
EU AI Act (Quy định về Trí tuệ nhân tạo của Liên minh Châu Âu) chính thức có hiệu lực từ ngày 1 tháng 8 năm 2024, trở thành khung pháp lý toàn diện đầu tiên trên thế giới quản trị AI. Với tiếp cận dựa trên rủi ro (risk-based approach), Act phân loại hệ thống AI thành 4 mức độ: unacceptable risk (cấm), high risk (quản trị chặt chẽ), limited risk (minh bạch), và minimal risk (tự quy ước). Đối với developer, startup và doanh nghiệp Việt Nam xuất khẩu phần mềm/solution AI sang thị trường EU, tuân thủ không còn là lựa chọn — là yêu cầu bắt buộc.
Tóm tắt EU AI Act: 4 mức rủi ro và nghĩa vụ tương ứng
| Mức rủi ro | Ví dụ | Nghĩa vụ chính | Hạn chế tuân thủ |
|---|---|---|---|
| Unacceptable (Cấm) | Social scoring, real-time biometric identification ở công cộng, manipulative AI, exploitation vulnerable groups | Cấm hoàn toàn phát triển, triển khai, sử dụng | 2/2/2025 (6 tháng sau effective) |
| High Risk (Cao) | AI trong y tế (chẩn đoán), HR (tuyển dụng), tài chính (credit scoring), giáo dục, cơ sở hạ tầng quan trọng, enforcement pháp luật, migration | Conformity assessment, QMS, risk management, data governance, technical documentation, human oversight, accuracy/robustness/cybersecurity, registration EU database | 2/8/2026 (24 tháng) — hệ thống sẵn có; 2/8/2027 cho sản phẩm mới |
| Limited Risk (Hạn chế) | Chatbot, deepfake generator, emotion recognition, AI content recommendation | Transparency obligation: thông báo user đang tương tác AI, watermark AI-generated content | 2/8/2026 |
| Minimal Risk (Tối thiểu) | Spam filter, game AI, recommendation system (non-high-risk) | Tự quy ước (voluntary codes of conduct) | Không bắt buộc |

General-Purpose AI (GPAI) Models — Quy định riêng cho Foundation Model
GPAI (như GPT-4, Llama 3, Claude, Qwen) có quy định riêng theo tỷ lệ compute training:
- GPAI thông thường: Technical documentation, training data summary, copyright policy, downstream provider information.</
- GPAI với Systemic Risk (compute > 10^25 FLOPs — ví dụ GPT-4, Gemini Ultra): Thêm: model evaluation (red-teaming), risk assessment/mitigation, incident reporting, cybersecurity protection, energy consumption reporting.</
Lưu ý: Open-weight model (Llama 3, Qwen, Mistral) KHÔNG được miễn trừ — nếu deploy commercial hoặc fine-tune cho high-risk use case, provider vẫn chịu trách nhiệm. Chỉ miễn trừ khi release dưới license open-source VÀ không commercial intent.
Những gì Developer Việt Nam cần làm NGAY
1. Inventory & Classification (Sổ sách & Phân loại)
- Liệt kê tất cả model/component AI trong product (first-party + third-party API).
- Map từng component vào 4 mức rủi ro. Câu hỏi then chốt: “Hệ thống này có ảnh hưởng đến quyết định quan trọng về con người (việc làm, tiền bạc, sức khỏe, an ninh)?” → Nếu yes → High Risk.
- Đặc biệt chú ý: AI dùng trong HR tech (screening CV), fintech (credit scoring), healthtech (triage), edtech (grading) — gần như tất cả đều High Risk.</
2. Data Governance & Documentation (Quản trị dữ liệu & Tài liệu hóa)
- Training/validation/testing data: provenance, representativeness, bias assessment, data sheet (theo chuẩn GPAI).
- Technical documentation: architecture, design spec, algorithm logic, intended use, limitations, accuracy metrics (theo Annex IV).
