Chile - AI and Robotics Regulation (Boletín 15869-19)

Bill to regulate AI systems, robotics and related technologies

Proyecto de Ley (Boletín 15869-19) — Regula los sistemas de inteligencia artificial, la robótica y tecnologías conexas

Chile

RAI-CL-NA-PDLB1XX-2023
Under Review(Under Review)
BillRisk ManagementGovernance and OversightConformity Assessment and Registration
Export PDF

This bill (Boletín 15869-19), later refundido with Executive Message Boletín 16821-19, establishes a risk-based regulatory framework for AI systems, robotics and related technologies in Chile. It sets classification by risk, requires transparency, human oversight, documentation and conformity mechanisms, and creates institutional oversight structures while preserving innovation.

Overview

The Proyecto de Ley (Boletín 15869-19) seeks to regulate the development, commercialization, distribution and use of artificial intelligence systems, robotics and related technologies across Chilean territory. Filed in the Chamber of Deputies on 24 April 2023 and later consolidated with an Executive message (Boletín 16821-19), the draft advances a risk-based, use-focused regulatory approach that emphasizes protection of fundamental rights while promoting innovation. The initiative frames the regulation around four risk categories (unacceptable, high, limited, and no evident risk) and proposes differentiated obligations for providers and operators depending on those categories. Official legislative materials and tracking pages provide the primary text and procedural history; see the Chamber of Deputies project page at Cámara de Diputadas y Diputados — Tramitación (Boletín 15869-19) and the Ministry of Science summary at MinCiencia — Project summary.

Definitions

The bill defines core terms to delimit scope and obligations: "system of artificial intelligence" (a set of software systems that, on input data, produce outputs such as predictions, recommendations or decisions capable of influencing physical or digital environments), "developer", "provider", "operator", "user", "data of entry", "biometric data", and "serious incident". These definitions are functionally oriented (use- and effect-based) to avoid overbroad capture of generic software, and to target systems whose operation can produce legal, economic or bodily harms. The draft also clarifies exclusions (national defense, certain basic research) and sets out how composite systems and components (including open-source elements) are treated for compliance purposes.

Governance and Institutional Framework

The proposal places the Ministry of Science, Technology, Knowledge and Innovation (MinCiencia) at the center of coordination and policy implementation, charged with convening a consultative Technical Advisory Council on AI that will provide expert lists of high-risk systems and periodic evaluations. Sectoral regulators (health, financial markets, transport, telecommunications) retain competence over domain-specific rules; the draft requires inter-agency coordination with the national data protection authority created by Law No. 21.719 for privacy supervision. The bill contemplates a national registry for high-risk systems and a public mapping of critical deployments to enable market surveillance. For background on the governance design and ongoing institutional discussions see the Senate information bulletin at Senado de la República — notice on referral and the Chamber committee documentation available at Cámara de Diputadas y Diputados — Commissions.

Key Focus Areas

The bill focuses on multiple intersecting policy objectives. First, a risk-classification system directs proportional obligations (e.g., pre-market conformity or registration for high-risk systems). Second, transparency: model cards, provenance records, and human-understandable documentation are required so affected persons and regulators can understand system capabilities and limits. Third, safety and cybersecurity: technical safety-by-design, secure development lifecycles and measures to avoid adversarial manipulation are mandated. Fourth, data protection and privacy: data minimization, lawful bases for training, and privacy impact assessments when personal data are processed. Fifth, accountability and redress: operators must implement monitoring, incident reporting and complaint-handling processes, and the draft contemplates civil remedies for harm. Sixth, innovation policy: the text attempts to avoid undue barriers for SMEs and research by exempting certain non-commercial research and open-source components from onerous pre-market certification. The combination seeks to balance consumer protection and technological development in a Chilean context.

Implementation Framework

Implementation is structured around obligations for different actors: developers/providers (technical documentation, risk classification, safety testing and compliance evidence), operators (ongoing monitoring, user notices, human oversight points), and distributors/importers (ensuring supply chain compliance). High-risk systems will be subject to conformity assessment procedures or mandatory registration in a national registry; the Ministry will publish criteria and maintain lists of high- and limited-risk use-cases. The draft anticipates delegated regulations to define technical standards and procedures, and encourages use of recognized international standards to harmonize processes and reduce duplication for exporters. Ministries and sector regulators must prepare guidance documents and technical specifications to operationalize the law within specific sectors.

Monitoring and Evaluation

The bill requires periodic evaluation of the law's implementation and its effects on rights and innovation. The Technical Advisory Council will propose lists of systems by risk category and will review the law's application at set intervals (for example, every three years). The Ministry must maintain public registries and transparency portals with summaries of compliance actions, sanctions and guidance documents. The proposal also mandates incident reporting to permit regulators to detect systemic problems and conduct market surveillance. The combination of reactive (incident-driven) and proactive (periodic review, lists, conformity checks) monitoring aims to allow regulation to evolve with technological changes.

Penalties, Liability, and Appeals

Enforcement tools include administrative sanctions and fines for noncompliance, corrective orders (suspension, withdrawal from market), and public publication of sanctions. The bill contemplates civil liability routes allowing injured parties to pursue compensation and injunctive relief; one contested article on civil responsibility required qualified quorums and has been a focal point in Chamber debates. The draft establishes administrative appeal paths against regulator decisions and preserves judicial review for rights-related matters. Penalty levels are designed to be proportionate to the severity of infringements and scaled by the operator's size and culpability.

