Argentina - AI Regulation Bill (1747/23)

Senate Project 1747/23 – Bill to Regulate the Development, Implementation, and Use of AI Systems

Senado Expediente 1747/23 – Proyecto de Ley para controlar desarrollo, implementación y utilización de sistemas basados en IA

Argentina

RAI-AR-NA-SE1PDXX-2023
Under Review(Under Review)
BillGovernance and OversightConformity Assessment and RegistrationRisk Management
Export PDF

Senate Bill Expediente 1747/23 (presented 14 August 2023 by Sen. Juan Carlos Romero) proposes a national, risk-based regulatory framework for the development, deployment and use of AI systems in Argentina. The draft establishes principles, a National Registry of AI Systems, pre-deployment impact assessments for higher-risk systems, categories of unacceptable uses (including some biometric and subliminal interventions), obligations for transparency, human oversight, and an authority (Ministry of Science or designated body) to evaluate and supervise compliance.

Summary

Expediente 1747/23 is a Senate initiative introduced on 14 August 2023 by Senator Juan Carlos Romero proposing comprehensive rules to govern the development, deployment and utilization of systems based on Artificial Intelligence (AI) within Argentine territory. The draft adopts a risk-based approach inspired by international regulatory models (notably the European risk-tier approach), defining risk categories that range from limited/minimal to high and unacceptable. It sets out foundational principles for trustworthy AI—such as inclusion, sustainability, transparency/explainability, robustness and human oversight—and requires that both public and private actors that design, develop, provide or deploy AI systems within Argentina register those systems in a National Registry of AI Systems.

A central feature of the proposal is pre-deployment evaluation: the designated authority (explicitly referenced as the Ministry of Science or the competent authority appointed by law) must carry out Impact Assessments before commercialization or public use of systems classified above a minimal-risk threshold. The assessment process is intended to analyze bias, discrimination risks, transparency, safety, and other factors relevant to the defined principles. The bill enumerates categories of high-risk applications—examples include systems used for critical infrastructure management (traffic, public utilities), education and evaluation of candidates, employment decisions (promotion/termination), emergency response triage and prioritization, public safety and criminal investigation, migration and border control, and biometric identification systems. It also catalogs specific unacceptable uses, such as systems that rely on subliminal techniques to substantially alter behaviour without awareness, and places strong constraints on the real-time remote biometric identification in public spaces, permitting it only under narrow, judicially or legally defined exceptions (serious imminent threats, targeted searches of identified suspects, judicial orders).

The draft requires providers and deploying entities to ensure robust data governance, privacy protections, cybersecurity measures, transparency and documentation (including algorithmic provenance, model description, datasets used, and audit logs). It mandates human-in-the-loop or human-on-the-loop controls for certain categories, conformity assessment and recordkeeping, periodic audits, and the ability for the authority to require corrective measures, suspensions or removals from the registry where risks are identified. Enforcement measures include administrative sanctions, corrective orders and other penalties envisaged in the bill (the draft contemplates fines and operational restrictions but leaves procedural detail to implementing regulations). The proposal establishes coordination with existing data protection rules and national policies on science and technology; it references international instruments (OCDE, UNESCO recommendations) as guiding principles.

Although actively discussed in commission stages, the expediente was recorded as entered on 14 August 2023, routed to the Committee on Science and Technology on 28 August 2023, and shows an expiry (caducidad) date of 28 February 2025 in the Senate record; it was reproduced by subsequent expediente 71/25. Primary official documentation for the expediente is available on the Argentine Senate parliamentary portal and a PDF of the original text is hosted on the Senate site. Secondary summaries and press coverage track the bill’s main provisions and notable policy choices (registry, risk-tiering, biometric restrictions).

