什么是越南AI法律?人工智能监管框架(2026年更新)
Trí tuệ nhân tạo

什么是越南AI法律?人工智能监管框架(2026年更新)

2026年越南AI监管框架全览:第134/2025/QH15号法律、第71/2025号法律、个人数据保护、风险分级与AI系统标注义务。

系列文章: Trí tuệ nhân tạo
  1. 1 向量数据库是什么?语义 AI 搜索的基础
  2. 2 推荐系统是什么?TikTok 与 Shopee 如何推荐产品
  3. 3 什么是AI Agent?智能体如何自动化完成复杂任务?
  4. 4 Deepfake 是什么?如何检测和保护自己
  5. 5 什么是Prompt Engineering?高效指令AI的艺术
  6. 6 Fine-tuning 是什么?为企业定制 AI 模型
  7. 7 什么是RAG?Retrieval-Augmented Generation — 让AI学会查阅文档
  8. 8 什么是越南AI法律?人工智能监管框架(2026年更新)
✦ 快速摘要
2026年越南AI监管框架全览:第134/2025/QH15号法律、第71/2025号法律、个人数据保护、风险分级与AI系统标注义务。
这篇文章怎么样?

2025—2026年标志着越南人工智能领域最重大的法制转折:历史上首次颁布专门针对AI的立法,同时配套发布了从数据保护到数字产业的一系列相关文件。对于正在构建AI产品的企业和开发者而言,深入理解这一监管框架已不再是竞争优势,而是合规必须。

越南是否已有专属AI法律?

简短回答:有——而且这一法律框架在2025—2026年间已得到显著完善。

2025年12月10日,越南国会通过了第134/2025/QH15号《人工智能法》——这是全国首部专门针对AI的法律,自2026年3月1日起施行。这不是在某部更大法律中的细枝末节修订,而是一部完全专注于AI的独立法律,涵盖定义、风险分类、法律责任以及部署方义务等各方面内容。

与此同时,第71/2025/QH15号《数字技术产业法》(自2026年1月1日起施行)在更广泛的数字产业背景下——包括半导体和数字资产——专设一章对AI系统作出规定。两部法律并行不悖,共同构成越南AI法律的两大支柱。

除这两部核心法律外,AI监管框架还辅以:第91/2025/QH15号《个人数据保护法》(自2026年1月1日起施行)、第24/2018/QH14号《网络安全法》第20/2023/QH15号《电子交易法》,以及《2030年国家AI战略》(第127/QĐ-TTg号决定)等政策文件。

两部并行AI法律——需要区分什么?

越南目前有两部法律直接规制AI,对于任何构建产品或部署AI系统的人而言,了解两者之间的差异至关重要:

**第71/2025/QH15号——《数字技术产业法》**是一部综合性法律。该法AI章节定义了"人工智能系统",确立了开发和使用原则,规定了AI产品标注要求,并对高风险类别进行了分类。第3条第9款的定义从技术角度切入:

"基于机器的系统,设计为以不同程度的自主性运行,能够在部署后进行自适应,以实现明确或隐含的目标"

来源:第71/2025/QH15号《数字技术产业法》第3条第9款

**第134/2025/QH15号——《人工智能法》**是专门立法。全部内容聚焦于AI,从更宏观的定义到三级风险分类体系、赔偿责任规则,乃至基本原则。第2条将其定义为:

"人工智能是对人类智力能力的电子化实现,包括学习、推理、感知、判断和自然语言理解。"

来源:第134/2025/QH15号《人工智能法》第2条

根据法律原则,当两部法律对同一问题有不同规定时,专门法优先适用。但由于这仍是一个极为新兴的法律领域,具体情形的适用仍需专业律师确认。

第134/2025/QH15号《人工智能法》的基本原则

第134/2025/QH15号法律第4条确立了四项具有法律约束力的基本原则:

第1款——以人为本:

"以人为本;保障人权、隐私权、国家利益、公共利益和国家安全;遵守宪法和法律。"

来源:第134/2025/QH15号《人工智能法》第4条第1款

第2款——AI服务于人,不替代人的权威:

"人工智能服务于人,不替代人的权威和责任。确保保持人对人工智能系统一切决策和行为的控制和干预能力;保障系统安全、数据安全和信息安全;确保对人工智能系统开发和运行过程可检查和可监督。"

来源:第134/2025/QH15号《人工智能法》第4条第2款

第3款——公平、透明、道德:

"确保公平、透明、无偏见、无歧视,且不对人或社会造成伤害;遵守越南道德规范和文化价值观;对人工智能系统的决策及其后果承担可解释责任。"

来源:第134/2025/QH15号《人工智能法》第4条第3款

第4款——绿色、可持续AI:

"促进绿色、包容和可持续人工智能的发展;鼓励朝着高效利用能源、节约资源、减少对环境负面影响方向开发和应用人工智能技术。"

来源:第134/2025/QH15号《人工智能法》第4条第4款

第4款尤为值得关注:越南是少数几个在基本原则中明确将绿色AI发展要求写入法律的国家,反映出在AI能耗持续攀升背景下推动可持续发展的战略取向。

风险分类与标注义务

风险分类体系

第134/2025/QH15号法律将AI系统分为低、中、高三个风险等级。根据第9条精神,高风险AI系统是指可能对生命健康及合法权益造成重大损害的系统——典型例子包括医疗、司法、信贷或大规模监控领域的AI。

第71/2025/QH15号法律(第43条)亦将高风险类别界定为:

"可能对人体健康、人权、公民权利、公共利益和社会安全秩序造成严重风险或损害的系统"

来源:第71/2025/QH15号《数字技术产业法》第43条

标注与告知义务(第71/2025/QH15号第44条)

AI系统部署之时即须遵守两项重要义务:

第一——AI交互告知:

"与人直接交互的人工智能系统必须通知用户其正在与人工智能系统交互,除非用户显然已知晓"

来源:第71/2025/QH15号《数字技术产业法》第44条第1款

第二——AI产品标注:

"属于由人工智能生成的数字技术产品目录的数字技术产品,必须带有可供用户或机器识别的标识"

来源:第71/2025/QH15号《数字技术产业法》第44条第2款

这意味着:聊天机器人、虚拟助手、AI图像生成工具和内容写作工具均须遵守上述透明度要求。具体须强制标注的产品目录由主管部门另行详细规定。

赔偿责任——严格责任

第134/2025/QH15号法律的一大亮点是严格责任机制。根据第29条第2款:

"高风险人工智能系统依规管理和运营,但仍造成损害的,部署方须承担赔偿责任"

来源:第134/2025/QH15号《人工智能法》第29条第2款

与通常需要证明过错的民事责任不同,这是严格责任:部署高风险AI的企业即便已完全遵循合规流程,仍须承担赔偿责任。这给AI系统上线前的测试、监控与文档化工作带来了强大的合规压力。

主要法律文件时间线

文件名称 编号 生效日期 主要内容
网络安全法 24/2018/QH14 2019年1月1日 要求在越南境内存储越南用户数据;适用于所有收集数据的数字服务
2030年国家AI战略 QĐ 127/QĐ-TTg 2021年1月26日 国家AI发展和应用政策方向(非约束性法律)
电子交易法 20/2023/QH15 2024年7月1日 数字交易、电子合同、数字签名的法律基础
九项负责任AI原则 QĐ 1290/QĐ-BKHCN 2024年6月11日 关于道德AI开发的建议性指南(非强制性)
数字技术产业法 71/2025/QH15 2026年1月1日 定义AI系统、开发原则、高风险分类、标注义务及AI交互告知
个人数据保护法 91/2025/QH15 2026年1月1日 独立个人数据保护法,取代第13/2023号政令;适用于AI系统中的数据处理
人工智能法 134/2025/QH15 2026年3月1日 首部专门AI法律:定义AI、四项基本原则、三级风险分类、赔偿责任、监督
国家AI伦理框架 TT 05/2026/TT-BKHCN 2026年3月10日 适用于政府机关和公共服务;四项核心原则:安全、人权、可持续发展、负责任创新

