Law on Artificial Intelligence, risk classification and conformity assessment
Law No. 134/2025/QH15, arts. 9-10, 13-14
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 7 months, effective 1 March 2026.
An AI risk obligations rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Classify your AI system's risk level (high, medium, or low) before putting it into service, based on its potential impact on rights, safety, security, and public interest, and the scale and context of its use.
- For a medium-risk or high-risk AI system, prepare a classification dossier and notify the classification result to the Ministry of Science and Technology through the one-stop AI portal before putting the system into service.
- For a high-risk AI system, complete a conformity assessment before putting it into service or after a significant change, and maintain that conformity throughout operation.
- Re-classify an AI system's risk level when a modification, integration, or functional change gives rise to a new or higher risk.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Article 29(1) provides that a violation of the Law or other relevant AI regulations is, depending on its nature, severity, and consequences, sanctioned as an administrative offence or examined for penal liability, with civil compensation where damage is caused; the Law does not itself define an AI-specific criminal offence or state an administrative fine amount, and Article 29(5) leaves the sanctioning regulations to a Government decree not yet issued as of this review.
Who enforces it
Enforcement body
The Ministry of Science and Technology, the focal agency responsible to the Government for state management of artificial intelligence nationwide, with the Government performing unified state management and provincial People's Committees managing artificial intelligence locally (art. 30(2)).
What it reaches
Obligation class
Governance, DPIA, Reporting
Who checks it
Audit expectation
continuous
Who audits it
Self, Registered or designated auditor
Where the report goes
Kept, Produced on request
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 9 classifies an AI system as high, medium, or low risk based on its potential to cause significant harm to rights, safety, security, or public interest, its capacity to confuse users about whether they are dealing with an AI system, and criteria the Government is to detail further, including the field of use and the scale and range of its impact.
Article 10 requires a provider to classify its own system before putting it into service, to prepare a classification dossier for a medium-risk or high-risk system, and to notify the classification result to the Ministry of Science and Technology through the one-stop AI portal before deployment; a deployer inheriting a provider's classification must re-classify if a modification creates a new or higher risk.
Articles 13 and 14 require a high-risk system to undergo conformity assessment, by a registered assessment organization or by the provider itself depending on the system, before being put into service or after a significant change, and require the assessment result to be maintained throughout operation as a condition of continued use.
Decision No. 367/QD-TTg, the government's implementation plan for the Law, is preparing a Prime Ministerial decision listing high-risk AI systems by five criteria, but this list had not been issued as of this review.
When LexLint raises it
high_risk_decisionsdeploys_chatbotgenerates_contenttrains_modelscrawls_webautomated_outreach