Which Healthcare AI Systems Are High-Risk in Viet Nam? What Decision No. 33/2026/QD-TTg Means for Healthcare Organizations

POLICY & REGULATORY INSIGHT

9/18/202614 min read

Which Healthcare AI Systems Are High-Risk in Viet Nam? What Decision No. 33/2026/QD-TTg Means for Healthcare Organizations

Artificial intelligence is moving rapidly into healthcare. Hospitals and clinics are beginning to encounter AI in medical imaging, endoscopy, clinical decision support, documentation, patient communication, remote monitoring, workflow management, and increasingly sophisticated medical devices.

Since Viet Nam's Law on Artificial Intelligence took effect in March 2026, an important question has emerged for healthcare organizations: Is an AI system high-risk simply because it is used in healthcare?

The answer is no.

On June 30, 2026, the Prime Minister issued Decision No. 33/2026/QD-TTg, promulgating Viet Nam's List of High-Risk Artificial Intelligence Systems. The Decision took effect on August 15, 2026. Healthcare is one of the sectors covered, but the current list does not classify every healthcare AI application as high-risk. Instead, it identifies specific systems and the circumstances in which they fall within the high-risk category.

This distinction matters. An AI system used to schedule appointments, an AI-assisted endoscopy system, a medical-imaging algorithm, a generative AI documentation tool, and an autonomous surgical robot should not automatically be treated as if they have the same legal risk classification. At the same time, being outside the current high-risk list does not mean that a healthcare AI system is risk-free, lightly regulated, or exempt from clinical governance.

Understanding both sides of that distinction is essential for responsible AI implementation in Vietnamese healthcare.

How Viet Nam's AI risk framework works

The Law on Artificial Intelligence No. 134/2025/QH15, effective March 1, 2026, classifies AI systems into three risk levels: high risk, medium risk, and low risk. Under Article 9, a high-risk AI system is one capable of causing significant harm to life, health, lawful rights and interests of organizations or individuals, national interests, public interests, or national security.

The Law also gives healthcare a particularly important status. Article 6 requires stricter risk management for the use of AI in essential fields that directly affect life, health, lawful rights and interests, or public order and safety. For healthcare specifically, the Law refers to patient safety, reliability under real-world conditions, and protection of health data. This broader requirement applies to healthcare AI as a field, but it should not be confused with formal classification as a high-risk AI system under Decision 33.

Decree No. 142/2026/ND-CP, effective May 1, 2026, provides the detailed classification framework. Under the Decree, an AI system is legally classified as high-risk when it is included in the List of High-Risk AI Systems promulgated by the Prime Minister. The criteria used to develop and update that list include the potential impact on life, health, property and rights, the degree of automation, the role of the system in final decision-making, the ability of humans to supervise and intervene, the sector of use, and the scale of potential impact.

The Decree also identifies situations in which a system meeting one or more of the general high-risk criteria should ordinarily not be proposed for inclusion on the high-risk list. These include systems limited to functions such as collecting, processing, standardizing, classifying, translating, or improving data without directly creating decisions affecting lawful rights and interests; systems with meaningful human oversight allowing an authorized person to independently review, intervene in, reject, or change a decision before it takes effect; systems used only for internal administration without directly affecting external parties; and systems that provide analysis, forecasts, assessments, or recommendations that remain advisory and are not used as the sole basis for a final decision.

There is, however, a limited exception. Even where one of these exclusions applies, the Prime Minister may consider including a system in the high-risk list if measurable technical or practical evidence shows a serious vulnerability or risk capable of directly harming national defense, security, or public order and safety.

This is why the statement “healthcare AI is high-risk” is too broad under the current Vietnamese legal framework.

What does Decision No. 33/2026/QD-TTg actually list in healthcare?

As of September 18, 2026, the healthcare section of the official high-risk list contains two entries, both concerning AI-supported surgery and surgical robotics. The two entries have related descriptions, but the level of autonomous action and the applicable conformity-assessment route differ.

