Vietnamese banks have used machine learning for years, to score credit, flag fraud and power chatbots. Until now there was no banking-specific rule on how far those systems could go on their own. Thông tư 53/2026/TT-NHNN fills that gap. It applies the general Luật Trí tuệ nhân tạo (Law on Artificial Intelligence, 134/2025/QH15) and the Prime Minister’s high-risk AI list (Quyết định 33/2026/QĐ-TTg) to the banking sector. It also turns several abstract principles into hard numbers. The headline change for customers is that an AI agent may now make payments for you, but only within an agreement you sign and a daily ceiling set by the regulator.
The document
- Number and title: Thông tư 53/2026/TT-NHNN, “Quy định về an toàn, quản lý rủi ro và điều kiện triển khai đối với việc ứng dụng hệ thống trí tuệ nhân tạo trong ngành Ngân hàng” (safety, risk management and deployment conditions for the use of AI systems in banking).
- Issued by: the Governor of the State Bank of Việt Nam (Ngân hàng Nhà nước Việt Nam). It was signed by Deputy Governor Phạm Tiến Dũng on the proposal of the State Bank’s IT Department (Cục Công nghệ thông tin).
- Signed: 30 September 2026.
- Effective: 15 November 2026, with phased dates for some articles (see below).
- Size: 5 chapters, 25 articles.
- Legal bases: the Law on the State Bank, the Law on Credit Institutions 32/2024/QH15, the AI Law 134/2025/QH15, its implementing decree Nghị định 142/2026/NĐ-CP, and Quyết định 33/2026/QĐ-TTg.
Who it covers
The circular applies to credit institutions and foreign bank branches, payment intermediaries, Mobile Money providers, credit information companies, the National Payment Corporation (NAPAS), the asset management company VAMC, the National Banknote Printing Plant and Deposit Insurance of Việt Nam. It covers AI that makes or supports decisions in customer-facing business. AI used only for internal administration is encouraged, not required, to follow the rules, and so is AI running inside a regulatory sandbox. A third-party AI tool that staff use as a personal assistant is outside the scope, as long as it is not integrated into a business process or information system. In practice, that means an employee using a public chatbot to draft an email.
What changes
1. Banking-specific “high-risk” thresholds (Điều 4). Every system must be classified as high, medium or low risk before deployment, using the national high-risk list. The circular adds banking criteria. An AI that executes payments automatically is high-risk if it handles any individual customer’s payment above 10 million đồng, or above 20 million đồng a day for one customer. For business customers the thresholds are 50 million per payment and 100 million a day. An AI that decides credit automatically is high-risk for any loan of 50 million đồng or more. Each unit must keep an inventory of its AI systems (name, risk level, purpose, vendor, version, approval document) and review it at least once a year.
2. AI agents may pay, under strict conditions (Điều 5). Before an AI can make payments on its own, the customer and the bank must sign an agreement. That agreement must set out its scope, per-payment and daily limits, its validity period and when payments are suspended. It must also give the customer the right to end it at any time, and the bank must act on that immediately. If the agreement is set up electronically, the customer’s identity must be checked with biometric matching plus one other authentication method under Thông tư 50/2024/TT-NHNN. The total the AI may spend for one customer in a day is capped at 100 million đồng for individuals and 500 million đồng for organisations, or less if the bank’s internal limit is lower. Customers must have a tool to pause or revoke the AI’s authority. Within an agreed scope, the AI’s payments are exempt from the per-transaction confirmation steps in Thông tư 50/2024. They also do not count towards that circular’s cumulative-value thresholds for stronger authentication. Banks must also be able to tell which payments a machine made and which a person made.
3. A human can always pull the plug (Điều 5, 9). Supervising staff must be able to override, adjust or suspend an AI decision. They must also be able to trigger an emergency stop that halts or isolates the system. Every override must be logged with what was done, when, by whom and why. After a serious incident, the bank must switch to manual operation where needed. It must report to the competent authority and to the State Bank’s IT Department, notify affected customers under the personal-data law, and re-assess the system’s risk level.
