South-east Asia now enforces a mix of voluntary AI governance frameworks and mandatory AI regulations that include penalties for violations, reflecting a growing regional focus on AI oversight [1, 2]. Mandatory rules cover existing data protection laws, newly enacted AI regulations, and sector-specific requirements across industries [1, 2].
The European Union established the EU AI Act (Regulation 2024/1689) in 2024, introducing binding requirements and penalties for AI applications within its jurisdiction [1, 2]. Vietnam followed suit in 2025 by passing Law 134/2025, its standalone AI regulatory framework and the first of its kind in the region [1, 2]. Both legal frameworks classify AI systems using risk-based categories, applying to domestic and foreign entities involved with AI outputs in their territories [1, 2].
Prohibited AI practices under these regulations include social scoring and real-time biometric identification in public spaces [1, 2]. High-risk AI uses subject to stricter controls encompass hiring processes, credit scoring, healthcare delivery, educational tools, and essential public services [1, 2].
The EU AI Act imposes significant fines, with penalties up to 35 million euros or 7% of a company’s worldwide turnover for prohibited AI uses and up to 15 million euros or 3% for high-risk AI non-compliance [1, 2]. The law extends extraterritorially, targeting providers outside the EU if their AI outputs are used within EU borders [1, 2].
Vietnam’s Law 134/2025 marks a regional milestone as the first comprehensive standalone AI legislation, complementing existing data protection and sectoral rules [1, 2]. Enforcement details and compliance requirements under Vietnam’s law are evolving.
Regulators in South-east Asia continue to build on these frameworks, balancing voluntary guidelines with mandatory rules and penalties to govern rapidly developing AI technologies effectively [1, 2].