AIセキュリティ

ASEAN's First Comprehensive AI Law — Vietnam Law 134/2025: Four-Year Phased Force and Impact on ~1,800 Japanese Companies

Published2026-05-20Updated2026-07-06Ryuta Hamamoto

Vietnam's AI Law (Law No. 134/2025) took force 1 March 2026 — ASEAN's first comprehensive, binding AI statute.

ASEAN's First Comprehensive AI Law — Vietnam Law 134/2025: Four-Year Phased Force and Impact on ~1,800 Japanese Companies
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

In March a Japanese manufacturing subsidiary in Hanoi told me local staff had started raising "the AI law" internally. HQ legal said they did not know Vietnam had an AI law. Fair. In Japanese media I found essentially zero front-page treatments.

Yet the law is ASEAN's first comprehensive AI statute, and it will set regional direction. About 1,800 Japanese companies operate in Vietnam. Manufacturing, finance, IT, logistics, retail: almost every sector is in some way in scope from 1 March 2026.

I want to close that coverage gap on Law No. 134/2025/QH15, with enough operational detail that a Vietnam COO and a Tokyo legal lead can share one checklist.

TL;DR

  • Force 1 March 2026. ASEAN's first comprehensive, binding AI law
  • Four-tier risk (prohibited / high / medium / low), EU-style risk base
  • Phased force: 12 months general; 18 months for finance, healthcare, education
  • Fines up to VND 2 billion (~USD 75,800); revenue-based fines under discussion
  • Lead body MOST (Ministry of Science and Technology); PM-chaired National AI Committee for strategy
  • Japanese top priority: use-case inventory and four-tier classification

Why Vietnam, not Singapore, moved first

Everyone expected Singapore to write ASEAN's first AI law. IMDA built AI Verify first, crosswalked ISO/IEC 42001 and NIST AI RMF, and iterates AI Governance Frameworks. ASEAN's governance leader on paper.

Vietnam wrote the comprehensive statute first. Singapore stays voluntary; Vietnam chose National Assembly law with penalties.1

Three reasons I hear on the ground:

First, Vietnam's centralized political structure can finish regulation fast. Party and assembly decisions resist lobby delay, similar to how Chinese AI rules moved quickly.

Second, Singapore treats "not writing hard law" as competitive advantage, keeping voluntary frameworks to attract regional AI HQs.

Third, Vietnam put AI at the core of Industry 4.0, targeting ~10% annual AI-related GDP growth to 2030, so regulation and industrial policy must move together.2

Read Vietnam's AI Law less as "restraint" and more as infrastructure to put industry on a growth track. Japanese firms should ask how to ride the government's industrial design, not only how they are bound.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

Four-tier risk — subtle differences from the EU AI Act

On the surface it looks like an EU copy. Close reading shows an ASEAN-tuned subject-based axis.

Tier Content Examples
Unacceptable (banned) Implementation banned Unauthorized real-time public biometric surveillance; large facial DBs from illicit data; deceptive manipulation AI
High-risk Conformity assessment, human oversight, tech docs, ops logs HR tech, credit, medical diagnosis, education assessment, transport/energy control
Medium-risk Classification docs, transparency, light risk management Chatbots, recommendations, content moderation
Low-risk Light duties, best practices Spam filters, in-game AI, search ranking

Two big EU differences:

First, the ban category carries a Chinese-style surveillance shadow. Unauthorized public biometrics and large facial DBs exist in the EU too, but "deceptive manipulation AI" (manipulating public opinion/behavior) is broader. Government frames it as fake-news defense; practice can also enable political content-moderation discretion.

Second, subject-based classification mixed in. EU classifies by use case; Vietnam partly asks who can be harmed. AI aimed at children, elderly, persons with disabilities, or ethnic minorities may uplift to high-risk even if the use case looks light.

I read the subject-based axis as a Global South regulatory stance shared with Brazil PL 2338. EU use-case design assumes rational advanced-economy citizens; Global South politics often needs explicit protection of the vulnerable. Miss this axis in ASEAN or Latin America and you mis-scope conformity assessments.

Four-year phased force — 12 vs 18 months

Phasing maps directly to Japanese operating plans.3

Sector Grace Full compliance
Finance, healthcare, education 18 months 1 September 2027
All other general sectors 12 months 1 March 2027

MOST says finance/health/education get longer windows because alignment with existing sector statutes takes time. Patterns for Japanese entities:

  • HR tech / recruiting AI: high-risk + general sector → 12-month grace
  • Bank subsidiary credit models: high-risk + finance → 18-month grace
  • Manufacturing CV inspection (defect detection): medium + general → 12 months toward low-risk ops
  • Call-center speech / sentiment: medium–high border → 12 months for human-oversight layers
  • Medical AI (SaMD): high-risk + healthcare → 18 months

Grace is not a do-nothing period. MOST will publish a PM high-risk AI list and National AI Ethics Framework in 2026; the grace exists so you can prepare conformity and human oversight.

I keep saying "18 months is not long." Many Japanese firms missed even the EU's 24-month window. Vietnam's 18 months, with HQ approval cycles, is really "12–13 months to operationalize."