数据保护与AI的交叉地带

AI系统几乎必然涉及个人数据处理——从人脸识别到用户行为分析。这正是AI法律与数据保护法律的交叉领域。

第91/2025/QH15号法律(《个人数据保护法》,2026年1月1日起施行)为个人数据的收集和处理——包括AI系统中的数据处理——建立了全面的法律框架。该法继承并升级了已于2026年1月1日失效的第13/2023/NĐ-CP号政令中的相关原则。如需进一步了解AI与隐私的交叉领域,可参阅什么是情感分析一文,了解用户数据分析系统的运作方式。

此外,第24/2018/QH14号《网络安全法》(第26条第3款)提出了直接影响AI基础设施的数据本地化要求:

"在越南提供电信网络、互联网及网络增值服务的境内外企业,凡在越南从事收集、开采、分析和处理越南用户个人信息数据、用户关系数据及越南用户生成数据活动的,须按政府规定在越南境内存储上述数据。"

来源:第24/2018/QH14号《网络安全法》第26条第3款

这意味着,在越南提供服务并处理越南用户数据的AI企业——包括外国企业——须在越南境内存储相关数据。这一要求直接影响系统架构决策,对云端AI模型尤为如此。

政策与伦理文件——非约束性但具有重要意义

除具有法律约束力的法律外,若干重要的指导性文件虽不具强制性,却反映了监管趋势:

**第1290/QĐ-BKHCN号决定(2024年6月11日)**由科学技术与创新部发布,提出负责任AI开发的九项原则,包括:合作创新精神、透明性、可控性、安全性、保密性、隐私保护、尊重人权和人的尊严、用户支持以及可问责性。这是建议性指南,不具强制法律约束力。

第05/2026/TT-BKHCN号通知(自2026年3月10日起施行)颁布了国家AI伦理框架,适用于政府机关和公共服务,确立了四项核心原则:安全、人权、可持续发展和负责任创新。

与欧盟AI法案的简要对比

为提供国际参照,有必要与欧盟AI法案(EU AI Act)进行比较——该法案于2024年8月1日正式生效,将于2026年8月2日全面适用。这是一部域外法律,不在越南境内直接适用,但对在欧盟经营或向欧盟用户提供服务的越南企业有重要影响。详情可参阅欧盟官方网站

比较维度 越南AI法律(134/2025/QH15) 欧盟AI法案
生效日期 2026年3月1日 2024年8月1日(2026年8月全面适用)
风险分类 3级:低 / 中 / 高 4级:不可接受 / 高 / 有限 / 最低
高风险AI赔偿责任 严格责任(无需证明过错) 责任机制通过单独的《AI责任指令》处理
绝对禁止 尚无明确列出的绝对禁止目录(等待指导性文件) 禁止特定应用(社会评分、公共场所实时生物特征识别等)
地域范围 适用于在越南境内的活动 适用于欧盟市场,无论提供者位于何处

值得关注的共同点:两者均以人为本,要求透明并在系统全生命周期内进行风险管控。主要差异在于:欧盟AI法案对禁止应用清单和具体技术要求规定更为详尽,而越南法律目前仍处于早期实施阶段——许多详细的实施细则可能尚未同步发布。

如需进一步了解技术背景,可参阅什么是生成式AI什么是AI Agent

在越南部署AI的注意事项

基于上述监管框架,企业和开发者在越南部署AI时需注意以下实务要点:

1. 在设计阶段即评估风险等级。 第134/2025/QH15号法律划分了三个等级——确定您的系统属于哪一级,将决定法律义务的程度。

2. 遵守透明度义务。 聊天机器人、虚拟助手和与用户交互的AI工具必须明确告知。AI生成的内容(图像、文本、视频)需带有识别标识。

3. 数据基础设施须在越南境内。 若处理越南用户数据,《网络安全法》规定的境内存储要求同样适用于外国企业。

4. 为严格责任做好准备。 高风险AI系统需要对管理、测试和监督流程进行详细文档化——这不是为了规避责任(因为是严格责任),而是为了风险管理和保险。

5. 持续追踪实施细则。 第71号和第134号法律均属全新法规;许多详细的实施细则可能尚未同步发布。AI产品强制标注目录、具体风险分类标准——这些细节需要密切关注。

