From AI Adoption to Responsible Implementation: Why Healthcare AI Governance Matters Now in Viet Nam
IMPLEMENTATION INSIGHT
9/13/202611 min read


From AI Adoption to Responsible Implementation: Why Healthcare AI Governance Matters Now in Viet Nam
Artificial intelligence is moving rapidly into healthcare.
Hospitals and other healthcare organizations are considering AI for medical imaging, clinical decision support, documentation, patient communication, monitoring, workflow optimization, and administrative processes. Some AI capabilities may also enter an organization less visibly, embedded within software, medical equipment, or digital platforms already in use.
This creates an understandable question for healthcare leaders:
Which AI technologies should we adopt?
But another question is becoming just as important:
How do we make sure AI is implemented safely, responsibly, and effectively once it enters the organization?
That is where healthcare AI governance matters.
And in Viet Nam, the timing is particularly important.
The Law on Artificial Intelligence No. 134/2025/QH15 took effect on March 1, 2026. It was followed by Decree No. 142/2026/ND-CP, effective from May 1, 2026, and Decision No. 33/2026/QD-TTg, which established the current list of high-risk AI systems and took effect on August 15, 2026. On August 28, 2026, the Ministry of Science and Technology also put the national Single-Window Artificial Intelligence Portal and national AI database into operation.
Healthcare receives specific attention under the AI Law. Article 6 requires stricter risk management for AI in essential sectors and, for healthcare specifically, highlights patient safety, reliability under real-world conditions of use, and protection of health data.
At the same time, the international conversation is also shifting from AI adoption toward governance readiness.
On September 1, 2026, the World Health Organization Regional Office for Europe published the report of its Knowledge Community on responsible AI in health. Participants identified governance gaps, unclear accountability, fragmented or biased data, and gaps in AI literacy as persistent barriers to responsible implementation. The report emphasized that responsible progress should be judged not simply by the speed of deployment, but by the strength of governance around it. WHO notes that the report reflects the perspectives of Knowledge Community participants and does not necessarily represent a formal WHO position.
For healthcare organizations in Viet Nam, the practical message is increasingly clear:
AI adoption without AI governance is not enough.
What does healthcare AI governance actually mean?
AI governance can sound abstract.
In practice, it is very concrete.
Healthcare AI governance is the set of roles, decision-making processes, policies, controls, and monitoring mechanisms that determine how an organization selects, evaluates, implements, uses, changes, monitors, and eventually retires AI systems.
It should help answer questions such as:
Who decides whether an AI system should be introduced?
What evidence should be reviewed before adoption?
Is the proposed use appropriate for this patient population and setting?
Who evaluates patient safety, data, cybersecurity, and operational risks?
Who is accountable once the system is deployed?
What level of human oversight is required?
How will staff know when an AI output should not be trusted?
What happens when the system or underlying model changes?
Who monitors performance after implementation?
And what happens if something goes wrong?
These questions show why AI governance is much more than an Information Technology issue.
Depending on the system and its intended use, it may involve clinical governance, patient safety, quality management, data governance, cybersecurity, medical device management, procurement, legal and compliance functions, workforce development, and senior leadership.
Adoption is an event. Implementation is a lifecycle.
One reason governance matters is that purchasing an AI product and implementing it responsibly are not the same thing.
Procurement may happen at one point in time.
AI risk does not.
Imagine a clinical AI system that performs well during a vendor demonstration and has encouraging validation results.
Several things may still change once it enters a real hospital.
The local patient population may differ from the population used to develop or validate the system.
Clinical workflows may cause staff to use it differently from what the developer intended.
Data quality may vary between departments, facilities, or over time.
Users may become too dependent on its recommendations.
A software update may change system behavior.
The vendor may update the underlying model.
The hospital may integrate the system with another platform or gradually use it for purposes beyond its original intended use.
Performance itself may also change over time.
Responsible implementation therefore requires healthcare organizations to think about AI across its entire lifecycle, not only at the point of purchase.
A simple way to think about that lifecycle is:
Need → Evaluation → Decision → Implementation → Use → Monitoring → Reassessment → Change or Retirement
Governance should exist throughout that pathway.
Start with the problem, not the technology
A common temptation with new technology is to begin with what the product can do.
