Back to Blog
May 28, 2026Updated July 10, 2026Explainer5 min read

How Vietnam’s AI Law Applies to Clinical AI

Vietnam’s AI Law replaced the DTI Law’s AI chapter on 1 March 2026. Hospital AI now raises legal questions about risk, transparency, and human control.

Meddies Research

Clinical AI research at Meddies

How Vietnam’s AI Law Applies to Clinical AI

Vietnam's Digital Technology Industry Law took effect on 1 January 2026 with a chapter on artificial intelligence. Two months later, the country's dedicated AI Law took effect and repealed that chapter. For hospital AI, those dates describe a legal handoff, not two complete AI regimes operating side by side.

The distinction matters because an electronic medical record and the AI attached to it answer to different questions. One set of rules governs how the record is created, stored and used. The AI Law governs how an AI system is classified, disclosed, assessed and controlled.

The dedicated AI Law replaced the earlier chapter

Law 71/2025/QH15 on the Digital Technology Industry was enacted on 14 June 2025 and took effect on 1 January 2026. It originally supplied Vietnam's statutory AI framework in Chapter IV.

Law 134/2025/QH15 on Artificial Intelligence was enacted on 10 December 2025 and took effect on 1 March 2026. Article 33 repealed Chapter IV and related AI provisions of the earlier law. The Digital Technology Industry Law remains important, but its original AI chapter is no longer the operative source for those duties.

Hospitals therefore need to keep the legal layers separate. Circular 13 governs electronic medical records. The dedicated AI Law governs AI systems, alongside other rules that apply to healthcare, data and cybersecurity.

Healthcare requires tighter management, not an automatic label

The AI Law classifies systems as high, medium or low risk. A high-risk system is one that may cause significant harm to life, health, lawful rights and interests, public interests or national security. A medium-risk system may mislead, influence or manipulate users because they do not recognize that they are interacting with AI or viewing AI-generated content. Systems outside those definitions are low risk.

Classification also considers the field of use, especially essential fields or uses connected directly to the public interest. Article 6 names healthcare as a field that requires tighter risk management, including patient safety, reliability under real conditions of use and protection of health data.

That does not make every healthcare AI system high risk by definition. The provider must classify the actual system before use. Medium- and high-risk systems require a classification dossier and notification to the Ministry of Science and Technology. High-risk systems also face conformity assessment and additional duties around risk management, data governance, technical records, human oversight and incident handling.

For a hospital, the intended use matters. A tool that changes the basis of a treatment decision presents a different risk from software used for a low-impact administrative task, even if both use similar model technology.

Transparency and source traceability are different

Article 11 requires a system that interacts directly with people to be designed and operated so users recognize that they are interacting with AI, unless another law provides otherwise. It also sets specific marking or notice duties for AI-generated or AI-edited content in defined circumstances.

For high-risk systems, Article 14 assigns different human-control duties to each actor. A provider must design the system so people can oversee and intervene in its operation. A deployer must preserve the ability to intervene while the system is in use. Both must give users and affected people public information describing the system's functions, operation and risk warnings.

Article 14 treats the main input data types differently. Only the provider must include them in its explanation to the competent authority, alongside the system's purpose, how it works at a functional level, and its risk-management and control measures. These are meaningful transparency and accountability duties. The law does not say that every sentence in a clinical answer must link to the exact chart entry or guideline passage behind it.

That second standard is source traceability. A label tells the clinician that AI produced the output. A source trail helps the clinician inspect what the output relied on. A clinical system may need both, but they solve different problems and should not be presented as the same legal obligation.

The 18-month period applies only to existing systems

The law's transition period is narrower than a general grace period for healthcare AI. Article 35 applies to systems already in operation before 1 March 2026. Providers and deployers of those health, education and finance systems have 18 months from the effective date to meet the law's obligations, which runs to 1 September 2027. Other pre-existing systems receive 12 months.

Systems may continue operating during that period unless the AI regulator identifies a risk of serious harm and requires suspension or termination. The provision does not give every new health AI system launched after 1 March 2026 an 18-month delay.

Where Meddies stops its claim

Meddies is being designed to make AI involvement visible and to connect clinical claims with the patient facts or evidence behind them. The current implementation preserves retrieved passages and provenance identifiers, but the live interface does not yet provide a complete trail from each claim back to its supporting passage. A citation is not verification, and an intended source trail is not the same as a deployed one.

This direction may support transparency and human review, but it is not a compliance certification. Classification and legal duties depend on the system's actual intended use, risk, technical implementation and hospital deployment.

The practical review for a hospital is therefore broader than asking whether a vendor has placed an AI label on the screen. The hospital needs to know how the system was classified, what information it uses, where a clinician can intervene, what happens when it fails and which claims can be checked against their source. The law sets the regulatory floor. Clinical evaluation still has to show whether the system deserves a place in care.

Review the intended workflow

Review the intended workflow and one synthetic medication-safety example, with the evidence boundary kept visible.

Book a demo

References

  1. Law 71/2025/QH15 on the Digital Technology IndustryGovernment of Vietnam (2025)
  2. Law 134/2025/QH15 on Artificial IntelligenceGovernment of Vietnam (2025)