Applying AI in business: The legal trap under cyber security Law 116
- Thanh Hoang

- May 19
- 4 min read
The era of Artificial Intelligence (AI) is redefining how B2B enterprises operate. However, alongside this boom comes a wave of unpredictable legal pitfalls. With the introduction of the Cyber Security Law No. 116/2025/QH15 (effective from July 1, 2026) and tightened regulations on controlling distorted content, deepfakes, and digital sovereignty violations, a fine line has inadvertently been drawn between "technological breakthrough" and "legal violation." The ultimate question remains: "How can businesses implement AI without driving themselves into legal jeopardy and cybersecurity crises?"
AI copyright: who owns the intellectual property when machines learn on their own?
Risks from "Junk Data" and Derivative Copyright Infringement
If B2B enterprises commercialize AI-generated products trained on scraped or unverified data, they face an immense risk of cross-border copyright litigation.
Complete Loss of Intellectual Property Rights
Under current Vietnamese and international legal frameworks, copyright is strictly protected only for products directly created by human authors. If your enterprise's product is generated 100% by AI, competitors can legally replicate it without facing lawsuits, as the product does not qualify for copyright protection.
Flashpoint cyber security Law 116: when AI crosses the safety threshold
While copyright issues result in financial damage, violating Cyber Security Law No. 116/2025/QH15 can expose B2B enterprises to severe administrative penalties, operational suspension, or even criminal prosecution.
B2B enterprises frequently fall victim to three major risks:
Confidential Data Leakage via Prompts: When employees paste customer data, unreleased financial reports, or proprietary software source code into public AI tools (such as ChatGPT or Claude) for optimization, that data is instantly stored on external cloud servers. This constitutes a severe violation of information security and core backbone system safety under Law 116.
Weaponized Deepfakes and Impersonation: Inadvertently using AI to generate unauthorized images, voices, or videos for marketing and communication purposes will be classified as online information manipulation and impersonation under Law 116.
Joint and Several Liability of IT Providers: For B2B firms specializing in software outsourcing or tech solutions, if the product delivered to a partner contains security vulnerabilities caused by AI-generated code (which often hides latent security bugs), your business must bear direct liability for compensation and legal penalties.

Strict fines and penalties under the draft decree
The draft decree regulating administrative sanctions in cybersecurity and personal data protection establishes a distinct penalty framework for the cybersecurity sector. According to Article 6, Clause 3 of the draft decree:
Maximum monetary fines: Up to VND 100 million for individuals and VND 200 million for organizations (with organizational fines being double those of individuals per Article 6, Clause 1).
Beyond monetary fines, Article 4 of the draft decree outlines supplementary penalties:
Revocation of licenses for cybersecurity products and services for 1 to 3 months.
Suspension of operations for 1 to 3 months.
Confiscation of exhibits, vehicles, and digital accounts used to commit violations.
Deportation for violating foreign nationals.
Remedial measures include forced deletion of violating information, mandatory public apologies in mass media, and revocation of domain names.
Compliance roadmap for B2B enterprises
To protect organizations ahead of the 2026 legal tightening, executives must proactively transition from a "reactive" posture to "active compliance" through three core steps:
Step | Core Activity | Objective |
1. Establish an AI Policy | Issue clear internal regulations on which AI tools are permitted and what data can be inputted. | Prevent data leaks at the root cause (human element). |
2. Source Code Auditing | Utilize specialized scanning tools to check for copyright issues and security vulnerabilities in AI-assisted products. | Ensure "clean" products before delivering them to B2B partners. |
3. Deploy DLP (Data Loss Prevention) | Implement technical solutions to automatically block employees from sending sensitive data to external AI platforms. | Ensure absolute compliance with Cyber Security Law 116 and Decree 356. |
Conclusion: turning legal compliance into a competitive advantage
In B2B business, trust is the most valuable asset. An enterprise that proves its systems strictly comply with Cyber Security Law 116, robustly protects data under Decree 356, and maintains transparency in AI copyright will always be the top choice for large corporations and international partners.
Why choose solutions from IPSIP Vietnam?
Originating with a rich heritage of over 15 years of experience from France, the IPSIP Vietnam ecosystem is positioned as a leading strategic partner that deeply understands every pain point of risk management and business operations.

IPSIP Vietnam's management and monitoring systems have successfully passed the most rigorous audits to achieve international information security certifications: ISO 27001:2022 and SOC 2 Type II.
By providing round-the-clock, 24/7 core services including our Security Operations Center (SOC), Network Operations Center (NOC), and a dedicated IT Support/Helpdesk team, IPSIP commits to directly responding to and intercepting all intrusion attempts day or night. The companionship of top technical minds will help your business completely untangle legal risks and free up resources for growth objectives.
------------------------------------------------------
References:











Comments