- 1 What Is a Vector Database? The Foundation of Semantic AI Search
- 2 What Is a Recommendation System? How TikTok and Shopee Suggest Products
- 3 What is an AI Agent? How Autonomous AI Agents Automate Complex Work
- 4 What Is Deepfake? How to Detect and Protect Yourself
- 5 What is Prompt Engineering? The Art of Giving AI Effective Instructions
- 6 What Is Fine-Tuning? Customizing AI Models for Enterprise Use
- 7 What is RAG? Retrieval-Augmented Generation — when AI knows how to look things up
- 8 What is Vietnam's AI Law? The Legal Framework for Artificial Intelligence (Updated 2026)
The years 2025–2026 mark the most significant legal turning point for artificial intelligence in Vietnam: for the first time, a dedicated AI statute has been enacted, alongside a wave of related legislation spanning personal data protection to the digital industry. For businesses and developers building AI products, understanding this legal framework is no longer a competitive advantage — it is a compliance requirement.
Does Vietnam have its own AI law?
The short answer: Yes — and the framework was substantially completed in 2025–2026.
On 10 December 2025, the Vietnamese National Assembly passed Law on Artificial Intelligence No. 134/2025/QH15 — the country's first standalone AI statute, effective from 1 March 2026. This is not a minor amendment tucked inside a broader piece of legislation; it is a dedicated law whose entire content addresses AI, from definitions and risk classification to legal liability and deployer obligations.
In parallel, Law on Digital Technology Industry No. 71/2025/QH15 (effective 1 January 2026) devotes a dedicated chapter to AI systems within the broader context of the digital industry — including semiconductors and digital assets. The two laws are complementary, not mutually exclusive; together they form the legal pillars for AI in Vietnam.
Beyond these two core statutes, the AI legal framework is further supported by: Law on Personal Data Protection No. 91/2025/QH15 (effective 1 January 2026), Law on Cybersecurity No. 24/2018/QH14, Law on Electronic Transactions No. 20/2023/QH15, and policy instruments such as the National AI Strategy to 2030 (Decision 127/QĐ-TTg).
Need data solutions for your business?
AlgoData has helped businesses with data engineering, analytics & AI since 2019.

Two parallel AI laws — What is the key distinction?
Vietnam now has two legislative instruments that directly regulate AI, and the distinction between them matters for anyone building or deploying AI systems:
Law 71/2025/QH15 — Law on Digital Technology Industry is a multi-sector statute. Its AI chapter defines "artificial intelligence system," establishes principles for development and use, sets out AI product labelling rules, and identifies the high-risk category. The definition in Article 3(9) takes a technical approach:
"A machine-based system designed to operate with varying degrees of autonomy, capable of adapting after deployment to achieve explicit or implicit objectives"
Source: Law on Digital Technology Industry No. 71/2025/QH15, Article 3(9)
Law 134/2025/QH15 — Law on Artificial Intelligence is a specialist statute. Its entire content focuses on AI, from a broader definitional framework to a three-tier risk classification system, liability rules, and foundational principles. Article 2 defines:
"Artificial intelligence is the electronic performance of human intellectual capacities, including learning, reasoning, perception, judgment, and understanding of natural language."
Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 2
As a matter of legal principle, the specialist law takes precedence when the two instruments contain differing provisions on the same issue. However, because this is still a very new area of law, the specific application in any given scenario should be confirmed by a specialist lawyer.
The foundational principles of AI Law 134/2025/QH15
Article 4 of Law 134/2025/QH15 establishes four legally binding foundational principles:
Clause 1 — Human-centricity:
"To place human beings at the centre; to safeguard human rights, privacy, national interests, public interests, and national security; to comply with the Constitution and the law."
Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 4(1)
Clause 2 — AI serves humans, not a substitute for human authority:
"Artificial intelligence serves human beings and does not replace human authority and responsibility. To ensure the maintenance of human control and the ability to intervene in all decisions and actions of artificial intelligence systems; system safety, data security, and information security; and the auditability and oversight of AI system development and operation."
Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 4(2)
Clause 3 — Fairness, transparency, and ethics:
"To ensure fairness, transparency, freedom from bias, non-discrimination, and freedom from harm to individuals or society; to comply with ethical standards and Vietnamese cultural values; and to implement accountability for the decisions and consequences of artificial intelligence systems."
Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 4(3)
Clause 4 — Green and sustainable AI:
"To promote the development of green, inclusive, and sustainable artificial intelligence; to encourage the development and application of artificial intelligence technologies that use energy efficiently, conserve resources, and reduce negative environmental impacts."
Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 4(4)
Clause 4 is particularly noteworthy: Vietnam is among the few countries to codify green AI development requirements directly within its foundational principles — a reflection of the sustainability agenda at a time when AI is consuming ever greater amounts of energy.