Healthcare organizations should begin somewhere else:
What problem are we trying to solve?
Is the objective to improve diagnostic accuracy?
Reduce turnaround time?
Support clinical documentation?
Identify deteriorating patients earlier?
Reduce administrative workload?
Improve access?
Standardize a difficult workflow?
Address a workforce constraint?
Once the problem is clear, another question should follow:
What outcome would show us that the technology is actually helping?
Without this step, AI projects can easily become technology projects looking for a problem.
Good governance keeps the discussion focused on healthcare value, rather than technological novelty.
It also makes it easier to decide later whether an AI system has delivered what the organization expected.
Regulatory compliance is part of governance, but governance goes further
Viet Nam’s new AI framework makes organizational governance increasingly important.
The Law distinguishes different actors, including developers, providers, deployers, and users. A healthcare organization using AI supplied by an external company may, depending on the circumstances, act as a deployer.
For high-risk AI systems, the Law and Decree establish specific responsibilities relating to areas such as appropriate operation, risk control, monitoring, human intervention, data safety, incident management, transparency, and accountability. Providers must classify AI systems before putting them into use, while deployers must cooperate in reassessment when modification, integration, or a change in purpose creates new or greater risk.
But healthcare AI governance should not be reduced to a compliance exercise.
Not every AI system used in healthcare is automatically classified as high-risk under Viet Nam’s AI framework. Decree No. 142/2026/ND-CP uses a risk-based approach that considers factors such as potential impact, level of automation, role in final decision-making, human oversight, sector of use, and scale of impact. It also recognizes circumstances in which systems with substantive human oversight or advisory-only outputs may not be proposed for the high-risk list.
This creates an important distinction:
“Not legally classified as high-risk” does not mean “no governance is needed.”
A generative AI tool used to draft an internal administrative document clearly does not create the same level of risk as an AI system directly influencing a treatment decision.
But the first system may still create problems involving confidentiality, inaccurate information, unauthorized data disclosure, intellectual property, or inappropriate staff reliance.
Governance should therefore be proportionate to risk.
The goal is not to place the same controls around every AI tool.
The goal is to apply the right level of oversight to the right use case.
Evidence should come before enthusiasm
One of the most important functions of AI governance is deciding what evidence an organization should require before adoption.
A sophisticated demonstration is not evidence of clinical value.
Neither is an impressive accuracy number presented without context.
Healthcare leaders should ask:
What exactly was evaluated?
Against what comparator?
In which patient population?
In what clinical setting?
Was the system externally validated?
Does the evidence match the proposed intended use?
Were important limitations identified?
How does performance vary across relevant patient groups?
What happens with missing, unusual, or poor-quality data?
Has the effect on workflow, clinician behavior, or patient outcomes been evaluated?
What evidence exists from real-world use?
The WHO, International Telecommunication Union, and World Intellectual Property Organization Global Initiative on AI for Health similarly places robust governance, standards, technical guidance, and evidence-based adoption among the foundations for trustworthy AI in health.
For healthcare organizations, evidence assessment should therefore happen before a technology is selected, not after a contract has already been signed.
Human oversight must be designed, not assumed
Healthcare AI is often described as keeping a “human in the loop.”
That phrase can create false reassurance.
A clinician technically being present does not necessarily mean meaningful human oversight exists.
Effective oversight requires the person using the system to understand enough about its intended use and limitations to recognize when its output may be unreliable.
The user must also have the authority and practical ability to question, override, or stop its use.
This raises very practical questions:
Who makes the final decision?
Can the AI recommendation be rejected or overridden?
Will the user know when the system is operating outside its intended conditions?
What happens when clinical judgment and AI output disagree?
Are important overrides recorded?
Is there a safe fallback if the AI system becomes unavailable?
Are staff trained to recognize automation bias and overreliance?
Viet Nam’s AI Law itself places human oversight and the ability for humans to intervene among its fundamental principles.
In healthcare, meaningful human oversight is therefore not simply an ethical principle.
It is a patient safety control.
Data governance is part of AI governance
AI and data governance cannot be separated.
Before adopting an AI system, healthcare organizations should understand not only what the system produces, but also what happens to the data around it.
What patient or organizational information enters the system?
