In short
Buying a Copilot or ChatGPT Business seat is not like buying an Office licence. This guide compares the commercial terms of Microsoft, OpenAI, Anthropic and Google on the three questions Vietnamese enterprises most often skip: who owns the output, whether your data trains the model, and what the copyright indemnity excludes. It also covers two new AI provisions in Law 131/2025/QH15, the AI disclosure duty under the Digital Technology Industry Law 71/2025/QH15, and the repeal of Decree 13/2023 effective 01/01/2026.
Quick answer
When a company buys a generative AI seat, what it buys is not a licence to a piece of software but access to a service, carrying three completely separate contractual promises: who owns the output, whether the data you type in is used to train the model, and whether the vendor will defend you if a third party claims that output infringes its copyright. None of those three come by default. They exist only in the commercial tier, and even there they arrive with long exclusion lists.
On output ownership, all four major vendors assign rights to the customer, and all four attach the same self-protecting qualifier. OpenAI states in its Services Agreement that it assigns all of OpenAI right, title, and interest, if any, in and to Output. The phrase "if any" is the important part. The vendor is not promising that the output is protected by copyright at all; it is only promising not to contest whatever rights it might itself hold.
Under Vietnamese law the question of who authored a passage written by AI already has an answer. Article 12a(1) of the Law on Intellectual Property provides that an author is the person who directly creates the work, and Article 12a(2) expressly excludes anyone who merely assists, comments or supplies materials. Law No. 131/2025/QH15 did not amend that article when it took effect on 01/4/2026 — but the same law added two entirely new AI provisions that very few businesses have read.
In practice the largest exposure is not in the contract at all; it is in the absence of one. IBM Cost of a Data Breach 2025 found that one in five organisations suffered a breach involving shadow AI, at an average of USD 670,000 in additional breach cost. When an employee pastes company data into a personal AI account, every protection the procurement team negotiated simply does not apply.
Dzo.software advises Vietnamese enterprises on inventorying, standardising and regularising software licences, including the layer of AI tools now spreading beyond the reach of the IT department. Genuine licences, electronic VAT invoices, payment in VND.
This article is provided for general information and is not legal advice. The specific contract a business signs always prevails over public policy pages, and every terms page cited here was retrieved on 03/08/2026 — AI vendors revise their terms very frequently.
The numbers that matter
The six data points below come from primary legal texts or first-party reports by the issuing organisation, each with a link so you can verify them yourself rather than take this article on trust.
- 79% of organisations reported regularly using generative AI in at least one business function, up from 71% in 2024. Survey of 1,993 respondents across 105 countries, fielded 25/06 to 29/07/2025 — AI Index Report 2026, Stanford HAI.
- Only 22% of American office workers rely exclusively on AI tools provided by their employer, while 80% use AI at work. IBM and Censuswide surveyed 3,000 North American office workers, published 03/11/2025 — IBM Think.
- USD 670,000 is the additional breach cost borne by organisations with high levels of shadow AI. Verbatim: "Organizations that used high levels of shadow AI observed an average of $670,000 in higher breach costs" — IBM Cost of a Data Breach 2025, based on 600 organisations studied by Ponemon Institute.
- 63% of breached organisations either had no AI governance policy or were still drafting one. Among those that had one, only 34% ran regular audits for unsanctioned AI — same IBM 2025 source.
- 01/01/2026 is the date the Digital Technology Industry Law No. 71/2025/QH15 took effect, bringing a duty to notify users that they are interacting with an AI system. On the same date the Personal Data Protection Law No. 91/2025/QH15 took effect and Decree 13/2023 ceased to have effect.
