Search across all content
A standalone AI law that classifies systems by risk level and assigns responsibilities across the AI supply chain, paired with an ethics circular giving practical guidance.
Vietnam has been investing heavily in artificial intelligence and semiconductors as part of a strategy to become a regional technology powerhouse. AI is being adopted across sectors, including healthcare, education, and finance. But as AI systems become more widespread, the risks they pose, to privacy, to fair treatment, to public safety, grow alongside the benefits.
Vietnam's provisions governing AI were set out in the broader Law on the Digital Technology Industry, which covered a wide range of digital issues. Those provisions were new and had only just taken effect in January 2026. But the government judged that AI required its own dedicated legal framework, one that could address the specific risks of AI systems in detail, assign clear responsibilities to the people who build, provide, and use them, and establish a system for classifying AI by the level of risk it poses.
The challenge was to move quickly without creating a framework that would be too rigid to adapt as the technology develops. Vietnam needed a law that was comprehensive enough to provide clear rules, flexible enough to accommodate a fast-moving technology, and attractive enough to investors and innovators that it did not drive AI development elsewhere.
Vietnam took a two-step approach: a standalone AI law that sets out the legal framework, followed by a national ethics circular that provides practical guidance on responsible development and use.
The AI Law
Enacted on December 10 2025, and effective from 1 March 2026, Vietnam's Law on Artificial Intelligence is one of the first standalone AI laws in Southeast Asia. It fully replaces the AI provisions in the earlier Law on Digital Technology Industry.
AI systems are classified into three risk levels: high (potential significant harm to life, health, rights, or national security), medium (risk of users being misled by undisclosed AI interactions or generated content), and low (all others). Rather than fixing a list of high-risk systems in the law, Vietnam delegates that list to the Prime Minister, a design choice that allows the classification to be updated as new risks emerge without requiring new legislation.
The law sets out who is responsible for what across the AI supply chain. It defines five roles, developers, providers, deployers, users, and affected persons, and assigns obligations accordingly. Providers and deployers carry the heaviest responsibilities. Developers also face fewer requirements, which is a deliberate choice to avoid discouraging the research and experimentation that move the field forward.
On transparency, the law requires that people interacting with an AI system are told they are doing so. AI-generated audio, images, or video must bear machine-readable markings identifying them as AI-produced. The law bans the use of AI to deceive, simulate real people or events to manipulate, exploit vulnerable groups, or obstruct human oversight.
The requirements are especially specific regarding accountability when an AI system causes harm. When a serious incident occurs, developers and providers must act quickly, fixing the problem, suspending the system, or withdrawing it, and report through a centralised national portal. High-risk systems face additional requirements, including risk assessments, human oversight, registration in a national database, and incident reporting. Some require mandatory certification before use; others can opt for self-assessment. Foreign providers of high-risk systems must establish a local point of contact in Vietnam.
The law doesn't only regulate, it actively encourages AI development. A National AI Development Fund provides grants for research. Regulatory sandboxes allow companies to test AI products under simplified rules before facing full compliance requirements. Designated AI clusters in high-tech parks offer tax breaks and shared infrastructure to attract investment.
For organisations already using AI systems before the law took effect, the transition is phased rather than immediate. Systems operating in sensitive sectors, healthcare, education, and finance, have 18 months to comply. All others have 12 months. This gives organisations time to assess their systems against the new requirements and make adjustments, rather than facing an overnight change in what is expected of them.
The National AI Ethics Framework
Issued by the Ministry of Science and Technology via Circular No. 05/2026/TT-BKHCN and effective from 10 March 2026, the ethics framework translates the law's broad principles into requirements that organisations can act on.
Safety must be embedded from the design stage. Developers and operators are required to anticipate potential harmful scenarios, adopt preventive controls, and establish clear quality criteria for data, models, and outputs. Internal testing and validation must take place before any system is deployed.
