Argentina - Santa Fe - AI Adoption Protocol (2726/2025)

Decree 2726/2025 – Protocol for the Adoption and Use of Generative Artificial Intelligence Technologies in Public Administration (Province of Santa Fe)

Decreto 2726/2025 – Protocolo para la Adopción y Uso de Tecnologías de Inteligencia Artificial Generativa en la Administración Pública (Provincia de Santa Fe)

Argentina

RAI-AR-NA-D2PPLXX-2025
Effective: November 3, 2025
In Force(In Force)
DecreeGovernance and OversightData Protection and PrivacyAccountability and Documentation
Export PDF

Decree No. 2726/2025 (Province of Santa Fe) approves a Protocol for the adoption and use of Generative Artificial Intelligence (IAG) in public administration. It designates the Secretariat of Technologies for Management as the implementing authority, mandates human oversight, training, data minimization and anonymization, restricts certain non‑institutional uses, and establishes disciplinary sanctions for noncompliance.

Summary

Decreto N.º 2726/2025 of the Province of Santa Fe (published 3 November 2025) approves the "Protocol for the Adoption and Use of Generative Artificial Intelligence Technologies in the scope of the Public Administration". The regulation establishes definitions (including AI, generative AI/IAG, personal and sensitive data, high‑risk AI systems, prompts, and human supervision), a scope of application covering all agents of the centralized and decentralized provincial administration, and specific principles and operational rules. The Secretariat of Technologies for the Management (Secretaría de Tecnologías para la Gestión) is designated as the Authority of Application with powers to issue interpretive norms, publish guidance, supervise compliance and coordinate mandatory training. The Protocol emphasizes that IAG is a tool to assist —not to replace— administrative decision‑making, requiring significant and competent human oversight by trained personnel. It requires proportional transparency and explainability, audit trails, data protection through minimization and anonymization before any use of non‑institutional tools, and limits on non‑institutional IAG to low‑sensitivity tasks. High‑risk applications that may affect rights, health, public safety, or outcomes of administrative procedures are subject to stricter governance and may be classified by the Authority of Application. The Protocol mandates annual training plans (Unit TIMBÓ or its delegate), channels for consultation and citizen complaints, proportional disclosure obligations when AI substantially contributes to decisions or external communications, rules on intellectual property (works produced under supervision belong to the provincial State), and disciplinary liabilities for breaches (without prejudice to civil or criminal responsibility). The document excludes from its technical regulation those institutional/high‑risk systems’ full life‑cycle governance, leaving those aspects to separate technical governance frameworks and contracting rules for providers. The decree references national and international standards (Argentine data protection law, access to public information law, national recommendations on trustworthy AI, the EU GDPR and AI Act proposals, UNESCO and OECD AI principles), and frames the Protocol as a precautionary, human‑centered approach to enable innovation while protecting fundamental rights.

Full article

Read full text ↗

Overview

The Decree N.º 2726/2025 (Santa Fe Province) approves an annexed "Protocol for the Adoption and Use of Generative Artificial Intelligence Technologies in the scope of the Public Administration" and was published in the provincial Boletín Oficial on 3 November 2025. The Protocol defines Generative AI (IAG) as systems designed to create novel content from training data (text, images, audio, code) and treats IAG as a tool for assistance rather than a replacement for legally competent administrative acts. It designates the Secretaría de Tecnologías para la Gestión as the Authority of Application with responsibilities for guidance, supervision and mandatory training. The instrument balances enabling uptake across public bodies (including use of widely accessible tools) with precautions: mandatory anonymization/minimization of personal data, restricted uses of non‑institutional AI to low‑sensitivity assistance, required human oversight, proportional transparency, and disciplinary remedies for violations. The text cross‑references national and international standards to align provincial practice with emerging best practices and legal obligations. For the official text see the Boletín Oficial entry.

Definitions

The Protocol sets out precise definitions to reduce ambiguity: "AI" means machine systems that, given human‑defined objectives, make predictions, recommendations or take decisions influencing real or virtual environments; "Generative AI (IAG)" denotes systems primarily intended to generate new content (text, image, audio, code) from training data; "Personal Data" and "Sensitive Data" align with Argentine and provincial law and cover identifiers, biometric/genetic data and attributes that may cause discrimination; "High‑Risk AI System" is any AI whose use may significantly affect health, safety, rights, or the outcome of administrative procedures; "Prompt" is a natural language instruction to an IAG; "Significant and Competent Human Supervision" requires the public agent to understand capabilities and limitations and to be able to override outputs; and "Principle of Minimization" constrains personal data to what is strictly necessary.

