Chile - AI Regulation Overview

Chile AI Regulation Overview

Resumen de la Regulación de IA en Chile

Chile

RAI-CL-NA-SUMMARY-2026
Governance and OversightData Protection and PrivacyRisk Management
Export PDF

Chile's AI landscape features a robust, risk-based regulatory model centered on the National AI Policy, a new Data Protection Agency (Law 21.719), and comprehensive cybersecurity mandates (Law 21.663). This framework balances innovation with fundamental rights, aligning with OECD and EU standards to ensure a safe and transparent digital ecosystem for all citizens.

Overview

Chile has established itself as a pioneer in the Latin American region regarding the governance and ethical deployment of artificial intelligence. This leadership is not accidental but the result of a sustained, multi-year effort to integrate digital technologies into the national fabric while safeguarding the democratic values that define the nation. The journey began with the 2021 National Artificial Intelligence Policy, which provided a foundational vision for the country's technological future. However, the rapid acceleration of AI capabilities, particularly in the realm of generative models and large-scale data processing, necessitated a more robust and legally binding approach. Consequently, in 2024, Chile updated its National AI Policy through Decree No. 12, shifting the focus from mere promotion to a comprehensive governance model that prioritizes human rights, social equity, and environmental sustainability. This strategic update serves as a ten-year roadmap, guiding the public sector, private industry, and academic institutions toward a shared goal of 'AI for Good.' The current regulatory landscape is a sophisticated blend of horizontal laws, such as the Framework Law on Cybersecurity and the modernized Data Protection Law, and sector-specific guidelines that address the unique challenges of AI in finance, health, and consumer services. By aligning its domestic regulations with international benchmarks like the OECD AI Principles and the EU AI Act, Chile ensures that its digital economy remains competitive, interoperable, and, most importantly, trusted by its citizens. The maturity of this framework is evidenced by the creation of specialized enforcement bodies like the National Cybersecurity Agency (ANCI) and the Agency for the Protection of Personal Data, which provide the necessary oversight to transform ethical principles into enforceable legal mandates. As Chile moves toward the full implementation of its AI-specific legislation, it continues to serve as a model for how a developing nation can navigate the complexities of the fourth industrial revolution with foresight and responsibility.

Regulatory Approach

The Chilean model is characterized by 'Dynamic Regulation,' a philosophy that balances the need for legal certainty with the inherent agility of technological advancement. Instead of a static law that might become obsolete, the government uses a combination of high-level statutory principles and agile administrative guidelines. The pending AI Bill (Boletín 16821-19) is the centerpiece of this strategy, adopting a risk-based architecture that mirrors the European Union's AI Act. This bill classifies AI systems into four distinct risk categories: Unacceptable Risk, High Risk, Limited Risk, and Minimal Risk. Prohibited systems include those that use subliminal techniques to distort behavior or exploit vulnerabilities of specific groups, as well as real-time remote biometric identification in public spaces for law enforcement, subject to narrow exceptions. High-risk systems, such as those used in critical infrastructure, education, employment, or essential private services, must undergo rigorous 'Conformity Assessments' and maintain detailed technical documentation. Limited-risk systems, like chatbots or deepfake generators, are subject to transparency obligations, ensuring users are aware they are interacting with an automated system. This approach ensures that innovation is not stifled in low-risk areas while providing a safety net for applications that could impact fundamental rights. Furthermore, the regulatory approach is 'Human-Centric,' meaning that human oversight is not just a recommendation but a requirement for high-risk systems. The government also utilizes 'Regulatory Sandboxes' to allow for the testing of AI innovations in the public sector under controlled conditions, fostering a culture of 'learning by doing' among regulators and developers alike.

Key AI Legislation

The legislative foundation of Chile's AI governance is composed of several landmark acts and decrees. Law No. 21.719, published in December 2024, is perhaps the most significant achievement, as it modernizes the data protection framework and creates the independent Personal Data Protection Agency. This law aligns Chile with the GDPR and sets the stage for AI data governance with a deferred entry into force in December 2026. Equally vital is Law No. 21.663 (2024), the Framework Law on Cybersecurity, which establishes the National Cybersecurity Agency (ANCI) and sets security obligations for 'Operators of Vital Importance' (OIV), including those utilizing AI in critical infrastructure. Decree No. 12 (2024) formally adopts the 2024 update to the National AI Policy, reorienting the national strategy toward ethics, inclusion, and the governance of generative models. In the administrative realm, Oficio Circular N° 711 (2023), issued by the Ministry of Science and the Ministry Secretariat General of the Presidency, establishes mandatory guidelines for the use of AI tools within the state administration, prohibiting the use of sensitive data in uncontracted generative AI. Additionally, Resolución Exenta N° 372 (2024) from the Council for Transparency (CPLT) provides recommendations on algorithmic transparency for public bodies, requiring them to maintain registers of automated decision systems. Finally, the primary government bill to regulate AI systems (Boletín 16821-19) is currently under review, which will introduce the formal risk-based classification and conformity assessment regime for the private sector, completing the statutory circle.

