Vietnam Law on Digital Technology Industry
Framework law covering the digital technology industry, semiconductors, digital assets and AI, with risk-based AI classification, labelling of AI products and incentives for domestic development.
| Jurisdiction | Vietnam |
|---|---|
| Category | AI Regulations |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
Vietnam’s Law on Digital Technology Industry No. 71/2025/QH15 (often called the Digital Technology Industry Law – DTI Law) is a comprehensive framework for digital technology, semiconductors, digital assets and AI, with risk‑based AI regulation, labelling obligations, and strong incentives for domestic development, effective 1 January 2026. According to the official text and government/industry analyses, many AI‑specific provisions are now partially superseded or complemented by Vietnam’s standalone Artificial Intelligence Law No. 134/2025/QH15, effective 1 March 2026, but the DTI Law remains central for the broader digital technology and digital assets ecosystem.
Below is a structured analysis based on the DTI Law as described in official and expert sources, with explicit links. Where interaction with the newer AI Law is relevant, this is noted and linked.
Key Requirements
1. Scope and Objectives
- Comprehensive coverage of digital technology, semiconductors, digital assets and AI
- The DTI Law explicitly “provides for the development of the digital technology industry, semiconductor industry, artificial intelligence, digital assets, and the rights and responsibilities of relevant agencies, organizations, and individuals.”
- Full English translation – Law on Digital Technology Industry No. 71/2025/QH15 (PDF)
- LuatVietnam English summary – Law on Digital Technology Industry 71/2025/QH15
- Vietnam Briefing – Overview of Law on Digital Technology Industry
- Effective date and implementation timeline
- The law was passed on 14 June 2025 by the 15th National Assembly and takes effect on 1 January 2026.
- Vietnam Briefing – Passed June 14, 2025; effective January 1, 2026
- HKTDC – New Digital Technology Law for Digital Assets and AI Use
- LuatVietnam English summary – effective date
2. AI Principles and General Obligations
- Human‑centric, rights‑respecting AI
- The law establishes detailed principles for developing, providing and implementing AI, including:
- Serving human prosperity and happiness, adopting human‑centered methods.
- Ensuring inclusive, fair, non‑discriminatory access and respecting human rights, citizens’ rights and legitimate rights of organizations and individuals.
- Ensuring transparency, accountability, explainability, and that AI does not exceed human control.
- Ensuring cyber safety and security.
- Ensuring compliance with data laws and personal data protection.
- Ensuring the capacity to control AI algorithms and models and control risks across the AI system lifecycle.
- Ensuring compliance with consumer protection law.
- Official DTI Law text – AI principles (Chapter IV, Section on AI)
- LinkedIn legal analysis – “Vietnam's Digital Technology Industry Law”
- Morrison Foerster – AI Library: Vietnam – DTI Law overview
- Prohibited AI practices
- The law prohibits certain AI uses, including AI systems that:
- Manipulate users without their awareness.
- Rank or score people based on social behavior (“social scoring”).
- Exploit vulnerable individuals (e.g., children, persons with disabilities).
- HKTDC – summary of banned AI practices
- Morrison Foerster – discussion of AI‑related restrictions
- Legal briefing – AI regulations in Vietnam (Draft DTI Law, later finalized)
3. Risk‑Based AI Classification
- Risk levels and high‑risk AI definition
- The DTI Law (following the Draft DTI Law structure) classifies AI systems based on risk, separating high‑risk AI from other AI systems, using criteria such as potential impact on health, rights, safety, and critical infrastructure.
- Asia & Data Protection Newsletter – Draft DTI Law AI risk classification
- Digital Policy Alert – Draft DTI Law risk‑based AI classification
- Vietnam Briefing – DTI Law’s risk‑based approach to AI
- Obligations for high‑risk AI
- High‑risk AI systems must comply with stringent technical standards, safety and quality requirements, and may be subject to enhanced oversight by competent authorities.
- Digital Policy Alert – obligations for high‑risk AI in draft DTI Law
- Asia & Data Protection Newsletter – compliance obligations for high‑risk AI
- Morrison Foerster – overview of sector‑specific frameworks, including AI controls
4. Labelling of AI‑Generated Products
- Mandatory AI labelling requirements
- The framework requires AI‑generated digital products (e.g., images, audio, video, text) to be labelled in a machine‑readable format to indicate artificial creation or manipulation, based on guidelines from the Ministry of Information and Communications (MIC).
