Key Points of Vietnam’s AI Law Draft Decree and Four Practical Actions for Foreign Companies (Effective March 2026)

In Vietnam, the Law on Artificial Intelligence (Law No. 134/2025/QH15, the “AI Law”), passed by the 15th National Assembly on December 10, 2025, entered into force on March 1, 2026. Ahead of this, in February 2026 the Ministry of Science and Technology released a draft decree setting out detailed rules for the AI Law (the “Draft Decree”).

The provisions of the draft decree, however, are broad in scope, and many people in charge at Japanese companies operating in Vietnam have questions such as whether their own AI systems fall within the regulation, whether a notification is required, and what must be reported if an incident occurs.

This article explains, in order, the three-tier risk classification of artificial intelligence systems (the “AI systems”), the four practical obligations set out in the draft decree, and the preparations that Japanese companies should begin now from the perspective of TMI Consulting.

Definition of an “AI system (Hệ thống trí tuệ nhân tạo)” (AI Law, Article 3(2))

2. An AI system is a machine-based system designed to perform artificial intelligence functions with varying degrees of autonomy, capable of self-adaptation after deployment, and which, based on explicitly defined or implicitly formed objectives, infers from input data to generate outputs such as predictions, content, recommendations, or decisions that may influence physical or digital environments.

TOC

Positioning of Vietnam’s AI Law and the Draft Decree

Vietnam’s AI regulation is built on the AI Law. The law has been in force since March 1, 2026 and, for the purpose of protecting the “users” of AI systems, establishes a regulatory framework for “providers” and “deployers”.

  • Provider (an organization or individual that, regardless of whether it or a third party developed the system, places an AI system on the market or puts it into use under its own name, brand, or trademark) (AI Law, Article 3(4), definition of Nhà cung cấp)
  • Deployer (an organization or individual that uses an AI system under its control in professional, commercial, or service-providing activities, excluding personal or non-commercial use) (AI Law, Article 3(5), definition of Bên triển khai)
  • User (an organization or individual that interacts directly with an AI system, or that uses the outputs of such a system) (AI Law, Article 3(6), definition of Người sử dụng)

The AI Law sets out the outline of risk-based regulation, and on this basis the decree defines the specific standards and obligations that directly affect day-to-day operations, such as the criteria for risk classification, notification procedures, labeling methods, and incident-reporting timelines.

In February 2026 the Ministry of Science and Technology released this Draft Decree, which specifies the provisions of the current AI Law in detail, and it is expected to be formally enacted within 2026 after a public comment period.

The important point for companies operating in Vietnam is to advance their own preparations based on the draft decree published so far, rather than waiting for the decree to be formally enacted. This is because the Draft Decree contains many items that take time to build into internal systems, such as the classification scheme for AI systems, notification obligations, and incident-response procedures.

Three-Tier Risk Classification of AI Systems

The Draft Decree classifies AI systems into three levels, namely high risk, medium risk, and low risk.

Criteria for High, Medium, and Low Risk

CategoryCriteria
High riskSystems included in the list of high-risk AI systems issued by the Prime Minister
Medium riskSystems that do not fall under high risk and that meet any of the following. (1) Interacting directly with humans through conversation, voice, images, or virtual assistants without disclosing that they are AI systems. (2) Creating or editing content that may mislead as to the authenticity of events, persons, or information sources. (3) Using deep synthesis technology to simulate or imitate the appearance or voice of a real person
Low riskSystems that fall under neither high risk nor medium risk

Responsibility of the Provider for Self-Classification

Before placing an AI system on the market or putting it into use, the provider is responsible for classifying the system on its own, and bears legal responsibility for the accuracy and truthfulness of the classification result.

Four Practical Obligations Under the Draft Decree

Action 1 (Provider) Notification of the Classification Result Before Market Placement, via the AI One-Stop Electronic Portal

Providers of medium-risk and high-risk AI systems are obliged to notify the Ministry of Science and Technology of the classification result before placing the system on the market or putting it into use. The notification is made through the AI One-Stop Electronic Portal using the prescribed electronic method and form.