MOST consolidation and National AI Committee

In February–March 2025 Vietnam merged MIC (Information and Communications) into Science and Technology, creating the new MOST.4 That was deliberate scaffolding for AI-law enforcement.

Before, AI policy split between MIC (digital) and old science (research). Split ownership is the main bottleneck for tech-policy intersections. Post-merger, R&D through market regulation sits under one MOST roof.

The National AI Committee (stood up in 2025), chaired by the Prime Minister, owns:

  1. National AI strategy design and updates
  2. Approval of major AI programs and projects
  3. Regulatory frameworks for highly autonomous AI systems

Item 3 targets GPAI-class models and AI agents. An expand-later domain. EU GPAI rules (live since August 2025) are a template for National AI Committee work in 2026–2027.

Local counsel tell me MOST's AI-law staff is thin. 2026 enforcement will be a distributed model with sector ministries (SBV for finance, MoH for health). Compliance intake design needs "not only MOST, also sector interpretation notices."

Impact on ~1,800 Japanese companies — where to start

JETRO counts roughly 1,800 Japanese companies in Vietnam. Manufacturing (Hanoi–Haiphong north; Ho Chi Minh–Binh Duong south) plus growing finance, IT, logistics, retail. Unaffected firms are the minority.

Three common patterns:

Manufacturing computer-vision inspection. Defect detection and assembly monitoring are medium-risk. If anomaly models are read as performance management of Vietnamese workers (subject-based uplift), they go high-risk. Write internal guidelines that forbid reuse for worker evaluation.

HR tech and recruiting screens. CV parsing, interview-video analysis, aptitude AI are solidly high-risk. Align with Labor Code (2019 amendments); build conformity and human oversight. Start by inventorying whether HQ HR systems (Workday, SuccessFactors, etc.) use AI when evaluating Vietnam staff.

Finance subsidiary credit and KYC. Japanese banks and non-banks lean hard on AI for scoring, fraud, and AML. 18-month window → full compliance by September 2027 is the realistic plan.

Hardest case: HQ-built models used by Vietnam subsidiaries. Law distinguishes Provider and Deployer; HQ as provider and local as deployer means HQ may owe Vietnam conformity duties. "We only run this in Japan" from Tokyo legal is a failure mode I have already heard in the wild.

Starting point for ASEAN hard-law cascade — WARP SECURITY

Vietnam's deeper meaning is the start of an ASEAN hard-law chain reaction. Singapore can stay voluntary; Vietnam's statute raises pressure on Indonesia, Thailand, and the Philippines. Indonesia was expected to sign a presidential AI framework in early 2026; Thailand's ETDA is revising integrated draft principles.

TIMEWELL's WARP SECURITY includes modules for multi-country ASEAN response, starting from questions like:

  • Which Vietnam-subsidiary AI tools trigger Law 134/2025 subject-based risk uplift?
  • Can we build an ASEAN common response template that reuses the 18-month grace work for Indonesia and Thailand later?
  • Can HQ reverse-translate Japanese internal materials into Vietnam MOST conformity files when HQ is the provider?

ASEAN seats often need HQ legal, HQ CIO, local COO, and local CTO together. A formation rare in US/EU engagements.

The most dangerous pattern I see: Hanoi optimism of "we're still fine."

Latest developments as of July 2026

As of July 2026 the EU AI Act Vietnam referenced is heading into its next phase. Commission GPAI supervision and enforcement take effect 2 August 2026; fines up to €15 million or 3% of global turnover (Regulatory framework on AI, European Commission). My view that National AI Committee–led highly autonomous AI rules will arrive 2026–2027 is consistent with that EU path. Vietnam GPAI rules may trail EU enforcement practice. Domestically, also track Japan's personal information protection law 2026 reform.

Summary

Fail in Vietnam and you may fail five times across ASEAN. Treat the first market as the place to build the ASEAN regulatory template.

  • Vietnam AI Law (Law 134/2025) force 1 March 2026. ASEAN's first comprehensive binding AI law
  • Four-tier risk references the EU but mixes a subject-based axis
  • Grace: 12 months general, 18 months finance/health/education. Really "12–13 months to ops"
  • MOST consolidation (Feb 2025) and PM-led National AI Committee build enforcement
  • Of ~1,800 Japanese firms, few are untouched. Watch subject-based uplift

Vietnam moving first in ASEAN is likely strategy, not accident. Hard law into the gap Singapore leaves voluntary. Indonesia and Thailand will reference Vietnam's design.

Monday morning for a Hanoi subsidiary: inventory every AI tool that touches workers, customers, or credit decisions, then map each one against the four tiers before HQ asks for a "simple summary." Vietnam lessons become ASEAN intellectual capital.

Further reading: Korea AI Basic Act, January 2026, EU AI Act digital simplification and 2026 schedule, Texas TRAIGA vs New York RAISE Act.

References

Footnotes

  1. Vietnam's first standalone AI Law - IAPP

  2. Vietnam AI Law: Regulatory Milestone and Business Implications - Vietnam Briefing

  3. Vietnam AI Law 2025: First Binding AI Law in Southeast Asia - Pertama Partners

  4. Vietnam: Artificial Intelligence Law - Foundation and Outlook - Baker McKenzie

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles