AI Assistant Online
DCOMPASS - Aim with Precision, Build with Trust
NEWS/RESEARCH

AI DATA CENTERS IN VIETNAM: ARE RISK CLASSIFICATION AND NOTIFICATION OF AI SYSTEMS REQUIRED?

The rapid development of artificial intelligence (“AI”) is driving increasing demand for high-performance data centers in Vietnam. In addition to traditional data centers, many projects are being developed under the AI Data Center model, incorporating GPU systems, high-performance computing capabilities, cloud computing platforms, and infrastructure serving the development, training, and deployment of AI models. This development raises an important legal question: Is an AI Data Center required to carry out procedures for classifying or registering an AI system in Vietnam? The answer depends primarily on the nature of the activities performed by the Data Center. The fact that a data center is used to operate AI systems does not mean that the entire data center itself becomes an “AI system” and is therefore automatically subject to the legal obligations applicable to AI systems.

AI DATA CENTERS IN VIETNAM: ARE RISK CLASSIFICATION AND NOTIFICATION OF AI SYSTEMS REQUIRED?
DCOMPASS Editorial•2026-09-28
NEWS/RESEARCH
AI DATA CENTERS IN VIETNAM: ARE RISK CLASSIFICATION AND NOTIFICATION OF AI SYSTEMS REQUIRED?

The rapid development of artificial intelligence (“AI”) is driving increasing demand for high-performance data centers in Vietnam. In addition to traditional data centers, many projects are being developed under the AI Data Center model, incorporating GPU systems, high-performance computing capabilities, cloud computing platforms, and infrastructure serving the development, training, and deployment of AI models.

This development raises an important legal question: Is an AI Data Center required to carry out procedures for classifying or registering an AI system in Vietnam?

The answer depends primarily on the nature of the activities performed by the Data Center. The fact that a data center is used to operate AI systems does not mean that the entire data center itself becomes an “AI system” and is therefore automatically subject to the legal obligations applicable to AI systems.

1. Legal framework for Artificial Intelligence in Vietnam

Vietnam has established a dedicated legal framework governing the development, provision, and use of artificial intelligence. Law on Artificial Intelligence No. 134/2025/QH15, effective from March 1, 2026, establishes the foundation for a risk-based AI governance framework, including regulations on AI system classification, risk management, conformity assessment, and the national database on AI systems. Subsequently, Decree No. 142/2026/ND-CP, effective from May 1, 2026, provides detailed regulations and guidance on the implementation of certain provisions of the Law on Artificial Intelligence. In addition, Decision No. 33/2026/QD-TTg, effective from August 15, 2026, provides the list of high-risk AI systems.

Article 6 of Decree No. 142/2026/ND-CP clearly assigns responsibility for AI system classification to the Provider. The Provider must carry out self-classification of the AI system in accordance with Clause 1, Article 10 of the 2025 Law on Artificial Intelligence before putting the system into use and shall be legally responsible for the accuracy and truthfulness of the classification results. Where the Deployer modifies, integrates, or changes the functions or purpose of use of the system compared with the Provider’s original declaration, resulting in new or higher risks, the Deployer is responsible for coordinating with the Provider to review and reclassify the risk level.

However, it should be noted that this classification requirement applies only to AI systems and does not apply to AI models, unless the model is used as a component of a specific AI system.

AI systems are classified into three risk levels. The risk level of an AI system is determined as follows:

  • High-risk AI systems: Systems included in the list of high-risk AI systems promulgated by the Prime Minister in accordance with Clause 4, Article 13 of the 2025 Law on Artificial Intelligence;

  • Medium-risk AI systems: Systems that do not fall into the above category but fall within the cases specified in Article 9 of Decree No. 142/2026/ND-CP;

  • Low-risk AI systems: Systems that do not fall within either of the two categories above.

In principle, the Provider is responsible for self-declaring and bearing legal responsibility for the contents of the notification. However, for AI systems classified as medium-risk or high-risk, the Provider must notify the Ministry of Science and Technology of the risk classification results through the AI Single-Door Electronic Portal before putting the system into use, in accordance with Article 14 of Decree No. 142/2026/ND-CP. Following the notification, the enterprise must retain the relevant records and update them where any changes affect the classification results.