- VND 500,000,000 is the maximum administrative fine for an organisation in the field of copyright and related rights, under Article 5(1) of Decree 341/2025/ND-CP, effective 15/02/2026, replacing Decree 131/2013/ND-CP.
| Vendor | Output ownership | Customer data used for training? | Copyright indemnity for output |
|---|---|---|---|
| Microsoft 365 Copilot | No separate assignment clause in public documentation; governed by the Product Terms | No. "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs" | Yes — Customer Copyright Commitment, conditional on using the guardrails and content filters Microsoft builds in |
| OpenAI (API, ChatGPT Enterprise) | Yes. Customer owns all Output; OpenAI assigns its rights "if any" | No, unless the customer explicitly opts in. Applies to the API from 01/3/2023 | Yes for API and Enterprise. No clause found granting it expressly to ChatGPT Business |
| Anthropic Claude (commercial) | Yes. "Anthropic hereby assigns to Customer its right, title and interest (if any) in and to Outputs" | No. "Anthropic may not train models on Customer Content from Services" | Yes, for paid use, and it extends to the data Anthropic used to train the model |
| Google Workspace / Google Cloud | No separate assignment clause in the Service Specific Terms reviewed | No, absent the customer prior permission or instruction | Yes, in two distinct limbs: one for generated output, one for training data |
Who owns AI-generated output
The short answer: contractually the customer owns it, but what is being transferred may be an empty set of rights. This is where the marketing translation and the legal translation diverge most sharply, and it is the point Vietnamese businesses most often misread at signature.
Read the OpenAI clause closely. Services Agreement section 4.1, updated 01/12/2025 and effective 01/01/2026, states: "OpenAI hereby assigns to Customer all OpenAI's right, title, and interest, if any, in and to Output." Those two words "if any" are not lawyerly decoration. They concede that OpenAI itself is not certain it holds any rights in the output to assign. Anthropic uses the identical structure in its Commercial Terms effective 17/06/2025: "assigns to Customer its right, title and interest (if any) in and to Outputs".
Why hedge like that? Because the output of a language model is not automatically eligible for copyright protection. OpenAI itself writes in Services Agreement section 4.4 that "Due to the nature of OpenAI's Services and artificial intelligence generally, Output may not be unique, and other users may receive similar content from OpenAI's services." A passage that two different companies could each obtain from the same service is very hard to argue as the exclusive creative product of either one.
Place that beside Vietnamese law and the picture closes. Article 12a(1) of the Law on Intellectual Property defines an author as the person who directly creates the work, and Article 12a(2) states that a person who assists, comments on or supplies materials for a work created by another is not an author or co-author. An AI system is not a person and therefore cannot be an author. Exactly where the person writing the prompt sits between those two provisions is a question no Vietnamese case law has yet answered.
The practical consequence is not that businesses should avoid AI, but that they should reclassify the asset. AI-generated material is better treated as operational output than as intellectual property that can be licensed, valued or contributed as capital. Where a software product or a brand identity contains AI-generated parts, those parts need human intervention and an auditable record of that editing, so that the human contribution is the thing you can actually prove. The discipline is the same one required to separate your own source code from borrowed libraries when complying with open source licences.
One small but expensive detail: the assignment is not always complete. The OpenAI service terms carve voice output out of the assignment, and Beta services are supplied as-is and sit outside any indemnification obligation. A business that moves an experimental feature into production is discarding the protection it has paid for.

Vietnamese law: an author must be a person, and two new provisions few have read
The short answer: the definition of authorship did not change on 01/4/2026, but Law No. 131/2025/QH15 added two entirely new provisions that lay the groundwork for establishing rights in AI-assisted creations and for using published data to train AI systems. This is the most consequential legal development on this topic in two years, and it has had very little coverage.
First, dispose of a common misreading. Several news summaries claim Law 131/2025 changed the definition of an author. It did not. Reviewing the full list of more than seventy amended provisions in Article 1 of Law No. 131/2025/QH15, promulgated 10/12/2025 and effective 01/4/2026, Article 12a does not appear. The amendment sequence runs from Article 8, inserts Articles 8a, 11a and 11b, then jumps to Article 15. The principle that an AI cannot be an author stands untouched.
What the law did add is Article 6(5): the Government is to prescribe how intellectual property rights arise and are established where the subject matter was created using an artificial intelligence system. In other words, the National Assembly did not itself decide who owns AI-assisted creations; it delegated that to a Government decree. Businesses should track that implementing decree closely, because it will directly determine the legal standing of any content and code library bearing the fingerprints of AI.
