Colombia - AI Regulation Bill (C200/2023)
Bill to define and regulate AI
Por medio de la cual se define y regula la inteligencia artificial (Proyecto 200/23)
Colombia
RAI-CO-NA-PMDLCXX-2023A 2023 statutory bill (Proyecto 200/23) presented in the Colombian Chamber of Representatives to define and regulate artificial intelligence with an explicit human-rights focus. The project proposed risk-based governance, restrictions on certain uses, obligations for transparency, documentation, security and data protection, and institutional oversight; it was archived (ended) in mid-2024 without becoming law.
Summary
Proyecto de Ley Estatutaria C200/2023 (Proyecto 200/23) was introduced to the Colombian Chamber of Representatives on 6 September 2023 by Representatives Alirio Uribe Muñoz and Karyme Adriana Cotes Martínez. The draft statutory law sought to define "artificial intelligence" and to establish a comprehensive regulatory framework to align AI development and use with international human-rights standards and Colombian constitutional protections. The bill combined a rights-based approach with risk management: it proposed to classify systems by risk level and to impose stricter obligations on higher-risk systems (including registration, impact assessment, prior authorization in certain contexts, independent audits and more robust documentation and transparency measures). It would have required human oversight safeguards, mechanisms to prevent discriminatory outcomes, technical and organizational security measures, and stronger data protection alignment by explicitly amending parts of Law 1581/2012 (Colombian data protection framework) where necessary.
The project included provisions to prohibit or limit specific uses of AI deemed incompatible with human dignity or rights, and it proposed institutional arrangements for governance, including designated oversight authorities and coordination between the Ministry of Information Technologies and Communications (MinTIC), the national data protection authority (Superintendencia de Industria y Comercio — SIC), and other bodies for supervision, market surveillance and sanctions. The bill foresaw obligations for developers, deployers and public-sector users, such as mandatory risk assessments, documentation and auditability, explainability and notice requirements, cybersecurity standards for models and systems, incident reporting and redress mechanisms for affected persons. It also contemplated sanctions and administrative penalties and envisaged mechanisms for consumer protection and enforcement.
The bill proceeded through the Chamber's First Constitutional Commission, with a published first-debate ponencia in November 2023, but it was ultimately archived for expiration of terms on 19 June 2024 (status: archived / ended). The text and legislative folder were published in public legislative trackers and university repositories but the draft did not reach promulgation. Key references and the Chamber of Representatives project page record the project's objectives, authorship, timeline and archival status. Because it did not become law, the proposal remains an important reference for Colombia's AI policy debate but imposes no binding legal obligations as enacted legislation.
Full article
Read full text ↗Overview
The Proyecto de Ley Estatutaria C200 de 2023 (commonly referenced as Proyecto 200/23) was lodged in the Cámara de Representantes on 6 September 2023 with the stated objective of defining and regulating artificial intelligence to ensure compliance with human-rights standards and to establish limits on its development, use and implementation. The project is recorded on the Chamber's legislative page and in public legislative observatories; see the Chamber project record at Cámara de Representantes – Inteligencia Artificial and the replicated dossier on Congreso Visible at Congreso Visible – Proyecto 200/23. The project combined human-rights protections with operational rules for developers, deployers and public-sector users and proposed institutional oversight mechanisms. The legislative record shows a first-debate ponencia in November 2023 and an archival entry for expiration of terms in June 2024, after which the bill's formal status is 'archived' (ended).
Definitions
The draft provided operational definitions intended to cover the lifecycle of AI systems: (i) "artificial intelligence" as systems performing tasks that would require intelligence if executed by humans, including algorithmic models, machine learning, expert systems, and generative models; (ii) "provider/developer" and "operator/deployer" distinguished by roles in design vs. deployment; (iii) "automated decision-making" and "high-risk system" defined by potential impact on fundamental rights; (iv) ancillary terms such as "training data", "model update", "explainability" and "human oversight". The aim of these definitions was to ensure legal clarity across data protection, administrative law and sectoral oversight, and to align with comparable definitions used in international guidance while reflecting Colombia's constitutional framework.
Governance and Institutional Framework
The bill proposed a multi-institutional governance architecture that would coordinate across the Ministry of Information Technologies and Communications (MinTIC), the national data protection authority (Superintendencia de Industria y Comercio — SIC), sectoral ministries and the judiciary. It envisaged the creation or designation of a national AI oversight body to maintain registries, supervise compliance for high-risk systems, coordinate conformity assessment and market surveillance activities, and convene technical advisory committees drawn from academia, civil society and industry. The bill contemplated memoranda of understanding among agencies to allocate investigative, sanctioning and technical functions; it also contemplated ex ante review for specified high-risk applications used by the public sector. The governance approach emphasized transparency, multi-stakeholder advisory inputs, and mechanisms to protect fundamental rights in public-sector AI deployments.
Key Focus Areas
The draft centered on several interlocking policy areas: (1) rights and prohibitions — establishing uses of AI incompatible with constitutional protections and human dignity (e.g., mass biometric surveillance without safeguards); (2) risk classification — a tiered framework that subjects higher-risk systems to stronger obligations (impact assessments, registration, audit); (3) transparency and accountability — mandatory documentation, model cards, human-readable explanations, user notice and logging; (4) data protection and privacy — alignment with Law 1581/2012 and strengthened safeguards for training data, consent/legitimate basis and data minimization; (5) safety, testing and conformity — procedures for testing, validation, and third-party conformity assessment for specific categories; (6) cybersecurity and model security — baseline requirements for integrity, vulnerability management, patching and supply-chain risk management; (7) redress and liability — clear pathways for affected persons to seek remedies and shifting burdens for demonstrable harms; (8) enforcement and penalties — administrative sanctions, corrective measures and market surveillance to detect unsafe or noncompliant systems. Across these foci, the bill sought to balance innovation promotion with protective duties to prevent discriminatory, opaque or otherwise harmful deployments.
