|
GOVERNMENT OF VIETNAM
--------
|
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom – Happiness
---------------
|
|
No. 142/2026/ND-CP
|
Hanoi, April 30, 2026
|
DECREE
ELABORATION
ON SOME ARTICLES OF THE LAW ON ARTIFICIAL INTELLIGENCE
Pursuant to the Law on Government Organization No. 63/2025/QH15;
Pursuant to the Law on Artificial Intelligence No. 134/2025/QH15;
At the request of the Minister of Science and Technology;
The Government promulgates the Decree on elaboration on some articles of
the Law on Artificial Intelligence.
Chapter I
GENERAL REGULATIONS
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
This Decree elaborates some articles of the Law on Artificial Intelligence
(hereinafter referred to as “AI”) including:
a)
Clause 4, Article 8 on mechanisms for operation, management and use of the
Single-window portal on AI and the National database on AI systems;
b)
Article 9 on classification of risk levels of AI systems;
c)
Clause 7, Article 10 on announcement, procedures for announcement and technical
guidelines on risk classification;
d)
Clause 6, Article 11 on methods for announcement and labeling;
dd)
Clause 5, Article 12 on the reporting and responsibilities of relevant
authorities, organizations and individuals in accordance with the severity of
incidents and the impact of AI systems;
e)
Article 13 on evaluation of the conformity of high-risk AI systems;
g)
Article 14 on management of high-risk AI systems;
h)
Clause 6, Article 6 on mechanisms for coordination, share, incentive and
measures for development of national AI infrastructure for each stage in
accordance with requirements for national security;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
k)
Clause 5, Article 18 on mechanisms, criteria and methods for mastery over AI
technology for each stage in accordance with requirements for national security;
l)
Clause 6, Article 20 on mechanisms, requirements and procedures for applying
measures for development of AI ecosystem and market;
m)
Article 21 on regulatory sandbox mechanisms for AI systems;
n)
Clause 4, Article 24 on criteria, procedures for recognition, operational
mechanisms of AI linkage clusters, and incentives;
o)
Clause 7, Article 25 on mechanisms, policies, requirements and procedures for
supporting enterprises in AI;
p)
Clause 5, Article 27 on content, procedures and responsibilities for impact
evaluation, risk management and supervision of the use of AI systems in state
management and public services.
2.
This Decree regulates measures for implementation of the Law on AI regarding
transparency responsibility and responsibilities of authorities and
organizations.
3.
AI activities related to state secrets shall also comply with laws on state
secrets, cybersecurity and cipher activities.
Article 2. Regulated entities
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Providers, developers, deployers and users of AI systems; persons affected by
AI systems.
2.
Vietnamese authorities, individuals and organizations; foreign organizations
and individuals engaging in AI activities in Vietnam.
Article 3. Definitions
For
the purposes of this Decree, the terms below shall be construed as follows:
1.
Technical dossiers on high-risk AI systems are a collection of technical documents
in conformity with risk levels of systems to serve the classification,
conformity evaluation, incident supervision and handling including functions of
systems, descriptions on training data, testing procedures, risk management
measures, and relevant technical information in accordance with the laws.
2.
An identification code of an AI system is an electronic code to serve the
management of dossiers that are automatically established on the Single-window portal
on AI when a provider notify the results on risk classification.
3.
Value at risk is a total monetary value of transactions or assets that
organizations or individuals participating in the testing propose, approve, or
execute within the scope of the regulatory sandbox.
4.
An AI model is the algorithmic component of an AI system that is trained by
data to learn, represent and infer patterns from the data in order to generate
outputs such as predictions, content, recommendations or decisions.
5.
A model card is a document attached to an AI model to provide descriptions on
features, purposes of use, scope of application, limitations and potential
risks, training data, parameters and training requirements, as well as results
on performance evaluation of the system in order to ensure the transparency,
traceability and reproducibility throughout the development and use of the
model.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
7.
Conditional open data means data that may be accessed and used when
authorities, organizations or individuals satisfy requirements for
registration, purposes of use and security requirements as prescribed by laws.
8.
Commercial data for AI means data of organizations, enterprises and individuals
that is provided, shared and used on the basis of civil or commercial
agreements in accordance with laws on data, personal data protection and
intellectual property.
Article 4. Single-window portal on AI and National database
on AI systems
1.
The Ministry of Science and Technology shall manage and operate the
Single-window portal on AI for implementation of the following tasks:
a)
Receive announcements on risk classification results, conformity evaluation
results; generate identification codes for AI systems; receive updated
information on risk classification dossiers and other information on AI systems
in accordance with this Decree;
b)
Receive reports on incidents, periodic reports and information to serve the
management and supervision of AI systems in accordance with this Decree;
c)
Support the automatic classification of risk levels of AI systems;
d)
Publish information on AI systems, conformity evaluation results, list of
recognized AI linkage clusters, violation handling results, information on
shared AI infrastructure capacity, access requirements, technical regulations,
methods and procedures for use of data, supporting programs and mechanisms;
dd)
Receive technical guidelines; receive and collect opinions, publish impact
evaluation reports, and serve the supervision of the use of AI systems in state
management in accordance with this Decree;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
The Ministry of Science and Technology shall take charge of data in the
National database on AI to serve the state management, supervise and summarize
data on AI systems.
3.
The collection, update, disclosure, connection, share and use of information in
the Single-window portal on AI and the National database on AI shall comply
with laws on electronic transactions and the following requirements:
a)
Comply with the purpose of state management and the scope of information
permitted by laws;
b)
Comply with laws on cybersecurity, protection of state secrets, business
secrets and personal data;
c)
Not pose additional administrative procedures, reporting obligations or requirements
for provision of information for organizations and individuals, except for
cases prescribed in this Decree;
d)
AI systems, databases serving internal activities of authorities of the
Communist Party of Vietnam, political organizations; AI systems included in the
List of state secrets, national defense and security are not required for
announcement, registration and disclosure of data on the Single-window portal
on AI.
4.
The Ministry of Science and Technology shall issue standards, technical guidelines
on data, data models, and policies for updating, using and sharing data in the
National database on AI to ensure seamless connection and data sharing between
central and local authorities.
Chapter II
CLASSIFICATION AND EVALUATION OF THE CONFORMITY OF AI SYSTEMS
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
AI systems shall be classified in accordance with risk levels prescribed in the
Law on AI and this Decree.
2.
Providers shall classify AI systems before putting them into use.
3.
Deployers shall cooperate with providers in reviewing and re-classifying AI
systems when deploying, adjusting, integrating, changing functions, or changing
purposes of use that poses a new risk or a higher risk level of classified
systems.
4.
Providers and deployers shall evaluate the conformity of high-risk AI systems
in accordance with the Law on AI and this Decree.
5.
In cases where AI systems are integrated in products, goods or services that
are regulated entities of specialized laws, laws on standards and technical
regulations, or laws on quality of products and goods, organizations and
individuals shall comply with corresponding laws; and comply with specific risk
management requirements for AI components in accordance with the Law on AI and
this Decree.
6.
State management authorities for AI and specialized state management
authorities shall prevent overlapping during the classification, evaluation of
the conformity and inspection of AI systems. For results of sandbox, inspection,
conformity certification or conformity evaluation in accordance with
specialized laws, laws on standards and technical regulations, or laws on
quality of products and goods for proving the compliance with corresponding
requirements prescribed in laws on AI that have been evaluated as lawful and
complete, and remain valid, organizations and individuals are not required to
repeat such procedures.
7.
In cases where results prescribed in clause 4 of this Article do not cover all
specific risk management requirements for AI systems as prescribed the Law on
AI and this Decree, providers and deployers shall only provide additional
information on the content that have not been evaluated or proved.
8.
The Ministry of Science and Technology shall provide electronic supporting tool
for self-evaluation and self-classification of AI systems in accordance with
criteria prescribed in Article 8 of this Decree. Electronic supporting tool
shall only be used for supporting purposes. The use of such tools shall not be compulsory,
and not pose additional approval procedures or obligations beyond those
prescribed in this Decree.
Article 6. Classification of AI systems
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
The classification prescribed in this Article shall only be applied to AI
systems; not be applied to AI models, except for cases where such models are
used as a component of specific AI systems.
3.
Risk levels of AI systems shall be determined in accordance with the following
regulations:
a)
High-risk AI systems are those included in the List of high-risk AI systems
issued by the Prime Minister in accordance with clause 4, Article 13 of the Law
on AI;
b)
Medium-risk AI systems are those not prescribed in point a of this clause and
those prescribed in Article 9 of this Decree;
c)
Low-risk AI systems are those not prescribed in points a and b of this clause.
4.
In cases where deployers adjust, integrate, change functions or change purposes
of use of AI systems compared to the original declaration of providers that
pose a new risk or a higher risk level, they shall cooperate with providers in
reviewing and re-classifying the risk level.
Article 7. The List and procedures for issuance of
high-risk AI systems
1.
The List of high-risk AI systems issued by the Prime Minister in accordance
with clause 4, Article 13 of the Law on AI including:
a)
AI systems identified as high-risk systems;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
The review and proposal for changes to the List prescribed in clause 1 of this Article
shall comply with the following regulations:
a)
Province-level People’s Committees, within their tasks and authority, are
responsible for reviewing and evaluating the deployment of AI systems within
local areas; proposing changes to the List, and submitting to managing
ministries for consideration and summary;
b)
Ministries and ministerial authorities, within their tasks and authority, are
responsible for reviewing, evaluating, proposing changes to the List regarding
AI systems under their management, and submitting to the Ministry of Science
and Technology for summary and appraisal;
c)
Central authorities of political organizations and socio-political
organizations have the right to propose changes to the List of high-risk AI
systems that are used for evaluation, planning, rotation, and assignment of
personnel within the political system, and submit to the Prime Minister for
consideration and decision;
d)
The Ministry of Science and Technology shall take charge and cooperate with
ministries, ministerial authorities and relevant organizations in considering,
developing and proposing the Prime Minister for issuance and amendment to the
List prescribed in clause 1 of this Article in accordance with criteria and
principles in Article 8 of this Decree.
Article 8. Criteria and principles for development of the
List of high-risk AI systems
1.
An AI system is identified as a high-risk system when it satisfies one or more
of the following criteria:
a)
Impact level: The impact may cause harm to life, health, property, human
rights, national interests, public interests, or national security; the
automation level of the system; the extent of support for final
decision-making; and the capability of human oversight and intervention in the
execution of actions;
b)
Field of use: The system shall be deployed in essential fields prescribed in
clause 2, Article 6 of the Law on AI, or in fields related to public interests;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
An AI system that satisfies criteria prescribed in clause 1 of this Article may
not be included in the List of high-risk AI systems when it satisfies one or
more of the following criteria:
a)
The system only performs tasks of collection, processing, standardization,
classification, translation of data, or improvement of data quality; and does
not directly make decisions affecting legitimate rights and interests of
organizations or individuals;
b)
The system has technical mechanisms and operational procedures to ensure human
oversight whereby competent persons are able to independently review, intervene
in, reject, or adjust decisions of the system before such decisions take effect;
c)
The system only serves administration and internal operation of organizations
and enterprises; does not directly affect to rights, legal obligations, or
legitimate interests of external organizations and individuals;
d)
The system only performs analysis, prediction, evaluation, or advisory
functions for reference purposes. Providers and deployer shall not use output
results as the sole basis for making final decisions.
3.
Ministries and ministerial authorities shall refer to criteria prescribed in
clauses 1 and 2 of this Article to propose adding AI systems in the List of
high-risk AI systems.
4.
Ministers and ministerial authorities shall refer to the List of high-risk AI
systems prescribed in Article 7 of this Decree and requirements for management
in each field to propose high-risk AI systems that have to undergo conformity
certification before use.
5.
In cases where an AI system satisfies regulations prescribed in clause 2 of
this Article but there is technical or practical evidence proving that the
system contains serious risks or vulnerabilities causing harm to national
defense, security, or social order and safety, the Prime Minister shall
consider including such system in the List of high-risk AI systems and clearly
state grounds therefore in the Decision on issuance of the List.
Article 9. Classification of medium-risk AI systems
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
The system is not included in the List of high-risk AI systems issued by the Prime
Minister in accordance with clause 4, Article 13 of the Law on AI;
b)
The system may cause confusion, influence, or manipulate users because users
are unable to recognize whether the interacting entity is an AI system or the
content generated by such system in accordance with point b, clause 1, Article
9 of the Law on AI.
2.
Deployers shall comply with clause 1 of this Article for classification of AI
systems for cases prescribed in clause 2, Article 10 of the Law on AI.
3.
Providers and deployers shall not classify medium-risk AI systems in one of the
following cases:
a)
The system only supports technical modification to improve the presentation of
content; and does not generate new content and alter the identity of the
subject;
b)
The system supports office-related tasks where users can clearly recognize that
it is an AI tool, and the system does not possess simulation or emulation
functions causing confusion regarding identity or authenticity of events;
c)
The system does not directly interact and provide services or content to the
public including not publishing such services and content to the public via a
third party or intermediary platform;
d)
The system is used for art, cinematic, video games activities, or other
creative activities; or used for demonstration of fictional content;
dd)
The system only processes and analyzes data, or optimizes the operation of the
technical system; does not directly interact with users, generate content for
the public, and directly interact with physical environment as a primary
control function of the system.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
The Ministry of Science and Technology shall install and maintain automatic
supporting tool for risk classification on the Single-window portal on AI to
help providers and deployers conduct self-evaluation and self-classification of
AI systems.
2.
Providers are not required to use the automatic supporting tool for risk
classification prescribed in clause 1 of this Article. State competent authorities
shall not request providers to submit classification results extracted from
this tool as a compulsory document for any administrative procedures.
3.
Classification results generated from the automatic supporting tool for risk
classification shall be recognized as valid electronic documents of the dossier
on risk classification, and shall serve as one of the grounds for state
competent authorities to consider and evaluate the compliance with laws on risk
classification of the providers.
4.
If the risk level cannot be identified after using the automatic supporting
tool for risk classification, providers may request guidelines for
classification from the Ministry of Science and Technology according to
technical dossiers as prescribed in clause 4, Article 10 of the Law on AI.
Article 11. Review and update of risk levels
1.
Providers shall review and re-classify the risk level of an AI system when one
of the following legal events occurs:
a)
The system has significant change to functions, purposes of use or deployment
context that affects the criteria for initial classification of the system;
b)
The system experiences a serious incident demonstrating that the actual risk
level is higher than the classified one;
c)
The Prime Minister issues the Decision on amendments to the List of high-risk
AI systems resulting in the change of risk level of the system;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
Deployers shall cooperate with providers in re-classifying AI systems in cases
where deployers modify, integrate, or change functions that pose a new risk or
a risk level higher than initial classification results of providers.
3.
The announcement of results after reviewing and re-classifying risk levels is
as follows:
a)
In cases where the result of re-classification of the risk level of an AI
system is higher than the classified one, deployers shall notify the
re-classification result to state competent authorities within 15 working days
from the completion of the review, and immediately apply risk management
measures in conformity with new risk level;
b)
In cases where the result of re-classification of the risk level of an AI
system is lower than the classified one, providers and deployers may notify the
re-classification result to state competent authorities in order to apply risk
management measures in conformity with new risk level;
4.
Providers and deployers are not required to review and notify re-classification
results when upgrading, optimizing performance, fixing regular technical
errors, or performing periodic data updates that does not alter the risk nature
of systems.
5.
In cases where AI systems must be re-classified as high-risk in accordance with
point a, clause 1 of this Article, providers and deployers shall make
transition within 12 months from the effective date of the Decision on
amendments to the List of high-level AI systems of the Prime Minister for
completion of dossiers and procedures for conformity evaluation in accordance with
the Law on AI. During the transition period, systems may continue operating but
providers and deployers shall establish and maintain a mechanism for human
oversight. Persons in charge of oversight shall be provided with information,
and granted authority for individual evaluation, intervention or invalidation
of results of systems. Providers and deployers shall fully archive operation
logs and intervention decisions for inspection.
Article 12. Dossiers on risk classification for AI systems
1.
Providers shall establish dossiers on risk classification for high-risk AI
systems and medium-risk AI systems before putting them into use in accordance
with clause 1, Article 10 of the Law on AI.
2.
For high-risk AI systems and medium-risk AI systems, providers shall establish
dossiers on risk classification including the following documents:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
Description of the system and its context of use: purposes of use; main
functions; system architecture at functional and operational levels; scope of
deployment; users and affect persons;
c)
Information on data: general description of main types of input data for
operation of the system;
d)
Risk management content: Outline on risk management measures, safety and
transparency of the system.
3.
In cases where providers develop AI systems according to platforms, models or
AI systems of third parties, providers shall only provide technical information
and data information within their rights to access and control.
4.
