Artificial intelligence has entered companies’ daily operations: customer care chatbots, CV screening tools, internal credit scoring systems, drafting assistants. But behind the convenience are legal risks many companies have not fully anticipated: customer data uploaded to public AI models, AI-generated content infringing intellectual property, automated decisions causing damage with nobody accountable.
From 01/01/2026, the Digital Technology Industry Law 2025 (No. 71/2025/QH15) officially sets principles for artificial intelligence application in Vietnam. Companies using AI need to both comply with the new legal framework and establish contracts and internal governance mechanisms to control risks.
Quick summary
| Main legal bases | Article 41 Law 71/2025/QH15; Law 91/2025/QH15; Intellectual Property Law |
|---|---|
| Key points | AI must be human-centred, transparent and explainable; contracts with AI providers must clearly define data, IP and liability |
| Target audience | Companies deploying chatbots, recruitment AI, customer care AI |
Legal framework on artificial intelligence in Vietnam
The Digital Technology Industry Law 2025 (No. 71/2025/QH15), effective from 01/01/2026, is Vietnam’s first statute directly regulating artificial intelligence. Article 41 sets AI application principles that all organisations and individuals using AI in Vietnam must follow.
Note that AI is not only governed by Law 71/2025/QH15. When AI systems process personal data, the Personal Data Protection Law 2025 and Decree 356/2025/ND-CP apply simultaneously. When AI creates content, the Intellectual Property Law is invoked. Companies need to view AI within the overall legal framework, not as isolated statutes.
Seven AI application principles from 01/01/2026
Article 41 of Law 71/2025/QH15 sets artificial intelligence application principles, including: human-centred; ensuring transparency, accountability and explainability of AI systems; not letting AI exceed human control; ensuring safety and cybersecurity; complying with data and personal data protection regulations; controlling algorithms, models and managing risks throughout AI systems’ lifecycle.
For companies, these principles translate into practical obligations: reasonably understanding how AI systems make decisions affecting customers or employees; having human supervision and intervention when needed; assessing and controlling risks throughout use, not only at purchase.
Legal risks when companies use AI
The first and most common risk concerns data: employees paste customer data, contracts and financial reports into public AI tools for summarising, translating or analysing. This may constitute transferring personal data to third parties without legal basis, while leaking trade secrets. Usage often happens at individual level, beyond IT’s control, so many companies only discover it too late.
The second risk concerns intellectual property: AI-generated content may unlawfully copy others’ works, or companies may mistakenly believe they exclusively own it. The third risk is liability: when chatbots give wrong advice causing damage, when CV screening systems discriminate, the deploying company is usually the liable party.
Data fed into AI systems: silent leak risks
Every prompt employees enter into AI tools is a data transfer. With public AI tools, input data may be used by providers to train models, meaning customer data and company trade secrets may appear in AI answers to other users.
Prevention starts with internal policy: defining data types absolutely prohibited from public AI tools (see sensitive personal data processing); guiding the use of enterprise AI versions committed to not using data for training; and training employees to recognise risks. Contractually, when buying AI solutions, companies need clauses binding providers not to use company data to train shared models (see tech vendor and cybersecurity review).
Intellectual property in AI-generated content
The Intellectual Property Law protects works created by humans; content generated fully automatically by AI without human creative intervention is hard to recognise as copyright-protected subject matter. This means companies may not have exclusivity over AI-generated content as they assume.
Conversely, using AI-generated content also carries infringement risks: AI models trained on massive data may “remember” and reproduce protected works. Companies using AI to design logos or write advertising content need checking procedures to avoid inadvertently infringing others’ rights. In provider contracts, include warranties on training data legality and compensation mechanisms when third-party IP claims arise.
Liability when AI produces wrong results
When a company’s chatbot gives wrong warranty policy advice causing customer damage, when AI screening systems reject candidates based on discriminatory criteria, who bears legal liability? Under general principles, the company deploying and operating the AI system is liable to customers, employees and affected third parties.