Notification alone is sufficient, and no approval is required. It serves as the basis for subsequent audits and information management. The notification must include at least the following items.

  • Provider identification information, namely name, business registration number, tax identification number, registered address, and contact details
  • System identification information, namely system name, version, and a description of the main functions
  • Purpose of use, deployment area, and the expected scale of impact
  • Self-classification of the risk level and the classification criteria
  • An overview of the main risk-management measures and the human oversight and intervention mechanisms

After receiving a valid notification, the AI One-Stop Electronic Portal automatically sends an electronic confirmation containing the identifier of the AI system, and that information is updated in the national AI system database. Disclosure of information is carried out in compliance with the regulations on the protection of state secrets, business secrets, and personal data.

Action 2 (Provider and Deployer) Triggers for Reclassification When Changes or Risks Arise

Providers and deployers are responsible for reviewing and reclassifying the risk classification in any of the following cases.

  • When there is a change or update to the list of high-risk AI systems issued by the Prime Minister
  • When there is a significant change in the function, purpose of use, scale of deployment, or conditions of use
  • When a serious incident occurs, or a new risk arises, and it becomes clear that the actual risk level is higher than the classified level
  • When there is a written request from the competent authority
  • When the deployer modifies, integrates, or changes the intended use of the system from what was initially announced, giving rise to a higher risk

If the review concludes that the risk level needs to be raised, providers and deployers are obliged to apply risk-management measures promptly and to update their records and notification.

Action 3 (Provider and Deployer) Labeling of AI-Generated Content

The Draft Decree sets out an obligation for AI system providers and deployers to label AI-generated content.

When content such as audio, images, or video is created or edited using AI, it must be labeled so that the users of the content can identify it. Labeling is exempted, however, in any of the following cases.

  • Technical editing, such as noise removal, sharpness adjustment, white balance adjustment, resolution enhancement, image stabilization, and adjustment of audio, images, or video, provided that it does not change the essence or main context of the content
  • Removal of minor defects, such as red-eye correction, skin retouching within a range that does not affect identifiability, removal of small background objects, and noise cancellation
  • Text assistance, such as correction of spelling or grammar, summarization, translation, and paraphrasing, provided that it does not distort the basic content
  • Artistic creation and fictional settings, such as film works, art, games, and entertainment content whose fictional nature the recipient can clearly understand from the context at the time of publication
  • In-house AI systems, namely AI tools used internally between companies (B2B) or between a company and its employees (B2E) that do not provide content directly to the public
  • Testing and research in a controlled environment, namely content that is not disseminated or made public
  • Short audio content under 30 seconds, used in an interactive interface where an audio notice has already been given at the start of the session

As for how labeling is implemented, the Draft Decree does not require a single format, and organizations and individuals may choose the most suitable method according to the type of content and the conditions of use.

Action 4 (Provider and Deployer) Reporting and Response When a Serious Incident Occurs (48-Hour and 72-Hour Rules)

A “serious incident” under the Draft Decree means an incident that occurs in the operation of an AI system and that causes, or may cause, any of the following.

  • Loss of human life or serious harm to health
  • Serious material damage that significantly affects the operations of an organization
  • Serious infringement of human rights, the right to privacy, or other legitimate rights and interests
  • Serious interruption of public services or essential services, or an effect on national security, public order, or social safety

When a serious incident occurs in an AI system, providers and deployers are responsible for the following.

  • Taking, without delay, the technical measures necessary to prevent, mitigate, and remedy the effects of the incident
  • Maintaining and preserving the logs, data, and information related to the incident to facilitate verification, assessment, and remediation
  • Reporting the incident to the competent national authority through the AI information portal

The deadlines for submitting the initial report of a serious incident are as follows.

Risk classificationReporting deadlineReporting channel
High-risk systemWithin 48 hours of confirming the incidentThrough the AI information portal
Medium-risk systemWithin 72 hours of confirming the incidentThrough the AI information portal

Meeting the short timelines of 48 or 72 hours is difficult to achieve unless report templates, an internal escalation flow, and a logging system are prepared in advance.

