Loading…
Loading…
Law 134/2025/QH15 is structured into eight chapters and 35 articles:
applied principles (human rights, privacy, national security, no replacement of human authority, transparency, fairness, non-bias, "green AI"), prohibited acts.
management: three-tier system — - High-risk: systems capable of causing significant damage to life, health, fundamental rights, or national security; require conformity assessment before deployment; - Medium-risk: systems creating user confusion about whether they are interacting with AI or consuming AI-generated content (deepfake-adjacent), with mandatory labelling and disclosure obligations; - Low-risk:** all other systems, subject to baseline transparency duties only.
sovereignty:** computing infrastructure, datasets, foundation-model capability building.
human resources:** sectoral deployment, talent development, R&D incentives.
of ethics, accountability assignment across the provider / deployer / importer / distributor / user chain.
Ministry of Information & Communications (MIC) coordinating with Ministry of Science & Technology (MoST) and sectoral ministries.
effective date 1 March 2026, transition windows of 12 months (general) to 18 months (healthcare, education, finance) for existing AI systems, with override authority for systems posing "serious risk of significant damage."
The law is lex specialis for AI, applying cumulatively with the broader 2025-06-14 Law on Digital Technology Industry (Law 71/2025/QH15) and the 2024-11-30 Law on Data (Law 60/2024/QH15) where AI is in scope.
market** (~100m users): conformity assessment for high-risk systems, deepfake/AI-content labelling for medium-risk, mandatory registration of providers with MIC. Comparable in instrument design — though narrower in extraterritorial reach — to the EU AI Act 2024/1689.
South Korea (AI Basic Act, 2025-01-21) as one of the first Asian jurisdictions with a horizontal AI law. Other ASEAN members (Singapore, Malaysia, Indonesia, Thailand) have to date relied on non-binding model frameworks; Vietnam's binding statute raises the regional baseline.
VNG, VinAI — that already operate within Vietnamese regulatory perimeter and benefit from the data-localization + AI-licensing combination.
Anthropic, Google DeepMind, Meta AI, xAI) in their Vietnam deployments: high-risk classification triggers conformity assessment burden, and the prohibited-acts list (notably manipulation of human perception, deepfakes endangering national security) creates broad enforcement discretion.
Decree 53/2022/ND-CP (data localization), Law 60/2024/QH15 (data governance), Decree 147/2024/ND-CP (social-media identity verification) — extending the soft non-tariff barrier to AI workloads.
conformity-assessment thresholds, list of high-risk AI use cases, and registration procedures will be set by MIC and MoST guidance to be issued before 1 March 2026 (a draft implementation decree was released for public consultation in early 2026).
to be specified in subordinate legislation; comparison to EU AI Act's 7% / EUR 35m turnover-based ceiling not yet possible.
providers — extent to which EU-conformity-assessment results will be recognised under Vietnamese conformity assessment remains unspecified.
cross-border API: whether the law's extraterritorial scope reaches non-resident providers serving Vietnamese end-users without local establishment is not explicitly resolved in the statute (Article 2 scope clause to be clarified by implementing decree).