep human intervention possible, monitor for drift or misuse, and act and report if serious harm looks likely (Law Article 14(2); Decree Article 15(4)–(6)). A foreign provider of a high-risk system offered in Vietnam needs a lawful point of contact in Vietnam. If the system requires certification, it needs a commercial presence or an authorised representative (Law Article 14(6)).

What are the transparency and labelling rules for chatbots and AI content?

These duties apply to every risk level, not only to high-risk systems:

  • Tell users they are talking to AI. Providers must design systems that interact directly with people so users know it is an AI (Law Article 11(1)).
  • Machine-readable marking of AI audio, images and video. Use file structure, metadata, a digital signature or an equivalent technique (Decree Article 17). Machine-readable marking of text output is not mandatory unless another law requires it. Open-source or free systems comply by shipping the marking function or publishing how to configure it.
  • Visible labels from deployers. When you publish AI-generated or AI-edited content that could mislead people about real events or people, say so clearly. Audio, images or video that imitate a real person's face or voice, or recreate real events, must carry an easy-to-see label (Law Article 11(3)–(4); Decree Article 18).
  • Exemptions. Quality-only edits, spelling and grammar fixes, summaries and translations that keep the meaning, internal-only content, and R&D content not released to the public (Decree Article 18(4)).

How fast must you report a serious AI incident?

File a preliminary report within 72 hours for incidents involving loss of life or serious harm to health, serious disruption of public or essential services, or national security. The same 72-hour limit applies to serious rights violations that are out of control. Other serious incidents get 5 working days. A full report on the remediation follows within 15 days of the preliminary one (Decree 142 Article 19). The clock starts when you have enough information to confirm an incident happened and probably came from the AI system, not when the investigation ends. Filing on time is not an admission of fault. Reports use forms AI01a (organisations) or AI01b (individuals) via the national portal. Providers and deployers must keep system logs and incident data, and a deployer must file if it cannot reach the provider.

What are the deadlines for AI systems already in use?

There are three sets of dates, depending on when the system went live and whether it is on the high-risk list:

SituationDeadline to complySource
Any AI system in operation before 1 Mar 2026, in health, education or finance18 months: by 1 Sep 2027Law Article 35(1)(a)
Any AI system in operation before 1 Mar 2026, other sectors12 months: by 1 Mar 2027Law Article 35(1)(b)
Listed high-risk system in operation before 15 Aug 2026, health, education or financeBefore 1 Sep 2027Decision 33/2026 Article 4(1)(a)
Listed high-risk system in operation before 15 Aug 2026, other listed sectorsBefore 1 Mar 2027Decision 33/2026 Article 4(1)(b)
Listed high-risk system put into operation within 6 months after 15 Aug 2026Before 1 Mar 2027Decision 33/2026 Article 4(3)
System that becomes high-risk because the list is amendedUp to 12 months from the amendment, with real human oversight and full logs in the meantimeDecree 142 Article 11(5)

Systems in transition can keep operating, unless the authority finds a risk of serious harm and orders a suspension. A new system launched today gets no grace period for classification and notification. Those happen before use.

Vietnam AI Law timeline: law in force 1 Mar 2026, Decree 142 on 1 May 2026, Decision 33 high-risk list on 15 Aug 2026, transition deadlines 1 Mar 2027 and 1 Sep 2027 for health, education and finance
Figure 1: Vietnam AI Law timeline: law in force 1 Mar 2026, Decree 142 on 1 May 2026, Decision 33 high-risk list on 15 Aug 2026, transition deadlines 1 Mar 2027 and 1 Sep 2027 for health, education and finance

What are the penalties under Vietnam's AI Law?

Violations lead to administrative fines or criminal liability depending on severity, plus civil compensation for damage (Article 29). The enacted law does not set fine amounts. It delegates administrative sanctions to a Government decree (Article 29(5)), and Decree 142 does not contain them. Earlier drafts, as reported in Vietnamese media, proposed a maximum of VND 2 billion and a percentage of revenue, but those figures are not in the law as passed. Two liability rules already apply. If a high-risk system causes damage even though it was operated correctly, the deployer compensates the injured party first and can then claim from the provider or developer if their contract allows (Article 29(2)). If a third party hacks the system, that party is liable, but a provider or deployer whose negligence allowed it shares liability (Article 29(4)). Authorities can also order reclassification, suspension or withdrawal of a system (Articles 10(6), 12(3)).

How does Vietnam's AI Law compare with the EU AI Act?

