From the journal

Vietnam's AI Law No. 134/2025/QH15 Takes Effect March 2026 with Risk-Based Obligations

Vietnam's Law on Artificial Intelligence No. 134/2025/QH15, adopted by the National Assembly on 10 December 2025, entered into force on 1 March 2026. The Law introduces a risk-based classification of AI systems into three tiers and imposes disclosure, registration, and operational obligations on AI developers, providers, and deployers operating in Vietnam or producing effects on Vietnamese persons. A transitional period of 12 to 18 months applies to systems already in operation.

3 min read

Vietnam's Law on Artificial Intelligence No. 134/2025/QH15 was adopted by the National Assembly on 10 December 2025 and entered into force on 1 March 2026. The Law applies to domestic and foreign organisations that research, develop, provide, deploy, or use AI systems in Vietnam or whose AI systems produce effects on Vietnamese persons. AI systems already in operation before 1 March 2026 benefit from a transitional period of 12 to 18 months, depending on the sector, during which they must satisfy the Law's obligations. Systems posing serious risks are excluded from the transitional period.

Article 9 of the Law classifies AI systems into three risk tiers: high, medium, and low. High-risk AI systems must be registered with the Ministry of Science and Technology, undergo conformity assessment, and be subject to ongoing monitoring by their providers and deployers. Article 14 requires providers to ensure transparency and explainability appropriate to the system's risk tier. Article 27 requires providers of generative AI systems to disclose training data sources and apply digital watermarks or equivalent technical markers to AI-generated content. AI activities exclusively serving national defence, national security, or cipher purposes are excluded from the Law's scope.

AI system providers who supply products into Vietnam without a local entity are not exempt: the Law applies wherever AI systems produce effects on Vietnamese persons. Deployers of high-risk AI systems in healthcare, financial services, critical infrastructure, and employment contexts face intensive compliance requirements, including conformity assessment and post-market monitoring. Generative AI service providers must implement content labelling from 1 March 2026, with the transitional period not available to systems newly placed on the market after that date. Foreign technology companies distributing AI-powered products or services to Vietnamese users must classify those products and map applicable obligations before supply.

Implementing regulations for several provisions of the Law were still being finalised as of 1 March 2026, leaving interpretive uncertainty for AI system categories whose risk classification depends on subsidiary criteria not yet published by the Ministry of Science and Technology. The Law spans 35 articles across 8 chapters and does not define all system categories within the statutory text; guidance from sector-specific regulators is expected to follow. The 18-month transitional deadline for high-risk systems in certain sectors falls in September 2027, and the 12-month deadline for other categories falls in March 2027.

Licentium advises on AI regulatory compliance in Southeast Asia and can draw on a partner network for Vietnam-specific legal counsel. Organisations assessing the risk classification of their AI systems, designing compliance programmes under Law No. 134/2025/QH15, or evaluating the transitional provisions' application to existing deployments are welcome to contact us. Work we undertake includes AI system risk classification, regulatory compliance gap analysis, generative AI provider obligations, AI governance documentation, and market-entry regulatory strategy for technology companies.

Source: Law on Artificial Intelligence No. 134/2025/QH15, National Assembly of Vietnam, 10 December 2025, in force 1 March 2026

AI Regulatory

More from the journal

See all
Illia Prokopiev

From Cloud Concentration to AI Dependence: The UK’s Critical Third Parties Regime

The United Kingdom now directly oversees designated technology suppliers whose service failures could threaten financial stability. The question is whether the first cloud designations show a legal expansion toward AI-model providers, and what the present regime requires. This analysis assumes the quoted statement concerns the UK financial-services Critical Third Parties regime and assesses the law through 14 July 2026.

Alberta Regulated iGaming Market Launched on 13 July 2026 with 22 Operators

Alberta's regulated private iGaming market launched on 13 July 2026, making Alberta the second Canadian province to permit private online gambling operators after Ontario. The Alberta Gaming, Liquor and Cannabis Commission serves as market regulator and the Alberta iGaming Corporation oversees commercial operations and operator contracts. Twenty-two operator sites went live on day one, including FanDuel, DraftKings, BetMGM, and BetRivers. Operators must fully launch or exit the Alberta market by 13 October 2026.

European Commission Presents Cybersecurity and AI Action Plan on 7 July 2026

On 7 July 2026, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence. The plan directs the Commission and ENISA to evaluate advanced AI models before they reach the EU market, establish a secure testing platform for critical-sector organisations, and launch an EU Grand Challenge on AI-powered cybersecurity solutions. It operates alongside the AI Act, NIS2 Directive, DORA, Cyber Resilience Act, and Cyber Solidarity Act, and introduces no new directly binding obligations.