The first entry covers an AI system supporting surgery or a surgical robot where AI is integrated into a robot that participates directly in an intervention or guides surgical manipulation, or is integrated into a fully autonomous or intelligent robot performing actions in place of human behavior.

The second entry also concerns an AI system supporting surgery or a surgical robot, but applies more specifically to machinery or robotic equipment using AI for autonomous control. It covers situations in which AI is integrated into a robot that directly performs a therapeutic action on a patient's body according to a medical order and carries out the action without requiring confirmation from a healthcare professional for each change in parameters.

The practical point is important. Decision 33 does not simply state that every product marketed as a “surgical robot” is automatically treated in exactly the same way. The actual functionality, level of autonomous control, relationship between the AI and the physical intervention, and role of healthcare-professional confirmation matter.

A product name or marketing description is therefore not enough to determine classification.

The two healthcare entries do not have the same conformity-assessment route

Article 13 of the AI Law requires high-risk AI systems to undergo conformity assessment before being put into use and again where significant changes affect the original assessment.

The Law provides two routes. For high-risk systems that are included in the subset requiring conformity certification before use, assessment must be performed by a registered or recognized conformity-assessment organization. For other high-risk systems, the provider may conduct the assessment itself or engage a registered or recognized conformity-assessment organization.

Decision 33 assigns the first healthcare entry to the latter route. In other words, the provider may perform the conformity assessment itself or use a qualified external organization. The more autonomous robotic-treatment category is assigned to the stricter route and requires conformity certification before being put into use, with assessment performed by a registered or recognized conformity-assessment organization.

This distinction is important for procurement. A healthcare organization considering an AI-enabled surgical system should not ask only whether the product has been “assessed.” It should understand which legal route applies, who performed the assessment, what system version and intended use were covered, and whether subsequent changes have affected the original conformity determination.

Are medical imaging AI, AI-assisted endoscopy and clinical decision support automatically high-risk?

Under the current version of Decision 33, they are not automatically classified as high-risk simply because they are used in healthcare.

The healthcare section does not currently list all AI used for radiology interpretation, pathology, AI-assisted endoscopy, diagnostic decision support, risk prediction, remote patient monitoring, clinical documentation, hospital administration, or generative AI. Its current scope is narrower and focuses on the two surgical and robotic configurations described above.

This should not be interpreted to mean that other forms of healthcare AI are unregulated or clinically low-risk. Article 6 of the AI Law still requires stricter risk management for AI used in healthcare, and other legal frameworks may apply depending on the technology, intended purpose, data use, and operating environment.

A more useful assessment therefore begins with several connected questions: What does the system actually do? What is its intended use? What decisions or physical actions does it influence? How autonomous is it? What meaningful human oversight exists? What patient or user population is affected? What other regulatory frameworks apply?

This is more reliable than starting from the label “AI” alone.

“Medium risk” does not mean moderate clinical risk

Another important point is that the terms high risk, medium risk, and low risk in Viet Nam's AI Law are legal classifications. They should not be treated as a complete measure of clinical or patient-safety risk.

Under Decree 142, an AI system that is not on the high-risk list is classified as medium risk when it can cause confusion, influence, or manipulation because users do not recognize that they are interacting with an AI system or with content generated by AI, subject to the more detailed exclusions in the Decree. Systems falling into neither the high-risk nor medium-risk categories are legally classified as low risk.

This has an important implication for healthcare. An AI application can potentially be classified as low risk under the AI-law taxonomy while still presenting clinically meaningful risks that require careful evidence review, medical-device analysis, cybersecurity controls, health-data protection, or patient-safety governance.

The AI-law category should therefore not be used as a substitute for a healthcare organization's own clinical, operational, information-security, and patient-safety risk assessment.

The high-risk list can change

Decision 33 should be understood as the current high-risk list, not as a permanent statement that other healthcare AI applications can never become high-risk.