The second provision matters even more to organisations building AI products. The new Article 7(5) permits organisations and individuals to use texts and data concerning intellectual property subject matter that has been lawfully published and is publicly accessible, for the purposes of scientific research, testing and training artificial intelligence systems, provided such use does not unreasonably prejudice the legitimate rights and interests of the author or rights holder. This is Vietnam first text and data mining exception, comparable in concept to the European provisions.
The exception carries three conditions that operate together, and all three are demanding. The data must have been lawfully published, the public must be permitted to access it, and the use must not unreasonably prejudice the rights holder. The same provision adds that where the texts and data are protected by copyright and related rights, the use must additionally follow Government regulations. So an organisation training a model on data scraped from the internet cannot treat Article 7(5) as a safe harbour yet.
Seen from the other direction, when your business is the party whose data is being harvested, this is the reason to revisit the terms of use on your website and document repositories. A document published openly without any access condition falls squarely within "lawfully published and publicly accessible".
And breaches at this layer are still handled under the existing administrative penalty regime. Article 5(1) of Decree 341/2025/ND-CP, effective 15/02/2026, sets the maximum fine in the field of copyright and related rights at VND 250 million for an individual and VND 500 million for an organisation, with the rule that an organisation is fined twice the individual amount for the same act. The inventory and provenance discipline set out in software asset management applies unchanged to the AI tooling layer.
New duties under the Digital Technology Industry Law
The short answer: from 01/01/2026, an AI system that interacts directly with people must tell users they are talking to a machine. The duty to mark AI-generated products does not yet bite, because it depends on a catalogue the Ministry of Science and Technology has still to issue. Separating those two limbs matters, so you neither over-comply nor under-comply.
The Digital Technology Industry Law No. 71/2025/QH15 was passed by the 15th National Assembly on 14/6/2025 and runs to 6 chapters and 51 articles. Article 50 provides that the law takes effect on 01/01/2026, except Articles 11, 28 and 29, which took effect earlier on 01/7/2025.
Article 44(1) imposes an immediately operative duty: an AI system interacting directly with humans must notify the user that they are interacting with an artificial intelligence system, unless the user obviously already knows. Any business running a customer service chatbot, an automated voice line or a website assistant should check whether that notice is actually present.
Article 44(2) is different in kind: digital technology products falling within the Catalogue of AI-generated digital technology products must carry an identifying mark recognisable to users or machines. That duty attaches to a Catalogue which Article 44(3) directs the Minister of Science and Technology to issue. Until the Catalogue exists, it is not correct to say that all AI-generated content must be labelled. A good deal of online commentary is currently overstating this.
Article 43 builds the classification framework. Article 43(1) defines a high-risk AI system as one capable of causing serious risk or harm to human health, human rights, citizens rights, the lawful rights and interests of organisations and individuals, the public interest, and social order and safety — while carving out three categories: systems performing specific tasks with narrow-scope effect, systems supporting humans in optimising work results, and systems checking errors in work already completed by humans without replacing human decisions.
Those three carve-outs cover most of what ordinary businesses do with AI today: drafting, summarising, error checking, code suggestion. But Article 43(3) still lists six categories of management requirement — technical requirements, transparency in storing and supplying information, data governance, monitoring and inspection, cyber safety and security, and other necessary requirements — and Article 43(4) directs the Government to prescribe details by sector. Organisations using AI for recruitment, credit scoring or medical record triage should expect to fall into the closely regulated group.
Where your data goes after you press Enter
The short answer: in the commercial tier of all four major vendors, customer data is not used to train the foundation models, and that promise sits in the contract rather than only on a marketing page. In the consumer tier the default is the opposite. The boundary between those two tiers is the boundary of your risk.
Microsoft states in Data, Privacy, and Security for Microsoft 365 Copilot, updated 09/07/2026: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft 365 Copilot." The same page is equally explicit that Copilot surfaces only what the user could already see: "Microsoft 365 Copilot only surfaces organizational data to which individual users have at least view permissions."
