Written and maintained by CASRAI Editorial Board
Last updated
Last verified against primary sources: 25 September 2026. Most surveys of AI regulation in Asia stop at Korea, Japan, Singapore and China. That map is now out of date. On 10 December 2025 the 15th National Assembly of Vietnam passed Law No. 134/2025/QH15 on Artificial Intelligence, by 429 votes of 434 deputies present — 90.7 per cent. It entered into force on 1 March 2026, and it is the first comprehensive, standalone, binding AI statute in Southeast Asia.
That last claim is worth stating precisely, because the region has no shortage of AI governance documents. Singapore has published influential model frameworks, but they are advisory. Several ASEAN states have guidelines, strategies and sectoral rules. Vietnam has a law: eight chapters, 35 articles, obligations that attach to named actors, and an enforcement chapter. This page walks that structure article by article rather than paraphrasing a press summary, because the structure is where the surprises are.
One honest caveat up front, and it governs everything below. Law 134/2025/QH15 is a framework statute. It repeatedly delegates the operative detail — the classification criteria, the labelling standards, the incident thresholds, the conformity-assessment procedures, the scope of the local-presence duty — to implementing decrees and to lists the Prime Minister has yet to issue. A reader who needs to know whether a specific system is in scope cannot answer that question from the statute alone. That is the same position the Italian AI law 132/2025 is in, and it is a normal stage in a civil-law jurisdiction, but it should temper any compliance plan built on the text as it currently stands.
The Shape of the Law: Eight Chapters, 35 Articles
The chapter headings do a lot of work here. Read them in order and the drafters’ priorities are legible.
| Chapter | Articles | Subject |
|---|---|---|
| I | 1–8 | General provisions: scope, definitions, principles, state policy, prohibited acts |
| II | 9–15 | Risk-based classification and management of AI systems |
| III | 16–18 | Infrastructure development and assurance of national AI sovereignty |
| IV | 19–25 | AI application, innovation ecosystem and human resources |
| V | 26–27 | Ethics and responsibilities in AI activities |
| VI | 28–29 | Inspection, supervision and handling of violations |
| VII | 30–32 | State governance of artificial intelligence |
| VIII | 33–35 | Implementation and transitional provisions |
Article 1 sets the scope: the research, development, provision, deployment and use of AI systems — collectively “artificial intelligence activities” — together with the rights and obligations of the organisations and individuals involved, and state management of those activities in Viet Nam. Note the verb list. The statute reaches research and development, not only the placing of a finished product on a market. That is a broader entry point than a pure product-safety regulation.
Article 7: The Prohibited Acts
Every risk-tiered AI statute needs a floor beneath its tiers, and Article 7 is Vietnam’s. It is a list of acts prohibited outright, irrespective of which risk class a system would otherwise fall into. The prohibitions cover:
- Unlawful use generally — using an AI system to commit acts that are already illegal.
- Forged elements and simulations of real persons or events created or used to deceive or to manipulate human perception, where that deception is intentional and systematic. This is the deepfake and synthetic-impersonation provision, and it is drafted around the purpose of the artefact rather than the technique used to make it.
- Exploitation of vulnerable groups, with children, the elderly and persons with disabilities named.
- Fabricated content that threatens national security or social order.
- Circumventing safety controls or human oversight — obstructing the oversight mechanisms the law elsewhere requires.
- Unlawful data collection for AI development, and breaches of intellectual property, cybersecurity and personal data protection rules.
- Concealing required information or falsifying labels, which ties back to the marking duty at Article 11.
Two of these repay a second reading. The manipulation prohibition is framed by intent and systematicity, which means an isolated synthetic image is not automatically caught but a campaign is. And the oversight-circumvention prohibition makes human oversight not merely a compliance control to be documented, but something it is unlawful to defeat — a structurally different move from treating oversight as a checklist item.