Risk classification and labelling obligations
The risk classification system
Law 134/2025/QH15 classifies AI systems into three risk tiers: low, medium, and high. In the spirit of Article 9, high-risk AI systems are those that could cause significant harm to human life, health, rights, and legitimate interests — typical examples include AI used in healthcare, the justice system, credit assessment, or mass surveillance.
Law 71/2025/QH15 (Article 43) also identifies the high-risk category as systems:
"Capable of posing risks or causing serious harm to human health, human rights, civil rights, public interests, and public order and safety"
Source: Law on Digital Technology Industry No. 71/2025/QH15, Article 43
Labelling and notification obligations (Article 44, Law 71/2025/QH15)
Two important obligations apply from the moment an AI system is deployed:
First — AI interaction notification:
"An artificial intelligence system that interacts directly with human beings must notify users that they are interacting with an artificial intelligence system, unless the user is clearly already aware of this"
Source: Law on Digital Technology Industry No. 71/2025/QH15, Article 44(1)
Second — AI product labelling:
"Digital technology products on the List of AI-generated digital technology products must carry an identifier enabling users or machines to recognise them as AI-generated"
Source: Law on Digital Technology Industry No. 71/2025/QH15, Article 44(2)
This means chatbots, virtual assistants, AI image generators, and AI writing tools are all subject to these transparency requirements. The specific product list subject to mandatory labelling is to be defined in detail by the responsible Ministry.
Liability for damages — Strict liability
A particularly significant feature of Law 134/2025/QH15 is its strict-liability mechanism. Under Article 29(2):
"Where a high-risk artificial intelligence system has been managed and operated in accordance with regulations but harm still arises, the deploying party shall be liable to provide compensation"
Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 29(2)
Unlike ordinary civil liability, which requires proof of fault, this is strict liability: a company deploying a high-risk AI system bears the obligation to compensate even when it has fully complied with all applicable procedures. This creates strong incentives to invest in rigorous testing, monitoring, and documentation of AI systems before launch.
Timeline of key legislation
| Instrument | Reference | Effective date | Key provisions |
|---|---|---|---|
| Law on Cybersecurity | 24/2018/QH14 | 1 Jan 2019 | Requires localised storage of Vietnamese user data; applies to all digital services that collect data |
| National AI Strategy to 2030 | Decision 127/QĐ-TTg | 26 Jan 2021 | Policy direction for national AI development and application (not a binding statute) |
| Law on Electronic Transactions | 20/2023/QH15 | 1 Jul 2024 | Legal foundation for digital transactions, electronic contracts, and digital signatures |
| 9 Principles for Responsible AI | Decision 1290/QĐ-BKHCN | 11 Jun 2024 | Advisory guidance (non-binding) on ethical AI development |
| Law on Digital Technology Industry | 71/2025/QH15 | 1 Jan 2026 | Defines AI systems, development principles, high-risk classification, labelling and AI interaction notification obligations |
| Law on Personal Data Protection | 91/2025/QH15 | 1 Jan 2026 | Standalone personal data protection statute replacing Decree 13/2023; applies to data processing within AI systems |
| Law on Artificial Intelligence | 134/2025/QH15 | 1 Mar 2026 | First dedicated AI statute: AI definition, 4 foundational principles, three-tier risk classification, liability for damages, oversight |
| National AI Ethics Framework | Circular 05/2026/TT-BKHCN | 10 Mar 2026 | Applies to state agencies and public services; 4 core principles: safety, human rights, sustainable development, responsible innovation |
Personal data protection in the AI context
AI systems almost invariably process personal data — from facial recognition to user behaviour analysis. This is where AI law and data protection law intersect.
Law 91/2025/QH15 (Law on Personal Data Protection, effective 1 January 2026) establishes a comprehensive framework for the collection and processing of personal data, including within AI systems. It inherits and upgrades the principles from Decree 13/2023/NĐ-CP (which expired on 1 January 2026). For more on the intersection of AI and privacy, see the article on What is Sentiment Analysis and how user data analysis systems operate.
In addition, Law on Cybersecurity No. 24/2018/QH14 (Article 26(3)) imposes data localisation requirements that directly affect AI infrastructure:
"Domestic and foreign enterprises providing services over telecommunications networks, the Internet, and value-added services in cyberspace in Vietnam that engage in the collection, exploitation, analysis, and processing of personal data, user relationship data, and data generated by users in Vietnam shall store such data in Vietnam in accordance with Government regulations."
Source: Law on Cybersecurity No. 24/2018/QH14, Article 26(3)
This means AI companies — including foreign entities — that provide services in Vietnam and process Vietnamese user data must store that data in Vietnam. This requirement directly affects system architecture decisions, particularly for cloud-based AI models.
