Vietnam’s AI Decree 142/2026 and Foreign AI Providers

IP

Introduction : This can be achieved by buying a cloud API on the internet, getting a Vietnamese client to insert a chatbot or even deploying the scoring model on servers that are not located in Vietnam. The newly developed AI technology in Vietnam will be tasked with monitoring activities, instead of monitoring companies’ addresses. As of March 1, 2026, all Vietnamese and foreign organizations or individuals involved in any AI related activities in Vietnam are bound by the law No. 134/2025/QH15 on Artificial Intelligence (AI Law). These initial implementation guidelines are provided for by decree No. 142/2026/ND-CP.

While the apparent extraterritorial scope is established through the language above, there is no actual conflict of laws rule set up. It is not defined in Article 2 when an overseas service would be considered an “activity in Vietnam.” No targeting, establishment, effects or revenue test is contained therein. However, in Decree 142, there is an affirmation of the wide scope but there is no indication if a foreign supplier providing a Vietnam subsidiary from its regional base or dealing directly with Vietnamese consumers will always be caught. It seems more logical to be practical in this case and expect compliance from a vendor of AI technology if he decides to make this product available to Vietnam, localize it for Vietnamese consumers, contract with Vietnamese customers, or assist Vietnamese deployers.

Legal Framework and Reported Extraterritorial Reach

Regulated Roles

There are some distinctions made regarding the developer, provider, deployer, user, and the affected individual in the AI Law. It doesn’t matter whether it was developed by itself or was purchased from another developer; the provider refers to the entity that markets or makes use of an AI system under its own brand, trade name, or trademark. Even when the Indian brand owner will be the supplier, the Vietnamese firm deploying the Indian design might be the deployer. If that’s not the case in reality, then the contractual names should not be considered.

What Article 2 Does and Does not Do

The most substantial justification for offshore application is textual, as foreign entities engaged in AI activities in Vietnam fall under the purview of this law. The framework is applicable to research, development, provision, implementation, and utilization. Hence, a foreign provider cannot think that the lack of any of these factors, such as incorporation, employees, or servers in Vietnam, will relieve it from being covered by the law. On the other hand, any responsible interpretation needs to distinguish between the issue of whether an entity falls within the scope of the law and its enforceability.

The Vietnamese language version of interfaces or pricing contracts for Vietnam, onboarding, marketing, or support tailored specifically for Vietnam, Vietnamese resellers or implementers of the product, Vietnamese user data processing, and knowledge that the system is used for Vietnamese decision-making are some of the relevant nexus indicators applicable to an India-based company. This is not an established test but rather a list of danger signs. An example of an API paid for by a Vietnamese bank, hospital, school, job placement or government organization is more convincing than a demo for the world.

Risk Classification: The Gateway Obligation

There are three categories of legal risks employed by the regime. Great damage to life, health, legal rights and interests, interests of the community or nation, or national security may happen due to high-risk systems. As the users will not know that they are dealing with AI or that they are viewing content produced by AI, medium-risk systems could mislead, influence, or manipulate users. Those who fall into the remaining category are low-risk systems. Impact on rights, safety, and security, relevance to sector and general public, user base, and impact size are determinants.

Classification should precede the operation of any system. Classification documentation and notification for medium-risk and high-risk systems should be done before implementation and should notify the Ministry of Science and Technology (MoST) through the AI Single Window Portal. The portal is made to allow for regulatory disclosures, system identification codes, classification results, and incident reporting. In case of integration, modification, purpose change, or other relevant events and regulations that can elevate risk, Decree 142 should also be reviewed.

The highest control measures are initiated by the designation of risk as high-risk; however, throughout the time frame involved in the current legal discussion about the implementation period, the officially designated Prime Ministerial list, including that which is needed to be pre-certified before using it, has yet to be determined. The interactive assistants, chatbots, and the synthetic media tools are highly relevant to medium-risk designation. According to reports, Decree 142 relieves certain internal applications from the requirement of control; these exemptions require case-by-case examination.

Transparency and User-Facing Duties

Transparency comes in two tiers. First, direct interaction platforms have to be developed by the providers to make sure people realize that they interact with AI. Music, images, and video created by AI must also have machine readable tags put on them by providers, like digital signature, metadata, etc. Secondly, when AI-generated or altered material can mislead people into thinking that something is authentic, providers distributing the material must give a human-readable warning. Replicas of reality and simulating the appearance or voice of a real person have to be labelled.

