Skip to main content
AI in ASIA
Vietnam AI law regulation Southeast Asia first
Business

Vietnam Enforces Southeast Asia's First AI Law

Three risk tiers, mandatory registration, and a 12-month compliance clock. Vietnam is not asking nicely.

Intelligence Desk7 min read

Vietnam draws the regulatory line on AI for Southeast Asia

AI Snapshot

The TL;DR: what matters, fast.

Vietnam enforced Southeast Asia's first comprehensive AI law on 1 March 2026 with three risk tiers

Foreign AI providers must appoint local representatives and register high-risk systems

Neighbours including Thailand and the Philippines are watching before drafting their own rules

Advertisement

Advertisement

Vietnam Writes History With Southeast Asia's First Enforceable AI Law

On 1 March 2026, Vietnam quietly made history. Its Law on Artificial Intelligence came into force, making the country the first in Southeast Asia to enforce a comprehensive, risk-based regulatory framework for AI. The law covers domestic and foreign operators alike, classifying AI systems into three tiers: high-risk, medium-risk, and low-risk.

High-risk systems, including those used in healthcare, finance, and education, face the strictest controls. Real-time biometric surveillance is banned without explicit government approval. Foreign AI providers must appoint a local legal representative, and a new National AI Database will require registration of all high-risk systems operating in the country.

The law was passed by Vietnam's National Assembly on 10 December 2025 and drew heavily from the European Union's AI Act, but adapted for a developing economy with different priorities. This move positions Vietnam ahead of the region's surging AI startup ecosystem in regulatory maturity.

What the Law Actually Requires

Businesses already running AI systems get a 12-month grace period, with full compliance required by 1 March 2027. For sectors deemed especially sensitive, including finance, healthcare, and education, the deadline extends to 18 months, or 1 September 2027.

A National AI Commission is set to be established by 1 July 2026 to oversee enforcement. The Ministry of Science and Technology will lead centralised governance, and a national AI computing centre is planned to support Vietnamese-language large language models and public data resources.

"The law represents a significant shift in how Vietnam approaches technology governance, moving from reactive oversight to proactive, risk-based regulation that mirrors international best practice." - Tran Thi Thu Hang, Senior Associate, Baker McKenzie Vietnam

Sandbox mechanisms are also built in. Vietnam wants to attract investment, not just regulate it. The law includes tax incentives for AI research, support for startups, and a national AI development fund to channel public and private capital into data centres and computing infrastructure.

By The Numbers

  • 1 March 2026: Enforcement date, making Vietnam first in Southeast Asia with comprehensive AI legislation
  • 3 risk tiers: AI systems classified as high-risk, medium-risk, or low-risk under the new framework
  • 12 months: Grace period for existing AI systems to achieve full compliance (18 months for finance, healthcare, education)
  • 1 July 2026: Deadline for establishing the National AI Commission to oversee enforcement
  • 100%: Proportion of high-risk AI systems that must be registered in the National AI Database

Why Vietnam Moved First

Vietnam's decision to regulate before its wealthier neighbours is not accidental. The country has positioned itself as a technology manufacturing hub for years. Samsung, Intel, and dozens of smaller firms operate major facilities there. AI regulation is part of a broader strategy to climb the value chain from assembly to innovation.

The timing also matters regionally. Singapore has voluntary AI governance frameworks but no binding law. Thailand is drafting AI legislation. Indonesia finalised its AI roadmap in 2025 but has not passed enforceable rules. South Korea enacted its AI Basic Act in 2024, making it the closest regional comparison, but Vietnam's law goes further in several areas, particularly on biometric surveillance and mandatory risk classification.

"Vietnam has been fast out of the box. By moving early, the country is positioning itself not just as a compliant market but as a credible destination for responsible AI investment." - David Brown, Managing Partner, Duane Morris Vietnam

This regulatory approach complements Vietnam's education strategy, as the country integrates AI teaching from primary school level, creating a comprehensive national approach to artificial intelligence development.

Vietnam AI law regulation Southeast Asia first
Vietnam's regulatory framework classifies AI systems into three risk tiers, with the strictest controls on healthcare, finance, and education applications

The EU Comparison and Where It Diverges

The parallels with the EU AI Act are obvious. Both use risk-based classification. Both ban certain AI practices outright. Both require transparency in high-risk deployments. But Vietnam's version has important differences.

First, the law explicitly promotes national AI sovereignty. The government plans to develop Vietnamese-language LLMs and build public computing infrastructure, a priority that reflects both practical needs and strategic ambition. Second, the compliance timelines are tighter than the EU's phased approach, which stretches to 2027 for most provisions.

