How Vietnam and Thailand Regulate AI in 2026: Southeast Asia Writes Its Own Rulebook

How Vietnam and Thailand Regulate AI in 2026
Takeaways
  • Vietnam’s AI Law 134/2025 is Southeast Asia’s first binding, enforced AI statute, tested on 13 August 2026 when ministries were barred from putting state secrets into public chatbots.
  • Thailand’s Draft AI Act closed consultation on 14 August 2026 with joint-and-several liability that reaches offshore providers serving Thai users, even those with no office in the country.
  • Europe’s high-risk deadline for standalone Annex III systems has slipped to 2 December 2027, leaving European firms tracking three separate rulebooks while Hanoi already enforces a binding AI statute Brussels just postponed parts of.

On August 13, 2026, Vietnam’s Ministry of Science and Technology told every ministry, court, and provincial government to stop feeding classified documents into public AI chatbots. The instruction was aimed at civil servants using tools like OpenAI’s ChatGPT to expedite legal research. It also marked Southeast Asia’s first real enforcement action under a binding national AI law.

That law, Vietnam’s AI Law No. 134/2025, took effect on March 1, 2026, five months before Thailand closed public consultation on its own Draft AI Act, and while ASEAN works to turn a voluntary ethics guide into a shared regional baseline.

China, Japan, Taiwan and South Korea have built their AI governance around sector rules, national-security carve-outs, and chip controls. Three separate Southeast Asian efforts are converging on structured, risk-based, statute-first regulation instead, each written on its own terms, and each with direct consequences for European companies doing business in the region.

Vietnam’s AI Law Has Been in Force Since March 2026, and August Brought Its First Test

Vietnam’s National Assembly passed AI Law No. 134/2025/QH15 on December 10, 2025. It took effect on March 1, 2026, and it sorts every AI system into one of three risk tiers. 

  • High-risk systems are those on the Prime Minister’s list in Decision 33/2026/QĐ-TTg, issued 30 June 2026 and in force since 15 August 2026: 46 systems across transport, ethnicity and religion, education, healthcare, banking, and judicial proceedings. They face periodic audits, and listed systems that require it must complete pre-market conformity certification.
  • Medium-risk systems answer to reports, sample audits, or assessments by independent organizations. 
  • Low-risk systems are checked only when an incident or complaint triggers a review. 

According to reports, the classification is based on four factors:

  1. Impact on human rights and safety.
  2. Sector involved.
  3. Number of users affected.
  4. Scale of potential harm.

The law also bans “obstructing, disabling, or falsifying” human supervision of an AI system, a direct human-in-the-loop requirement. It applies to domestic and foreign entities alike, covering anyone who researches, builds, provides, deploys, or uses AI in Vietnam. Systems already on that list get a transition window: 1 March 2027 for most listed systems, and 1 September 2027 for healthcare, education, and finance systems that were already in use before 15 August 2026.

The Ministry of Science and Technology handles day-to-day enforcement. The prime minister has already issued the high-risk list; systems on it that require certification must obtain it before they reach the market, subject to the transition dates below.

August 2026 Brought Vietnam’s AI Law Its First Real Test

The August directive is where that framework met daily government work. MoST barred ministries, judicial bodies, the National Assembly, and provincial governments from uploading state-secret documents to public AI platforms, a response to what officials described as widespread “shadow AI” use, with staff pasting internal files into consumer chatbots. Two vetted domestic systems, including CMC Technology’s C-AI Legal platform, were approved on July 7, 2026, as the only tools cleared for state legal document review. Any output still needs sign-off from “a responsible official,” who must check, assess, and confirm each result before it carries legal force, under a six-step review workflow tied to Vietnam’s Cybersecurity Law and National AI Ethics Framework.

Legal commentators have flagged a separate concern that the law’s prohibitions on AI-enabled “toxic content” and deepfakes are written broadly enough that, as one published analysis put it, they leave local authorities considerable room to interpret and apply the rules as they see fit. For companies, the practical upshot is that Vietnam now has a functioning enforcement chain, not just a statute on paper.

