Colombia - AI Regulation (154/2024)

Statutory bill to define and regulate AI

Proyecto de Ley Estatutaria No.154 de 2024: Por la cual se define y regula la Inteligencia Artificial

Colombia

RAI-CO-NA-PDLENXX-2024
Under Review(Under Review)
BillGovernance and OversightRisk ManagementData Protection and Privacy
Export PDF

This statutory bill (Cámara No. 154 de 2024) proposes a comprehensive legal framework to define, develop and regulate artificial intelligence (AI) in Colombia by aligning AI with human rights standards, amending parts of Law 1581 of 2012 (data protection), establishing risk‑based limits, transparency and accountability obligations for public and private actors, and creating institutional oversight mechanisms. Key measures include classification of high‑risk AI systems, impact assessments, registration/conformity requirements and sanctions for noncompliance. See primary sources: Cámara de Representantes – Audiencia Pública PLE 154/24C and Congreso Visible – Project summary.

Summary

Proyecto de Ley Estatutaria No. 154 de 2024 (Cámara) is a proposed statutory bill introduced in August 2024 by representatives including Alirio Uribe Muñoz and Karyme Cotes Martínez that seeks to define, regulate and set limits on the development, deployment and use of artificial intelligence (AI) in Colombia. The bill frames AI as a socio‑technical area requiring alignment with constitutional and international human rights standards and proposes amendments to existing data protection law (Law 1581 of 2012) to ensure compatibility with AI practices. Core policy pillars are (1) definitions and scope to capture algorithmic systems, models and ecosystems that process data and automate or assist decision‑making; (2) a risk‑based approach that distinguishes ordinary uses from "high‑risk" AI systems that may affect fundamental rights (e.g., biometric identification, health, justice, employment, credit and social services), subjecting the latter to stricter oversight, mandatory impact assessments and conformity procedures; (3) transparency and disclosure duties including labelling of synthetic content, provenance records for models and human‑interpretable explanations where automated decisions materially affect individuals; (4) governance and institutional design that assigns oversight roles to national agencies, coordinates capacity building across ministries, and creates registration, monitoring and market surveillance mechanisms; (5) mandates for security, auditability and documentation — including model cards, datasets registries, logging, and incident reporting — to support accountability, audits and independent evaluation; (6) requirements to perform Data Protection Impact Assessments (DPIAs) and specific adjustments to Law 1581 to reflect AI‑specific processing risks; (7) obligations on public procurement and use of AI by public authorities; and (8) enforcement tools ranging from administrative sanctions and corrective orders to civil liability and mechanisms for judicial and administrative redress. The bill emphasizes protecting fundamental rights and encourages innovation by proposing scaled obligations (lighter for SMEs/innovators) while reserving prohibitions or strict controls for uses that produce unacceptable human rights risks. The bill has been considered in the Cámara's Comisión Primera with public hearings (e.g., 30 September 2024) and a positive committee report for first debate was issued in October 2024; it remains under review in the legislative process. Primary references and legislative materials are published by the Cámara de Representantes and included in public legislative gazettes. See: Cámara – Audiencia PLE 154/24C, Congreso Visible, and the committee gazette/performance report: Imprenta Nacional / Gaceta (ponencia).

Full article

Read full text ↗

Overview

The Proyecto de Ley Estatutaria No.154 de 2024 is a comprehensive statutory initiative introduced in August 2024 that seeks to define "artificial intelligence" and regulate its lifecycle (research, design, development, deployment and decommissioning) while aligning AI activities with constitutional and international human rights standards. The bill aims to apply to public and private actors, Colombian and foreign providers operating within Colombia, and to amend provisions of Law 1581 of 2012 (data protection) where necessary. The legislative dossier, committee hearings and supporting documents are available through official Cámara de Representantes publications and legislative monitoring platforms. Key legislative milestones (radication, public hearings, committee ponencia) and the proposed text are available at the Cámara site and in the published committee gazette. For event materials and committee documents see Cámara – Audiencia Pública PLE 154/24C and for public summaries and monitoring see Congreso Visible.

Definitions

The bill proposes precise definitions to reduce legal uncertainty: "artificial intelligence" (covers algorithmic models, machine learning, deep learning architectures, expert systems and hybrid models); "AI system" (integrated components enabling data input, automated or semi‑automated outputs and continuous update mechanisms); "model provider" (entity that develops, trains or supplies models); "operator" (entity deploying or controlling model outputs); "data controller/processor" aligned with Law 1581 definitions; and categories such as "high‑risk AI" vs "low‑risk AI". These definitions determine obligations (e.g., DPIAs, registration, conformity assessment) and the scope of prohibitions or restrictions. The proposed text clarifies cross‑references to data protection terminology to ensure interoperability with existing privacy law.

