Vietnam Ministry of Science and Technology

Vietnam's Ministry of Science and Technology issued a binding directive on August 13, 2026 prohibiting every arm of the national government from uploading classified documents to public AI platforms — making it the first country in Southeast Asia to translate a parliamentary AI law into specific, operational enforcement guidance for its own bureaucracy.

The directive, addressed to cabinet ministries, judicial bodies, the National Assembly, and provincial administrations, names two government-approved AI platforms as the only systems authorized for state legal review work. All other AI tools — including commercial platforms available to the general public — are prohibited from receiving any document classified under Vietnam's state secrecy framework.

What the Directive Actually Requires

The ministerial letter is specific where most AI governance documents are aspirational. AI is designated strictly as a support instrument for civil servants — capable of analyzing legal texts, synthesizing provisions, flagging inconsistencies, and suggesting revisions — but explicitly barred from replacing the review conclusions of any authorized government body.

Every AI-generated output must be traceable, verifiable, and cross-referenced against source legal documents before any official can act on it. A responsible official must check, assess, and confirm each result before it carries force. This human-in-the-loop requirement — the principle that a human agent must participate in every consequential decision cycle — was the foundational philosophy articulated by then-Minister Nguyen Manh Hung when Vietnam's AI Law was signed in December 2025. Current Minister Vu Hai Quan, who took office on April 8, 2026, is now translating that philosophy into enforceable agency-level rules.

The August 13 directive also mandates compliance with Vietnam's existing state secret protection laws, its Cybersecurity Law, and the National AI Ethics Framework that took effect on March 10, 2026.

Why a Government Is Reviewing Its Entire Legal Code With AI

The directive is timed to support a comprehensive, government-wide audit of Vietnam's regulatory code — a large-scale exercise to identify outdated, contradictory, or redundant provisions across the country's legal framework.

Minister Vu Hai Quan's own August 3 statement to the ministry's July state management review captured the working philosophy driving the effort. The minister told officials not to strive for perfection or wait, but to do what can be done immediately.

The guidance establishes a six-step workflow for AI-assisted legal review: preparing documentation; creating inventories; conducting the review; verifying the results; issuing authoritative conclusions; and archiving records. All AI tools are expected to support the six priority review criteria established under Steering Committee Guidance No. 06/HD-BCĐ, issued April 22, 2026.

Documents eligible for AI-assisted review include currently valid legislation, partially expired instruments, temporarily suspended regulations, draft legislation, and related reports. The August 13 directive builds on an earlier communication, letter 2766/BKHCN-TTCNTT, issued April 29, 2026, which first introduced guidance on using digital technology and AI in the review process.

The Classified Documents Rule and What It Means for AI Vendors

The prohibition on uploading state secrets to public AI platforms is the directive's most commercially significant requirement. The ministry's platform evaluation criteria issued in July 2026 require AI platforms seeking approval for government work to meet a minimum score of 70 points out of 100 on a standardized evaluation framework, serve at least 5,000 simultaneous users in a pilot phase and 50,000 upon full deployment, use a Vietnamese-language model built using technology owned by a domestic company, and host all operational infrastructure within Vietnam.

The infrastructure-in-Vietnam requirement extends Vietnam's existing data localization logic — already codified in the Law on Data (Law No. 60/2024/QH15) and the Law on Personal Data Protection — from where data is stored to where it is processed. That distinction matters: a cloud AI service processing Vietnamese government documents on servers in Singapore, the United States, or anywhere outside Vietnam's borders cannot meet these criteria regardless of its technical capabilities.

The ministry's earlier letter (4920/BKHCN-CNCNTT, dated July 7, 2026) announced the two approved platforms by name. Neither is a Western AI product.

Who Benefits — and Who Is Locked Out

The approval criteria structurally favor Vietnam's dominant state-linked domestic technology companies. Viettel, the military-affiliated telecommunications and technology conglomerate that is Vietnam's largest company by revenue, recently introduced its VT-Super-120B-A12B large language model with 120 billion parameters — the kind of domestically owned, Vietnam-hosted model the criteria are designed to reward. VNPT, the state-owned telecoms group, and FPT Corporation, Vietnam's largest private technology company, have each built substantial AI infrastructure within Vietnam and established themselves as government technology partners.

Viettel Cyber Security issued warnings in April 2026 that "shadow AI" had become an uncontrollable risk across Vietnamese enterprise networks — workers routinely pasting proprietary documents into unapproved external platforms. The August 13 directive is, in part, a government-sector response to exactly that pattern.

For international AI providers — including those headquartered in the United States, the European Union, or elsewhere — the barrier is not technical quality but jurisdictional. A platform that cannot meet Vietnam's domestic infrastructure hosting mandate is categorically ineligible for government AI work regardless of its benchmark performance, and no waiver mechanism for foreign providers has been announced.

The Legal Architecture Behind the Directive

Vietnam's AI Law (Law No. 134/2025/QH15) was passed by the National Assembly on December 10, 2025, with 429 of 434 delegates voting in favor. It took effect on March 1, 2026, positioning Vietnam as the first Southeast Asian country to adopt comprehensive, parliamentary-level AI legislation.

The law introduced a three-tier risk classification system — high, medium, and low — with stricter obligations for higher-risk applications. For AI systems deployed in state management or public service, operators of high-risk systems must conduct impact assessments addressing risk identification, mitigation measures, and human oversight mechanisms. MoST sits at the apex of this structure as the lead body for centralized AI governance.

On April 30, 2026, the government issued Decree No. 142/2026/ND-CP, which took effect on May 1 and provided the first detailed implementation guidance for the law. Decree 142 established a national AI registration portal and database for AI system registration, managed by MoST, including a function to receive guidance requests and monitor AI usage within state agencies. Prime Minister Le Minh Hung's implementing plan — Decision No. 367/QD-TTg, dated March 3, 2026 — assigned detailed tasks, timelines, and responsibilities to ministries, including a comprehensive audit of legal instruments and a dedicated mandate for MoST to report findings to the Prime Minister.

Where Vietnam Stands in Southeast Asia

The August 13 directive is notable not for what it prohibits — state secrets have always been sensitive — but for the administrative specificity it imposes on how AI integrates with government work. No other Southeast Asian country has issued equivalent operational guidance.

According to multiple independent analyses of the regional AI governance landscape — including from the Singapore-based ISEAS-Yusof Ishak Institute and the Tech For Good Institute — Vietnam's binding AI Law stands in contrast to the broader ASEAN posture, which relies on voluntary compliance frameworks. Singapore, the region's governance leader by most measures, has built a sophisticated voluntary framework but has signaled no plans for a binding AI law. Malaysia, Thailand, Indonesia, and the Philippines are in various stages of drafting AI legislation but have not enacted any.

An analysis published in The Diplomat in July 2026 identified a meaningful structural gap: the AI Law is state-centric in its design, incorporating robust controls on how AI is used within government, but contains no independent oversight body — no equivalent to the EU's AI Office — to monitor whether the government itself is using AI within the law's stated principles.

The ASEAN Digital Economy Framework Agreement, expected to be signed by the end of 2026, could produce the first region-wide binding AI governance mechanism — one that Vietnam will have shaped from a position of legislative experience none of its neighbors yet possess.

What Does AI-Assisted Legal Review Actually Involve?

The technical requirements for the approved platforms reveal what Vietnamese government officials will actually experience when using these tools. Systems must be able to search and systematize legal documents by subject and applicability, track the validity status of regulations over time, compare and cross-reference legal provisions across different instruments, and detect signs of contradiction, overlap, or inconsistency between rules.

The anti-hallucination requirements are specific: platforms must not fabricate legal citations or create their own legal provisions. Each answer must fully reference the article, clause, and point of the legal document it draws from. When a question falls outside the scope of available data, the AI must proactively warn or decline to answer rather than generating an unverified response.

This level of operational specificity is what distinguishes a governance framework law from an enforcement directive. Vietnam has both. Most of its neighbors have neither.


Frequently Asked Questions

Can ChatGPT or other Western AI platforms be used for Vietnam government work under this directive?

No. Commercial public AI platforms — including tools developed by OpenAI, Anthropic, Google, and Microsoft — are explicitly barred from receiving any document classified under Vietnam's state secrecy framework. More broadly, only platforms approved through the Ministry of Science and Technology's evaluation process are authorized for the government legal review exercise. That evaluation requires Vietnamese-owned language models and infrastructure physically located within Vietnam, criteria that no major Western AI provider currently meets. Foreign AI companies operating in Vietnam have 12 months from the AI Law's March 2026 effective date to bring existing AI systems into compliance with the law's broader requirements, but government platform approval is a separate, higher bar.

How does Vietnam's approach compare to what ASEAN has done on AI governance?

Vietnam is the only Southeast Asian country that has enacted binding AI legislation at the parliamentary level. ASEAN's regional approach — the ASEAN Guide on AI Governance and Ethics, last updated in early 2025 — is voluntary and principle-based, carrying no enforcement mechanisms. Singapore leads the region on governance maturity through voluntary frameworks and sectoral guidance but has not introduced a binding AI law. Malaysia, Thailand, Indonesia, and the Philippines are drafting legislation but have not enacted any. The ASEAN Digital Economy Framework Agreement, expected to be signed by the end of 2026, could change this picture — but as of August 2026, Vietnam's combination of a framework law, implementing decree, ethics framework, and now operational agency directives is without parallel in the region.

What is the significance of Vietnam requiring AI platforms to be hosted inside Vietnam?

The infrastructure-in-Vietnam requirement extends the country's data localization logic from storage to processing. Under Vietnam's Law on Data (effective July 2025) and the Law on Personal Data Protection (effective January 2026), certain categories of data are already restricted from leaving Vietnam. Requiring government AI platforms to operate on infrastructure within Vietnam ensures that the compute process — not just the stored data — remains under Vietnamese jurisdictional control. For context, Vietnam demonstrated in May 2025 that it will enforce its digital governance rules: the government blocked Telegram nationwide after the platform declined to comply with data-sharing requests. That enforcement posture makes the infrastructure requirement consequential rather than merely aspirational.

What are the concerns critics have raised about Vietnam's AI Law?

Civil-liberties advocates and international legal analysts have flagged two structural gaps. First, Article 7 of the AI Law, which enumerates prohibited AI behaviors, uses broad language that grants Vietnamese authorities wide enforcement latitude — raising concerns, documented by IAPP and The Diplomat, that vague phrasing on "protecting legitimate rights" could enable politically motivated censorship. Second, the law contains no independent oversight body to monitor how the government itself uses AI — a gap that distinguishes it from the EU AI Act, which established an AI Office with cross-member supervisory functions. Supporters of the law argue that the regulatory sandbox, the human-in-the-loop requirement, and MoST's centralized governance role provide sufficient accountability; critics argue those mechanisms are effective only when the regulated party and the regulator are different entities.

Originally published on Tech Times