Viet Nam’s Law on Artificial Intelligence: What Healthcare Organizations Need to Know and Prepare For

POLICY & REGULATORY INSIGHT

9/13/202611 min read

Viet Nam’s Law on Artificial Intelligence: What Healthcare Organizations Need to Know and Prepare For

Artificial intelligence is becoming increasingly visible in healthcare, from clinical decision support and medical imaging to documentation, patient communication, monitoring, workflow automation, and increasingly sophisticated medical technologies.

As AI becomes more common, the conversation is increasingly shifting from whether healthcare organizations will use AI to a more practical question:

How should healthcare organizations evaluate, implement, and govern AI safely and responsibly under Viet Nam’s new regulatory framework?

That question became much more important in 2026.

Viet Nam’s Law on Artificial Intelligence, Law No. 134/2025/QH15, took effect on March 1, 2026. It was followed by Decree No. 142/2026/ND-CP, effective from May 1, 2026, which provides more detailed rules on risk classification, conformity assessment, transparency, incident management, and other implementation requirements.

Decision No. 33/2026/QD-TTg, effective from August 15, 2026, subsequently established the current list of high-risk AI systems.

Another important implementation milestone came on August 28, 2026, when the Ministry of Science and Technology officially put Viet Nam’s National Single-Window Artificial Intelligence Portal and National Artificial Intelligence Database into operation. The portal provides a digital channel for activities including risk-classification notifications, serious-incident reporting, regulatory information, and other procedures under the AI framework.

For healthcare leaders, these developments matter because healthcare receives specific attention under the Law.

But understanding what they mean in practice requires more than asking whether an organization is “using AI.”

It requires looking at what the system does, how it is used, what decisions it influences, who controls it, what risks it creates, what data it uses, and what safeguards are in place.

Healthcare receives specific attention under the AI Law

Viet Nam’s AI Law takes a human-centered and risk-based approach.

Its fundamental principles include human oversight and the ability to intervene in AI-supported decisions, along with safety, data security, transparency, fairness, and accountability. The Law states that AI should serve people rather than replace human authority and responsibility.

Healthcare is specifically addressed as an essential sector.

Article 6 requires stricter risk management for AI applications in sectors that may directly affect human life, health, legitimate rights and interests, or public safety. For healthcare, the Law highlights three considerations in particular:

patient safety, reliability under real-world conditions of use, and protection of health data.

These are important distinctions.

An AI system may perform well during development or controlled testing and still encounter problems once introduced into a real healthcare environment.

The patient population may differ from the population on which the system was developed or validated. Data quality may change. Staff may use the technology differently from how its developers expected. Integration with existing clinical workflows may introduce new risks. Users may also place too much, or too little, trust in an AI recommendation.

For healthcare organizations, responsible AI therefore cannot stop at technical performance or formal regulatory status alone.

An equally important question is whether the technology can be used safely, reliably, and appropriately in the organization’s actual setting of care.

The first question is not only “What does the AI do?” but also “What role do we have?”

The Law distinguishes several actors, including developers, providers, deployers, users, and people affected by AI systems.

For many hospitals and other healthcare organizations purchasing and implementing an external AI product, one of the most relevant roles will be that of the deployer.

Under the Law, a deployer is an organization or individual that uses an AI system under its control as part of professional, commercial, or service activities.

This distinction matters because responsibility does not remain entirely with the technology vendor.

For high-risk systems, deployers have responsibilities related to appropriate operation and monitoring, data safety and confidentiality, human intervention, transparency, incident management, accountability, and cooperation with providers and regulators.

A healthcare organization may also take on additional responsibilities depending on what it develops, modifies, integrates, or introduces into use.

For example, an organization that develops its own AI application, substantially modifies an existing system, or introduces a system under its own name may have responsibilities that go beyond those of a conventional end user.

This is why healthcare organizations should identify their legal and operational role for each AI system, rather than viewing AI governance simply as a relationship between “the hospital” and “the vendor.”

Not every healthcare AI system is automatically high-risk

This is one of the most important points for healthcare organizations to understand.