FeatureVietnam AI LawEU AI ActSouth Korea AI Basic Act
Effective date1 March 2026Phased, 2024-2027January 2025
Risk classification3 tiers4 tiersHigh-risk focus
Biometric surveillance banYes, without approvalYes, with exceptionsLimited
Foreign provider obligationsLocal representative requiredEU-based representativeVoluntary compliance
National AI fundYesNo (member state level)Yes
Sandbox provisionsYesYesYes

What This Means for Businesses

For companies operating AI in Vietnam, the compliance clock is ticking. The 12-month grace period sounds generous, but the requirements are substantial. Businesses must conduct risk assessments, register high-risk systems, appoint compliance officers, and document their AI decision-making processes.

Foreign AI providers face an additional layer: the mandatory local representative requirement. This is a clear signal that Vietnam intends to enforce the law against overseas operators, not just domestic ones. Companies like Google, Microsoft, and ByteDance, all of which have growing AI footprints in Vietnam, will need to ensure their systems comply.

  • All high-risk AI systems must be registered in the National AI Database before deployment
  • Transparency requirements mandate that users are told when they are interacting with an AI system
  • AI-generated content in media and communications must be clearly labelled
  • Companies must conduct and document regular impact assessments for high-risk deployments
  • Violations can result in fines, suspension of AI operations, or revocation of operating licences

Regional Ripple Effects

Vietnam's move will put pressure on its neighbours. ASEAN has been discussing AI governance frameworks for years, but progress has been slow and largely voluntary. A binding national law from one of the bloc's fastest-growing economies changes the dynamics.

Thailand's draft AI legislation, expected later in 2026, will likely reference Vietnam's framework. The Philippines and Malaysia are also watching closely. For multinational companies operating across the region, the patchwork of different national approaches is becoming the core compliance challenge.

The timing coincides with broader regional challenges, as Southeast Asia's AI ambitions hit data infrastructure constraints, making regulatory clarity even more critical for investment decisions.

How does Vietnam's AI law differ from Singapore's approach?

Singapore relies on voluntary governance frameworks and industry self-regulation, whilst Vietnam has created binding legal requirements with specific penalties. Singapore's Model AI Governance Framework provides guidance but lacks enforcement mechanisms that Vietnam's law includes.

What happens to foreign AI companies that don't comply?

Foreign AI providers must appoint local legal representatives and register high-risk systems. Non-compliance can result in fines, suspension of operations, or complete prohibition from offering AI services in Vietnam's market.

Which AI applications are considered high-risk under the new law?

High-risk systems include AI used in healthcare diagnostics, financial services, education assessment, employment decisions, and any real-time biometric surveillance. These require the strictest compliance measures and government registration.

How will this affect Vietnam's AI development goals?

The law includes support mechanisms like tax incentives, research funding, and sandbox environments for AI startups. It aims to balance regulation with innovation, promoting responsible AI development rather than stifling growth.

What are the penalties for violations?

Violations can result in administrative fines, suspension of AI operations, or revocation of business licences. The specific penalty amounts will be detailed in implementing regulations expected before the law takes effect.

The AIinASIA View: Vietnam's AI law is the most consequential piece of technology regulation to come out of Southeast Asia in years. Not because it's perfect, but because it exists. The region has spent too long relying on voluntary frameworks and aspirational guidelines. By creating binding legal requirements, Vietnam forces the conversation beyond good intentions to actual implementation. This will accelerate regulatory development across ASEAN and give businesses the clarity they need to invest confidently in AI infrastructure. Other nations will now face pressure to match Vietnam's regulatory maturity or risk being left behind in the race for responsible AI investment.

Vietnam's pioneering approach to AI regulation reflects broader regional trends, as Southeast Asian professionals grapple with AI readiness challenges. The country's comprehensive framework addresses both innovation and oversight, setting a template others may follow.

As Vietnam becomes the first Southeast Asian nation to enforce comprehensive AI legislation, the implications extend far beyond regulatory compliance. This law represents a fundamental shift in how the region approaches technology governance, moving from reactive to proactive oversight. What aspects of Vietnam's approach do you think other Southeast Asian nations should adopt? Drop your take in the comments below.

YOUR TAKE

We cover the story. You tell us what it means on the ground.

What did you think?

Written by

Share your thoughts

Be the first to share your perspective on this story

This is a developing story

We're tracking this across Asia-Pacific and may update with new developments, follow-ups and regional context.

Advertisement

Advertisement

This article is part of the This Week in Asian AI learning path.

Continue the path →

No comments yet. Be the first to share your thoughts!

Leave a Comment

Your email will not be published