Colombia - Ethical AI Law Proposal (PL 005/2024C)

Project 05/24: Law on Ethical and Sustainable Artificial Intelligence for Social Welfare

Proyecto 05/24: Ley de inteligencia artificial ética y sostenible para el bienestar social

Colombia

RAI-CO-NA-P0LDIXX-2024
Stalled(Stalled)
BillGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

Proyecto 05/24 (PL 005/2024C) proposed a comprehensive, principle-based regulatory framework for the development, deployment and use of artificial intelligence in Colombia, prioritizing ethics, sustainability and social welfare. The bill (radicated 2024-07-20) introduced requirements for privacy protection, human oversight, transparency, risk-based conformity and measures to protect children and vulnerable groups; the legislative process was archived in mid-2025.

Summary

Proyecto 05/24 (registered in the Cámara as PL 005/2024C) is a parliamentary initiative titled “Ley de inteligencia artificial ética y sostenible para el bienestar social” that sought to create a national legal framework for artificial intelligence emphasizing ethical design, sustainability and protection of citizens’ rights. Radicated on July 20, 2024, by a group of representatives (including Olga Lucía Velásquez Nieto, Gloria Liliana Rodríguez Valencia, Jaime Raúl Salamanca Torres, Wilmer Yair Castellanos Hernández and María del Mar Pizarro García), the bill framed AI governance around human-centered principles and public-interest safeguards. The project text and summary (published on the Cámara website and catalogued by legislative trackers such as Congreso Visible and academic repositories) describe objectives including: protection of fundamental rights (privacy, nondiscrimination, freedom of expression), gender and child protection, reduced digital divides, environmental sustainability of AI systems (including lifecycle and obsolescence management), and cybersecurity requirements.

Substantively, Proyecto 05/24 proposed a tiered, risk-based approach to obligations: higher-risk AI systems (those affecting healthcare, social services, employment, public safety, biometric identification and core democratic processes) would be subject to stricter procedural safeguards — mandatory impact assessments (ethical and data protection impact assessments), pre-deployment conformity checks, registration or notice to competent authorities, and mandatory documentation and audit trails. The bill emphasizes transparency obligations for AI developers and deployers: documentation of data sources, model provenance, explanation of automated decisions to affected individuals, and clear labeling when content is synthetic. It also proposed institutional governance mechanisms: inter-agency coordination (placing oversight responsibilities with relevant ministries and supervisory agencies), creation or designation of a national AI oversight body or registry, and mechanisms for public consultations and multi-stakeholder participation.

On data protection and privacy, the draft expressly references compliance with Colombia’s personal data regime (Law 1581/2012) and positions the Superintendence of Industry and Commerce (SIC) and other competent authorities as actors for enforcement of privacy-related duties. Cybersecurity and model-security obligations — for example, logging, penetration testing, and adversarial robustness measures — were included as baseline requirements, together with provisions for sustainability (energy-efficiency reporting, management of hardware/software obsolescence, and circular procurement practices in public contracting).

Accountability and remedies are core features: the bill envisions recordkeeping, incident-reporting channels, user redress mechanisms and rights to contest automated decisions; it contemplates administrative enforcement measures and sanctions for non-compliance (administrative fines, suspension of operation, corrective orders) and preserves civil liability routes. The project advanced through Comisión Sexta and had a positive ponencia for first debate (published 2024-11-22) but was archived at the transit of legislature in June 2025 (status: archived). Key documentation is accessible on the Cámara project page and on curated legislative trackers (see official sources). The project’s approach aligns with international ethical AI frameworks (including UNESCO policy instruments and risk-based EU approaches) and seeks to combine rights-protective rules with innovation-friendly implementation via institutional coordination and capacity-building measures.

Note on status: the instrument was archived (transit of legislature June 2025) and therefore did not become law in its presented form. The official parliamentary pages and institutional repositories provide the authoritative record of the proposal and its procedural history.

Full article

Read full text ↗

Overview

Proyecto 05/24 (PL 005/2024C) — "Ley de inteligencia artificial ética y sostenible para el bienestar social" — was presented to the Colombian Cámara of Representatives on 20 July 2024. Its stated aim was to establish a principle-based regulatory framework governing development and use of artificial intelligence in Colombia, with a specific emphasis on human rights protection, environmental sustainability, and social welfare. The Cámara of Representatives maintains an official project page for the bill and basic procedural metadata; see the Cámara project record and the Universidad de los Andes / Congreso Visible dossier for legislative timeline details. The proposal advanced through the Comisión Sexta (Constitutional) and a positive ponencia for first debate was published on 22 November 2024. The draft proposes a tiered, risk-sensitive regime that combines documentation and transparency obligations, data-protection safeguards, mandatory risk assessments for high-impact systems, cybersecurity measures, and institutional arrangements for oversight and enforcement. For primary project records, consult the Cámara project page at Cámara - Ley de Inteligencia Artificial Ética and the legislative tracker at Congreso Visible - Project 05/24.

