Vietnam Law on Artificial Intelligence (No. 134/2025/QH15)
National Assembly; Government (Decree 142/2026); Prime Minister (Decision 33/2026) · VN · 6 provisions encoded · verified against the official source as of 2026-10-02.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 6 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 6.
Audit standard
6 of 6 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
11 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
2026.10.03.3 (3 Oct 2026): 6 provisions added
Each data release records which provisions changed; the full list is on Changes.
Binding law — in force
AI systems that interact directly with people must let users recognise they are dealing with AI (Vietnam AI Law)
Luật Trí tuệ nhân tạo, Điều 11 khoản 1 (nhận biết đang tương tác với hệ thống) · official text · In force: applies since 1 Mar 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027 · VN
Under Art. 11(1) of Vietnam's Law on Artificial Intelligence (No. 134/2025/QH15), a provider must ensure that an AI system that interacts directly with people is designed and operated so that users recognise they are interacting with the system, unless the law provides otherwise; providers and deployers must keep this transparency in place for as long as the system, product or content is provided (Art. 11(5)). Decree 142/2026 Art. 16 requires providers and deployers to give the notices, technical marks and visible labels of Art. 11, proportionate to the purpose, deployment context and risk level, and to give information on the system's purpose, scope, conditions of use and limits. A system that may confuse, influence or manipulate users because they cannot tell they are dealing with AI is medium-risk (Art. 9(1)(b); Decree Art. 9(1)), and medium-risk providers and deployers must ensure Art. 11 transparency (Art. 15(1)(a)). In force 2026-03-01; systems already in operation before then must comply by 2027-03-01, or 2027-09-01 in health, education and finance (Art. 35). Detect a chat or voice interface with no AI notice at the start of the interaction, or instructions that tell the model to hide that it is AI.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 1 Mar 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027
Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
3 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Prompts stored in a database or prompt-management service outside the repository
Fiction or role-play features where the user set up the persona may need human judgement; Art. 11(1) still requires that the user can recognise the AI.
Notice shown by a third-party chat widget configured outside the repository
3 more known limits in the data release.
Who it applies to
Duty falls on: provider, deployer
Providers of AI systems that interact directly with people in Vietnam, Vietnamese or foreign (Arts. 2, 3(4), 11(1)); providers and deployers keep the transparency in place (Art. 11(5)). In force 2026-03-01; systems in operation before then by 2027-03-01, or 2027-09-01 in health, education and finance (Art. 35). Whether Art. 11(1) also binds systems that Decree 142 Art. 9(3) keeps out of the medium-risk class (for example office tools whose AI nature is clear from context) is for counsel (review flag).
Not covered:
AI activities serving only national defence, security or cipher purposes are outside the Law (Art. 1(2))
Use of an AI system for personal, non-commercial purposes is not deployment (Art. 3(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.
Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.
What this provision adds:
Tell users, before or at the first interaction, that they are dealing with an AI system, and keep the indication in place for as long as the system is provided (Law Art. 11(1), (5)).
Give users information on the system's purpose, scope, conditions of use and limits (Decree 142 Art. 16(2)(b)).
Example (Next.js + Vercel AI SDK (useChat)), before:
const { messages, input, handleSubmit } = useChat({
api: '/api/chat',
initialMessages: [{ id: 'ai-notice', role: 'assistant',
content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant message
Control: AI chat interaction without disclosure. The same guard addresses 29 items with binding law in 22 jurisdictions. Engineering guidance, not legal advice.
Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id vn-ai-law.ai-interaction-notice · review status: primary source derived
Binding law — in force
AI-generated audio, images and video must carry a machine-readable mark (Vietnam AI Law and Decree 142)
Luật Trí tuệ nhân tạo, Điều 11 khoản 2 (đánh dấu ở định dạng máy đọc) · official text · In force: applies since 1 Mar 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027 · VN
Under Art. 11(2) of Vietnam's Law on Artificial Intelligence, a provider must ensure that audio, image and video content its AI system generates is marked in a machine-readable format as the Government prescribes. Decree 142/2026 Art. 17 sets the detail: the provider applies a technical solution so that audio, image or video output carries a machine-readable mark (text output is not required to be marked unless the law says otherwise) (17(1)); the mark may be embedded in the file structure or content data, in the file's metadata, by a digital or electronic signature or equivalent authentication, or by another technical solution that lets the content be identified as AI-created or edited (17(2)); it must state that the content was created or edited by an AI system and may add the provider, system and time (17(3)); marking must be kept through creation, export and provision within the functions the system controls (17(4)). Open-source or free systems are deemed compliant if marking is built in or the provider publishes tools, configurations, APIs or documentation for deployers to run it, and a deployer that uses such a system to provide content to the public must apply the marking (17(5)). Erasing or falsifying mandatory information, labels or warnings is prohibited (Art. 7(5)). In force 2026-03-01 (Decree detail from 2026-05-01; systems already operating: Art. 35). Detect generated audio, images or video saved or served with no machine-readable mark (C2PA, metadata, watermark).