The implementation of each layer by the overseas provider without regarding this as an attempt to circumvent any regulation needs to be spelled out in the contract. Technical marking capabilities, the guidance on integration, and the confirmation that provenance will stand up to standard export or platform procedures need to be delivered by the Indian supplier. The final placement of the notice, language, and context need to be controlled by the Vietnamese deployer. Instead of the generic “AI may be used” language, the product documentation and notices for the Vietnamese audience need to be meaningful.

Safety, Conformity, and Incident Response

Lifecycle risk management, ensuring appropriateness and quality of training, testing, and validation data, documenting technical information and operations records, enabling human supervision and control, communicating use and risk information, and assisting with inspection, post-audit, and remediation are all necessary activities for high-risk providers. Source code, complex algorithms, parameter sets, and trade and technological secrets need not be disclosed in explanations. High-risk products must be subject to conformity assessment prior to service provision and after major changes; the PM’s list determines when independent testing and certification is required rather than provider evaluation alone.

Decree 142 provides for serious incident reporting. In case of emergencies, the provider and the deployer, in the absence of the former, must file a preliminary report within 72 hours from the event through the AI portal, while for other serious incidents, a report must be filed within 5 working days. Corrective measures must be documented, logs and related information must be kept, and follow-up reports must be prepared. The 15-day follow-up schedule was stated in the latest note.

Thus, before deployment, a third party should create the escalation path specific to Vietnam, which will have 24/7 intake, the criteria for severity aligned with the serious incident legal definition, service suspension/restriction authority, ability to preserve evidence, bilingual document drafting capabilities, and a single point of decision-maker contact that can speak to the deployer and MoST. The operations response plan does not obligate parties to “notify promptly.

Local Compliance Contracts without a Vietnamese Company

There is a local connection in relation to international suppliers of high-risk systems supplied in Vietnam as provided for in the AI Law. Every one of the suppliers of the systems must have a genuine local representative in Vietnam. However, where the system falls under the subset requiring compulsory conformity certification before use, the supplier must have a commercial representation or a genuine local representative in Vietnam. The issues related to qualifications, authorities, form filling, liability sharing, and even the adherence to law by existing groups because Decree 142 has failed to provide sufficient clarity in relation to this foreign provider requirement.

This distinction is crucial. In view of future directions and local Vietnamese guidance, a valid contact point does not have to take the form of a new subsidiary, but may well be an entity available locally that can handle communications and compliance coordination. An agreement granting a designated representative access to notifications and communications related to compliance alerts, necessary documentation, portal submissions, compliance assessments, incident handling, and communication with both authorities and users must be prepared. In the absence of any clear guidance on authority, confidentiality, speed, and survival post-contract termination, the commercial contact of a reseller is not appropriate.

Subsection (6) of Article 14 does not impose such extensive local contact criteria on medium risk and low risk overseas service providers. This is because the need for local coordination would be required for matters relating to classification notices, complaints from users, management of incidents, data protection obligations, sector licenses, or agreements with the customer. Appointment is simply a governance measure, and does not by itself solve any of the above matters.

Practical Implications for Indian Lawyers

Compliance for businesses in India should not be seen as a one-off compliance document. The very same model may be deemed low-risk when used as a tool for drafting assistance internally, medium-risk when used as a public chatbot, and high-risk when used to make decisions about health, finance, education, employment, vital services, or rights. It all depends on the objective and utilization of the specific use case. Deployment control required for the use cases, due diligence for the customer, change notification, auditing, and logging, as well as collaboration in incidents and suspension, are all limitations of use cases.

The operational control will have to establish alignment between the commitment of Vietnam and governance of India. Cross-border movement and flow of information relevant to Vietnam, localization of user notices, evidencing classification, evaluation of behaviour of the model in Vietnamese language, documentation of the limitations of human supervision, and validation of downstream change triggering re-evaluation should be performed. In case of any uncertainty about the legal boundary, an official evaluation should be done according to the Vietnam laws.

Checklist

  1. Classify all Vietnam use cases, communities of users, customers, deployers, data flows, language capabilities, industries and decisions that are impacted by the system.
  2. Make sure you assign the statutory roles for developers, providers, deployers, users, resellers, and integration partners.
  3. In the event of distant, indirect or global supply, make sure to document the Vietnam element and consult with local legal counsel.
  4. Before the deployment of your system, classify it, create the portfolio for mid and high-risk systems and determine the triggers for reclassification.
  5. Conformity certification requirements must be checked before deployment based on the current high-risk list of the Prime Minister.
  6. Document the machine-readable provenance, notification of artificial intelligence interactions and labels for the synthetic materials in Vietnamese.
  7. Lifecycle risk management, data quality management, logging, human oversight, testing and change management for the high-risk systems.
  8. Multilingual incident reporting procedure, 5 working days fall back, evidence holding, suspension authority and 72 hours incident response procedure.
  9. If applicable to high-risk suppliers, provide a genuine contact person from Vietnam; in case of certification, set up a business entity or designate an agent.
  10. Coordinate contractual provisions concerning classification, notification, logging, audit, incident management, complaints, amendments, and regulatory cooperation with the deployers and resellers.
  11. Review the AI system together with laws on personal data protection, cybersecurity, consumers, intellectual property, sector-specific, tax, and foreign investment in Vietnam.
  12. Monitor technical requirements, sanctions, high-risk lists, activation of the MoST Portal, and all other directions; update the compliance document prior to major changes.

Conclusion

The Vietnamese model is geographically incomplete, but there is an extraterritoriality aspect to it. Although Article 2 does not provide any sort of specific test for services that can be accessed around the world, foreign status alone does not make an Indian entity ineligible under the service if that service is implemented or deployed in Vietnam. Identify the Vietnam element, classify the use cases, keep a file, build safety and transparency into the product, and design a locally accessible compliance regime before high-risk implementation.

Author:- Raj Ranjanin case of any queries please contact/write back to us at support@ipandlegalfilings.com or   IP & Legal Filing.

Endnotes

  1. National Assembly of the Socialist Republic of Viet Nam, Law No. 134/2025/QH15 on Artificial Intelligence, arts. 1–3, 8–10 (Dec. 10, 2025), effective Mar. 1, 2026. Article 2 expressly applies the Law to Vietnamese and foreign organisations and individuals participating in AI activities in Viet Nam, while Article 3 defines the roles of developer, provider, deployer, user and affected person.
  2. National Assembly of the Socialist Republic of Viet Nam, Law No. 134/2025/QH15 on Artificial Intelligence, arts. 9–10 (Dec. 10, 2025). The Law establishes a three-tier classification of AI systems—high-risk, medium-risk and low-risk—and requires providers to classify systems before putting them into service. Medium- and high-risk systems must be supported by classification documentation and notified through the National Single-Window Artificial Intelligence Portal.
  3. National Assembly of the Socialist Republic of Viet Nam, Law No. 134/2025/QH15 on Artificial Intelligence, arts. 11–15 (Dec. 10, 2025). These provisions address transparency obligations, including notice of AI interaction, machine-readable marking of AI-generated audio, image and video content, labelling of potentially misleading synthetic content, serious-incident handling, conformity assessment and obligations applicable to high-risk systems.
  4. Government of the Socialist Republic of Viet Nam, Decree No. 142/2026/NĐ-CP Detailing Certain Articles and Measures for Implementation of the Law on Artificial Intelligence (Apr. 30, 2026), effective May 1, 2026.The Decree provides detailed implementation measures concerning risk-based classification and conformity assessment of AI systems.
  5. Government of the Socialist Republic of Viet Nam, Decision No. 33/2026/QĐ-TTg, Promulgating the List of High-Risk Artificial Intelligence Systems (2026). The subsequently issued list identifies high-risk AI systems across areas including education, healthcare, banking, transport and judicial activities, making the current position more specific than the earlier stage of implementation described in the article.
  6. Government News of Viet Nam, “Viet Nam’s Law on Artificial Intelligence” (July 15, 2026). The official English publication reproduces the AI Law and is particularly useful for citing provisions concerning foreign providers, transparency, risk classification, serious incidents and the requirement under Article 14(6) for foreign providers of high-risk AI systems provided in Viet Nam to maintain a legal point of contact in Viet Nam, with additional commercial-presence or authorised-representative requirements where mandatory conformity certification applies.