
Ho Chi Minh City, 3 September 2026
Vietnam became the first country in Southeast Asia to bring a comprehensive law on artificial intelligence into force when its Law on Artificial Intelligence took effect on 1 March 2026 (the “AI Law” or the “Law”). Reflecting the broader “Brussels effect” in AI regulation, the AI Law adopts a risk based regulatory architecture that shares similar structural features with the EU AI Act.
Although prohibited practices are regulated separately under Article 7 and Article 9 subsequently classifies AI systems into three risk levels, these provisions, read together, effectively establish four categories of regulatory treatment: (1) prohibited AI practices, (2) high risk AI systems, (3) medium risk AI systems and (4) low risk AI systems.
Within this framework, high-risk AI systems are subject to the most extensive compliance requirements, with the applicable obligations depending on the role of the stakeholder in the AI value chain. Providers in particular face a broad range of obligations, which are generally more stringent than those imposed on deployers.
Vietnam has now taken a further step with Decision No. 33/2026/QD TTg (“Decision 33”). Effective from 15 August 2026, Decision 33 introduces the list of AI systems classified as high-risk, giving practical effect to an important part of the new regulatory framework.
In this post, we focus on the key compliance requirements for high-risk AI systems under the Vietnamese AI Law
What is a “high risk” AI system?
Under the AI Law, a high risk AI system is one that is capable of causing significant harm to human life or health, the lawful rights and interests of organisations or individuals, national interests, public interests or national security. Classification considers its impact on human rights, safety and security, field of use, user scope and scale of effects, as well as its degree of automation, role in final decision making and the extent of human supervision and intervention under Decree No. 142/2026/ND-CP (“Decree 142”).
Decision 33 lists 46 high risk AI systems across six fields: education, ethnic and religious affairs, healthcare, banking, legal proceedings and transport. Examples include systems that automatically assess or rank learners, support surgical procedures, execute specified electronic banking transactions or make credit decisions, and perform specified autonomous or safety critical transport functions.
Classification depends on the specific description and conditions for each listed system. Decree 142 generally excludes systems limited to specified data processing without directly affecting lawful rights or interests, systems subject to substantive and independent human review before a decision takes effect, systems used only for internal administration, and systems whose analyses, forecasts, evaluations or recommendations are not the sole basis for a final decision.
Key compliance obligations
For high risk AI systems, the principal compliance requirements include:
- Classification and notification: Providers must self-classify AI systems before putting them into use. A high risk system must have a classification dossier, and the provider must notify the Ministry of Science and Technology of the classification result before the system is put into use. Where a deployer modifies, integrates or changes the functionality of a system in a way that creates new or higher risks, it must coordinate with the provider to reclassify the system.
- Risk management and data governance: Providers must establish and maintain a risk management system appropriate to the system’s intended purpose, deployment scope and risk level, and ensure appropriate quality, suitability and representativeness of relevant training, testing and evaluation data. Deployers must manage risks during operation, monitor the system for errors, risks and incidents, and maintain appropriate human oversight.
- Conformity assessment: Every high risk AI system must undergo conformity assessment before it is put into use and following significant changes that affect the initial assessment. Systems subject to mandatory conformity certification must be assessed by a registered or recognised conformity assessment organisation. For other high risk systems, the provider may conduct a self assessment or use an eligible conformity assessment organisation.
- Documentation, human oversight and transparency: Providers must prepare, update and retain the required technical documentation and operational logs, and design systems so that human supervision and intervention remain possible. Providers and deployers are also subject to transparency and incident management requirements, including applicable notification and labelling requirements for AI generated content. Compliance does not generally require disclosure of source code, detailed algorithms, model parameters or protected business or technological secrets.
- Liability: Where a high risk AI system causes damage despite being managed, operated and used in accordance with applicable law, the deployer must compensate the affected person, subject to the statutory exemptions. After paying compensation, the deployer may seek reimbursement from the provider, developer or other relevant parties where the parties have agreed on that allocation.
What should businesses do now?
For businesses, the starting point for compliance is to determine whether an AI system falls within the high-risk list in Decision 33 by assessing it against the relevant description and applicable conditions.
Compliance deadlines then depend on when the system was put into operation. For high-risk systems already operating before 15 August 2026, the deadline is before 1 September 2027 for systems in the healthcare, education and financial sectors,* and before 1 March 2027 for systems in the other listed fields. Systems put into operation during the six month period beginning on 15 August 2026 must complete the applicable compliance requirements before 1 March 2027.
* Article 4.1(a) refers to the “finance” sector, while the Appendix identifies “banking” as one of the six listed sectors. Decision 33 does not clarify this difference in terminology.
—
See the previous part here: Part 1|Part 2
—
If your business is developing, providing or deploying AI systems, contact our team for tailored advice on compliance requirements:
📧 info@indochinecounsel.com
☎️ (+84) 28 3823 9640