免责声明

本文内容仅供参考,不构成法律意见;相关法律可能发生变化——请以权威来源为准,并参阅更新章节。

结论: 越南在不到两年时间内建立了一套相对完善的AI监管框架——从国家战略到专门立法。第134/2025/QH15号《人工智能法》以清晰的定义、三级风险分类和严格责任机制奠定了重要基础。在越南构建和部署AI的企业需充分掌握两大核心支柱——第134号法律和第71号法律——以及配套的数据保护和网络安全要求。在详细实施细则尚在完善的阶段,持续跟踪动态并咨询专业法律意见是必要之举。

参考资料

常见问题

常见问题Q&A
越南是否已有专门的AI法律?
是的。第134/2025/QH15号《人工智能法》于2025年12月10日经国会通过,自2026年3月1日起施行——这是越南首部专门针对AI的法律。与此同时,第71/2025/QH15号《数字技术产业法》(自2026年1月1日起施行)也专设一章对AI系统作出规定。
依据越南法律,哪些AI系统被认定为高风险?
根据第134/2025/QH15号法律,AI系统分为低、中、高三个风险等级。高风险是指可能对人的生命健康、合法权益造成重大损害的系统(第9条精神),典型例子包括医疗、司法、信贷或大规模监控领域的AI。第71/2025/QH15号法律(第43条)亦将高风险组定义为可能对公民健康、人权、公共利益和社会安全秩序造成严重损害的系统。
AI聊天机器人是否必须告知用户?
是的。第71/2025/QH15号《数字技术产业法》(第44条)规定,与人直接交互的AI系统必须通知用户其正在与AI交互,除非用户显然已知晓。此外,由AI生成的产品(图像、视频、文本等)必须带有可供用户或机器识别的标识。
如果AI造成损害但已依规运营,谁来承担责任?
根据第134/2025/QH15号法律第29条第2款,即使高风险AI系统已按规定管理和运营,若仍造成损害,部署方仍须承担赔偿责任。这是严格责任机制(strict liability)——无需证明部署方存在过错。
第134/2025/QH15号《人工智能法》与第71/2025/QH15号《数字技术产业法》有何区别?
第71/2025/QH15号是涵盖半导体、数字资产和AI的综合性法律,其中AI章节只是整体的一部分。第134/2025/QH15号则是专门法,全部内容集中于AI。根据法律原则,当两部法律对同一问题有不同规定时,专门法优先适用,但具体适用情形仍需专业律师确认。

The years 2025–2026 mark the most significant legal turning point for artificial intelligence in Vietnam: for the first time, a dedicated AI statute has been enacted, alongside a wave of related legislation spanning personal data protection to the digital industry. For businesses and developers building AI products, understanding this legal framework is no longer a competitive advantage — it is a compliance requirement.

Does Vietnam have its own AI law?

The short answer: Yes — and the framework was substantially completed in 2025–2026.

On 10 December 2025, the Vietnamese National Assembly passed Law on Artificial Intelligence No. 134/2025/QH15 — the country's first standalone AI statute, effective from 1 March 2026. This is not a minor amendment tucked inside a broader piece of legislation; it is a dedicated law whose entire content addresses AI, from definitions and risk classification to legal liability and deployer obligations.

In parallel, Law on Digital Technology Industry No. 71/2025/QH15 (effective 1 January 2026) devotes a dedicated chapter to AI systems within the broader context of the digital industry — including semiconductors and digital assets. The two laws are complementary, not mutually exclusive; together they form the legal pillars for AI in Vietnam.

Beyond these two core statutes, the AI legal framework is further supported by: Law on Personal Data Protection No. 91/2025/QH15 (effective 1 January 2026), Law on Cybersecurity No. 24/2018/QH14, Law on Electronic Transactions No. 20/2023/QH15, and policy instruments such as the National AI Strategy to 2030 (Decision 127/QĐ-TTg).

Two parallel AI laws — What is the key distinction?

