Skip to content
Blog

Digital Tech Industry Law 71/2025: Vietnam first legislates AI risk management

Phạm Hải AnhPhạm Hải Anh · AI engineer··1 min read
Digital Tech Industry Law 71/2025: Vietnam first legislates AI risk management

Photo: Igor Omilaev / Unsplash

When an AI model reads your internal documents, what happens if it answers wrong, or accidentally leaks data? That question is no longer just technical — it is now legal. On 14 June 2025, the National Assembly passed the Digital Technology Industry Law (71/2025/QH15, effective 1 January 2026), first legislating lifecycle AI risk management.

Diagram of the four AI risk tiers under the Digital Tech Industry Law

How the law tiers AI risk

The law takes a risk-based approach, tiered from low to unacceptable. The higher the risk, the stricter the governance, transparency and control required. This mirrors international trends like the EU AI Act.

What it means for enterprise AI

  • AI handling sensitive data (internal documents, records) often falls into a higher-risk tier needing tighter control.
  • Businesses need to know what their AI does with data, where it is stored, and who accesses results.
  • Transparency and traceability become requirements, not options.

Why local AI fits this direction

When AI runs on your own infrastructure (local/on-prem), data is not sent to outside services — reducing leak risk and making control easier to prove. That is why Molly Reader runs AI locally to read and extract document data.

In practice

The law is a frame; many details will emerge through guidance. But the direction is clear: enterprise AI must be governable. If you are interested in local document AI, book a consultation.

Related articles

Free resource

Personal Data Protection checklist

Review your business before the law takes effect on 01/01/2026.

Get the checklist