Human oversight and the ability to intervene must be maintained for all AI-driven decisions and actions, proportionate to the system's potential impact. Organisations must establish mechanisms to gather feedback, detect errors, initiate corrections, and maintain contingency plans for malfunctions or misuse. Security protocols must address threats such as unauthorised access, data poisoning, adversarial attacks, and system hijacking.
The framework requires efforts to detect and mitigate biases in data, models, and operations, with particular attention to effects on vulnerable groups, including children, the elderly, and people with disabilities. Organisations must provide clear notification when AI is being used, including reasonable information about the system's purpose, scope, data sources, general operating principles, and known limitations.
Environmental responsibility is also addressed. Organisations are encouraged to evaluate energy use, computing resources, and environmental impact across the full AI lifecycle, favouring energy-efficient technologies. The framework also encourages responsible experimentation, open research, and knowledge sharing while protecting intellectual property rights.
The framework will be reviewed and updated every three years, or sooner if significant changes in technology, legislation, or governance practices warrant it.
1. Vietnam is among the first countries in the Asia-Pacific region to enact a standalone AI law
With this legislation, Vietnam joins a short list of jurisdictions, including the EU and South Korea, that have moved from governing AI through broader digital or data-protection laws to dedicated AI legislation, and it is one of the first standalone AI laws in Southeast Asia. The speed of enactment, from initial framework provisions in mid-2025 to a standalone law within three months, shows that comprehensive AI regulation need not take years of legislative development.
2. The risk classification system is designed to be updated without new legislation
By delegating the list of high-risk AI systems to the Prime Minister rather than fixing it in the law, Vietnam created a mechanism for the classification to evolve as the technology and its applications change. This avoids a problem that fixed legislative lists can create: the law becoming outdated before it can be amended.
3. The framework establishes clear obligations across the AI supply chain
The law's role-based approach means that developers, providers, deployers, and users each know what is expected of them. The decision to place most obligations on providers and deployers while giving developers more latitude was a deliberate choice to avoid discouraging research and early-stage innovation.
A standalone AI law can be enacted quickly when political will exists. Vietnam moved from initial AI provisions within a broader digital law, passed in mid-2025, to a dedicated, standalone AI law passed on 10 December 2025, in under three months. For governments debating whether AI regulation requires prolonged legislative processes, Vietnam's experience suggests speed and comprehensiveness are not mutually exclusive, provided there is clear political direction and a willingness to defer detailed rules to secondary legislation.
Delegating risk classification lists to the executive allows faster adaptation. Rather than fixing the list of high-risk AI systems in the law, Vietnam gave the Prime Minister the power to issue it, and the implementing decree, Decree 142/2026, sets out how the framework operates in practice. This means the classification can be updated through executive decision rather than fresh legislation. For countries designing risk-based frameworks, this trades some legislative certainty for speed of adaptation.
Balancing innovation incentives with regulatory requirements is an explicit design choice. Vietnam's law pairs its compliance requirements with a national AI development fund, regulatory sandboxes, and tax incentives. Unlike frameworks that focus primarily on rules and enforcement, Vietnam made the economic case for AI development a visible part of the legislation. For governments concerned that AI regulation will deter investment, Vietnam's approach demonstrates that incentives and safeguards can be built into the same law.
The ethics framework operationalises the law's principles. The AI law sets out principles such as safety, transparency, and human oversight; the National AI Ethics Framework, issued as a circular effective 10 March 2026, adds the practical detail, requiring safety to be embedded from the design stage, testing before deployment, human intervention capabilities, bias detection with attention to vulnerable groups, and clear notification when AI is in use. For governments that have adopted AI principles but struggle to apply them, Vietnam's two-layer approach of law plus operational circular offers one model.
This case study was written with assistance from artificial intelligence.





Connect with 500,000+ public servants solving your hardest challenges.





Connect with 500,000+ public servants solving your hardest challenges.
Help public servants worldwide learn from your work, what worked, what flopped and what you'd do differently
Share your project
Log in or sign up to continue the conversation