Vietnam now has two legislative instruments that directly regulate AI, and the distinction between them matters for anyone building or deploying AI systems:

Law 71/2025/QH15 — Law on Digital Technology Industry is a multi-sector statute. Its AI chapter defines "artificial intelligence system," establishes principles for development and use, sets out AI product labelling rules, and identifies the high-risk category. The definition in Article 3(9) takes a technical approach:

"A machine-based system designed to operate with varying degrees of autonomy, capable of adapting after deployment to achieve explicit or implicit objectives"

Source: Law on Digital Technology Industry No. 71/2025/QH15, Article 3(9)

Law 134/2025/QH15 — Law on Artificial Intelligence is a specialist statute. Its entire content focuses on AI, from a broader definitional framework to a three-tier risk classification system, liability rules, and foundational principles. Article 2 defines:

"Artificial intelligence is the electronic performance of human intellectual capacities, including learning, reasoning, perception, judgment, and understanding of natural language."

Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 2

As a matter of legal principle, the specialist law takes precedence when the two instruments contain differing provisions on the same issue. However, because this is still a very new area of law, the specific application in any given scenario should be confirmed by a specialist lawyer.

The foundational principles of AI Law 134/2025/QH15

Article 4 of Law 134/2025/QH15 establishes four legally binding foundational principles:

Clause 1 — Human-centricity:

"To place human beings at the centre; to safeguard human rights, privacy, national interests, public interests, and national security; to comply with the Constitution and the law."

Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 4(1)

Clause 2 — AI serves humans, not a substitute for human authority:

"Artificial intelligence serves human beings and does not replace human authority and responsibility. To ensure the maintenance of human control and the ability to intervene in all decisions and actions of artificial intelligence systems; system safety, data security, and information security; and the auditability and oversight of AI system development and operation."

Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 4(2)

Clause 3 — Fairness, transparency, and ethics:

"To ensure fairness, transparency, freedom from bias, non-discrimination, and freedom from harm to individuals or society; to comply with ethical standards and Vietnamese cultural values; and to implement accountability for the decisions and consequences of artificial intelligence systems."

Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 4(3)

Clause 4 — Green and sustainable AI:

"To promote the development of green, inclusive, and sustainable artificial intelligence; to encourage the development and application of artificial intelligence technologies that use energy efficiently, conserve resources, and reduce negative environmental impacts."

Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 4(4)

Clause 4 is particularly noteworthy: Vietnam is among the few countries to codify green AI development requirements directly within its foundational principles — a reflection of the sustainability agenda at a time when AI is consuming ever greater amounts of energy.

Risk classification and labelling obligations

The risk classification system

Law 134/2025/QH15 classifies AI systems into three risk tiers: low, medium, and high. In the spirit of Article 9, high-risk AI systems are those that could cause significant harm to human life, health, rights, and legitimate interests — typical examples include AI used in healthcare, the justice system, credit assessment, or mass surveillance.

Law 71/2025/QH15 (Article 43) also identifies the high-risk category as systems:

"Capable of posing risks or causing serious harm to human health, human rights, civil rights, public interests, and public order and safety"

Source: Law on Digital Technology Industry No. 71/2025/QH15, Article 43

Labelling and notification obligations (Article 44, Law 71/2025/QH15)

Two important obligations apply from the moment an AI system is deployed:

First — AI interaction notification:

"An artificial intelligence system that interacts directly with human beings must notify users that they are interacting with an artificial intelligence system, unless the user is clearly already aware of this"

Source: Law on Digital Technology Industry No. 71/2025/QH15, Article 44(1)

Second — AI product labelling:

"Digital technology products on the List of AI-generated digital technology products must carry an identifier enabling users or machines to recognise them as AI-generated"

Source: Law on Digital Technology Industry No. 71/2025/QH15, Article 44(2)

This means chatbots, virtual assistants, AI image generators, and AI writing tools are all subject to these transparency requirements. The specific product list subject to mandatory labelling is to be defined in detail by the responsible Ministry.

Liability for damages — Strict liability

A particularly significant feature of Law 134/2025/QH15 is its strict-liability mechanism. Under Article 29(2):

"Where a high-risk artificial intelligence system has been managed and operated in accordance with regulations but harm still arises, the deploying party shall be liable to provide compensation"

Source: Law on Artificial Intelligence No. 134/2025/QH15, Article 29(2)

Unlike ordinary civil liability, which requires proof of fault, this is strict liability: a company deploying a high-risk AI system bears the obligation to compensate even when it has fully complied with all applicable procedures. This creates strong incentives to invest in rigorous testing, monitoring, and documentation of AI systems before launch.