Operationally, that second sentence matters more than the first. Copilot does not break your permissions, but it exposes every permission mistake you already have. A SharePoint folder shared with the whole company by accident years ago may never have been discovered, until the day an employee asks the assistant a question and gets back exactly what is in that folder. Permission review is work to be done before you enable Copilot, not after.
On the OpenAI side the strongest binding sits in Services Agreement section 4.2: "OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use." The Enterprise privacy page, updated 08/01/2026, draws the line between the two worlds plainly: data from ChatGPT Business, Enterprise, Edu and the API Platform after 01/3/2023 is not used for training by default, while that same page acknowledges OpenAI does use "data from versions of ChatGPT and other services for individuals".
Anthropic uses the tersest formulation of the four: "Anthropic may not train models on Customer Content from Services", with Customer Content defined to include both Inputs and Outputs. The Google Workspace Service Specific Terms at section 12.11, last modified 16/07/2026, state: "Google will not use Customer Data to train or fine-tune any of its generative artificial intelligence models supporting the Google Workspace Generative AI Services without Customer's prior permission or instruction."
Read the conditional in the Google clause carefully. The commitment is not absolute; it is "not, without your prior permission or instruction". Google explanatory material on the Workspace privacy hub uses a similar limiting phrase on human review: "Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission." Qualifiers like these should be carried through verbatim into internal briefings, not compressed into an absolute promise.
One newer point deserves attention from businesses with data location requirements: Microsoft documentation notes that models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary. For Vietnamese businesses weighing data residency in Vietnam, the fact that an AI service may route through multiple subprocessors in multiple regions is a question to raise during vendor assessment, not after.
| Criterion | Consumer tier | Business tier (Business, Enterprise, API) |
|---|---|---|
| Data used for training by default | Yes. OpenAI: "We may use Content to provide, maintain, develop, and improve our Services", with an opt-out | No. Used only where the customer explicitly opts in |
| Legal basis of the promise | Terms of use, amendable unilaterally by the vendor | Commercial contract with binding obligations both ways |
| Copyright indemnity for output | None | Yes for API and Enterprise; Anthropic requires the use to be paid |
| Administrator control | None. The account belongs to the individual employee | Yes. Provisioning, revocation, logging, retention policy |
| What happens to the data when the employee leaves | It leaves with the personal account; the company loses access | It belongs to the organisation and is revoked through the normal offboarding process |
Warning: Decree 13/2023 ceased to have effect on 01/01/2026
The short answer: any internal policy, contract annex or impact assessment still citing Decree 13/2023/ND-CP as current law is out of date. The replacements are the Personal Data Protection Law No. 91/2025/QH15 and Decree 356/2025/ND-CP, both effective 01/01/2026. This is an easy mistake to make, because Decree 13/2023 has been the standard citation for almost three years.
The proof sits in the replacing instrument itself. Article 42(2) of Decree 356/2025/ND-CP, issued 31/12/2025, provides that Decree No. 13/2023/ND-CP of 17 April 2023 on personal data protection ceases to have effect from the date the new decree takes effect.
Law No. 91/2025/QH15 was passed on 26/6/2025 and runs to 5 chapters and 39 articles. Article 2(6) defines personal data processing as activity affecting personal data, including collection, analysis, aggregation, encryption, decryption, modification, deletion, destruction, de-identification, provision, disclosure and transfer of personal data, and other activities affecting personal data. Feeding a customer list into an AI tool to have it summarised falls squarely inside that definition.
Article 9(4) sets four principles for consent, two of which collide directly with how many businesses are rolling out AI. Point (b) forbids consent from being bundled with a compulsory condition to agree to purposes outside the agreed scope, which means you cannot fold the disclosure of customer data to an AI vendor into the same tick box as the original purpose. Point (d) confirms that silence or non-response does not constitute consent.
There is a transitional provision that gives businesses some breathing room. Article 39(1) provides that ongoing personal data processing for which valid consent was obtained under Decree 13/2023 before the Law took effect may continue without fresh consent. But that only protects what already exists; it does not cover a new processing purpose. Putting data into an AI tool that was never within the original consent scope is a new purpose.