Relationship to Other Instruments

The proposed law is designed to operate alongside Chilean data protection reform (Law No. 21.719 creating a national data protection authority), sectoral statutes (healthcare, financial regulation, transport safety), consumer protection laws, and intellectual property frameworks. The draft references the new data protection agency for cross-referral on personal data issues and envisages memoranda of understanding between MinCiencia and sectoral regulators to coordinate oversight. It also foresees compatibility with public procurement rules when the State acquires AI systems, to ensure accountable procurement and deployment.

International Alignment

The bill deliberately aligns with international best practices and regulatory patterns, notably the European Union's risk-based approach in the EU AI Act and OECD AI principles, by adopting risk classification, transparency requirements and proportional governance. It encourages use of international standards for conformity assessment to facilitate trade and interoperability. The draft contains explicit provisions for cross-border data flows to remain consistent with the requirements emerging from Chile's upgraded data protection framework and international adequacy discussions.

Implementation Timeline

MilestoneTarget / Actual date
Initial filing (moción)2023-04-24
Executive message (refundido)2024-05-07
Committee hearings (continuing)2024-2025 (ongoing)
General Approval in Chamber2025-08-04 (approved in general)
Return to Commission for particular revision2025 (subsequent sessions through 2025)

Compliance Checklist

RequirementWhoNotes
Risk classificationProvider / OperatorDocument classification rationale; retain evidence
Model documentation (model cards, training data summary)ProviderPublic summary for transparency; full technical dossier for authority
Privacy Impact AssessmentOperatorWhen processing personal data or biometric data
Incident reportingOperator / ProviderSerious incidents to be notified within stated timeframe
Conformity assessment / RegistrationProvider / ImporterFor high-risk systems prior to deployment

Sources and References

SourceType
Cámara de Diputadas y Diputados — Tramitación (Boletín 15869-19)Primary Source
Ministry of Science — Project summary (Boletín 16821-19 consolidated)Primary Source
Senado de la República — Notice on referral and advisory councilPrimary Source
Plain English

Chile is moving to regulate artificial intelligence (AI) systems, robotics, and related technologies, establishing a risk-based framework that applies to anyone developing, commercializing, distributing, or using these technologies within the country.

This proposed law, currently under review in the Chilean legislature, aims to protect fundamental rights while fostering innovation. It places obligations on a wide range of actors, including developers, providers, operators, users, distributors, and importers of AI systems. The core of the regulation is a classification system that categorizes AI systems into four risk levels: unacceptable, high, limited, or no evident risk.

The most important obligations depend on this risk classification. For instance, high-risk systems will face strict requirements, including pre-market conformity assessments or mandatory registration in a national registry. All systems will generally need to meet transparency standards, such as providing clear documentation about their capabilities and limitations, often called "model cards." There are also strong mandates for human oversight, ensuring systems are safe and secure by design, and robust data protection measures, including data minimization and privacy impact assessments when personal data is involved.

The Ministry of Science, Technology, Knowledge and Innovation (MinCiencia) will coordinate implementation, supported by a Technical Advisory Council. While the bill has passed a general vote in the Chamber of Deputies, it is still under review in the Senate, meaning its final form and effective date are unknown.

Non-compliance could lead to significant penalties, including administrative fines, corrective orders like suspending or withdrawing systems from the market, and public disclosure of sanctions. The bill also allows individuals harmed by AI systems to seek compensation through civil lawsuits. A practical pitfall for businesses is the complexity of classifying systems and the extensive documentation required, especially for high-risk applications, which will demand significant upfront investment in compliance and technical expertise.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 14 marked complete

Plain-English obligations under Chile - AI and Robotics Regulation (Boletín 15869-19). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market

    Applies to: Providers and operators of AI systems.

    a risk-classification system directs proportional obligations
  2. #2CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    High-risk systems will be subject to conformity assessment procedures
  3. #3CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    mandatory registration in a national registry
  4. #4CriticalBefore placing on market

    Applies to: Developers and providers of AI systems.

    technical safety-by-design... are mandated.
  5. #5CriticalBefore placing on market

    Applies to: Developers and providers of AI systems.

    secure development lifecycles... are mandated.
  6. #6CriticalBefore placing on market

    Applies to: Developers and providers of AI systems.

    measures to avoid adversarial manipulation are mandated.
  7. #7CriticalBefore processing personal data

    Applies to: Operators of AI systems processing personal data.

    privacy impact assessments when personal data are processed.
  8. #8Critical

    Applies to: Operators of AI systems.

    operators must implement monitoring, incident reporting
  9. #9CriticalBefore deployment

    Applies to: Operators of AI systems.

    operators (ongoing monitoring, user notices, human oversight points)
  10. #10ImportantBefore placing on market

    Applies to: Providers of AI systems.

    model cards, provenance records, and human-understandable documentation are required
  11. #11ImportantBefore placing on market

    Applies to: Developers and providers of AI systems.

    developers/providers (technical documentation, risk classification, safety testing and compliance evidence)
  12. #12ImportantBefore placing on market

    Applies to: Developers and providers of AI systems.

    developers/providers (technical documentation, risk classification, safety testing and compliance evidence)
  13. #13Important

    Applies to: Operators of AI systems.

    operators must implement monitoring
  14. #14ImportantBefore placing on market

    Applies to: Distributors and importers of AI systems.

    distributors/importers (ensuring supply chain compliance)

© Regulations.AI — created on 13-Jun-2026