This article argues that, while borrowing the EU’s formal risk-based architecture, Vietnam’s AI Law reconfigures it through expansive administrative discretion, shaping a distinct regional trajectory that may influence ASEAN’s divergence from the EU’s normative governance.
- Vietnam’s AI Law as a legislative leapfrogging
Emerging at a critical era of rapid digital transformation, rising geopolitical competition, and an increasingly state-led developmental strategy, the adoption of the Artificial Intelligence Law in Vietnam in 2025 and its enforcement on 1 March 2026 marks a decisive institutional response.
Far from an isolated event, this law represents the culmination of an intensive period of legal activity aimed at closing the gap between innovation and oversight. The provided timeline shows that “regulatory density” began to thicken in 2020 with the National Digital Transformation Program, marking the end of a 14-year latency period and the start of a strategic sprint. This transition culminated on December 10, 2025, a day without precedent in Vietnamese legislative history: the National Assembly passed 34 new laws in a single day. In addition, by moving from the December 2025 Law on AI to the April 2026 implementing Decree in under six months, the government has signalled an era of a fast-paced, sophisticated regime designed to govern the country’s 2030 technology goals.
Figure 1: Evolution of Vietnam’s legal framework for digital transformation and AI
(Illustrated by author)
Vietnam’s AI Law emerges less as a preventive regulatory instrument and more as a foundational framework for steering an already unfolding technological reality. From a societal perspective, AI technologies in Vietnam are becoming increasingly normalised, reflected in high levels of public trust and, in some cases, overreliance on AI-based tools in everyday life (Partnership on AI, 2026). At the industrial policy level, early initiatives such as the 1,000 Vietnamese Genome Project (1KVG), launched in 2018 by the VinBigData Institute (Vietnam News 2018), illustrate Vietnam’s entry into large-scale data and AI-driven scientific research, emerging shortly after Singapore introduced its AI Singapore, AI4I, and AI4E initiatives in 2017. AI has increasingly been integrated into governance functions since 2025, with judicial and prosecutorial bodies deploying AI for predictive crime mapping, evidence processing, and administrative support systems (Bảo Vệ Pháp Luật, 2025). These developments are reinforced by the “Make in Vietnam” strategy, which encourages domestic technological innovation, alongside growing foreign investment from firms such as NVIDIA, Qualcomm, SpaceX, Marvell, and Cadence.
In such a context, in competing with regional neighbours like Singapore, Indonesia and Thailand for high-tech investment, a formal law provides a predictable legal corridor as a legislative strategy. Concerning the EU–Vietnam Free Trade Agreement, the adoption of more formalised and enforceable legal instruments in AI regulation can be understood as part of Vietnam’s strategy to maintain credibility as a reliable trade partner for the EU. Furthermore, by codifying a law to govern AI, Vietnam ensures that AI development becomes a statutory priority for all ministries, not just a set of best practices that can be ignored during budget cycles, thus aligning with the national strategies since 2020 and the Resolution of the 13th National Congress of the Communist Party of Vietnam in 2021 regarding «…perfecting the legal system […] to remove bottlenecks hindering the country’s development.» Furthermore, by becoming one of the first ASEAN states to institutionalise AI governance through binding legislation, Vietnam could set a new regional benchmark for how developing states may regulate AI while balancing technological innovation, economic modernisation, national sovereignty, and administrative control. This exemplifies General Secretary To Lam’s vision of «Institutional and legal breakthroughs for the nation’s rising» (Đột phá thể chế, pháp luật để đất nước vươn mình) and his proactive foreign policy goal – «actively and effectively participating in the development of international institutions and laws, and shaping the global legal order» (Tuoitre News, 2025), positioning Vietnam as a rule-maker rather than a passive rule-taker in the global governance of emerging technologies.
- From an open normative space of innovation…
Vietnam’s AI Law clearly reflects substantial influence from the EU’s AI governance model and broader OECD governance principles. Both frameworks adopt risk-based regulatory systems, emphasise human-centric AI, prohibit manipulative AI practices, and recognise transparency and accountability as core governance principles. These similarities could be understood within the broader context of the EU’s adequacy framework and the global politics of cross-border data governance, particularly as Vietnam has already demonstrated a degree of regulatory convergence through its recent Law on Personal Data Protection, reflecting its efforts to align aspects of its digital governance framework with emerging international standards. Nevertheless, a deeper comparison reveals that Vietnam selectively borrowed the structure and terminology of the EU AI Act without fully importing its institutional foundations.
