AI regulation is entering a new phase. The conversation is moving beyond the broad question of whether artificial intelligence should be regulated and toward a more practical question: what happens when we classify AI systems according to the risk they create?
On August 15, 2026, Vietnam's new framework establishing an official list of high-risk artificial intelligence systems took effect. The framework identifies AI applications in areas including education, healthcare, banking, transportation, judicial functions, and other areas where AI can have significant consequences for individuals, organizations, public interests, national security, or social safety.
That development deserves more attention than it has received, not because Vietnam is suddenly becoming the center of global AI regulation, but because it illustrates a broader direction that multinational enterprises should be watching closely.
AI Is Becoming a Risk Classification Problem
For years, organizations have approached AI governance by asking relatively broad questions: Do we use AI? Which AI tools are employees using? What data is being sent to AI systems? Do we have an AI policy?
A more mature governance model asks different questions entirely:
- What does this particular AI system do?
- Who can it affect?
- How much autonomy does it have?
- What happens if it makes a mistake?
- What jurisdiction does it operate in?
- What level of human oversight is appropriate?
Those questions lead naturally toward risk classification. Vietnam's new framework is an example of that transition.
Context Matters More Than the Label "AI"
Consider two AI systems. One might summarize internal meeting notes. Another might evaluate students, influence a medical decision, assess financial risk, or support a judicial process.
Both are AI. Their potential consequences are very different. Treating them as equivalent simply because they use artificial intelligence makes little sense from a governance perspective. This is why risk-based classification is becoming so important: the technology itself isn't necessarily the risk.
Vietnam Is One Piece of a Larger Global Movement
Vietnam's approach is particularly interesting because it adds another jurisdiction to a growing global patchwork of AI governance. The European Union has taken a risk-based approach through the EU AI Act. The United States continues to develop AI governance through a combination of federal agencies, standards organizations, executive policy, state laws, and sector-specific requirements. Other countries are developing their own frameworks.
The result is a complicated environment for multinational organizations. An AI system that is acceptable in one market may require additional controls, documentation, transparency, oversight, or classification in another. That means AI governance can no longer be designed entirely around the technology. It increasingly needs to be designed around technology plus use case plus jurisdiction plus risk.
The Procurement Question
AI governance begins before deployment. If a business purchases an AI-enabled product from a third-party vendor, the organization may still be responsible for understanding how that technology is being used and what risks it creates. That means procurement teams, legal teams, security teams, technology teams, compliance teams, and business owners increasingly need to participate in AI governance.
The question shouldn't simply be "does this vendor offer AI?" It should be: what does the AI do, what decisions does it influence, what data does it use, where does it operate, and what controls exist around it?
The Global Enterprise Challenge
The difficult part for multinational organizations is that AI regulation isn't developing as one universal system. It is developing as a collection of frameworks, which creates the potential for regulatory fragmentation.
Organizations may eventually need to maintain a common enterprise AI governance framework while mapping individual AI systems against the requirements of the jurisdictions in which they operate. That could look something like: Identify → Inventory → Classify → Assess → Control → Monitor → Reassess.
The important word is reassess. AI systems change. Models change. Vendors change. Data changes. Use cases expand. Regulations change. A system that was low-risk when it was introduced can become substantially more consequential when an organization gives it access to new data, additional autonomy, or a new business process. AI governance therefore cannot be a one-time approval exercise. It needs to become an operating capability.
What Enterprise Leaders Should Be Asking
Organizations preparing for this next phase should consider five questions:
1. Do we actually know where AI is being used?
Shadow AI can make an enterprise AI inventory incomplete almost immediately.
2. Can we classify our AI systems by risk and business impact?
Not every AI deployment deserves the same level of governance.
3. Can we identify the jurisdictions that apply to each system?
Geography increasingly matters.
4. Do we know who owns the risk?
AI governance cannot succeed if responsibility disappears between IT, security, legal, procurement, and the business.
5. Can we continuously monitor the systems after deployment?
Governance that stops at procurement or implementation isn't enough.
The Bigger Signal
Vietnam's new high-risk AI classification framework is important not because every enterprise will immediately need to comply with Vietnamese requirements. It is important because it reinforces a broader global trend: AI governance is becoming contextual.
The future isn't likely to be a world where every AI system receives identical treatment. Instead, organizations will increasingly need to understand the specific risks created by specific AI systems operating in specific environments. That is a much more sophisticated approach to technology governance, and it creates an opportunity for enterprises to get ahead of regulation rather than constantly reacting to it.
At North Velocity Group, we believe the organizations that will navigate this environment most effectively will be those that treat AI governance as part of enterprise transformation, not as a separate compliance exercise. The question isn't simply "are we using AI?" The better question is: do we understand the risk of every AI system we put into operation, and do we have the governance to manage it?
Sources & Further Reading
- Vietnam Ministry of Science and Technology, Decision No. 33/2026/QĐ-TTg: List of High-Risk Artificial Intelligence Systems, effective August 15, 2026.
- European Commission, EU Artificial Intelligence Act: risk-based framework for artificial intelligence systems.
Disclosure: This article is an independent North Velocity Group analysis of publicly available regulatory and technology developments. It is not legal advice, and North Velocity Group is not affiliated with or endorsed by the government of Vietnam or the European Commission.