- Risk management system: ISO 14971 style — identify, evaluate, mitigate risk suốt vòng đời.</
- Quality Management System (QMS): ISO 9001 / ISO 13485 aligned — document control, change management, post-market surveillance.</
3. Human Oversight & Accuracy (Giám sát người & Độ chính xác)
- Thiết kế “human-in-the-loop” (HITL) hoặc “human-on-the-loop” (HOTL) cho high-risk: override capability, explainability, audit trail.</
- Metrics: accuracy, precision, recall, F1, fairness (demographic parity, equalized odds), robustness (adversarial testing), cybersecurity (penetration test).
- Logging: automatic recording của input, output, decision, confidence score — lưu tối thiểu 10 năm cho high-risk.
4. Conformity Assessment & CE Marking (Đánh giá sự tuân thủ & Dấu CE)
- High-risk AI system: self-assessment (internal control) HOẶC third-party notified body (nếu dùng harmonized standard hoặc biometric/critical infrastructure).
- Kết quả: EU Declaration of Conformity + CE marking + đăng ký vào EU Database (Article 71).
- Post-market surveillance plan: monitor incident, field safety corrective action, periodic safety update report.
5. Vendor & Supply Chain Management (Quản lý nhà cung cấp & Chuỗi cung ứng)
- Nếu dùng third-party API (OpenAI, Anthropic, Google, Microsoft Azure AI): cần Data Processing Agreement (DPA), Standard Contractual Clauses (SCC), đảm bảo vendor hỗ trợ compliance obligations của bạn (data access, model card, incident notification).
- Open-weight model self-host: bạn là “provider” theo Act — chịu toàn bộ nghĩa vụ high-risk/GPAI.
- Contract clauses: indemnification, liability cap, audit right, termination for non-compliance.

Timeline quan trọng cần nhớ
- 1/8/2024: Act effective (có hiệu lực pháp lý).
- 2/2/2025: Cấm unacceptable risk AI systems.
- 2/8/2025: GPAI obligations áp dụng (12 tháng).
- 2/8/2026: High-risk AI systems (Annex III) + Limited risk transparency — DEADLINE CHÍNH cho hầu hết startup.
- 2/8/2027: High-risk AI systems là safety component của sản phẩm regulated (medical devices, machinery, toys, etc.).
- 2/8/2030: High-risk AI systems được dùng bởi public authorities (legacy).
Phạt vi phạm: Đừng chủ quan
| Vi phạm | Mức phạt tối đa |
|---|---|
| Unacceptable risk AI (cấm nhưng vẫn triển khai) | 35 triệu EUR hoặc 7% global annual turnover (cao hơn) |
| High-risk obligations (Article 8-15) | 15 triệu EUR hoặc 3% turnover |
| GPAI obligations (Article 52-53) | 15 triệu EUR hoặc 3% turnover |
| Transparency obligations (Article 50) | 7.5 triệu EUR hoặc 1.5% turnover |
| Cung cấp thông tin sai lệch cho notified body/authority | 7.5 triệu EUR hoặc 1% turnover |
Cơ hội cho Startup Việt Nam
- Compliance-as-a-Service: Xây dựng tool/framework giúp client EU tuân thủ AI Act (risk assessment automation, documentation generator, conformity assessment prep).
- Audit & Red-teaming: Cung cấp dịch vụ evaluation cho GPAI systemic risk (red-teaming, penetration testing, bias audit).
- Privacy-preserving AI: Federation learning, differential privacy, synthetic data — align với cả AI Act và GDPR.</
- Explainability Tooling: SHAP, LIME, counterfactual explanation integrated vào MLOps pipeline.
Kết luận
EU AI Act không chỉ là rào cản — là tín hiệu chuyển biến: AI responsibility trở thành competitive advantage. Startup Việt Nam có 18-24 tháng (tính từ 8/2024) để ready cho deadline 8/2026. Bắt đầu từ inventory, classification, rồi từng bước build QMS, technical documentation, human oversight. Đừng đợi harmonized standard (CEN/CENELEC JTC 21) hoàn tất — bắt đầu implement best practice ngay (ISO/IEC 42001 AI Management System, NIST AI RMF). Tham khảo: EU AI Act Official Text, EU Commission AI Regulation, ISO/IEC 42001.