Full article

Read full text ↗

Overview

Expediente 1747/23, introduced in the Argentine Senate on 14 August 2023 by Senator Juan Carlos Romero, proposes a national regulatory framework to "control the development, implementation and utilization of systems based on Artificial Intelligence" inside Argentina. The bill embraces a risk-based approach to AI governance, establishes five guiding principles (inclusive growth and welfare; transparency and explainability; robustness, security and protection; collaboration and human supervision; responsibility and accountability), and creates institutional tasks for a national authority to manage a National Registry of AI Systems and to perform pre-deployment Impact Assessments. The draft targets both public and private actors (developers, deployers, providers) and distinguishes between limited/minimal-risk, high-risk and unacceptable uses. It places specific constraints on biometric identification and techniques that manipulate behaviour without consent, while requiring documentation, audits, human oversight mechanisms and data governance safeguards. The primary registry and the bill text are published on the official Senate portal and the expediente was later reproduced under expediente 71/25 for continued handling by commissions in 2025. Official Senate metadata and the downloadable parliamentary text are accessible on the Senate website (original text stored as parlamentaria PDF).

Definitions

The proposed law defines key terms to anchor scope and obligations: "Artificial Intelligence systems" (systems that process data and produce outputs such as classification, prediction, recommendation or decision-support by algorithmic means); "provider" (the natural or legal person that develops or produces an AI system and places it on the market); "operator/deployer" (entity that deploys, operates or uses an AI system); "impact assessment" (a structured pre-deployment evaluation that examines risks, bias, discrimination, privacy and safety issues); "registry" (the National Registry of AI Systems where providers/deployers must register systems above predefined risk thresholds); and risk categories (limited/minimal, high, unacceptable). Definitions align conceptually with international instruments referenced in the bill, including OECD and UNESCO guidance, to ensure that risk and harm analyses consider social, economic and human rights dimensions.

Governance and Institutional Framework

The draft designates the Ministry of Science or a similarly empowered body as the primary enforcing authority, tasked with maintaining the National Registry, conducting or overseeing Impact Assessments, authorizing high-risk system deployment, and coordinating cross-sectoral supervision. Technical advisory committees and inter-agency coordination (including data protection authorities and sectoral regulators) are anticipated by the text to ensure sector-specific expertise for decisions affecting critical infrastructure, public safety, health or education. The authority may require conformity assessments, audits, transparency reports and may issue binding remedial orders. The bill foresees rulemaking powers to develop implementing regulations, procedural rules for impact assessments, and operational guidance for compliance; it also contemplates public consultation steps for regulatory norms. For official record and legislative progress see the Senate parliamentary entry and downloadable text on the Senate portal (senado.gob.ar - Expediente 1747/23).

Key Focus Areas

The bill concentrates obligations and controls across several domains: (1) Risk classification — systems are categorized by potential for harm and public impact, with stricter controls on high-risk systems and prohibition of unacceptable uses; (2) Registration and pre-market evaluation — a National Registry and mandatory Impact Assessments for systems above a threshold; (3) Transparency and documentation — providers must supply model descriptions, training data provenance, performance metrics, and interpretability explanations to the authority and, where appropriate, to impacted individuals; (4) Human oversight and operational constraints — mandatory human-in-the-loop/ human-on-the-loop arrangements for certain automated decision processes and explicit limits on fully autonomous decisions in sensitive domains; (5) Data protection and privacy — obligations to align with Argentina’s data protection norms, minimize personal data usage, and adopt privacy-preserving design choices; (6) Robustness, cybersecurity and model security — technical controls to prevent tampering, leakage and adversarial manipulation; (7) Conformity assessment, auditability and recordkeeping — periodic independent audits and retention of logs for accountability; (8) Restrictions and prohibitions — rules against subliminal manipulation and tight limitations on remote real-time biometric identification in public spaces except under narrowly defined exceptions. These focus areas reflect and adapt internationally recognized trustworthy AI requirements while being tailored for national institutions.

