Colombia - AI for Road Safety (255/2024)
Project 255/24: Guidelines for the Use of AI to Reduce Road Accidents
Proyecto 255/24: Lineamientos de uso de IA para la disminución de siniestros viales
Colombia
RAI-CO-NA-P2LDUXX-2024Proyecto de Ley 255 de 2024 (Senado) proposes guidelines for the use of artificial intelligence to reduce road accidents and associated costs by enabling real-time data collection, predictive risk analysis, and alerting systems. It sets governance roles for national and territorial authorities, data and cybersecurity safeguards, and obligations for registration, human oversight and impact assessment prior to deployment.
Summary
Proyecto de Ley 255 de 2024 (Senate) is a legislative initiative introduced on March 13, 2024, by Senator Guido Echeverri Piedrahita with support from Representative Hernando González that aims to create a regulatory framework of guidelines for the use of Artificial Intelligence (AI) to prevent and reduce road traffic accidents (siniestros viales) in Colombia. The bill seeks to harness AI capabilities — including sensor networks, data integration, predictive analytics, and real-time alerting to drivers, pedestrians and authorities — to improve road safety outcomes while controlling costs associated with medical treatment, insurance, and economic loss. The project identifies state actors (e.g., Agencia Nacional de Seguridad Vial, Ministry of Transport, Dirección de Tránsito y Transporte de la Policía Nacional, and municipal traffic authorities) as primary implementers and beneficiaries of AI systems and proposes rules on data collection, processing, storage, transparency, human oversight and accountability.
Key structural elements of the bill include: mandatory impact assessments and conformity checks for AI systems that are safety-critical or used in public road management; data protection and privacy safeguards aligned with national standards for personal data processing; cybersecurity and model security requirements to ensure resilience of sensor networks and AI decision-support systems; transparency and record-keeping obligations (logging, explainability summaries, public reporting of performance metrics and incidents); and provisions on liability, sanctions and remedy mechanisms when AI systems are implemented negligently or cause harm. The bill emphasizes non-discrimination, respect for fundamental rights, and the need to avoid fully automated punitive enforcement actions without human review.
Operational requirements described in the draft include: (i) registration or notification of deployed AI systems to a designated national registry or authority; (ii) periodic safety testing and third-party evaluation for high-risk AI deployments affecting traffic management or automated interventions; (iii) deployment of human-in-the-loop oversight when decisions affect legal or life-safety outcomes; (iv) interoperability and standards for sensor data and alerts to enable multi-agency coordination; and (v) public communication strategies and pilot program authorization for testing new AI tools. The project contemplates penalties such as administrative fines, suspension of systems, mandatory remediation measures and potential referral to judicial authorities when criminal negligence is suspected.
The bill has been discussed in the Senate’s Sixth Commission, with reports (informes de ponencia) published for first and second debate during 2024 and with support from academic institutions (University Nacional—Manizales) and sector experts. Official press material and legislative tracking entries record the project’s objectives, sponsors and procedural milestones. If adopted, Proyecto 255 would be among Colombia’s sector-specific AI regulatory efforts addressing safety-critical uses of AI in public infrastructure and transport governance. The initiative aims to balance innovation in AI-enabled road safety with safeguards for privacy, model robustness, transparency and clear accountability structures.
Full article
Read full text ↗Overview
Proyecto de Ley No. 255 de 2024 (Senado) was filed on 13 March 2024 and proposes operational and governance lineamientos for the use of Artificial Intelligence (AI) to reduce road traffic accidents and their socio-economic costs in Colombia. The initiative positions AI as a tool for automated collection and analysis of sensor and incident data, predictive risk modeling, and real-time alerting to drivers, pedestrians and authorities. The bill frames its objectives around improving prevention, detection and management of road incidents while limiting negative impacts on privacy and fundamental rights. Official Senate coverage and legislative summaries describe the project’s sponsors and the public-sector actors to be involved — notably the Senate press release (March 21, 2024) and a technical synopsis published by Congreso Visible / Uniandes.
