HANOI, 23 AUG 2026 — Vietnam's National Assembly passed the Law on Artificial Intelligence on 10 December 2025 and it took effect on 1 March 2026, making Vietnam the first country in Southeast Asia with a comprehensive, risk-based statute covering the research, development, provision, deployment and use of AI systems.
It binds foreign entities as well as domestic ones. Most existing providers and deployers have until 1 March 2027 to comply, extended to 1 September 2027 for systems in health, education and finance.
The shape of the law
The law pairs obligations with encouragement. It imposes stringent compliance requirements for high-risk applications, but also offers incentives, funding, and a regulatory sandbox to keep development from moving offshore.
Two grace periods, and the second one is the interesting choice
Giving existing systems a year is unremarkable. Giving health, education and finance an extra six months is a deliberate decision that runs against the obvious intuition.
Those are the sectors where AI decisions carry the most consequence for individuals, and a risk-based framework would normally bring them into scope first rather than last. The longer runway says the drafters weighed something else more heavily.
The defensible reading is operational. Those three sectors already sit under dense sector-specific regulation, run older systems with longer procurement and certification cycles, and cannot swap a component without revalidating a clinical or financial process around it. A hospital cannot patch its way into compliance the way a consumer application can, and a deadline that ignores that produces either mass non-compliance or the withdrawal of systems patients are relying on.
The uncomfortable reading is that the sectors with the most institutional weight negotiated the most time. Both readings predict the same schedule, and only enforcement behaviour after September 2027 will distinguish them.
Extraterritorial scope is the part regional businesses keep missing
A law applying to foreign entities engaged in AI activities in Vietnam is not unusual in drafting, and it is routinely ignored in practice.
A Singapore software company selling an AI-enabled product to Vietnamese customers is within scope in the same way a Vietnamese company is. So is a Malaysian firm deploying an AI system in a Vietnamese subsidiary, and a Thai platform whose service is used in Vietnam. The obligation attaches to the activity, not to the incorporation.
This is now the second Asian jurisdiction with this shape of statute — Korea's AI Basic Act, in force since January, reaches foreign providers above defined revenue and user thresholds. The two do not have identical triggers, which is precisely the problem for a company selling across the region.
A regional software business now faces at least two overlapping AI compliance regimes with different scoping rules, different risk categories, and different deadlines.
The sandbox is the part worth taking seriously
Regulatory sandboxes appear in many announcements but function in few. Vietnam included one to head off a specific problem.
A developing AI ecosystem faced with a comprehensive statute has an obvious response: develop somewhere with less regulation and import the result. This would leave Vietnam regulating deployment while capturing none of the development — the exact outcome the incentives are meant to prevent.
Whether a sandbox achieves that depends entirely on whether it grants meaningful relief on a workable timescale. A sandbox that takes eight months to enter and exempts nothing consequential is just a consultation exercise. One that lets a startup deploy a high-risk system under supervision while the compliance path is worked out is a real tool.
Nothing in the available material establishes which of those Vietnam has built, and that is the detail that will determine whether the law reads as pro-development or merely says so.
What this means for the rest of ASEAN
Vietnam moving first changes the regional calculation for everyone else, and not only through example.
Regulatory sequencing has competitive consequences. A jurisdiction that legislates early sets a template others may find easier to copy than to design, and it also becomes the market where compliance capability gets built first — the law firms, the auditors, the tooling and the in-house expertise.
Indonesia has a presidential regulation on AI that has been pending for roughly a year. Singapore governs through sectoral guidance and model frameworks rather than a comprehensive statute. Thailand and Malaysia have neither. Each of those is a defensible position, and Vietnam has now created a reference point that makes the absence of one more visible.
The practical question for a regional business is no longer whether to build AI compliance capability but which jurisdiction's framework to build it against first, and the answer for anyone selling into Vietnam is now settled by a date.
Why a comprehensive statute suits Vietnam better than it would suit its neighbours
The choice of instrument is as informative as its content, and it fits this state in a way it would not fit others.
Comprehensive framework legislation works where a government can direct implementation across ministries without extended negotiation, and where the domestic industry is young enough that compliance costs land on companies still choosing their architecture rather than on established estates that must be retrofitted. Vietnam has both conditions.
Singapore's sectoral approach reflects the opposite position: a mature financial and healthcare sector with regulators already exercising detailed supervisory authority, where a general AI statute would overlap awkwardly with instruments that already work. Indonesia's difficulty is different again, being a question of implementation capacity across a very large and decentralised administration.
So the useful conclusion is not that Vietnam is ahead. It is that comprehensive legislation is one available instrument among several, and that a jurisdiction choosing sectoral guidance instead is not necessarily behind — though it does have to answer what a foreign vendor should read to know its obligations, and a statute answers that more cleanly than a set of frameworks does.
What remains unconfirmed
The material reviewed does not describe the risk categories, how systems are classified, which authority administers the law, or what penalties apply. No enforcement action has been reported, which is expected during a grace period.
The sandbox's entry criteria, duration and the scope of relief it offers are not established. The law's interaction with existing cybersecurity and data protection regimes is not described, nor is there any mention of guidance or implementing decrees issued since March. Whether any foreign provider has registered or been assessed is not stated.
What to watch for
The first thing to watch for is implementing decrees. A framework law like this is defined by its underlying regulations; the classification rules for high-risk systems are what will set the actual cost of compliance.
The second is whether the sandbox admits anyone. An empty sandbox a year after commencement would answer the pro-development question decisively.
The third is whether Indonesia's pending presidential regulation issues. Two comprehensive frameworks in ASEAN would begin to look like a regional direction; one would remain an outlier, and the difference matters for anyone deciding how much compliance capability to build.