Control
AI serious incident not recorded, contained and reported to the authority
An organisation that develops, provides or deploys an AI system recognises serious incidents caused by it, records them, contains or suspends the system, preserves the logs and data, and reports to the competent authority within the statutory window, with a later official report on the remedy.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Reach
Law in force in VN.
Trust and provenance
How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.
- This control
- Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
- Lanes
- Binding law — in force 1
- Verification
- Sources last verified 3 Oct 2026; each provision states how.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
- Audit standard
- 1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
- 1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
The guard to add
Keep an AI serious-incident runbook that classifies incidents by the statutory definition, runs the reporting clocks and preserves the logs.
An incident-response runbook section owned by the AI product's operations or safety lead, reviewed when the system, its monitoring or the governing law changes. It lists the serious-incident classes as the statute words them, names who confirms that an incident has occurred and likely stems from the AI system, starts the clock at that point, and gives the recipient authority, the channel or portal, the report form and fields, the preliminary and official report deadlines, and the step that freezes and keeps the system logs, inputs and outputs for the incident. Deployers and users of the system have a documented way to tell the provider. In code, the alerting and severity taxonomy route a candidate incident to that runbook with the timers attached, and the log store keeps the incident's records from rotation.
Where it goes: 12 repository artifacts, 10 logs and telemetry.
What reviewers look for: a maintained runbook (for example docs/incident-response/ai-serious-incidents.md) with the statutory classes, the clocks, the recipient and channel, the report forms and the log-preservation step; a severity class for AI serious incidents in the alerting or on-call configuration; a record of reports filed.
Organizational control: the evidence is a kept record, its owner and its upkeep, not code.
Example (Incident severity taxonomy), before:
severities:
sev1: {page: oncall, examples: [outage, data_breach]}After:
severities:
sev1: {page: oncall, examples: [outage, data_breach]}
ai_serious_incident:
classes: [death_or_serious_injury, significant_property_damage, serious_rights_infringement, essential_service_or_security_disruption]
page: [ai-safety-lead, legal]
timers: {preliminary_report: 72h_or_5_working_days, official_report: 15d_after_preliminary}
on_open: [freeze_logs, snapshot_inputs_outputs]
runbook: docs/incident-response/ai-serious-incidents.mdEngineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
Every rule this guard addresses
Binding law — in force (1)
- VN
- Serious AI incidents must be recorded, contained and reported within 72 hours or 5 working days (Vietnam AI Law and Decree 142) Luật Trí tuệ nhân tạo, Điều 12 khoản 1-2 (quản lý và xử lý sự cố)
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.