Definitions
The bill defines key terms to delimit scope and obligations. Important definitions include: "Artificial Intelligence (AI) systems" (software systems that perform tasks by processing data and generating predictions, classifications or recommendations); "safety-critical AI" (systems whose malfunction could lead to serious harm to persons or property, e.g., traffic-control automation or automated vehicle interventions); "real-time alerting" (systems that process live data streams and issue immediate notifications to road users or authorities); "personal data" and "sensitive data" (as per Colombia's data protection regime); "human-in-the-loop" (operational models requiring human review before enforcement or life-safety decisions); "operator" (entity deploying or controlling an AI system); and "incident" (any event classified as a traffic accident, near-miss, or hazard detected or predicted by the AI).
Governance and Institutional Framework
The project assigns roles to national and territorial institutions with road-safety mandates. Primary institutional actors named in the bill include the Agencia Nacional de Seguridad Vial (ANSV), the Ministry of Transport">Ministry of Transport and the Dirección de Tránsito y Transporte de la Policía Nacional. The bill contemplates an inter-institutional coordination mechanism and designates a lead regulatory authority (or joint secretariat) responsible for: (i) maintaining a registry of deployed AI systems for road safety; (ii) issuing technical guidelines and minimum standards for safety testing, data governance and cybersecurity; (iii) coordinating pilot programs between central and territorial governments; and (iv) receiving reports of incidents and overseeing enforcement actions. The draft further envisages cooperation with academia and technical experts (e.g., Universidad Nacional sede Manizales) to define validation methodologies and evaluation frameworks. These governance arrangements are described in legislative ponencias published by the Senate commission process and are intended to avoid fragmented local rules while allowing territorial adaptation. See the Senate commission first- and second-debate reports for procedural details and institutional assignments (Congreso Visible and vLex - informe de ponencia).
Key Focus Areas
The bill’s substantive provisions cluster around several focus areas. First, data governance: standards for lawful collection (including what sensor and mobility data may be gathered), retention limits, pseudonymization/anonymization and permitted sharing with public bodies, researchers and third-party evaluators. Second, risk and safety management: mandatory safety impact assessments (SIA) and risk mitigation plans before deployment, and continuous monitoring obligations with defined trigger thresholds for system downgrades or suspension. Third, transparency and accountability: public registries, model cards or technical summaries describing system purpose, performance metrics, known limitations and the human oversight model. Fourth, conformity, testing and certification: requirements for pre-deployment testing in controlled environments and for periodic third-party audits of high-risk systems. Fifth, cybersecurity and model security: minimum technical controls for sensor integrity, secure telemetry, cryptographic protections and incident response plans. Sixth, privacy and fundamental rights: procedures to prevent discriminatory profiling, safeguards for sensitive personal data (e.g., health status following accidents) and channels for affected persons to request explanations and remedies. Seventh, operational coordination: protocols for multi-agency alerting, interoperability standards for sensor networks and mechanisms for localized pilot projects and scaling after evaluation. These themes are articulated across the project's articles and the accompanying commission reports (vLex - informe de ponencia (first debate)).
Implementation Framework
Practical implementation envisioned by the bill proceeds in stages: (1) Registry and notification — Operators must notify/register AI systems with the lead authority and provide technical documentation, data flow diagrams, and the SIA; (2) Pilot certification — New technologies qualify for time-limited pilots under strict monitoring with predefined evaluation metrics and public disclosure requirements; (3) Validation and conformity — High-risk systems require independent testing laboratories or accredited conformity assessment entities to validate model safety and performance against specified benchmarks; (4) Deployment with human oversight — For systems producing potentially enforceable outcomes or life-safety actions, the bill mandates human-in-the-loop review or human-on-the-loop monitoring and explicit escalation procedures; (5) Operations and monitoring — Continuous logging, anomaly detection, periodic re-evaluation and an incident reporting channel to the lead authority; and (6) Decommissioning and data erasure — Sunset or retirement processes with secure deletion of personal data when no longer needed. The implementation framework assigns responsibilities across national and territorial actors and anticipates technical guidance documents to be issued by the competent agencies after the law’s adoption.