Chapter II: Three Tiers, and What Actually Triggers Each One
Articles 9 to 15 build the risk regime. The tiers themselves will look familiar to anyone who has read the EU AI Act, but the triggers do not line up, and the supervision method differs at each level.
| Tier | What puts a system here | How the state supervises it |
|---|---|---|
| High risk | Capable of causing significant damage to human life, health, fundamental rights, or national security | Pre-market conformity assessment for systems on a list issued by the Prime Minister; ongoing risk management; human oversight; registration on the national AI portal; periodic audits and audits triggered by signs of violation |
| Medium risk | Liable to confuse users about whether they are interacting with an AI system | Supervision through reporting, sample audits, and assessments by independent organisations; transparency disclosures to users |
| Low risk | Everything not meeting the above | Monitoring, with audit triggered by incidents, complaints, or where otherwise necessary for safety |
The medium tier is the interesting one, and it is where most comparative summaries go wrong by assuming the tiers are simply three magnitudes of the same harm. They are not. High risk is defined by severity of damage. Medium risk is defined by a specific failure of transparency — the user not knowing they are dealing with a machine. A system can be entirely harmless in its outputs and still sit in the medium tier because of how it presents itself. That is a categorical distinction, not a quantitative one, and it means classification is not a single sliding scale.
Providers self-classify before deployment, and notify medium- and high-risk systems through the single-window portal. Self-classification with state audit is a materially lighter front-end burden than mandatory third-party certification across the board — the certification requirement bites only for the subset of high-risk systems the Prime Minister names.
That Prime-Ministerial list is the single most consequential document the statute does not contain. Until it is published, no provider can say with certainty whether its high-risk system needs pre-market conformity certification or merely the general high-risk obligations. For a comparison of how differently jurisdictions draw this scoping line, see our survey of AI regulations around the world.
Article 11: Machine-Readable Marking, Plus a Deployer Duty
Article 11 does two separate things that are easy to collapse into one.
First, a provider obligation: providers must ensure that audio, image and video content generated by their AI systems is marked in a machine-readable format, in accordance with government regulations. This is a provenance requirement aimed at automated detection, not at a human reader — the same family of approach as content-credential and watermarking schemes.
Second, a deployer obligation: a deployer must clearly notify the public when it provides text, audio, image or video content that was generated or edited by an AI system, where that content could cause confusion about its authenticity. Note the scope difference. The provider marking duty covers audio, image and video. The deployer notification duty adds text, and is conditioned on a confusion test rather than applying universally.
The technical standard for the machine-readable mark is left to government regulation. That detail is not yet settled.
Chapter III: “National AI Sovereignty” — a Framing No Comparable Statute Uses
Articles 16 to 18 sit under a chapter heading that has no real counterpart in the other statutes in this corpus: Infrastructure development and assurance of national AI sovereignty. Neither the EU AI Act, nor Korea’s framework act, nor Italy’s national law has a chapter of that name.
What is inside it is industrial and strategic rather than regulatory: developing domestic computing capacity, building Vietnamese-language models, developing core technologies, and ensuring national capability to keep AI systems safe, secure and under control. The word “sovereignty” is doing genuine work — the concern is not only that AI systems behave safely, but that the state retains capability over the infrastructure they run on.
This matters for reading the law as a whole. Law 134/2025/QH15 is not purely a risk-control instrument. It is simultaneously a development statute, and Chapters III and IV are where that second purpose lives. Korea’s framework act makes a comparable pairing of promotion with regulation, though it organises it differently; see Korea’s AI Basic Act for how a neighbouring jurisdiction balances the same two goals.
Articles 21 and 22: A Sandbox That Can Relax the Statute, and an Off-Budget Fund
Two provisions in Chapter IV deserve separate treatment because of how unusual they are.
