The Law on Artificial Intelligence ("AI") 2026 officially takes effect on 01 March, 2026, this specialized law means that the use of AI in businesses is a matter of risk management, responsibility and compliance. Meanwhile, many businesses are sprinting to build policies to use AI internally as a way to respond to the situation. The common reaction of many businesses in using AI today is divided into two extremes. On the one hand, it is floating, allowing personnel to freely use AI tools without direction, without controlling input data, without delineating responsibilities. The other side is frozen, concerned about risks, so they prohibit and tighten to the point of suppressing the benefits that AI can bring. Neither is a sustainable strategy.

Many businesses in using AI today is divided into two extremes.
From the perspective of enterprise risk control, in the current context, the problem for businesses should be to develop policies on how to use AI internally correctly and adequately.
When AI is no longer a personal tool, but an enterprise-level risk
An employee feeds customer data into a third-party AI system for analysis; the marketing department uses AI-generated images without examining the training data source; the HR department applies AI to screen candidate profiles but does not assess the risk of bias... can all touch on issues of personal data protection, intellectual property rights, civil liability caused by products, or even discrimination in the context of new laws.
AI-assisted jobs as mentioned above take place silently and scattered in many parts of the business, but the legal consequences, if any, are not "personalized" according to the user. The final responsibility is often attributed to the enterprise as the entity that organizes operations, manages data and exploits work results. Therefore, building an internal AI policy is not merely a manual for using tools, but a component of the overall risk management system required of the business.
The mistake is called "what not to do"
A common mistake that many businesses make when developing AI policies is the tendency to list what not to do. This approach can create a sense of short-term security, but it quickly becomes obsolete in the context of constantly changing technology. Instead of just stopping at prohibitions, businesses can design policies according to the risk management model including clearly defining the scope of application, classifying the level of risk, assigning responsibilities, establishing approval processes and monitoring mechanisms.
First of all, it is necessary to determine how AI is understood within the enterprise, the scope of application to establish the policy focus. We need to clarify points, such as the policy of using AI only applies to AI systems developed by businesses, or including third-party platforms such as OpenAI, Google or Microsoft; Are AI integration tools in office software regulated?
Next, businesses need to classify the use of AI according to the level of risk. Activities that are only internal support, do not involve sensitive data, and do not make decisions that directly affect other individuals/organizations may be classified as low-risk. In contrast, AI systems used for credit scoring, recruitment, performance reviews, or large-scale processing of personal data should be considered high-risk and subject to tighter control.
In this regard, enterprises need to rely on the provisions of the Law on Artificial Intelligence on the classification of the risk level of artificial intelligence systems[1], and at the same time compare them with their activities to have an appropriate classification. Risk stratification allows businesses to avoid a one-size-fits-all approach, while creating a flexible space for innovation.
Data classification
If you have to choose a starting point when developing a policy using AI, it must be data. Indeed, AI operates on data and generates new data. Every time an employee enters information into an external AI system, the business is actually performing an act of processing and transferring data.
The AI use policy needs to clearly define what types of data are allowed to be included in public AI systems, which are strictly prohibited, and which types can only be used with special approval. Personal data, business secrets, information that has not been disclosed to the market, confidential documents according to internal regulations, etc. are the data that businesses especially consider when putting into the AI system.
In addition, businesses need to set an obligation to anonymize or simulate data when using AI for testing purposes. Training or refining the internal model must also be accompanied by an impact assessment on data protection and information security.

Source: The Saigon Times
Delimitation of liability
One point that is easily overlooked is the relationship between AI-generated results and human responsibility. One of the basic principles in artificial intelligence activities is to be human-centered, artificial intelligence serves people, and does not replace human authority and responsibility. Ensure that human control and intervention over all decisions and behaviors of artificial intelligence systems are maintained; system safety, data security and information security; the ability to test and monitor the development and operation of artificial intelligence systems[2].
On that basis, the internal policy on the use of AI needs to affirm the principle that AI is only a support tool, and the final decision still belongs to humans. This is not only moral, but also a matter of delimitation of liability. If an AI-generated false report is used to make an investment decision, or an illegal advertising content is released based on AI's suggestions, businesses cannot cite "machine-made" reasons.
Therefore, it is necessary to clearly stipulate the obligation to review, verify and approve the results generated by AI, especially in activities that have external influences. The "human in the loop" mechanism is clearly stipulated in the internal policy and also helps businesses easily determine internal responsibilities in case of errors and errors from products created by AI.
In addition, AI raises new questions about copyright, industrial property rights, and data rights. When an employee uses AI to create design, content, software, or business strategy, who has the rights to that product? Is that personnel responsible for the intellectual property issues of the input data? What are the limitations of the AI platform's terms of use for commercial mining... These are issues that businesses need to pay attention to and include in their internal policies.
In the world, there have been disputes over intellectual property rights related to data fed into AI, typically the copyright dispute between Getty Images and Stability AI, [3]posing a compliance problem for businesses, in the context of the Law on Artificial Intelligence 2025 emphasizing legal compliance, especially intellectual property rights.
AI does not exist separately from other legal obligations, on the contrary, it intersects with the laws of personal data protection, cybersecurity, labor, intellectual property, competition, and consumer protection,... Therefore, the effective Law on Artificial Intelligence 2025 should not be seen as a timeline for businesses to sprint in promulgating policies on the use of AI.
On the contrary, it is an opportunity for businesses to restructure their approach to new technology, control risks, protect assets, and exploit the full potential of technology. Building an internal AI policy, after all, is not just about complying with a law. It's how businesses shape their own future in a world that's being reprogrammed day by day.
Lawyer Nguyen Nhat Duong
HM&P Law Firm
Read more: Xây dựng chính sách sử dụng AI nội bộ: Đừng vội làm cho có
[1] Article 9 of the Law on Artificial Intelligence 2025.
[2] Clauses 1 and 2, Article 4 of the Law on Artificial Intelligence 2025.
[3] https://nhandan.vn/toa-an-anh-xet-xu-vu-kien-ban-quyen-giua-getty-images-va-stability-ai-post885733.html, last accessed on 02/3/2026.