Is identifiable health information involved?
Where are the data processed?
Where are they stored?
Who has access?
Are data transferred to another organization or jurisdiction?
How long are they retained?
Can the vendor use them to train or improve its models?
Can the organization restrict secondary use?
What happens to the data when the contract ends?
These questions now sit within Viet Nam’s AI framework as well as the country’s broader data protection environment. The Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP have both been in force since January 1, 2026.
For healthcare leaders, reviewing an AI product therefore cannot stop at reviewing the algorithm.
The data lifecycle around the algorithm matters just as much.
Vendor governance should not stop when procurement ends
Most healthcare organizations will not develop all of their own AI systems.
They will purchase, subscribe to, integrate, or otherwise use technologies developed by external vendors.
That makes vendor governance an important part of AI governance.
Traditional procurement questions about functionality, price, implementation, interoperability, and technical support remain important.
But AI introduces additional questions.
What is the intended use?
What is the system’s regulatory and risk classification?
What evidence supports the claims being made?
What data were used to develop and validate it?
What important limitations are known?
How does the vendor monitor performance?
How are serious incidents communicated?
Can the model change after implementation?
Will the healthcare organization be informed before significant updates?
What information will be available for audit or investigation?
How are patient and organizational data used?
Who is responsible for what when something goes wrong?
A strong contract cannot remove AI risk.
But weak due diligence and contracting can make good governance much harder once the technology is already embedded in clinical or operational workflows.
AI literacy is becoming an organizational capability
Governance frameworks can fail if the people making decisions about AI do not understand enough about it.
That does not mean every clinician needs to become a data scientist.
It means different people need different levels of AI literacy according to their roles.
Senior leaders need enough understanding to make informed strategy and risk decisions.
Clinicians need to understand intended use, limitations, appropriate reliance, and human oversight.
Quality and patient safety teams need to understand how AI-related risks and incidents may appear.
Information Technology and cybersecurity teams need to understand architecture, integration, access, and security.
Procurement teams need to know what evidence and documentation to request.
Legal and compliance teams need to understand applicable obligations.
Patients may also need meaningful information when AI materially influences their care or decisions concerning them.
The September 2026 WHO/Europe Knowledge Community report identified gaps in AI literacy and unclear accountability among recurring barriers to responsible AI implementation. It also highlighted participation by patients, communities, and frontline professionals as an important part of responsible governance.
Healthcare organizations should therefore think about AI capability building, not only AI acquisition.
Monitoring starts when AI goes live
Traditional technology projects sometimes treat “go-live” as the end of implementation.
For AI, it should be the beginning of another phase.
Before deployment, an organization should already know what it intends to monitor afterward.
Depending on the use case, this might include:
system performance;
relevant clinical outcomes;
false-positive and false-negative patterns;
unexpected or unsafe outputs;
override rates;
user concerns or complaints;
patient safety events;
workflow effects;
performance differences across relevant patient groups;
system downtime;
cybersecurity events;
changes in data quality; and
changes introduced through software or model updates.
Monitoring should also lead to action.
If performance deteriorates, who investigates?
If the risk profile changes, who reassesses the system?
If the vendor changes the model, does anything need to be revalidated locally?
When should use be restricted?
When should an AI system be retired?
These decisions are much easier to make when the governance pathway has been defined before a problem emerges.
Healthcare organizations do not necessarily need another committee
When organizations hear “AI governance,” one instinct may be to create an AI committee.
That may be appropriate for some organizations, but it is not automatically the answer.
Hospitals already have structures responsible for clinical governance, patient safety, quality management, Information Technology, cybersecurity, medical devices, procurement, ethics, legal compliance, and data protection.
For some organizations, the most practical model may be to connect AI governance to existing structures, with clearly defined responsibilities and escalation pathways.
For organizations implementing multiple AI systems, or systems with more significant clinical or organizational risks, a dedicated multidisciplinary AI governance group may make sense.
The right structure depends on the organization’s size, complexity, AI portfolio, and risk profile.
The important question is not:
“Do we have an AI committee?”
It is:
“Can our organization reliably make, document, monitor, and revisit the right decisions about AI throughout its lifecycle?”
What should healthcare organizations in Viet Nam start building now?
