Chile - AI Systems Regulation (Boletín 16821-19)

Government bill to regulate AI systems

Proyecto de Ley que regula los Sistemas de Inteligencia Artificial

Chile

RAI-CL-NA-PDLQRXX-2024
Under Review(Under Review)
BillGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

A risk-based framework proposed by the Chilean Executive (Boletín 16821-19) to regulate the development, deployment and use of AI systems in Chile. The bill sets definitions, classifies systems by risk (unacceptable, high, limited, no-evident-risk), establishes prohibited uses, governance structures, incident reporting and sanctioning powers for supervisory agencies while seeking to balance innovation and rights protection.

Summary

Background and purpose: The bill (Message submitted 7 May 2024; Boletín 16821-19) proposes a national statutory framework regulating "systems of artificial intelligence" used or having impact in Chile. Its stated goal is to promote development, innovation and implementation of AI while protecting fundamental rights and democratic principles. The Executive frames the measure as complementary to Chile's updated National AI Policy and as aligned with international instruments (notably the EU AI Act and UNESCO recommendations).

Scope and actors: The draft applies to natural or legal persons that introduce AI systems into the market, put them into service, implement them, import them or distribute them when these activities affect Chilean territory or produce outputs used in Chile. It covers providers, implementers, importers, distributors and authorized representatives located in Chile; extraterritorial application is aimed at outputs and uses that materially affect Chile.

Risk-based approach and classification: The bill adopts a four-tier classification: (i) systems of unacceptable use (prohibited), (ii) high-risk systems (subject to stricter obligations, monitoring and conformity measures), (iii) limited-risk systems (subject to transparency and mitigation measures) and (iv) systems with no evident risk. Examples and lists of specific prohibited uses appear in the draft (e.g., subliminal manipulation, certain forms of biometric remote identification, mass extraction of facial images, certain emotional evaluation uses and categorization based on sensitive attributes), and the draft empowers authorities to issue lists and clarifications.

Governance & institutional architecture: The bill contemplates creating or designating a national governance structure with leading responsibilities for the Ministry of Science, Technology, Knowledge and Innovation, a Council or a "Consejo Asesor Técnico de IA" with public-private membership to advise policy and propose lists of high-risk systems, and enforcement/fiscalization powers for the national data protection authority (created by Ley 21.719). Cybersecurity authorities (Agencia Nacional de Ciberseguridad) are referenced for incident coordination.

Key operator obligations: The draft imposes obligations that vary by risk level: high-risk operators must implement continuous lifecycle monitoring, risk-management systems, pre-deployment testing and conformity assessments; limited-risk operators must observe specific transparency measures; all operators must respect data protection rules and embed technical and organizational measures for security. The bill requires incident notification (notably a 72-hour preliminary notification in coordination with the Data Protection Agency for certain relevant incidents), logging and documentation for accountability, and labelling obligations for synthetic content where applicable.

Innovation measures and sandboxes: The draft explicitly contemplates supervised regulatory sandboxes for public bodies and private actors, tailored measures for small and medium enterprises, and support mechanisms to avoid overburdening nascent innovations.

Sanctions and proportionality: A sanctions regime is foreseen with administrative fines scaled by gravity and proportionality criteria (including company size and number of affected people). Public summaries of the draft indicate potential sanction ranges in UTM (Unidad Tributaria Mensual) with graduated scales; the project explicitly includes criteria of proportionality and cooperation as mitigating factors. Enforcement responsibilities are mapped primarily to the data protection authority for data-related infringements and to other named agencies for safety and cybersecurity-related breaches.

Legal and international alignment: The draft references international instruments (EU AI Act, UNESCO guidance) and is explicitly influenced by comparative law. It cross-references Chile's recent privacy reform (Ley N° 21.719) and the national cybersecurity framework (Ley N° 21.663) to allocate duties and coordinate supervision.