Insights from TMI Consulting and What Foreign Companies Should Begin Now

For Providers

Carry out a provisional risk classification. By tentatively classifying your own AI against the criteria in the Draft Decree, namely high risk, the three requirements for medium risk, and low risk, you can shorten the lead time for the notification preparations that will be needed after the decree is promulgated.

For Providers and Deployers Alike

First, create an AI inventory. Listing the AI systems your company provides or uses, and documenting their purpose, data sources, and using departments, is the basis for risk classification, notification, and incident response. SaaS-type AI developed by an overseas parent company, in-house tools, generative AI APIs, and every other AI system put into use within Vietnam are subject to this inventory.

Second, prepare an incident-response playbook. To meet the extremely short preliminary reporting deadlines of 48 and 72 hours, you need to prepare in advance the initial-response flow from the occurrence of an incident to the report to the national authority, together with internal communication routes, a log-retention system, and report templates.

Third, establish guidelines for labeling AI-generated content. Companies that use generative AI in their operations for marketing, public relations, or internal document creation may wish to put in place a standard procedure for labeling, together with an operational flow for the cases where labeling is exempted, such as where a document has gone through an editorial control process and can be shown to have been created under human responsibility, and a mechanism that records and preserves the editing history in a form that can be verified objectively.

Fourth, build a cross-functional project structure. Responding to the AI Law calls for cross-functional action spanning legal, IT, business divisions, marketing, and public relations. Setting up an internal project structure that involves the relevant departments from the early stage ultimately minimizes the cost of compliance.

Questions About Vietnam’s AI Law Draft Decree

Q1. Will AI systems already in operation also be subject to the regulation?

A. Yes. In principle, AI systems put into use in the Vietnamese market are subject to the regulation. For the medium-risk and high-risk AI systems that are subject to the notification obligation, the provider must carry out self-classification promptly and give notice before placing the system on the market or putting it into use. The Draft Decree also sets out reclassification triggers, such as a significant change in the function, purpose of use, scale of deployment, or conditions of use, an update to the high-risk list to be set by a future Prime Minister’s decision, or a written request from the competent authority, so an ongoing review of the classification is required even after operation begins.

Q2. (Deployer) If our Vietnamese entity uses an AI system developed by our overseas parent company, is that also covered?

A. AI systems put into use within Vietnam are subject to the Draft Decree regardless of how they are supplied. This includes overseas-developed SaaS-type AI, in-house tools, and generative AI APIs. Because the legal responsibility for self-classification and for the accuracy of the classification result rests with the provider, a deployer is advised to confirm the risk classification and notification status of the AI system when creating and updating its own AI system inventory.

Q3. (Provider) If we have judged a system to be low risk through self-classification, is notification still required?

A. Under the Draft Decree, the notification of the classification result before market placement applies to medium-risk and high-risk AI systems. Low-risk AI systems are understood to be outside the notification obligation, but because the provider bears legal responsibility for the accuracy of the self-classification, it is advisable to keep objective grounds for the classification as evidence in the form of documents or data.

Q4. (Deployer) Do all marketing materials created with generative AI require a label?

A. While the Draft Decree requires labeling for audio, images, and video, it exempts labeling where a document has gone through an editorial control process and can be shown to have been created under human responsibility. In practice, this calls for putting in place internal procedures (SOPs) that define the editorial control process, and for recording and preserving the editing history of each material.

Summary and Starting AI Governance Before the Decree Is Promulgated

Vietnam’s AI Law and this Draft Decree form a risk-based regulatory framework, and they include standards and obligations that operational staff cannot ignore, such as the 48-hour and 72-hour incident-reporting rules and the notification obligation on the AI One-Stop Electronic Portal.

Rather than waiting to act until the decree is formally promulgated, advancing based on the draft decree published so far, by putting in place an AI inventory, a provisional risk classification of your own AI, an incident-response playbook, and labeling guidelines, is the key to running compliance smoothly after enforcement.

Referenced Legislation

TOC