Related daily report
August 15, 2026: Vietnam’s high-risk AI list becomes effective
The complete August 15 report also covers the proposed Pax Silica exclusivity test, Microsoft Foundry model retirements, Anthropic IPO valuation assumptions, AI infrastructure finance and recent multi-agent safety research.
Open the permanent August 15 reportThe direct answer
Vietnam is regulating particular AI uses by consequence, not declaring powerful AI illegal
Decision 33/2026/QĐ-TTg, signed on June 30 and effective from August 15, 2026, publishes a formal list of AI systems Vietnam considers high-risk. The list covers specific uses in education, ethnicity and religion administration, healthcare, banking, legal proceedings and transport.
The decision is easiest to understand if you separate three ideas that are often blurred together:
Power
How capable is the underlying model?
Use
What decision or physical process is the AI system actually performing?
Consequence
What can happen to a person, institution or public system if it is wrong?
Vietnam’s list is mainly about the second and third questions. It does not name frontier model brands. It names systems and functions: automated student assessment, automated credit decisions, surgical AI, certain public-administration decisions, broad biometric recognition in a defined legal setting, high-level autonomous transport and other safety-critical transport functions.
“High-risk AI” here means an AI system used in a context where failure or misuse can seriously affect health, rights, lawful interests, public interests or national security. It does not mean every system on the list must be switched off.
Today’s trigger
What changed on August 15?
The decision itself was issued earlier, on June 30. What changes today is its legal effect. The Vietnamese government’s official record lists August 15 as the effective date, and the Ministry of Justice’s implementation summary sets out how already-operating systems move into compliance.
That distinction matters. A regulation can be announced weeks before companies must actually treat it as operative. August 15 is therefore not a new draft or consultation date. It is the point at which Decision 33 becomes part of the active compliance framework around Vietnam’s AI law and its implementing decree.
The decision sits on top of a broader structure. Vietnam’s AI law defines high-risk systems by potential for serious harm, while Decree 142/2026/NĐ-CP supplies more detailed classification rules. The government’s summary of Decree 142 says providers must classify AI systems before they are put into use and are responsible for the accuracy and honesty of that classification.
Decision 33 adds something operational: a named list of use cases. Instead of leaving every organization with only an abstract instruction to judge “serious risk,” the government points to categories of systems that deserve heightened treatment.
What does “high-risk” mean in the Vietnamese framework?
The decision says a system can be treated as high-risk when it can cause significant harm to life, health, lawful rights and interests, national interests, public interests or national security, provided it is not excluded under the implementing decree.
The underlying AI law also contains an important limiting idea. Some narrow systems can fall outside the high-risk category when they perform a specific limited task, help a person optimize work, or check errors in work already completed by a human without replacing the human decision.
That creates a practical distinction between AI that assists and AI that materially determines.
Lower-consequence pattern
Assist a person
An AI system helps summarize, organize, check or suggest, while a responsible person still makes the substantive decision.
Higher-consequence pattern
Determine an outcome
An AI system automatically ranks a learner, decides credit, approves or rejects a public-administration file, operates critical transport infrastructure or otherwise changes a person’s position without meaningful human review.
This does not mean every assistive tool is automatically low-risk. Context still matters. But it explains why the decision repeatedly focuses on automation that becomes an official basis for decisions, creates direct effects, or operates at large scale.
The list
Which AI systems are named as high-risk?
The Ministry of Justice summarizes six broad sectors. The full annex is more detailed, especially for transport, but the examples show the logic of the classification.
AI that can shape learning outcomes or monitor students
The list includes AI that supplies self-study content under an education program using uncontrolled data sources, automatically tests or evaluates learners and ranks them, or monitors and analyzes learner behavior. The annex specifically points to biometric or behavioral analysis where privacy or psychological pressure can become material concerns.
AI used inside consequential public administration
Examples include automated scoring, classification or ranking of files used to identify beneficiaries of ethnic-policy programs, automated verification of ethnicity- or religion-related information, and systems that make final approval or rejection decisions in government processes without meaningful review.
AI close to physical medical intervention
The official summary highlights AI-assisted surgery and robotic surgical systems. The reason is intuitive: an error is not merely a bad recommendation on a screen; it can affect a person’s body and health directly.
AI that moves money or decides access to credit
The list includes systems that automatically conduct electronic transactions in banking and systems that automatically decide whether to grant credit. These functions can affect property, financial access and legal rights.
Broad biometric recognition in a defined litigation setting
The Ministry of Justice identifies wide-area biometric recognition used for public-interest civil litigation. The important point is that biometric identification becomes higher-stakes when it is tied to formal legal action rather than ordinary device access.
AI controlling vehicles, signals and critical infrastructure
Transport is the largest group: the Ministry says the list contains 31 systems in this sector. Examples include high-level autonomous vehicle control, automatic traffic or railway signal operation and dispatch, and AI used to operate or control important transport works and technical infrastructure.
The common thread is not “AI is advanced.” It is AI is close to a consequential decision or a safety-critical physical process.
Why does “high-risk” not mean “banned”?
The strongest evidence is in the decision’s own transition clause. Systems on the list that were already operating before August 15 are allowed to keep operating during the transition period unless a competent state authority determines that the system presents a risk of serious harm and orders it suspended or terminated.
If “high-risk” automatically meant prohibited, there would be no reason to create compliance deadlines for continued operation.
A better mental model is:
- Identify the use. Does the deployed system match one of the listed high-risk functions?
