Generative AI is unlocking numerous new ways for businesses to produce images, videos, and audio. With just a few tools, enterprises can generate advertising visuals, product introduction videos, voiceovers, or virtual avatars in a short time. However, as AI becomes increasingly realistic in simulating the likeness and voice of real people, businesses must also pay close attention to personal data, individual rights, transparency, and legal liabilities. What should businesses keep in mind when utilizing AI images and AI voices in the context of Vietnam’s new legal regulations on AI?
Are AI Images and AI Voices Always a Legal Violation?
First, it is essential to distinguish between creating content using AI and using AI to simulate a specific individual. An image entirely generated by AI from text prompts without simulating any real person is fundamentally different from a business using the likeness of an employee, customer, or specific individual to generate new imagery.
Similarly, a business can utilize synthetic AI voiceovers that do not mimic a specific person. However, if AI is used to clone or imitate the voice of a real person, the business must carefully examine the underlying data, the intended purpose, and how the content will be distributed.
Therefore, the core issue is not simply whether AI is being used, but rather how the business is using AI, who owns the data, and what impact the resulting content might create.

What Does the 2025 Law on Artificial Intelligence Regulate?
The Law on Artificial Intelligence No. 134/2025/QH15 was passed by the National Assembly on December 10, 2025, and officially takes effect on March 1, 2026. The Law establishes a legal framework for research, development, provision, and deployment of AI systems in Vietnam. (vanban.chinhphu.vn)
A notable aspect directly concerning AI images and voices is the legal control over elements of forgery or the simulation of real people and events. The Law strictly prohibits the use of these elements via AI to intentionally and systematically deceive or manipulate human perception and behavior, causing severe harm to legitimate rights and interests. The creation or dissemination of fabricated content capable of seriously endangering national security, public order, and social safety is also strictly prohibited. (xaydungchinhsach.chinhphu.vn)
Consequently, businesses must evaluate the intended use case before generating content that simulates real people, especially if that content could lead viewers to believe the individual actually made a statement or carried out an action.
Using Likeness and Voice of Real People: Personal Data Considerations
Another critical aspect lies in input data. Images, voices, or any information capable of identifying an individual may constitute personal data. Businesses must therefore identify what data they are processing, who owns that data, and the legal basis authorizing its processing.
The Law on Personal Data Protection No. 91/2025/QH15, effective January 1, 2026, governs personal data processing activities and the responsibilities of relevant parties. (vanban.chinhphu.vn)
For example, if a business intends to use an employee’s likeness or voice to produce an AI training video, it should not assume that it has blanket authorization to use that data for all purposes. The purpose, scope, and specific processing methods must be properly evaluated.
In particular, businesses should refrain from inputting unnecessary personal data into AI tools. The technical capability of a tool to process data does not imply that an enterprise has the legal right to use that data at its discretion.

AI Voice and the Risk of Identity Impersonation
Voice is an exceptionally sensitive element given AI’s growing capability for accurate replication. An AI-generated audio clip can lead listeners to believe an executive, employee, or partner has genuinely made a specific request or statement.
The Law on Cybersecurity No. 116/2025/QH15, effective July 1, 2026, has updated provisions regarding AI and emerging technologies. According to information from the Government Portal, the Law strictly prohibits using AI or emerging technologies to unlawfully forge another person’s video, image, or voice. (xaydungchinhsach.chinhphu.vn)
This is a critical consideration for businesses when developing marketing, training, or communications content that utilizes real human voices. Any simulation must be evaluated in terms of its purpose, the input data used, and the potential for misunderstanding.
How Should Businesses Govern AI Images and Voices?
Businesses should establish a controlled AI deployment process, beginning with input data. Prior to using an individual’s image or voice, the data source, purpose, and scope of use must be defined. If the content is created for advertising or public distribution, relevant rights and obligations must be reviewed more thoroughly.
After AI generates the content, human review is required before publication. The output must be assessed for accuracy, potential for misunderstanding, and the lawful use of third-party data. This also aligns with the principle in the Law on Artificial Intelligence regarding the guarantee of human oversight, intervention, and control over AI systems. (xaydungchinhsach.chinhphu.vn)
Furthermore, businesses should clearly define what data is permitted for input into AI tools, what content mandates review, and who is accountable for final sign-off. This forms the operational foundation for leveraging AI effectively while mitigating risk.
Instead of asking “should we use AI images and voices?”, businesses should assess three key questions: Who owns this data? For what purpose is it being used? Could the resulting content mislead others or infringe upon anyone’s legitimate rights and interests? By addressing these questions prior to deployment, enterprises can harness AI more effectively while proactively managing risks.
AI generates sustainable value only when deployed alongside appropriate personnel, data governance, and operational processes. BPO.MP partners with businesses in training and practical AI adoption, empowering teams to understand the technology correctly, identify potential risks, and systematically implement AI into operations effectively and safely.
BPO.MP COMPANY LIMITED
– Da Nang: No. 252, 30/4 St., Hoa Cuong Ward, Da Nang city
– Hanoi: 10th floor, SUDICO building, Me Tri St., Tu Liem Ward, Hanoi
– Ho Chi Minh City: 36-38A Tran Van Du St., Tan Binh Ward, Ho Chi Minh City
– Hotline: 0931 939 453
– Email: info@mpbpo.com.vn