Companies may then claim compensation from providers under contracts, but this depends on whether contracts contain appropriate clauses. Many current contracts limit provider liability to very low levels, even excluding liability for indirect damage. Accepting such terms without negotiation means companies bear all risks from systems they do not fully control.
Contract terms with AI solution providers
Contracts buying or leasing AI solutions should be drafted like high-risk technology contracts. Core contents: clear description of system scope, features and limits; measurable quality and accuracy commitments; model update and maintenance obligations; clauses allowing companies to inspect and evaluate systems.
Contracts should define provider liability when systems malfunction causing damage, including compensation mechanisms and reasonable liability caps; termination rights when systems fail to meet committed quality metrics, with data migration plans.
Data clauses in AI contracts
Contracts with AI providers must include personal data processing agreements under Article 7 of Decree 356/2025/ND-CP. Specific contents: commitments not to use company data to train shared models without consent; data storage and processing locations; obligations to delete and return data upon contract termination.
Companies should also require providers to be transparent about whether systems log prompts and results, where logs are stored and for how long, as logs may contain personal data and trade secrets.
Internal governance of AI use in companies
Alongside contracts, companies need internal AI use policies. Policies should classify permitted and prohibited AI tools for work; define data types allowed into each tool category; approval procedures before deploying new AI systems; and each department’s responsibilities in monitoring use.
Employees need to understand risks of pasting data into public AI, how to verify AI outputs, and obligations to report when systems behave abnormally. For AI making decisions affecting people, periodic reviews should detect bias and errors.
AI in special sectors: recruitment, finance, customer care
Some AI applications are simultaneously governed by multiple regulatory layers. CV screening and candidate evaluation AI must comply with AI principles under Law 71/2025/QH15, employee data regulations at Article 25 of Law 91/2025/QH15, and must not violate labour equality and anti-discrimination regulations. Companies need to notify candidates about AI use in recruitment and give them the right to explanations about decisions concerning them.
AI in finance needs additional sectoral regulations. Customer care chatbots must fully meet consent and data subject rights requirements. For each special sector, companies should have dedicated legal assessments before deployment.
How FLAT LAW FIRM supports companies
FLAT LAW FIRM supports companies with legal review before AI system deployment: assessing compliance with Law 71/2025/QH15, Law 91/2025/QH15 and sectoral regulations; drafting and negotiating contracts with AI solution providers, including data, IP and liability allocation clauses; building internal AI use policies and employee training programmes.
We also support AI-related dispute handling: customer complaints about automated decisions, disputes with providers over system quality. We work in Vietnamese, Chinese and English. See also tech vendor and cybersecurity review and the data and technology compliance checklist.
Frequently asked questions
Which law regulates artificial intelligence in Vietnam?
The Digital Technology Industry Law 2025 (No. 71/2025/QH15), effective from 01/01/2026, is the first statute directly regulating AI, with Article 41 setting AI application principles. Meanwhile, the Personal Data Protection Law 2025 and related sectoral laws also apply when AI processes data or operates in special sectors.
What are the risks of employees using public ChatGPT for work?
Input data may be used by providers to train models, leading to customer data and trade secret leaks. Companies need internal policies defining data types allowed into public AI tools and guide the use of enterprise AI versions with data protection commitments.
Is AI-generated content protected by intellectual property?
Current Vietnamese law protects works created by humans; fully automatically AI-generated content is hard to recognise as copyright-protected. Companies should not assume exclusivity over AI-generated content.
What are the most important clauses in AI solution purchase contracts?
Data clauses (not using company data to train shared models), quality and accuracy commitments, liability allocation when systems malfunction, system inspection rights, and obligations to delete and return data upon contract termination.
Does AI CV screening require candidate notification?
It should. AI use in recruitment is governed by both Law 71/2025/QH15 and employee data regulations; candidates have the right to know and receive explanations about decisions concerning them, and systems must not discriminate.
Talk to FLAT LAW FIRM
If your company is deploying AI or negotiating contracts with AI solution providers, FLAT LAW FIRM is ready to support legal review in Vietnamese, Chinese and English.