Definitions

The bill establishes definitions to ensure legal clarity. Key terms include: "artificial intelligence" (a system that, given a set of human-defined objectives, generates outputs such as content, predictions, recommendations or decisions influencing environments or human actors), "AI system developer", "provider/operator", "high-risk AI system" (systems with significant potential to affect fundamental rights, health, safety, or socioeconomic status), "data controller/processor" (aligned with Law 1581/2012), "explainability" (the capacity to provide meaningful information about model logic and outputs), and "sustainability" (environmental and lifecycle obligations including obsolescence management). The bill’s definitions create the baseline for obligations, conformity processes and enforcement actions outlined in later sections.

Governance and Institutional Framework

The draft creates an institutional architecture for AI oversight that combines sectoral, horizontal, and advisory roles. It envisions coordination among the Ministry of Science, Technology and Innovation (Minciencias), the Ministry of Information Technologies and Communications (MinTIC), the Superintendence of Industry and Commerce (SIC) for data protection and consumer protection, and the Agencia Nacional Digital (AND) for public-sector digital transformation and interoperability. The bill contemplates either (a) designation of an existing agency as the national AI oversight coordinator or (b) establishment of an inter-agency council to manage registration, high-risk system review, public consultations, capacity building and international cooperation. Institutional duties include maintaining registries of high-risk systems, issuing technical guidelines and conformity frameworks, operating complaint and redress channels, and coordinating market surveillance and enforcement actions.

Key Focus Areas

The project concentrates on several core areas: (1) Rights protection and nondiscrimination — ensuring AI respects constitutional rights and mitigates algorithmic bias; (2) Data protection and privacy — requiring adherence to Law 1581/2012 and privacy impact assessments where relevant; (3) Transparency and explainability — obliging providers to disclose system capabilities, limitations and data provenance and to label synthetic content; (4) Risk management — mandatory risk classification, pre-deployment impact assessments, and continuous post-deployment monitoring for high-risk systems; (5) Safety, testing and conformity — standardized testing, third-party audits and technical conformity checks; (6) Cybersecurity and model-security — baseline requirements for secure development, logging and vulnerability management; (7) Environmental sustainability — lifecycle disclosures, energy consumption reporting, and obligations on obsolescence management in public procurement; and (8) Access and inclusion — measures to reduce the digital divide and promote gender- and child-sensitive protections.

Implementation Framework

The draft defines phased implementation sequenced by risk and sector. Low-risk systems would face light-touch obligations (transparency and documentation), whereas high-risk systems would be subject to mandatory impact assessments, conformity assessment or registration, and periodic audits. Obligations rest primarily on developers/providers and public-sector procurers. The bill proposes guidance documents and implementation roadmaps to be issued by coordinating agencies, capacity-building programs for public actors, and a central registry for high-risk systems to enable market surveillance. Public procurement rules would be adapted to require sustainability and ethics criteria for AI acquisitions by state entities.

Monitoring and Evaluation

Monitoring mechanisms include periodic reporting by regulated entities, a national registry of high-risk AI systems for sampling and inspection, incident and harm reporting channels, and requirements for independent or third-party audits in specified cases. The oversight body or council is required to publish yearly enforcement and impact reports, and to update risk taxonomies and technical standards in light of technological evolution. The bill promotes participatory monitoring involving civil society, academia and affected communities to ensure responsive evaluation of social impacts and policy coherence.

Penalties, Liability, and Appeals

The draft contemplates administrative sanctions (corrective orders, fines, temporary suspension of systems, and orders to withdraw noncompliant services) and preserves civil liability claims for harm caused by AI systems. It also defines internal appeals and administrative review processes for sanctioned parties and protects procedural due process. Sanctions are calibrated according to the severity of harm and the culpability of the operator, and the bill foresees remedial obligations (product fixes, public notifications, remediation funds for affected individuals) alongside enforcement actions. Criminal penalties are not central in the text but may apply where existing criminal laws are implicated (e.g., fraud, privacy breaches with aggravated circumstances).