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 1 Mar 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027
Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Marking applied by a CDN or media pipeline outside the repository
Presence of a metadata write does not prove the mark states AI generation
Marking may be applied in a shared post-processing module or by the model provider (confirm from provider documentation); text output is not required to be marked.
Who it applies to
Duty falls on: provider, deployer
Providers of AI systems that generate audio, images or video for use in Vietnam; deployers that use an open-source or free system to provide such content to the public (Decree 142 Art. 17(5)). In force 2026-03-01 with the Decree's detail from 2026-05-01; systems already in operation before 2026-03-01 by 2027-03-01, or 2027-09-01 in health, education and finance (Art. 35). Which reference standards satisfy Art. 17 is for the Ministry of Science and Technology to publish (17(6)); counsel confirms the reading of 'within the functions the system controls' (review flag).
Not covered:
AI activities serving only national defence, security or cipher purposes are outside the Law (Art. 1(2))
Use of an AI system for personal, non-commercial purposes is not deployment (Art. 3(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Mark every generated image, audio, video, or text output with machine-readable provenance, such as a signed C2PA manifest or watermark, before it is saved, served, or published.
In the generation service, a marking step sits between the generator call and every sink (image.save, s3.put_object, blob.upload, FileResponse, res.send, publish). Images, video, and audio get a signed C2PA manifest whose actions record digitalSourceType trainedAlgorithmicMedia, and where robustness matters an invisible watermark as well (imwatermark WatermarkEncoder, AudioSeal, SynthID) so the mark survives metadata stripping. Generated text carries provenance metadata in the API response or document, or a text watermark where the model provider offers one. Sinks accept only the marked artifact, and a test confirms the mark is present and detectable.
Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts.
What this provision adds:
Mark generated audio, images and video in a machine-readable way that states the content was created or edited by AI; the provider, system and time may be added (Decree 142 Art. 17(1)-(3)).
Keep the mark through creation, export and download, and never strip it on a re-encode (Decree 142 Art. 17(4); Law Art. 7(5)).
Example (diffusers + invisible-watermark + c2pa), before:
Rule id vn-ai-law.generated-media-machine-marking · review status: primary source derived
Binding law — in force
High-risk AI systems need risk management and working human supervision and intervention (Vietnam AI Law, Decree 142, Decision 33)
Luật Trí tuệ nhân tạo, Điều 14 khoản 1 (trách nhiệm của nhà cung cấp hệ thống có rủi ro cao) · official text · In force: applies since 15 Aug 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027 · VN
For AI systems on the Prime Minister's list of high-risk AI systems (Decision 33/2026/QD-TTg, in force 2026-08-15; systems that may cause significant harm to life, health, rights and legitimate interests, national or public interests or security, Art. 9(1)(a)), Vietnam's Law on Artificial Intelligence requires the provider to set up and maintain risk-management measures and review them on significant change or new risk, govern training, test and operating data, design the system so people can supervise and intervene, meet the transparency and incident duties, give users and affected persons functional information, operating guidance and risk warnings, and cooperate with authorities and deployers (Art. 14(1)(a), (b), (d), (đ), (e), (g)); the deployer must operate and supervise the system within its classified purpose and risk, ensure data safety and human intervention during use, and meet the transparency and incident duties (Art. 14(2)). Decree 142/2026 Art. 15 fixes the minimum risk-management system (identify risks to human rights, safety, security and public interest; data quality and representativeness; human supervision and intervention proportionate to risk; technical or management controls; review on significant change of model, data, operation or purpose), the information the provider gives deployers, and the deployer's monitoring, human-oversight and escalation duties, including limiting risk and notifying the provider and authority of a serious threat. Obstructing, disabling or falsifying human supervision, intervention and control mechanisms is prohibited (Art. 7(4)), and listed systems must ensure human supervision, control and intervention in operation (Decision 33 Art. 1(2)). The list covers education, ethnic and religious affairs, health, banking (including automated credit decisions), judicial proceedings and transport. Listed systems already in operation comply before 2027-09-01 (health, education, finance) or 2027-03-01 (others); systems put into operation within six months after 2026-08-15 by 2027-03-01 (Decision 33 Art. 4). Conformity assessment (Art. 13) and classification notice (Art. 10) are not encoded. Detect a listed system whose model output takes effect with no human review or override step.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Aug 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027
Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (code pattern, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Review performed in an operations console outside the repository
Statuses set through numeric codes or enums
Applies only to systems on the Decision 33 list under the entry's conditions; human review may sit in a separate queue service.
Providers and deployers of AI systems on the high-risk list (Decision 33/2026 Annex) used in Vietnam, from 2026-08-15; listed systems already operating before then, or put into operation within six months after it, follow the Decision 33 Art. 4 deadlines (2027-03-01; 2027-09-01 in health, education and finance). Whether a system meets an Annex entry's conditions, including the State Bank's value levels, is for counsel and the business (review flag).
Not covered:
AI activities serving only national defence, security or cipher purposes are outside the Law (Art. 1(2))
Use of an AI system for personal, non-commercial purposes is not deployment (Art. 3(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Put human supervision and a per-decision explanation record between high-impact model output and the action it triggers, backed by a documented risk-management plan.
On the high-impact path (credit, hiring, healthcare, essential services), model output becomes a pending decision rather than an action: a person can approve, override, or stop it (review queue with override, LangGraph interrupt, a kill switch checked before acting). Each decision stores the final result, the main criteria or reason codes, the model version, and the reviewer, and an explanation endpoint returns that record to the affected user. Alongside the code, keep the risk-management plan, user-protection measures, an overview of the training data used for explanations, and documentation of these measures in the repository.
Where it goes: 9 AI output handling, 15 agent action surface, 2 data models, 12 repository artifacts.
What this provision adds:
Review and update the risk-management measures when the model, data, operating mode or purpose changes significantly (Decree 142 Art. 15(2)(đ)).
Never ship a way to bypass, disable or falsify the human supervision and intervention controls (Law Art. 7(4)).
Example (Python + scikit-learn), before:
score = model.predict_proba([features])[0][1]
status = 'approved' if score > 0.7 else 'denied'
applications.save(app_id, status=status)
After:
if settings.HIGH_IMPACT_AI_PAUSED: # kill switch
raise ServiceUnavailable('automated scoring paused')
score = model.predict_proba([features])[0][1]
proposed = 'approved' if score > 0.7 else 'denied'
decisions.insert(app_id=app_id, proposed=proposed, score=score,
reason_codes=top_reason_codes(features, k=3), model_version=MODEL_VERSION,
status='pending_review')
# applications.save runs from the reviewer's approve/override handler
Rule id vn-ai-law.high-risk-risk-management-and-human-oversight · review status: primary source derived
Binding law — in force
High-risk AI systems must keep a technical dossier and operating logs (Vietnam AI Law and Decree 142)
Luật Trí tuệ nhân tạo, Điều 14 khoản 1 (trách nhiệm của nhà cung cấp hệ thống có rủi ro cao) · official text · In force: applies since 15 Aug 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027 · VN
For AI systems on Vietnam's high-risk list (Decision 33/2026, from 2026-08-15), the provider must prepare, update and keep a technical dossier and operating logs (nhật ký hoạt động) to the extent needed for conformity assessment and post-market checks, and give them to the competent authority on a necessity and proportionality basis without exposing trade secrets (Law on AI Art. 14(1)(c)). Providers and deployers must keep information and documents for inspection (Decree 142/2026 Art. 16(2)(c)) and, after a serious incident, keep the system logs, data and information about it for verification and remedy (Decree Art. 19(4)). Deadlines for listed systems already in operation follow Decision 33 Art. 4 (2027-03-01; 2027-09-01 in health, education and finance). Detect a listed system whose model decisions take effect with no event or decision log.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Aug 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027
Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Platform-level request logging that records model inputs and outputs outside the repository
Logging may be done by middleware, an API gateway or a tracing sidecar; confirm before reporting. Applies to listed systems only.
Providers of AI systems on the high-risk list (Decision 33/2026 Annex) used in Vietnam, from 2026-08-15 (Decision 33 Art. 4 deadlines for systems already operating); providers and deployers keep incident logs after a serious incident (Decree 142 Art. 19(4)). How long logs must be kept is not stated in the captured text (review flag).
Not covered:
AI activities serving only national defence, security or cipher purposes are outside the Law (Art. 1(2))
Use of an AI system for personal, non-commercial purposes is not deployment (Art. 3(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Write a structured event record for every inference and decision of the high-risk system (when, model version, input reference, output, operator) to a log store with explicit retention.
An audit event emitted automatically by the service at the decision boundary, where model output becomes a status change, score, or response, rather than left to callers: decision_id, timestamp, model and resolved model_version, an input reference (a pointer rather than raw personal data where possible), the output, the operator or user identity, and any human verification. Events go to a central store (CloudWatch Logs, Log Analytics, Cloud Logging, Loki) whose retention is set explicitly in IaC, not left to a console default, and monitoring queries over those events flag risk situations and drift.
Where it goes: 1 application source code, 4 infrastructure-as-code, 10 logs and telemetry.
What this provision adds:
Keep operating logs and the technical dossier current with each significant change, and retain the logs, data and information about any serious incident (Law Art. 14(1)(c); Decree 142 Art. 19(4)).
Example (Python + OpenAI SDK + structlog), before:
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
Court compelled discovery on how nH Predict works (2026-03-09; confirmed). A federal magistrate judge in the District of Minnesota ordered UnitedHealth to produce documents on how nH Predict works, including whether it was designed to supplant physician decision-making. Plaintiffs needed litigation discovery to learn how the model was designed and used. Source: U.S. District Court, D. Minn. (Order, Doc. 162) · evidence grade: primary · cited by Record enough at decision time to reproduce and explain every consequential AI decision
Rule id vn-ai-law.high-risk-technical-records-and-logs · review status: primary source derived
Binding law — in force
Deployers must label AI content that imitates real people or events, and flag AI content that could mislead (Vietnam AI Law and Decree 142)
Luật Trí tuệ nhân tạo, Điều 11 khoản 3 (thông báo nội dung có khả năng gây nhầm lẫn) · official text · In force: applies since 1 Mar 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027 · VN
Under Art. 11(3) of Vietnam's Law on Artificial Intelligence, a deployer must clearly notify the public when it provides text, audio, images or video created or edited by an AI system that may cause confusion about the authenticity of events or persons, unless the law provides otherwise; and under Art. 11(4) it must ensure that AI-created or AI-edited audio, images or video that simulate a real person's appearance or voice, or recreate real events, carry an easily recognisable label that distinguishes them from real content (films, art and creative works in a suitable manner that does not obstruct display or enjoyment). Decree 142/2026 Art. 18 sets the detail: the notice and label must be clear, easy to understand and notice, given before or at the time the recipient accesses the content, not designed to hide or weaken recognition, suited to the content and channel, and must not significantly obstruct its display (18(3)); they may be shown on the content, in its title, description or caption, on the platform interface, or by audio (18(5)); creative works may carry them at the opening, end, credits or accompanying material (18(6)). No label is needed for technical quality edits, for spelling, grammar, summary, paraphrase or translation tools that keep the meaning, for internal use, or for research in a controlled environment not released to the public (18(4)). Erasing or falsifying mandatory labels is prohibited (Art. 7(5)). Detect face swap, voice cloning or lip-sync output published with no visible AI label.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 1 Mar 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027
Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Labels added in a video editor or caption template outside the repository
The label may be added by the front end or the publishing service; internal and controlled-research use is exempt (Decree 142 Art. 18(4)(c)-(d)).
Who it applies to
Duty falls on: deployer
Deployers (organisations and individuals using an AI system under their control in professional, commercial or service activity, Art. 3(5)) that provide AI-created or AI-edited content to the public in Vietnam. In force 2026-03-01 with the Decree's detail from 2026-05-01; Art. 35 transition for systems already in operation. When content 'may cause confusion about authenticity' (Art. 11(3)) and when an edit only improves quality (Decree Art. 18(4)(a)) need counsel's reading of the Vietnamese terms (review flag).
Not covered:
AI activities serving only national defence, security or cipher purposes are outside the Law (Art. 1(2))
Use of an AI system for personal, non-commercial purposes is not deployment (Art. 3(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Attach a visible 'AI-generated or manipulated' disclosure to face-swapped, voice-cloned, or likeness-generated media on every path that publishes or returns it.
In the handler that publishes or serves the output of a face-swap, voice-clone, lip-sync, or likeness model, add the disclosure to the content itself (an overlay or caption on image and video, a spoken or on-screen statement for audio) and to the post text where it is published; the publish function refuses media that lacks the disclosure. In an evidently artistic or satirical work the disclosure can be adapted so it does not spoil the work, but it is still present. Pair it with machine-readable marking so the label survives re-sharing.
Where it goes: 9 AI output handling, 1 application source code, 14 user-facing text.
What this provision adds:
Show the notice or label before or at the moment the person accesses the content, clearly and in a way that is not hidden or minimised (Decree 142 Art. 18(3)(a)-(c)).
Place it on the content, in its title, description or caption, on the platform interface, or as an audio notice; for creative works, at the opening, end or credits (Decree 142 Art. 18(5)-(6)).
Control: Deepfake content not disclosed. The same guard addresses 3 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.
Rule id vn-ai-law.misleading-content-notice-and-likeness-label · review status: primary source derived
Binding law — in force
Serious AI incidents must be recorded, contained and reported within 72 hours or 5 working days (Vietnam AI Law and Decree 142)
Luật Trí tuệ nhân tạo, Điều 12 khoản 1-2 (quản lý và xử lý sự cố) · official text · In force: applies since 1 Mar 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027 · VN
Under Art. 12 of Vietnam's Law on Artificial Intelligence, developers, providers, deployers and users of an AI system must keep it safe and reliable and promptly detect and remedy incidents that may harm people, property, data or social order; when a serious incident occurs (an event that causes or risks significant damage to life, health, human rights, property, cybersecurity, public order or the environment, or disrupts critical national-security information systems, Art. 3(8)), the developer and provider must urgently apply technical measures to fix, suspend or withdraw the system and notify the competent authority, and the deployer and user must record and promptly report it and cooperate (Art. 12(2)); reporting runs through the one-stop AI portal (Art. 12(4)). Decree 142/2026 Art. 19 sets the detail: serious incidents are those causing loss of life or serious injury, significant property damage, serious infringement of rights, or serious disruption of public or essential services or national security and order (19(1)); deployers and users record the incident, limit its effects and notify the provider; providers apply technical measures (19(2)); the provider or deployer files a preliminary report (form AI01a or AI01b) within 72 hours of confirming an incident under 19(1)(a) or (d) or an uncontrollable 19(1)(c) incident, and within 5 working days for the rest, counted from when there is enough initial information that the incident occurred and likely stems from the AI system, without waiting for a full investigation (19(3)); and they keep the system logs, data and information about the incident and send the official remediation report within 15 days of the preliminary report (19(4)). Detect a missing incident procedure for AI serious incidents with the Vietnamese classes, clocks, forms and log preservation.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 1 Mar 2026; a further phase applies from 1 Mar 2027, 1 Sep 2027
Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 9 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Code cannot show this item: the evidence is a kept record or process.
Who it applies to
Duty falls on: developer, provider, deployer
Developers, providers and deployers of any AI system in Vietnam (users too, outside TwinEthos's scope), whatever its risk level (Art. 12), from 2026-03-01, with the Decree's clocks and forms from 2026-05-01; the Art. 35 transition applies to systems already in operation. Where an incident is also reportable under cybersecurity, personal data or sector law, it is reported under that law (Decree 142 Art. 19(5), not stored). Whether an incident 'likely stems from' the AI system and when it is 'confirmed' are for counsel (review flag).
Not covered:
AI activities serving only national defence, security or cipher purposes are outside the Law (Art. 1(2))
Use of an AI system for personal, non-commercial purposes is not deployment (Art. 3(5))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.
Keep an AI serious-incident runbook that classifies incidents by the statutory definition, runs the reporting clocks and preserves the logs.
An incident-response runbook section owned by the AI product's operations or safety lead, reviewed when the system, its monitoring or the governing law changes. It lists the serious-incident classes as the statute words them, names who confirms that an incident has occurred and likely stems from the AI system, starts the clock at that point, and gives the recipient authority, the channel or portal, the report form and fields, the preliminary and official report deadlines, and the step that freezes and keeps the system logs, inputs and outputs for the incident. Deployers and users of the system have a documented way to tell the provider. In code, the alerting and severity taxonomy route a candidate incident to that runbook with the timers attached, and the log store keeps the incident's records from rotation.
Where it goes: 12 repository artifacts, 10 logs and telemetry.
What this provision adds:
File the preliminary report within 72 hours for incidents causing death or serious injury, disrupting public or essential services or security, or uncontrollable rights infringements, and within 5 working days otherwise (Decree 142 Art. 19(3)).
Keep the system logs, data and information about the incident and send the official remediation report within 15 days of the preliminary report (Decree 142 Art. 19(4)).
Rule id vn-ai-law.serious-incident-reporting · review status: primary source derived
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.