For businesses buying AI on subscription, this review should run alongside a review of the whole cloud subscription estate, because the legal shape is identical: data leaves your infrastructure and comes to rest under someone else terms. The approach set out in SaaS and cloud subscription licence compliance transfers directly.
Copyright indemnities and their escape hatches
The short answer: all four vendors promise to defend customers against third-party intellectual property claims over output, but each attaches an exclusion list, and most of those exclusions describe precisely what businesses actually do. Reading the exclusions matters more than reading the promise.
Microsoft announced its Customer Copyright Commitment on 07/9/2023. The commitment is expressed in the Copilot documentation as follows: "If a third party sues a commercial customer for copyright infringement for using Microsoft's Copilots or the output they generate, we'll defend the customer and pay the amount of any adverse judgments or settlements that result from the lawsuit, as long as the customer used the guardrails and content filters we have built into our products."
There is a technical trap here worth spelling out so businesses do not do the wrong work. The Microsoft page describing required mitigations states precisely that those requirements "apply only to customers using Azure OpenAI in Microsoft Foundry Models and other Covered Products with configurable Metaprompts or other safety systems", and "do not apply to customers using other Covered Products including Copilots with safety systems that are fixed". So a business using Microsoft 365 Copilot does not have to go and enable any filter from that list; the only written condition is to use the built-in guardrails. Conversely, an organisation building its own application on Azure OpenAI must configure the metaprompt and retain a testing report to produce in the event of a claim.
OpenAI expresses its commitment in the service terms updated 12/6/2026, separately for the API and for the Enterprise group. Notably, the marketing name Copyright Shield announced in 2023 no longer appears in the current legal documents; the contractual term is now Output indemnity. And section 3 defines the Enterprise group as ChatGPT Enterprise, Edu and Healthcare, while ChatGPT Business is listed separately from that definition. No clause was found expressly extending Output indemnity to ChatGPT Business, so a business buying that tier should ask the vendor directly rather than assume.
Anthropic has the broadest scope of the four in one respect: its commitment covers the training data as well. Commercial Terms section K.1 defines a Customer Claim as a claim that "Customer's paid use of the Services (which includes data Anthropic has used to train a model that is part of the Services) in accordance with these Terms or Outputs generated through such authorized use violates any third-party intellectual property right". The words "paid use" are simultaneously the limit: the free tier carries no such protection.
Google splits the protection most transparently. Service Specific Terms section 12.10 separates a Generated Output limb from a Training Data limb, the latter protecting customers against allegations that Google use of training data to build the model itself infringed third-party rights. Note that the Google Cloud version at cloud.google.com, modified 29/7/2026, carries five exclusions rather than four, so do not blend the two documents when citing them.
Taken together, the four exclusion lists converge on one message. A business loses protection where it knew or should have known the output was likely infringing, where it disabled or ignored the citation tools and filters the vendor supplied, where it modified the output or combined it with third-party products, where it lacked rights in the input data itself, and where the dispute concerns trademarks arising from commercial use of the output. That last one deserves underlining for marketing teams: using AI to generate a brand name, tagline or logo and then registering and trading under it falls outside the indemnity of OpenAI, Anthropic and Google alike.
| Exclusion | OpenAI | Anthropic | Google Workspace |
|---|---|---|---|
| Knew or should have known the output was likely infringing | Yes | Yes | Yes |
| Disabled, ignored or circumvented filters, citations or safety tools | Yes | Not separately stated | Yes |
| Modified the output or combined it with non-vendor products | Yes | Yes (split across two limbs) | Protection applies only to unmodified output |
| Lacked rights in the input data or fine-tuning files | Yes | Yes | Yes in the Google Cloud version (fifth exclusion) |
| Trademark dispute from commercial use of the output | Yes | Yes | Yes |
| Continued use after notice of an infringement claim from the rights holder | Not separately stated | Not separately stated | Yes |
| Output originates from a third-party offering, or from Beta services | Yes (both) | Not separately stated | Applies only to paid services, not free tier usage |
Shadow AI: the cost that appears in no contract
The short answer: every protection analysed above applies only to accounts the company issued. When employees use personal accounts to process company data, the business loses the contractual protection and picks up a measurable incident cost at the same time. This is the largest slice of the risk and also the cheapest to fix.
