The rapid development of generative artificial intelligence is changing how businesses produce images, videos, audio, and communication content. With just a few AI tools, users can generate highly realistic content, even simulating the face, voice, or actions of a real person. This brings numerous opportunities for enterprises, but also raises an increasingly important question: when can AI-generated fake content become a legal risk?
Using AI to create content does not automatically constitute a legal violation. Risks depend on the generated content, the data used, the intended purpose, and the impact of the content on individuals, organizations, or society. Starting in 2026, Vietnam has established more specific regulations regarding AI, deepfakes, and the use of technology to simulate real people or events.

What Is AI-Generated Fake Content?
AI-generated fake content can be understood as the use of AI technology to create or modify images, videos, audio, or text in a way that produces information not accurately reflecting reality. A common form is deepfakes, where AI is used to simulate the face, voice, or actions of a real person.
However, a distinction must be made between AI-generated content and AI content utilized for the purpose of forgery or deception. A business using AI to create illustrative images or a fictional character for a communications campaign does not inherently create violating content. Legal issues become prominent when AI content infringes upon the rights and legitimate interests of others or is used for purposes strictly prohibited by law.
This approach aligns with the Law on Artificial Intelligence No. 134/2025/QH15, passed by the National Assembly on December 10, 2025, and effective from March 1, 2026. The Law establishes a risk-based management principle for AI while specifying prohibited acts in AI activities.
When Does AI Content Become a Legal Risk?
A particularly notable case is the use of AI to forge or simulate real people or events for the purpose of deception or manipulation. The Law on Artificial Intelligence strictly prohibits using fraudulent elements or simulating real people and events to intentionally and systematically deceive or manipulate human perception and behavior, causing serious harm to legitimate rights and interests. The Law also strictly prohibits creating or disseminating fraudulent content capable of causing severe harm to national security, public order, and social safety.
Therefore, businesses should not merely ask, “Was this content created by AI?”, but need to examine deeper: What is the AI used for? Does the content simulate real people or events? And what impact could the use of that content have on others?

Data Used to Create AI Content Can Also Generate Risks
A common mistake is that businesses only inspect the final product while overlooking input data. In reality, images, videos, audio, or information capable of identifying an individual may relate to personal data and other legal rights.
The Law on Artificial Intelligence also stipulates that data must not be collected, processed, or used to develop, train, test, or operate AI systems in violation of laws concerning data, personal data protection, intellectual property, and cybersecurity.
This means businesses must pay attention to the entire AI utilization chain, from input data -> content creation process -> review -> publication and use. Content that appears legitimate at the final stage may still harbor issues if the initial data used was inappropriate.
How Should Businesses Control AI Content?
Businesses do not necessarily need to restrict AI usage. Instead, they need to establish controlled AI deployment workflows. Before creating content, it is necessary to define the purpose, data source, and scope of use. If the content features images, voices, or identifying information of real people, data usage rights must be specially verified.
After AI generates content, there should be a human review step before publication, especially for content related to customers, brands, leadership, or issues prone to misunderstanding. The Law on Artificial Intelligence also sets a human-centric principle and ensures mechanisms for human monitoring, intervention, and control over AI systems.
Businesses can start with a simple internal policy: defining what data is permitted for AI input, what content requires review, and who is responsible before content is published.
The Law on Artificial Intelligence 2025 and the Law on Cybersecurity 2025 demonstrate that Vietnam is gradually perfecting its legal framework to address new risks arising from AI and deepfakes. Therefore, the issue is not “whether to use AI or not,” but rather “how to use AI effectively, legally, and responsibly?”
AI only delivers sustainable value when accompanied by people, appropriate processes, and control mechanisms. BPO.MP partners with businesses in training and practical AI adoption, helping teams correctly understand the technology, identify risks, and systematically integrate AI into operations efficiently and safely.
BPO.MP COMPANY LIMITED
– Da Nang: No. 252, 30/4 St., Hoa Cuong Ward, Da Nang city
– Hanoi: 10th floor, SUDICO building, Me Tri St., Tu Liem Ward, Hanoi
– Ho Chi Minh City: 36-38A Tran Van Du St., Tan Binh Ward, Ho Chi Minh City
– Hotline: 0931 939 453
– Email: info@mpbpo.com.vn