The date being reported is 1 March, and for the labeling requirement it is wrong by about two months.
Vietnam’s Law on Artificial Intelligence did take effect on 1 March, and it is the first comprehensive statute of its kind in Southeast Asia, which is the part worth marking. But the obligation everybody has attached to that date, the requirement to label AI generated content, does not begin until May. Nobody in Vietnam is currently required to label anything.
The distinction matters more than a pedantic correction usually would, because the gap is where the difficult work sits, and because the received view of what that work involves is close to backward.
What everyone believes
The consensus position, across a remarkable range of people who agree on nothing else, is that labeling is the sensible first move. It is minimal. It does not ban anything, restrict any model, or pick winners. It leaves the technology alone and gives the public a piece of information.
On that reading, labeling is the easy rule you pass while the hard arguments about liability and deployment rumble on for another decade.
Which sounds right and is the opposite of the truth. Labeling is the hardest thing in this area to make work, and the reasons are technical rather than political.
The record: why a label is difficult
Start with what the statute actually asks for, because it is well drafted and the difficulty is not a drafting failure.
The scope is narrow and sensible: audio, images and video generated or modified by AI where the content imitates the appearance or voice of a real person, or recreates real events in a way that could be mistaken for authentic. That is the category that causes harm, and it is correct to target it rather than everything a model produces. The marking must be conspicuous, in a machine readable format, clear and displayed before or at the time a user encounters the content.
Now the three problems, in ascending order of severity.
The first is that the population being regulated is self selecting for compliance. An advertising agency generating a product image will label it, because it is a company with lawyers in a jurisdiction. Somebody manufacturing a video of a politician saying something they did not say will not, because labeling would defeat the entire purpose of the exercise. The rule binds exactly the people who were not the problem.
The second is that machine readable marks are fragile in a specific way. Provenance metadata embedded in a file survives as long as every piece of software touching that file preserves it. Take a screenshot of a labeled image and the screenshot is a new image with no metadata. Re-encode a video, crop it, pass it through a messaging app that strips metadata for privacy reasons, and the mark is gone. None of that requires intent. The ordinary life of a file online destroys the label as a matter of course, which means absence of a mark tells you nothing at all.
The third is the one that compounds the other two. Once labeling is widespread and expected, its absence starts to read as a certificate of authenticity. That is precisely the inference the system cannot support, and it makes the unlabelled forgery more credible than it was before the rule existed. A regime that is partially effective can leave the public worse informed than no regime, and this is the failure mode nobody plans for because it looks like success from the inside.
There is a fourth problem that is really a consequence of the first three. Any labeling regime has to decide what to do about content that is partly generated, and almost everything will be. A photograph taken on a phone has already been through computational processing before the owner sees it. A video with an AI upscale applied, or a voice cleaned up by a model, or a background removed, sits somewhere on a spectrum with no natural break in it. Vietnam’s answer, to limit the duty to content imitating real people or recreating real events, is about the best available line. It is still a line drawn across a continuum, and lines like that generate argument rather than clarity at the margin.
The exception that will do the work
There is a further wrinkle, and it is not a criticism of the drafters so much as a prediction about where the arguing will happen.
The law exempts imaginative works where audiences clearly understand the content is fictional. That is obviously right: nobody wants a label on an animated film.
It is also the boundary every contested case will be fought on. Satire is imaginative work. So is a dramatized reconstruction. So, according to whoever made it, is a video posted without context that a viewer might reasonably take as a record of something that happened. The question of whether an audience clearly understands is not a fact about the work; it is a fact about the audience, and it varies by viewer.
Which regulations are actually easier
Here is the reversal stated plainly. The rules that look more intrusive are considerably more enforceable, because they attach to entities rather than to artifacts.
A rule that a deployer of a system in a defined high risk setting must keep records, run an assessment and name a responsible person is enforceable, because there is a company, a filing and an auditor. A liability rule allocating responsibility for harm caused by a system is enforceable, because it operates in a courtroom after the fact where evidence can be compelled. A rule restricting a specific application is enforceable, because deployment is visible.
Labeling attaches to a file. Files are copied, re-encoded, screenshotted and stripped, by everybody, constantly, without anyone intending anything. That is why it is hard, and it is why it should be the last piece of the framework rather than the first.
If you are the one implementing it
For anyone with a product that will need to comply, in Vietnam now and very likely elsewhere later, the useful reading of the two month gap is that it is implementation time and it is short.
Three things are worth doing before May regardless of how the guidance lands. Work out which of your outputs fall inside the narrow scope, because the answer is probably fewer than the panic suggests and the exercise gives you a defensible position. Decide how the mark survives your own pipeline, since most products re-encode their own media at least once and a label your own system destroys is a compliance problem you built. And write down the reasoning for anything you conclude is exempt, at the time you conclude it, because the imaginative works exception will eventually be tested and a contemporaneous note is worth a great deal more than a reconstruction.
None of which will stop a single deepfake. That is a different problem, and the honest position is that this law does not solve it and was probably never going to.




