Chile - AI Systems Regulation (Boletín 16821-19)
Government bill to regulate AI systems
Proyecto de Ley que regula los Sistemas de Inteligencia Artificial
Chile
RAI-CL-NA-PDLQRXX-2024A risk-based framework proposed by the Chilean Executive (Boletín 16821-19) to regulate the development, deployment and use of AI systems in Chile. The bill sets definitions, classifies systems by risk (unacceptable, high, limited, no-evident-risk), establishes prohibited uses, governance structures, incident reporting and sanctioning powers for supervisory agencies while seeking to balance innovation and rights protection.
Summary
Background and purpose: The bill (Message submitted 7 May 2024; Boletín 16821-19) proposes a national statutory framework regulating "systems of artificial intelligence" used or having impact in Chile. Its stated goal is to promote development, innovation and implementation of AI while protecting fundamental rights and democratic principles. The Executive frames the measure as complementary to Chile's updated National AI Policy and as aligned with international instruments (notably the EU AI Act and UNESCO recommendations).
Scope and actors: The draft applies to natural or legal persons that introduce AI systems into the market, put them into service, implement them, import them or distribute them when these activities affect Chilean territory or produce outputs used in Chile. It covers providers, implementers, importers, distributors and authorized representatives located in Chile; extraterritorial application is aimed at outputs and uses that materially affect Chile.
Risk-based approach and classification: The bill adopts a four-tier classification: (i) systems of unacceptable use (prohibited), (ii) high-risk systems (subject to stricter obligations, monitoring and conformity measures), (iii) limited-risk systems (subject to transparency and mitigation measures) and (iv) systems with no evident risk. Examples and lists of specific prohibited uses appear in the draft (e.g., subliminal manipulation, certain forms of biometric remote identification, mass extraction of facial images, certain emotional evaluation uses and categorization based on sensitive attributes), and the draft empowers authorities to issue lists and clarifications.
Governance & institutional architecture: The bill contemplates creating or designating a national governance structure with leading responsibilities for the Ministry of Science, Technology, Knowledge and Innovation, a Council or a "Consejo Asesor Técnico de IA" with public-private membership to advise policy and propose lists of high-risk systems, and enforcement/fiscalization powers for the national data protection authority (created by Ley 21.719). Cybersecurity authorities (Agencia Nacional de Ciberseguridad) are referenced for incident coordination.
Key operator obligations: The draft imposes obligations that vary by risk level: high-risk operators must implement continuous lifecycle monitoring, risk-management systems, pre-deployment testing and conformity assessments; limited-risk operators must observe specific transparency measures; all operators must respect data protection rules and embed technical and organizational measures for security. The bill requires incident notification (notably a 72-hour preliminary notification in coordination with the Data Protection Agency for certain relevant incidents), logging and documentation for accountability, and labelling obligations for synthetic content where applicable.
Innovation measures and sandboxes: The draft explicitly contemplates supervised regulatory sandboxes for public bodies and private actors, tailored measures for small and medium enterprises, and support mechanisms to avoid overburdening nascent innovations.
Sanctions and proportionality: A sanctions regime is foreseen with administrative fines scaled by gravity and proportionality criteria (including company size and number of affected people). Public summaries of the draft indicate potential sanction ranges in UTM (Unidad Tributaria Mensual) with graduated scales; the project explicitly includes criteria of proportionality and cooperation as mitigating factors. Enforcement responsibilities are mapped primarily to the data protection authority for data-related infringements and to other named agencies for safety and cybersecurity-related breaches.
Legal and international alignment: The draft references international instruments (EU AI Act, UNESCO guidance) and is explicitly influenced by comparative law. It cross-references Chile's recent privacy reform (Ley N° 21.719) and the national cybersecurity framework (Ley N° 21.663) to allocate duties and coordinate supervision.
Parliamentary status and process: Submitted by Message on 7 May 2024 (Boletín 16821-19) and subsequently refundido with parliamentary motions (notably Boletín 15869-19), the bill has undergone extended committee scrutiny in the Chamber of Deputies (Comisión de Futuro/Comisión de Ciencias) with multiple sessions and reports during 2024–2025. The draft has been modified through parliamentary indications and remains under review in the legislative process (see official tramitación pages). Several high-impact provisions—such as certain civil liability rules and financial reports—have been the subject of debate and were at times rejected in committee votes, requiring further revision. The IAPP and Chilean legal press have published helpful summaries and timelines of the bill's iterations.
Implications for stakeholders: The draft is wide-ranging and will affect technology vendors, integrators, public sector procurers, and users. It demands cross-disciplinary compliance (privacy, cybersecurity, consumer protection and technical safety) and signals Chile's intention to establish a comprehensive national AI regulatory architecture aligned with global standards while attempting to preserve space for innovation.
Full article
Read full text ↗Overview
The "Proyecto de Ley que regula los Sistemas de Inteligencia Artificial" (Boletín 16821-19) is an Executive message submitted on 7 May 2024 that establishes a nationwide, risk-based regulatory framework for the development, deployment and use of AI systems affecting Chile. Its primary objectives are to (a) promote responsible innovation, (b) protect fundamental rights and democratic principles, and (c) create governance and enforcement mechanisms to manage AI-related harms. The bill adopts a four-tier risk classification (unacceptable, high, limited, no-evident-risk) and lists prohibited uses such as subliminal manipulation and certain biometric remote-identification practices. The full text of the Executive message and the project text are available from the Chamber of Deputies (full legislative message and project PDF). For the official submission see Message and bill (Chamber PDF) and the Senate tramitación portal at Senate tramitación (Boletín 16821-19).
Definitions
The bill provides detailed definitions to ground scope and obligations, including: "system of artificial intelligence" (machine-based systems that infer outputs such as predictions, content, recommendations or decisions from inputs); "use" (development, testing, validation, distribution, market placement or any activity performed by an operator); "operator/provider/implementer/importer/distributor" (roles with defined responsibilities); "person affected" (individuals impacted by system outputs); and risk categories (unacceptable, high, limited, no-evident-risk). Definitions largely mirror international models (citations to EU AI Act concepts and UNESCO recommendations appear in the explanatory memoranda) and emphasize outputs that can influence physical or virtual environments.
Governance and Institutional Framework
The bill organizes governance along three pillars: (1) policy leadership and coordination under the Ministry of Science, Technology, Knowledge and Innovation; (2) a multi-stakeholder "Consejo Asesor Técnico de IA" (technical advisory council) to provide recommendations, produce yearly reports to Congress and propose lists of high-risk or limited-risk uses; and (3) supervisory and sanctioning functions placed with Chile's data protection authority for data-related violations and with cybersecurity agencies for incidents impacting system security. The documentation of the project references coordination with the newly-created Agency for Personal Data Protection (Ley 21.719) and the national cybersecurity agency (Agencia Nacional de Ciberseguridad) to ensure alignment on incident reporting and enforcement resources. The Council's composition brings together Ministers (or delegates), technical experts, civil society and industry representatives; institutional roles include drafting risk lists, advising on guidelines and assessing the law's implementation every three years.
Key Focus Areas
The bill addresses several substantive regulatory areas: risk classification and prohibitions (defining and forbidding certain inacceptable uses of AI); obligations for high-risk systems (mandatory risk management systems, pre-deployment conformity checks, continuous monitoring, lifecycle impact assessment and documented mitigation measures); incident reporting and coordination (preliminary notifications and follow-ups, often within 72 hours for relevant incidents, coordinated with the Data Protection Agency and ANCI for cybersecurity-related breaches); transparency and disclosure (explainability obligations for affected persons, labelling of synthetic content, and provenance disclosure when AI systems generate or manipulate audio, images, video or text); data governance alignment (requiring compliance with Chilean personal data law and references to cross-border transfer safeguards); safety and cybersecurity (technical and organizational security measures, resilience requirements and integration of cybersecurity incident taxonomies); accountability and documentation (mandated record-keeping, logs, risk registers and documentation for audit and conformity assessments); proportionality and support for SMEs (scaled obligations and tailored support measures); and innovation safeguards (regulated sandboxes for supervised experimentation, limited exemptions for research prior to commercialization and measures to avoid blocking open-source components except where they are marketed as high-risk products).
