AI Regulation

Decree 142/2026: detailed rules under Vietnam's AI Law — what businesses need to know

Scales of justice and a wooden gavel — symbols of law

On 30/04/2026, the Government issued Decree 142/2026/NĐ-CP detailing a number of articles of, and measures to implement, the Law on Artificial Intelligence (Law No. 134/2025/QH15), effective from 01/05/2026. The Law itself — Vietnam's primary AI statute — has been in force since 01/03/2026; the Decree adds the operational detail: a 3-tier risk classification (high, medium, low), a conformity assessment requirement for high-risk systems, a controlled testing mechanism (sandbox), and business support measures. This article summarizes the key points and what businesses need to prepare.

Quick summary

  • Document: Decree 142/2026/NĐ-CP, issued 30/04/2026, effective 01/05/2026 (Official Gazette).
  • Parent law: Law on Artificial Intelligence No. 134/2025/QH15, in force since 01/03/2026.
  • Structure: 8 chapters, 46 articles.
  • 3-tier AI risk classification (Article 6(3)): high · medium · low.
  • Who is covered: AI providers, developers, deployers and users — including foreign organizations/individuals carrying out AI activities in Vietnam.
  • Support: the Decree details the controlled testing (sandbox) mechanism and the measures to support AI businesses provided for in the Law.

What is Decree 142/2026?

According to Article 1 of the Decree, it sets out detailed rules on: the operation of the AI one-stop information portal, the risk-level classification of AI systems, conformity assessment, management of high-risk systems, the controlled testing mechanism (sandbox), and the responsibilities of agencies, organizations and individuals.

The scope is very broad: providers, developers, deployers, users of AI systems, and people affected by AI systems; it also includes foreign organizations and individuals taking part in AI activities in Vietnam. The Decree comprises 8 chapters and 46 articles. It does not replace the Law: it is the implementing text of Law No. 134/2025/QH15.

A person filling out paperwork beside a laptop — compliance procedures
A risk classification dossier is mandatory for high- and medium-risk AI. Photo: Sora Shimazaki / Pexels

The 3-tier AI risk classification and the classification dossier

Under Article 6(3) of Decree 142/2026, AI systems fall into 3 risk tiers: high — only systems on the high-risk list issued by the Prime Minister; medium — systems not on that list that could mislead users who cannot tell they are dealing with AI (Article 9); and low — everything else. For high- or medium-risk AI, the provider must prepare a risk classification dossier (Article 12), comprising: system identification information; a description of the system and its context of use; information on input data; and risk management content, and notify the classification result through the AI one-stop portal before use (Article 14).

A point of interest for businesses: under Article 12(4), the dossier does not require disclosure of source code, model parameters, raw training data, or state/business secrets — easing concerns about exposing intellectual property.

Obligations for high-risk AI systems

High-risk systems must undergo a conformity assessment before use (Article 13): systems on the list that requires certification go through a registered conformity assessment body; other high-risk systems may use such a body or self-assess, with a technical file and legal liability for the result. In operation, businesses must establish a risk management system throughout the lifecycle, provide human oversight, keep operational logs and report incidents.

On reviews: if a system is reclassified to a higher risk tier, this must be notified within 15 working days from the date the review is completed.

Table — The 3-tier AI risk classification and key obligations (Decree 142/2026, Articles 6, 9, 12–15)
Risk tierWhich systemsKey obligations
HighOnly systems on the Prime Minister's high-risk listRisk classification dossier; notify the result via the one-stop portal before use; conformity assessment before use; lifecycle risk management; human oversight; keep operational logs; report incidents
MediumNot on the list, and could mislead users who cannot tell they are interacting with AIRisk classification dossier; notify the result via the one-stop portal before use
LowEverything elseNo classification dossier or notification under Articles 12 and 14; general transparency duties still apply

The sandbox and business support

The Decree introduces a controlled testing mechanism (sandbox) — detailing Article 21 of the Law — a space to test AI while remaining within legal control.

On support: Article 1 of the Decree also covers the mechanisms, conditions and procedures for supporting businesses in the AI sector (Article 25 of the Law) and for developing the AI ecosystem and market (Article 20 of the Law). Check the full text for the specific eligibility conditions before planning around them.

Abstract data structures — AI and technology
The Decree classifies AI systems into 3 risk tiers: high, medium and low. Photo: Google DeepMind / Pexels

What do businesses need to prepare?

What to do early: review the AI systems currently in use, determine their risk level, and prepare a classification dossier where one is required. Since 15/08/2026 the high-risk list is in force: Decision 33/2026/QĐ-TTg (issued 30/06/2026) sets out the Prime Minister's list of high-risk AI systems. A document-lookup assistant used only for internal operations is generally low risk: systems serving only internal management that do not directly affect the rights or obligations of outside parties are not proposed for the high-risk list (Article 8(2)(c)), and office-support systems whose users clearly know they are using AI are not classified as medium risk (Article 9(3)). The final tier depends on how each organization uses the system. For high-risk AI, you need operational logs, human oversight and lifecycle risk management processes ready.

This is where on-premise (in-house) AI has a clear compliance advantage: when the model and data run on the company's own infrastructure, you control the input data, keep full logs, supervise and manage access — exactly what Decree 142/2026 requires — without depending on a third party. That is the direction of Namtech's private in-house AI platform.

Frequently asked questions

When does Decree 142/2026 take effect?

According to the Official Gazette, Decree 142/2026/NĐ-CP was issued on 30/04/2026 and takes effect from 01/05/2026. It details the Law on Artificial Intelligence No. 134/2025/QH15, in force since 01/03/2026. This is reference information and does not replace reading the original document.

How many AI risk tiers does Decree 142/2026 define?

Three: high, medium and low (Article 6(3)). High risk covers only systems on the Prime Minister's list, issued as Decision 33/2026/QĐ-TTg; medium covers systems that could mislead users about interacting with AI; everything else is low risk.

Who must comply with this Decree?

Providers, developers, deployers and users of AI systems — including foreign organizations and individuals taking part in AI activities in Vietnam.

What must a 'high-risk' AI system do?

It must undergo a conformity assessment before use, establish lifecycle-wide risk management, provide human oversight, keep operational logs and report incidents.

Do you have to submit source code or training data?

Under Article 12(4) of the Decree, the risk classification dossier does not require disclosure of source code, model parameters, raw training data, or state/business secrets.

How does in-house AI help with compliance?

When AI runs on-premise, the business controls input data, keeps full operational logs, supervises and manages access — aligning with the Decree's requirements for high-risk systems.

Ready for the new AI legal framework

Namtech deploys a private in-house AI platform that helps you control data, keep logs and supervise — making it easier to comply with Decree 142/2026.

Book a free consultation

Note: This article was first compiled from publicly available sources on 23/06/2026. Last updated 24/09/2026: risk tiers corrected against the original Decree (3 tiers, not 4), and the Law on AI and Decision 33/2026/QĐ-TTg added. The information is for reference and is not legal advice.

Get started

Start with a free assessment

To define the right package and detailed scope, Namtech offers a short, no-cost assessment.

We reply within 1 business day. No spam, we never share your info.