Implementation Framework

Implementation relies on a multi-stage administrative regime: registration of covered systems, submission of an Impact Assessment for review, a clearance/authorization or conditional approval for high-risk systems, and ongoing monitoring through periodic reporting obligations and audits. Providers and deployers must maintain technical documentation, internal risk management processes, and channels for redress. The authority is empowered to set templates for Impact Assessments, to require corrective actions (model retraining, limits on deployment), and to coordinate with sector regulators (health, transport, education, justice). The bill contemplates capacity-building measures within the public administration to evaluate technical dossiers and a phased rollout of registry and assessment obligations to allow time for compliance by small and medium enterprises.

Monitoring and Evaluation

The proposal establishes supervisory powers including on-site inspections, requests for information, periodic reporting obligations, and the ability to commission independent audits. Performance indicators for oversight will include rates of registration, outcome of impact assessments, incidents reported (bias/discrimination/security breaches), and compliance with corrective orders. The authority must publish aggregated statistics and non-confidential summaries of impact assessments to promote transparency and public trust. Coordination with the National Data Protection Authority and sectoral supervisors is required for cases implicating personal data or regulated sectors.

Penalties, Liability, and Appeals

Enforcement tools include administrative sanctions (fines and orders to suspend or withdraw systems from the registry or the market), mandated corrective measures (model re-design, data remediation), and public naming/notification of non-compliant actors. The draft also affirms that legal responsibility remains with natural and legal persons (providers, deployers), not with the AI as an entity; liability and redress frameworks are to be enforced through administrative procedures supplemented by civil or criminal remedies where existing law applies. The bill foresees evidentiary obligations to facilitate investigations and preserves legal avenues of appeal against administrative decisions in accordance with Argentine administrative law.

Relationship to Other Instruments

The project positions itself to complement existing national instruments: Argentina’s data protection regime, national science & technology policies, sectoral safety rules, and consumer protection law. It calls for alignment with the National Strategy or programs on AI, and coordination with the Data Protection Authority for privacy-intensive matters. It also contemplates regulatory cross-referrals to sectoral regulators (health, transport, financial authorities) where overlapping competencies exist. The bill is explicit that it does not supplant sector-specific safety rules but provides baseline obligations and a supervisory architecture for algorithmic systems across sectors.

International Alignment

Expediente 1747/23 references international standards and instruments (OCDE, UNESCO recommendations, European regulatory approaches) as normative guidance to ensure interoperability and to attract compliance alignment for providers operating across borders. The approach mirrors risk-tiering and pre-deployment assessments found in EU AI regulatory debates and emphasizes reciprocity in conformity and assessment mechanisms to facilitate trade and technical cooperation. The draft encourages cooperation with international bodies and inclusion in multilateral AI governance fora to exchange best practices for audits, impact assessment methodologies and cross-border enforcement assistance.

Implementation Timeline

MilestoneDate / Description
Introduction14-08-2023 — Bill presented to Senate (Sen. Juan Carlos Romero)
Committee referral28-08-2023 — Referred to Committee on Science and Technology
Dado Cuenta (Senate Registry)18-04-2024 — Procedural note on file
Caducidad (expiry)28-02-2025 — Official Senate record shows expediente caducó
Archived11-07-2025 — Senate record: sent to archive; later reproduced by Exp. 71/25

Sources and References

SourceType
Número de Expediente 1747/23 - Honorable Senado de la Nación ArgentinaParliament/Legislature
Número de Expediente 71/25 - Honorable Senado de la Nación ArgentinaParliament/Legislature
Dossier Legislativo: Inteligencia Artificial - Biblioteca del Congreso de la NaciónParliament/Legislature
Regulaciones e inteligencias artificiales en Argentina - InMediaciones de la Comunicación (Universidad ORT Uruguay)Academic Institution

Requirements for a company

What an organisation has to do under Argentina - AI Regulation Bill (1747/23), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.