Implementation Framework
Implementation is organized in sequenced layers: (a) immediate obligations tied to risk classification and basic transparency; (b) medium-term obligations requiring certification or conformity assessment for designated high-risk systems; and (c) delegated rulemaking and technical standards set by competent agencies (including interoperability and reporting protocols). The bill contemplates delegated powers for ministers and agencies to publish mandatory technical guidance, lists of high-risk systems, templates for risk-management systems and procedures for sandbox approvals. It also anticipates cooperation agreements between the data protection authority and the national cybersecurity agency to coordinate incident response and joint supervision.
Monitoring and Evaluation
The bill mandates monitoring through: (i) periodic reporting by operators (frequency depends on risk level), (ii) annual reports by the Consejo Asesor Técnico to Congress and the Ministry of Science, and (iii) mandatory impact studies for certain categories. The Advisory Council is required to evaluate the law's practical implementation and to recommend changes every three years. Supervisory authorities will maintain registers and publish enforcement outcomes to enhance accountability and market transparency.
Penalties, Liability, and Appeals
Enforcement is primarily administrative with fines and corrective orders. Public summaries and parliamentary materials indicate a graduated fine regime with amounts scaled by UTM and proportionality factors (company size, number of affected people, remediation efforts, cooperation). The bill reserves judicial review and specific civil liability routes for damage caused by AI systems, and contemplates simplified judicial procedures for liability claims. Mitigating factors—such as prompt cooperation and active remediation—are explicit. The data protection authority has investigatory and sanctioning powers for data-related breaches; cybersecurity agencies maintain parallel incident-handling authorities.
Relationship to Other Instruments
The draft explicitly cross-references and coordinates with: (a) Ley N° 21.719 (new Chilean personal-data protection law that creates the Agency for Personal Data Protection), (b) Ley N° 21.663 and its implementing regulations on cybersecurity and incident reporting (which created the Agencia Nacional de Ciberseguridad), (c) Chile's updated Política Nacional de Inteligencia Artificial and Ministry circulars on responsible AI use in the public sector, and (d) consumer protection and transparency laws (notably provisions of Ley N° 20.285 on access to public information where applicable). The bill is positioned as complementary—rather than replacing—these instruments, and relies on inter-agency memoranda and delegated rulemaking to operationalize cross-sector coordination.
International Alignment
The bill takes comparative law from the EU AI Act and UNESCO recommendations as reference points: it adopts a risk-based stratification, enumerates prohibited uses similar to EU lists (e.g., certain biometrics and subliminal manipulation), and emphasizes conformity assessment and transparency. The explanatory memorandum cites the EU approach and emphasizes interoperability with international standards to support cross-border trade and research cooperation. Chile intends to remain aligned with major regulatory regimes while tailoring obligations to national institutional capacity and economic contexts.
Implementation Timeline
| Milestone | Date / Period |
|---|---|
| Executive message submitted | 2024-05-07 |
| Committee hearings (Chamber of Deputies) | 2024–2025 (ongoing) |
| Hacienda Committee report (observations & financial review) | Mid-2025 (series of reviews and votes) |
| Possible dispatch to Senate (second chamber) | 2025 (follow-up depending on committee outcomes) |
| Delegated rulemaking & guidance issuance | To be scheduled after enactment (phased implementation) |
Sources and References
Requirements for a company
What an organisation has to do under Chile - AI Systems Regulation (Boletín 16821-19), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.
Must do
12- Do not develop, deploy, or use AI systems for prohibited purposes.All developers, deployers, and users of AI systems in Chile.
- Classify AI systems according to the four-tier risk framework.All developers, deployers, and users of AI systems.
- Implement and maintain a mandatory risk management system for high-risk AI systems.Providers and implementers of high-risk AI systems.
- Conduct pre-deployment conformity checks for high-risk AI systems.Providers and implementers of high-risk AI systems.
- Report relevant AI incidents to supervisory authorities within 72 hours for preliminary notification.Operators of AI systems.
- Ensure full compliance with Chilean personal data protection law for all AI systems.All operators of AI systems processing personal data.