- Digital Policy Alert – AI‑generated digital product labelling
- Asia & Data Protection Newsletter – labelling obligations for AI systems and outputs
- HKTDC – description of AI product labelling and consumer protection
5. Incentives for Domestic Development
- Tax, land, credit and R&D incentives
- The DTI Law introduces strong incentives to promote digital technology, semiconductors and AI, including:
- Tax incentives (including personal income tax exemptions in certain roles).
- Incentives for investments in data centres and semiconductor facilities.
- Support for research, testing, development, production of digital technology products and services.
- Preferential treatment in public procurement to promote domestic technology products.
- HKTDC – incentives for digital technology, AI, semiconductors
- Vietnam Briefing – state policies and incentives under the DTI Law
- Morrison Foerster – DTI Law state policies, procurement preferences, and incentives
6. Digital Assets and Cybersecurity Obligations
- Digital assets regulation and AML/CTF
- The DTI Law establishes rules for digital assets, including measures to prevent money laundering, terrorist financing, and funding weapons of mass destruction, requiring appropriate cybersecurity and compliance controls.
- HKTDC – digital assets provisions and AML/CTF requirements
- Morrison Foerster – DTI Law coverage of digital assets
- LuatVietnam – law scope including digital assets
7. Regulatory Sandboxes and Experimental Mechanisms
- Controlled testing (“sandbox”)
- The law provides mechanisms for controlled testing and sandboxes for innovative digital products and services, including AI, enabling deployment in a monitored environment with specific risk controls.
- Digital Policy Alert – sandbox for new digital products and AI
- Morrison Foerster – controlled testing (“sandbox”) provisions in DTI Law
- HKTDC – sandbox mechanisms under the Digital Technology Law
Compliance Challenges
1. Navigating Overlap Between DTI Law and standalone AI Law
- Multi‑layered framework and superseding provisions
- Vietnam has adopted a standalone Artificial Intelligence Law No. 134/2025/QH15 effective 1 March 2026, which supersedes and replaces the general AI provisions in the DTI Law and consolidates AI oversight under a unified framework.
- IAPP – Vietnam’s first standalone AI Law and impact on DTI Law
- Baker McKenzie – “Artificial Intelligence Law – Foundation and Outlook”
- Tilleke & Gibbins – Vietnam’s multi‑layered AI development framework
- Compliance challenge: Organizations must map obligations under the DTI Law (for digital technology and digital assets) and under the AI Law (for AI systems) to avoid gaps or duplication, which is a common challenge cited in legal briefings.
- Tilleke & Gibbins – description of overlapping frameworks
- IAPP – need for alignment with multiple instruments
- AI regulations in Vietnam – LNT & Partners
2. Implementing Risk‑Based AI Classification
- Complexity of risk assessment and self‑classification
- Industry analyses note that risk‑based AI classification is difficult in practice: organizations must evaluate potential harms to rights, safety, health, and infrastructure for each AI application, and, under the AI Law regime, self‑classify and notify authorities for medium/high‑risk systems.
- TechPolicy.Press – obligations for AI companies to self‑classify risk levels
- Asia & Data Protection Newsletter – complexity of risk definitions and criteria
- Digital Policy Alert – risk‑based AI classification under DTI Law draft
- Example challenge: Companies with multi‑purpose AI models (e.g., general‑purpose AI used across several domains) struggle to determine whether any deployment context triggers high‑risk obligations, which is a concern raised in comparative AI law commentary.
- TechPolicy.Press – analysis of challenges for AI companies in Vietnam
- IAPP – overview of implications for AI developers and deployers
- Tilleke & Gibbins – multi‑layered framework and compliance burdens
3. Labelling and Technical Implementation
- Implementing machine‑readable labelling of AI outputs
- Compliance requires technical changes to content pipelines (e.g., watermarking, metadata tags) for AI‑generated content to meet MIC guidelines; industry commentary highlights implementation cost and interoperability issues.
- Digital Policy Alert – requirement to label AI‑generated digital products
- Asia & Data Protection Newsletter – technical labelling obligations
- TechPolicy.Press – mandatory labelling for images, video, audio
- Example: Media and platform providers must integrate labelling logic into content production and distribution systems; this is a common challenge highlighted in discussions of AI output labelling globally and applied to Vietnam’s regime.