Monitoring and Evaluation
Monitoring mechanisms combine technical, administrative and public-reporting tracks. The lead agency must operate a central dashboard consolidating key performance indicators (KPIs): accident reduction metrics, false-positive/false-negative rates for predictive alerts, mean time to remediate vulnerabilities, and incident frequency. Independent periodic audits and open aggregate reports are required to ensure transparency. The bill proposes a feedback loop enabling adaptation of algorithms, retraining regimes and updates to safety thresholds based on operational evidence. Academic partnerships and data-sharing arrangements for approved research are explicitly encouraged to create an evidence base for policy refinement and to inform national road-safety strategies.
Penalties, Liability, and Appeals
The draft contemplates administrative enforcement measures and penalties for non-compliance. Typical sanctions include graduated administrative fines, orders to suspend or deactivate non-compliant AI systems, mandatory corrective plans, public disclosure of violations, and potential referral to judicial authorities where criminal negligence or willful misconduct is alleged. The bill also outlines civil liability pathways for victims harmed by negligent deployment or insufficient oversight, including obligations for operators to maintain proof of conformity, insurance requirements for certain high-risk systems, and administrative appeal channels to contest sanctions before the designated authority. Remediation, restitution and access to explanations for affected persons are foreseen as remedies.
Relationship to Other Instruments
Proyecto 255 is designed to complement existing Colombian legal frameworks rather than replace them. It intersects with the Personal Data Protection Law (Ley 1581/2012), sectoral transport law and police traffic regulations; it also touches obligations under procurement and public contracting rules when public entities procure AI systems. The bill anticipates harmonization with national cybersecurity law and with any future horizontal AI governance frameworks. Coordination clauses require that AI systems used by the police, health services or emergency response follow applicable confidentiality and evidentiary rules, especially when data may be used in judicial or administrative enforcement actions.
International Alignment
The project references global best practices for safe deployment of AI in safety-critical settings and aligns with emerging international guidance on trustworthy AI: risk-based regulation, impact assessments, human oversight, and third-party conformity assessment. By adopting conformity-assessment and documentation regimes, the bill aims for interoperability with foreign certification practices and for Colombia to comply with cross-border data-sharing agreements for research. The initiative positions Colombia to engage with international road-safety and AI governance fora and to accept technical cooperation with academic partners and international standard-setting organizations.
Implementation Timeline
| Phase | Estimated Timeline | Key Activities |
|---|---|---|
| Filing and Commission Review | Mar–Aug 2024 | Radication, commission ponencias, first/second debate reports (registered 13 March 2024; commission activity reported in April–June 2024). |
| Promulgation and Rulemaking | 0–12 months after enactment | Lead authority issues registries, technical guidance, conformity assessment procedures and pilot frameworks. |
| Pilot Phase | 6–18 months | Time-limited pilot programs, monitored KPIs, independent evaluation and public reporting. |
| Full Deployment | 18–36 months | Scaled deployments after certification and satisfactory pilot results; ongoing audits and reporting. |
Sources and References
| Source | Type |
|---|---|
| Senate press release: 'Senador Guido Echeverri radica proyecto...' | Primary Source |
| Congreso Visible / Uniandes project summary | Primary Source |
| vLex: Informe de ponencia para segundo debate (02 Aug 2024) | Primary Source |
Requirements for a company
What an organisation has to do under Colombia - AI for Road Safety (255/2024), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.
Must do
14- Notify and register AI systems with the lead authority.Operators of AI systems for road safety.
- Complete mandatory safety impact assessments before deployment.Operators of AI systems for road safety.
- Develop and implement risk mitigation plans.Operators of AI systems for road safety.
- Obtain independent conformity assessment for high-risk systems.Operators of high-risk AI systems for road safety.
- Mandate human-in-the-loop review for enforceable outcomes or life-safety actions.Operators of AI systems producing enforceable outcomes or life-safety actions.
- Apply data minimization, pseudonymization, and retention limits to personal data.Operators of AI systems processing personal data.