One of the Vietnam AI Law’s most significant features is its pro-innovation orientation, accommodating the developmental needs of an emerging economy. First, unlike Article 3(3) of the EU AI Act, which consolidates the technical creator and the commercial distributor into a single category of “providers”, Vietnam distinguishes between developers, providers, and deployers in Article 3. This role-based allocation of responsibility acknowledges the realities of the tech economy in Vietnam where the entity developing the tech and the entity using it are different branches of the same family tree (like VinBrain’s DrAid used in Vinmec Healthcare System) (NVDIA, 2024), demonstrating Vietnam’s attempt to encourage domestic AI innovation by allowing for more precise contracts and indemnity clauses between business partners, while concentrating compliance obligations on commercially deployed systems. Such role-based allocation of responsibility also serves as the necessary foundation for the regulatory flexibility in Article 21, which explicitly provides for «exemptions or reductions of certain compliance obligations» to remove legal barriers that hinder domestic startups. For example, a startup developer might be exempted from certain rigorous technical documentation hurdles to encourage innovation, while the provider remains strictly liable for the market-entry safety of that same AI system. This is distinct from the EU’s sandbox, which primarily serves as a compliance guidance tool to ensure that developers meet strict safety and fundamental rights standards (Artificial Intelligence Act EU, 2025).
In addition, while the EU AI Act is fundamentally a market-regulating “product safety” law focused on establishing boundaries for prohibited AI practices, the Vietnamese AI Law is structured as a strategic developmental tool. The AI Law emphasises policies promoting AI infrastructure, data access, technology transfer, workforce development, and support for small and medium-sized enterprises adopting AI technologies, set out in Article 5 on national AI development policy and Article 20 on AI market and ecosystem promotion. The National AI Development Fund provided in Article 22 of the AI Law is where the two frameworks diverge the most, with a support voucher scheme (phiếu hỗ trợ) in Article 25, which is even included to directly subsidise compute power (GPU), shared data, and national large language models for local businesses. Furthermore, rather than constructing ex ante certification and dense, procedurally oriented compliance systems comparable to those in the EU’s regulatory frameworks, Article 10(1) of Vietnam’s AI Law requires providers to self-classify AI systems before deployment and to notify the Ministry of Science and Technology. By bypassing the dense, third-party conformity assessments required by the EU for many high-risk systems, Vietnam allows businesses to move from development to deployment with minimal administrative delay, though at the risk of under-classification to avoid stricter oversight.
Such pro-growth flexibility may prove institutionally advantageous for a developing digital economy seeking to accelerate AI adoption without constructing the highly resource-intensive compliance infrastructure embedded in the EU model. Critically, the developmental orientation of the law may also blur the boundary between regulation and industrial policy, as the state simultaneously serves as a regulator, promoter, financier, and strategic coordinator of AI development.
3. …To holding down the fort
A critical comparison between Vietnam’s AI Law and the EU AI Act reveals a profound divergence in legislative philosophy. The EU governs AI primarily through proceduralized compliance infrastructures, whereas Vietnam currently governs AI mainly through administrative registration, executive supervision, and future bylaws. Structurally, the law consists of eight chapters and 35 articles and functions primarily as a framework, or “basic law”, rather than a highly technical, exhaustive regulatory code. Instead of embedding detailed technical obligations directly within the statute, the law repeatedly delegates operational details to future governmental decrees and subordinate regulations, stating that «The Government shall provide detailed regulations…» The high density of such delegation clauses within the law, appearing in 17 out of 35 provisions, reveals a deliberate strategy of administrative elasticity, in which a framework that is “hard” in authority but “fluid” in application.
Beyond this formal reliance on delegated authority, the deeper regulatory logic becomes clearer when comparing how risks are conceptualised across jurisdictions. While both frameworks utilise a risk-based structure, the EU’s model is primarily “rights-centric”, aimed at shielding the individual from the potential overreach of technology. Its four-tier system, which includes an «Unacceptable Risk» category, establishes moral “red lines” against practices like social scoring or mass biometric surveillance, with enforcement embedded in multi-layered institutional checks. In contrast, Vietnam’s three-tier model (High, Medium, and Low) is development-centric. By omitting a categorical «unacceptable» tier and instead listing specific prohibitions in Article 7, Vietnam adopts broader normative prohibitions embedded within a centralised governance structure, expanding the scope of administrative control over AI systems beyond clearly predictable legal boundaries. Undefined terms such as «violating lawful rights and interests» or «severely harmful AI deployment» can be interpreted expansively, particularly when combined with Vietnam’s broader cybersecurity and national security frameworks.