Governance and Institutional Framework

The Decree designates the Secretariat of Technologies for the Management as the Authority of Application, with explicit functions: issue clarifying/interpretive norms, publish best‑practice guides and usage manuals, supervise compliance and initiate proceedings, coordinate and promote mandatory training, and periodically evaluate and update the regulatory framework. The Secretariat retains its role as the ICT rector and custodian of provincial databases and infrastructures. The Protocol creates channels for confidential consultation by agents and a citizen complaints channel, and assigns the Unit TIMBÓ (Platform of Digital Management) or its delegate responsibility for implementing the annual training plan. For broader executive oversight and alignment, the instrument operates within the Ministry of Government and Innovation (Ministerio de Gobierno e Innovación Pública), which holds responsibility for ensuring administrative compliance and for integrating the Protocol into procurement and digital transformation programs. See the official publication in the provincial Boletín Oficial for the authority text.

Key Focus Areas

The Protocol organizes obligations and safeguards around several core areas: (1) Human‑centricity and supervision — IAG outputs are non‑binding proposals requiring explicit validation by trained agents; (2) Transparency and explainability — proportional to risk, with contextual mechanisms to expose logic and criteria for decisions (without automatically demanding source code disclosure); (3) Data protection and privacy — strict minimization and anonymization requirements prior to use in non‑institutional tools, preference for institutional/certified tools that guarantee confidentiality and non‑reuse for training; (4) Equity and non‑discrimination — proactive mitigation of biases through responsible prompting, supervision and correction; (5) Limits on non‑institutional tools — public, free or personal IAGs may only be used for low‑sensitivity assistance (search, ideation, draft improvement) and must never receive personal or sensitive data; (6) Automation limits — flows that automate decisions must clearly identify human checkpoints and not substitute legally‑reserved competences; (7) Capacity building — mandatory training and certification plans via TIMBÓ; (8) Accountability and recordkeeping — traceability obligations and individual agent responsibility for validated outputs; and (9) Intellectual property — works generated under supervision are owned by the Provincial State. The Protocol explicitly references national (data protection and access to information laws) and international standards (EU GDPR/AI proposals, UNESCO, OECD) as normative anchors (Boletín Oficial).

Implementation Framework

Implementation is operationalized through the Secretariat's authority to issue interpretive rules and guides, to publish manuals for different IAG systems and use cases, and to operate a Plan Annual de Capacitación through the TIMBÓ Unit. Agencies must adopt internal processes that ensure anonymization and minimize personal data before any interaction with non‑institutional tools, log IAG usage for traceability, and register cases where IAG assisted substantially in decisions or external communications. Procurement and contracting with third‑party providers must include clauses that prevent reuse of submitted queries for model training, ensure confidentiality, and require supplier documentation (technical dossiers, model descriptions). The Protocol distinguishes between user‑level obligations (agents as end‑users or consumers) and separate technical life‑cycle governance for institutional or high‑risk systems (excluded from this Protocol's operational user rules and to be governed by dedicated technical frameworks and contractual obligations). The Secretariat may classify high‑risk categories and build proportional compliance paths, including testing, validation, and conformity assessment requirements. For the full implementation clauses see the Official Decree text.

Monitoring and Evaluation

The Authority of Application is empowered to supervise compliance and to initiate ex officio actions. Monitoring mechanisms include mandatory training completion records, usage logs (traceability and audit trails), incident and complaint channels for both agents and citizens, and periodic evaluations of the regulatory framework to update obligations in line with technological evolution. The Secretariat will publish guidance materials and good practice manuals and may require periodic reporting from agencies about IAG deployments, incidents, bias assessments and mitigation steps. Where systems are identified as high risk, the Authority may demand additional testing, validation, and evidence of conformity with established safeguards. The Protocol emphasizes periodic review of policies by the Secretariat to ensure the regime remains proportionate and effective given fast‑moving developments in IAG.

Penalties, Liability, and Appeals

Article 7 establishes disciplinary liability for breaches of the Protocol and its Annex: sanctions will be applied following assessment of seriousness, intentionality, harm caused and the actor's rank, following applicable statutory disciplinary regimes and due process. The decree clarifies that disciplinary measures are without prejudice to potential civil or criminal liability. Remedies include internal disciplinary measures, suspension or revocation of access to IAG tools, contract sanctions (including termination) for third‑party providers, and referral to competent authorities for civil or criminal action where statutes permit. The Protocol also creates channels for complaints and appeals: agents may seek guidance or challenge supervisory actions through the Secretariat's procedures, and citizens may file complaints about rights impacts via the designated channel. The Secretariat's supervisory decisions are subject to existing administrative review and judicial oversight consistent with provincial law.

Relationship to Other Instruments

The Decree explicitly situates the Protocol within the existing statutory and constitutional framework: it references national laws on personal data protection and access to public information, Provincial Law Nº 14256 on Data Governance and Access to Public Information, and the Provincial Constitution (Article 29) requiring transparent and auditable algorithmic systems. It interoperates with ongoing digital transformation decrees (e.g., measures on digitalization of administrative records and the TIMBÓ platform) and leaves lifecycle technical governance and procurement compliance for institutional/high‑risk systems to specialized normative instruments and contractual clauses. The Protocol therefore complements data protection regimes, freedom of information obligations, procurement rules and the Province’s digital transformation strategy rather than supplanting them. See the official text for cross‑references: Boletín Oficial.