- +8 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Colombia - AI for Road Safety (255/2024), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Operators of AI systems for road safety. | Notify and register AI systems with the lead authority. “Operators must notify/register AI systems with the lead authority and provide technical documentation, data flow diagrams, and the SIA” | Before deployment | — | Critical |
| 2 | Operators of AI systems for road safety. | Complete mandatory safety impact assessments before deployment. “mandatory safety impact assessments (SIA) and risk mitigation plans before deployment” | Before deployment | — | Critical |
| 3 | Operators of AI systems for road safety. | Develop and implement risk mitigation plans. “mandatory safety impact assessments (SIA) and risk mitigation plans before deployment” | Before deployment | — | Critical |
| 4 | Operators of high-risk AI systems for road safety. | Obtain independent conformity assessment for high-risk systems. “High-risk systems require independent testing laboratories or accredited conformity assessment entities to validate model safety and performance” | Before deployment | — | Critical |
| 5 | Operators of AI systems producing enforceable outcomes or life-safety actions. | Mandate human-in-the-loop review for enforceable outcomes or life-safety actions. “For systems producing enforceable outcomes or life-safety actions, the bill mandates human-in-the-loop review or human-on-the-loop monitoring” | Before deployment and continuously | — | Critical |
| 6 | Operators of AI systems processing personal data. | Apply data minimization, pseudonymization, and retention limits to personal data. “standards for lawful collection... retention limits, pseudonymization/anonymization and permitted sharing with public bodies” | Continuous | — | Critical |
| 7 | Operators of AI systems for road safety. | Implement minimum technical controls for sensor integrity, secure telemetry, and incident response. “minimum technical controls for sensor integrity, secure telemetry, cryptographic protections and incident response plans.” | Before deployment and continuously | — | Critical |
| 8 | Operators of AI systems for road safety. | Conduct continuous monitoring, anomaly detection, and report incidents to the lead authority. “Continuous logging, anomaly detection, periodic re-evaluation and an incident reporting channel to the lead authority” | Continuous | — | Critical |
| 9 | Operators of AI systems processing personal data. | Establish procedures to prevent discriminatory profiling and safeguard sensitive personal data. “procedures to prevent discriminatory profiling, safeguards for sensitive personal data (e.g., health status following accidents)” | Before deployment and continuously | — | Critical |
| 10 | Operators of certain high-risk AI systems. | Maintain proof of conformity and insurance for certain high-risk systems. “obligations for operators to maintain proof of conformity, insurance requirements for certain high-risk systems” | Continuous | — | Critical |
| 11 | Operators of AI systems for road safety. | Provide technical documentation, data flow diagrams, and the SIA to the lead authority. “Operators must notify/register AI systems with the lead authority and provide technical documentation, data flow diagrams, and the SIA” | Before deployment | — | Important |
| 12 | Operators of AI systems for road safety. | Publish non-sensitive model cards, performance reports, and incident summaries. “public registries, model cards or technical summaries describing system purpose, performance metrics, known limitations and the human oversight model.” | Before deployment and continuously | — | Important |
| 13 | Operators participating in pilot programs for new AI technologies. | Adhere to strict monitoring, evaluation metrics, and public disclosure for pilot programs. “New technologies qualify for time-limited pilots under strict monitoring with predefined evaluation metrics and public disclosure requirements” | During pilot phase | — | Important |
| 14 | Operators of AI systems for road safety. | Securely delete personal data during decommissioning when no longer needed. “Sunset or retirement processes with secure deletion of personal data when no longer needed.” | Upon decommissioning or when data is no longer needed | — | Important |
Related Regulations
Proyecto de Ley Estatutaria No.154 de 2024: Por la cual se define y regula la Inteligencia Artificial (Statutory bill to define and regulate AI)
Colombia93% similar
By which the use of Artificial Intelligence in the management of Petitions, Complaints, Claims, Suggestions and Reports (PQRSD) in public entities of the Colombian State is regulated and implemented, and other provisions are issued (Proyecto de Ley No. 417 de 2025)
Colombia92% similar
Por medio de la cual se regula la inteligencia artificial en Colombia para garantizar su desarrollo ético y responsable (Government bill, Senate 442/25)
Colombia92% similar
Proyecto 05/24: Ley de inteligencia artificial ética y sostenible para el bienestar social (Ethical and sustainable AI law proposal)
Colombia92% similar
Por medio de la cual se define y regula la inteligencia artificial (Proyecto 200/23) (Bill to define and regulate AI)
Colombia91% similar
© Regulations.AI · updated on 13-Jun-2026