Parliamentary status and process: Submitted by Message on 7 May 2024 (Boletín 16821-19) and subsequently refundido with parliamentary motions (notably Boletín 15869-19), the bill has undergone extended committee scrutiny in the Chamber of Deputies (Comisión de Futuro/Comisión de Ciencias) with multiple sessions and reports during 2024–2025. The draft has been modified through parliamentary indications and remains under review in the legislative process (see official tramitación pages). Several high-impact provisions—such as certain civil liability rules and financial reports—have been the subject of debate and were at times rejected in committee votes, requiring further revision. The IAPP and Chilean legal press have published helpful summaries and timelines of the bill's iterations.

Implications for stakeholders: The draft is wide-ranging and will affect technology vendors, integrators, public sector procurers, and users. It demands cross-disciplinary compliance (privacy, cybersecurity, consumer protection and technical safety) and signals Chile's intention to establish a comprehensive national AI regulatory architecture aligned with global standards while attempting to preserve space for innovation.

Full article

Read full text ↗

Overview

The "Proyecto de Ley que regula los Sistemas de Inteligencia Artificial" (Boletín 16821-19) is an Executive message submitted on 7 May 2024 that establishes a nationwide, risk-based regulatory framework for the development, deployment and use of AI systems affecting Chile. Its primary objectives are to (a) promote responsible innovation, (b) protect fundamental rights and democratic principles, and (c) create governance and enforcement mechanisms to manage AI-related harms. The bill adopts a four-tier risk classification (unacceptable, high, limited, no-evident-risk) and lists prohibited uses such as subliminal manipulation and certain biometric remote-identification practices. The full text of the Executive message and the project text are available from the Chamber of Deputies (full legislative message and project PDF). For the official submission see Message and bill (Chamber PDF) and the Senate tramitación portal at Senate tramitación (Boletín 16821-19).

Definitions

The bill provides detailed definitions to ground scope and obligations, including: "system of artificial intelligence" (machine-based systems that infer outputs such as predictions, content, recommendations or decisions from inputs); "use" (development, testing, validation, distribution, market placement or any activity performed by an operator); "operator/provider/implementer/importer/distributor" (roles with defined responsibilities); "person affected" (individuals impacted by system outputs); and risk categories (unacceptable, high, limited, no-evident-risk). Definitions largely mirror international models (citations to EU AI Act concepts and UNESCO recommendations appear in the explanatory memoranda) and emphasize outputs that can influence physical or virtual environments.

Governance and Institutional Framework

The bill organizes governance along three pillars: (1) policy leadership and coordination under the Ministry of Science, Technology, Knowledge and Innovation; (2) a multi-stakeholder "Consejo Asesor Técnico de IA" (technical advisory council) to provide recommendations, produce yearly reports to Congress and propose lists of high-risk or limited-risk uses; and (3) supervisory and sanctioning functions placed with Chile's data protection authority for data-related violations and with cybersecurity agencies for incidents impacting system security. The documentation of the project references coordination with the newly-created Agency for Personal Data Protection (Ley 21.719) and the national cybersecurity agency (Agencia Nacional de Ciberseguridad) to ensure alignment on incident reporting and enforcement resources. The Council's composition brings together Ministers (or delegates), technical experts, civil society and industry representatives; institutional roles include drafting risk lists, advising on guidelines and assessing the law's implementation every three years.

Key Focus Areas

The bill addresses several substantive regulatory areas: risk classification and prohibitions (defining and forbidding certain inacceptable uses of AI); obligations for high-risk systems (mandatory risk management systems, pre-deployment conformity checks, continuous monitoring, lifecycle impact assessment and documented mitigation measures); incident reporting and coordination (preliminary notifications and follow-ups, often within 72 hours for relevant incidents, coordinated with the Data Protection Agency and ANCI for cybersecurity-related breaches); transparency and disclosure (explainability obligations for affected persons, labelling of synthetic content, and provenance disclosure when AI systems generate or manipulate audio, images, video or text); data governance alignment (requiring compliance with Chilean personal data law and references to cross-border transfer safeguards); safety and cybersecurity (technical and organizational security measures, resilience requirements and integration of cybersecurity incident taxonomies); accountability and documentation (mandated record-keeping, logs, risk registers and documentation for audit and conformity assessments); proportionality and support for SMEs (scaled obligations and tailored support measures); and innovation safeguards (regulated sandboxes for supervised experimentation, limited exemptions for research prior to commercialization and measures to avoid blocking open-source components except where they are marketed as high-risk products).

