Colombia - AI Regulation (154/2024)
Statutory bill to define and regulate AI
Proyecto de Ley Estatutaria No.154 de 2024: Por la cual se define y regula la Inteligencia Artificial
Colombia
RAI-CO-NA-PDLENXX-2024This statutory bill (Cámara No. 154 de 2024) proposes a comprehensive legal framework to define, develop and regulate artificial intelligence (AI) in Colombia by aligning AI with human rights standards, amending parts of Law 1581 of 2012 (data protection), establishing risk‑based limits, transparency and accountability obligations for public and private actors, and creating institutional oversight mechanisms. Key measures include classification of high‑risk AI systems, impact assessments, registration/conformity requirements and sanctions for noncompliance. See primary sources: Cámara de Representantes – Audiencia Pública PLE 154/24C and Congreso Visible – Project summary.
Summary
Full article
Read full text ↗Overview
The Proyecto de Ley Estatutaria No.154 de 2024 is a comprehensive statutory initiative introduced in August 2024 that seeks to define "artificial intelligence" and regulate its lifecycle (research, design, development, deployment and decommissioning) while aligning AI activities with constitutional and international human rights standards. The bill aims to apply to public and private actors, Colombian and foreign providers operating within Colombia, and to amend provisions of Law 1581 of 2012 (data protection) where necessary. The legislative dossier, committee hearings and supporting documents are available through official Cámara de Representantes publications and legislative monitoring platforms. Key legislative milestones (radication, public hearings, committee ponencia) and the proposed text are available at the Cámara site and in the published committee gazette. For event materials and committee documents see Cámara – Audiencia Pública PLE 154/24C and for public summaries and monitoring see Congreso Visible.
Definitions
The bill proposes precise definitions to reduce legal uncertainty: "artificial intelligence" (covers algorithmic models, machine learning, deep learning architectures, expert systems and hybrid models); "AI system" (integrated components enabling data input, automated or semi‑automated outputs and continuous update mechanisms); "model provider" (entity that develops, trains or supplies models); "operator" (entity deploying or controlling model outputs); "data controller/processor" aligned with Law 1581 definitions; and categories such as "high‑risk AI" vs "low‑risk AI". These definitions determine obligations (e.g., DPIAs, registration, conformity assessment) and the scope of prohibitions or restrictions. The proposed text clarifies cross‑references to data protection terminology to ensure interoperability with existing privacy law.
Governance and Institutional Framework
The bill establishes a multi‑layered governance architecture combining existing national regulators and new coordination roles. It tasks the Comisión Primera (and other relevant standing committees) with legislative oversight and proposes assignment of operational roles to national authorities including the Superintendencia de Industria y Comercio (for data protection alignment and market surveillance), sectoral ministries (health, labor, defence, interior) for sector‑specific oversight, and a proposed national AI observatory or registry for monitoring models and aggregated risk metrics. The legislative materials and committee report discuss capacity‑building for regulators and interagency cooperation mechanisms to implement conformity assessment, incident reporting and public procurement controls. Relevant committee materials and the ponencia for first debate outline these institutional assignments and coordination mechanisms; see the Cámara event page and the ponencia published in the Gaceta of the Congreso. For official committee descriptions see Cámara – Audiencia Pública and the ponencia publication Imprenta Nacional / Gaceta.
Key Focus Areas
The bill emphasizes a risk‑based regulatory approach. Core focus areas include: (1) Human rights protection — explicit alignment with constitutional rights, non‑discrimination and due process; (2) Data protection and privacy — amendments to Law 1581 to require AI‑specific DPIAs, restrictions on certain data uses for training (sensitive data) and stronger consent/transparency regimes; (3) High‑risk classification — mandatory conformity assessment, external audits, pre‑deployment certification for systems affecting life, health, liberty, employment, credit, and public services; (4) Transparency and explainability — requirements for model cards, dataset documentation, provenance and labelling of synthetic media; (5) Security and robustness — obligations for cybersecurity, adversarial testing, patching and vulnerability disclosure; (6) Accountability, documentation and logging — obligations to retain technical documentation, logs and impact mitigation plans to enable audits and remedial actions; (7) Public sector limits — restrictions and stricter controls on automated decision‑making used in public administration and criminal justice; (8) Redress and liability — individual rights to contest automated decisions and administrative and civil remedies. These focus areas are discussed in the committee ponencia and public hearings materials. See Congreso Visible and the Cámara documentation at Cámara – PLE 154/24C.