4. Security testing against named standards (Điều 6). Systems must be security-tested before go-live, periodically and after major changes. The tests must cover privacy attacks, data and model poisoning, evasion and model extraction for high-risk systems, and prompt injection and hallucination for generative AI. High-risk systems, and medium-risk systems that make decisions, must apply the OWASP Machine Learning Security Top Ten and the OWASP Top 10 for LLM Applications, or an equivalent standard. They must use the latest version or one issued within the previous six months.
5. Transparency to customers (Điều 20). When an AI replaces a human in talking to customers, the bank must say so at the start of the session or conversation. If an automated decision affects a customer’s legal liability, financial obligations or access to a product, the bank must keep the main reasons and explain them on request. It does not have to reveal source code, parameters or trade secrets. For anti-fraud and anti-money-laundering decisions, a short reason is enough. Complaints about automated decisions must be reviewed by a human, and the human’s finding is final.
6. Vendors and the supply chain (Điều 18, 19). Outsourcing does not move responsibility away from the bank. AI vendors must provide an independent IT audit report or a current certificate such as SOC 2, ISO/IEC 27001 or ISO/IEC 42001. They must give the bank logs or APIs to monitor model performance and warn it of model updates. They also may not use the bank’s data to train or fine-tune their models without written consent. Banks must keep an inventory of AI components, much like a software bill of materials (libraries, models, training datasets, versions, licences and integrity hashes), and check open-source models and libraries for malicious code.
7. Governance. The board approves AI strategy and, for high-risk systems, the decision to go live. Operations must be reported to the board at least every 6 months for high- and medium-risk systems. High-risk systems need a documented impact assessment covering fairness, explainability and discrimination. Banks must also pay attention to vulnerable groups such as children, the elderly and people with disabilities.
Phased deadlines
| From | What applies |
|---|---|
| 15 Nov 2026 | Most of the circular, for new systems |
| 1 Jan 2027 | Điều 14: AI risk-management framework with three lines of defence |
| 1 Mar 2027 | Systems already in production must meet Chapters II–IV |
| 1 Sep 2027 | Điều 6(1)(b) OWASP-based controls; Điều 21 staffing and training requirements (units running high-risk AI are covered from 15 Nov 2026) |
Practical implications
- For customers: “let the app pay my bills” features become legal, but only with explicit consent, limits you can see and an off switch. If a machine rejects your loan, you can ask why and get a human to review it.
- For banks and fintechs: classify every customer-facing model now. Any auto-pay feature above 10 million đồng, or any automated credit decision at 50 million đồng or more, falls into the high-risk regime. That means board approval, an impact assessment, continuous monitoring and six-monthly reporting.
- For AI vendors: expect contract clauses on audit rights, SOC 2 or ISO 42001 evidence, log access, model-change notice and a ban on training with client data.
Open questions
- The thresholds are low. Many ordinary bill-payment or savings-sweep automations will be high-risk, which may slow product launches.
- The circular does not say how the exemption from transaction confirmation fits with banks’ own anti-fraud controls when an AI agent is compromised.
- Reports go both to “the competent state authority” under the AI Law and to the State Bank. Until the reporting channels are set up, banks may have to file twice.
Sources
- Văn bản Chính phủ: Thông tư 53/2026/TT-NHNN (metadata and signed PDF)
- Signed text (PDF), datafiles.chinhphu.vn
- VietnamPlus: Ngân hàng Nhà nước đặt nhiều yêu cầu khi ngân hàng ứng dụng AI
- Dân trí: Giao dịch ngân hàng tự động bằng AI: Nếu có sự cố, trách nhiệm thuộc về ai?
- CafeF: Quy định về an toàn, quản lý rủi ro đối với việc ứng dụng AI trong ngân hàng
This post is general information, not legal advice.