The AI Law establishes three risk levels: high risk, medium risk, and low risk.

Providers are responsible for classifying their systems before putting them into use. Deployers generally inherit the provider’s classification. Reclassification may be required when a deployer modifies, integrates, or changes the system in a way that introduces new or higher risks.

For medium-risk and high-risk systems, providers must notify the classification result to the Ministry of Science and Technology through the National Single-Window Artificial Intelligence Portal before the system is put into service.

Being used in healthcare does not, by itself, make every AI system legally high-risk.

Under the current framework, high-risk classification needs to be understood by reading the AI Law, Decree No. 142/2026/ND-CP, and the high-risk list issued under Decision No. 33/2026/QD-TTg together.

Decree No. 142 considers factors such as the potential impact on life, health, rights and safety, the level of automation, the system’s role in final decision-making, the possibility of human oversight and intervention, the sector in which the system operates, and the scale of its impact.

It also recognizes circumstances in which a system should not normally be proposed for inclusion on the high-risk list, including certain systems used only for internal organizational operations and systems whose outputs are advisory rather than the sole basis for a final decision.

As of September 2026, the healthcare section of Decision No. 33 currently focuses on specified forms of AI-assisted surgical systems and surgical robots, including AI integrated into robots that participate directly in interventions or guide procedures, and certain AI-controlled robotic equipment that directly performs therapeutic actions under defined conditions.

This is an important reminder that terms such as “clinical AI,” “medical AI,” and “high-risk AI” should not be treated as interchangeable.

An AI-assisted imaging application, a diagnostic support tool, a generative AI documentation assistant, a patient-facing chatbot, and an autonomous surgical system may have very different risk profiles and regulatory classifications.

At the same time, being outside the current high-risk list does not mean that an AI system is outside governance or regulation.

Healthcare organizations may still need to consider transparency, patient safety, personal data protection, cybersecurity, professional responsibilities, and other applicable sector-specific requirements.

The high-risk list may also evolve as technology and patterns of use change.

AI risk classification and medical device classification are not the same thing

Healthcare organizations should also distinguish risk classification under the AI Law from classification and regulatory requirements applicable to medical devices.

Where an AI-enabled product falls within Viet Nam’s medical device framework, relevant medical device requirements may operate alongside the AI regulatory framework.

This distinction has become particularly relevant following Circular No. 24/2026/TT-BYT, effective from July 1, 2026, which addresses risk determination and management measures for medical device products.

The two frameworks may overlap around the same technology, but they answer different regulatory questions.

In practice, healthcare organizations assessing an AI-enabled medical technology should therefore avoid asking only:

“What is its AI risk classification?”

They should also ask:

“Does this product fall under medical device regulation, and if so, what additional requirements apply?”

High-risk AI brings additional requirements

Where an AI system is classified as high-risk, the regulatory expectations become more demanding.

The Law requires high-risk AI systems to undergo conformity assessment before being put into service and again when significant changes occur during use.

Depending on the system and its position in the applicable high-risk list, conformity assessment may involve provider self-assessment or assessment by a registered or recognized conformity assessment organization. Certain systems may require mandatory conformity certification before use.

Providers of high-risk systems are expected to maintain risk-management measures, manage the quality of relevant training, testing, and operational data, retain appropriate technical documentation and logs, enable human oversight and intervention, meet transparency and incident-management requirements, and provide information needed for accountability and safe use.

Deployers have their own responsibilities.

They must operate and monitor high-risk systems according to the intended purpose, scope, and classified risk level, maintain data safety and confidentiality, ensure the ability for human intervention, address transparency and incident obligations, and cooperate in post-market monitoring and corrective action.

This moves AI governance beyond a one-time purchasing decision.

It becomes an ongoing organizational responsibility throughout the technology lifecycle.

Human oversight needs to be real, not symbolic

Human oversight appears repeatedly throughout Viet Nam’s AI framework.

For healthcare, this is particularly important.

Simply placing a clinician somewhere “in the loop” does not necessarily create effective oversight.