Implementation Framework
The bill proposes staged obligations and graduated enforcement to balance innovation and rights protection: (a) immediate requirements for transparency, documentation and minimal security controls for providers and operators; (b) a medium term registry/conformity system for high‑risk AI requiring third‑party assessment and registration with the national observatory; (c) DPIA and stakeholder consultation duties prior to deployment of high‑risk systems; (d) sectoral guidance and technical standards developed by ministries in collaboration with the proposed national AI observatory and standardization bodies; and (e) special rules for SMEs/startups including simplified compliance paths and phased implementation to avoid stifling innovation. The committee report and explanatory notes discuss capacity building, model labelling, procurement rules and a transitional regime. For the committee’s implementation recommendations see the published ponencia and Comité materials: Imprenta Nacional / Gaceta (ponencia).
Monitoring and Evaluation
Monitoring relies on a public registry, periodic audits and market surveillance coordinated by existing supervisory agencies (notably the Superintendencia de Industria y Comercio) and a proposed national AI observatory to collect registry data, incident reports and performance metrics. The bill contemplates periodic public reporting, mandatory breach/incident notifications for AI systems that harm fundamental rights, and public transparency dashboards to track registered high‑risk systems and sanctions. The committee materials recommend indicators for evaluating coverage, compliance rates and rights impacts; these are to be published and reviewed regularly by the legislative committees. See committee sessions and public hearing records at Cámara – Audiencia Pública.
Penalties, Liability, and Appeals
The draft law contemplates administrative sanctions for noncompliance (fines, suspension or prohibition of operations), corrective orders, and civil liability channels for damages caused by AI systems, especially those classified as high‑risk; it also foresees procedural safeguards and administrative/judicial appeals against supervisory decisions. The ponencia and Gaceta describe a framework combining administrative enforcement by sectoral regulators with civil liability claims and obligations to provide restorative remedies for harmed individuals. Specific sanctioning ranges and mechanisms are addressed in the proposed articles and committee report. See Gaceta / Ponencia for the committee’s treatment of enforcement measures.
Relationship to Other Instruments
The bill explicitly references and proposes targeted amendments to Law 1581 of 2012 (Data Protection) to incorporate AI‑specific DPIAs and adapted consent/processing rules, while maintaining compatibility with the Constitution, existing sectoral laws (health, financial sector, labor, criminal procedure) and international human rights treaties to which Colombia is party. It aims to integrate existing supervisory structures (e.g., Superintendencias, sector ministries) rather than create numerous new enforcement agencies, while proposing a national AI observatory/registry for coordination. The bill’s explanatory notes and committee documents outline how it interacts with current privacy, consumer protection and administrative procedure law. See the project description at Congreso Visible.
International Alignment
The bill repeatedly cites international human rights standards and proposes alignment with global AI governance trends (risk‑based regulation, transparency, conformity assessment and documentation) and with soft law instruments (e.g., OECD AI Principles, UNESCO guidance) to enable cross‑border interoperability and facilitate trade in AI services. Committee discussions and expert hearings referenced international frameworks as normative guidance for defining high‑risk categories, labelling synthetic content and implementing DPIAs. The bill also contemplates cooperation with foreign regulators for cross‑border enforcement and data access under appropriate legal safeguards. See the bill’s explanatory and committee materials for international references and the Cámara’s hearing records at Cámara – Audiencia Pública.
Implementation Timeline
| Phase | Action | Indicative Deadline |
|---|---|---|
| Radication & Early Review | Radicated and initial committee hearings | 2024-08-06 (radication) |
| Committee Deliberation | Public hearings, ponencia for first debate | Sep–Oct 2024 (public hearing 2024-09-30; ponencia Oct 2024) |
| First Debate | Commission and plenary consideration | Indicative — during 2024–2025 legislative sessions |
| Secondary Rulemaking | Regulatory guidance and standards (ministries, observatory) | 6–18 months after enactment |
| Phased Compliance | SME simplified timelines; high‑risk registration & audits | 6–24 months after enactment |
Sources and References
| Source | Type |
|---|---|
| Cámara de Representantes — Audiencia pública PLE 154/24C (event page, documents) | Primary Source |
| Congreso Visible — Project profile and synopsis | Primary / Explanatory |
| Imprenta Nacional / Gaceta — Informe de ponencia positiva (Gaceta n.1694, Oct 2024) | Primary Source |
Requirements for a company
What an organisation has to do under Colombia - AI Regulation (154/2024), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.
Must do
15- Perform an AI-specific data protection impact assessment.Providers and operators of AI systems.