The scale has been measured by primary survey. IBM and Censuswide surveyed 3,000 North American office workers and reported on 03/11/2025 that "while 80% of American office workers use AI in their roles, only 22% rely exclusively on tools provided by their employers". The same study found that 35% of employees aged 18 to 24 said they were likely to use only personal AI applications rather than company-approved ones, against 14% in other age groups.
The pattern is not new. The Work Trend Index 2024 from Microsoft and LinkedIn, covering 31,000 knowledge workers across 31 markets and fielded from 15/02 to 28/3/2024, already recorded that "78% of AI users are bringing their own AI tools to work (BYOAI)", rising to 80% at small and medium-sized companies. The same survey found 52% of people using AI at work were reluctant to admit using it for their most important tasks — meaning the true figure always exceeds the internally reported one.
The price now has a number attached. IBM Cost of a Data Breach 2025, studying 600 breached organisations between 03/2024 and 02/2025 through the Ponemon Institute, found one in five organisations breached via shadow AI, with high-shadow-AI organisations carrying USD 670,000 in additional breach cost. More serious is what leaked: shadow AI incidents exposed personally identifiable information in 65% of cases and intellectual property in 40%, against global averages of 53% and 33%.
The same report found 63% of breached organisations either lacked an AI governance policy or were still drafting one, and that among those with a policy only 34% ran regular audits for unsanctioned AI. The 2026 edition, published 29/7/2026 in the IBM newsroom, reports more than 20% of organisations experiencing a breach targeting AI models or applications, with the two most common causes tied at 27%: weaknesses in surrounding APIs, applications and plug-ins, and cloud misconfigurations affecting AI workloads.
The encouraging trend is in governance. The AI Index Report 2026 from Stanford HAI records the share of businesses with no responsible AI policies falling sharply from 24% to 11%, and dedicated AI governance roles growing 17% during 2025. The most effective response is not blocking, because blocking only pushes staff onto personal phones. It is issuing an official tool that is good enough, stating clearly which data may be entered, and auditing periodically as you would for any other software in the departmental licence cost inventory.

The base licence: an AI invoice is always an addition
The short answer: the list price of an AI assistant is almost always the price of an add-on, on top of a base licence you must already hold. Missing the second half is the usual reason budgets break in the first month. The arithmetic mirrors the trap in counting licences on virtualised infrastructure: the number on the pricing page is not the final number.
Microsoft says so directly in the Copilot licensing documentation: "Microsoft 365 Copilot is available as an add-on plan with one of the licensing prerequisites listed in this article." The requirements page adds two more conditions: users must have a Microsoft 365 licence assigned, and Copilot is only supported on primary mailboxes hosted on Exchange Online. Businesses still running on-premises mail need to know that before they negotiate.
The list of qualifying base licences is fairly broad, covering Microsoft 365 E3, E5, F1 and F3, the Business Basic, Standard and Premium plans, Apps for business and Apps for enterprise, plus Office 365 E1, E3, E5 and F3. The Microsoft enterprise pricing page lists Microsoft 365 Copilot at USD 30 per user per month billed annually, carrying the matching warning that "A separate license for a qualifying Microsoft 365 plan is required".
On the OpenAI side, the pricing page localises by region, so a visit from Vietnam displays Vietnamese dong. As retrieved on 03/08/2026, ChatGPT Business was listed at VND 519,000 per user per month billed annually, with a two-user minimum, and VND 649,000 billed monthly. ChatGPT Enterprise publishes no price and directs buyers to the sales team. Anthropic lists Claude Team at USD 20 per seat per month billed annually on its pricing page, with Claude Enterprise also at USD 20 per seat plus usage billed at API rates.