Decree 142 establishes a process for ministries, provincial authorities, and other relevant bodies to review AI deployment and propose amendments to the list. Ministries and ministerial-level agencies review systems within their areas of responsibility, while the Ministry of Science and Technology coordinates, appraises, and submits proposed changes to the Prime Minister.

Healthcare organizations should therefore treat regulatory monitoring as part of AI governance. An organization should know which AI systems it is using, whether their functions are changing, whether new modules or models are being added, and whether the regulatory classification applicable to them changes over time.

This matters because the system itself may change even when its commercial name remains the same. Software updates, model replacement, additional functionality, increased autonomy, changes in data inputs, new integrations, or changes in intended use may alter the system's risk profile.

Significant changes can trigger reassessment

Decree 142 provides more detail about when conformity reassessment may be required for high-risk AI.

Examples include changes to the system's main function, intended purpose, or scope of application that create new risks or alter the assessed level of risk; changes to system architecture, the AI model, or key technical configurations that may affect accuracy, reliability, safety, or controllability; material changes to data sources or principal input data; integration with other systems or a new operating environment; and other changes that materially affect compliance with the high-risk management requirements under Article 14 of the AI Law.

For healthcare organizations, this means the relevant procurement question is not simply whether the product was compliant when it was purchased. It is also whether there is a defined process for identifying when a software update, model change, hardware change, new integration, or expanded intended use requires reassessment.

That question is particularly important for AI because many systems evolve more frequently than traditional medical technologies.

A hospital may be a deployer, not simply a customer

Healthcare organizations also need to understand their own legal role.

The AI Law distinguishes among developers, providers, deployers, and users. A hospital or clinic that operates an AI system under its control in its professional or service-delivery activities may fall within the role of deployer, depending on the circumstances.

This matters because Article 14 places responsibilities directly on deployers of high-risk AI systems. These include operating and supervising the system within its intended purpose, scope, and classified risk level; maintaining data safety and security and the ability for human intervention; maintaining applicable AI standards and technical-regulation compliance during operation; fulfilling transparency and incident-management obligations; providing information needed for regulatory accountability; and cooperating with providers and authorities in inspection, evaluation, post-market review, and incident remediation.

A hospital therefore cannot assume that AI compliance belongs entirely to the manufacturer or technology company.

In practice, these legal responsibilities connect directly with clinical governance. Hospitals need defined accountability, trained users, access controls, escalation pathways, incident management, change control, performance monitoring, and mechanisms for communicating with the provider when problems occur.

Human oversight remains fundamental

Decision 33 explicitly states that the use of an AI system does not change, transfer, or eliminate the authority and responsibility of the legally competent organization or individual. It also requires human supervision, control, and the ability to intervene during system operation.

In healthcare, meaningful human oversight should involve more than a clinician simply clicking “accept” after an AI recommendation appears on a screen. The responsible person needs sufficient information, competence, authority, time, and system support to review the output, recognize situations in which it may be unreliable, reject or override it when appropriate, and stop use if a safety problem arises.

Healthcare organizations therefore need to determine who may rely on AI output, when independent verification is required, how disagreements with AI are handled, whether overrides are possible and documented, and who has authority to suspend a system when a patient-safety concern emerges.

These are governance questions, but they are also patient-safety questions.

AI conformity assessment is not the same as clinical evidence

Healthcare organizations should also avoid confusing regulatory conformity with evidence that a technology is clinically appropriate.

A conformity assessment addresses whether the AI system satisfies applicable regulatory requirements. It does not, by itself, demonstrate that the technology will improve clinical outcomes, perform appropriately in a hospital's patient population, integrate successfully into its workflow, or provide sufficient value to justify adoption.

A hospital evaluating AI should therefore address two different questions: Has the system satisfied the applicable regulatory requirements? And is there sufficient evidence to support safe and effective use in our specific clinical environment?