- TechPolicy.Press – obligations for providers and deployers to label AI outputs
- IAPP – overview of transparency and labelling provisions in Vietnam’s AI framework
- Digital Policy Alert – machine‑readable labelling requirement
4. Aligning With Data Protection and Cybersecurity Laws
- Cross‑compliance with data, personal data protection and cybersecurity law
- The DTI Law requires compliance with personal data protection and data laws, and cyber safety and security, meaning organizations must align with Vietnam’s data protection decrees and cybersecurity legislation in parallel.
- Official DTI Law – principle of compliance with data and personal data protection law
- HKTDC – cybersecurity measures to prevent AML/CTF abuses
- Asia & Data Protection Newsletter – cross‑references to data protection
- Challenge: Multinational companies must harmonize Vietnam‑specific requirements with their global privacy and security frameworks, which legal briefings note as a significant compliance burden.
- Tilleke & Gibbins – multi‑layered regulatory environment
- LNT & Partners – AI regulations and opportunities for investors
- IAPP – future implications for compliance programs
Implementation Best Practices
1. Establish an Integrated AI & Digital Technology Governance Program
- Create unified governance covering DTI Law + AI Law
- Best practice is to implement one internal framework that maps requirements under the DTI Law and the AI Law, including risk categorization, labelling, data protection and cybersecurity. Legal advis
Recent developments
- — Vietnam Briefing’s updated coverage explains that the Law on Digital Technology Industry took effect on 2026-01-01 and highlights AI compliance obligations, including high-risk categorization, technical standards, and transparency labeling. It remains a useful reference for businesses tracking implementation details. (source)
- — This legal update describes Vietnam’s transition from broad digital technology rules to a more detailed AI compliance regime, noting that the Digital Technology Industry Law’s AI framework is now being applied alongside later AI-specific rules. It emphasizes practical compliance steps for companies operating in Vietnam. (source)
- — Baker McKenzie’s analysis says the AI-specific legal framework now complements the earlier Digital Technology Industry Law, with the newer AI law taking the lead on risk-based oversight. The article is important because it explains how the Digital Technology Industry Law’s AI provisions fit into the broader regulatory architecture. (source)
- — Duane Morris’ update explains that AI systems in sensitive sectors may benefit from phased compliance periods, with different grace periods depending on the sector. This matters for industry because it affects timing, budgeting, and product rollout decisions. (source)
- — Recent commentary suggests industry reaction is focused on compliance burden, especially around labeling, risk classification, and conformity assessment. At the same time, legal advisers note the law also provides clearer rules and a more predictable framework for AI businesses. (source)
- — This article says Vietnam requires AI providers to self-classify products by risk level and label AI-generated images, video, and audio. It reflects industry concern that Vietnam is trying to balance innovation with tighter state oversight. (source)
- — This update points to the broader regulatory shift around AI implementation in Vietnam, which affects how the earlier Digital Technology Industry Law is being operationalized. The practical impact is that companies now need to align product governance, documentation, and risk controls across overlapping rules. (source)
- — This investor-focused update says AI systems must be classified as high, medium, or low risk before deployment, and that high-risk systems require conformity assessment. It underscores the commercial impact of the law on companies planning to launch AI products in Vietnam. (source)
- — This piece frames Vietnam’s AI rules as a major regulatory milestone and highlights business implications for foreign investors and tech firms. It suggests the Digital Technology Industry Law is already shaping market entry and compliance planning. (source)
- — A July update summarizes Vietnam’s Digital Technology Industry framework for AI, including a risk-based classification system, machine-readable labeling for AI-generated digital technology products, and ethical guidance expected from the Ministry of Information and Communications. The update is one of the clearest recent summaries of how the law’s AI provisions are being interpreted in practice. (source)
Related regulations
- Law on Cybersecurity of Vietnam — Vietnam, Active
- Vietnam Personal Data Protection Law (Law No. 91/2025/QH15) — Vietnam, Active, effective 2026-01-01
- Vietnam Law on Artificial Intelligence — Vietnam, Active, effective 2026-03-01
- Brazilian Artificial Intelligence Act — Brazil, Proposed
- NIST AI Risk Management Framework (AI RMF 1.0) — United States, Active, effective 2023-01-26
- Artificial Intelligence and Data Act — Canada, Superseded
- Colorado Artificial Intelligence Act (SB 24-205) — Colorado, Superseded, effective 2026-06-30
- Texas Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149) — Texas, Active, effective 2026-01-01
Put it into practice
- Generate the policy: Vietnam cybersecurity policy generator (generatepolicy.com)
- Buy the policy pack: Privacy Program Bundle (cyberpolicy.shop)
- Build it yourself: GDPR & DPIA Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates