Vietnam identifies high-risk AI systems across six sectors
19 August 2026
On 15 August 2026, Vietnam’s Decision No. 33/2026/QD-TTg (“Decision 33”), setting out a list of high-risk artificial intelligence (“AI”) systems, came into effect. Decision 33 follows the coming into effect on 1 March 2026 of Vietnam’s first AI law, the Law on Artificial Intelligence No. 134/2025/QH15 (“AI Law”).
High-risk AI systems
The AI Law introduced a three-tier, risk-based classification framework for AI systems, with additional compliance obligations applying to systems classified as high-risk. An AI system may be classified as high-risk based on various factors, including its potential to cause significant harm to life, health, property, lawful rights and interests, national interests, public interests or national security, having regard to the nature and degree of risk associated with the system. For more on the AI Law, please read our article “Vietnam’s new Law on Artificial Intelligence: Risk-based regulatory framework in force 1 March 2026”.
Decision 33 provides greater specificity on the application of the high-risk classification framework. The Appendix to Decision 33 lists 46 high-risk AI systems across six sectors: education (three systems), ethnic and religious affairs (seven systems), healthcare (two systems), banking (two systems), judicial proceedings (one system), and transportation (31 systems). A selection of the systems set out under each sector is set out below.
- Education: AI systems that (1) provide automated content to support learners' self-study activities using uncontrolled data sources; (2) automatically conduct examinations, assess learning outcomes or rank learners; or (3) monitor and analyse learner behaviour using biometric data or other automated monitoring mechanisms.
- Ethnic and religious affairs: AI systems used to (1) automatically check, compare, or verify information relating to ethnicity or religion; (2) assess or classify applications; or (3) make final decisions on the approval or rejection of applications without review, intervention, or approval by the competent authority.
- Healthcare: AI systems integrated into surgical robots or other automated machinery that directly perform therapeutic interventions without requiring confirmation from medical personnel for each relevant parameter change.
- Banking: AI systems that automatically perform high-value electronic transactions, including creating, modifying, confirming or approving transactions, without human inspection, approval or control before execution; and AI systems used for credit scoring and automated decisions on credit granting or loan disbursement without independent approval by credit officers.
- Judicial proceedings: Large-scale biometric AI systems used in connection with the resolution of public civil cases.
- Transportation: A broad range of AI systems relating to road, rail, and aviation safety and operations, including systems used for autonomous driving, infrastructure safety, traffic management, air traffic management, autonomous flight control, collision avoidance, emergency flight decisions, airport operations, and the management, monitoring, or protection of critical transport infrastructure.
The above examples are not exhaustive. Importantly, not all AI systems used in these sectors will automatically be classified as high-risk. The relevant system must fall within the specific descriptions and conditions set out in the Appendix to Decision 33.
Compliance requirements
Decision 33 identifies the applicable conformity-assessment route under Article 13 of the AI Law for each high-risk AI system included in the Appendix. Providers and deployers of listed systems should therefore assess the applicable conformity-assessment requirements based on the specific category into which the system falls.
AI systems must also comply with the basic operating principles under the AI Law, including ensuring human supervision, control, and intervention during operation. In particular, the framework seeks to ensure that AI systems do not improperly replace or transfer the powers and responsibilities of competent persons or authorities.
Transitional arrangements
Decision 33 provides transitional periods for high-risk AI systems that were already in operation before 15 August 2026. Providers and deployers of such systems must fulfil the applicable compliance obligations by 1 September 2027 for systems in the healthcare, education, and finance sectors, and by 1 March 2027 for systems in the other sectors covered by Decision 33.
During the transitional period, existing systems may continue to operate unless a competent State agency determines that a system poses a serious risk and requires its temporary suspension or termination.
For AI systems put into operation within six months after the effective date of Decision 33, the applicable compliance obligations must be fulfilled by 1 March 2027.