The establishment, provision and management of dossiers on risk classification
do not require providers to disclose source codes, model parameters, detailed
algorithm, raw training data, or information included in the List of state
secrets, business secrets and technology secrets in accordance point e, clause
1, Article 14 of the Law on AI, unless otherwise provided by laws.
5.
Providers have the right to use description of modeling techniques or
corresponding technical documents established in accordance with international
standards to comply with components of dossiers prescribed in clauses 2 and 3
of this Article if such documents comply with requirements in this Decree.
6.
Providers and deployers shall archive classification dossiers throughout the
operation period of systems.
7.
In cases where AI systems use personal data, providers may use dossiers on
evaluation of impact of personal data processing in accordance with laws on
personal data protection to replace or integrate as a component of dossiers on
risk classification in order to reduce administrative procedures compliance
costs.
Article 13. Evaluation of the conformity of high-risk AI
systems
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
During
use, providers shall re-evaluate the conformity when there is any significant
change that affects results of initial conformity evaluation including one of
the following cases:
a)
Changing main functions, purposes of use, or the scope of application of
systems that poses a new risk or a risk level higher than the classified one;
b)
Changing system architecture, AI models or main technical configurations that
affects the accuracy, reliability, safety, or controllability of systems;
c)
Changing data sources, main types of input data or methods for processing of
data that significantly affects performance or risk levels of systems;
d)
Integrating AI systems into other systems, or new operational environments that
may pose a new risk or change evaluated operational conditions;
dd)
Other changes that significantly affect the compliance with regulations
prescribed in Article 14 of the Law on AI.
Activities
of performing periodic data updates, fixing regular technical errors, optimizing
performance, or upgrading versions of systems in accordance with regulations
prescribed in Article 14 of the Law AI are not considered significant changes
as prescribed in this clause.
2.
Providers shall evaluate the conformity of systems in accordance with
regulations prescribed in Article 14 of the Law on AI by the following methods:
a)
For high-risk AI systems included in the List of AI systems required to undergo
conformity certification before use, providers shall evaluate the conformity
via conformity evaluation bodies prescribed in clause 4 of this Article;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
In cases where high-risk AI systems are regulated entities of specialized laws
on standards and technical regulations, or conformity evaluation, providers
have the right to use results of conformity evaluation in accordance with
specialized laws to prove the conformity with requirements as prescribed in
Article 14 of the Law on AI. State competent authorities shall not request
providers to re-evaluate the content that is certified as satisfied in order
not to pose overlapping administrative procedures.
4.
Conformity evaluation bodies performing evaluation on high-risk AI systems
shall simultaneously comply with all of following requirements:
a)
Be established and have registered conformity evaluation operation in
accordance with laws on standards and technical regulations;
b)
Ensure the independence and objectivity during conformity evaluation activities;
c)
Comply with operational requirements as prescribed by laws on standards and
technical regulations in conformity with the evaluation of AI systems;
d)
Have experts, personnel and technical equipment satisfying professional
requirements for AI, cybersecurity, and data administration in accordance with
standards, technical regulations or guidelines issued by the Ministry of
Science and Technology;
dd)
Be put under periodic supervision of state competent authorities as prescribed
by laws.
5.
State competent authorities shall recognize conformity evaluation results
conducted by foreign conformity evaluation bodies in accordance with laws on
standards and technical regulations, and international treaties to which the
Socialist Republic of Vietnam is a member.
Providers
may use recognized conformity evaluation results to prove the conformity for
evaluated corresponding content. For content that has not been evaluated or
recognized, providers shall continue performing conformity evaluation as prescribed
in this Article.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Name of the AI system, system version and identification code of the AI system
(if any);
b)
Name, address and contact information of the provider;
c)
Applied methods for conformity evaluation;
d)
Name of conformity evaluation body in cases where the provider evaluate the
conformity via the conformity evaluation body;
dd)
Conformity conclusion on the AI system;
e)
Time of completion of conformity evaluation, or time of recognition of
conformity evaluation result;
g)
Latest information update.
Article 14. Announcement of results of classification of
risk levels of AI systems
1.
Providers of medium-risk and high-risk AI systems shall notify results of
classification of risk levels to the Ministry of Science and Technology via the
Single-window portal on AI before putting them into use. Providers shall
declare and be accountable to the laws for announced information.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Providers shall make announcement via the Single-window portal on AI by one of
the following electronic methods:
a)
Direct declaration using the online Form on the Single-window portal on AI;
b)
Submission of information via the application programming interface or other
appropriate electronic methods in accordance with the laws.
4.
The Ministry of Science and Technology shall automatically receive information,
issue identification code for AI systems, and send electronic confirmation to
providers via the Single-window portal on AI after providers complete the
announcement. During the receipt of announcement, state competent authorities
shall not request providers to submit any additional document or information
not prescribed in clause 2 of this Article. State competent authorities shall
conduct inspection and post-inspection in accordance with the laws.
Article 15. Management of high-risk AI systems
1.
Providers of high-risk AI systems shall establish and maintain risk management
systems for AI systems that they provide in conformity with purposes of use,
deployment scope and risk level of systems.
2.
Risk management systems prescribed in clause 1 of this Article shall comply with
the following regulations:
a)
Identify and evaluate risks that may arise to human rights, safety, security or
public interests during the design, development and provision of the system;
b)
Ensure the quality, conformity and representativeness of training data, testing
data and evaluation data within necessary scope to minimize risks arising from
the data;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
d)
Apply technical measures or management measures to prevent, reduce or control
identified risks;
dd)
Review and update risk management measures when the system has significant
change to model, data, operational methods or purposes of use.
3.
Providers shall provide deployers with necessary information on purposes of use
of systems, safe operating requirements, identified risks, and corresponding
risk management measures to ensure that systems are deployed and used for their
intended purposes.
4.
Deployers of high-risk AI systems shall manage risks during the deployment and
operation of systems in conformity with purposes of use, deployment scope, risk
level of systems, and technical guidelines of providers.
5.
During the deployment and operation, deployers shall implement the following risk
management measures:
a)
Operate systems in accordance with purposes of use, usage requirements, and
usage limits identified as providers;
b)
Supervise the operation of systems in order to detect errors, risks or
incidents that may arise;
c)
Establish and maintain human oversight and intervention mechanism during the
use of systems in accordance with the laws;
d)
Apply measures to limit or control risks within the scope of control when
detecting that the systems are operating against their purposes of use or that
new risks have arisen;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
6.
In cases where AI systems pose a risk of causing serious harm to human life,
health, human rights, property, cybersecurity, social order and safety, or
public interests, deployers shall promptly apply risk mitigation measures
within the scope of control, and notify providers and state competent
authorities in accordance with the laws.
Chapter III
TRANSPARENCY, EXPLANATION AND HANDLING OF INCIDENTS OF AI SYSTEMS
Article 16. Principles of transparency and explanation
1.
Providers and deployers of AI systems shall perform responsibilities for
transparency, announcement, technical marking and labeling for AI systems and
content generated by systems in accordance with Article 11 of the Law on AI.
The performance of the responsibility for transparency shall comply with
purposes of use, deployment context and risk levels of systems.
2.
Providers and deployers shall perform the following obligations:
a)
Notify, mark and label AI systems and content generated by systems in
accordance with the laws;
b)
Provide information on purposes of use, scope of application, requirements for
use and limitations of AI systems;
c)
Archive information and documents serving the inspection and supervision in
accordance with the laws.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
4.
When providing explanation and information in accordance with the laws,
providers and deployers are not compulsory to disclose source codes, detailed
algorithm, training data, parameter set or information that is considered
business secrets, technology secrets, unless otherwise provided by laws.
5.
The provision of information during the transparency and explanation shall
comply with laws on personal data protection and laws on data.
6.
In cases where AI systems integrate with AI models of other organizations and
individuals, providers shall agree with organizations and individuals providing
models to ensure the cooperation and provision of necessary technical
information for transparency and explanation in accordance with the laws.
Article 17. Technical marking for content generated by AI
systems
1.
Providers of AI systems shall apply technical measures for outputs that are
sounds, images or videos marked in machine-readable format in accordance with
clause 2, Article 11 of the Law on AI. Providers are not required to apply
technical markings in machine-readable format if the outputs are documents,
unless otherwise provided by laws.
2.
The application of technical markings prescribed in clause 1 of this Article
shall ensure machine-readable detectability and may be implemented by one of
the following measures:
a)
Integrate identifying marks into the file structure or data;
b)
Integrate identifying marks into big data of files;
c)
Use digital signatures, electronic signatures or corresponding authentication
methods;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Identifying marks in machine-readable format shall contain information
confirming that the content was generated or modified by AI systems. Providers
shall integrate information on providers, AI systems, or time of generating or
modifying the content (if available) to serve the purposes of source
authentication and content traceability.
4.
Providers shall ensure that technical marking shall always operate throughout
the preparation, export and provision of content within the scope of functions
controlled by systems.
5.
In cases where AI systems are provided in open sources or free of charge,
providers shall be deemed to have fulfilled obligations prescribed in clause 1
of this Article when:
a)
They integrate a built-in technical marking function; or
b)
They publish tools, standard configurations, application programming interface
or technical documents for deployers to configure and operate the marking
function.
Deployers
shall apply technical measures for marking output content when using such
systems for providing content to the public.
6.
The Ministry of Science and Technology shall notify and update the List of
standards, technical regulations or reference technical guidelines for
technical marking as prescribed in this Article. The announcement
prescribed in this clause shall not pose additional administrative procedures,
business investment requirements or obligations prescribed in this Decree.
Article 18. Announcement and labeling for content generated
by AI systems
1.
Deployers shall make announcement when publishing content generated by AI or
making changes that may cause confusion about the authenticity of events,
characters or origins of content in accordance with clause 3, Article 11 of the
Law on AI.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Simulation or emulation of appearances and voices of real persons;
b)
Re-creation of real events to differentiate with real content, unless otherwise
provided by laws.
3.
The announcement and labeling shall comply with the following requirements:
a)
Be clear, easy to understand and recognize for recipients;
b)
Be performed before or at the moment that recipients access the content;
c)
Not be designed in a manner that conceals or diminishes recipients’ ability to
recognize the nature of the content;
d)
Be in accordance with the format of the content and the method for providing
the content;
dd)
Not cause significant interference with the display, presentation or use of the
content.
4.
Deployers are not required to perform labeling in the following cases:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
Texts are processed using tools for spell-checking, grammar correction,
summarization, paraphrasing or translation that does not distort the essential
content of the original text;
c)
The content shall be used for internal activities of authorities, organizations,
enterprises and shall not be published;
d)
The content shall be generated during the research, development or sandbox, and
shall not be published.
5.
Deployers have the right to select the method for presenting announcement and
labeling in accordance with the content and the provision method including:
a)
Be displayed along with the content;
b)
Be displayed in the title, description or note attached to the content
c)
Be displayed on the interface of the platform providing the content;
d)
Be notified via sound or another appropriate method.
6.
For cinema works, art programs or creative content, the announcement and
labeling shall be implemented by deployers in charge of publication, and be
displayed in the opening section, ending section, credits, description, or
attached documents of the works in accordance with the nature of each type of
content. Such announcement and labeling shall ensure that recipients can
clearly recognize that the content was generated or modified by AI systems and
must not cause confusion regarding the origin of the content.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
7.
The Ministry of Science and Technology shall publish and update reference
technical guidelines regarding the methods for announcement and labeling in
accordance with this Article. The announcement prescribed in this clause shall
not pose additional administrative procedures, business investment requirements
or obligations prescribed in this Decree.
Article 19. Reporting and handling of serious incidents
1.
A serious incident of an AI system as prescribed in clause 8, Article 3 of the
Law on AI is an event occurred during the operation of that AI system that
causes one of the following consequences:
a)
Loss of life or serious harm to human health;
b)
Significant damage to assets or serious disruption to operations of
organizations;
c)
Infringement upon human rights, rights and legitimate interests of authorities,
organizations and individuals;
d)
Serious disruption to public services or essential services as prescribed by
laws, or negative impacts on national security, social order and safety.
2.
When AI systems experience serious incidents, entities shall:
a)
Deployers and users shall promptly record incidents, implement necessary
measures to mitigate consequences and notify providers to cooperate in
implementing remedial measures;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c)
Providers and deployers shall cooperate in providing information and
implementing necessary measures for handing of incidents in accordance with the
laws.
3.
Providers or deployers shall submit preliminary reports on serious incidents to
state competent authorities using Form A101a (in case of organizations) or Form
A101b (in case of individuals) in the Appendix attached to this Decree via the
Single-window portal on AI within the following deadlines:
a)
For serious incidents of an emergency nature as prescribed in points a and d,
clause 1 of this Article, and in cases where the situations prescribed in point
c, clause 1 of this Article cannot be controlled, a preliminary report shall be
submitted within 72 hours from the confirmation of such incidents;
b)
For other serious incidents, a preliminary report shall be submitted within 05
working days from the confirmation of such incidents;
c)
The time of incident confirmation prescribed in this clause shall be considered
from the time at which organizations or individuals have sufficient initial
information to determine that incidents have occurred and is likely to
originate from a fault of AI systems without having to wait for completing a
comprehensive investigation into the technical cause. The submission of
preliminary reports within prescribed time limit shall not be deemed an
admission of technical fault or legal liability by reporting organizations or
individuals.
In
cases where deployers cannot contact with providers, deployers shall submit
reports as prescribed in this clause.
4.
Providers and deployers shall maintain and archive system logs, data and
information related to incidents for verification, evaluation and remediation
of incidents; submit official reports on remediation results to state competent
authorities within 15 days from the submission of preliminary reports.
5.
In cases where it is required to report serious incidents in accordance with
cybersecurity, personal data protection or other specialized laws, the
reporting shall comply with corresponding laws.
State
competent authorities shall cooperate and share information; shall not request
for re-submission of information and documents available in information
systems, or databases connected and shared in accordance with the laws, AI
systems, and databases prescribed in point d, clause 3, Article 4 of this
Decree.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
7.
In cases where incidents may affect the national security, social order and
safety, or show signs of criminal violations, the Ministry of Science and
Technology shall cooperate with the Ministry of Public Security and relevant
authorities in verifying and handling in accordance with the laws.
8.
The reporting and receipt of reports on serious incidents shall be performed
via the Single-window portal on AI.
Article 20. Evaluation of impacts of the use AI systems of
state authorities
1.
State authorities shall evaluate impacts of AI systems in one of the following
cases:
a)
Systems are included in group of high-risk AI systems in accordance with the laws;
b)
AI systems prescribed in clause 7 of this Article of which results are used for
grounds for competent authorities to consider and issue administrative
decisions.
2.
In cases where AI systems prescribed in clause 1 of this Article are changed
regarding purposes of uses, main functions, input data sources, or regulated
entities that pose a new risk or a different risk level, deployers shall
evaluate additional impacts before continue using such systems.
3.
Deployers shall prepare reports on impact evaluation using Form AI02 in the
Appendix attached to this Decree. The report on impact evaluation shall comply
with clause 3, Article 27 of the Law on AI and the following information:
a)
Description on the AI system and purposes of use;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c)
Risk control and mitigation measures;
d)
Mechanisms for human oversight and intervention during the operation of the
system.
4.
Heads of deployers shall prepare and approve reports on impact evaluation before
putting AI systems into use, and be accountable to the laws for the
information, truthfulness and completeness of reports.
5.
Deployers shall publish reports on impact evaluation as prescribed in clause 4,
Article 27 of the Law on AI, except for information on state secrets, business
secrets or personal data in accordance with the laws.
6.
The use of AI systems of state authorities shall comply with the national
artificial intelligence ethics framework, and shall not replace the authority
and responsibilities for issuing decisions of competent persons as prescribed
in clauses 1 and 2, Article 27 of the Law on AI.
7.
AI systems deployed by state authorities are considered to be related to human
rights, social equity or public interests in one of the following cases:
a)
Results of systems are used as grounds for consideration and issuance of
decisions regarding state management or provision of public services;
b)
Results of systems are used for classification, grading, evaluation or ranking
of organizations and individuals;
c)
Results of systems are used for allocation of budget, public resources, or
determination of rates of entitlement, beneficiaries and benefits;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
8.
The Ministry of Science and Technology shall supervise the evaluation of
impacts of the use of AI systems of state authorities; summarize results and
report to the Prime Minister when necessary.
9.
The evaluation of impacts shall be funded by the state budget in accordance
with decentralized state budget, legitimate revenues of public service
providers, and other legitimate funding sources in accordance with the laws.
Chapter IV
REGULATORY SANDBOX MECHANISMS
Article 21. Principles of regulatory sandbox mechanisms for
AI systems
1.
The application of regulatory sandbox mechanisms for AI systems shall comply
with Article 21 of the Law on AI, laws on science, technology and innovation,
and this Decree.
2.
The participation in regulatory sandbox mechanisms for AI systems is voluntary.