- Conduct a mandatory conformity assessment for high-risk AI systems.Providers of high-risk AI systems.
- Obtain pre-deployment certification for high-risk AI systems.Providers of high-risk AI systems.
- Register high-risk AI systems with the national observatory.Providers of high-risk AI systems.
- Notify authorities of breaches or incidents that harm fundamental rights.Providers and operators of AI systems.
- Provide restorative remedies for individuals harmed by AI systems.Providers and operators of AI systems.
- +9 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Colombia - AI Regulation (154/2024), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers and operators of AI systems. | Perform an AI-specific data protection impact assessment. “amendments to Law 1581 to require AI‑specific DPIAs” | Before deploying high-risk AI systems | — | Critical |
| 2 | Providers of high-risk AI systems. | Conduct a mandatory conformity assessment for high-risk AI systems. “mandatory conformity assessment, external audits, pre‑deployment certification for systems affecting life, health, liberty, employment, credit, and public services” | Before pre-deployment certification | — | Critical |
| 3 | Providers of high-risk AI systems. | Obtain pre-deployment certification for high-risk AI systems. “pre‑deployment certification for systems affecting life, health, liberty, employment, credit, and public services” | Before placing on market | — | Critical |
| 4 | Providers of high-risk AI systems. | Register high-risk AI systems with the national observatory. “a medium term registry/conformity system for high‑risk AI requiring third‑party assessment and registration with the national observatory” | 6-24 months after enactment | — | Critical |
| 5 | Providers and operators of AI systems. | Notify authorities of breaches or incidents that harm fundamental rights. “mandatory breach/incident notifications for AI systems that harm fundamental rights” | Upon discovery | — | Critical |
| 6 | Providers and operators of AI systems. | Provide restorative remedies for individuals harmed by AI systems. “obligations to provide restorative remedies for harmed individuals” | Upon harm | — | Critical |
| 7 | Model providers. | Restrict the use of sensitive data for AI system training. “restrictions on certain data uses for training (sensitive data)” | Before training AI systems | — | Important |
| 8 | Providers and operators of AI systems. | Implement stronger consent and transparency regimes for data processing. “stronger consent/transparency regimes” | Before deployment | — | Important |
| 9 | Providers of high-risk AI systems. | Undergo external audits for high-risk AI systems. “mandatory conformity assessment, external audits, pre‑deployment certification for systems affecting life, health, liberty, employment, credit, and public services” | Before pre-deployment certification | — | Important |
| 10 | Model providers. | Provide model cards for AI systems. “requirements for model cards, dataset documentation, provenance and labelling of synthetic media” | Before deployment | — | Important |
| 11 | Model providers. | Document datasets used for AI system development. “requirements for model cards, dataset documentation, provenance and labelling of synthetic media” | Before deployment | — | Important |
| 12 | Operators and publishers of AI systems. | Label synthetic media and provide provenance information. “provenance and labelling of synthetic media” | Before publishing synthetic media | — | Important |
| 13 | Providers and operators of AI systems. | Ensure cybersecurity for AI systems throughout their lifecycle. “obligations for cybersecurity, adversarial testing, patching and vulnerability disclosure” | Ongoing | — | Important |
| 14 | Providers and operators of AI systems. | Conduct adversarial testing for AI systems. “obligations for cybersecurity, adversarial testing, patching and vulnerability disclosure” | Before deployment | — | Important |
| 15 | Providers and operators of AI systems. | Retain technical documentation, logs, and impact mitigation plans. “obligations to retain technical documentation, logs and impact mitigation plans to enable audits and remedial actions” | Ongoing | — | Important |
Related Regulations
Por medio de la cual se regula la inteligencia artificial en Colombia para garantizar su desarrollo ético y responsable (Government bill, Senate 442/25)
Colombia94% similar
Por medio de la cual se define y regula la inteligencia artificial (Proyecto 200/23) (Bill to define and regulate AI)
Colombia94% similar
Proyecto 05/24: Ley de inteligencia artificial ética y sostenible para el bienestar social (Ethical and sustainable AI law proposal)
Colombia93% similar
By which the use of Artificial Intelligence in the management of Petitions, Complaints, Claims, Suggestions and Reports (PQRSD) in public entities of the Colombian State is regulated and implemented, and other provisions are issued (Proyecto de Ley No. 417 de 2025)
Colombia93% similar
Proyecto 255/24: Lineamientos de uso de IA para la disminución de siniestros viales (AI for road-accident reduction)
Colombia93% similar
© Regulations.AI · updated on 13-Jun-2026