NEXORA
· 8 min read

AI Is No Longer Just an IT Department Issue: The New Reality Vietnam's 2025 AI Law Poses for Corporate Management

Attorney admitted in Vietnam

NEXORA Law Firm — Managing Attorney
Attorney admitted in Vietnam
Mediator, Bankruptcy Trustee, Outside Statutory Auditor

Table of Contents
01 - Establishing a Unified Legal Conceptual Framework for AI
02 - A Risk-Based Management Regime for AI Systems
03 - Policies Promoting the Development of the AI Ecosystem
04 - The Transparency Obligation for AI-Generated Content
05 - Practical Implications for Companies

This article provides a legal-practice explanation of Vietnam's "AI Law 2025," which takes effect in March 2026. It examines in detail the risk-based management of AI systems, the legal liability of developers and deployers, and the transparency obligation aimed at combating deepfakes, together with the new legal realities companies now face. It offers practical guidance for building a compliance framework and making use of investment incentives.

In 2025, Vietnam formally enacted its Law on Artificial Intelligence (the "AI Law"), which takes effect on March 1, 2026. The enactment of this law represents an important institutional development, marking the first time a relatively comprehensive legal framework has been established covering the entire lifecycle of AI systems — from development, through provision, to deployment, and finally to operation and oversight.

Notably, the scope of application of this law is not limited to organizations, entities, and individuals within Vietnam. A foreign company or individual is also subject to the law where it engages in developing, providing, or deploying an AI system in the Vietnamese market. This approach reflects the cross-border nature of digital technology and signals a legislative policy requiring AI systems that affect Vietnamese users to meet certain legal standards, regardless of where they originate.

01 - Establishing a Unified Legal Conceptual Framework for AI

a. Legislative Background

Before the AI Law was enacted, Vietnam's legal system had no dedicated statute comprehensively regulating artificial intelligence. AI-related provisions were scattered across multiple areas of law, including the Law on Information Technology, the Law on Cybersecurity, the Law on Personal Data Protection, the Law on Intellectual Property, and the Law on E-Commerce.

This fragmented regulatory structure gave rise to a number of practical problems. First, there was no clear standard for how to legally define an AI system.

Second, the division of roles and responsibilities among the actors involved in the AI value chain was unclear.
Third, the legal basis for determining responsibility for the impact of AI on individuals and society was insufficiently developed.

In recent years, AI has been rapidly adopted across a wide range of sectors, including finance, healthcare, education, and e-commerce. Against this backdrop, establishing a unified legal conceptual framework for AI had become an important precondition for achieving the sound development and appropriate management of the technology.

b. Establishing a Legal Conceptual Framework for AI

The AI Law 2025 is the first instance, under Vietnam's legal system, of a clear, unified legal conceptual framework for artificial intelligence. Under Article 3 of the law, "artificial intelligence" refers to technology that realizes, through electronic means, human intellectual capabilities such as learning, reasoning, perception, judgment, and natural language understanding.

Further, an "AI system" is defined as a machine-based system designed to perform AI capabilities with a degree of autonomy, which may also possess adaptive capability after deployment. It refers to a system that generates outputs — such as predictions, content, recommendations, or decisions — that may affect the physical or digital environment.

In addition, the law clearly delineates the actors involved in the AI value chain. Specifically, it identifies the "Developer," who designs, builds, trains, and tunes an AI system; the "Provider," who supplies the AI system to the market; the "Deployer," who uses the AI system in the course of business or service provision; the "User," who directly interacts with the AI system or its output; and the "Affected Person," who is directly or indirectly affected by the deployment of the AI system.

By clearly defining the actors that make up the AI value chain in this way, the allocation of legal responsibility becomes clearer, making it possible to establish a framework of obligations and liability that applies when AI-related risks or disputes arise.

02 - A Risk-Based Management Regime for AI Systems

a. Risk Classification of AI Systems

One of the important features of the AI Law 2025 is that it adopts a "risk-based approach" to AI systems. Rather than applying a uniform set of rules to all AI technologies, the law imposes differing obligations depending on the scope of an AI system's impact and its degree of risk. This approach, which is increasingly being adopted in AI regulation around the world, rests on the idea that AI with a greater impact on society and individuals should be subject to stricter controls.