A practical AI governance foundation does not need to begin with a large or complicated framework.
Organizations can start by building several core capabilities:
Know what AI is already in the organization. Maintain an inventory that includes embedded AI, pilots, departmental tools, and centrally procured systems.
Define the problem and intended use. Be clear about what each AI system is expected to do, for whom, in what setting, and what success should look like.
Use risk-proportionate evaluation. Increase the depth of review as potential consequences for patients, staff, data, or operations increase.
Require appropriate evidence. Determine whether the available evidence supports the proposed use and is relevant to the organization’s patient population and context.
Clarify accountability. Define who owns the implementation, who oversees clinical or operational use, who approves changes, and who is responsible for escalation.
Design meaningful human oversight. Ensure users understand limitations and can question, override, intervene, or use a safe alternative when necessary.
Integrate data and cybersecurity governance. Understand the complete data flow around the system and apply appropriate privacy, security, and access controls.
Strengthen vendor governance. Require transparency about intended use, evidence, limitations, updates, incidents, data practices, and responsibilities.
Build role-specific AI literacy. Train people according to the decisions they need to make rather than giving everyone the same generic AI training.
Monitor and reassess after implementation. Establish performance indicators, safety signals, incident pathways, change controls, and triggers for reassessment or retirement.
Good governance does not require organizations to stop innovating.
In fact, it can make innovation easier.
When evidence requirements, decision rights, risk thresholds, and accountability are clear, organizations can evaluate promising technologies more consistently and with greater confidence.
The goal is not slower AI. It is better AI implementation.
Healthcare AI has real potential.
It may support clinicians, improve access to information, reduce burdensome work, identify patterns that are difficult to detect manually, and help health systems use limited resources more effectively.
The answer to AI-related risk is not to avoid innovation.
But speed alone is not a useful measure of progress.
A hospital that adopts ten AI tools without knowing how they are performing is not necessarily more advanced than one that implements three carefully selected systems, understands their evidence, trains its workforce, monitors performance, and knows who is accountable when something changes.
A better measure is whether AI creates safe, meaningful, and sustainable value for patients and the organization.
That is why healthcare AI governance matters now.
Viet Nam has entered a new regulatory phase for artificial intelligence at the same time that healthcare organizations are being presented with a rapidly growing range of AI possibilities.
The organizations best prepared for this environment will not necessarily be those that adopt AI first.
They will be those that build the capability to evaluate evidence, govern risk, implement responsibly, monitor real-world performance, and learn as the technology evolves.
That is the shift from AI adoption to responsible implementation.
And it is increasingly a healthcare leadership issue, not simply a technology issue.
Key references
Law on Artificial Intelligence No. 134/2025/QH15, adopted December 10, 2025, effective March 1, 2026.
Decree No. 142/2026/ND-CP, detailing provisions and implementation measures under the Law on Artificial Intelligence, effective May 1, 2026.
Decision No. 33/2026/QD-TTg, promulgating the current List of High-Risk Artificial Intelligence Systems, effective August 15, 2026.
World Health Organization Regional Office for Europe. Report of the Knowledge Community on responsible artificial intelligence in health, published September 1, 2026.
World Health Organization Regional Office for Europe. Bridging theory and practice: implementation insights on artificial intelligence in health care, published June 26, 2026.
WHO, ITU and WIPO Global Initiative on AI for Health, supporting governance, standards, technical guidance, and evidence-based adoption of AI for health.
Law on Personal Data Protection No. 91/2025/QH15, effective January 1, 2026, and Decree No. 356/2025/ND-CP, detailing its implementation.
This article is intended for educational and informational purposes. It does not constitute legal, regulatory, clinical, or technology procurement advice. Organizations should assess AI systems according to their specific intended uses, risks, evidence, regulatory requirements, and operating environments.
Updated: September 13, 2026
Digital Medicine Vietnam
Advancing evidence-based Digital Medicine in Viet Nam. A VietnamWellcare Initiative.
RESOURCES
COLLABORATION
info@digitalmedicine.vn
68 Nguyen Hue, HCMC, Vietnam
+84 909 228 476
+1 (202) 886 8868
© 2026 Digital Medicine Vietnam. Digital Medicine Vietnam is an initiative developed and operated by VietnamWellcare™.
