Risk begins where intelligence becomes action
An AI model can analyse information, recognise patterns and recommend a course of action. The commercial risk changes when that recommendation can move money, operate machinery, affect healthcare or control infrastructure.
On 15 August 2026, a new Vietnamese decision identifying high-risk AI systems entered into effect. Its significance extends beyond one jurisdiction. The categories include automated banking transactions, credit decisions, robotic surgery, autonomous vehicles and the control of critical transport infrastructure.
These systems have something important in common: their outputs can create real consequences. The regulatory statements in this perspective are derived from official Vietnamese-language sources; no authoritative English translation was located.
Capability is not authority
The decision states that using AI must not alter, transfer or remove the authority and responsibility held by competent organisations and individuals. It also requires human supervision, control and the ability to intervene during operation.
Giving an AI system access to a payment service does not necessarily give it authority to make every payment. Connecting an AI system to a vehicle does not mean every proposed movement should become effective. A recommendation to alter a software stack is not automatically permission to deploy the change.
The relevant question is not simply what the AI can do. It is what the AI is authorised to do in this particular context.
Intervention needs an operational mechanism
Human oversight is often described as a principle. Consequential systems need it to become an operating capability.
An organisation must be able to determine when an action can proceed, when it should be constrained, when additional authority is required and when operation must stop.
PF Kernel expresses that boundary through five possible outcomes. It does not make the underlying probabilistic AI deterministic. It provides a separate decision boundary governing whether a proposed action may become effective.
- Allow
- Deny
- Modify
- Step Up
- Stop the Line
Evidence must remain after the action
Intervention alone is insufficient if nobody can reconstruct what happened. A governed system should preserve enough linked evidence to examine what was requested, what governed context was available, which authority applied, what decision was returned and what action ultimately became effective.
PF Systems separates these responsibilities deliberately. PF Memory knows. PF Core proves. PF Kernel decides.
This separation is relevant across finance, robotics, autonomous transport, software agents and other environments where AI outputs can create material consequences.
Governed AI can go further
The purpose of governance should not be to prevent useful AI from operating. It should establish the boundaries that allow organisations to use increasingly capable systems responsibly.
A controlled shadow pilot provides a practical starting point. Proposed actions can be observed, governed and examined without permitting live actuation. Production use remains a separate decision.
As AI acquires more capable arms, tools and system access, the last mile of agentic computing becomes increasingly important. The question is no longer only whether AI can act. It is whether the organisation can control, intervene in and prove the authority behind that action.
PF Systems does not claim that its software provides compliance with Vietnamese law, guarantees safety or establishes production readiness.
Sources
Public sources supporting the factual statements in this perspective. Reported statements and company or vendor-reported results are identified in the article.