Article 21 — the regulatory sandbox. Controlled-testing regimes are now common. What is not common is the consequence Vietnam attaches to the results. Sandbox outcomes can serve as a basis for state agencies to recognise conformity results, or to grant exemptions from, reductions in, or adjustments to the relevant compliance obligations under this Law. A sandbox that can relax the statute’s own requirements, rather than merely offering supervised space to test inside them, is a materially stronger instrument than the usual model. It also puts significant discretion in the hands of the administering agencies, and the criteria for exercising that discretion are not in the statute.
Article 22 — the National AI Development Fund. An off-budget state financial fund, operating on a not-for-profit basis, capitalised from state budget allocations, donations and other lawful sources, and explicitly designed with flexible financial mechanisms that accept the risk inherent in innovation. The off-budget structure is the point: it lets the fund operate outside ordinary public-expenditure rules, and the risk-acceptance language is an unusual thing to write into primary legislation.
The Local-Presence Rule
This is the provision most likely to affect an organisation outside Vietnam, and it has two levels.
- A foreign provider of a high-risk AI system that is subject to mandatory pre-market conformity certification must have a commercial presence or an authorised representative in Vietnam.
- Other foreign providers of high-risk systems must maintain a lawful contact point in Vietnam.
The distinction is not cosmetic. A contact point is an addressable channel. A commercial presence or authorised representative is an entity or person within Vietnamese jurisdiction who can be held to the obligations — a substantially heavier commitment, and one with tax, corporate and liability consequences that sit well outside AI compliance. Which of the two applies depends on the Prime Minister’s list, which is why that list matters so much. The precise scope of the duty is among the items explicitly left to implementing guidance.
The Two Grace Periods
Article 35 gives systems already in operation when the law took effect a transition window, and it splits into two:
| Sector | Window | Deadline |
|---|---|---|
| Healthcare, education, finance | 18 months from 1 March 2026 | 1 September 2027 |
| All other sectors | 12 months from 1 March 2026 | 1 March 2027 |
Systems may continue to operate during the transition unless a competent state agency determines they are likely to cause serious damage, in which case the window does not protect them.
It is worth noticing which way the carve-out runs. Healthcare, education and finance are the sectors a risk-based regime usually treats most strictly. Here they get the longer runway. The drafters appear to have judged that these sectors have the most embedded legacy systems and the highest switching cost, so the extra six months is a concession to remediation difficulty, not a judgement that the risk is lower. The obligations when they arrive are the same.
Who Administers It
Chapter VII assigns the machinery. The Ministry of Science and Technology (MoST) is the lead agency, answerable to the Government for state management of AI nationwide. MoST also operates the National Single-Window AI Portal, through which high-risk systems are registered and through which serious incidents are reported. The Prime Minister issues the list of high-risk systems and specifies which of them require pre-market conformity certification.
A single-window portal that serves as both the registration channel and the incident-reporting channel is a sensible consolidation, and it is more centralised than the sectoral-regulator model several other jurisdictions use. The incident thresholds — what counts as serious enough to report, and how fast — are not in the statute.
What Is Still Missing
To be explicit about the gaps, because a compliance plan needs to know what it cannot yet plan for. Still pending in implementing decrees and government regulations as of this writing:
- The Prime Minister’s list of high-risk AI systems, and which entries on it require pre-market certification.
- The detailed risk-classification criteria that make self-classification operable.
- The technical standard for machine-readable marking under Article 11.
- Serious-incident thresholds and reporting timelines for the single-window portal.
- Conformity-assessment procedures and who may perform them.
- The precise scope of the local-presence and authorised-representative obligations.
Vietnam has published draft implementation documents, but until the decrees are in force the statute describes a regime rather than fully constituting one.
What This Means for Research Institutions
The research-administration angle here is genuine but narrow, and it is worth being precise rather than stretching it.