Implementation Framework

Implementation is organized in sequenced layers: (a) immediate obligations tied to risk classification and basic transparency; (b) medium-term obligations requiring certification or conformity assessment for designated high-risk systems; and (c) delegated rulemaking and technical standards set by competent agencies (including interoperability and reporting protocols). The bill contemplates delegated powers for ministers and agencies to publish mandatory technical guidance, lists of high-risk systems, templates for risk-management systems and procedures for sandbox approvals. It also anticipates cooperation agreements between the data protection authority and the national cybersecurity agency to coordinate incident response and joint supervision.

Monitoring and Evaluation

The bill mandates monitoring through: (i) periodic reporting by operators (frequency depends on risk level), (ii) annual reports by the Consejo Asesor Técnico to Congress and the Ministry of Science, and (iii) mandatory impact studies for certain categories. The Advisory Council is required to evaluate the law's practical implementation and to recommend changes every three years. Supervisory authorities will maintain registers and publish enforcement outcomes to enhance accountability and market transparency.

Penalties, Liability, and Appeals

Enforcement is primarily administrative with fines and corrective orders. Public summaries and parliamentary materials indicate a graduated fine regime with amounts scaled by UTM and proportionality factors (company size, number of affected people, remediation efforts, cooperation). The bill reserves judicial review and specific civil liability routes for damage caused by AI systems, and contemplates simplified judicial procedures for liability claims. Mitigating factors—such as prompt cooperation and active remediation—are explicit. The data protection authority has investigatory and sanctioning powers for data-related breaches; cybersecurity agencies maintain parallel incident-handling authorities.

Relationship to Other Instruments

The draft explicitly cross-references and coordinates with: (a) Ley N° 21.719 (new Chilean personal-data protection law that creates the Agency for Personal Data Protection), (b) Ley N° 21.663 and its implementing regulations on cybersecurity and incident reporting (which created the Agencia Nacional de Ciberseguridad), (c) Chile's updated Política Nacional de Inteligencia Artificial and Ministry circulars on responsible AI use in the public sector, and (d) consumer protection and transparency laws (notably provisions of Ley N° 20.285 on access to public information where applicable). The bill is positioned as complementary—rather than replacing—these instruments, and relies on inter-agency memoranda and delegated rulemaking to operationalize cross-sector coordination.

International Alignment

The bill takes comparative law from the EU AI Act and UNESCO recommendations as reference points: it adopts a risk-based stratification, enumerates prohibited uses similar to EU lists (e.g., certain biometrics and subliminal manipulation), and emphasizes conformity assessment and transparency. The explanatory memorandum cites the EU approach and emphasizes interoperability with international standards to support cross-border trade and research cooperation. Chile intends to remain aligned with major regulatory regimes while tailoring obligations to national institutional capacity and economic contexts.

Implementation Timeline

MilestoneDate / Period
Executive message submitted2024-05-07
Committee hearings (Chamber of Deputies)2024–2025 (ongoing)
Hacienda Committee report (observations & financial review)Mid-2025 (series of reviews and votes)
Possible dispatch to Senate (second chamber)2025 (follow-up depending on committee outcomes)
Delegated rulemaking & guidance issuanceTo be scheduled after enactment (phased implementation)

Sources and References

SourceType
Proyecto de Ley que regula los Sistemas de Inteligencia Artificial (IA) en ChileGovernment Website
Consulta experta: Proyecto de ley sobre sistemas de Inteligencia Artificial (Boletín 16821-19)Parliament/Legislature
Tramitación del Proyecto de Ley que regula los sistemas de inteligencia artificial (Boletín 16821-19)Parliament/Legislature
ISAL N°19 - Proyecto de ley que regula los sistemas de inteligencia artificial (Boletines Nos 15869-19 y 16821-19)Government Website

Requirements for a company

What an organisation has to do under Chile - AI Systems Regulation (Boletín 16821-19), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.