Under Article 9 of the AI Law, AI systems are primarily classified into three risk categories.

The first is "high-risk AI systems." These refer to systems that may have a material impact on human life or health, human rights, national security, the public interest, or social order. Examples potentially falling into this category include credit-scoring systems in the financial sector, diagnostic-support systems in healthcare, and AI used in public administrative services. Because these systems carry significant social impact, they must undergo strict review and management before entering actual operation.
The second is "medium-risk AI systems." These refer to AI that may affect users' behavior or perception — for example, systems where a user might mistake the AI for a human, or AI capable of manipulating a user's judgment or behavior. Systems of this kind are primarily subject to transparency obligations.
The third is "low-risk AI systems." These are AI systems primarily intended for technical assistance or operational efficiency and that do not have a material effect on individuals or society. These systems are not subject to excessive regulation, and are merely required to comply with general principles of safety and data protection.

This kind of risk-based management regime is regarded as a well-balanced institutional design, one that secures social safety while avoiding excessive regulation that would stifle technological innovation.

b. Conformity Assessment for High-Risk AI

High-risk AI systems are required to undergo a "conformity assessment" before being brought to market or put into actual operation. Under Articles 13 and 14 of the AI Law, this assessment may be carried out by a conformity assessment body designated by the government, or, under certain conditions, through self-assessment by the provider itself.

In addition, companies that provide or develop high-risk AI are required to establish a management system covering the entire lifecycle of the AI system. This includes an AI risk-management framework, management of training data, retention of technical documentation and operational logs, and human oversight of important decisions.

These requirements demand that companies developing or providing AI in fields such as finance, healthcare, education, and public services build a substantial compliance framework. It will be important for companies to design AI governance from the earliest stages of product development.

03 - Policies Promoting the Development of the AI Ecosystem

The AI Law 2025 introduces not only regulation of AI technology but also support policies aimed at promoting the development of the AI industry. Under provisions such as Article 20 of the law, companies engaged in research, development, or application in the AI field may be eligible for the highest level of incentives available under the Law on Science and Technology, the Law on High Technology, and the Law on Investment, among others.

In addition, new AI services or business models may, in certain cases, be permitted a period of pilot testing under a regulatory sandbox. This system is intended both to promote the trial introduction of new technology and to serve as an important means for regulators to assess the technology's social impact.

Furthermore, the establishment of a national AI development fund is also planned, and it is expected that this fund will provide financial support for research and development, technology transfer, and the support of AI startups.

04 - The Transparency Obligation for AI-Generated Content

Another important feature of the AI Law 2025 is the introduction of a transparency obligation for AI-generated content.

Advances in AI technology have made it possible to generate audio, images, and video with extremely high fidelity. At the same time, however, the risk has grown that technologies such as deepfakes will be used to spread misinformation or infringe individuals' rights.

Against this backdrop, Article 11 of the law requires that content generated or manipulated by AI bear an identifiable marking. Specifically, audio, image, and video content must carry machine-readable identifying information making clear that it is AI-generated content.

The law also establishes an obligation to clearly notify users when they are interacting with an AI system.

05 - Practical Implications for Companies

In preparing for the AI Law 2025's entry into force, companies need to prepare in the following respects. First, it is important to clearly identify which actor in the AI value chain the company corresponds to. Next, companies should comprehensively review the AI systems used within the organization to check for any legal risk.

In addition, it is desirable to establish internal management systems — such as AI risk classification and technical documentation management — in preparation for future regulatory compliance. Making use of the government's support programs and regulatory sandbox scheme may also become an important strategic consideration for companies.

【Disclaimer】

Articles on this website are based on the laws and regulations in effect at the time of writing. Where laws or policies subsequently change, the content may no longer be accurate and should be reviewed accordingly.

Content on this website does not constitute legal advice. Please consult a qualified professional for guidance on your specific situation. We accept no responsibility for any direct or indirect damages arising from the use of this website's content without appropriate professional review.

info@nexorawoco.com0985 677 501 (Zalo/LINE: m2H6M8wpfJ)