Policy and ethics documents — Non-binding but significant
Alongside the legally binding statutes, several important guidance documents are non-binding but nonetheless reflect the direction of regulation:
Decision 1290/QĐ-BKHCN (11 June 2024), issued by the Ministry of Science, Technology and Innovation, sets out 9 principles for responsible AI development: a spirit of collaboration and innovation, transparency, controllability, safety, security, privacy, respect for human rights and dignity, user support, and accountability. This is advisory guidance — it carries no mandatory legal force.
Circular 05/2026/TT-BKHCN (effective 10 March 2026) promulgates the National AI Ethics Framework, applicable to state agencies and public services, built around 4 core principles: safety, human rights, sustainable development, and responsible innovation.

A brief comparison with the EU AI Act
For international context, it is worth comparing Vietnam's framework with the EU AI Act — the European Union's AI legislation (officially in force from 1 August 2024, fully applicable from 2 August 2026). This is a foreign law that does not apply in Vietnam, but it is relevant for Vietnamese companies operating in the EU or providing services to EU users. Full details are available at the official EU AI Act website.
| Criterion | Vietnam AI Law (134/2025/QH15) | EU AI Act |
|---|---|---|
| Effective date | 1 Mar 2026 | 1 Aug 2024 (fully applicable Aug 2026) |
| Risk classification | 3 tiers: low / medium / high | 4 tiers: unacceptable / high / limited / minimal |
| High-risk AI liability | Strict liability (no proof of fault required) | Liability handled through a separate AI Liability Directive |
| Absolute prohibitions | No explicit list of absolute prohibitions yet (pending implementing regulations) | Prohibits certain applications (social scoring, real-time biometric identification in public spaces, etc.) |
| Territorial scope | Applies to activities in Vietnam | Applies to the EU market, regardless of where the provider is based |
A notable similarity: both frameworks are human-centric, require transparency, and mandate risk management across the AI system lifecycle. A key difference: the EU AI Act is more detailed regarding prohibited application lists and specific technical requirements, while Vietnam's law is still in its early implementation phase — many detailed implementing decrees may not yet have been issued.
For further technical context, see the articles on What is Generative AI and What is an AI Agent.
Key compliance considerations for deploying AI in Vietnam
Based on the above legal framework, businesses and developers deploying AI should keep the following practical points in mind:
1. Assess the risk tier from the design stage. Law 134/2025/QH15 defines three tiers — determining which tier your system falls into will determine the extent of your legal obligations.
2. Comply with transparency obligations. Chatbots, virtual assistants, and AI tools that interact with users must provide clear disclosure. AI-generated content (images, text, video) must carry an identifying marker.
3. Data infrastructure must be in Vietnam. If you process Vietnamese user data, the domestic storage requirement under the Cybersecurity Law applies to foreign companies as well.
4. Prepare for strict liability. High-risk AI systems require thorough documentation of management processes, testing, and monitoring — not to avoid liability (since it is strict), but to manage risk and insurance exposure.
5. Monitor implementing regulations. Laws 71 and 134 are both very new; many detailed implementing decrees may not yet have been issued. The list of AI products subject to mandatory labelling and the specific criteria for risk classification are details that warrant close attention.
This information is for general reference only and does not constitute legal advice; legislation may change — please consult authoritative sources and refer to the updates section.
Conclusion: Vietnam has built a relatively comprehensive AI legal framework in under two years — from national strategy to a dedicated statute. Law on Artificial Intelligence No. 134/2025/QH15 lays an important foundation with clear definitions, a three-tier risk classification system, and a strict-liability mechanism. Businesses building and deploying AI in Vietnam need to understand the two main pillars — Law 134 and Law 71 — alongside the accompanying data protection and cybersecurity requirements. As detailed implementing regulations are still being finalised, continuous monitoring and specialist legal advice remain essential.
Sources
- Law on Artificial Intelligence No. 134/2025/QH15 — Official Gazette of the Government
- Vietnam officially enacts the Law on Artificial Intelligence (AI) — Government News
- Key provisions of the Law on Artificial Intelligence — Policy Development Portal (Government)
- Law on Digital Technology Industry No. 71/2025/QH15 — vbpl.vn (National Legal Database)
- Law on Personal Data Protection No. 91/2025/QH15 — Official Gazette of the Government
- Circular 05/2026/TT-BKHCN — National AI Ethics Framework — vanban.chinhphu.vn
- Law on Cybersecurity No. 24/2018/QH14 — tulieuvankien.dangcongsan.vn
- Decision 127/QĐ-TTg — National AI Strategy to 2030 — vanban.chinhphu.vn