The person responsible for oversight needs to understand what the AI is intended to do, where its limitations lie, when its output should be questioned, how intervention can occur, and who remains responsible for the final clinical or operational decision.

In practical terms, healthcare organizations should be able to answer questions such as:

Who is authorized to accept, reject, or override an AI recommendation?

What happens when a clinician disagrees with the system?

Can the technology be safely stopped or bypassed?

Are important overrides and interventions recorded?

Do users understand automation bias and the risk of overreliance?

Who reviews patterns of errors, unexpected outcomes, complaints, overrides, or changes in performance?

These are not simply abstract questions about “AI ethics.”

They are questions of clinical governance, operational reliability, and patient safety.

AI incidents need a clear governance pathway

Hospitals already manage patient safety events, information security incidents, medical device problems, clinical complaints, and other forms of operational risk.

AI adds another layer, but it should not become another disconnected silo.

The AI Law requires relevant actors to detect, address, record, and report serious AI incidents. Decree No. 142 provides more detailed reporting requirements.

For serious incidents considered emergencies, a preliminary report is generally required within 72 hours after the incident is confirmed. Other serious incidents are subject to a preliminary reporting period of five working days, followed by further reporting requirements under the Decree.

The National Single-Window Artificial Intelligence Portal is now the central digital channel for these regulatory processes.

For a hospital, the practical implication is important.

An AI-related problem should not disappear between the Information Technology Department, clinical departments, quality management, patient safety, biomedical engineering, information security, senior leadership, and the vendor.

Organizations should determine in advance what constitutes an AI incident, who receives the first report, who evaluates its clinical significance, when the vendor must be contacted, when use should be restricted or stopped, and when regulatory reporting is required.

AI incident management should be connected with the organization’s existing patient safety, clinical governance, cybersecurity, medical device vigilance, and quality-management processes.

The safest time to answer these questions is before an incident occurs.

Health data cannot be treated simply as “fuel for AI”

AI systems often depend heavily on data.

Healthcare organizations therefore need to understand not only what an AI system produces, but also what data it receives, where those data go, how they are processed, who can access them, how long they are retained, and whether they may be reused for training or system improvement.

The AI Law explicitly links healthcare AI with the protection of health data. It also prohibits collecting, processing, or using data for the development, training, testing, or operation of AI systems in ways that violate applicable laws on data, personal data protection, intellectual property, or cybersecurity.

This sits alongside Viet Nam’s broader personal data protection framework.

The Law on Personal Data Protection No. 91/2025/QH15 has been in force since January 1, 2026, together with Decree No. 356/2025/ND-CP, which provides detailed implementation measures.

For healthcare organizations, this means that an AI assessment should examine the entire data lifecycle, not only the algorithm.

A system that appears clinically useful may still create unacceptable risk if the organization does not understand how sensitive health information is collected, transmitted, stored, accessed, transferred, or reused.

Existing AI systems should not be ignored

Another important feature of the new framework is its transitional arrangements.

AI systems that were already operating before the new rules took effect are not simply outside the regulatory framework.

For systems covered by the high-risk list under Decision No. 33 that were already operating before the Decision took effect, providers and deployers in the healthcare, education, and financial sectors have until before September 1, 2027 to complete the applicable compliance obligations.

Decision No. 33 also provides that systems covered by the Decision that are put into operation during the six months following its effective date must complete the applicable compliance obligations before March 1, 2027.

This means organizations should not focus only on future procurement.

An inventory of AI already in use may be just as important.

Some healthcare organizations may discover that AI functionality is already embedded in medical equipment, imaging platforms, clinical software, administrative systems, communication tools, or vendor services without having previously been treated as part of an organization-wide AI governance program.

What should healthcare organizations do now?

Healthcare organizations do not need to create layers of bureaucracy around every AI tool.

They do need a structured and risk-proportionate way to understand what they are using and where the important risks lie.

A practical starting point is to:

  1. Create an AI inventory. Identify systems already in operation, under pilot, being procured, or being considered. Include AI embedded within other products and services, not only solutions explicitly marketed as “AI.”