The second question may require evidence of technical and clinical performance, external validation, applicability to the intended population, usability, human factors, workflow integration, local verification, and post-deployment performance.

Regulatory compliance and clinical evidence are complementary. One should not be treated as a substitute for the other.

AI risk classification is different from medical-device classification

This distinction is especially important for healthcare AI.

Viet Nam has a separate regulatory framework for medical devices under Decree No. 98/2021/ND-CP, as amended and supplemented, with the current consolidated framework reflected in Consolidated Document No. 08/VBHN-BYT dated March 6, 2026. Circular No. 24/2026/TT-BYT, effective July 1, 2026, further addresses the determination of risk levels and management measures for medical-device products.

Depending on its intended medical purpose and characteristics, an AI-enabled product may therefore also need to be analyzed under the medical-device framework. Whether a product is a medical device and how it is classified as a medical device are separate questions from whether its AI component is legally high-risk under the AI Law.

An AI-enabled surgical robotic system, for example, may have obligations under both frameworks. Satisfying requirements under one should not automatically be assumed to satisfy every requirement under the other.

At the same time, Viet Nam's AI framework seeks to avoid unnecessary duplication. Decree 142 allows valid results from testing, inspection, certification, conformity assessment, specialized regulation, technical standards, technical regulations, or product-quality law to demonstrate corresponding AI requirements to the extent that those requirements have already been lawfully and adequately assessed and the results remain valid. Additional assessment is then needed only for requirements that have not already been covered.

What about health data?

AI risk classification is only one part of healthcare AI governance.

Many clinical AI systems process personal and health information. Viet Nam's Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP took effect on January 1, 2026. Healthcare organizations using AI therefore need to consider not only the AI system's risk category but also how personal and health data are collected, accessed, processed, disclosed, transferred, stored, protected, and potentially reused.

A system may therefore sit outside Decision 33's current healthcare high-risk list while still raising important issues involving personal-data protection, medical-device regulation, cybersecurity, professional responsibility, clinical safety, contractual accountability, or intellectual property.

A mature AI governance process should not use the question “Is this system high-risk under Decision 33?” as its only screening test.

Serious incidents require a defined response process

Viet Nam's AI framework also places significant emphasis on what happens after deployment.

Under Article 19 of Decree 142, providers or deployers must submit a preliminary report for specified urgent serious incidents within 72 hours from the time the incident is confirmed. Other serious incidents must be preliminarily reported within five working days from confirmation. The Decree defines the point of confirmation as the time when the organization or individual has sufficient initial information to determine that the incident has occurred and is highly likely to originate from an AI-system fault, without waiting for completion of a comprehensive technical investigation. An official report on remediation results must subsequently be submitted within 15 days from submission of the preliminary report.

For healthcare organizations, this means AI incident management should be designed before a serious event occurs. The organization should know who receives the first internal report, who has authority to suspend use, how an AI event connects to the existing patient-safety reporting system, how the provider will be contacted, what logs and evidence must be preserved, and who determines whether regulatory reporting is required.

AI safety should therefore be integrated into existing clinical governance, patient-safety, risk-management, information-security, and quality-management systems rather than managed as an isolated information-technology issue.

The transitional dates are important

Decision 33 contains specific transitional arrangements that healthcare organizations should not overlook.

For systems included in Decision 33 that were already in operation before August 15, 2026, providers and deployers of systems in healthcare, education, and finance must complete the applicable AI-law compliance obligations before September 1, 2027. During this transitional period, the systems may continue operating unless a competent authority determines that a system presents a risk of serious harm and orders suspension or termination.

There is a separate rule for systems put into operation during the six months following the Decision's effective date. Providers and deployers of those systems must complete the applicable compliance obligations before March 1, 2027.

The transition timetable therefore depends not only on the sector but also on when the system entered operation. Healthcare organizations should not assume that all systems have the same compliance deadline.