Organizations and individuals participating in regulatory sandbox shall comply
with the following principles:
a)
Clearly determine and comply with the scope, scale, subjects, time limit,
requirements for regulatory sandbox, and risk management measures at the
request of state competent authorities;
b)
Protect rights and legitimate interests of organizations and individuals
participating in the regulatory sandbox;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
d)
Comply with laws on national security, social order and safety, data, personal
data protection, cybersecurity, and relevant laws;
dd)
Be put under supervision of state competent authorities throughout the
regulatory sandbox.
3.
The research, development and regulatory sandbox of AI systems in simulated
environment, closed environment; or internal regulatory sandbox without real
participants and without producing impacts outside of an organization is not
within the scope of regulatory sandbox mechanisms prescribed in this Decree.
4.
Organizations and individuals participating in regulatory sandbox shall:
a)
Develop and apply risk management measures;
b)
Publish potential risks; establish mechanisms for receiving and handling
complaints of participants.
5.
The result of completing the regulatory sandbox is one of grounds for state
competent authorities to consider and issue the Decision on:
a)
Recognition of all or part of regulatory sandbox results for evaluation of the
conformity of AI systems;
b)
Exemption, reduction or adjustment of the application of compliance obligations
in accordance with laws on AI.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
7.
Within the scope, time and requirements for regulatory sandbox prescribed in
the Certificate of participation in regulatory sandbox, authorities and
individuals participating in regulatory sandbox are entitled to the following
supporting mechanisms in accordance with decisions issued by state competent
authorities:
a)
Apply alternative announcement or transparency measures in place of certain
obligations regarding risk classification, technical marking or labeling as
prescribed by the Law on AI if participants are fully and clearly informed;
b)
If AI systems are subject conformity evaluation in accordance with the Law on
AI, the conformity evaluation may be implemented after the sandbox is completed;
c)
Be given priority access to supporting programs, resources and policies for AI
development in accordance with the laws.
8.
In cases where specialized laws have regulations on regulatory sandbox
mechanisms for products, services or business models, regulatory sandbox for AI
systems in any field shall comply with regulatory sandbox mechanisms for
corresponding field. State management authorities in charge of AI shall
cooperate with specialized management authorities in evaluating, supervising
and managing risks regarding AI of the regulatory sandbox system.
9.
Authorities of the Communist Party of Vietnam, Vietnam Fatherland Front
Committee, and socio-political authorities may voluntarily apply regulatory
sandbox mechanisms prescribed in this Chapter for AI systems to serve internal
activities. Competent authorities of the Communist Party of Vietnam shall issue
the Decision on the scope, scale, appraisal and evaluation of independent
sandbox results regarding regulations on administrative procedures in this
Decree.
Article 22. Classification of levels of regulatory sandbox
1.
AI systems participating in regulatory sandbox shall be classified in 03 levels
according to the evaluation of the following factors:
a)
Risk levels of AI systems in accordance with the Law on AI:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c)
The scope and scale for deployment of regulatory sandbox including the
deployment area, number of sandbox sites, participants, and the level of
connectivity with data systems or information systems;
d)
The level of impacts to national security, social order and security, rights
and legitimate interests of organizations and individuals.
2.
In cases where AI systems satisfy criteria of multiple levels of regulatory
sandbox, systems shall be classified according to the highest level.
The
classification of levels of regulatory sandbox shall be classified in
accordance with functions, purposes of use and general impacts of AI systems
including cases where systems are deployed by combining multiple components,
modules or services.
3.
AI systems are classified as level-3 regulatory sandbox when participants, number
of sandbox sites and duration for sandbox are determined in one of the
following cases:
a)
Handle sensitive personal data, core data, important data or children personal
data in cases where it is required to evaluate impacts on handling of personal data
in accordance with laws on personal data protection;
b)
Systems for handling data are included in the List of state secrets in
accordance with the laws;
c)
Systems are deployed within or connected to information systems included in the
List of important information systems regarding national security in accordance
with laws on cybersecurity.
4.
AI systems are classified as level-2 regulatory sandbox when participants,
sandbox sites and duration for sandbox are determined in accordance with the
following requirements:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
Results of systems are used in actual activities including cases where such
results are integrated into procedures for service provision or work handling;
provided to users, or used as reference grounds for issuing decisions, but do
not pose additional, change, or terminate rights or obligations of
organizations or individuals;
c)
Cases not included in clause 3 of this Article.
5.
AI systems are classified as level-1 regulatory sandbox when participants,
sandbox sites and duration for sandbox are determined in accordance with the
following requirements:
a)
Participants determined in accordance with specific criteria;
b)
Results of systems are not used in actual activities; not integrated into
procedures for service provision or work handling; not provided to users; and
not used as reference grounds for issuing decisions;
c)
Cases not included in clauses 3 and 4 of this Article.
6.
State competent authorities shall determine levels of regulatory sandbox for AI
systems according to criteria in accordance with this Article when receiving
and handling applications for participating in regulatory sandbox.
Article 23. Authority and procedures for approval of
participation in regulatory sandbox
1.
State competent authorities shall approve the participation in regulatory
sandbox for AI systems in accordance with Article 21 of the Law on AI and this
Decree.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
Organizations and individuals shall submit 01 set of application via the
National public service portal for handling in accordance with the laws. The
application shall be synchronized to the Single-window portal on AI for
performing other state management tasks in accordance with this Decree.
3.
The authority for receipt, appraisal and issuance of written approval is
determined as follows:
a)
Province-level People’s Committees have the authority for receipt, appraisal
and issuance of written approvals for level-1 or level-2 AI systems deployed
within a province or city;
b)
Ministries and ministerial authorities have the authority for receipt,
appraisal and issuance of written approvals for level-1 or level-2 AI systems
when such systems are under the management of ministries and ministerial
authorities, and deployed in more than 02 provinces and cities; or are deployed
by authorities and organizations under the management of ministries and
ministerial authorities;
c)
The Ministry of Public Security has the authority for receipt, appraisal and
issuance of written approvals for level-3 AI systems.
In
cases where AI systems are under the management of multiple ministries and
ministerial authorities, those directly managing the main activities of systems
have the authority for receipt, appraisal and issuance of written approvals.
4.
Within 03 working days from the receipt of applications, competent authorities
shall review the validity of the application and send an electronic written
request for amendment to the application.
5.
For valid applications, competent authorities shall appraise and issue written
approvals or written refusals within the following deadline:
a)
Within 10 working days for cases prescribed in point a, clause 3 of this
Article;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c)
Within 30 working days for cases prescribed in point c, clause 3 of this
Article.
During
the appraisal, competent authorities may collect information under the
management of relevant state competent authorities when such information
affects appraisal results.
6.
In cases of refusal, competent authorities shall send a written response stating
the reasons.
7.
Written approvals for participation in regulatory sandbox using Form AI09a (in
case of organizations) or Form AI09b (in case of individuals) in the Appendix
attached to this Decree shall include the following information:
a)
Scope, geographical scope and period for sandbox;
b)
Scale and limit of sandbox;
c)
Technical requirements; requirements for safety, security, data protection and
risk management;
d)
Reporting responsibility and supervision mechanisms;
dd)
Cases of suspension or termination of sandbox;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
8.
Written approvals are only valid within the scope of the sandbox and do not
pose additional right to officially deploy the artificial intelligence system
beyond such scope.
Article 24. Requirements and applications for participation
in regulatory sandbox
1.
Authorities and individuals registering for participation in regulatory sandbox
shall comply with the following requirements:
a)
Have AI systems or AI measures that apply innovation, new technology or new
deployment models;
b)
Have sandbox measures which determine targets, scope and time for sandbox,
participants, and risk management measures in conformity with levels of sandbox
as prescribed in Article 22 of this Decree;
c)
Measures for protection of rights and legitimate interests of affected
organizations and individuals during the sandbox;
d)
In cases where AI systems may directly cause damages to the life and health of
persons, or large-scale property, participants shall apply civil insurance
responsibility or financial measures in conformity with the scope of the
sandbox.
2.
An application for registration for participation in regulatory sandbox includes
the following documents:
a)
A written request using Form AI03a (in case of organizations) or Form AI03b (in
case of individuals) in the Appendix attached to this Decree;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c)
Description on measures for protection of rights and legitimate interests of
affected organizations and individuals during the sandbox;
d)
Description on technical competency, workforce or infrastructure for related to
the scope of proposed sandbox.
3.
Startups, small- and medium-sized enterprises, scientific and technological
organizations, and research groups registering for participation in regulatory
sandbox for AI systems classified as level-1 sandbox shall submit a simplified
application including the following documents:
a)
A written request using Form AI03a (in case of organizations) or Form AI03b (in
case of individuals) in the Appendix attached to this Decree;
b)
Description on the AI system proposed for sandbox, main risks that may arise,
and risk mitigation measures during the sandbox.
4.
Applications prescribed in clause 2 and 3 of this Article shall be submitted
online in accordance with Article 23 of this Decree.
5.
State competent authorities shall not request organizations and individuals to
provide additional documents not prescribed in this Article, except for cases
where the laws prescribe specific documents for regulatory sandbox in the
corresponding field.
Article 25. Supervision and reporting during regulatory
sandbox
1.
During the sandbox period as prescribed in written approvals for participation
in regulatory sandbox, authorities issuing written approvals shall supervise
the activities of the regulatory sandbox by the following methods:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
Request participants to provide additional risk management measures, or propose
adjustment of the scope of sandbox for consideration within the authority when
risks arise beyond the scope of sandbox;
c)
Issue the Decision on suspension of regulatory sandbox, termination of
regulatory sandbox, or termination of written approval for participation in
regulatory sandbox when participants violate the limit of sandbox or fail to
mitigate incidents as required by state competent authorities.
2.
Participants shall submit periodic reports on the sandbox status via the
Single-window portal on AI using Form AI05a (in case of organizations) or Form
AI05b (in case of individuals) in the Appendix attached to this Decree in
accordance with the following intervals:
a)
Level 1 and level 2: Once every 06 months;
a)
Level 3: Once every 03 months.
3.
When one of the following cases occurs, participants shall immediately apply
remedial measures and submit an ad hoc report to the Single-window on AI within
72 hours:
a)
AI systems experience serious incidents as prescribed in clause 8, Article 3 of
the Law on AI;
b)
AI systems exceed the limit of sandbox prescribed in the written approval.
The
report on incidents shall comply with Form AI06a (in case of organizations) or
Form AI06b (in case of individual. The report on exceeding the limit of sandbox
shall comply with Form AI07a (in case of organizations) or Form AI07b (in case
of individuals) in the Appendix attached to this Decree.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Article 26. Financial support for regulatory sandbox
1.
Enterprises participating in regulatory sandbox; startups; small- and
medium-sized enterprises, scientific and technological organizations, and
research groups having potential innovation projects may be considered for
granted the Paper for support for AI development in accordance with this
Decree.
2.
The financial support for regulatory sandbox shall comply with the following
principles:
a)
Comply with the mechanism for co-payment between the State and participants;
b)
Ensure the openness, transparency, proper use for intended purposes and
non-duplication with other forms of support from the state budget and state
financial foundations outside the state budget;
c)
Only provide support for costs directly serving regulatory sandbox within the
scope approved by competent authorities;
d)
Implement within the limit of resources of the National foundation for AI
development and other legitimate financial sources in accordance with relevant
laws.
3.
The Paper for support for AI development shall be used for covering a part of
the costs of services directly supporting regulatory sandbox including:
a)
Hire and use computing infrastructure, storage facilities, and platform
services for training, testing, or operation of AI systems;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c)
Use services of technical consultancy, safety testing, security evaluation,
risk evaluation, or other technical services supporting regulatory sandbox.
The
support rate shall not exceed 50% of the total actual eligible costs incurred
for services prescribed in this clause.
4.
Eligible costs are costs directly incurred for regulatory sandbox and are
determined on the following basis:
a)
Contracts for service provision;
b)
Legal invoices and records;
c)
Laws on accounting, taxes and state budget.
5.
The Paper for support for AI development shall be paid directly to service
providers on the following basis:
a)
The actual volume of provided services;
b)
Contracts, invoices and confirmations for service provision;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
6.
The issuance, use, payment and supervision of the Paper for support for AI
development shall comply with this Decree and relevant laws; and shall not pose
additional administrative procedures, requirements for business investment or
obligations of organizations and individuals beyond the Law on AI and this
Decree.
Article 27. Completion of regulatory sandbox and transition
after regulatory sandbox
1.
Within 15 working days from the receipt of the final report as prescribed in
this Decree, competent authorities issuing written approvals for participation
in regulatory sandbox shall evaluate final reports and issue the Certificate of
completion of regulatory sandbox using Form AI04 in the Appendix attached to
this Decree. In case of refusal, a written response stating the reasons shall
be provided.
If
organizations and individuals wish to extend the sandbox period, within 15
working days prior to the deadline of the sandbox, they shall submit a written
request for extension using the Form in Appendix AI03c or AI03d, and the final
report on results of sandbox using the Form in Appendix AI08a or AI08b. Within
10 working days, competent authorities shall appraise and issue the Decision on
extension of the written approval for participation in regulatory sandbox. In
case of refusal, a written response stating the reasons shall be provided.
2.
The Certificate of completion of regulatory sandbox is the ground for state
competent authorities to consider and issue the Decision in accordance with the
Law on AI including the following information:
a)
Recognition of all or part of regulatory sandbox results for evaluation of the
conformity of AI systems;
b)
Application of exemption, reduction or adjustment of compliance obligations.
3.
Participants of the sandbox may continue operating AI systems during the
transition period within 12 months from the issuance of the Certificate of
completion of regulatory sandbox in accordance with the scope, requirement,
limits and risk management measures prescribed in the written approval for
participation in regulatory sandbox and the Certificate of completion of
regulatory sandbox.
4.
During the operation within the transition period, organizations and
individuals may adjust operational measures, technical parameters and technical
operating methods of systems within determined scope, requirements, limits and
risk management measures in accordance with the approved risk management plan;
and shall ensure the ability to control risks if such adjustments do not change
the primary intended purpose or change the risk level of the system as approved
in the application.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
6.
Where there is a need to extend the operation within the transition period,
within 15 days before the expiry of the transition period prescribed in clause
3 of this Article, organizations or individuals shall submit a written request
to the authority that issued the Certificate of completion of regulatory
sandbox. Within 07 working days from the receipt of a valid written request,
such authority shall consider and issue the Decision on a one-time extension of
no more than 06 months if the following requirements are satisfied:
a)
Sandbox items have been completed and incidents have been remedied as required
by state competent authorities;
b)
All approved risk management measures are maintained.
7.
When the transition period is over, organizations and individuals shall
complete all compliance obligations in accordance with the Law on AI, this
Decree and relevant laws before continuing to provide products, services, or
operate AI systems.
8.
Certificates of completion of regulatory sandbox shall not replace permits,
certificates, written approvals or requirements for business investment as
prescribed by laws.
9.
The handling of cases that fail to comply with clause 7 of this Article shall
comply with laws on penalties for administrative violations and relevant laws.
Chapter V
INFRASTRUCTURE, DATA AND SELF-RELIANCE CAPABILITY IN DEVELOPMENT
OF AI
Article 28. Infrastructure of national AI
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
The AI infrastructure invested by the State shall be organized and assigned for
management as follows:
a)
For the infrastructure serving research, development and innovation, the
Ministry of Science and Technology shall take charge of the development,
operation and coordination of the connection, share and use of components of
this infrastructure within the national AI infrastructure;
b)
For the infrastructure serving state management activities, such infrastructure
shall be organized under an integrated, unified, synchronized and interoperable
model to ensure the connectivity and data sharing between the AI infrastructure
developed and operated by the Ministry of Public Security at national data
centers and the AI infrastructure developed and managed by ministries,
ministerial authorities and province-level People’s Committees in accordance
with practical needs and requirements of each sector and local area.
3.
The AI infrastructure shall serve the research, development and innovation
including components invested in, commissioned for development or hired by the
State which includes:
a)
Shared computing, storage and data capabilities serving the training, testing
and evaluation of AI systems;
b)
Platforms and environments serving the development, training, testing and
evaluation of AI systems;
c)
Shared AI models including foundation models, general-purpose AI models, and
Vietnamese as well as ethnic minority language models;
d)
Other infrastructure components serving research, development and innovation as
decided by competent authorities.
4.
AI infrastructure serving state management is one of the key and core
components for the management and development of the national AI system
including:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
AI platforms serving provision of public services, and protection of social
security and safety;
c)
Other infrastructure components serving state management as decided by
competent authorities.
5.
The Ministry of Science and Technology shall take charge of the development,
operation and use of infrastructure components as prescribed in clause 3 of
this Article; provision of access and use under the mechanism for provision of
public services in accordance with the laws.
6.
The Ministry of Public Security shall take charge of the development, operation
and provision of AI infrastructure serving the state management and other
purposes assigned by the Government at national data centers prescribed in
clause 4 of this Article; provision of access and use in accordance with laws
on AI, data and relevant laws.
