Part of the AI Regulation News hub.
Vietnam's Decision 1875/QĐ-TTg issues the National Cybersecurity Architecture Framework, whose principles say AI systems are built and operated as "AI Trustworthy" with data-poisoning defence and risk monitoring for virtual assistants and GenAI
The Decision is a signed Prime Minister's instrument, effective from the day it was signed. Its AI text is one principle inside the annexed framework, and the Decision tells ministries and provinces to refer to and compare against that framework. It is a state-systems document, not a general AI statute.
Bottom line: Decision 1875/QĐ-TTg is a binding Prime Minister's decision, signed on 30 September 2026 and effective from that date. It issues the National Cybersecurity Architecture Framework, version 1.0. One of the framework's principles says AI systems are built and operated on transparent, fair, safe and responsible ("AI Trustworthy") lines, with training-data protection, data-poisoning defence and specific risk monitoring for virtual assistants and generative AI. The Decision frames the duty of ministries and provinces as referring to and comparing against the framework.
Who this affects: Vendors, integrators and IT or security leads who supply or run AI systems for Vietnamese ministries, provincial People's Committees and other state bodies, and the security heads of those bodies. Also state-owned groups and public service units that operate information systems important to national security, which the framework lists in its scope.
Issue date: Signed in Hanoi on 30 September 2026 by Deputy Prime Minister Hồ Quốc Dũng on behalf of the Prime Minister. Article 3.1 says the Decision is effective from the date of signing.
What changed: Article 1 issues the framework as an annex. In Annex I, section II (principles), principle 3 ("AI First") says AI application systems are built and operated as AI Trustworthy, without infringing privacy, without bias, with accountability, with training data kept safe and data poisoning defended against, and with a specific risk-monitoring mechanism for virtual assistant and GenAI systems to avoid leaks of sensitive data.
Analysis: On our reading, the AI text is a design principle for state cybersecurity architecture, not a standalone AI rule. The signed text attaches no penalty to it, sets no AI-specific deadline, and establishes no direct AI-specific supplier duty or procurement condition. Suppliers meet it only through the state bodies that adopt the framework.
Primary sources: Chinhphu.vn legal document page, Quyết định số 1875/QĐ-TTg (30 September 2026), with the signed PDF attached · Signed PDF, 1875_qd-ttg_30092026-signed.signed.pdf (40 pages, scanned)
- Instrument (EN)
- Decision No. 1875/QĐ-TTg issuing the National Cybersecurity Architecture Framework (Version 1.0)
- Authority
- Prime Minister of Vietnam (Thủ tướng Chính phủ), signed on the Prime Minister's behalf by Deputy Prime Minister Hồ Quốc Dũng, on the proposal of the Minister of Public Security
- Jurisdiction
- Vietnam
- Status
- Signed 30 September 2026; effective from the date of signing (Article 3.1)
- Bindingness
- Binding decision on its addressees. Ministries and provinces are told to refer to and compare against the framework; operators of information systems important to national security are told to comply with the mandatory requirements in Article 2.7(a)
- Issue date / next deadline
- 30 September 2026. The annex encourages basic connection targets within 24 months of effect; no AI-specific deadline is printed
- Location of the AI text
- Annex I (Phụ lục I), section II on principles, principle 3 "AI First", page 5 of the annex (PDF page 9)
- Primary source
- https://chinhphu.vn/?pageid=27160&docid=219687
What does the framework say about AI?
The AI wording sits in principle 3 of the annexed framework, headed "Nguyên tắc vận hành thông minh và tự động hóa trên cơ sở ưu tiên ứng dụng trí tuệ nhân tạo (AI First)". In our translation, that is the principle of intelligent operation and automation on the basis of prioritising AI. It forms part of a binding decision, effective since 30 September 2026, but the text is phrased as a principle of the framework, not as a numbered duty on a named party.
In our translation, the operative paragraph says that AI application systems are built and operated on the principles of transparency, fairness, safety and responsibility (AI Trustworthy). It lists five safeguards: no infringement of privacy, no bias, accountability, safety of training data, and defence against data poisoning. It then says a specific risk-monitoring mechanism applies to virtual assistant and generative AI systems to avoid leaks of sensitive data. The Vietnamese text is reproduced in the quotation on this page.
The phrase "có khả năng giải trình" can be rendered as accountability or as explainability; we use accountability. The framework does not define AI Trustworthy, data poisoning or the risk-monitoring mechanism. The terms "AI Trustworthy", "Data Poisoning" and "GenAI" appear in English in the Vietnamese original.
Who does the Decision bind, and how?
Article 3.2 makes ministers, heads of ministry-level agencies, chairs of provincial People's Committees and the organisations and individuals concerned responsible for implementing the Decision, which has been effective since signing. Article 2.1 puts the Ministry of Public Security in charge of guiding, supervising and assessing the framework's application nationwide.
The duty on ministries and provinces is framed softly. Article 2.7(a) opens "Tham khảo, đối chiếu với các định hướng và yêu cầu tại Khung kiến trúc an ninh mạng quốc gia", in our translation to refer to and compare against the orientations and requirements in the framework. Article 2.8 is firmer for one group. It says organisations and enterprises directly managing or operating information systems important to national security "có trách nhiệm tuân thủ các yêu cầu bắt buộc quy định tại điểm a khoản 7 Điều này", in our translation are responsible for complying with the mandatory requirements in point (a) of clause 7. The Decision does not say whether the AI principle counts among those mandatory requirements.
The annex's own scope list names ministries, provincial People's Committees, socio-political organisations using the state budget, Party, National Assembly, court and procuracy bodies, and "Các tập đoàn, tổng công ty, doanh nghiệp nhà nước và đơn vị sự nghiệp công lập vận hành các hệ thống thông tin quan trọng về an ninh quốc gia", in our translation state-owned groups, corporations and enterprises and public service units operating information systems important to national security. On that list, the framework, binding since 30 September 2026 through the Decision, is a state-sector instrument. Article 2.9 only requests ("Đề nghị") Party, National Assembly, court and procuracy bodies to study and apply it. Annex I, section I also carves out systems: in our translation, the framework does not apply to military information systems managed by the Ministry of Defence or to cipher information systems under the Government Cipher Committee. The Ministry of Defence instead refers to and applies this framework or builds a specialised cybersecurity architecture framework for the systems it manages, the same route Article 2.4 sets.
Is there a deadline for the AI principle?
No AI-specific date appears in the parts we read. The Decision has been effective since signing on 30 September 2026. The annex's roadmap runs in three phases: 2026 to 2027 (foundation), 2027 to 2028 (connection) and 2029 to 2030 ("Thông minh hóa", which we translate as intelligentisation), where one item reads "áp dụng AI sâu rộng trong phòng vệ chủ động", in our translation broad application of AI in active defence. That is a roadmap target for the national defence system, not a compliance date for AI systems.
A transitional clause says implementation "được khuyến khích phấn đấu hoàn thành các mục tiêu kết nối cơ bản trong khoảng thời gian 24 tháng" from the date the Decision has effect, in our translation is encouraged to aim to complete basic connection targets within about 24 months. The verb is encouragement, and the target is connection, not AI.
What does this mean for AI vendors and integrators?
The Decision establishes no direct AI-specific supplier duty or procurement condition, so we do not say it binds suppliers directly. Article 2.10 does list investment by enterprises providing telecommunications and IT infrastructure among the framework's funding sources, which is not an AI duty. On our reading, the practical route runs through the client. A ministry or province referring to the framework when it builds or updates its own cybersecurity architecture would read principle 3 into the AI systems it buys or runs, and the Decision has been effective since 30 September 2026.
For a state-body security lead, the text gives a checklist in principle form: privacy, bias, accountability, training-data security, data-poisoning defence, and dedicated monitoring of virtual assistants and generative AI for sensitive-data leaks. It does not say how any of these is tested, documented or audited. The annex points to Decree 331/2026/NĐ-CP and national standard TCVN 14423:2026 for level-specific technical requirements, and we did not open either.
