Viet Nam now has a standalone AI law, and unlike most of Southeast Asia, which has leaned on voluntary guidelines, it comes with binding obligations.
The Law on Artificial Intelligence was passed in December 2025 and took effect on March 1, 2026. It covers how AI is developed, provided, deployed and used.
The law sorts AI systems into three tiers by risk.
- High-risk systems are those that could cause significant harm to people's lives, health, rights or legitimate interests, or affect the public interest, national interests or national security.
- Medium-risk systems are those that could confuse, influence or manipulate users because they may not realize they are interacting with AI or AI-generated content.
- Everything else counts as low-risk.
In practice, a basic AI writing assistant and an AI system that automatically makes credit decisions are not held to the same standard.
What Counts as High-risk
Viet Nam has published its first official list of high-risk AI systems, covering 46 categories across six sectors, from automated student grading to autonomous vehicles. Decision 33/2026/QĐ-TTg was issued on June 30 and took effect on August 15.
Transport accounts for 31 of the 46, including high-level autonomous driving systems and AI that controls road and railway traffic signals. The remaining 15 systems cover ethnic and religious affairs (7), education (3), healthcare (2), banking (2) and judicial proceedings (1).
In education, the list covers AI that automatically evaluates and ranks students, and systems that monitor learner behavior using biometric data. In banking, it names AI that makes credit decisions on its own, along with systems that automatically execute high-value electronic transactions. In healthcare, it covers AI assisted surgical systems and surgical robots.
Some categories become high-risk when they operate without human review, such as AI systems that approve or reject applications without human oversight. Providers of listed systems must carry out conformity assessments, risk management and human oversight.
Systems already running before August 15 have until March 1, 2027 to comply, or until September 1, 2027 for education, healthcare and banking.
Classification is The Provider's Responsibility
Before putting an AI system into use, the provider has to classify it by risk and is accountable for the accuracy and truthfulness of that classification. Providers of medium and high-risk systems must also notify the Ministry of Science and Technology through the National Single Window Artificial Intelligence Portal.
Regulators can step in after a serious incident and require a system to be suspended, recalled or reassessed.
Systems already operating when the law took effect have until March 1 or September 1, 2027, depending on the sector, but authorities can still order a suspension or termination during that window if they judge a system to pose a risk of serious harm.
Urgent Incidents Must Be Reported Within 72 hours
Decree 142/2026/ND-CP, issued on April 30 and effective May 1, fills in the operating rules for the AI law. It covers risk classification and conformity assessment, labelling of AI generated content, and the handling of serious incidents.
Providers must file a preliminary report through the national AI portal within 72 hours of confirming an urgent or uncontrollable serious incident, and within five working days for other serious incidents. A formal remediation report is due within 15 days of the preliminary one. If the provider cannot be reached, the deployer files instead.
The Ministry of Science and Technology brought the national AI portal and a national database of AI systems into operation on August 28. The portal is meant to be the single gateway for filings and procedures, and the database will hold information on AI systems nationwide for monitoring and inspection.
Where Viet Nam stands in Southeast Asia
Viet Nam is the first country in Southeast Asia to pass a standalone AI law.
ASEAN's Guide on AI Governance and Ethics, endorsed in February 2024 and expanded for generative AI in 2025, is voluntary, while countries such as Singapore, Malaysia and Brunei have developed largely voluntary AI governance frameworks of their own.
Malaysia, Indonesia and Thailand are pursuing their own AI legislation or regulatory instruments, but none had enacted a standalone AI law as of the latest reports, according to the Institute of Southeast Asian Studies (ISEAS).
The Viet Namese law does not ban AI as such, but it does prohibit specific conduct. That includes using AI to produce fake content that endangers national security, concealing information that must be disclosed, and obstructing or falsifying the mechanisms that let humans supervise and control AI systems.