Timeline of key legislation

Instrument Reference Effective date Key provisions
Law on Cybersecurity 24/2018/QH14 1 Jan 2019 Requires localised storage of Vietnamese user data; applies to all digital services that collect data
National AI Strategy to 2030 Decision 127/QĐ-TTg 26 Jan 2021 Policy direction for national AI development and application (not a binding statute)
Law on Electronic Transactions 20/2023/QH15 1 Jul 2024 Legal foundation for digital transactions, electronic contracts, and digital signatures
9 Principles for Responsible AI Decision 1290/QĐ-BKHCN 11 Jun 2024 Advisory guidance (non-binding) on ethical AI development
Law on Digital Technology Industry 71/2025/QH15 1 Jan 2026 Defines AI systems, development principles, high-risk classification, labelling and AI interaction notification obligations
Law on Personal Data Protection 91/2025/QH15 1 Jan 2026 Standalone personal data protection statute replacing Decree 13/2023; applies to data processing within AI systems
Law on Artificial Intelligence 134/2025/QH15 1 Mar 2026 First dedicated AI statute: AI definition, 4 foundational principles, three-tier risk classification, liability for damages, oversight
National AI Ethics Framework Circular 05/2026/TT-BKHCN 10 Mar 2026 Applies to state agencies and public services; 4 core principles: safety, human rights, sustainable development, responsible innovation

Personal data protection in the AI context

AI systems almost invariably process personal data — from facial recognition to user behaviour analysis. This is where AI law and data protection law intersect.

Law 91/2025/QH15 (Law on Personal Data Protection, effective 1 January 2026) establishes a comprehensive framework for the collection and processing of personal data, including within AI systems. It inherits and upgrades the principles from Decree 13/2023/NĐ-CP (which expired on 1 January 2026). For more on the intersection of AI and privacy, see the article on What is Sentiment Analysis and how user data analysis systems operate.

In addition, Law on Cybersecurity No. 24/2018/QH14 (Article 26(3)) imposes data localisation requirements that directly affect AI infrastructure:

"Domestic and foreign enterprises providing services over telecommunications networks, the Internet, and value-added services in cyberspace in Vietnam that engage in the collection, exploitation, analysis, and processing of personal data, user relationship data, and data generated by users in Vietnam shall store such data in Vietnam in accordance with Government regulations."

Source: Law on Cybersecurity No. 24/2018/QH14, Article 26(3)

This means AI companies — including foreign entities — that provide services in Vietnam and process Vietnamese user data must store that data in Vietnam. This requirement directly affects system architecture decisions, particularly for cloud-based AI models.

Policy and ethics documents — Non-binding but significant

Alongside the legally binding statutes, several important guidance documents are non-binding but nonetheless reflect the direction of regulation:

Decision 1290/QĐ-BKHCN (11 June 2024), issued by the Ministry of Science, Technology and Innovation, sets out 9 principles for responsible AI development: a spirit of collaboration and innovation, transparency, controllability, safety, security, privacy, respect for human rights and dignity, user support, and accountability. This is advisory guidance — it carries no mandatory legal force.

Circular 05/2026/TT-BKHCN (effective 10 March 2026) promulgates the National AI Ethics Framework, applicable to state agencies and public services, built around 4 core principles: safety, human rights, sustainable development, and responsible innovation.

A brief comparison with the EU AI Act

For international context, it is worth comparing Vietnam's framework with the EU AI Act — the European Union's AI legislation (officially in force from 1 August 2024, fully applicable from 2 August 2026). This is a foreign law that does not apply in Vietnam, but it is relevant for Vietnamese companies operating in the EU or providing services to EU users. Full details are available at the official EU AI Act website.

Criterion Vietnam AI Law (134/2025/QH15) EU AI Act
Effective date 1 Mar 2026 1 Aug 2024 (fully applicable Aug 2026)
Risk classification 3 tiers: low / medium / high 4 tiers: unacceptable / high / limited / minimal
High-risk AI liability Strict liability (no proof of fault required) Liability handled through a separate AI Liability Directive
Absolute prohibitions No explicit list of absolute prohibitions yet (pending implementing regulations) Prohibits certain applications (social scoring, real-time biometric identification in public spaces, etc.)
Territorial scope Applies to activities in Vietnam Applies to the EU market, regardless of where the provider is based

A notable similarity: both frameworks are human-centric, require transparency, and mandate risk management across the AI system lifecycle. A key difference: the EU AI Act is more detailed regarding prohibited application lists and specific technical requirements, while Vietnam's law is still in its early implementation phase — many detailed implementing decrees may not yet have been issued.

