Artificial intelligence is now embedded in daily business operations, from customer-facing chatbots to automated credit scoring and AI-generated marketing content. Regulators are responding. Vietnam has become the first ASEAN member state to enact a dedicated AI law, effective 1 March 2026.
If your organization operates in or sells into Vietnam, this law may apply to you directly. If you operate in the Philippines, it is a preview of the regulatory direction across Southeast Asia. Either way, now is the time to assess your exposure.
What you'll find in this article
- 1. What Is Vietnam’s AI Law?
- 2. “We Only Use ChatGPT or Claude.” Does the Law Still Apply?
- 3. Compliance Deadlines
- 4. Your Compliance Roadmap: 6 Steps to Take Before the Deadline
- 5. The Cost of Non-Compliance
- 6. Why ISO/IEC 42001 Belongs in Your AI Governance Strategy
- 7. Is the Philippines Next?
- 8. Join Our Webinar: Vietnam Just Regulated AI. Is the Philippines Next?
What Is Vietnam’s AI Law?
Vietnam’s AI law follows a risk-based regulatory framework: the greater the potential harm an AI system can cause, the stricter the obligations placed on the organizations behind it. The approach will be familiar to anyone who has followed the EU AI Act, but it is now taking hold within ASEAN.
Every AI system falls into one of three risk tiers.
1. Low-risk AI
Internal tools and basic automation fall here. Obligations are minimal and largely self-managed, though organizations must keep basic records and be able to explain how the system is used.
2. Medium-risk AI
This covers chatbots, AI-generated content, and any customer-facing system that could be mistaken for a human or for authentic content. These systems must disclose that users are interacting with AI and label AI-generated audio, image, and video content. This is the law’s anti-deepfake and synthetic media safeguard.
3. High-risk AI
Systems that make or influence decisions affecting safety, health, finance, legal rights, and similar areas fall here. They face the heaviest requirements:
- Conformity assessment and certification before launch
- Registration in the national AI database
- Documented risk management and event logging
- Mandatory human oversight
- A legal presence or authorized representative in Vietnam for foreign suppliers
“We Only Use ChatGPT or Claude.” Does the Law Still Apply?

Yes, potentially. The law assigns responsibilities across the AI value chain. Whether your organization is a developer, a supplier (including those who resell or rebrand AI), or a deployer (an organization that uses AI in its operations), you have defined duties. One company can hold several roles across different tools.
Using a third-party large language model (LLM) does not exempt you. Once AI output reaches your customers or influences your business decisions, disclosure and accountability obligations are likely to follow. Many organizations assume they are out of scope because they did not build the technology. That assumption is the most common compliance gap.
Compliance Deadlines
Vietnam has provided a transition period, and it applies to AI systems already operating before 1 March 2026:
| Sector | Compliance deadline |
| Most industries | March 2027 |
| Health, education, finance | September 2027 |
The grace period should not be read as a safe harbor. Authorities can suspend or recall an AI system during this window if it is deemed a serious risk.
Your Compliance Roadmap: 6 Steps to Take Before the Deadline
- Identify your role. Determine whether you are a developer, supplier, or deployer for each AI system.
- Classify each system by risk tier. Assess what the system does and who it affects. Misclassification is itself a legal risk under the law.
- Meet your tier’s obligations.
- Low-risk: maintain basic records and be ready to explain your use of AI.
- Medium-risk: disclose AI interaction and label synthetic content.
- High-risk: complete conformity certification, register in the national database, maintain risk management documentation and logs, and ensure human oversight.
- Notify the Ministry of Science and Technology. Do this through the AI Portal before putting a system into use.
- Establish incident-reporting procedures with defined response timeframes.
- Build your documentation now. Technical documentation and audit trails must be available to inspectors on request.
The Cost of Non-Compliance
The penalties go beyond fines:
- Administrative fines
- Forced suspension or recall of the AI system, even during the grace period if the risk is judged serious
- Civil liability. A deploying company may owe damages if a high-risk system causes harm, even when it followed the rules. It may then seek reimbursement from the developer or supplier.
- Criminal liability for serious violations
- Reputational and operational damage, including loss of the ability to run the system and blacklisting from the national database
Why ISO/IEC 42001 Belongs in Your AI Governance Strategy
Regulatory compliance should not be a box-ticking exercise. ISO/IEC 42001, the international standard for an AI Management System (AIMS), provides a structured, auditable framework for responsible AI governance. It covers risk assessment, accountability, lifecycle management, and continual improvement. Aligning your compliance program with ISO/IEC 42001 gives you a recognized foundation that supports multiple regulatory regimes, and it builds credibility with customers, partners, and auditors.
Is the Philippines Next?

The Philippines does not yet have a comprehensive AI law, though AI-related bills have been under discussion in Congress. Vietnam’s move shows the direction regional regulation is heading: risk-tiering, transparency requirements, and clear accountability across the AI supply chain. Organizations that build governance capability today will adapt faster when local regulation arrives. They will also be better prepared to serve cross-border clients and operate across ASEAN.
Join Our Webinar: Vietnam Just Regulated AI. Is the Philippines Next?
Learn what ASEAN’s first AI law means for your business and how to get ready, directly from the experts at APEX.
📅 Date: Tuesday, October 13, 2026
🕑 Time: 2:00–3:00 PM PHT
With enforcement dates approaching, early preparation is the lowest-cost path to compliance.