As of March 1, 2026, the Law on Artificial Intelligence 2025 ("Law on AI") has officially come into effect, marking a transformation when it is officially recognized separately in specialized legal regulations. Currently, the Government is also urgently collecting comments on 04 draft documents, including: (i) Decree guiding the implementation of the Law on AI; (ii) Circular guiding the National Artificial Intelligence Ethics Framework; (iii) 02 Decisions related to the List of high-risk artificial intelligence systems and the List of datasets for the development of artificial intelligence in essential fields to soon complete this very new legal framework in Vietnam.

In order to clarify the roles and responsibilities of enterprises in artificial intelligence activities, the Law on AI has delineated each specific subject on the basis of each stage.
In this article, we will clarify some of the impacts of the Law on AI on the operation of enterprises, especially enterprises specializing in developing, supplying, deploying, and commercially exploiting artificial intelligence systems. At the same time, HM&P also makes a number of recommendations for businesses to refer to and consider implementing during the period of adapting to this specialized operating framework.
1. Determining the roles/responsibilities of subjects participating in artificial intelligence activities
In order to clarify the roles and responsibilities of enterprises in artificial intelligence activities, the Law on AI has delineated each specific subject on the basis of each stage. In the early stages, the subject referred to is the developer[1]. Developers are understood as individuals and organizations that directly impact all or part of artificial intelligence models, algorithms or systems, have the right to control and refine the intellectual products they make. After the artificial intelligence product is completed, the suppliers[2] will have the role of commercializing the artificial intelligence product or system in the markets for the public and people who need to use it to access and use. In fact, the provider can make this distribution under its name or brand without depending on whether the entities directly develop the system or not. Next is the implementer when this is the subject using the artificial intelligence system within the scope of control to serve professional activities, trade or service provision. Finally, users when this is a common user of artificial intelligence system platforms to serve the purpose and needs of that individual.
In each specific situation, the clear delineation of each group of subjects helps to accurately determine the scope of rights, obligations and the level of legal responsibility of each party. Therefore, businesses need to proactively determine which role they are playing in the AI value chain to build appropriate compliance, internal control, and risk management mechanisms. Because, if they do not properly identify their legal roles, enterprises may be responsible for obligations that belong to other subjects, or fail to promptly fulfill the mandatory requirements according to the provisions of the Law on AI 2025, leading to the risk of being handled for violations or arising disputes, compensation for damages.
2. Review of artificial intelligence application activities
One of the important preparation steps since the Law on AI takes effect is that enterprises need to conduct a comprehensive review and inspection of the research, development, supply and deployment of artificial intelligence systems that are being applied. This review aims to compare with acts strictly prohibited under Article 7 of the Law, promptly adjust or eliminate potential factors at risk of violation. Specifically, businesses need to take the step of assessing whether their intellectual systems are at risk of infringing on human rights, infringing on personal data, or being used for illegal purposes. For example, AI tools are built into financial products but make automated recommendations without a human monitoring mechanism, to the detriment of customers. In some other common cases such as illegally collecting and processing data on personal data and intellectual property to train or operate artificial intelligence systems; creating content capable of producing fake images and sounds (Deepfake) but without a control or warning mechanism, leading to the risk of infringing on the honor and reputation of other individuals.
3. Classification of the risk level of artificial intelligence systems
Artificial intelligence systems are classified according to 03 risk levels, including:[3] (i) Artificial intelligence systems with high risks; (ii) Artificial intelligence systems are medium-risk; (iii) Low-risk artificial intelligence systems. The classification will be based on groups of criteria such as the level of impact on human rights; national safety and security, public interests; fields of use; user range and system scale. The principle for determining this level of risk is specified in Article 6 of the Draft Decree guiding the implementation of the Law on AI and the Appendix to the Decision on the promulgation of the List of high-risk artificial intelligence systems.
Accordingly, it is first necessary to determine whether the artificial intelligence system of the enterprise is in a high-risk case or not. In case artificial intelligence is not a high-risk case, it will be further evaluated to determine whether the system belongs to a medium or low-risk artificial intelligence system.

VinRobotics' humanoid robot will be showcased at AI4VN 2025. Source: Government Newspaper
Depending on the role of the subject, businesses will have different obligations and responsibilities. For example, if the enterprise is the implementer, it will be responsible for ensuring the safety and integrity of the system during use and must coordinate with the supplier to reclassify it. Particularly for enterprises that are suppliers, they will have to be obliged to self-classify before putting them into use. Therefore, enterprises must determine their role in the value chain and proactively classify and manage themselves according to the level of risk from the beginning, ensuring compliance with obligations arising in the new regulations.
4. Taking advantage of the State's preferential mechanism in the development of the field of artificial intelligence
In addition to compliance obligations, the Law on AI also designs many incentives and support mechanisms to promote the formation of a sustainable artificial intelligence ecosystem.
Enterprises operating in the field of AI are entitled to the highest incentives in accordance with the law on science and technology, high technology, digital transformation and investment.[4] At the same time, the State creates conditions for businesses to access computing infrastructure, data sources and testing environments for product research and development. The State also orients market development through prioritizing the use of intellectual products and solutions in bidding activities, building technology trading floors and ensuring a transparent testing environment and equal competition among subjects. More prominent is the documented sandbox testing mechanism, which learns from many models in developed countries, allowing new intelligence systems to be deployed within controlled scope, timing and risk conditions. On the basis of the test results, enterprises can be considered for exemption or reduction of certain compliance obligations, creating room for flexibility for innovation activities.[5]
Article 22 of the Law on AI stipulates the establishment of the National Artificial Intelligence Development Fund, which is an off-budget state financial fund, operating under a flexible mechanism and accepting a level of risk suitable to the characteristics of innovation. This fund prioritizes investing in AI infrastructure development, training high-quality human resources, researching core technologies and supporting start-ups. In addition, the policy also provides specialized support for startups and small businesses, including supporting the cost of conformity assessments, providing compliance self-assessment tools, and facilitating access to shared datasets for the development of artificial intelligence systems.
The above-mentioned incentives and support mechanisms show that the new legal framework also opens up many favorable conditions for innovation activities in the field of AI. Therefore, businesses should actively consider investment strategies and expand research, development, testing as well as commercialization of artificial intelligence products in an environment that is encouraged and supported by the State.
In summary, businesses currently using/applying artificial intelligence, especially those specializing in deploying and exploiting business on artificial intelligence objects, need to understand the current legal framework, provide implementation orientations to optimally exploit the incentives from the new policies of state agencies. At the same time, grasping regulations is the basis for businesses to comply with new principles and requirements to blame for the risks arising in the process of application, deployment and business in the field of artificial intelligence in Vietnam.
Nguyen Viet Hung
HM&P Law Firm
Read more: Doanh nghiệp cần làm gì khi Luật Trí tuệ nhân tạo 2025 có hiệu lực
[1] Clause 3, Article 3 of the Law on AI.
[2] Clause 4, Article 3 of the Law on AI.
[3] Article 9 of the Law on AI.
[4] Article 20 of the Law on AI.
[5] Article 21 of the Law on AI; Article 24 of the Draft Decree details a number of articles and measures to organize and guide the implementation of the Law on AI.