- +6 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Chile - AI Systems Regulation (Boletín 16821-19), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | All developers, deployers, and users of AI systems in Chile. | Do not develop, deploy, or use AI systems for prohibited purposes. “lists prohibited uses such as subliminal manipulation and certain biometric remote-identification practices.” | Before placing on market or using | — | Critical |
| 2 | All developers, deployers, and users of AI systems. | Classify AI systems according to the four-tier risk framework. “The bill adopts a four-tier risk classification (unacceptable, high, limited, no-evident-risk).” | Before placing on market or using | — | Critical |
| 3 | Providers and implementers of high-risk AI systems. | Implement and maintain a mandatory risk management system for high-risk AI systems. “obligations for high-risk systems (mandatory risk management systems, pre-deployment conformity checks, continuous monitoring, lifecycle impact assessment and documented mitigation measures)” | Before placing on market | — | Critical |
| 4 | Providers and implementers of high-risk AI systems. | Conduct pre-deployment conformity checks for high-risk AI systems. “obligations for high-risk systems (mandatory risk management systems, pre-deployment conformity checks, continuous monitoring, lifecycle impact assessment and documented mitigation measures)” | Before deployment | — | Critical |
| 5 | Operators of AI systems. | Report relevant AI incidents to supervisory authorities within 72 hours for preliminary notification. “incident reporting and coordination (preliminary notifications and follow-ups, often within 72 hours for relevant incidents)” | Within 72 hours of incident discovery | — | Critical |
| 6 | All operators of AI systems processing personal data. | Ensure full compliance with Chilean personal data protection law for all AI systems. “data governance alignment (requiring compliance with Chilean personal data law and references to cross-border transfer safeguards)” | Ongoing | — | Critical |
| 7 | All operators of AI systems. | Implement technical and organizational security measures and resilience requirements for AI systems. “safety and cybersecurity (technical and organizational security measures, resilience requirements and integration of cybersecurity incident taxonomies)” | Ongoing | — | Critical |
| 8 | Operators of AI systems generating or manipulating content. | Label synthetic content and disclose AI-generated outputs where required. “transparency and disclosure (explainability obligations for affected persons, labelling of synthetic content, and provenance disclosure when AI systems generate or manipulate audio, images, video or text)” | Before placing on market or using | — | Important |
| 9 | Operators of AI systems impacting individuals. | Fulfill explainability obligations for affected persons regarding AI system outputs. “transparency and disclosure (explainability obligations for affected persons, labelling of synthetic content, and provenance disclosure when AI systems generate or manipulate audio, images, video or text)” | Before placing on market or using | — | Important |
| 10 | All operators of AI systems. | Maintain mandated record-keeping, logs, risk registers, and documentation for audit and conformity. “accountability and documentation (mandated record-keeping, logs, risk registers and documentation for audit and conformity assessments)” | Ongoing | — | Important |
| 11 | Providers and implementers of high-risk AI systems. | Continuously monitor high-risk AI systems throughout their lifecycle. “obligations for high-risk systems (mandatory risk management systems, pre-deployment conformity checks, continuous monitoring, lifecycle impact assessment and documented mitigation measures)” | Ongoing after deployment | — | Important |
| 12 | Operators of AI systems. | Submit periodic reports to supervisory authorities, with frequency depending on risk level. “monitoring through: (i) periodic reporting by operators (frequency depends on risk level)” | As specified by risk level | — | Important |
Related Regulations
Proyecto de Ley (Boletín 15869-19) — Regula los sistemas de inteligencia artificial, la robótica y tecnologías conexas (Bill to regulate AI systems, robotics and related technologies)
Chile97% similar
Proyecto de Ley (Boletín 17112-19) — Establece límites al desarrollo de la inteligencia artificial en resguardo de los derechos humanos fundamentales (Limits on AI development to protect fundamental human rights)
Chile95% similar
Proyecto de Ley (Boletín 15935-07) — Modifica el Código Penal para sancionar el mal uso de la inteligencia artificial (Amendment to Criminal Code to sanction misuse of AI)
Chile92% similar
Instructivo del Ministerio de Ciencia sobre uso de IA en el Estado (MinCiencia instructive on AI use in government)
Chile92% similar
Proyecto de Ley (Boletín 16021-07) — AI-use aggravating circumstance
Chile92% similar
© Regulations.AI · updated on 13-Jun-2026