The risk classification dossier must include these following documents:

(i) System identification information, including: The system name; version; internal identifier or identifier issued by a competent state authority; and the name, address, and contact information of the Provider;

(ii) Description of the system and its context of use: Purpose of use; principal functions; system architecture at the functional and business-operation levels; scope of deployment; user groups; and persons affected;

(iii) Data information: A general description of the primary types of input data used to operate the system;

(iv) Risk management information, including a summary of measures for risk management, system safety, and transparency.

2. Obligations of the AI Data Center Investor to Classify and Notify AI Systems

To apply the above regulations to a specific Data Center project, it is necessary to clearly distinguish Data Center infrastructure from the AI system deployed on such infrastructure. A Data Center is, by nature, technical infrastructure serving the placement, storage, connectivity, and processing of data. It may provide various services such as colocation, cloud, hosting, data storage, network connectivity, and other technical infrastructure services. An AI system, on the other hand, is a system with specific functions, purposes, and operating mechanisms involving the use of AI technology. Such a system may be deployed on servers, equipment, and computing resources located at a Data Center. Accordingly, the fact that a Data Center provides infrastructure for a customer to store data, deploy servers, or operate an AI system does not mean that the Data Center or its investor automatically becomes an AI system or the Provider of an AI system.

For example, an enterprise invests in and operates a Data Center in Vietnam and provides colocation services to a foreign technology group for the deployment of an AI system. In this case, the Data Center investor primarily provides physical infrastructure, such as equipment space, power supply, cooling systems, network connectivity, physical security, and related technical services. The technology group is the entity deploying and operating the AI system and independently determines its purpose of use, functions, input data, and operating methods. Accordingly, it is necessary to determine whether the technology group qualifies as the Provider of the AI system based on the parties’ actual roles. If the group develops and provides the AI system to users or the market, the risk-classification obligation, in principle, rests with the Provider. The Data Center investor is not automatically required to perform the classification merely because it provides infrastructure for such system.

If the Data Center operator also develops, provides, or directly operates an AI system for customers, for example, by providing an AI platform, an AI-powered data analytics system, or an AI service whose functions and purposes of use are controlled by the operator, the enterprise’s role under the AI legal framework should be reassessed. In such circumstances, the enterprise may become subject to obligations to classify the system, notify the classification results, and implement corresponding risk-management measures.

Accordingly, during the legal due diligence of a Data Center project involving AI, the following issues should be clarified:

  • Who develops and provides the AI system?

  • Does the Data Center investor merely provide infrastructure, or does it participate in the governance and operation of the AI system?

  • What data is stored and processed? Is it used solely for model-training purposes, or does it directly serve end users and consequently involve the collection of additional information from such users?

  • What is the system used for, and what risk level does it fall under?

  • Do any obligations arise regarding notification, record retention, or risk management under AI regulations?

Clearly defining the roles of each party from the project-design stage will help determine the appropriate scope of legal obligations, avoid conflating the provision of Data Center infrastructure with the provision or operation of an AI system, and mitigate compliance risks during project implementation.

Accordingly, for projects involving AI, legal assessment should not be limited to the requirements applicable to Data Center infrastructure. It is also necessary to determine whether the project involves the development, provision, or deployment of an AI system falling within the scope of AI regulations. In particular, a clear distinction should be made between AI systems and AI models, as risk-classification obligations generally apply to AI systems.

Incorrect classification may result in an inaccurate determination of notification, record-keeping, and risk-management obligations, thereby giving rise to legal and operational risks. Depending on the nature, severity, and consequences of the violation, an enterprise may be required to take remedial measures, make adjustments, or restrict the provision or use of the system, and may be subject to administrative sanctions or other liabilities under applicable law. Where an AI system causes damage to users, customers, or third parties, the enterprise may also face complaints, disputes, or claims for compensation.

In practice, determining the appropriate legal structure and allocating responsibilities among the AI Data Center investor, AI system Provider, and user of AI Data Center services requires simultaneous consideration of technological factors, the business model, and relevant legal regulations.

Recognizing this need, DCompass provides specialized legal and investment advisory services for Data Center and AI Data Center projects in Vietnam, supporting investors in assessing investment structures, reviewing the applicable legal framework, determining compliance obligations, and identifying legal risks from the project preparation and implementation stages.

DCOMPASS Intelligence Edition

Share & Reading Tools

AI Intelligence Assistant

Ask questions directly about this article

SPECIAL REPORT

Vietnam Data Center Market Report 2026

Complete analysis of PDP8 power grid, DPPA mechanism, and 25+ high-capacity sites.

Get Report & Advisory

Send us a Message

Directly connected to DCOMPASS Operations Center