7.
Ministries, ministerial authorities, and province-level People’s Committees
shall take charge of the development and operation of the AI infrastructure
serving the state management within their functions and tasks as agreed with
the Ministry of Science and Technology and Ministry of Public Security to prevent
overlapping investment and waste in accordance with principles in Article 29 of
this Decree.
Article 29. Principles for development, coordination and
mobilization of resources for the national AI infrastructure
1.
The national AI infrastructure shall be developed in a unified, open, secure,
interoperable, shareable and scalable manner in accordance with national
strategies, planning’s and programs for science, technology, innovation and
digital transformation; and in accordance with requirements for national
defense, security and safety.
2.
Authorities, organizations and individuals participating in investment in,
development, management, operation and provision of AI services in the network
of national AI infrastructure shall comply with the following principles:
a)
Ensure the interoperability, connectivity, data sharing and technical
compatibility in accordance with technical regulations and connection
requirements issued or announced by state competent authorities. The
application of standards shall comply with laws on standards and technical
regulations;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c)
Protect cybersecurity, national security, data, state secrets, business
secrets, legitimate interests of authorities, organizations and individuals in
accordance with the laws;
d)
Connect, share and effectively use existing infrastructure resources to prevent
overlapping investment;
dd)
Comply with laws on efficient use of energy. Authorities, organizations and
individuals shall perform measures to reduce greenhouse gas emissions.
Operational activities shall not pose a threat to the safety of the national
power system.
3.
The Ministry of Public Security shall take charge and cooperate with the
Ministry of Science and Technology, ministries, ministerial authorities and relevant
authorities in coordinating the national AI infrastructure according to
strategies, planning’s and orientations for development of AI infrastructure
including the following information:
a)
Coordinate the connection, share and use of AI infrastructure in the network of
national AI infrastructure;
b)
Review and summarize the needs; take charge of cooperation and proposal for
efficient investment, use, share and extraction of infrastructure to prevent
overlapping investment;
c)
Announce information on the capability for using shared AI infrastructure.
4.
The Ministry of Public Security shall take charge of coordination, operation
and use of AI infrastructure for state management activities deployed at
national data centers in accordance with clause 2 of this Article and relevant
laws.
5.
The State shall encourage the mobilization of social resources for investment
and development of AI infrastructure by PPP investment, hire of services and
other cooperation methods in accordance with laws on PPP investment and
relevant laws.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Authorities, organizations and individuals managing and operating AI
infrastructure within the network of national AI infrastructure shall connect,
share and use infrastructure to efficiently use computing capacity, data and AI
platforms serving state management, research, development and innovation in the
field of AI in accordance with the following principles:
a)
For infrastructure invested by the State, authorities managing and operating
infrastructure shall connect and announce information on the infrastructure
capability, provision scope, using methods and technical requirements within
their functions, tasks and powers in accordance with relevant laws;
b)
For infrastructure invested by organizations and organizations, the
connectivity, share and use of infrastructure shall be optional via agreements
or contracts in accordance with the laws;
c)
The connection, share and use of infrastructure shall not change ownership
rights, management rights or lawful rights to use the infrastructure and
relevant resources, except where otherwise provided by laws.
2.
Authorities, organizations and individuals wishing to use AI infrastructure
within the network of national AI infrastructure shall access and use such
infrastructure by the methods announced by managing and operating authorities,
or via the Single-window portal on AI.
The
provision and use of infrastructure shall comply with laws on provision of
public services; science, technology and innovation; state budget; public
investment; PPP investment; and relevant laws without posing additional
administrative procedures.
3.
Authorities, organizations and enterprises managing and operating AI
infrastructure bear the following responsibilities when connecting to, sharing
and using AI infrastructure within the network of national AI infrastructure:
a)
Comply with standards, technical regulations and reference technical specifications
issued or announced by state competent authorities;
b)
Protect cybersecurity, data, state secrets, business secrets, rights and
legitimate interests of authorities, organizations and individuals in
accordance with the laws;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Article 31. Standards, technical regulations and inspection
of national AI infrastructure
1.
The Ministry of Science and Technology is the conduit taking charge and
cooperating with the Ministry of Public Security and relevant state
authorities, within their functions, tasks and powers, in issuing or announcing
the following standards and technical regulations in accordance with the laws:
a)
Compulsory national technical regulations applied to AI infrastructure
participating in the network of national AI infrastructure;
b)
Technical requirements for connection and technical specifications for
connecting to, sharing and using AI infrastructure;
c)
Technical criteria regarding cybersecurity of AI infrastructure in accordance
with laws on cybersecurity;
d)
Applied standards for AI infrastructure in accordance with laws on standards
and technical regulations.
2.
Authorities, organizations and enterprises managing and operating AI
infrastructure shall comply with compulsory national technical regulations,
technical criteria regarding cybersecurity and connectivity technical
requirements issued or announced in accordance with clause 1 of this Article
when participating in the network of national AI infrastructure. The
application of standards for Ai infrastructure shall comply with laws on
standards and technical regulations.
3.
The inspection and handling of violations regarding the connection, share and
use of Ai infrastructure shall comply with laws on inspection, laws penalties
for administrative violations and relevant laws.
Article 32. Database for AI
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Open data;
b)
Conditional open data;
c)
Commercial data of organizations and enterprises in accordance with the laws.
2.
The Ministry of Public Security is the governing body of the national database
on AI and bears the following responsibilities:
a)
Be responsible for developing, managing and operating the national database on
AI at national data centers;
b)
Take charge of the development of standards for connection, share, and
technical standards for security of the national database on AI;
c)
Take charge and cooperate with ministries and ministerial authorities in
proposing the Prime Minister for promulgation and update of the List of
datasets serving the development of AI in essential fields.
3.
Ministries and ministerial authorities shall develop, issue or propose for
issuance of standards and technical regulations on data serving the development
of AI in the fields under their management as prescribed by laws.
4.
National data centers shall provide technical infrastructure, storage
capability and technical requirements for operation of the national database
for AI in accordance with the laws.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Develop and update open data, conditional open data and commercial data under
their management;
b)
Collect, develop, update, ensure the quality of, label, annotate and
standardized datasets included in the List of datasets serving the development
of AI in essential fields;
c)
Uniformly connect, share and use the national database for AI in accordance
with the laws.
6.
The state budget shall cover the collection, development, quality control,
standardization, labeling and annotation of datasets, databases serving AI via
the following methods:
a)
Deploy investment projects for application of information technology;
b)
Perform tasks related to science, technology and innovation;
c)
Perform mechanisms whereby the State commissions, assigns tasks, conducts
bidding for provision of products and services, and other methods in accordance
with the laws.
Article 33. Supporting mechanisms for development of AI via
voluntary sharing
1.
Organizations, enterprises and individuals that voluntarily share data, AI
models, tools, software or research results for the development of AI in
accordance with laws on data, personal data protection and intellectual
property may be considered for support according to the criteria prescribed in
clause 3 of this Article and within support resources as prescribed by laws.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Prioritize the access and use of computing infrastructure and data storage
infrastructure in accordance with mechanisms for use of AI infrastructure
prescribed in this Decree and relevant laws;
b)
Prioritize the access and use of technical services for handling data,
training, testing or evaluating AI infrastructure;
c)
Other lawful forms of non-financial support in accordance with the laws
excluding monetary payment or forms having equivalent monetary value.
3.
The Ministry of Science and Technology shall refer to the following criteria to
consider and decide supporting levels:
a)
The volume, scale and scope of application of shared data, models, tools or
research results;
b)
The level of completeness, standardization and direct usability of the data,
models or research results;
c)
The level of availability and substitutability of the data, models, tools or
research results within existing resources;
d)
The level of support for development of Vietnamese and ethnic minority language
AI models; support for public interests, state management tasks; or promotion
for innovation.
4.
The support prescribed in this Article shall comply with the following
principles:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Not pose additional transactions involving the sale or purchase of data,
models, tools or research results in violation of the laws;
c)
Not convert non-financial support into money or assets of equivalent value.
5.
The Minister of Science and Technology shall regulate electronic form and
guidelines for implementation of this Article. The guidelines shall not pose
additional administrative procedures, business investment requirements or
documents that are not prescribed in this Decree.
Article 34. Implementation of non-financial support
1.
Organizations, enterprises and individuals wishing to receive non-financial
support as prescribed in Article 33 of this Decree shall provide information on
the resources that they wish to share and their needs to use support via the
Single-window portal on AI.
The
provision of information prescribed in this clause is optional, does not pose
additional administrative procedures, and is not a requirement for
consideration for support.
2.
The information includes:
a)
A description of the shared data, AI models, tools, software or research
results including basic technical information and the scope of use;
b)
Information on ownership rights or lawful rights of use with respect to shared
resources, and a commitment to comply with laws on data, personal data
protection, cybersecurity and intellectual property;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
The Ministry of Science and Technology shall receive, summarize and evaluate
the information according to criteria prescribed in clause 3, Article 33 of
this Decree, and capacity of the announced support resources in order to
determine the appropriate level and form of support.
The
determination of support shall be performed according to public, transparent
and non-discriminatory criteria in conformity with the proposed usage needs and
the capacity to provide infrastructure, data and support services.
4.
The results of the support determination shall be notified to organizations,
enterprises and individuals by electronic means, which specify the form of
support, scope of use, duration of use and requirements for use, if any.
5.
Organizations, enterprises and individuals receiving support shall use such
support for its intended purposes and cooperate in providing information on the
results of its use, if necessary, to facilitate the evaluation of support
effectiveness.
The
provision of information under this clause shall not pose additional periodic
reporting regime or regular administrative obligation.
6.
The Ministry of Science and Technology shall issue electronic form for
provision of information and guidelines for implementation of this Article.
The
use of electronic forms is supportive in nature, optional, does not constitute
a requirement for consideration of support, and does not pose additional
administrative procedures, business investment requirements, or information
provision obligations beyond those prescribed in this Decree.
Article 35. Extraction and use of data serving the
development of AI
1.
Organizations and individuals may extract and use data in data facilities
serving the development of AI when satisfying requirements for access, scope of
extraction and purposes of use in accordance with laws on data, personal data
protection, intellectual property, and requirements for access announced by
authorities governing the data or data owners in accordance with clause 2 of
this Article.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
The
determination of requirements for access and extraction of data shall ensure
openness, transparency and non-discrimination among organizations and
individuals that satisfy the same requirements for access in accordance with
the laws.
2.
Authorities and organizations managing and operating databases invested and
developed by the State shall announce the following information on the
Single-window portal on AI:
a)
List of data that is allowed to be shared and extracted;
b)
Requirements for access, scope of extraction and purposes of use of the data;
c)
Applied standards, technical regulations and technical requirements in
accordance with the laws;
d)
Methods for access to the data and technical support conduit.
Regulations
prescribed in this clause shall be interconnected and synchronized with the
Data Information Portal. The announcement of information prescribed in this
clause shall ensure the capability to access and extract data, and shall not
pose additional administrative procedures.
3.
The provision of data serving the development of AI shall be performed via one
or more of the following methods:
a)
Allow direct access to the data system or through an application programming
interface (API);
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c)
Develop a secure environment for data extraction in which organizations and
individuals may process data or train AI models by using the infrastructure of
data management authorities without changing data ownership rights.
4.
Authorities and organizations managing and operating databases bear the
following responsibilities when providing data:
a)
Develop mechanisms for management of access in conformity with the type of data
and scope of extraction;
b)
Record and supervise the connection and extraction of data in accordance with
the laws;
c)
Take control over the extraction of data in accordance with prescribed purposes
and scope in conformity with announced or agreed requirements for connection;
d)
Apply technical measures and management measures to protect data safety,
cybersecurity, and comply with laws on data, personal data protection and
relevant laws.
5.
Organizations and individuals extracting and using the data shall:
a)
Use data for announced or agreed purposes, scope and requirements for access;
b)
Not change and distort, or use data against the laws;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
6.
The collection of fees for extraction and use of data in the national database
for AI and other databases for AI managed by the State shall comply with laws
on data, and laws on fees and charges.
Article 36. Security and safety for the infrastructure and
data serving the development of AI
1.
Authorities and organizations managing and operating AI infrastructure or
databases serving the development of AI shall apply technical measures and
management measures in conformity with purposes of use, scope of deployment and
risk level to protect security and safety of the infrastructure and data in
accordance with the laws, relevant standards and national technical regulations.
2.
Authorities and organizations managing and using AI infrastructure or databases
serving the development of AI shall comply with announced or agreed
requirements for access and requirements for extraction within the scope of
using infrastructure and data in accordance with relevant laws.
3.
Measures prescribed in clause 1 of this Article include:
a)
Protect the confidentiality, integrity and availability of infrastructure and
data in accordance with the laws;
b)
Prevent, detect and handle risks, cybersecurity incidents and data safety
incidents in accordance the laws;
c)
Prevent and take control over specific risks of AI systems including the risk
of attacks, exploitation of vulnerabilities in AI models, and the risk of
re-identification of de-identified personal data during processing and use of
data.
4.
The announcement, reporting and cooperation in handling incidents related to
personal data and cybersecurity shall comply with laws on personal data
protection, laws on cybersecurity and relevant laws.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
The Ministry of Science and Technology is the conduit coordinating the
promotion of research, development and mastery of AI technology; responsible
for summarizing the needs, determining priority orientations, supervising,
evaluating the deployment, and ensuring the cooperation between ministries,
ministerial authorities and province-level People's Committees in accordance
with the laws.
2.
Core AI technology is prioritized for mastery includes:
a)
General-purpose AI models, foundation models, and large language models in
Vietnamese and ethnic minority languages;
b)
Technology for processing knowledge, data and Vietnamese language;
c)
High-performance training technology and computing capabilities serving the
development and deployment of AI systems;
d)
Hardware, semiconductor integrated circuits, and computing technologies serving
AI;
dd)
Open-source solutions and foundational technologies serving the development of
the domestic AI ecosystem;
e)
Other AI technologies in accordance with the list issued by the Prime Minister
in each stage.
3.
Ministries, ministerial authorities and province-level People’s Committees,
within their functions, tasks and powers, shall perform the following measures
in accordance with the laws:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
Support the research, development, testing, completion and application of AI
technology;
c)
Organize the connection and cooperation between enterprises, scientific and
technological organization and higher educational institutions;
d)
Prioritize the allocation and use of AI products and solutions in public
procurement activities in accordance with laws on bidding and relevant laws.
4.
Organizations and individuals performing research, development and mastery of
AI technology as prescribed in clause 2 of this Article may access and use
supporting mechanisms and preferential policies in accordance with laws on
science, technology and innovation; investment; tax; and relevant laws.
5.
The application of measures prescribed in this Article shall ensure openness,
transparency, proper authority and conformity with prescribed objectives; avoid
overlapping support funded by the state budget; and comply with relevant laws.
Chapter VI
DEVELOPMENT OF INNOVATION ECOSYSTEM AND AI MARKET
Article 38. Development of AI ecosystem and market
1.
The Ministry of Science and Technology is the conduit coordinating the
development of AI ecosystem and market; responsible for announcing the
information on infrastructure capacity, data, programs, tasks and demand for AI
applications in the public sector in order to connect supply and demand, and
enhance the efficient use of resources in accordance with the laws.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Develop AI technology supply by facilitating access to and use of computing
infrastructure, data and regulatory sandbox environment; and promoting the
development of AI products and services with commercialization potential;
b)
Stimulate market demand and expand the application of AI by prioritizing the
use of AI products and services within the scope of projects and tasks for
application of information technology, digital transformation, digital
government and digital economy development, and provision of public services in
accordance with the laws; encouraging the implementation of innovation
procurement and commissioning models, as well as the application of AI in state
administration, production, business and social life. The allocation of
recurrent expenditures and public investment expenditures shall comply with
laws on the state budget, bidding and relevant laws;
c)
Connect the market and promote commercialization of AI products and services by
developing platforms for connecting the technology demand and supply; promoting
cooperation between enterprises, scientific and technological organizations,
higher education institutions and investors.
3.
Technology enterprises, small-sized and medium-sized enterprises, startups,
scientific and technological organizations and higher education institutions
participating in development, provision or application of AI products and
services are prioritized for policies prescribed in clause 2 of this Article
and relevant laws.
4.
The policies prescribed in this Article shall be implemented via programs,
projects, tasks related to science and technology, and mechanisms in accordance
with the laws; shall not pose additional administrative procedures or new
business investment requirements.
Article 39. AI linkage cluster
1.
The Ministry of Science and Technology shall issue the Decision on recognition
of AI linkage cluster as prescribed in clause 1, Article 24 of the Law on AI
when the following criteria is satisfied:
a)
Involve the participation of at least two of the following three groups of
entities: enterprises; scientific research institutions or higher education
institutions; innovation support organizations, intermediary organizations of
the science and technology market, state authorities, or public service
providers;
b)
Have objectives, scope and information focused on the research, development,
testing, application or commercialization of AI technology;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
d)
Have mechanisms for coordination of operation of the linkage cluster including
coordination conduit and cooperation methods between members.
