AI IN THE ENTERPRISE: LEGAL BLIND SPOTS BUSINESSES SHOULD ADDRESS BEFORE THEY BECOME LIABILITIES
Artificial intelligence is no longer confined to technology companies. Businesses across industries are increasingly integrating AI into marketing, human resources, accounting, customer service and day-to-day operations. As adoption accelerates, the key legal question is no longer whether businesses should use AI, but how they can do so without creating avoidable regulatory and liability risks.
Vietnam’s emerging AI regulatory framework includes the 2025 Law on Artificial Intelligence, Decree No. 142/2026/ND-CP, and Circular No. 05/2026/TT-BKHCN on the National AI Ethics Framework.
Importantly, these rules are not limited to businesses developing AI technologies. Companies that deploy customer-service chatbots, use AI to screen job applications, operate internal credit-scoring tools, or rely on generative AI to produce advertising materials may also fall within the scope of the regulatory framework.
Yet, in practice, many businesses continue to deploy AI without fully assessing the legal implications.
1. Four Questions Every Business Should Be Asking
Is the Data Behind Your AI System Lawfully Sourced?
Data is often the starting point — and the starting point for legal risk.
When a business purchases an AI model from a third-party provider or collects data from publicly available sources to fine-tune an AI system, several questions arise: Was the data lawfully collected? Does it contain personal data? Does its use infringe third-party intellectual property rights? Are there contractual restrictions on how the data may be used?
Article 7 of the Law on Artificial Intelligence prohibits the collection, processing and use of data for the development, training, testing or operation of AI systems where such activities violate applicable laws on data, personal data protection, intellectual property or cybersecurity.
For businesses, this means that data governance cannot be treated as a purely technical issue. Using customer data to train an AI chatbot without an appropriate legal basis, or incorporating third-party data without reviewing the relevant terms of use, may expose the business to regulatory and legal liability.
The key takeaway is straightforward: before asking what an AI system can do, businesses should first establish whether they are legally entitled to use the data that powers it.
What Risk Category Does Your AI System Fall Into?
AI classification is more than a compliance formality. It determines the regulatory obligations that apply throughout the system’s lifecycle.
The Law on Artificial Intelligence classifies AI systems into three categories: high-risk, medium-risk and low-risk.
High-risk systems are subject to more extensive obligations, including conformity assessment, technical documentation, human oversight and periodic inspection by competent authorities. Medium-risk systems are subject to transparency and accountability requirements, while low-risk systems generally face fewer regulatory requirements.
The classification therefore needs to be approached carefully.
Consider, for example, an AI-powered credit-scoring system. If a system that should be classified as high-risk is incorrectly declared to be medium-risk, the resulting compliance gap may extend far beyond a simple filing error.
Under Article 10 of the Law on Artificial Intelligence, competent authorities may require the system to be reclassified, suspend its operation and take measures in response to violations.
For businesses, the practical question is not simply “What does our AI system do?” but “What regulatory consequences follow from what our AI system does?”
Is AI-Generated Content Properly Disclosed?
Another requirement that businesses may easily overlook concerns the identification of AI-generated content.
Under Article 11 of the Law on Artificial Intelligence and Articles 17 and 18 of Decree No. 142/2026/ND-CP, providers must apply technical markers in machine-readable formats to AI-generated audio, images and video.
Deployers also have disclosure and labelling obligations when making AI-generated or AI-modified content available to the public, where the content could otherwise create a misleading impression.
This is particularly relevant to advertising and communications teams.
For example, where a business uses AI to generate an advertisement depicting a real person, or modifies an image to recreate an event that did not actually occur, the business may be required to provide appropriate disclosure.
Failure to comply may result in administrative sanctions and, depending on the circumstances and consequences involved, may potentially give rise to criminal liability.
The message for businesses is clear: AI disclosure should be built into content-production workflows rather than treated as an afterthought.
If AI Causes Harm, Who Pays?
This is perhaps the most commercially significant question.
Article 29 of the Law on Artificial Intelligence establishes a liability framework for high-risk AI systems. Where such a system has been properly managed, operated and used in accordance with applicable requirements but nevertheless causes damage, the deployer bears responsibility for compensating the injured party. The deployer may subsequently seek reimbursement from the provider or developer where an applicable contractual arrangement provides for such recourse.
This creates an important distinction between who develops an AI system and who bears liability when that system is deployed.