Google took a different route, and this one is frequently described incorrectly. From January 2025 the AI features were folded into the Workspace Business and Enterprise editions, and four former add-ons — Gemini Business Legacy, Gemini Enterprise Legacy, AI Meetings and Messaging, and AI Security — are no longer available for purchase. But saying Google has abandoned the add-on model altogether is inaccurate: other paid AI add-ons still exist above that baseline. The accurate phrasing is that core Gemini features are now included in the subscription, while advanced AI add-ons remain separately purchasable.
For Vietnamese businesses there is one more cost layer that rarely makes it into comparison tables: foreign contractor tax, invoice format, and whether the service can be paid in VND. A seat that is a few dollars cheaper but payable only by an international credit card in an individual name creates exactly the documentation problem accounting has to unpick at year end — and in practice that is the shortest road to shadow AI.
| Product | Published price | Base licence required | Notes |
|---|---|---|---|
| Microsoft 365 Copilot | USD 30 per user per month billed annually; USD 31.50 billed monthly | Yes — a qualifying Microsoft 365 or Office 365 plan | Primary mailbox must be hosted on Exchange Online |
| Microsoft 365 Copilot Business | USD 21 per user per month billed annually (promotional USD 18 at time of writing) | Yes — Business Basic, Standard, Premium or Apps for Business | A separate SKU from the enterprise Copilot plan |
| ChatGPT Business | VND 519,000 per user per month billed annually; VND 649,000 monthly | No | Two-user minimum. Output indemnity not confirmed for this tier |
| ChatGPT Enterprise | Not published; contact sales | No | Output indemnity confirmed in the service terms |
| Claude Team | USD 20 per seat per month billed annually; USD 25 monthly | No | For teams of 2 to 150; Premium seat at USD 100 |
| Claude Enterprise | USD 20 per seat plus usage at API rates | No | Billed annually |
| Gemini in Google Workspace | No separate price for core features | Yes — a Workspace Business or Enterprise edition | Four legacy Gemini add-ons withdrawn from sale in 2025; other AI add-ons remain |
Review checklist before signing an AI contract
The list below is drawn directly from the clauses cited in this article. Each item is a question you can put to the vendor and require an answer to in writing, rather than accepting a product page.
- Which agreement governs — the commercial terms or the consumer terms? Settle this before discussing anything else, because the data regimes are opposites.
- Where is the output assignment clause, and does it carry the words "if any"? Record that the vendor is not warranting the output is protected by copyright.
- Is the no-training commitment in the contract, or only on a marketing page? Only the contractual version binds.
- Does the indemnity actually apply to the tier you intend to buy? For ChatGPT Business this must be asked directly, because the public documentation does not say so.
- Does the exclusion list cover output your teams modify? If so, revisit the internal editing workflow, because modification is nearly always what happens.
- Which subprocessors does the service use, and in which regions? This determines whether data residency requirements can be met at all.
- Is the personal data you plan to enter already within the data subject consent scope? Under Law 91/2025/QH15 a new processing purpose needs fresh consent.
- Does the system interact directly with customers? If so, check the AI disclosure notice required by Article 44(1) of Law 71/2025/QH15 is in place.
- Have repository permissions been reviewed before enabling the assistant? It does not break permissions, but it exposes every permission error you already have.
- What base licence is mandatory, and do you already hold it? Add both halves to the budget before comparing vendors on price.
- Are invoicing, payment method and foreign contractor tax obligations settled? These are the direct cause of employees falling back on personal accounts.
- Do you have a written AI governance policy and a means of detecting unsanctioned tools? Per IBM, only 34% of organisations with a policy actually audit for them.
The bottom line
When buying generative AI for a business, legal safety is determined not by which vendor is strongest but by three questions answered in writing before signature: who owns the output, whether the data is used for training, and which situations the copyright indemnity excludes.
Frequently asked questions
Can a business register copyright in AI-generated content? Vietnamese intellectual property law defines an author as the person who directly creates the work, so an AI system cannot be named as author. The part a human edits, selects and arranges is the part with an arguable basis. How rights are specifically established for AI-assisted creations awaits Government regulation under the newly added Article 6(5) of Law 131/2025/QH15.
