The new AI law takes effect 1 March 2026, binds any company serving Vietnamese users, and forces a human in the loop on every critical decision.
Vietnam's new AI law takes effect on 1 March 2026. Law No. 134/2025/QH15 is the first standalone, legally binding AI statute in Southeast Asia, and its scope reaches any company that develops or deploys AI for Vietnamese users, including foreign providers.
The mechanism that determines whether a product is even permissible sits in Article 4: a human-arbiter rule. The law frames AI as an assistive tool, with the principle that "the human remains the final arbiter" in all critical decisions. Pertama Partners' compliance guide and Securiti's regulatory walkthrough both flag this as the architectural constraint, not the penalty schedule. A credit-scoring model can recommend a denial; a person has to sign off. A diagnostic system can flag a tumor; a clinician has to confirm. A hiring tool can rank candidates; a human has to make the call. The rule binds any AI system whose output drives a critical decision about a person, and it cannot be engineered around with a UI label.
Scope is the second question most readers need answered. The statute binds Vietnamese companies developing or deploying AI systems, and it carries extraterritorial pull for multinationals operating across ASEAN. A Singapore-headquartered fintech serving customers in Hanoi cannot ship a fully autonomous lending model; the same human-arbiter rule applies. Foreign-flagged deployments get no exemption.
Chapter II establishes a risk-based management framework, and Chapter IV stacks on aggressive innovation incentives: regulatory sandboxes for testing under supervisor oversight, and green-infrastructure preferences for energy-efficient data centers. Low-risk systems face light-touch duties. High-risk systems, those used in healthcare, credit, employment, education, and public services, face pre-deployment review, ongoing audit, and human-arbiter compliance. The prohibited-acts decree layered on top bars specific uses outright: social-scoring systems, AI-generated disinformation at scale, and biometric mass surveillance outside narrow law-enforcement exceptions.
Enforcement runs through the Ministry of Science and Technology, which gains authority to issue sandbox licenses, audit high-risk systems, and impose penalties for non-compliance. Tilleke's analysis and the compliance-firm summaries that anchor this piece flag enforcement capacity as an open question. Several key provisions depend on implementing regulations that were not yet published at the time of the source summaries, and the state's audit bandwidth for high-risk AI across sectors is untested in practice.
What to watch between now and 1 March 2026: the implementing regulations for the prohibited-acts decree, the sandbox license rules, and the first enforcement actions. Vietnam's statute is also a regional signal, the first binding AI law in a Southeast Asian jurisdiction, and a template neighboring regulators can copy, soften, or reject. Compliance analysts describe it as the close of the self-regulation era in the region. The wire will tell readers that Vietnam regulated AI. The work for any company whose model touches a Vietnamese user is the human-arbiter clause, the extraterritorial reach, and the prohibited-acts list.