2.
Organizations representing linkage clusters shall submit 01 set of electronic
application for recognition of AI linkage via the National public service
portal for processing in accordance with the laws. Such application shall be
synchronized to the Single-window portal on AI for state management activities
in accordance with this Decree. The application include:
a)
A written request for recognition of AI linkage cluster;
b)
List of members of linkage cluster;
c)
Cooperation agreement, operational regulations or linkage scheme;
d)
Proofs of satisfaction of criteria as prescribed in clause 1 of this Article.
3.
b) Within 15 working days from the receipt of valid application, the Ministry
of Science and Technology shall consider and issue the Decision on recognition
of AI linkage cluster. The List of recognized AI linkage clusters shall be
announced on the Single-window portal on AI. Competent authorities receiving
and handling applications shall not request for additional documents,
requirements or procedures prescribed in this Article.
4.
AI linkage clusters shall operate on the basis of voluntariness, autonomy and
cooperation. Participation in such clusters shall not change the legal status, or
independent rights and obligations of participating members, nor shall it
establish a state administrative management organization within clusters.
5.
Recognized AI linkage clusters are prioritized for supporting policies in
accordance with the laws including:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
Be prioritized for accessing and using shared data and datasets serving the
training, testing and evaluation of AI systems in accordance with laws on data
and relevant laws;
c)
Be prioritized for participation in programs and tasks for science and
technology, innovation programs, AI development programs and digital
transformation programs funded by the state budget in accordance with laws on
the state budget, science and technology, and relevant laws;
d)
Be considered for support by applying the Paper for support for AI development
and other supporting forms as prescribed in Article 40 of this Decree and
relevant laws.
6.
The Ministry of Science and Technology is the conduit supporting AI linkage
clusters to connect to programs, infrastructure, databases and supporting policies
for AI development. The support shall not interfere with internal operations of
linkage clusters.
Article 40. Supporting mechanisms for development of AI via
the Paper for support
1.
The Paper for support for AI development is an electronic instrument that
records the funding limit provided by the National foundation for AI
development and other lawful sources for the payment of expenses related to the
use of computing infrastructure, shared data, large language models in
Vietnamese and ethnic minority languages, training and testing platforms, and
technical consulting services serving the research, development and deployment
of AI application.
2.
Entities eligible for grant of the Paper for support for AI development include:
a)
Startups, small-sized and medium-sized enterprises;
b)
Scientific and technological organizations, research groups with potential
innovation projects;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
d)
Other organizations and individuals having projects for research, development
or application of AI in accordance with supporting programs, schemes or
mechanisms approved by competent authorities as prescribed by laws.
3.
The issuance, management and use of the Paper for support for AI development
shall comply with the following principles:
a)
Ensure openness, transparency, objectivity and non-discrimination;
b)
Comply with policy objectives and the capability to allocate support resources;
c)
The Paper for support shall not be redeemable for cash, transferable, and may
only be used within the scope, purpose, limit, validity period and requirements
specified therein;
d)
No overlapping support shall be provided for the same expenditure item that has
already been financed by the state budget or other lawful financial sources,
unless otherwise provided by laws.
4.
Organizations and individuals prescribed in clause 2 of this Article shall
submit an application for grant of the Paper for support via the National public
service portal in accordance with the laws. The application shall be
synchronized to the Single-window portal on AI for state management in
accordance with this Decree. The application includes:
a)
A written request for issuance of the Paper for support;
b)
An explanation of the needs for using services and expected objectives;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Within
05 days from the receipt of a valid application, the Ministry of Science and
Technology shall consider and issue the Decision on issuance of the Paper for
support in accordance with announced criteria and the availability of support
resources; shall not request for documents other than those prescribed in this
clause.
5.
The Paper for support shall be used for paying expenses for services directly
supporting AI activities including:
a)
Services of computing and storage infrastructure, and technical platforms;
b)
Data services and AI models within the scope prescribed by laws;
c)
Data processing, training, testing and evaluation services for AI systems;
d)
Technical consulting services for safety, security and risk management.
6.
Organizations and enterprises providing services prescribed in clause 5 of this
Article may provide payment services by using the Paper for support in the
following cases:
a)
Operate in accordance with the laws;
c)
Announce information on services, requirements for provision of services, and
service prices;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
The
announcement of information prescribed in point b of this clause is not a
business requirement and shall not pose additional administrative procedures.
7.
Organizations and individuals granted the Paper for support may choose
organizations or enterprises providing services prescribed in clause 6 of this
Article to use services suitable to their needs. Such selection shall
constitute a civil transaction between the parties. The payment using the
Application for support shall not give rise to a contractor selection
relationship by a state authority under laws on bidding.
8.
The payment using the Application for support shall be performed directly to
organizations or enterprises providing services according to the following
basis:
a)
Granted Application for support;
b)
Contracts or agreements for service provision;
c)
Invoices and accounting records for proving the completion of service provision
in accordance with the laws.
The
payment shall not be made through entities granted the Application for support.
9.
The Ministry of Science and Technology shall:
a)
Issue, manage and use the Application for support;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c)
Supervise and inspect the use of Application for support as prescribed by laws;
d)
Announce information on the implementation of mechanisms regarding the
Application for support to an appropriate extent to ensure that state secrets,
business secrets, personal data, and lawful rights and interests of
organizations and individuals are not infringed upon.
10.
Organizations and individuals engaging in fraud, collusion, inflation of
service prices, false declaration, incorrect certification of the volume or
results of service provision, use of unlawful invoices or supporting documents,
misuse of the Application for support, transfer of support vouchers, or
exploitation of the mechanism to obtain overlapping support shall refund the
full amount of support received and be handled in accordance with the laws.
Chapter VII
RESPONSIBILITIES OF AUTHORITIES AND ORGANIZATIONS
Article 41. Responsibilities of the Ministry of Science and
Technology
The
Ministry of Science and Technology is the conduit, accountable to the
Government for state management regarding AI nationwide, and have the following
tasks and powers:
1.
Develop, manage and operation the Single-window portal on AI and the national
database on AI systems.
2.
Take charge and cooperate with ministries and ministerial authorities in
summarizing, developing and proposing the Prime Minister for promulgation and
update of the following items:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
List of important AI applications in essential fields.
3.
Receive and summarize information serving the state management regarding AT via
the Single-window portal on AI including:
a)
Announcement on risk classification;
b)
Announcement on serious incidents;
c)
Feedback and petitions from organizations and individuals;
d)
Other information as prescribed in this Decree.
The
receipt and summary of information prescribed in this clause shall not pose
reporting obligations beyond those prescribed by laws.
4.
Promulgate, provide guidelines and inspect the implementation of the National
AI ethnics framework in accordance with the laws.
5.
Perform state management regarding conformity evaluation for AI systems in
accordance with the laws.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
7.
Perform regulatory sandbox for AI systems under its authority in accordance
with this Decree and relevant laws.
8.
Implement supporting mechanisms for AI development in accordance with this
Decree and relevant laws.
9.
Take charge of developing and proposing the Government for promulgation of
financial mechanisms, organization and operation of the National foundation for
AI development in accordance with the laws.
10.
Inspect and handle complaints, denunciations, and handle violations in
accordance with the laws.
11.
Promulgate standards, regulations and guidelines for AI systems.
12.
Provide guidelines for information regime and periodic reporting regime
regarding the development, application and management of AI.
Article 42. Responsibilities of the Ministry of Public
Security
The
Ministry of Public Security, within their functions, tasks and powers, shall
cooperate in performing state management of AI regarding protection of national
security, social order and safety, cybersecurity and data including the
following tasks and powers:
1.
Take charge and cooperate with ministries, ministerial authorities,
province-level People's Committees, relevant authorities and organizations in
detecting, preventing, investigating and handling violations regarding
exploitation of AI systems to infringe upon national security, social order and
safety, and lawful rights and interests of organizations and individuals.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Act as a conduit; be responsible for developing, managing and operating the
National database on AI at national data centers in accordance with this Decree
and laws on data.
4.
Take charge of developing standards for cybersecurity, issuing technical regulations
on infrastructure for deploying important AI applications in essential fields
as assigned by the Government.
5.
Take charge of verifying and handling serious AI incidents showing signs of
affecting national security, social order and safety; and cooperate with the
Ministry of Science and Technology and relevant authorities in determining
causes and providing guidelines on remedial measures within their respective
authority.
6.
Review, evaluate and submit to the Ministry of Science and Technology proposals
for AI systems in the field of security and order that should be included in
the List of high-risk AI systems.
7.
Cooperate with the Ministry of Science and Technology in deploying regulatory
sandbox and other regulations prescribed in this Decree.
8.
Take charge and cooperate with the Ministry of Finance in promulgating
economic-technological norms for collection, establishment, quality control,
standardization, labeling and annotation of AI to serve as a basis for the
management and use of the state budget in accordance with clause 6 Article 32
of this Decree.
9.
Take charge and cooperate with ministries and ministerial authorities in
summarizing, developing and proposing the Prime Minister for promulgation and
amendment of Lists of datasets serving the development of AI in essential
fields.
Article 43. Responsibilities of ministries, ministerial
authorities and authorities under the management of the Government
Ministries,
ministerial authorities and other authorities under the management of the Government,
within their functions, tasks and powers and according to the need for state
management, shall:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
Conduct inspections within their authority; inspect and supervise the
implementation and application of AI systems in fields under their management
in accordance with the Law on AI, this Decree and relevant laws.
3.
Receive, appraise and issue written approvals for participation in regulatory sandbox
for level-1 and level-2 AI systems under their authority; cooperate with the
Ministry of Science and Technology in appraising the conformity for
applications for participation in regulatory sandbox for AI systems in fields
under their management in accordance with this Decree.
4.
Collect, develop, control, label, annotate, standardize, manage and use
databases serving AI under their management; develop and operate AI
infrastructure serving state management under their management; connect and
share the national database on AI in accordance with standards, technical
regulations and requirements for cyber security in accordance with the laws.
5.
Integrate AI development objectives and tasks into development strategies and plans
of the fields; prioritize allocation of resources and use of AI products and
services in state management and public service provision in accordance with
the Law on AI.
Article 44. Responsibilities of province-level People’s
Committees
Province-level
People’s Committees shall perform state management of AI in local areas and
bear the following responsibilities:
1.
Issue and implement programs and plans for development and application of AI in
conformity with local conditions in accordance with the laws.
2.
Collect, develop, control, label, annotate, standardize, manage and use
databases serving AI at local areas; develop and operate AI infrastructure
serving state management at local areas; connect and share the national
database on AI in accordance with standards, technical regulations and
requirements for cyber security in accordance with the laws.
3.
Integrate AI development objectives and tasks into local development strategies
and plans; prioritize allocation of resources and use of AI products and
services in state management and public service provision in accordance with
the Law on AI; direct authorities and units under their management to evaluate
impacts and ethnics requirements during the use of AI in accordance with the
laws.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
5.
Receive, appraise and issue written approvals for participation in regulatory
sandbox for level-1 and level-2 AI systems within their authority; cooperate
with the Ministry of Science and Technology in implementing regulations on risk
classification, incident reporting, conformity evaluation and regulatory
sandbox for AI systems at local areas.
6.
Conduct inspections, handle violations, make announcement and submit periodic
reports on the status of development, application and management of risks of AI
systems at local areas in accordance with the laws.
Chapter VIII
IMPLEMENTATION CLAUSE
Article 45. Effect
This
Decree comes into force from May 01, 2026.
Article 46. Transitional provision
1.
In cases where the National Single-window portal on AI has not yet been
officially launched by the Ministry of Science and Technology, the announcement
and reporting as prescribed in this Decree shall be carried out via electronic
information systems, online public services, or other receipt methods announced
by the Ministry of Science and Technology to ensure consistency nationwide.
The
announcement and reporting by methods prescribed in this clause have the same
legal validity as implementation via the National single-window portal on AI.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Applications and information received before the time prescribed in clause 3 of
this Article shall be handled in accordance with applicable regulations at the
time of receipt./.
ON BEHALF OF THE GOVERNMENT
PP. PRIME MINISTER
DEPUTY PRIME MINISTER
Ho Quoc Dung
APPENDIX
LIST OF
FORMS
(Attached to Decree No. 142/2026/ND-CP dated April 30, 2026 of the Government)
Form AI01a
Report
on serious incidents for organizations
Form AI01b
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI02
Report
on evaluation of impacts of AI systems for state authorities
Form AI03a
Written
request for participation in regulatory sandbox on AI systems for
organizations
Form AI03b
Written
request for participation in regulatory sandbox on AI systems for individuals
Form AI03c
Written
request for extension of regulatory sandbox on AI systems for organizations
Form AI03d
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI04
Certificate
of completion of regulatory sandbox on AI systems
Form AI05a
Report
on the status of regulatory sandbox on AI systems for organizations
Form AI05b
Report
on the status of regulatory sandbox on AI systems for individuals
Form AI06a
Report
on serious incidents during regulatory sandbox on AI systems for organizations
Form AI06b
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI07a
Report
on exceeding the limit of sandbox for organizations
Form AI07a
Report
on exceeding the limit of sandbox for individuals
Form AI08a
Final
report on results of regulatory sandbox on AI systems for organizations
Form AI08b
Final
report on results of regulatory sandbox on AI systems for individuals
Form AI09a
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI09b
Written
approval for participation in regulatory sandbox on AI systems for individuals
Form AI01a: Report on serious incidents for organizations
[NAME OR ORGANIZATION/ENTERPRISE]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
No. .../BC-[NAME OF ORGANIZATION]
...........(place of issuance),
(date of issuance)
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
To:
...........................................................
I. General information
1.
Name of the organization/enterprise: .........................................................................................
2.
Address, contact:
...................................................................................................
II. Information on AI system
1.
Name of the system:
...................................................................................................................
2.
Identification code of AI system (AI-ID):
......................................................................................
3.
Risk level:
....................................................................................................................
4.
Provider, deployer:
.............................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Time of incident detection:
.................................................................................................
2.
Time of confirmation of causal relationship with the AI system:
...........................
3.
Location of the incident:
........................................................................................................
4.
Description on the incident:
.......................................................................................................
5.
Type of consequence (tick [x] in the appropriate box):
[
] Human life, health;
[
] Property;
[
] Human rights, privacy rights;
[
] Public services, essential services;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
[
] Estimated number of affected persons/organizations.
6.
System operational status at the time of reporting:
[
] Operating
[
] Restricted operation
[
] Suspended
7.
Preliminary evaluation of the cause of the incident (if any):
................................................
IV. Performed emergency measures
1.
Technical measures
.............................................................................................................
2.
Organizational/administrative measures:
...............................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
………………………………………………………………………………………...…………..........
VI. Proposals and petitions (if any)
………………………………………………………………………………………...………….........
(place of issuance), (date of
issuance)
Recipient:
- Board of Management;
- Archive.
HEAD OF ENTERPRISE/ORGANIZATION
(Signature, full name, title and seal)
Form AI01b: Report on serious incidents for individuals
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
REPORT ON SERIOUS INCIDENTS
To:
.................................................................
I. General information
1.
Full name:
............................................................................................................................
2.
Identification card number:
...........................................................................................................................
3.
Address:
......................................................................................................
4.
Phone number: ..................................... Email:
...........................................................................
II. Information on AI system
1.
Name of the system: ......................................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Risk level: ......................................................................................................................
4.
Provider, deployer:
...............................................................................................
III. Risk information
1.
Time of incident detection: ..................................................................................................
2.
Time of confirmation of causal relationship with the AI system:
............................
3.
Location of the incident: .........................................................................................................
4.
Description on the incident:
........................................................................................................
5.
Type of consequence (tick [x] in the appropriate box):
[
] Human life, health;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
[
] Human rights, privacy rights;
[
] Public services, essential services;
[
] National security;
[
] Estimated number of affected persons/organizations.
6.
System operational status at the time of reporting:
[
] Operating
[
] Restricted operation
[
] Suspended
7.
Preliminary evaluation of the cause of the incident (if any):
...................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Technical measures ..............................................................................................................
2.
Organizational/administrative measures:
.................................................................................................
V. Preliminary evaluation of damages and scope of impact
………………………………………………………………………………………...………….......
VI. Proposals and petitions (if any)
………………………………………………………………………………………...………….......
........, (place of issuance),
(date of issuance)
REPORTING PERSON
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI02: Report on evaluation of impacts of AI systems
for state authorities
[NAME OF AUTHORITY/UNIT]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
No.
.../BC-[NAME OF AUTHORITY/UNIT]
..........(place of issuance),
(date of issuance)
REPORT ON EVALUATION OF IMPACTS OF
AI SYSTEMS FOR STATE AUTHORITIES
To:
..........................................................