Thailand’s Draft AI Act Closed Consultation With Four Risk Tiers Still on the Table

Thailand’s Electronic Transactions Development Agency (ETDA) released its Draft Artificial Intelligence Act on July 9, 2026, and closed public consultation on August 14, 2026, one day after Vietnam’s directive. The draft sorts AI into four categories: prohibited AI, high-risk AI, systems that require a license, and systems that carry transparency obligations, a group that includes deepfakes, chatbots, and generative AI, according to Baker McKenzie’s review of the seven implications businesses should watch. The structure closely tracks the EU AI Act’s risk pyramid.

Thailand’s draft reaches further than Vietnam’s law on paper. It covers “developers, providers, deployers, and platform operators, including offshore entities,” meaning a company with no Thai office could still fall under the rules if it serves users there. Liability is “strict and joint,” and regulators would gain the power to suspend services, order product recalls, and block AI systems inside Thailand. Vendors selling to government agencies or critical infrastructure operators may also face mandatory data localization and stricter contract terms.

Enforcement architecture is still taking shape. The draft creates an AI Governance Center within ETDA to conduct research, provide compliance advice, and oversee a regulatory sandbox, while sector-specific regulators would designate which systems are considered prohibited or high-risk. Specific fines have not been published; the draft only notes that the use of prohibited AI may be criminalized. ETDA will now review consultation comments, consult with other agencies, and send a revised draft to the Cabinet, the step that will determine whether Thailand’s rulebook keeps its current teeth or gets filed down first.

ASEAN’s Roadmap Turns Voluntary Principles Into a 2030 Deadline

Above the national laws sits a regional layer that is still mostly guidance rather than statute. The ASEAN Guide on AI Governance and Ethics, published in 2024, offers organizations across the bloc a practical framework for commercial AI, deliberately excluding military and dual-use applications, and aims to keep national frameworks interoperable rather than identical. The ASEAN Responsible AI Roadmap 2025-2030 builds on it with concrete, staged steps for policymakers, pairing a shared foundational framework with country-specific initiatives geared to each member’s capacity, aiming to get responsible AI operating “in an integrated and interoperable manner” by 2030.

Below that regional layer, individual members are moving at noticeably different speeds. Singapore’s Model AI Governance Framework, updated by the Infocomm Media Development Authority on May 20, 2026, now specifically covers agentic AI, adding guardrails, human-approval checkpoints, logging, and monitoring of “human override rates” as core safety components. It remains voluntary. 

Malaysia’s National Guidelines on AI Governance and Ethics, issued by the Ministry of Science, Technology and Innovation and built around seven principles from fairness to “pursuit of human benefit and happiness,” are explicit that they are “not legally obligatory.” Indonesia has gone furthest toward a binding rule without adopting one yet: a Draft Presidential Regulation on AI Ethics, dated January 27, 2026, proposes its own three-tier risk model and would give businesses two years to comply, per Mondaq’s summary of the draft, but it is still a draft.

Put together, the region now runs on one binding law with active enforcement (Vietnam), one near-final draft with real teeth (Thailand), and three voluntary frameworks (Singapore, Malaysia, Indonesia), all pointed at the same 2030 regional target.

Where Southeast Asia’s Rules Have Teeth, and Where North Asia Still Doesn’t Bother

Southeast Asia’s approach looks different from its northern neighbors. China has never passed a single comprehensive AI statute, relying instead on a stack of targeted rules run mainly by the Cyberspace Administration of China, covering deepfakes since 2023, generative AI services since 2023, and mandatory content labeling since September 2025, as MRKT3.0 detailed earlier this year. Japan’s AI Promotion Act, in force since June 2025, is binding legislation but carries no fines or financial penalties. It leans on a “duty to cooperate” and public disclosure of non-compliant companies, an explicit, government-stated choice to avoid rules that might slow adoption.

South Korea’s AI Basic Act, effective January 22, 2026, was the first genuinely comprehensive, binding AI statute in Asia to take effect, ahead of Vietnam’s law by about six weeks. It sorts systems into generative, high-impact, and high-performance tiers, the last defined by a training-compute threshold of 10^26 floating-point operations, and backs them with administrative fines of up to 30 million Korean won, roughly $21,000. That is a modest number next to the penalties in the EU AI Act, but it is a real fine, with a one-year grace period attached.

Measured against that field, Vietnam’s law and its August directive give Southeast Asia its first working enforcement precedent, even with penalty amounts still unpublished. Thailand’s proposed joint-and-several liability and market-blocking powers, if the Cabinet keeps them in the final text, would hand Thai regulators sharper tools than Japan currently has and comparable ones to South Korea. Southeast Asia is closing the enforcement gap with North Asia faster than its smaller regulatory budgets would suggest, largely by borrowing the EU’s risk-tier structure rather than designing a new one from scratch.

What Vietnam and Thailand Mean for European Companies Watching Brussels’ Own Deadline Slip

The timing is notable because the EU AI Act’s own high-risk deadline just moved in the opposite direction. The original compliance date of August 2, 2026, for high-risk systems was pushed back to December 2, 2027, for employment-related high-risk AI, after the EU’s Digital Omnibus entered into force on July 27, 2026. While Brussels buys itself sixteen more months under part of its own rulebook, Hanoi is already enforcing it, and Bangkok is preparing to send a near-final draft to its Cabinet.

For European companies with AI systems active in Vietnam or Thailand, the EU AI Act compliance does not cover that exposure. Vietnam’s law applies to “domestic and foreign entities engaged in AI activities in Vietnam.” Thailand’s draft reaches “developers, providers, deployers, and platform operators, including offshore entities.” That means a European AI vendor already managing conformity assessments, technical documentation, and registration under the EU AI Act, where fines run up to €15 million or 3% of global turnover, has to track two additional, separate compliance regimes rather than assume one filing covers all three.

Thailand’s proposed localization requirements for government and critical-infrastructure vendors would put pressure on European cloud and AI providers bidding for Thai public contracts, echoing the sovereign-data arguments already shaping Europe’s own AI infrastructure buildout. Vietnam’s preference for domestically approved systems in state work points to  the same direction: a smaller, earlier version of the sovereign-AI instinct now driving investment decisions in Brussels, Paris, and Berlin. With Thailand’s Cabinet review still pending and ASEAN members moving toward its 2030 roadmap at different speeds, European companies operating across Southeast Asia have a narrow window to map their exposure to two, soon three, separate legal regimes before enforcement catches up with them, as it just did in Hanoi.

Southeast Asia’s AI Rulebook at a Glance

JurisdictionStatus (August 2026)Risk FrameworkEnforcement BodyPenalties
VietnamBinding law in force since March 1, 2026; first directive issued on August 13, 20263 tiers: high/medium/low riskMinistry of Science and TechnologyNot yet published
ThailandDraft Act; consultation closed August 14, 2026; headed to Cabinet4 tiers: prohibited/high-risk/licensed/transparencyAI Governance Center (ETDA) + sector regulatorsNot yet published; prohibited use may be criminalized
ASEAN (regional)Guide (2024) + Roadmap (2025-2030), both voluntaryPrinciples-basedNone (member states implement individually)Not applicable
SingaporeModel AI Governance Framework updated May 20, 2026Voluntary, agentic-AI focusedInfocomm Media Development AuthorityNot applicable (voluntary)
MalaysiaNational Guidelines on AI Governance and Ethics (2024)7 voluntary principlesMinistry of Science, Technology, and InnovationNot applicable (voluntary)
IndonesiaDraft Presidential Regulation on AI Ethics (January 27, 2026)3 tiers: unacceptable/high/low riskProposed National AI Ethics ForumNot yet defined; still a draft
EU (for comparison)AI Act in force; Annex III high-risk duties deferred to 2 December 2027; Annex I product-embedded duties deferred to 2 August 20284 tiers: unacceptable/high/limited/minimal riskNational authorities + AI OfficeUp to €15M or 3% of global turnoverA

Author: Ayanfe Fakunle

See Also:

TSMC Spies Got 10 Years. Taiwan’s AI Basic Act Has No Penalties at All

South Korea’s AI Basic Act Explained: The AI Law With No Teeth

Does Japan’s AI Promotion Act Have Any Penalties? Its 2nm Chip Bet Does.

Share this article

Latest news

Subscribe to our newsletter