A business does not necessarily escape liability simply because it purchased the AI system from a third-party provider. Depending on the circumstances, it may have to compensate the affected party first and pursue recovery against the provider or developer afterwards.
This makes contractual allocation of AI-related liability particularly important. AI procurement agreements should address, among other matters, responsibility for system failures, indemnification, data-related liabilities, incident response and recovery mechanisms.
2. Compliance Obligations That Can Become Expensive
Risk Classification Notifications: More Than a Procedural Step
Under Article 14 of Decree No. 142/2026/ND-CP, providers of medium-risk and high-risk AI systems must notify the Ministry of Science and Technology of their risk-classification results through the electronic One-Stop Portal for Artificial Intelligence before putting the system into operation.
The notification mechanism operates on a self-declaration and self-responsibility basis. In other words, businesses are not necessarily subject to prior regulatory approval before deployment, but their declarations may subsequently be reviewed by the competent authorities.
This makes the accuracy of the information submitted particularly important. An inaccurate or untruthful declaration may expose the relevant organization or individual to legal consequences.
Conformity Assessment Is an Ongoing Obligation
Conformity assessment should not be viewed as a one-time compliance exercise.
Article 13 of Decree No. 142/2026/ND-CP requires reassessment where there are material changes to an AI system’s functions, architecture, data sources or operating environment.
From a governance perspective, businesses should therefore establish internal procedures for identifying changes that may trigger a reassessment.
A seemingly minor technical modification may have regulatory significance if it changes how the system operates, what data it relies on or the environment in which it is deployed.
Incident Reporting: When Does the Clock Start?
Under Article 19 of Decree No. 142/2026/ND-CP, serious incidents must be reported within 72 hours in emergency cases or five working days in other cases.
The critical issue, however, is determining when the reporting period begins.
The relevant point is not necessarily the completion of a full technical investigation. The period starts when the organization or individual has sufficient preliminary information to establish that an incident has occurred and that it is highly likely to have originated from an AI system error.
Accordingly, an ongoing investigation does not necessarily justify delaying notification.
Businesses should have internal incident-response procedures that clearly identify:
-
who is responsible for escalating a potential AI incident;
-
when an incident is considered sufficiently substantiated for reporting purposes;
-
who is responsible for making the regulatory notification; and
-
how technical, legal and compliance teams coordinate during the reporting process.
Controlled Testing: A Regulatory Pathway for AI Innovation
The new framework also introduces a controlled testing mechanism under Article 21 of the Law on Artificial Intelligence and Chapter IV of Decree No. 142/2026/ND-CP.
The mechanism allows businesses to test AI systems within a controlled environment and subject to defined parameters, including scope, duration and operational limits.
Within the permitted testing framework, businesses may benefit from certain regulatory flexibilities, including potential exemptions, reductions or adjustments to specific compliance obligations. Test results may also be recognized for conformity assessment purposes, while eligible businesses may receive financial support through AI Development Support Vouchers.
However, controlled testing should not be mistaken for a regulatory exemption.
Businesses remain responsible for complying with the applicable testing conditions, operational limits and reporting requirements. Periodic reports are required every six months for Level 1 and Level 2 testing and every three months for Level 3 testing.
Where the prescribed limits are exceeded, the relevant incident must be reported within 72 hours.
For businesses developing or deploying innovative AI solutions, controlled testing may therefore provide a structured route to experimentation — but only where the relevant regulatory boundaries are clearly understood and managed.
3. What Should Businesses Do Now?
AI compliance should not be left until an incident occurs or a regulatory inspection is underway. Businesses should consider integrating AI legal review into their existing product development and governance processes.
First, map your AI use cases. Identify where AI is being developed, purchased, embedded or used across the organization. Many businesses may discover that AI is already being used in departments that have never been formally included in their technology-risk assessments.
Second, identify your regulatory role. A business may act as an AI provider in one context and as a deployer in another. The applicable obligations may differ depending on that role.
Third, review your AI contracts. Agreements with AI vendors should clearly address data rights, intellectual property, ownership and use of AI-generated outputs, system performance, liability, indemnification and incident-response obligations.
Finally, consider insurance and other risk-transfer mechanisms. For high-risk AI systems, civil liability insurance may provide an additional layer of protection against potentially significant compensation claims and should be considered as part of the business’s broader AI risk-management strategy.