I. General information
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
Name of AI system:
.............................................................................................
3.
System provider: .......................................................................................................
4.
Objectives, scope and main functions of the system:
..........................................................
5.
Legal basis for deploying the system (if any): ........................................................................
6.
Target users and estimated number of users:
........................................................
7.
Risk level of the system as prescribed by laws on AI:
………………………………………………………………………………………...………….......
8.
Expected date of official operation of the system:
..............................................
9.
Identification code of AI system (if any):
................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Roles of AI in professional activities:
...................................................................
2.
Input data of the system (data sources, data type, and whether personal data or
sensitive data are included): ...................................................................................................
3.
Output data of the system:
....................................................................................................
4.
Level of automation in making decisions or supporting decisions:
.....................
5.
Mechanism for human oversight and intervention during the operation of the
system: ................
6.
Scope and level of the system’s impact on organizations, individuals or communities
………………………………………………………………………………………...…………..
III. Risk evaluation
1.
Risk related to privacy rights and personal data protection:
...........................................
2.
Risk related to bias, discrimination or unfairness: ................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
4.
Risk related to transparency and accountability:
..............................................
5.
Risk related to information safety and cybersecurity:
...........................................................................
6.
Potential risk to human rights, social equity or the public interest:
………………………………………………………………………………………...…………..
7.
Other risks:
..................................................................................................................
IV. Risk control and mitigation measures
1.
Technical measures (data control algorithm control and system safety assurance):
………………………………………………………………………………………...…………..
2.
Organizational and management measures (operational procedures, assignment of
responsibilities, and workforce training):
....................................................................................................................................
3.
Measures for protecting rights and legitimate interests of affected
organizations/individuals:
………………………………………………………………………………………...…………..
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Frequency of reviewing and evaluating system operations:
..............................................................
2.
Mechanism for detecting, reporting and handling incidents or risks:
...........................................
3.
Mechanism for receiving feedback, complaints or petitions of
organizations/individuals related to the use of the system:
………………………………………………………………………..
VI. Consultation feedback and responses
Feedback
of authorities, organizations, experts or relevant units (if any):
………………………………………………………………………………………...…………..
VII. Commitments of deploying authorities
The
deploying authority/unit commits that:
1.
The information in this report truthful, complete and accurate.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
All measures are applied for risk management, supervision and protection of
rights, legitimate interests of affected organizations/individuals when they
use the AI system.
Recipient:
- Board of Management;
- Archive.
HEAD OF ORGANIZATION/UNIT
(Signature, full name, title and seal)
Form AI03a: Written request for participation in regulatory
sandbox on AI systems for organizations
[NAME OF ORGANIZATION]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
No. .../[CODE]
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
WRITTEN REQUEST FOR PARTICIPATION
IN REGULATORY SANDBOX ON AI SYSTEMS
To: [Name of state competent
authority]
I. Information of the organization
1.
Name of the organization/enterprise: ...................................................................................................
2.
Enterprise code/Decision on establishment of enterprise:
...........................................................................
3.
Address of headquarters:
..............................................................................................................
4.
Full name of the legal representative:
.............................................................................................
Title:
........................................................... Phone number/Email:
...........................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Name of the system: .....................................................................................................................
2.
Main functions/objectives of sandbox:
............................................................................
3.
Field of deployment: ............................................................................................................
4.
Self-evaluation of the sandbox level:
........................................................................................
□
Level 1 □ Level 2 □ Level 3
III. Scope of sandbox
1.
Objectives:
............................................................................................................................
2.
Time: From ..../.../.... to .../.../....
3.
Geographical scope for deployment/deploying unit: ........................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Most affected subjects:
........................................................................................
b)
Maximum processing frequency:
......................................................................................................
c)
Maximum value at risk (if any):
......................................................................................
IV. Commitments
The
applicant hereby commits to fully complying with the laws; properly
implementing methods for risk management; protecting the rights and interests
of participants; and truthfully and promptly reporting any incidents arising
during the sandbox.
V. Attached documents
□
Sandbox scheme □ Risk management measures
□
Insurance (if any) □ Proofs of capability
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
LEGAL REPRESENTATIVE OF THE
ORGANIZATION
(Signature, full name, title and seal)
Form AI03b: Written request for participation in regulatory
sandbox on AI systems for individuals
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
WRITTEN REQUEST FOR PARTICIPATION IN REGULATORY SANDBOX ON
AI SYSTEMS
To: [Name of state competent
authority]
I. Personal information
1.
Full name:
...........................................................................................................................
2.
Identification card number:
...........................................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
4.
Phone number ..........................................................Email:.......................................................
II. Information on the AI system proposed for regulatory sandbox
1.
Name of the system:
......................................................................................................................
2.
Main functions/objectives of sandbox:
.............................................................................
3.
Field of deployment:
...............................................................................................................
4.
Self-evaluation of the sandbox level:
□
Level 1 □ Level 2 □ Level 3
III. Scope of sandbox
1.
Objectives: ..............................................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Geographical scope for deployment/deploying unit:
............................................................................................
4.
Expected limits (choose and specify):
........................................................................................
a)
Most affected subjects: ............................................................................................
b)
Maximum processing frequency:
...........................................................................................................
c)
Maximum value at risk (if any): ...........................................................................................
IV. Commitments
I
hereby commits to fully complying with the laws; properly implementing the plan
for risk management; protecting the rights and interests of participants; and
truthfully and promptly reporting any incidents arising during the sandbox.
V. Attached documents
□
Sandbox scheme □ Risk management measures
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
APPLICANT
(Signature, full name and seal if any)
Form AI03a: Written request for extension of regulatory
sandbox on AI systems for organizations
[NAME OF ORGANIZATION]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
No. .../[CODE]
........, (place of issuance),
(date of issuance)
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
WRITTEN REQUEST FOR EXTENSION OF
REGULATORY SANDBOX ON AI SYSTEMS
To: [Name of state competent
authority]
I. Information of the organization
1.
Name of the organization/enterprise:
................................................................................................
2.
Enterprise code/Decision on establishment of enterprise:
.........................................................................
3.
Address of headquarters:
.............................................................................................................
4.
Full name of the legal representative:
.............................................................................................
Title:
.................................................. Phone number/Email: ...................................................
II. Information on the AI system proposed for regulatory sandbox
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
Main functions/objectives of sandbox:
...............................................................................
3.
Field of deployment: ...............................................................................................................
4.
Self-evaluation of the sandbox level:
□
Level 1 □ Level 2 □ Level 3
III. Scope of sandbox
1.
Objectives: ...............................................................................................................................
2.
Time: From ..../.../.... to .../.../....
3.
Geographical scope for deployment/deploying unit: ............................................................................................
4.
Expected limits (choose and specify):
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
Maximum processing frequency:
.........................................................................................................
c)
Maximum value at risk (if any):
.......................................................................................
IV. Commitments
The
applicant hereby commits to fully complying with the laws; properly
implementing the plan for risk management; protecting the rights and interests
of participants; and truthfully and promptly reporting any incidents arising
during the sandbox.
V. Attached documents
□
Final report □ Risk management measures
□
Insurance (if any) □ Proofs of capability
Recipient:
- Board of Management;
- Archive.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI03a: Written request for extension of regulatory
sandbox on AI systems for individuals
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
WRITTEN REQUEST FOR EXTENSION OF
REGULATORY SANDBOX ON AI SYSTEMS
To: [Name of state competent authority]
I. Personal information
1.
Full name:
...........................................................................................................................
2.
Identification card number:
..........................................................................................................................
3.
Address:
....................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
II. Information on the AI system proposed for regulatory sandbox
1.
Name of the system:
.......................................................................................................................
2.
Main functions/objectives of sandbox:
............................................................................
3.
Field of deployment:
.............................................................................................................
4.
Self-evaluation of the sandbox level:
□
Level 1 □ Level 2 □ Level 3
III. Scope of sandbox
1.
Objectives:
.............................................................................................................................
2.
Time: From ..../.../.... to .../.../....
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
4.
Expected limits (choose and specify):
a)
Most affected subjects: ..........................................................................................
b)
Maximum processing frequency:
..........................................................................................................
c)
Maximum value at risk (if any): .........................................................................................
IV. Commitments
I
hereby commits to fully complying with the laws; properly implementing the plan
for risk management; protecting the rights and interests of participants; and
truthfully and promptly reporting any incidents arising during the sandbox.
V. Attached documents
□
Final report □ Risk management measures
□
Insurance (if any) □ Proofs of capability
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
APPLICANT
(Signature, full name and seal if any)
Form AI04: Certificate of completion of regulatory sandbox
on AI systems
[NAME OF AUTHORITY/UNIT]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
No. .../GXNHT -[CODE]
............(place of issuance),
(date of issuance)
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Pursuant to the Law on Artificial Intelligence No. 134/2025/QH15;
Pursuant to Decree No. .../2026/ND-CP dated …………. of the Government
elaborating some articles and measures for enforcement of Law on AI;
Pursuant to Written approval for participation in regulatory sandbox on
AI systems No. .../GXN-[CODE] dated .../.../...;
Considering the Report on results of sandbox of [Name of organization].
Article 1. Information of the organization and sandbox system
Name
of the organization/enterprise/individual:
.....................................................................................
Tax
identification number/enterprise code: ..........................................................................................
Name
of the sandbox system:
.....................................................................................................
Sandbox
level: Level [X]
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Article 2. Applied scope, limits and duration of sandbox
Duration
of sandbox: From ..../.../.... to .../.../....
Scope
of sandbox:
..........................................................................................................
Applied
limits of sandbox:
......................................................................................
Article 3. Results of sandbox and compliance level
1.
Results achieved according to the sandbox objectives:
......................................................................
2.
Status of compliance, sandbox limits, and reporting obligations: ...........................................
3.
Incidents during the sandbox (if any):
..........................................................
4.
Overall evaluation of the risk level of the AI system after sandbox:
………………………………………………………………………………………...…………..
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
According
to the results of the sandbox, competent authorities provides the following
recommendations:
1.
Recommendations on conducting conformity evaluation for the AI system (if it is
required to conduct conformity evaluation in accordance with applicable laws);
2.
Recommendations on fulfilling compliance obligations in accordance with
applicable laws;
3.
Transition period (if applied):
..........................................................
Article 5. Effect
This
Certificate takes effect from the date on which it is signed.
This
Certificate confirms the completion of regulatory sandbox on the AI system
within the approved scope and does not replace any other licenses, certificates
or compliance obligations as prescribed by laws.
Recipient:
- Board of Management;
- Archive.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI05a: Report on the status of regulatory sandbox on
AI systems for organizations
[NAME OR ORGANIZATION/ENTERPRISE]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
No. .../GXNHT -[CODE]
..........(place of issuance),
(date of issuance)
REPORT ON THE STATUS OF REGULATORY
SANDBOX ON AI SYSTEMS
I. Information about the participant
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
Enterprise code/Tax identification
number::.....................................................................................
3.
Address, contact:
..................................................................................................
II. Information on the sandbox AI system
1.
Name of AI system: ............................................................................................
2.
Version of the AI system (if any):
...........................................................................
3.
Sandbox level: Level [X]
4.
Sandbox objectives: ............................................................................................................
III. Information about the Written approval for participation in
regulatory sandbox
1.
Number of the Written approval for participation in regulatory sandbox: ...........................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Issued by: ....................................................................................................................
IV. Time, place and scope of the sandbox
1.
Sandbox period during the reporting period: From ..../.../.... to .../.../....
2.
Place or environment for the sandbox:
.............................................................................
3.
Scope and participants of the sandbox:
...................................................
V. Status of deployment and compliance with sandbox limits
1.
The status of deployment of the sandbox during the reporting period:
...............................................................
2.
The status of compliance with or exceedance of sandbox limits prescribed in the
Written approval for participation in regulatory sandbox including:
a)
Maximum number of directly affected individuals or organizations:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
Scale of AI system deployment within the scope of sandbox:
………………………………………………………………………………………...…………..
c)
Maximum value at risk (if any):
………………………………………………………………………………………...…………..
d)
Technical, operational or other limits (specify key limits identified in the
sandbox scheme, if any):
………………………………………………………………………………………...…………..
3.
Risks arising during the sandbox and applied control measures:
………………………………………………………………………………………...…………..
4.
Risks arising during the reporting period (if any):
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Where:
-
Remedied:
.....................................................................................................................
-
Ongoing:
...........................................................................................................................
b)
Number of cases exceeding the sandbox limits (if any):
................................................
(place of issuance), (date of
issuance)
Recipient:
- Board of Management;
- Archive.
HEAD OF ENTERPRISE/ORGANIZATION
(Signature, full name, title and seal)
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
REPORT ON THE STATUS OF REGULATORY SANDBOX ON AI SYSTEMS
I. Information about the participant
1.
Full name:
.............................................................................................................................
2.
Identification card number: ............................................................................................................................
3.
Address:
......................................................................................................
4.
Phone number ..........................................................Email:.......................................................
II. Information on the sandbox AI system
1.
Name of AI system:
.............................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Sandbox level: Level [X]
4.
Sandbox objectives:
............................................................................................................
III. Information about the Written approval for participation in
regulatory sandbox
1.
Number of the Written approval for participation in regulatory sandbox:
............................................................................
2.
Date of issuance:
............................................................................................................................
3.
Issued by:
.......................................................................................................................
IV. Time, place and scope of the sandbox
1.
Sandbox period during the reporting period: From ..../.../.... to .../.../....
2.
Place or environment for the sandbox: .............................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
V. Status of deployment and compliance with sandbox limits
1.
The status of deployment of the sandbox during the reporting period:
...............................................................
2.
The status of compliance with or exceedance of sandbox limits prescribed in the
Written approval for participation in regulatory sandbox including:
a)
Maximum number of directly affected individuals or organizations:
………………………………………………………………………………………...…………..
b)
Scale of AI system deployment within the scope of sandbox:
………………………………………………………………………………………...…………..
c)
Maximum value at risk (if any):
………………………………………………………………………………………...…………..
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
………………………………………………………………………………………...…………..
3.
Risks arising during the sandbox and applied control measures:
………………………………………………………………………………………...…………..
4.
Risks arising during the reporting period (if any):
a)
Number of serious incidents:
......................................................................................
Where:
-
Remedied: ...................................................................................................................
-
Ongoing:
........................................................................................................................
b)
Number of cases exceeding the sandbox limits (if any):
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
.........(place of issuance),
(date of issuance)
REPORTING PERSON
(Signature, full name and seal if any)
Form AI06a: Report on serious incidents during regulatory
sandbox on AI systems for organizations
[NAME OR ORGANIZATION/ENTERPRISE]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
No. .../GXNHT -[CODE]
..........(place of issuance),
(date of issuance)
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
I. General information
1.
Information about the participant:
...........................................................................
a)
Name of the organization/enterprise:
..............................................................................................
b)
Address, contact:
...................................................................................................
c)
Person in charge and contact point:
.....................................................................................
2.
Information on the sandbox AI system
a)
Name of AI system:
.............................................................................................
b)
Version of the AI system (if any):
..............................................................................................
c)
Sandbox level: Level [X]
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Number of the Written approval for participation in regulatory sandbox: ............................................................................
b)
Date of issue
............................................................................................................................
c)
Issued by: ........................................................................................................................
II. Risk information
1.
Time of incident detection
Date
.../.../...
Time
..................
2.
Description on the incident
Incident
developments and scope of impact:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
☐
Impacts on human life and health
☐
Significant property damage
☐
Infringement of personal data or privacy rights
☐
Impacts on public services or essential services
☐
Impacts on national security, social order and safety
☐ Other:
............................................................................................................
4.
System operational status at the time of reporting:
☐
Operating
☐
Restricted operation
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
III. Preliminary evaluation
1.
Preliminary cause of the incident (if any):
...........................................................................
2.
Affected subjects (if any):
........................................................................
3.
Any exceedance of the sandbox limits prescribed in the Written approval for
participation in regulatory sandbox (if any):
...............................................................................................................................
4.
Is the incident related to an exceedance of the sandbox limits?
☐ Yes
☐ No
IV. Handling measures
1.
Performed technical measures:
........................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Emergency measures to mitigate damages:
......................................................................
V. Remediation plan
1.
Expected remediation measures:
..........................................................................................
2.
Expected time for completion of remediation measures:
.........................................................................
VI. Proposals and petitions
Proposals
for support from managing authorities (if any):
........................................................................
Recipient:
- Board of Management;
- Archive.
.............(place of
issuance), (date of issuance)
HEAD OF ENTERPRISE/ORGANIZATION
(Signature, full name, title and seal)
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI06b: Report on serious incidents during regulatory
sandbox on AI systems for individuals
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
REPORT ON SERIOUS INCIDENTS DURING
REGULATORY SANDBOX ON AI SYSTEMS
I. General information
1.
Information about the participant:
..........................................................................
a)
Full name: ..........................................................................................................................
b)
Identification card number:
...........................................................................................................................
c)
Address: ....................................................................................................
d)
Phone number
..........................................................Email:.......................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Name of AI system:
............................................................................................
b)
Version of the AI system (if any):
.............................................................................................
c)
Sandbox level: Level [X]
3.
Information about the Written approval for participation in regulatory sandbox
a)
Number of the Written approval for participation in regulatory sandbox:
...........................................................................
b)
Date of issue
..........................................................................................................................
c)
Issued by:
......................................................................................................................
II. Risk information
1.
Time of incident detection
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Time
..................
2.
Description on the incident
Incident
developments and scope of impact:
3.
Type of consequence (tick [x] in the appropriate box)
☐
Impacts on human life and health
☐
Significant property damage
☐
Infringement of personal data or privacy rights
☐
Impacts on public services or essential services
☐
Impacts on national security, social order and safety
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
4.
System operational status at the time of reporting:
☐ [ ]
Operating
☐ [ ]
Restricted operation
☐ [ ]
Suspended
III. Preliminary evaluation
1.
Preliminary cause of the incident (if any):
...........................................................................
2.
Affected subjects (if any): ........................................................................
3.
Any exceedance of the sandbox limits prescribed in the Written approval for
participation in regulatory sandbox (if any):
………………………………………………………………………………………...…………..
4.
Is the incident related to an exceedance of the sandbox limits?
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
☐ No
IV. Handling measures
1.
Performed technical measures:
........................................................................................
2.
Performed organizational/administrative measures: ...........................................................................
3.
Emergency measures to mitigate damages:
......................................................................
V. Remediation plan
1.
Expected remediation measures: ...........................................................................................
2.
Expected time for completion of remediation measures:
.........................................................................
VI. Proposals and petitions
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
..........(place of issuance),
(date of issuance)
REPORTING PERSON
(Signature, full name and seal if any)
Form AI07a: Report on exceeding the limit of sandbox for
organizations
[NAME OR ORGANIZATION/ENTERPRISE]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
No. .../GXNHT -[CODE]
..........(place of issuance),
(date of issuance)
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
REPORT ON EXCEEDING THE LIMIT OF SANDBOX
1. General
information
1.
Information about the participant
a)
Name of the organization/enterprise:
...............................................................................................
b)
Address, contact: ....................................................................................................
c)
Person in charge and contact point:
......................................................................................
2.
Information on the sandbox AI system
a)
Name of AI system:
............................................................................................
b)
Version of the AI system (if any):
.............................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Information about the Written approval for participation in regulatory sandbox
a)
Number of the Written approval for participation in regulatory sandbox:
...........................................................................
b)
Date of issue ...........................................................................................................................
c)
Issued by:
......................................................................................................................
II. Information on exceedance of sandbox limits
1.
Time of detection of limit exceedance
a)
Date .../.../...
b)
Time ..................
2.
Exceeded sandbox limit (tick and specify)
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
☐ Scale of
AI system deployment according to the scope of sandbox
☐
Maximum value at risk
☐
Technical, operational or other limits:
...........................................................
III. Verification data
1.
System log data:
2.
Data from other verification sources (if any):
IV. Initial handling measures
Technical
and organizational measures applied to prevent further exceedance of sandbox
limits (e.g., system shutdown, access restriction, transaction limits, module
isolation):
V. Preliminary risk evaluation
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
VI. Handling methods within 30 days (check and specify)
☐
Restore the system within the approved sandbox limits
☐
Request for amendment of the Written approval for participation in regulatory
sandbox
☐
Request for amendment of the sandbox level
Details:
...................................................................................................
VII. Proposals and petitions
Petitions
for support or guidelines from competent authorities (if any):
.........................
Recipient:
- Board of Management;
- Archive.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI07b: Report on exceeding the limit of sandbox for
individuals
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
REPORT ON EXCEEDING THE LIMIT OF
SANDBOX
1. General
information
1.
Information about the participant
a)
Full name:
b)
Identification card number:
.............................................................................................................................
c)
Address:
.......................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
Information on the sandbox AI system
a)
Name of AI system: .............................................................................................
b)
Version of the AI system (if any):
...............................................................................................
c)
Sandbox level: Level [X]
3.
Information about the Written approval for participation in regulatory sandbox
a)
Number of the Written approval for participation in regulatory sandbox:
.............................................................................
b)
Date of issue .............................................................................................................................
c)
Issued by:
.......................................................................................................................
II.
Information on exceedance of sandbox limits
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
a)
Date .../.../...
b)
Time ..................
2.
Exceeded sandbox limit (tick and specify)
☐
Maximum number of affected individuals/organizations
☐ Scale
of AI system deployment according to the scope of sandbox
☐
Maximum value at risk
☐
Technical, operational or other limits: ...................................
III. Verification data
1.
System log data:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
IV. Initial handling measures
Technical
and organizational measures applied to prevent further exceedance of sandbox
limits (e.g., system shutdown, access restriction, transaction limits, module
isolation):
V. Preliminary risk evaluation
Evaluation
of risks arising from exceedance of sandbox limits:
VI. Handling methods within 30 days (check and specify)
☐
Restore the system within the approved sandbox limits
☐
Request for amendment of the Written approval for participation in regulatory
sandbox
☐ Request
for amendment of the sandbox level
Details:
...................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Petitions
for support or guidelines from competent authorities (if any): ................
.............(place of
issuance), (date of issuance)
REPORTING PERSON
(Signature, full name and seal if any)
Form AI08a:
Final report on results of
regulatory sandbox on AI systems for organizations
[NAME OF ORGANIZATION]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
...........(place of issuance),
(date of issuance)
FINAL REPORT
on results of regulatory sandbox
on AI systems for individuals
To: [Name of the authority issuing
the Written approval for participation in regulatory sandbox]
Pursuant to the Law on Artificial Intelligence No. 134/2025/QH15;
Pursuant to Decree No. .../2026/ND-CP dated …………… of the Government
elaborating some articles and measures for enforcement of Law on AI;
Pursuant to the Written approval for participation in regulatory sandbox
on AI systems No. ../GXN-[CODE] dated ………………………. of [Name of the authority];
[Name
of the organization] hereby reports final results of regulatory sandbox on the
AI system:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Information about the participant
a)
Name of the organization/enterprise:
.............................................................................................
b)
Address, contact: .................................................................................................
c)
Person in charge and contact point:
....................................................................................
2.
Information on the sandbox AI system
a)
Name of AI system: ..........................................................................................
b)
Version of the AI system (if any):
..........................................................................................
c)
Sandbox level: Level [X]
3.
Information about the Written approval for participation in regulatory sandbox
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
b)
Date of issue ..........................................................................................................................
c)
Issued by:
....................................................................................................................
d)
Approved sandbox period: From ..../.../.... to .../.../....
dd)
Actual sandbox period: From ..../.../.... to .../.../....
II. COMPARISION OF ACTIVITIES OF THE ACTUAL SANDBOX WITH THOSE
PRESCRIBED IN THE WRITTEN APPROVAL FOR PARTICIPATION IN REGULATORY SANDBOX
No.
Item to be compared
Approve item
Actual activity
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1
Duration
of sandbox
□
Within limits/others
□
Exceeding limits/others
Basis
for amendment/approval: ...
2
Geographical
scope for deployment/deploying unit:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
3
Sandbox
field/scenario
□
Within limits/other
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Basis
for amendment/approval: ...
4
Maximum
number of directly affected individuals or organizations
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
5
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
6
Modules,
components, or version of the system used in the sandbox
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Exceeding limits/others
Basis
for amendment/approval: ...
7
Maximum
value at risk
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Technical,
operational limits or other requirements
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
9
Technical
requirements and risk management
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
In
case there are any item that exceeds, differs from, or is changed compared to
the Written approval for participation in regulatory sandbox, state the
reasons, the time of occurrence, remedial measures, and provide any written
approval or acknowledgment document issued by competent authorities (if any):
...................................................................................
………………………………………………………………………………………...…………....
III. RESULTS ACHIEVED ACCORDING TO THE SANDBOX OBJECTIVES
1.
Confirmed sandbox objectives:
No.
Sandbox objective
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Actual results
Level of achievement/Note
1
□
Satisfied
□
Partially satisfied
□
Not satisfied
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Satisfied
□
Partially satisfied
□
Not satisfied
3
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Satisfied
□
Partially satisfied
□
Not satisfied
2.
Evaluation of the performance, accuracy, reliability or output quality of the
system:
………………………………………………………………………………………...…………..
3.
Evaluation of the operability under actual sandbox conditions of the system:
………………………………………………………………………………………...…………..
4.
Evaluation of the scalability, integration or deployment capability after the
sandbox (if any):
………………………………………………………………………………………...…………..
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
………………………………………………………………………………………...…………..
IV. STATUS OF COMPLIANCE WITH THE SCOPE, LIMITS AND REPORTING REGIMES
1.
The compliance with the scope and limits of the sandbox:
□
Fully comply with confirmed scope and limits of the sandbox;
□
There were occurrences of exceeding the limits, but they were reported and
remedied;
□
There are items of non-compliance (provide explanations in clause 5 of this
Section).
2.
The status of periodic reporting:
No.
Period of reporting
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Actual submission date
Status
1
□
On schedule
□
Overdue
□
Not applicable
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
On schedule
□
Overdue
□
Not applicable
3
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
On schedule
□
Overdue
□
Not applicable
3.
The status of reporting serious incidents (if any):
.............................................................
4.
The status of reporting any exceedance of sandbox limits (if any):
...................................................
5.
Explanation for non-compliance items (if any):
.........................................................
6.
Implementation of requirements, proposals or directions of competent
authorities during the sandbox: …………………………………………………………………..........................
V. RISK MANAGEMENT, SYSTEM SAFETY, AND EMERGENCY STOP MECHANISM
1.
Identified risks before the sandbox:
................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3.
Applied risk control and mitigation measures:
No.
Risk
Control measures
Results
Remaining risk
1
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2
3
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
4.
Evaluation of the risk level of the system after the sandbox:
□
Unchanged compared to the time of sandbox approval;
□
Reduced compared to the time of sandbox approval;
□
Increased compared to the time of sandbox approval;
□
Risk level need to be reviewed and re-classified.
5.
Established and operating mechanisms for human oversight and intervention:
............................
6.
Persons/units competent to supervise and intervene, and number of interventions
(if any):
………………………………………………………………………………………...…………..
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
8.
Persons/units competent to activate emergency stop mechanism:
................................
9.
Number of emergency stop activations, triggering scenarios, and handling results
(if any):
………………………………………………………………………………………...…………..
10.
System log archive, archive period, and measures to ensure log integrity:
………………………………………………………………………………………...…………..
VI. EVALUATION OF IMPACTS FOR SANDBOX PARTICIPANTS, USERS, AND AFFECTED
ORGANIZATIONS/INDIVIDUALS
1.
Number of sandbox participants, users, or affected organizations/individuals
………………………………………………………………………………………...…………..
2.
Affected subjects: □ Direct users □ Customers/citizens/service recipients □
Internal personnel □ Other subjects:
3.
Benefits, effectiveness, or value generated during the sandbox:
..................................
4.
Negative impacts that occurred (if any):
..........................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
………………………………………………………………………………………...…………..
6.
Announcement of information regarding the sandbox and potential risks to
participants (if any): ………………………………………………………………...…………..
7.
The status of receiving and handling feedback, complaints, and support requests:
-
Number of received feedback, complaints, and support requests:
................................................................................................
-
Main content: ..............................................................................................
-
Number of handled cases:
.........................................................................................................
p-
Pending issues (if any): ...................................................................................
-
Performed remedial measures or adjustment measures:
...................................................
8.
Evaluation of the conformity of the system compared to its intended use after
the sandbox: ………………………………………………………………………………………...…………..
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Main types of data used during the sandbox:
............................................
2.
Sources of data used during the sandbox:
..........................................................................
3.
The compliance with data, personal data protection, cybersecurity and
intellectual property: □ Fully performed □ Partially performed □ Subject to
explanation □ Not applicable
4.
Performed measures for cybersecurity:
.................................................
5.
Measures for personal data protection (in cases of handling personal data):
........................................
6.
Incidents related to data, information security, or personal data protection
(if any):
………………………………………………………………………………………...…………..
7.
Measures for handling, remediation, or prevention of recurrence:
...................................................
8.
Evaluation of the capability to continue using the data, models, and sandbox
results after completing the sandbox: …………………………………………………………………………………………..
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Status:
□
Not subject to compulsory application;
□
Civil liability insurance has been implemented;
□
Equivalent financial assurance measures have been implemented;
□
Not yet implemented, reason:
.....................................................................................................
2.
Name of the insurance provider/guaranteeing organization (if any):
...........................................................
3.
Scope of insurance or guarantee:
..................................................................................
4.
Value of insurance or guarantee:
.....................................................................................
5.
Effect:
.........................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
………………………………………………………………………………………...…………..
7.
Results of handling claims for compensation, payment, or use of guarantee
measures (if any):
………………………………………………………………………………………...…………..
IX. RESULTS OF USING BENEFITS AND SUPPORT MECHANISMS WITHIN THE SCOPE OF
THE SANDBOX
No.
Mechanism prescribed in the
Written approval
Used or not
Use results/Issues encountered
Proposals after the sandbox
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Mechanism
for supporting and adjusting compliance obligations within the scope of the
sandbox
□
Yes
□
No
2
Program
for AI development
□
Yes
□
No
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3
Recognition
of all or part of sandbox results for conformity evaluation
□
Yes
□
No
Where
shared computing infrastructure, shared datasets, training/testing platforms,
shared AI models, technical consulting services, or other support services were
used, specify the actual scope and extent of such use:
………………………………………………………………………………
X. EVALUATION OF THE POSSIBILITY OF RECOGNIZING RESULTS, POST-SANDBOX
TRANSITION, AND PROPOSALS
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Request for confirmation of completion of regulatory sandbox;
□
Request for confirmation of completion of a part of regulatory sandbox;
□
Request for extension of regulatory sandbox;
□
Request for amendment to the scope of the sandbox;
□
Request for termination of the sandbox;
□
Other requests:
....................................................................................................
2.
Proposal on recognition of sandbox results for conformity evaluation (if any):
………………………………………………………………………………………...…………..
3.
Specific obligations proposed for exemption, reduction or adjustment (if any):
..............................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
5.
Replaced or supplemented risk control measures:
..........................................................
6.
Proposals on operation during transition period after the sandbox (if any)
including the duration, scope, requirements, limits, and supervision
mechanisms: ..................................................................................................
7.
Other proposals to competent authorities:
...............................................................
XI. ATTACHED DOCUMENTS
□
Technical reports or performance evaluation results;
□
Operation logs, incident logs, or documents extracted from the system;
□
Reports on serious incidents;
□
Reports on exceeding the limits of the sandbox;
□
Proofs of handling feedback and complaints;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Documents related to civil liability insurance or equivalent financial
guarantee measures;
□
Proofs of using support mechanisms within the scope of the sandbox;
□
Other documents:
The
provision of documents, logs and technical data attached to this Report shall
be carried out within the scope necessary for evaluating sandbox results in
accordance with laws on protection of state secrets, business secrets,
technological secrets, personal data, cybersecurity, and intellectual property.
Reporting
organizations and individuals are not required to provide source code, detailed
algorithms, model parameter sets, raw training data, or information classified
as state secrets, business secrets, or technological secrets, unless otherwise
required by laws.
XII. COMMITMENTS OF REPORTING ENTITY
1.
[Name of organization] hereby commits that this Report and attached documents
are truthful and complete within the scope of the approved sandbox, and is
accountable to the laws for the accuracy of provided information.
2.
[Name of organization] hereby commits that the AI system in the sandbox has
been conducted within the scope, requirements, and limits prescribed in the
Written approval for participation in regulatory sandbox , except for any
adjustments that have been approved or acknowledged by competent authorities in
accordance with the laws.
3.
[Name of organization] hereby commits not to provide, commercialize, or expand
the deployment of the AI system beyond the scope, requirements and limits
prescribed in the Written approval for participation in regulatory sandbox,
unless approved by competent authorities.
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Recipient:
- As prescribed above;
- Archive. ...
THE REPRESENTATIVE OF THE
REPORTING ORGANIZATION
(Signature, full name, title and seal
if any)
Form AI08a:
Final report on results of
regulatory sandbox on AI systems for individuals
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
..........(place of issuance),
(date of issuance)
FINAL REPORT
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
To: [Name of the authority issuing
the Written approval for participation in regulatory sandbox]
Pursuant to the Law on Artificial Intelligence No. 134/2025/QH15;
Pursuant to Decree No. .../2026/ND-CP dated …………… of the Government
elaborating some articles and measures for enforcement of Law on AI;
Pursuant to the Written approval for participation in regulatory sandbox
on AI systems No. ../GXN-[CODE] dated ………………………. of [Name of the authority];
[Full
name of the individual] hereby reports final results of regulatory sandbox on
the AI system:
I. GENERAL INFORMATION
1.