  2. Clarify intended use. Document what each system is intended to do, who will use it, what decisions it may influence, and what could happen if its output is wrong or misleading.

  3. Identify organizational roles. Determine whether the organization is acting as a deployer, provider, developer, user, or a combination of these roles.

  4. Confirm risk classification, notification, and regulatory status. Request the provider’s classification and supporting documentation. For medium-risk or high-risk systems, understand the relevant notification requirements. Where applicable, determine whether conformity assessment, medical device regulation, or other sector-specific requirements also apply.

  5. Evaluate evidence before adoption. Regulatory classification does not establish clinical value. Assess evidence of performance, validation, relevant patient populations, limitations, intended use, and suitability for the local context.

  6. Define human oversight and accountability. Establish who may rely on the system, who can override it, who remains responsible for decisions, and under what circumstances its use should be restricted or suspended.

  7. Build monitoring and incident management into implementation. Monitor performance, unexpected behavior, user concerns, overrides, patient safety signals, system updates, and significant incidents after deployment.

  8. Review data governance. Understand what personal and health data enter the system, where they are processed, who can access them, whether they leave the organization, and whether they may be retained or reused for other purposes.

  9. Include AI governance in procurement. Vendor selection should examine more than functionality and price. Due diligence and contracts should consider evidence, documentation, risk classification, system updates, data use, cybersecurity, incident notification, responsibilities, monitoring, and ongoing support.

  10. Use risk-proportionate multidisciplinary oversight. AI governance should not sit with Information Technology alone. Depending on the use case and level of risk, clinical leadership, patient safety, quality management, legal and compliance, information security, data governance, procurement, biomedical engineering, and senior management may all need to participate.

Compliance is necessary, but responsible implementation goes further

One of the most important lessons for healthcare organizations is that regulatory compliance and responsible implementation are related, but they are not the same thing.

A system can satisfy a formal regulatory requirement and still perform poorly in a particular hospital.

A technology can have promising published evidence and still encounter problems when patient populations, workflows, infrastructure, staffing, or data quality differ from the setting in which it was originally evaluated.

A clinician can technically remain responsible for a decision while, in practice, becoming overly dependent on an automated recommendation.

An AI system can also continue to change after deployment through software updates, model revisions, new integrations, changing data, or changes in how people use it.

For this reason, strong healthcare AI governance should keep asking two questions:

Are we meeting the applicable legal and regulatory requirements?

And:

Do we have enough evidence, governance, monitoring, and human oversight to use this system safely and effectively in our own environment?

Viet Nam’s new AI regulatory framework makes the first question increasingly unavoidable.

Patient safety makes the second one just as important.

As healthcare organizations expand their use of artificial intelligence, the goal should not simply be faster AI adoption.

It should be responsible implementation, where evidence, risk, accountability, human oversight, data governance, and real-world performance are considered throughout the technology lifecycle.

That is likely to become one of the most important governance challenges, and opportunities, for healthcare organizations in Viet Nam in the years ahead.

Key legal and regulatory sources

Law on Artificial Intelligence No. 134/2025/QH15, adopted December 10, 2025, effective March 1, 2026.

Decree No. 142/2026/ND-CP, detailing a number of provisions and measures for implementation of the Law on Artificial Intelligence, effective May 1, 2026.

Decision No. 33/2026/QD-TTg, promulgating the List of High-Risk Artificial Intelligence Systems, effective August 15, 2026.

Law on Personal Data Protection No. 91/2025/QH15, effective January 1, 2026.

Decree No. 356/2025/ND-CP, detailing provisions and implementation measures under the Law on Personal Data Protection, effective January 1, 2026.

Circular No. 24/2026/TT-BYT, addressing risk determination and management measures for medical device products, effective July 1, 2026.

This article is intended for educational and informational purposes and does not constitute legal advice. Organizations should assess the legal and regulatory requirements applicable to their specific technologies, intended uses, organizational roles, and operating circumstances.

Updated: September 13, 2026