For further technical context, see the articles on What is Generative AI and What is an AI Agent.

Key compliance considerations for deploying AI in Vietnam

Based on the above legal framework, businesses and developers deploying AI should keep the following practical points in mind:

1. Assess the risk tier from the design stage. Law 134/2025/QH15 defines three tiers — determining which tier your system falls into will determine the extent of your legal obligations.

2. Comply with transparency obligations. Chatbots, virtual assistants, and AI tools that interact with users must provide clear disclosure. AI-generated content (images, text, video) must carry an identifying marker.

3. Data infrastructure must be in Vietnam. If you process Vietnamese user data, the domestic storage requirement under the Cybersecurity Law applies to foreign companies as well.

4. Prepare for strict liability. High-risk AI systems require thorough documentation of management processes, testing, and monitoring — not to avoid liability (since it is strict), but to manage risk and insurance exposure.

5. Monitor implementing regulations. Laws 71 and 134 are both very new; many detailed implementing decrees may not yet have been issued. The list of AI products subject to mandatory labelling and the specific criteria for risk classification are details that warrant close attention.

Disclaimer

This information is for general reference only and does not constitute legal advice; legislation may change — please consult authoritative sources and refer to the updates section.

Conclusion: Vietnam has built a relatively comprehensive AI legal framework in under two years — from national strategy to a dedicated statute. Law on Artificial Intelligence No. 134/2025/QH15 lays an important foundation with clear definitions, a three-tier risk classification system, and a strict-liability mechanism. Businesses building and deploying AI in Vietnam need to understand the two main pillars — Law 134 and Law 71 — alongside the accompanying data protection and cybersecurity requirements. As detailed implementing regulations are still being finalised, continuous monitoring and specialist legal advice remain essential.

Sources

Frequently Asked Questions

Frequently Asked QuestionsQ&A
Does Vietnam have a dedicated AI law?
Yes. The Law on Artificial Intelligence No. 134/2025/QH15 was passed by the National Assembly on 10 December 2025 and took effect on 1 March 2026 — making it Vietnam's first standalone AI statute. Alongside it, the Law on Digital Technology Industry No. 71/2025/QH15 (effective 1 January 2026) devotes an entire chapter to AI systems.
Which AI systems are considered high-risk under Vietnamese law?
Under Law 134/2025/QH15, AI systems are classified into three risk tiers: low, medium, and high. The high-risk category covers systems that could cause significant harm to human life, health, rights, and legitimate interests (in the spirit of Article 9). Law 71/2025/QH15 (Article 43) likewise defines high-risk systems as those capable of causing serious harm to human rights, civil rights, and public order.
Are AI chatbots required to notify users?
Yes. The Law on Digital Technology Industry No. 71/2025/QH15 (Article 44) requires any AI system that interacts directly with people to notify users that they are interacting with an AI, unless it is already obvious to the user. Additionally, AI-generated content (images, videos, text, etc.) must carry an identifier that allows users or machines to recognise it as AI-produced.
If an AI system causes harm despite full regulatory compliance, who is liable?
Under Article 29(2) of Law 134/2025/QH15, even when a high-risk AI system has been managed and operated in full compliance with regulations, the deploying party is still required to provide compensation if harm arises. This is a strict-liability mechanism — no proof of fault on the deployer's part is needed.
How do Law 134/2025/QH15 (AI Law) and Law 71/2025/QH15 (Digital Technology Industry Law) differ?
Law 71/2025/QH15 is a multi-sector statute covering semiconductors, digital assets, and AI — its AI chapter is just one part of the whole. Law 134/2025/QH15, by contrast, is a specialist law whose entire content focuses on AI. As a general principle of Vietnamese law, the specialist law takes precedence when the two instruments conflict on the same issue, though the precise application in any given situation should be confirmed by a qualified lawyer.