- Classify it correctly. Apply the AI law and Decree 142 criteria, including any exclusions.
- Apply the required controls. High-risk status brings stronger governance obligations under the wider legal framework.
- Keep human authority real. The AI system must not silently replace the lawful authority and responsibility of the organization or person who is supposed to decide.
- Escalate serious danger. Authorities retain power to require suspension or termination where serious harm is at issue.
A hospital using surgical AI, a bank using automated credit decisioning or a transport operator using AI control systems is not automatically unlawful because the system is high-risk. The relevant question is whether the system is classified, governed and operated in accordance with the applicable obligations.
The most important sentence is about responsibility, not technology
Decision 33 says that using an AI system does not change, transfer or eliminate the authority and responsibility that the law assigns to a competent agency, organization or person. It also requires human supervision, control and the ability to intervene while the system operates.
That is a stronger principle than simply placing a person somewhere “in the loop.” A human can be nominally present while having no realistic ability to understand or stop what the system is doing. The decision points toward a more practical standard: the responsible human or institution must retain genuine authority.
For organizations, that raises questions that are easy to overlook during AI procurement:
- Who is legally responsible when the AI system produces the recommendation or action?
- Can that person actually review or override the output before it takes effect?
- What information is available to support that review?
- Is intervention technically possible while the system is operating, not only after damage occurs?
- Are logs retained so an organization can reconstruct how a consequential output was produced?
The decision itself does not answer every implementation detail in those five questions. They are operational implications of the responsibility and human-intervention principles, not a quotation of a prescribed checklist.
Transition
When do existing systems have to comply?
The transition timetable is not one date for every system.
Decision takes effect
The high-risk list becomes operative.
Most other listed sectors
Already-operating systems in the remaining listed sectors must complete applicable compliance obligations by this date.
Healthcare, education and finance
The decision gives already-operating systems in these areas the longer transition period.
The signed decision also addresses systems put into operation during the first six months after the effective date: providers and deployers of those systems must complete applicable compliance obligations before March 1, 2027.
One wording detail is worth preserving. The named sector in the list is banking, while the transition clause uses the broader term finance. Organizations should therefore rely on the Vietnamese legal text and competent local advice when mapping a specific system to a deadline rather than assuming an English summary resolves every boundary.
What should a company using AI in Vietnam do now?
The practical first step is not to ask whether your vendor sells a “high-risk model.” Model branding is the wrong unit. Map the deployed function.
Inventory AI systems by decision
Record what each system actually does, which people it affects and whether its output is advisory, automatically applied or physically executed.
Map systems to the Decision 33 list
Check the full Vietnamese annex, not only a short English-language summary. Transport in particular contains many detailed system types.
Document the human authority chain
Identify who is authorized to review, override, stop or approve consequential actions and whether the technical design actually gives that person control.
Determine transition status
Record whether the system was operating before August 15, enters service during the following six months, or is deployed later. The applicable timetable depends on that status and sector.
Separate vendor claims from legal classification
A supplier saying a product is “assistive” does not by itself decide the classification. Look at the real workflow, the automation level and the consequences of the output.
Get local legal confirmation for borderline cases
This article explains the public rules in plain English; it is not a substitute for Vietnamese legal advice on a specific deployment.
This use-case inventory has another benefit: it makes AI governance less abstract. Instead of maintaining a list of model names that quickly goes stale, the organization maintains a list of decisions and processes. Models can change underneath them without losing the governance map.
The bigger lesson: AI regulation is becoming operational
The most important part of Decision 33 may be its concreteness.
Early AI policy debates often stayed at the level of principles: fairness, safety, transparency, human oversight. Those principles matter, but companies cannot build a compliance program around slogans alone. They need to know which systems are in scope, who is responsible, what human control means in the workflow and when changes are due.
Vietnam’s new list moves in that direction. It names real activities: grading learners, making credit decisions, operating transport infrastructure, supporting surgery and making certain public decisions. That turns AI governance into an inventory problem and a workflow-design problem.
It also shows why comparing countries only by whether they have an “AI law” is too shallow. The practical burden appears in the layers underneath: implementing decrees, high-risk lists, transition dates, sector rules and enforcement practice.
For ordinary users, the takeaway is simpler. When an AI system affects a consequential decision, the important question is no longer only “Which model is this?” Ask:
Who can explain the decision, who can intervene, who can correct it, and who remains accountable when the software is wrong?
Vietnam’s Decision 33 puts that question near the center of its high-risk framework. That makes the August 15 effective date more than a bureaucratic milestone. It is another sign that AI governance is moving from broad principles into the machinery of real decisions.
Sources and legal boundary
Official Vietnamese sources used for this explainer
- Government of Vietnam — official record for Decision 33/2026/QĐ-TTg, issued June 30 and effective August 15, 2026
- Government of Vietnam — signed Decision 33/2026/QĐ-TTg and full annex of high-risk AI systems
- Vietnam Ministry of Justice — official implementation summary, sector examples and transition deadlines
- Government of Vietnam — official record for Decree 142/2026/NĐ-CP implementing the AI law
- Government of Vietnam — summary of Decree 142 classification responsibilities and three risk levels
- Vietnam national legal database — AI law text, including the definition and management of high-risk AI systems
Legal boundary: This article is an explanatory summary for general readers. Where an English description could blur a legal category, the Vietnamese source text controls. Organizations making compliance decisions should review the signed instruments and obtain qualified Vietnamese legal advice.