What should healthcare organizations do now?

For most hospitals and clinics, the most useful first step is not to label every AI system “high-risk.” It is to know what AI is actually being used, what it does, and how it is being used.

Healthcare organizations should maintain an inventory of AI systems already operating, being piloted, embedded within medical equipment, included within software or cloud services, or being considered for procurement. For each system, the organization should understand its intended use, provider, deployment model, clinical role, patient population, level of autonomy, data flows, human oversight, applicable regulatory status, and whether its functionality falls within Decision 33.

Where a system appears to fall within the high-risk list, the organization should determine the roles of the provider and deployer, confirm the applicable classification, understand which conformity-assessment route applies, examine the relevant evidence and documentation, identify the applicable transition timeline, and establish governance for human oversight, incident response, monitoring, and significant system changes.

Where a system does not fall within the current high-risk list, the assessment should continue rather than stop. The organization still needs to determine its classification under the AI framework and consider other applicable requirements involving medical devices, personal data, cybersecurity, clinical governance, patient safety, and professional accountability.

Most importantly, legal classification should not become the organization's only measure of risk.

From compliance to responsible implementation

Decision 33 is important because it makes Viet Nam's risk-based approach to AI more concrete. For healthcare, however, its current scope is significantly more specific than the phrase “high-risk healthcare AI” may initially suggest.

As of September 2026, the healthcare section focuses on particular AI-supported surgical and robotic systems, with the more autonomous therapeutic system assigned to the stricter conformity-certification route. It does not automatically place every clinical AI application into the high-risk category.

At the same time, the AI Law requires healthcare applications more broadly to be subject to stricter risk management because of their potential impact on life and health. That means the correct conclusion is neither that all healthcare AI is legally high-risk nor that AI outside Decision 33 is low concern.

For healthcare leaders, the more useful questions are what the system actually does, how autonomous it is, what clinical decisions or physical actions it influences, whether meaningful human oversight remains, what evidence supports its intended use, which regulatory frameworks apply, how patient and health data are protected, and how performance and safety will be monitored after deployment.

Decision 33 should therefore be understood as more than a compliance document. It is one part of a broader shift toward risk-based AI governance in Viet Nam.

Responsible healthcare AI requires regulation, evidence, clinical governance, patient safety, data governance, and real-world implementation to work together.

Key references

National Assembly of Viet Nam. Law on Artificial Intelligence No. 134/2025/QH15, dated December 10, 2025, effective March 1, 2026.

Government of Viet Nam. Decree No. 142/2026/ND-CP detailing provisions and measures for implementation of the Law on Artificial Intelligence, dated April 30, 2026, effective May 1, 2026.

Prime Minister of Viet Nam. Decision No. 33/2026/QD-TTg promulgating the List of High-Risk Artificial Intelligence Systems, dated June 30, 2026, effective August 15, 2026.

Ministry of Health of Viet Nam. Consolidated Document No. 08/VBHN-BYT on medical device management, dated March 6, 2026.

Ministry of Health of Viet Nam. Circular No. 24/2026/TT-BYT on determining risk levels and management measures for medical device products, effective July 1, 2026.

National Assembly of Viet Nam. Law on Personal Data Protection No. 91/2025/QH15, effective January 1, 2026.

Government of Viet Nam. Decree No. 356/2025/ND-CP detailing provisions and measures for implementation of the Law on Personal Data Protection, effective January 1, 2026.

This article is intended for educational and informational purposes. It does not constitute legal, regulatory, clinical, medical-device, procurement, or technology advice. The classification and regulatory requirements applicable to a particular AI system should be assessed according to its specific intended use, functionality, degree of autonomy, provider and deployer roles, data practices, operating environment, and applicable laws and regulations.

Updated: September 18, 2026

Digital Medicine Vietnam

Advancing evidence-based Digital Medicine in Viet Nam. A VietnamWellcare Initiative.