ContentsTap to jump to a section+
- The list took effect on August 15, 2026 and covers 46 system groups across six fields.
- Not every chatbot or AI feature is automatically high risk; purpose, data and consequences matter.
- Start by recording each system, its owner, its data and the decisions it can influence.
The decision is in force, but businesses should not jump to conclusions
Decision 33/2026/QD-TTg was issued on June 30 and took effect on August 15, 2026. Vietnam’s Official Gazette says the list contains 46 groups of AI systems across six fields. Any organisation building or buying AI in Vietnam should now include this decision in its governance work.
This does not mean every use of AI is automatically high risk. A chatbot that answers opening-hour questions is different from a system that scores candidates, analyses biometric data or shapes a decision affecting a person’s rights. Classification should follow what the system actually does, not the product name.
- Issued on June 30, 2026.
- Effective from August 15, 2026.
- Published scope: 46 system groups across six fields.
The first question is not which model a business uses, but whose rights and decisions the system can affect.
Risk follows consequences, not an AI label
The official list must be matched against each use case. In education, for example, it covers certain large-scale learning systems that rely on uncontrolled content sources. It also calls attention to systems using biometrics to monitor attention, emotion or behaviour when that use may intrude on privacy or place psychological pressure on learners.
A practical review traces consequences. Does AI prepare a draft for a person to edit, or is its output used directly to reject someone? Does the affected person know AI is involved? Can a human review the outcome? The same model can create a very different risk depending on those answers.
Build an inventory with a named owner
Start with a list of systems that use AI, including features embedded in purchased software. Record the business owner, supplier, input data, output, affected users and the response when the result is wrong.
Include unofficial experiments. Staff may put customer files, contracts or internal documents into AI services without the technology team knowing. The inventory should capture approved and trial tools, then decide which ones to stop, restrict or bring into a review process.
- Who owns the outcome?
- What data enters the system?
- Does AI advise or act?
- Can an affected person request human review?
Put four control layers in place before scaling
The first layer is data: approved sources, access and retention. The second is human oversight: the cases that require approval. The third is technical control: logs, limited permissions, bias testing and a kill switch. The fourth is operations: who receives alerts, how quickly they respond and how affected people are informed.
Supplier documentation should not be the only evidence. Test the system on representative data, record failure cases and check whether operators understand its limits. If nobody can explain why an output is accepted, deployment is moving faster than governance.
A 30-day review plan
Use week one for inventory, week two to compare systems with the official list, week three to review data, permissions, logs and approvals, and week four to assign fixes and deadlines.
If classification remains uncertain, keep the scope narrow and obtain appropriate legal advice. This article helps organise technical and governance work; it is not legal advice for a particular case.
Small businesses can keep the process lightweight
A small company can begin with a spreadsheet, one accountable owner and a monthly review. The objective is visibility, not bureaucracy.
For every new product, ask where data goes, who can inspect logs, how the feature can be disabled and how data can be exported at the end of the contract. Those questions support compliance and reduce supplier lock-in.
FAQ
Frequently asked questions
Is every AI chatbot a high-risk system?
No. Review purpose, data, autonomy and the consequences for affected people, then compare the specific use case with the official text.
Who should own the review?
Name a business owner and involve technology, security, data protection and legal specialists. One team should not make the entire decision alone.
How often should the AI inventory be updated?
Update it when a tool, data source or automated permission changes. A monthly review is a practical starting point in a fast-moving environment.
References
Sources used in this guide
We prioritise official guidance and primary technical sources. Visit each source for full context and the latest updates.