Governance and Institutional Framework

The bill establishes a multi‑layered governance architecture combining existing national regulators and new coordination roles. It tasks the Comisión Primera (and other relevant standing committees) with legislative oversight and proposes assignment of operational roles to national authorities including the Superintendencia de Industria y Comercio (for data protection alignment and market surveillance), sectoral ministries (health, labor, defence, interior) for sector‑specific oversight, and a proposed national AI observatory or registry for monitoring models and aggregated risk metrics. The legislative materials and committee report discuss capacity‑building for regulators and interagency cooperation mechanisms to implement conformity assessment, incident reporting and public procurement controls. Relevant committee materials and the ponencia for first debate outline these institutional assignments and coordination mechanisms; see the Cámara event page and the ponencia published in the Gaceta of the Congreso. For official committee descriptions see Cámara – Audiencia Pública and the ponencia publication Imprenta Nacional / Gaceta.

Key Focus Areas

The bill emphasizes a risk‑based regulatory approach. Core focus areas include: (1) Human rights protection — explicit alignment with constitutional rights, non‑discrimination and due process; (2) Data protection and privacy — amendments to Law 1581 to require AI‑specific DPIAs, restrictions on certain data uses for training (sensitive data) and stronger consent/transparency regimes; (3) High‑risk classification — mandatory conformity assessment, external audits, pre‑deployment certification for systems affecting life, health, liberty, employment, credit, and public services; (4) Transparency and explainability — requirements for model cards, dataset documentation, provenance and labelling of synthetic media; (5) Security and robustness — obligations for cybersecurity, adversarial testing, patching and vulnerability disclosure; (6) Accountability, documentation and logging — obligations to retain technical documentation, logs and impact mitigation plans to enable audits and remedial actions; (7) Public sector limits — restrictions and stricter controls on automated decision‑making used in public administration and criminal justice; (8) Redress and liability — individual rights to contest automated decisions and administrative and civil remedies. These focus areas are discussed in the committee ponencia and public hearings materials. See Congreso Visible and the Cámara documentation at Cámara – PLE 154/24C.

Implementation Framework

The bill proposes staged obligations and graduated enforcement to balance innovation and rights protection: (a) immediate requirements for transparency, documentation and minimal security controls for providers and operators; (b) a medium term registry/conformity system for high‑risk AI requiring third‑party assessment and registration with the national observatory; (c) DPIA and stakeholder consultation duties prior to deployment of high‑risk systems; (d) sectoral guidance and technical standards developed by ministries in collaboration with the proposed national AI observatory and standardization bodies; and (e) special rules for SMEs/startups including simplified compliance paths and phased implementation to avoid stifling innovation. The committee report and explanatory notes discuss capacity building, model labelling, procurement rules and a transitional regime. For the committee’s implementation recommendations see the published ponencia and Comité materials: Imprenta Nacional / Gaceta (ponencia).

Monitoring and Evaluation

Monitoring relies on a public registry, periodic audits and market surveillance coordinated by existing supervisory agencies (notably the Superintendencia de Industria y Comercio) and a proposed national AI observatory to collect registry data, incident reports and performance metrics. The bill contemplates periodic public reporting, mandatory breach/incident notifications for AI systems that harm fundamental rights, and public transparency dashboards to track registered high‑risk systems and sanctions. The committee materials recommend indicators for evaluating coverage, compliance rates and rights impacts; these are to be published and reviewed regularly by the legislative committees. See committee sessions and public hearing records at Cámara – Audiencia Pública.

Penalties, Liability, and Appeals

The draft law contemplates administrative sanctions for noncompliance (fines, suspension or prohibition of operations), corrective orders, and civil liability channels for damages caused by AI systems, especially those classified as high‑risk; it also foresees procedural safeguards and administrative/judicial appeals against supervisory decisions. The ponencia and Gaceta describe a framework combining administrative enforcement by sectoral regulators with civil liability claims and obligations to provide restorative remedies for harmed individuals. Specific sanctioning ranges and mechanisms are addressed in the proposed articles and committee report. See Gaceta / Ponencia for the committee’s treatment of enforcement measures.

Relationship to Other Instruments

The bill explicitly references and proposes targeted amendments to Law 1581 of 2012 (Data Protection) to incorporate AI‑specific DPIAs and adapted consent/processing rules, while maintaining compatibility with the Constitution, existing sectoral laws (health, financial sector, labor, criminal procedure) and international human rights treaties to which Colombia is party. It aims to integrate existing supervisory structures (e.g., Superintendencias, sector ministries) rather than create numerous new enforcement agencies, while proposing a national AI observatory/registry for coordination. The bill’s explanatory notes and committee documents outline how it interacts with current privacy, consumer protection and administrative procedure law. See the project description at Congreso Visible.