The 18-month carve-out is where universities land. Education and healthcare are two of the three sectors on the longer clock. A university already running AI tooling in teaching, assessment or student services in Vietnam, or an academic medical centre running clinical decision support, has until 1 September 2027 rather than 1 March 2027 — but it is on the clock either way, and the obligations at the end are identical. An institution with a Vietnamese campus, a joint programme or an affiliated hospital should be establishing which of its deployed systems would classify as high risk, and whether any of them are likely to appear on the Prime Minister’s list.
The local-presence rule reaches collaborations. An institution that provides AI tooling into Vietnam — a platform supplied to a partner university, a diagnostic model deployed at a collaborating hospital, a research instrument with an embedded model — may be a provider rather than a deployer under this law. If the system is high risk, that triggers at minimum a lawful contact point in Vietnam, and possibly a commercial presence or authorised representative. This is the kind of obligation that is easy to miss, because the institution’s legal and research-security functions are usually reading a collaboration agreement, not a foreign AI statute, and because the requirement attaches to the software rather than to the research relationship.
Beyond those two points, the law’s effect on ordinary sponsored-programme administration, IRB review or export-control practice is indirect at best, and we will not claim otherwise.
Reading It Against the Region
Vietnam has done something structurally different from its neighbours. Korea’s Basic Act pairs promotion with a lighter regulatory touch and a heavier emphasis on ecosystem-building. Singapore governs through detailed, influential, advisory frameworks — including its Model AI Governance Framework for agentic AI — and has deliberately not legislated a general AI statute. China regulates through a series of targeted binding measures aimed at specific technologies and services rather than one comprehensive law; see China’s AI regulation for that pattern.
Vietnam has passed one comprehensive binding statute, with a risk taxonomy, an enforcement chapter, extraterritorial reach through the local-presence rule, a sovereignty chapter, a development fund and a sandbox that can relax its own requirements. Whether that combination works is an empirical question that the implementing decrees and the first enforcement cycle will answer. What is already settled is that the regional map now has a binding general AI law on it, and any comparative analysis that omits Vietnam is describing a region that no longer exists.
Frequently Asked Questions
When did Vietnam’s AI Law take effect?
1 March 2026. The National Assembly passed it on 10 December 2025, by 429 votes of the 434 deputies present.
Does the law apply to organisations outside Vietnam?
Yes, in effect. Foreign providers of high-risk AI systems must maintain a lawful contact point in Vietnam, and those whose systems require mandatory pre-market conformity certification must have a commercial presence or an authorised representative there.
How many risk tiers does the law use?
Three: high, medium and low. High risk turns on the severity of potential damage to life, health, rights or national security. Medium risk turns on whether users may be confused about whether they are interacting with an AI system. Low risk is the residual category.
What is the deadline for systems already in operation?
1 March 2027 for most sectors, and 1 September 2027 for healthcare, education and finance. Systems may operate during the transition unless a state agency determines they are likely to cause serious damage.
Is the law fully operational yet?
Not entirely. The statute is in force, but the Prime Minister’s list of high-risk systems, the detailed classification criteria, the marking standard, the incident thresholds and the conformity-assessment procedures are all left to implementing decrees and government regulations that are still being finalised.
Is this really Southeast Asia’s first AI law?
It is the first comprehensive, standalone, binding AI statute in the region. Other Southeast Asian states have AI strategies, guidelines and sectoral rules — Singapore’s model frameworks are the best known — but those are advisory instruments or narrower in scope, not general binding AI legislation.
Sources
- Law No. 134/2025/QH15 on Artificial Intelligence, dated 10 December 2025 — English text, LuatVietnam and Thu Vien Phap Luat.
- Viet Nam Government Portal (baochinhphu.vn), “Viet Nam’s Law on Artificial Intelligence”.
- Baker McKenzie, “Vietnam: Artificial Intelligence Law — foundation and outlook” (February 2026).
- Duane Morris Vietnam, “Vietnam: The First Law on Artificial Intelligence — What You Must Know” (March 2026).
- VnExpress International, National Assembly passage report, December 2025.