Governance & Enforcement Bodies

The governance of AI in Chile is a distributed but coordinated effort involving several specialized agencies. The Ministry of Science, Technology, Knowledge, and Innovation (MinCiencia) acts as the primary policy lead, responsible for updating the National AI Policy and chairing the 'Inter-ministerial Commission on AI.' This commission ensures that AI policy is integrated across various government departments, including Economy, Justice, and Education. The operational enforcement of AI-related rules falls to the newly created Agencia Nacional de Ciberseguridad (ANCI) for matters of system security and the forthcoming Agencia de Protección de Datos Personales for matters of privacy and automated processing. This separation of powers ensures that AI systems are audited both for their technical resilience and their impact on individual privacy rights. The Division of Government Digital (DGD) within the Ministry Secretariat General of the Presidency (Segpres) monitors AI adoption across public services, ensuring that the state leads by example in ethical deployment. The National Consumer Service (SERNAC) plays a critical role in the private sector, supervising AI use in commercial relationships and protecting consumers from algorithmic bias or manipulative practices. The Council for Transparency (CPLT) ensures that algorithmic systems used by the state are explainable and accessible to the public, upholding the principle of administrative transparency. This multi-agency fabric is designed to prevent regulatory gaps, with the pending AI Law expected to further formalize a 'Technical Advisory Council on AI' to provide cross-sectoral expertise on high-risk classifications and technical standards.

Penalties & Enforcement

Enforcement in the Chilean AI ecosystem is characterized by a graduated sanctioning regime that scales with the severity of the infraction and the size of the entity. Under the Framework Law on Cybersecurity (Law 21.663), entities classified as Operators of Vital Importance (OIV) can face significant administrative fines for failing to report incidents or maintain security standards, with penalties reaching up to several thousand Monthly Tax Units (UTM). The new Data Protection Law (Law 21.719) introduces a robust sanctioning title administered by the new Agency, which includes corrective measures, temporary suspensions of data processing, and substantial pecuniary fines for serious breaches of data subject rights. Very grave infractions can lead to fines of up to 20,000 UTM, which is approximately 1.3 million USD, or up to 4% of the entity's annual revenue. Beyond administrative fines, Chile is actively updating its Criminal Code to address AI-enabled harms. Several legislative motions seek to establish the use of AI as an aggravating circumstance in crimes like fraud, identity usurpation, and the dissemination of non-consensual deepfakes. Enforcement also includes 'soft' measures, such as the power of the DGD to request information and audit public sector AI deployments, and the ability of SERNAC to initiate collective actions against companies using manipulative AI practices that harm consumer interests. The pending AI Bill will add another layer of enforcement, allowing the regulator to order the withdrawal of high-risk AI systems from the market if they fail to meet safety or transparency standards, ensuring that the cost of non-compliance outweighs the benefits of cutting corners.

Data Protection Framework

Chile's data protection landscape is currently in a transformative 'vacatio legis' period following the publication of Law No. 21.719 in December 2024. This law represents a comprehensive overhaul of the previous 1999 framework (Law 19.628), aligning Chilean standards with the EU's GDPR. It introduces core principles of lawful processing, including purpose limitation, proportionality, and data minimization. Crucially for AI, the law recognizes rights to portability, opposition to profiling, and the right to human intervention in automated decisions. The law is scheduled to fully enter into force on December 1, 2026, giving organizations time to implement the required technical and organizational measures. The new framework also establishes the Agencia de Protección de Datos Personales as an autonomous technical body with the power to issue binding instructions and conduct inspections. For AI developers, this means mandatory Data Protection Impact Assessments (DPIAs) for high-risk processing and the requirement to maintain a Record of Processing Activities (RAT). Furthermore, the law regulates the voluntary 'Models of Prevention of Infringements' (MPI), which allow companies to certify their compliance programs to mitigate liability. The law also places strict controls on 'Sensitive Data,' including biometric and genetic information, which are frequently used in AI systems for identification or health analysis. Until the new law is fully active, the SERNAC and the Council for Transparency continue to provide interim oversight based on existing constitutional protections and sectoral privacy rules, ensuring that the transition period does not result in a protection vacuum for Chilean citizens.

Sector-Specific Rules

Sector-specific AI regulation in Chile is most advanced in the public sector and consumer markets. For public administration, Oficio Circular N° 711 and the CPLT’s Resolución Exenta N° 372 set strict transparency and ethical standards. Agencies must maintain registers of automated decision systems (SDA), provide plain-language explanations of algorithmic logic, and ensure human oversight for any system affecting citizen rights. In the realm of public procurement, Directiva N° 45 from ChileCompra provides specific recommendations for handling personal data in state contracts, requiring vendors to undergo security evaluations and adhere to data minimization principles when providing AI-driven services to the government. This directive is a landmark document for ensuring data sovereignty and preventing vendor lock-in. In the private sector, the financial and consumer services industries are subject to interpretative guidance from SERNAC. This guidance focuses on the prevention of algorithmic bias in credit scoring and the prohibition of discriminatory pricing models. Additionally, the Framework Law on Cybersecurity identifies 'essential services' across sectors such as health, energy, and telecommunications, subjecting AI systems used in these domains to enhanced risk management and incident reporting duties. While healthcare-specific AI laws are still evolving, the National AI Policy identifies health as a priority area for 'sandbox' experimentation, aiming to balance clinical innovation with patient safety and data confidentiality. The Commission for the Financial Market (CMF) is also drafting guidelines for the use of AI in algorithmic trading and risk assessment, ensuring that the financial system remains stable in the face of automated volatility.

International Alignment

Chile’s AI regulatory strategy is explicitly designed to harmonize with international standards, particularly those of the OECD and UNESCO. As an OECD member, Chile has integrated the OECD AI Principles—such as transparency, explainability, and accountability—into its National AI Policy and the pending AI Bill. The influence of the European Union’s AI Act is also highly visible in the risk-based architecture of Chile’s legislative proposals, which adopt similar definitions of AI systems and tiered categories of risk. This alignment is a strategic choice intended to facilitate digital trade and ensure that Chilean AI exports meet global compliance requirements. Furthermore, Chile has been a vocal participant in regional and global forums, such as the Santiago Declaration on AI in Latin America and the Caribbean, which promotes a regional approach to AI ethics. The country frequently references UNESCO’s Recommendation on the Ethics of Artificial Intelligence as a foundational text for its rights-based approach. Chile also participates in the 'Global Partnership on AI' (GPAI) and has strong bilateral agreements with the EU to facilitate data flows, provided that Chilean standards remain 'adequate' under GDPR. This international outlook extends to technical standards, with the government encouraging the adoption of ISO/IEC standards for AI risk management and quality assurance to ensure interoperability with global markets. By positioning itself as a reliable digital hub, Chile aims to attract foreign investment while ensuring that its domestic regulatory environment remains robust and respected on the world stage.

Future Developments

The most significant upcoming development is the expected passage and implementation of the 'Proyecto de Ley que regula los Sistemas de Inteligencia Artificial' (Boletín 16821-19). This bill will provide the definitive legal framework for AI in Chile, establishing the technical advisory bodies and the formal certification process for high-risk systems. Stakeholders are also closely watching the 2026 full entry into force of the Data Protection Law, which will trigger the active supervision of the new Data Protection Agency. This period is expected to see a flurry of secondary rulemaking, including decrees defining the technical specifications for AI impact assessments and the registration of automated systems. Additionally, Chile is exploring the frontier of 'neuro-rights,' with ongoing legislative discussions regarding the protection of mental privacy and the regulation of neurotechnology-AI interfaces. The government is also expected to launch more supervised 'regulatory sandboxes' to allow for the testing of AI innovations in the public sector under controlled conditions. As the ANCI becomes fully operational, new general instructions regarding AI-related cyber-incident reporting thresholds are anticipated. These developments signal a move toward a more granular and technically specific regulatory environment, where high-level principles are translated into enforceable technical standards and audit protocols. The government is also considering a 'National Registry of AI Systems' to track the deployment of high-risk models across the country, providing a centralized database for transparency and accountability. As the ecosystem matures, the focus will likely shift from foundational legislation to the practical challenges of algorithmic auditing and the mitigation of systemic biases in large-scale AI deployments.

Key Regulations

TitleTypeStatusYear
Law No. 21.719 — Personal Data Protection and Agency CreationActAwaiting Entry2024
Ley N° 21.663 — Ley Marco de CiberseguridadActIn Force2024
Proyecto de Ley que regula los Sistemas de Inteligencia ArtificialBillUnder Review2024
Decreto N° 12 — Update of the National AI PolicyDecreeIn Force2024
Resolución Exenta N° 372 — Algorithmic Transparency RecommendationsGuidelineAdopted2024
Oficio Circular N° 711 — Guidelines for AI in the Public SectorGuidelineIn Force2023
SERNAC Interpretative Circular on AI and Consumer ProtectionGuidelineIn Force2022
Directiva N° 45 — Personal Data in Public ProcurementGuidelineIn Force2025

Enforcement Bodies

AgencyMandateKey PowersWebsite
MinCienciaPolicy leadership and AI strategy coordinationPolicy drafting, advisory council managementhttps://www.minciencia.gob.cl
ANCINational cybersecurity oversightOIV designation, incident reporting, sanctionshttps://www.anci.gob.cl
SERNACConsumer rights protectionMarket surveillance, collective actions, guidelineshttps://www.sernac.cl
CPLTPublic transparency and data accessTransparency audits, algorithmic disclosure ruleshttps://www.consejotransparencia.cl

© Regulations.AI — created on 06-Jan-2026 using Gemini 3 Flash Preview