Must do

12
  • Do not develop, deploy, or use AI systems for prohibited purposes.All developers, deployers, and users of AI systems in Chile.
  • Classify AI systems according to the four-tier risk framework.All developers, deployers, and users of AI systems.
  • Implement and maintain a mandatory risk management system for high-risk AI systems.Providers and implementers of high-risk AI systems.
  • Conduct pre-deployment conformity checks for high-risk AI systems.Providers and implementers of high-risk AI systems.
  • Report relevant AI incidents to supervisory authorities within 72 hours for preliminary notification.Operators of AI systems.
  • Ensure full compliance with Chilean personal data protection law for all AI systems.All operators of AI systems processing personal data.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Chile - AI Systems Regulation (Boletín 16821-19), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1All developers, deployers, and users of AI systems in Chile.Do not develop, deploy, or use AI systems for prohibited purposes.
lists prohibited uses such as subliminal manipulation and certain biometric remote-identification practices.
Before placing on market or usingCritical
2All developers, deployers, and users of AI systems.Classify AI systems according to the four-tier risk framework.
The bill adopts a four-tier risk classification (unacceptable, high, limited, no-evident-risk).
Before placing on market or usingCritical
3Providers and implementers of high-risk AI systems.Implement and maintain a mandatory risk management system for high-risk AI systems.
obligations for high-risk systems (mandatory risk management systems, pre-deployment conformity checks, continuous monitoring, lifecycle impact assessment and documented mitigation measures)
Before placing on marketCritical
4Providers and implementers of high-risk AI systems.Conduct pre-deployment conformity checks for high-risk AI systems.
obligations for high-risk systems (mandatory risk management systems, pre-deployment conformity checks, continuous monitoring, lifecycle impact assessment and documented mitigation measures)
Before deploymentCritical
5Operators of AI systems.Report relevant AI incidents to supervisory authorities within 72 hours for preliminary notification.
incident reporting and coordination (preliminary notifications and follow-ups, often within 72 hours for relevant incidents)
Within 72 hours of incident discoveryCritical
6All operators of AI systems processing personal data.Ensure full compliance with Chilean personal data protection law for all AI systems.
data governance alignment (requiring compliance with Chilean personal data law and references to cross-border transfer safeguards)
OngoingCritical
7All operators of AI systems.Implement technical and organizational security measures and resilience requirements for AI systems.
safety and cybersecurity (technical and organizational security measures, resilience requirements and integration of cybersecurity incident taxonomies)
OngoingCritical
8Operators of AI systems generating or manipulating content.Label synthetic content and disclose AI-generated outputs where required.
transparency and disclosure (explainability obligations for affected persons, labelling of synthetic content, and provenance disclosure when AI systems generate or manipulate audio, images, video or text)
Before placing on market or usingImportant
9Operators of AI systems impacting individuals.Fulfill explainability obligations for affected persons regarding AI system outputs.
transparency and disclosure (explainability obligations for affected persons, labelling of synthetic content, and provenance disclosure when AI systems generate or manipulate audio, images, video or text)
Before placing on market or usingImportant
10All operators of AI systems.Maintain mandated record-keeping, logs, risk registers, and documentation for audit and conformity.
accountability and documentation (mandated record-keeping, logs, risk registers and documentation for audit and conformity assessments)
OngoingImportant
11Providers and implementers of high-risk AI systems.Continuously monitor high-risk AI systems throughout their lifecycle.
obligations for high-risk systems (mandatory risk management systems, pre-deployment conformity checks, continuous monitoring, lifecycle impact assessment and documented mitigation measures)
Ongoing after deploymentImportant
12Operators of AI systems.Submit periodic reports to supervisory authorities, with frequency depending on risk level.
monitoring through: (i) periodic reporting by operators (frequency depends on risk level)
As specified by risk levelImportant

© Regulations.AI · updated on 13-Jun-2026