If you already build to the EU AI Act, most of the engineering carries over. Both are risk-based, both require disclosure for chatbots and AI-generated media, and both expect human oversight, logs and documentation for high-risk systems. Three differences matter in Vietnam. High-risk status comes from a closed national list of 46 named systems with detailed conditions. Medium-risk systems must also be notified to a national portal before use. And serious incidents have fixed 72-hour and 5-working-day reporting clocks. Keep one control set and map it to both regimes, rather than running two compliance projects.

What should your team do in the next 90 days?

  • Inventory every AI system you provide or deploy in Vietnam, including AI features inside larger products, and record your role in each one.
  • Check each against Decision 33/2026, condition by condition, and against the Decree 142 Article 8(2) exclusions.
  • Write a classification file for every medium- and high-risk system, reusing your personal-data impact assessment where you can.
  • Notify before launch through the national AI portal, or the channel the Ministry announces while the portal is not yet officially running (Decree Article 46).
  • Add an AI disclosure to every chat, voice or agent interface that faces users.
  • Turn on machine-readable marking for generated audio, images and video, and visible labels for synthetic people or events.
  • Design a real human override for consequential decisions: a person who sees enough context to approve, reject or change the output before it takes effect.
  • Log the operation: inputs, outputs, model version, tool calls and human interventions, kept for inspection.
  • Write an incident runbook with the 72-hour and 5-working-day clocks, the AI01a form and named owners.
  • Treat model swaps as changes. A new model, data source or integration can trigger re-assessment, so put it through your eval and change process.
  • Update contracts so provider, deployer and developer responsibilities and recourse under Article 29(2) are written down.
Eleven actions for the next 90 days under Vietnam’s AI Law, plus incident reporting clocks of 72 hours, 5 working days and a 15-day full report
Figure 2: Eleven actions for the next 90 days under Vietnam’s AI Law, plus incident reporting clocks of 72 hours, 5 working days and a 15-day full report

How does BeevR build AI that is ready for these rules?

We are a Hanoi-based engineering studio that builds AI for regulated industries, so these controls are part of our normal design work. We are not a law firm, and we work alongside your counsel.

  • Human oversight and kill switch by design. Our open-source agent framework Kite treats the LLM as an untrusted component. A kernel validates every proposed action before it runs, with a kill switch and idempotent retries.
  • Audit trails. Our HIPAA-compliant AI agent builds use PHI masking, tamper-evident audit logs and human review on anything affecting care. These are the same building blocks the Vietnamese texts ask for: logs and human intervention.
  • Data that stays put. Nebula, our on-device GraphRAG, runs in the browser so nothing leaves the device. That is useful when data residency is the hard constraint.
  • Regulated delivery. See our fintech MVP development and human-in-the-loop AI work, and the projects in our stories.

FAQ

Does the law apply to a chatbot on my website?

Yes. Any AI system that interacts directly with people must be designed so users know they are talking to an AI (Article 11(1)). If users could be misled about that, the system is likely medium-risk, which means a classification file and notification before use.

Do I need to register a low-risk AI system?

No. Notification is required for medium- and high-risk systems. For low-risk systems, publishing basic information is encouraged but not required (Article 10(3)).

Will I have to hand over source code or model weights?

No. The law and Decree 142 say explanations and classification files do not require source code, detailed algorithms, parameters, raw training data or trade secrets (Law Article 14(1)(e); Decree Articles 12(4) and 16(4)).

Does a foreign AI provider need a Vietnamese entity?

Only in some cases. A foreign provider of a high-risk system offered in Vietnam needs a lawful point of contact there. If that system must be certified before use, it needs a commercial presence or an authorised representative (Article 14(6)).

Must AI-generated text be watermarked?

Machine-readable marking is mandatory for AI-generated audio, images and video, not for text, unless another law says otherwise (Decree 142 Article 17(1)). Deployers still have to disclose AI-generated text that could mislead people about real events or people.

Is there a regulatory sandbox?

Yes. The law sets up a controlled testing mechanism, and its results can support recognition of conformity or a reduction of obligations (Article 21). Decree 142 Chapter IV sets out the levels, procedure and reporting.

BeevR is a senior, founder-led software and AI studio in Hanoi, Vietnam. We work at a fixed price per phase, you own the code and IP from day one, and we build compliant software for healthcare, fintech and other regulated industries. If you are building or reworking an AI system that has to meet Vietnam's AI Law, HIPAA or PCI DSS, tell us what you're building.