Information about the participant:
a)
Full name:
.......................................................................................................................
b)
Identification card number:
.......................................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
d)
Phone number
..........................................................Email:.......................................................
2.
Information on the sandbox AI system
a)
Name of AI system:
.........................................................................................
b)
Version of the AI system (if any):
...........................................................................................
c)
Sandbox level: Level [X]
3.
Information about the Written approval for participation in regulatory sandbox
a)
Number of the Written approval for participation in regulatory sandbox:
...........................................................................
b)
Date of issue
..........................................................................................................................
c)
Issued by:
.....................................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
dd)
Actual sandbox period: From ..../.../.... to .../.../....
II. COMPARISION OF ACTIVITIES OF THE ACTUAL SANDBOX WITH THOSE
PRESCRIBED IN THE WRITTEN APPROVAL FOR PARTICIPATION IN REGULATORY SANDBOX
No.
Item to be compared
Approve item
Actual activity
Comparison result/Note
1
Duration
of sandbox
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
2
Geographical
scope for deployment/deploying unit:
□
Within limits/other
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Basis
for amendment/approval: ...
3
Sandbox
field/scenario
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
4
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□Within
limits/other
□Exceeding
limits/others
Basis
for amendment/approval: ...
5
Maximum
scale of AI system deployment
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Exceeding limits/others
Basis
for amendment/approval: ...
6
Modules,
components, or version of the system used in the sandbox
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Maximum
value at risk
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
8
Technical,
operational limits or other requirements
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Within limits/other
□
Exceeding limits/others
Basis
for amendment/approval: ...
9
Technical
requirements and risk management
□
Within limits/other
□
Exceeding limits/others
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
In
case there are any item that exceeds, differs from, or is changed compared to
the Written approval for participation in regulatory sandbox, state the
reasons, the time of occurrence, remedial measures, and provide any written
approval or acknowledgment document issued by competent authorities (if any):
.............................................
III. RESULTS ACHIEVED ACCORDING TO THE SANDBOX OBJECTIVES
1.
Confirmed objectives of the sandbox:................................................................
No.
Sandbox objectives
Evaluation indicators/criteria
Actual results
Level of achievement/Note
1
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Satisfied
□
Partially satisfied
□
Not satisfied
2
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Partially satisfied
□
Not satisfied
3
□
Satisfied
□
Partially satisfied
□
Not satisfied
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
………………………………………………………………………………………...…………..
3.
Evaluation of the operability under actual sandbox conditions of the system:
………………………………………………………………………………………...…………..
4.
Evaluation of the scalability, integration or deployment capability after the
sandbox (if any):
………………………………………………………………………………………...…………..
5.
Unsatisfied items, causes and proposed remedial measures:
………………………………………………………………………………………...…………..
IV. STATUS OF COMPLIANCE WITH THE SCOPE, LIMITS AND REPORTING REGIMES
1.
The compliance with the scope and limits of the sandbox:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
There were occurrences of exceeding the limits, but they were reported and
remedied;
□
There are items of non-compliance (provide explanations in clause 5 of this
Section).
2.
The status of periodic reporting:
No.
Period of reporting
Submission deadline
Actual submission date
Status
1
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
On schedule
□
Overdue
□
Not applicable
2
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Overdue
□
Not applicable
3
□
On schedule
□
Overdue
□
Not applicable
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
4.
The status of reporting any exceedance of sandbox limits (if any):
.....................................................
5.
Explanation for non-compliance items (if any):
...........................................................
6.
Implementation of requirements, proposals or directions of competent
authorities during the sandbox: ………………………………………………………………………...…………..
V. RISK MANAGEMENT, SYSTEM SAFETY, AND EMERGENCY STOP MECHANISM
1.
Identified risks before the sandbox:
................................................................
2.
Risks arising during the sandbox:
......................................................
3.
Applied risk control and mitigation measures:
No.
Risk
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Results
Remaining risk
1
2
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
3
4.
Evaluation of the risk level of the system after the sandbox:
□
Unchanged compared to the time of sandbox approval;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Increased compared to the time of sandbox approval;
□
Risk level need to be reviewed and re-classified.
5.
Established and operating mechanisms for human oversight and
intervention:.....................
6.
Persons/units competent to supervise and intervene, and number of interventions
(if any):
………………………………………………………………………………………...…………..
7.
Established emergency stop mechanism:
..............................................................................
8.
Persons/units competent to activate emergency stop mechanism:
.................................
9.
Number of emergency stop activations, triggering scenarios, and handling
results (if any):
………………………………………………………………………………………...…………..
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
VI. EVALUATION OF IMPACTS FOR SANDBOX PARTICIPANTS, USERS, AND IMPACTED
ORGANIZATIONS/INDIVIDUALS
1.
Number of sandbox participants, users, or impacted organizations/individuals
………………………………………………………………………………………...…………..
2.
Affected subjects: □ Direct users □ Customers/citizens/service recipients □
Internal personnel □ Other subjects:
3.
Benefits, effectiveness, or value generated during the sandbox: ...................................
4.
Negative impacts that occurred (if any):
..........................................................................
5.
Measures for protecting rights and legitimate interests of affected
organizations/individuals:
………………………………………………………………………………………...…………..
6.
Announcement of information regarding the sandbox and potential risks to
participants (if any): ………………………………………………………………………………..
7.
The status of receiving and handling feedback, complaints, and support requests:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
-
Main content:
....................................................................................................
-
Number of handled cases:
.............................................................................................................
-
Pending issues (if any): .........................................................................................
-
Performed remedial measures or adjustment measures:
..........................................................
8.
Evaluation of the conformity of the system compared to its intended use after
the sandbox:
VII. DATA, CYBERSECURITY, PERSONAL DATA PROTECTION AND INTELLECTUAL
PROPERTY
1.
Main types of data used during the sandbox:
.....................................
2.
Sources of data used during the sandbox: .........................................................................
3.
The compliance with data, personal data protection, cybersecurity and
intellectual property: □ Fully performed □ Partially performed □ Subject to
explanation □ Not applicable
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
5.
Measures for personal data protection (in cases of handling personal data):
...................................
6.
Incidents related to data, information security, or personal data protection
(if any):
………………………………………………………………………………………...…………..
7.
Measures for handling, remediation, or prevention of recurrence:
...............................................
8.
Evaluation of the capability to continue using the data, models, and sandbox
results after completing the sandbox: ………………………………………………………………………………………..
VIII. Implementation of civil liability insurance or equivalent
financial assurance measures
1.
Status:
□
Not subject to compulsory application;
□
Civil liability insurance has been implemented;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Not yet implemented, reason:
.......................................................................................................
2.
Name of the insurance provider/guaranteeing organization (if any):
............................................................
3.
Scope of insurance or guarantee:
....................................................................................
4.
Value of insurance or guarantee: ........................................................................................
5.
Effect:
..............................................................................................................
6.
Events that gave rise to claims for compensation, payment, or use of guarantee
measures (if any):
………………………………………………………………………………………...…………..
7.
Results of handling claims for compensation, payment, or use of guarantee
measures (if any):
………………………………………………………………………………………...…………..
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
No.
Mechanism prescribed in the
Written approval
Used or not
Use results/Issues encountered
Proposals after the sandbox
1
Mechanism
for supporting and adjusting compliance obligations within the scope of the
sandbox
□
Yes
□
No
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2
Program
for AI development
□
Yes
□
No
3
Recognition
of all or part of sandbox results for conformity evaluation
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
No
Where
shared computing infrastructure, shared datasets, training/testing platforms,
shared AI models, technical consulting services, or other support services were
used, specify the actual scope and extent of such use:
………………………………………………………………………...…………..
X. EVALUATION OF THE POSSIBILITY OF RECOGNIZING RESULTS, POST-SANDBOX
TRANSITION, AND PROPOSALS
1.
Conclusions on sandbox results:
□
Request for confirmation of completion of regulatory sandbox;
□
Request for confirmation of completion of a part of regulatory sandbox;
□
Request for extension of regulatory sandbox;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Request for termination of the sandbox;
□
Other requests
....................................................................................................
2.
Proposal for recognition of sandbox results for conformity evaluation (if any):
………………………………………………………………………………………...…………..
3.
Specific obligations proposed for exemption, reduction or adjustment (if any):
.............................
4.
Scope, duration of application, and basis derived from sandbox results for
proposals on exemption, reduction or adjustment of compliance obligations:
...............................................................................................
5.
Replaced or supplemented risk control measures:
............................................................
6.
Proposals on operation during transition period after the sandbox (if any)
including the duration, scope, requirements, limits, and supervision
mechanisms:
......................................................................................................
7.
Other proposals to competent authorities:
.................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
□
Technical reports or performance evaluation results;
□
Operation logs, incident logs, or documents extracted from the system;
□
Serious incident report;
□
Reports on exceeding the limits of sandbox;
□
Proofs of handling feedback and complaints;
□
Proofs of implementation of personal data protection;
□
Documents related to civil liability insurance or equivalent financial
guarantee measures;
□
Proofs of using support mechanisms within the scope of the sandbox;
□
Other documents: ...................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Reporting
organizations and individuals are not required to provide source code, detailed
algorithms, model parameter sets, raw training data, or information classified
as state secrets, business secrets, or technological secrets, unless otherwise
required by laws.
XII. COMMITMENTS OF REPORTING ENTITY
1.
[Name of individual] hereby commits that this Report and attached documents are
truthful and complete within the scope of the approved sandbox, and is
accountable to the laws for the accuracy of provided information.
2.
[Name of individual] hereby commits that the AI system in the sandbox has been
conducted within the scope, requirements, and limits prescribed in the Written
approval for participation in regulatory sandbox , except for any adjustments
that have been approved or acknowledged by competent authorities in accordance
with the laws.
3.
[Name of individual] hereby commits not to provide, commercialize, or expand
the deployment of the AI system beyond the scope, requirements and limits
prescribed in the Written approval for participation in regulatory sandbox,
unless approved by competent authorities.
4.
[Name of individual] hereby undertakes to continue storing applications, logs,
and documents related to the sandbox to serve inspection, supervision,
evaluation of sandbox results, and handling of arising issues in accordance
with the laws.
Recipient:
- As prescribed above
- .....................;
- Archive .....
REPORTING PERSON
(Signature and full name)
............................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI09a:
Written approval for participation
in regulatory sandbox on AI systems for organizations
[NAME OF ISSUING AUTHORITY]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
No. .../GXN-[CODE]
..............(place of
issuance), (date of issuance)
WRITTEN APPROVAL FOR PARTICIPATION
IN REGULATORY SANDBOX ON AI SYSTEMS
Pursuant to the Law on Artificial Intelligence No. 134/2025/QH15;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
At the request of [Name of organization],
[HEAD OF ISSUING AUTHORITY] HEREBY
CERTIFIES:
Article 1. Information about the participant
1.
Name of the organization: [Name of the organization]
2.
Tax identification number/enterprise code: [Tax identification
number/enterprise code]
3.
Address of headquarters:
..................................................................................................
4.
Full name of the legal representative:
..................................................................................
5.
Representative or conduit during the sandbox:
a)
Full name:
........................................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
c)
Phone number:
...................................................................................................................
d)
Email: ......................................................................................................................
Article 2. The sandbox AI system
1.
Name of the system: [Name of the system]
2.
System version:
............................................................................................................
3.
Identification code of AI system (if any):
.................................................................
4.
Descriptions on functions of the system:
.........................................................................
5.
Sandbox level: Level [X]
Article 3. Scope of sandbox
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
Geographical scope for deployment/deploying unit:
................................................................................................
3.
Sandbox field/scenario:
........................................................................................
4.
Confirmed sandbox objectives:
..............................................................................
Article 4. Sandbox limits
The
sandbox on AI system shall be performed in accordance with the following scope
and limits:
1.
Maximum number of directly affected individuals or organizations:
..........................................
2.
Maximum deployment scale of the AI system within the scope of the sandbox
including all modules, components, or system versions deployed during the
sandbox (if any):
..............................................................................................................................................
3.
Maximum value at risk:
..............................................................................................
4.
Technical, operational limits, or other requirements (if any):
...................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Article 5. Technical requirements and risk management
The
participant shall comply with risk management requirements in accordance with
this Decree including:
1.
Establishing human oversight and intervention mechanisms for the AI system
during the sandbox: [ ]
2.
Establishing an emergency stop mechanism for the system in the event of risks
or incidents:[ ]
3.
Archiving system logs and implementing reporting regime in accordance with the
laws: [ ]
4.
Implementing civil liability insurance or equivalent financial guarantee
measures in cases where they are required as prescribed by laws: [ ]
5.
Other technical requirements and risk management (if any): [ ]
Article 6. Interests and support
The
participant may be considered for the application of the following mechanisms
within the scope of the sandbox:
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
2.
May be considered for access to programs for support for AI development in accordance
with the laws: [ ]
3.
May be considered for full or partial recognition of sandbox results for
conformity evaluation in accordance with the laws: [ ]
4.
Other interests and supports (if any): [ ]
Article 7. Effect
1.
This Written approval takes effect from the date on which it is signed to the
end of .../.../...
2.
This Written approval is only valid for regulatory sandbox within the scope
prescribed in this document and shall not be construed as a license to provide
or commercialize the AI system in the market.
Recipient:
- As prescribed in Article 1;
- Archive. ....
HEAD OF THE ISSUING AUTHORITY
(Signature, full name, title and seal)
[Full name]
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Form AI09b:
Written approval for participation
in regulatory sandbox on AI systems for individuals
[NAME OF ISSUING AUTHORITY]
THE SOCIALIST REPUBLIC OF
VIETNAM
Independence - Freedom - Happiness
No. .../GXN-[CODE]
.............(place of
issuance), (date of issuance)
WRITTEN APPROVAL FOR PARTICIPATION
IN REGULATORY SANDBOX ON AI SYSTEMS
Pursuant to the Law on Artificial Intelligence No. 134/2025/QH15;
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
At the request of Mr./Mrs. [Name of the individual],
[HEAD OF ISSUING AUTHORITY] HEREBY
CERTIFIES:
Article 1. Information about the participant
1.
Full name of the individual: [Full name of the individual]
2.
Date of birth:
.......................................................................................................
3.
Personal identification number/Identification card number/Passport number:
...............................................
4.
Tax identification number (if any): ..............................................................................................
5.
Address:
.....................................................................................................................
6.
Phone number: ....................................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
Article 2. The sandbox AI system
1.
Name of the system: [Name of the system]
2.
System version:
...........................................................................................................
3.
Identification code of AI system (if any): .................................................................
4.
Descriptions on functions of the system:
............................................................................
5.
Sandbox level: Level [X]
Article 3. Scope of sandbox
1.
Duration of sandbox: From ..../.../.... to .../.../....
2.
Geographical scope for deployment/deploying unit:
...................................................................................................
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
4.
Confirmed sandbox objectives:
..................................................................................
Article 4. Sandbox limits
The
sandbox on AI system shall be performed in accordance with the following scope
and limits:
1.
Maximum number of directly affected individuals or organizations:
...................................
2.
Maximum deployment scale of the AI system within the scope of the sandbox
including all modules, components, or system versions deployed during the
sandbox (if any):
..........................................................................................................................................
3.
Maximum value at risk:
.....................................................................................
4.
Technical, operational limits, or other requirements (if any):
...........................................
The
participant is responsible for ensuring that the deployment of the AI system
does not exceed the scope and sandbox limits prescribed in this Article, except
where adjustments have been approved by competent authorities.
Article 5. Technical requirements and risk management
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
1.
Establishing human oversight and intervention mechanisms for the AI system
during the sandbox: [ ]
2.
Establishing an emergency stop mechanism for the system in the event of risks
or incidents:[ ]
3.
Archiving system logs and reporting regime in accordance with the laws: [ ]
4.
Implementing civil liability insurance or equivalent financial guarantee
measures in cases where they are required as prescribed by laws: [ ]
5.
Other technical requirements and risk management (if any): [ ]
Article 6. Interests and support
The
participant may be considered for the application of the following mechanisms
within the scope of the sandbox:
1.
May be considered for the application of support mechanisms and adjustments to
compliance obligations within the scope of the sandbox in accordance with the
laws: [ ]
2.
May be considered for access to programs for support for AI development in
accordance with the laws: [ ]
...
...
...
Please sign up or sign in to your Pro Membership to see English documents.
4.
Other interests and supports (if any): [ ]
Article 7. Effect
1.
This Written approval takes effect from the date on which it is signed to the
end of .../.../...
2.
This Written approval is only valid for regulatory sandbox within the scope
prescribed in this document and shall not be construed as a license to provide
or commercialize the AI system in the market.
Recipient:
- As prescribed in Article 1;
- Archive. ...
HEAD OF THE ISSUING AUTHORITY
(Signature, full name, title and seal)
[Full name]