On 9 February 2026, the Ministry of Science and Technology opened a consultation on Decree No. 2026/ND-CP implementing the Law on AI. Article 4 establishes a one-stop web portal managed by the Ministry to serve as the central point for receiving reports on serious incidents involving AI systems. A serious incident is defined in Article 22 as an event causing loss of life, serious harm to health, major property damage, significant rights infringements, or disruption to public services and national security. Suppliers and implementers must apply immediate technical measures to prevent serious incidents upon detection, retain all related logs and data, and submit incident reports through the AI portal. Preliminary reports are required within 24 hours for high-risk systems and within 72 hours for medium-risk systems. Detailed reports with causes and remedial measures must follow within 30 days if necessary. Competent state agencies receive and verify these reports and may suspend, withdraw, or re-evaluate systems when necessary. Cases affecting national security involve coordination with the Ministry of Public Security. Article 38 mandates that entities managing AI infrastructure and data apply measures to ensure data confidentiality, integrity, and availability, while also preventing cyber risks, data poisoning, and re-identification. Incident notification obligations under personal data protection and cyber security laws remain applicable, and data assurance requirements do not compel data disclosure unless otherwise legally required.
Original source