Relationship to Other Instruments

The proposal explicitly links to domestic instruments — notably Colombia’s data protection regime (Law 1581/2012) and consumer protection law — and to international commitments and standards. It recommends alignment with global ethical AI guidance, interoperability standards, and cross-border cooperation for enforcement and certification. The bill is drafted to be complementary to sectoral regulation (health, finance, telecommunications) while providing horizontal safeguards and baseline obligations for AI across sectors.

International Alignment

The project references international frameworks and instruments as models and points of alignment — for example, ethical AI recommendations from UNESCO and risk-based approaches similar to the European Union’s AI Act. The text signals intent to coordinate with foreign regulators and international organizations for capacity building, mutual recognition of conformity assessments and exchange of best practices. The Colombian Ministry responsible for science and technology and the diplomatic apparatus were expected to coordinate international cooperation to facilitate alignment and technical assistance.

Implementation Timeline

StepTarget DateNotes
Radication2024-07-20Project filed in Cámara (PL 005/2024C).
Ponencia / First debate2024-11-22Positive ponencia for first debate published by Comisión Sexta.
Inter-agency guidelines issuancePlanned within 6-12 months of enactmentSequence: risk taxonomy, registry specs, conformity guidance.
Phased compliance for high-risk systems12-24 months after enactmentTime for capacity building and registries.
Archiving of the bill2025-06-20Archived at transit of legislature; project not enacted in current form.

Sources and References

SourceType
Cámara de Representantes — Ley de Inteligencia Artificial Ética (Project record PL 005/2024C)Primary Source
Congreso Visible — Project 05/24 dossierPrimary Source (legislative tracker)
Universidad de los Andes — Algorithms / Regulation repositorySecondary/Repository

Requirements for a company

What an organisation has to do under Colombia - Ethical AI Law Proposal (PL 005/2024C), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Stalled). These requirements apply once the instrument takes effect and may change before then.

Must do

15
  • Mitigate algorithmic bias in AI systems.Developers and providers of AI systems.
  • Adhere to Law 1581/2012 for personal data protection.All entities developing or using AI systems.
  • Conduct privacy impact assessments for AI systems where relevant.Entities developing or using AI systems.
  • Classify AI systems based on their potential risk level.Developers and providers of AI systems.
  • Conduct pre-deployment impact assessments for high-risk AI systems.Developers and providers of high-risk AI systems.
  • Continuously monitor high-risk AI systems after deployment.Providers of high-risk AI systems.
  • +9 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Colombia - Ethical AI Law Proposal (PL 005/2024C), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Developers and providers of AI systems.Mitigate algorithmic bias in AI systems.
ensuring AI respects constitutional rights and mitigates algorithmic bias
Critical
2All entities developing or using AI systems.Adhere to Law 1581/2012 for personal data protection.
requiring adherence to Law 1581/2012
Critical
3Entities developing or using AI systems.Conduct privacy impact assessments for AI systems where relevant.
privacy impact assessments where relevant
Critical
4Developers and providers of AI systems.Classify AI systems based on their potential risk level.
mandatory risk classification
Critical
5Developers and providers of high-risk AI systems.Conduct pre-deployment impact assessments for high-risk AI systems.
pre-deployment impact assessments... for high-risk systems
Critical
6Providers of high-risk AI systems.Continuously monitor high-risk AI systems after deployment.
continuous post-deployment monitoring for high-risk systems
Critical
7Developers and providers of high-risk AI systems.Register high-risk AI systems with the national oversight body.
mandatory... registration
Critical
8Developers and providers of AI systems.Implement baseline cybersecurity measures for AI system development and operation.
baseline requirements for secure development, logging and vulnerability management
Critical
9Regulated entities using AI systems.Report incidents and harms caused by AI systems.
incident and harm reporting channels
Critical
10Providers of AI systems.Disclose AI system capabilities, limitations, and data provenance.
obliging providers to disclose system capabilities, limitations and data provenance
Critical
11Providers of AI systems.Label synthetic content generated by AI systems.
to label synthetic content
Critical
12Developers and providers of AI systems.Perform standardized testing and technical conformity checks for AI systems.
standardized testing, third-party audits and technical conformity checks
Critical
13Public sector procurers of AI systems.Include sustainability and ethics criteria in public AI procurement.
require sustainability and ethics criteria for AI acquisitions by state entities
Critical
14Developers and providers of AI systems.Implement measures to protect children and vulnerable groups from AI risks.
promote gender- and child-sensitive protections
Critical
15Developers and providers of low-risk AI systems.Maintain documentation for low-risk AI systems.
light-touch obligations (transparency and documentation)
Important

© Regulations.AI · updated on 13-Jun-2026