International Alignment

The Protocol cites international standards and guidance as normative reference points, including the EU GDPR/AI proposals, UNESCO AI ethics recommendations, OECD AI principles and national recommendations for trustworthy AI (Subsecretaría de Tecnologías de la Información, Disposition Nº 2/2023). This demonstrates intent to align provincial practice with international best practices on transparency, auditability, data protection, and non‑discrimination. The Authority is instructed to consider these instruments when issuing guidance, to ensure that procurement and contracting clauses reflect internationally recognized expectations about model documentation, non‑reuse of training data and safeguards for rights. The Protocol also references cross‑jurisdictional approaches to high‑risk classification and explains that more technical lifecycle governance may follow models used in other jurisdictions, adapted to provincial legal constraints.

Implementation Timeline

MilestoneDate / PeriodRemarks
Decree promulgated and published2025-11-03Publication in the Boletín Oficial.
Authority designated and guidance mandate activatedImmediate (from publication)Secretariat of Technologies for the Management to begin preparatory guidance and training plans.
Plan Annual de Capacitación developmentWithin the following 3 months (expected Q1 2026)Unit TIMBÓ to design modules, schedules and certification for agents using IAG.
Implementation of mandatory training for agents in high‑use areasWithin 6–12 monthsPriority to units with high public interaction or decision‑impact.
Periodic review of ProtocolAnnually or as neededAuthority to propose updates responsive to tech evolution and regulatory harmonization.

Sources and References

SourceType
Decree N.º 2726/2025 – Boletín Oficial, Province of Santa FePrimary Source
SantaFe.com.ar – provincial press summarySecondary source
LT10 – news reportSecondary source

Requirements for a company

What an organisation has to do under Argentina - Santa Fe - AI Adoption Protocol (2726/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

11
  • Explicitly validate all Generative AI outputs before use.Public agents using Generative AI.
  • Anonymize and minimize personal data before using non-institutional Generative AI tools.Public agents using non-institutional Generative AI.
  • Never input personal or sensitive data into non-institutional Generative AI tools.Public agents using non-institutional Generative AI.
  • Use non-institutional Generative AI tools only for low-sensitivity assistance.Public agents using non-institutional Generative AI.
  • Identify clear human checkpoints in automated decision flows using Generative AI.Public agencies deploying automated decision systems with Generative AI.
  • Complete mandatory Generative AI training and certification.Public agents using Generative AI.
  • +5 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Argentina - Santa Fe - AI Adoption Protocol (2726/2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Public agents using Generative AI.Explicitly validate all Generative AI outputs before use.
IAG outputs are non‑binding proposals requiring explicit validation by trained agents
Before using outputsCritical
2Public agents using non-institutional Generative AI.Anonymize and minimize personal data before using non-institutional Generative AI tools.
strict minimization and anonymization requirements prior to use in non‑institutional tools
Before inputting dataCritical
3Public agents using non-institutional Generative AI.Never input personal or sensitive data into non-institutional Generative AI tools.
public, free or personal IAGs... must never receive personal or sensitive data
Before inputting dataCritical
4Public agents using non-institutional Generative AI.Use non-institutional Generative AI tools only for low-sensitivity assistance.
public, free or personal IAGs may only be used for low‑sensitivity assistance
Before useCritical
5Public agencies deploying automated decision systems with Generative AI.Identify clear human checkpoints in automated decision flows using Generative AI.
flows that automate decisions must clearly identify human checkpoints and not substitute legally‑reserved competences
Before deploymentCritical
6Public agents using Generative AI.Complete mandatory Generative AI training and certification.
Capacity building — mandatory training and certification plans via TIMBÓ
Within 6–12 monthsImportant
7Public agencies and agents using Generative AI.Maintain usage logs for Generative AI tools to ensure traceability.
Accountability and recordkeeping — traceability obligations and individual agent responsibility for validated outputs
OngoingImportant
8Public agencies and agents using Generative AI.Register cases where Generative AI substantially assisted in decisions or communications.
register cases where IAG assisted substantially in decisions or external communications.
OngoingImportant
9Public agents using Generative AI.Proactively mitigate biases in Generative AI outputs through responsible prompting and supervision.
Equity and non‑discrimination — proactive mitigation of biases through responsible prompting, supervision and correction
OngoingImportant
10Public agencies procuring Generative AI systems or services.Include specific clauses in third-party Generative AI contracts to prevent data reuse and ensure confidentiality.
Procurement and contracting with third‑party providers must include clauses that prevent reuse of submitted queries for model training, ensure confidentiality
Before contractingImportant
11Public agencies deploying Generative AI systems.Ensure proportional transparency and explainability for Generative AI decisions.
Transparency and explainability — proportional to risk, with contextual mechanisms to expose logic and criteria for decisions
Before deploymentImportant

© Regulations.AI · updated on 13-Jun-2026