Must do

12
  • Do not develop or deploy AI systems for subliminal manipulation or remote real-time biometric identification in public spaces.Providers and deployers of AI systems.
  • Submit system dossier to the National Registry before deployment for systems above predefined risk thresholds.Providers and deployers of AI systems above predefined risk thresholds.
  • Complete and file a pre-deployment Impact Assessment, including bias and safety testing, for systems above a threshold.Providers and deployers of AI systems above a threshold.
  • Maintain a technical dossier, training data provenance, performance metrics, and audit logs for AI systems.Providers and deployers of AI systems.
  • Design and implement human-in-the-loop or human-on-the-loop controls for certain automated decision processes, especially for high-risk systems.Providers and deployers of high-risk AI systems.
  • Implement privacy-by-design and minimize personal data usage, aligning with Argentina’s data protection regime.Providers and deployers of AI systems processing personal data.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Argentina - AI Regulation Bill (1747/23), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers and deployers of AI systems.Do not develop or deploy AI systems for subliminal manipulation or remote real-time biometric identification in public spaces.
Restrictions and prohibitions — rules against subliminal manipulation and tight limitations on remote real-time biometric identification in public spaces except under narrowly defined exceptions.
Always (if enacted)Critical
2Providers and deployers of AI systems above predefined risk thresholds.Submit system dossier to the National Registry before deployment for systems above predefined risk thresholds.
Registration and pre-market evaluation — a National Registry and mandatory Impact Assessments for systems above a threshold
Before placing on market (if enacted)Critical
3Providers and deployers of AI systems above a threshold.Complete and file a pre-deployment Impact Assessment, including bias and safety testing, for systems above a threshold.
Registration and pre-market evaluation — a National Registry and mandatory Impact Assessments for systems above a threshold
Before placing on market (if enacted)Critical
4Providers and deployers of AI systems.Maintain a technical dossier, training data provenance, performance metrics, and audit logs for AI systems.
Transparency and documentation — providers must supply model descriptions, training data provenance, performance metrics, and interpretability explanations to the authority
nullImportant
5Providers and deployers of high-risk AI systems.Design and implement human-in-the-loop or human-on-the-loop controls for certain automated decision processes, especially for high-risk systems.
Human oversight and operational constraints — mandatory human-in-the-loop/ human-on-the-loop arrangements for certain automated decision processes
nullImportant
6Providers and deployers of AI systems processing personal data.Implement privacy-by-design and minimize personal data usage, aligning with Argentina’s data protection regime.
Data protection and privacy — obligations to align with Argentina’s data protection norms, minimize personal data usage, and adopt privacy-preserving design choices
nullImportant
7Providers and deployers of AI systems.Apply technical controls to prevent tampering, leakage, and adversarial manipulation of AI systems.
Robustness, cybersecurity and model security — technical controls to prevent tampering, leakage and adversarial manipulation
nullImportant
8Providers and deployers of AI systems.Supply interpretability explanations to the authority and, where appropriate, to impacted individuals.
Transparency and documentation — providers must supply model descriptions, training data provenance, performance metrics, and interpretability explanations to the authority and, where appropriate, to impacted individuals
nullImportant
9Providers and deployers of AI systems.Arrange for periodic independent audits of AI systems for accountability.
Conformity assessment, auditability and recordkeeping — periodic independent audits and retention of logs for accountability
nullImportant
10Providers and deployers of AI systems.Establish and maintain internal processes for managing risks associated with AI systems.
Providers and deployers must maintain technical documentation, internal risk management processes, and channels for redress.
nullImportant
11Providers and deployers of AI systems.Ensure mechanisms are in place for individuals to seek redress.
Providers and deployers must maintain technical documentation, internal risk management processes, and channels for redress.
nullImportant
12Providers and deployers of AI systems.Provide necessary evidence to facilitate investigations by the authority.
The bill foresees evidentiary obligations to facilitate investigations
nullImportant

© Regulations.AI · updated on 13-Jun-2026