International Alignment

The bill repeatedly cites international human rights standards and proposes alignment with global AI governance trends (risk‑based regulation, transparency, conformity assessment and documentation) and with soft law instruments (e.g., OECD AI Principles, UNESCO guidance) to enable cross‑border interoperability and facilitate trade in AI services. Committee discussions and expert hearings referenced international frameworks as normative guidance for defining high‑risk categories, labelling synthetic content and implementing DPIAs. The bill also contemplates cooperation with foreign regulators for cross‑border enforcement and data access under appropriate legal safeguards. See the bill’s explanatory and committee materials for international references and the Cámara’s hearing records at Cámara – Audiencia Pública.

Implementation Timeline

PhaseActionIndicative Deadline
Radication & Early ReviewRadicated and initial committee hearings2024-08-06 (radication)
Committee DeliberationPublic hearings, ponencia for first debateSep–Oct 2024 (public hearing 2024-09-30; ponencia Oct 2024)
First DebateCommission and plenary considerationIndicative — during 2024–2025 legislative sessions
Secondary RulemakingRegulatory guidance and standards (ministries, observatory)6–18 months after enactment
Phased ComplianceSME simplified timelines; high‑risk registration & audits6–24 months after enactment

Sources and References

SourceType
Cámara de Representantes — Audiencia pública PLE 154/24C (event page, documents)Primary Source
Congreso Visible — Project profile and synopsisPrimary / Explanatory
Imprenta Nacional / Gaceta — Informe de ponencia positiva (Gaceta n.1694, Oct 2024)Primary Source

Requirements for a company

What an organisation has to do under Colombia - AI Regulation (154/2024), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.

Must do

15
  • Perform an AI-specific data protection impact assessment.Providers and operators of AI systems.
  • Conduct a mandatory conformity assessment for high-risk AI systems.Providers of high-risk AI systems.
  • Obtain pre-deployment certification for high-risk AI systems.Providers of high-risk AI systems.
  • Register high-risk AI systems with the national observatory.Providers of high-risk AI systems.
  • Notify authorities of breaches or incidents that harm fundamental rights.Providers and operators of AI systems.
  • Provide restorative remedies for individuals harmed by AI systems.Providers and operators of AI systems.
  • +9 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Colombia - AI Regulation (154/2024), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers and operators of AI systems.Perform an AI-specific data protection impact assessment.
amendments to Law 1581 to require AI‑specific DPIAs
Before deploying high-risk AI systemsCritical
2Providers of high-risk AI systems.Conduct a mandatory conformity assessment for high-risk AI systems.
mandatory conformity assessment, external audits, pre‑deployment certification for systems affecting life, health, liberty, employment, credit, and public services
Before pre-deployment certificationCritical
3Providers of high-risk AI systems.Obtain pre-deployment certification for high-risk AI systems.
pre‑deployment certification for systems affecting life, health, liberty, employment, credit, and public services
Before placing on marketCritical
4Providers of high-risk AI systems.Register high-risk AI systems with the national observatory.
a medium term registry/conformity system for high‑risk AI requiring third‑party assessment and registration with the national observatory
6-24 months after enactmentCritical
5Providers and operators of AI systems.Notify authorities of breaches or incidents that harm fundamental rights.
mandatory breach/incident notifications for AI systems that harm fundamental rights
Upon discoveryCritical
6Providers and operators of AI systems.Provide restorative remedies for individuals harmed by AI systems.
obligations to provide restorative remedies for harmed individuals
Upon harmCritical
7Model providers.Restrict the use of sensitive data for AI system training.
restrictions on certain data uses for training (sensitive data)
Before training AI systemsImportant
8Providers and operators of AI systems.Implement stronger consent and transparency regimes for data processing.
stronger consent/transparency regimes
Before deploymentImportant
9Providers of high-risk AI systems.Undergo external audits for high-risk AI systems.
mandatory conformity assessment, external audits, pre‑deployment certification for systems affecting life, health, liberty, employment, credit, and public services
Before pre-deployment certificationImportant
10Model providers.Provide model cards for AI systems.
requirements for model cards, dataset documentation, provenance and labelling of synthetic media
Before deploymentImportant
11Model providers.Document datasets used for AI system development.
requirements for model cards, dataset documentation, provenance and labelling of synthetic media
Before deploymentImportant
12Operators and publishers of AI systems.Label synthetic media and provide provenance information.
provenance and labelling of synthetic media
Before publishing synthetic mediaImportant
13Providers and operators of AI systems.Ensure cybersecurity for AI systems throughout their lifecycle.
obligations for cybersecurity, adversarial testing, patching and vulnerability disclosure
OngoingImportant
14Providers and operators of AI systems.Conduct adversarial testing for AI systems.
obligations for cybersecurity, adversarial testing, patching and vulnerability disclosure
Before deploymentImportant
15Providers and operators of AI systems.Retain technical documentation, logs, and impact mitigation plans.
obligations to retain technical documentation, logs and impact mitigation plans to enable audits and remedial actions
OngoingImportant

© Regulations.AI · updated on 13-Jun-2026