What is the exposure when an employee uses a personal ChatGPT account for company data? Three risks at once. First, the consumer default allows the data to be used to improve the service. Second, none of the copyright indemnities available to business customers apply. Third, if the data contains personal information the business remains the data controller and carries responsibility under Law 91/2025/QH15 — for a transaction it never knew about.
Is Decree 13/2023 still in force? No. Article 42(2) of Decree 356/2025/ND-CP provides that Decree 13/2023 ceased to have effect from 01/01/2026. The instruments now in force are the Personal Data Protection Law No. 91/2025/QH15 and Decree 356/2025/ND-CP. Ongoing processing for which valid consent was already obtained does not require fresh consent, under the transitional provision.
From 01/01/2026, must all AI-generated content be labelled? Not yet. Article 44(1) of Law 71/2025/QH15 only requires notice where an AI system interacts directly with people. The marking duty in Article 44(2) applies only to products within a Catalogue to be issued by the Minister of Science and Technology, and businesses should watch for its publication.
Which AI plan carries the most reliable copyright indemnity? There is no universal answer, because each vendor excludes a different set of situations and what matters is whether that set overlaps with how you actually work. Businesses that heavily edit output should note the unmodified-output condition in the Google terms. Businesses on free tiers should note that Anthropic protects paid use only. Businesses considering ChatGPT Business should require written confirmation, because the public documentation does not address that tier.
Should AI tools simply be blocked on the corporate network? Survey data suggests blocking does not reduce usage, it only moves it out of view: 78% of AI users in the Work Trend Index 2024 had already brought their own tools to work, and more than half were reluctant to admit it. The more effective route is to issue an official tool that is good enough, state clearly which data may be entered, and audit periodically.
Sources
- Microsoft — Data, Privacy, and Security for Microsoft 365 Copilot (09/07/2026)
- Microsoft — Microsoft 365 Copilot licensing prerequisites (19/05/2026)
- Microsoft — Microsoft 365 Copilot requirements (24/03/2026)
- Microsoft — Customer Copyright Commitment required mitigations (13/07/2026)
- Microsoft On the Issues — Copilot Copyright Commitment (07/09/2023)
- Microsoft 365 Copilot — enterprise pricing page (retrieved 03/08/2026)
- OpenAI — Services Agreement (effective 01/01/2026)
- OpenAI — Service terms (updated 12/06/2026)
- OpenAI — Enterprise privacy (updated 08/01/2026)
- ChatGPT — pricing page (retrieved 03/08/2026)
- Anthropic — Commercial Terms of Service (effective 17/06/2025)
- Claude — pricing page (retrieved 03/08/2026)
- Google Workspace — Service Specific Terms (modified 16/07/2026)
- Google Workspace — Generative AI privacy hub (updated 26/05/2026)
- Google Cloud — Service Specific Terms (modified 29/07/2026)
- Google Workspace — Gemini AI features now included in subscriptions
- Consolidated document 155/VBHN-VPQH — Law on Intellectual Property (Official Gazette PDF)
- Law No. 131/2025/QH15 amending the Law on Intellectual Property (effective 01/4/2026, PDF)
- Digital Technology Industry Law No. 71/2025/QH15 (effective 01/01/2026, PDF)
- Personal Data Protection Law No. 91/2025/QH15 (effective 01/01/2026, PDF)
- Decree 356/2025/ND-CP on personal data protection (PDF)
- Decree 341/2025/ND-CP on copyright administrative penalties (effective 15/02/2026, PDF)
- IBM — Cost of a Data Breach Report 2025 (30/07/2025)
- IBM — Cost of a Data Breach Report 2026 (29/07/2026)
- IBM Think — Rising AI adoption is creating shadow risks (03/11/2025)
- Microsoft WorkLab — Work Trend Index 2024 (08/05/2024)
- Stanford HAI — AI Index Report 2026 (PDF)
Need a software compliance review?
DZO experts provide a free compliance roadmap within 24 hours — e-VAT invoice, local implementation.
Book a free consultation