What we did not verify
What we opened: the 40-page signed PDF published on chinhphu.vn, through page images and an OCR pass. We read the four-page Decision in full against the page images, and from Annex I the scope and principles pages (PDF pages 8 and 9) and the roadmap page (PDF page 36), also against the images. We read PDF page 6 (end of the glossary and Annex I, section I) against its image, PDF page 5 and PDF page 35 only through OCR, and searched the OCR of all 40 pages for AI terms. Quotations were checked character by character against the page images, because the OCR drops several Vietnamese diacritics in the AI paragraph.
What we did not open: the rest of Annex I (PDF pages 5 to 36) beyond the pages above and the AI keyword search, the later annex pages (PDF pages 37 to 40), the Cybersecurity Law of 10 December 2025, Decree 331/2026/NĐ-CP, TCVN 14423:2026, Decision 1425/QĐ-TTg on the national digital architecture framework, and any Ministry of Public Security guidance issued under Article 2.1. We found no English text from the government.
What we refuse to claim: we do not say the Decision is a general AI law for private companies, that it binds vendors directly or through procurement, that a penalty attaches to the AI principle, or that any AI-specific deadline exists. We do not say the AI principle is one of the mandatory requirements Article 2.8 refers to. We make no claim that this is the first provision of its kind in the region.
Translations from Vietnamese are our own. Quotations are copied from the signed PDF with diacritics kept; line breaks are joined and no words are changed or omitted.
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
Any AI system within the framework's scope, run for a Vietnamese ministry, province or other listed body and outside the excluded military and cipher systems, now sits under a framework principle, effective since 30 September 2026 through Decision 1875/QĐ-TTg, covering privacy, bias, accountability, training-data security, data-poisoning defence and leak monitoring for virtual assistants and generative AI. The Decision frames the state body's duty as referring to the framework, so the client's own architecture documents are the place to confirm how it is applied.
Source File
https://chinhphu.vn/?pageid=27160&docid=219687
Open the signed PDF attached to the chinhphu.vn page for Quyết định số 1875/QĐ-TTg and confirm four things: the number and the 30 September 2026 date on page 1, Article 2.7(a) and 2.8 and Article 3.1 on effect at page 3, the signature of Deputy Prime Minister Hồ Quốc Dũng on page 4, and principle 3 "AI First" with the AI Trustworthy paragraph at PDF page 9 (annex page 5).
Các hệ thống ứng dụng trí tuệ nhân tạo (AI) được xây dựng và vận hành theo nguyên tắc minh bạch, công bằng, an toàn và có trách nhiệm (AI Trustworthy), bảo đảm không xâm phạm quyền riêng tư, không thiên lệch, có khả năng giải trình, bảo đảm an toàn cho dữ liệu huấn luyện và phòng chống đầu độc dữ liệu (Data Poisoning) · Quyết định số 1875/QĐ-TTg, Phụ lục I, mục II, nguyên tắc 3, 30 September 2026
FAQ
Is Decision 1875/QĐ-TTg an AI law?
No. It issues the National Cybersecurity Architecture Framework for state bodies. The AI text is one principle inside the annexed framework, covering AI Trustworthy design, training-data security, data-poisoning defence and risk monitoring for virtual assistants and generative AI.
Does it apply to private AI companies?
It depends on the role. Article 2.8 names organisations and enterprises that directly manage or operate information systems important to national security, with no state-ownership qualifier, and makes them responsible for the mandatory requirements in Article 2.7(a). A company that only supplies AI to a state body is given no direct AI duty in the text we read. The Decision does not say the AI principle is one of those mandatory requirements.
When did it take effect?
Article 3.1 says the Decision is effective from the date of signing, which was 30 September 2026. No AI-specific deadline is printed in the parts we read.
Is there a penalty for AI systems that do not meet the principle?
The Decision and the annex pages we read attach no penalty to the AI principle. Article 2.6 has the Ministry of Home Affairs guide the use of cybersecurity index results in the annual assessment of heads of agencies, which is not an AI-specific sanction.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.