Furthermore, Vietnam’s AI Law grants the executive branch broad power to define the rules of the game through high-level delegation, unlike the EU AI Act’s expertise-based approach, which establishes a centralised AI Office within the European Commission to oversee implementation and coordination between member states. Under Article 4, Clause 1 of Decree 142, the Ministry of Science and Technology (MOST) is tasked with operating the National AI One-Stop Portal. Under Article 7 of Decree 142, the Prime Minister holds the authority to issue and amend the List of High-Risk AI Systems. Besides, Provincial People’s Committees are responsible for reviewing and proposing updates to high-risk lists based on local deployment, illustrating that the current governance model relies heavily on administrative coordination rather than proceduralized technical governance. Meanwhile, the expansion of security-oriented governance into the regulation is evidenced by the role of the Ministry of Public Security (MOPS). As the drafting authority of the 2025 Law on Personal Data Protection, the MOPS continues to be the focal point responsible for overseeing, encouraging, and monitoring the creation of essential datasets across all ministries and local governments to implement the AI Law. Drawing from this design, the combination of AI regulation with national data governance, cybersecurity frameworks, and administrative supervision suggests that Vietnam increasingly views AI not merely as a commercial technology but as strategic infrastructure closely connected to regime stability, governance effectiveness, and technological independence. This is politically and administratively feasible in contexts where economic and technological levels across provinces are uneven, and executive-led governance structures play a dominant role. However, such a developmental and state-centred approach risks blurring the boundary between technical regulation and political governance, particularly in areas involving predictive policing, biometric systems, and data-intensive administrative technologies.
- Convergence with variation: a reference point to ASEAN regulatory trajectories
The Vietnamese framework offers a model that incorporates internationally recognisable AI governance principles, such as human-centricity, transparency, accountability, and risk classification, without requiring the highly resource-intensive compliance infrastructure embedded in the EU AI Act. Within the Southeast Asian context, Vietnam’s model may appear institutionally attractive because it reflects governance priorities shared by many developing states: maintaining political stability, strengthening technological sovereignty, and preserving executive flexibility while still participating in global AI governance discourse. However, the prioritisation of security, social stability, and administrative control could gradually shift AI governance away from its formally stated human-centric principles toward a more state-centric model of digital governance. Looking ahead, Vietnam’s emerging AI governance model may exert a normative pull on other ASEAN countries, but its security- and administration-heavy orientation may add to the regional spectrum of governance models, tilting between regulatory centralisation and innovation-driven approaches to AI development.
References:
Bảo Vệ Pháp Luật (2025) ‘Tọa đàm ứng dụng trí tuệ nhân tạo (AI) trợ lý ảo trong công tác giải quyết các vụ án hình sự’ [Panel discussion on applying artificial intelligence (AI) virtual assistant in criminal case resolution], February. Available at: https://baovephapluat.vn/kiem-sat-24h/ban-tin-kiem-sat/toa-dam-ung-dung-tri-tue-nhan-tao-ai-tro-ly-ao-trong-cong-tac-giai-quyet-cac-vu-an-hinh-su-173402.html (Accessed: 11 March 2026).
NVIDIA (2024) Vietnam’s VinBrain Deploys Healthcare AI to Thousands of Doctors via NVIDIA Technologies. Available at: https://blogs.nvidia.com/blog/vietnam-vinbrain-deploys-healthcare-ai/ (Accessed: 11 May 2026).
Partnership on AI (2026) Closing the Assurance Divide, p. 6. Available at: https://partnershiponai.org/wp-content/uploads/2026/02/PAI_report_closing-the-assurance-divide.pdf (Accessed: 11 March 2026).
Tuoitre News (2025) Tổng Bí thư Tô Lâm: Đột phá thể chế, pháp luật để đất nước vươn mình. Available at: https://tuoitre.vn/tong-bi-thu-to-lam-dot-pha-the-che-phap-luat-de-dat-nuoc-vuon-minh-20250504163313151.htm(Accessed: 11 May 2026).
Vietnam News (2018) ‘Vingroup completes first genome project for Vietnamese people’. Available at: https://vietnamnews.vn/brand-info/1107157/vingroup-completes-first-genome-project-for-vietnamese-people.html(Accessed: 11 March 2026).