Implementation Framework
Implementation measures in the draft included mandatory impact assessments (privacy, fundamental rights, non-discrimination), registration of certain high-risk systems on a public registry, periodic audits, incident and breach reporting, and technical documentation requirements (including model descriptions, datasets, training procedures and performance metrics). The bill proposed regulatory powers for the oversight authority to issue technical standards, require corrective measures, order suspensions and impose fines. For the public sector, prior evaluation and human oversight mandates would be required before adoption of automated decision-making that affects citizens' rights. The draft left room for secondary regulation and delegated technical standards to be issued by competent agencies to operationalize risk thresholds and conformity procedures.
Monitoring and Evaluation
Monitoring mechanisms included mandated reporting to the oversight body, indicators to measure compliance and impact, periodic public transparency reports, and joint inspections by regulatory authorities. The bill suggested a periodic review cycle to evaluate regulatory effectiveness, adapt risk categories, and revise obligations as technology and socio-technical contexts evolve. It also encouraged publication of anonymized enforcement data and impact metrics to promote accountability and evidence-based policy making. The bill proposed including civil-society participation in evaluation processes to strengthen legitimacy and rights-protective outcomes.
Penalties, Liability, and Appeals
The draft set out administrative remedies and sanctions for noncompliance, including fines, orders to suspend processing or decommission models, corrective action plans and public corrective notices. It anticipated contested-administration routes and judicial review for sanctioned entities and provided for compensation and redress channels for persons harmed by AI decisions. The bill contemplated escalation pathways between supervisory authorities and the judiciary for complex liability claims arising from algorithmic harms, and it emphasized obligations to preserve evidence and logs to facilitate investigations and remedies.
Relationship to Other Instruments
The bill explicitly referenced alignment with Law 1581 of 2012 (data protection) and proposed targeted modifications to ensure consistent treatment of training datasets and AI-specific processing. It positioned itself within Colombia's constitutional framework on fundamental rights and administrative law and envisaged coordination with sectoral regulation (health, finance, electoral law) to avoid fragmentation. The draft drew on international standards and regional guidance while respecting national competences and constitutional safeguards.
International Alignment
The proposal sought international alignment with key emerging frameworks and soft law — including the EU risk-based approach and principles-oriented guidance from multilateral organizations — while tailoring obligations to Colombia's legal and institutional context. It encouraged interoperability with international conformity-assessment mechanisms and recognized the value of cross-border cooperation on research, standards, and enforcement for models and datasets that operate transnationally.
Implementation Timeline
| Milestone | Date |
|---|---|
| Radication in Chamber of Representatives | 2023-09-06 |
| Publication in Gaceta (project record) | 2023-09-14 (Gaceta 1260/23) |
| Ponencia – first debate published | 2023-11-10 (First Debate Ponencia) |
| Archived / ended (expiration of terms) | 2024-06-19 |
Sources and References
| Source | Type |
|---|---|
| Cámara de Representantes – Proyecto: Inteligencia Artificial (C200/2023) | Primary Source |
| Congreso Visible – Project File (Proyecto 200/23) | Primary Source / Legislative Tracker |
| Universidad de los Andes – Algorithms Repository (project record) | Repository / Secondary |
Requirements for a company
What an organisation has to do under Colombia - AI Regulation Bill (C200/2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Stalled). These requirements apply once the instrument takes effect and may change before then.
Must do
11- Do not deploy AI systems incompatible with human rights or dignity.All providers and deployers of AI systems.
- Conduct mandatory impact assessments for privacy, fundamental rights, and non-discrimination.Developers, providers, and public-sector deployers of AI systems.
- Implement strengthened safeguards for training data, consent, and data minimization.Providers and operators of AI systems.
- Implement baseline cybersecurity for AI system integrity and vulnerability management.Providers and operators of AI systems.
- Provide user notice and ensure human oversight for automated decisions affecting rights.Deployers of AI systems, especially public authorities.
- Register high-risk AI systems on the public registry.Providers and deployers of high-risk AI systems.
- +5 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Colombia - AI Regulation Bill (C200/2023), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | All providers and deployers of AI systems. | Do not deploy AI systems incompatible with human rights or dignity. “establishing uses of AI incompatible with constitutional protections and human dignity” | — | — | Critical |
| 2 | Developers, providers, and public-sector deployers of AI systems. | Conduct mandatory impact assessments for privacy, fundamental rights, and non-discrimination. “mandatory impact assessments (privacy, fundamental rights, non-discrimination)” | — | — | Critical |
| 3 | Providers and operators of AI systems. | Implement strengthened safeguards for training data, consent, and data minimization. “strengthened safeguards for training data, consent/legitimate basis and data minimization” | — | — | Critical |
| 4 | Providers and operators of AI systems. | Implement baseline cybersecurity for AI system integrity and vulnerability management. “baseline requirements for integrity, vulnerability management, patching and supply-chain risk management” | — | — | Critical |
| 5 | Deployers of AI systems, especially public authorities. | Provide user notice and ensure human oversight for automated decisions affecting rights. “user notice and logging” | — | — | Critical |
| 6 | Providers and deployers of high-risk AI systems. | Register high-risk AI systems on the public registry. “registration of certain high-risk systems on a public registry” | — | — | Critical |
| 7 | Developers and providers of AI systems. | Maintain comprehensive technical documentation, model cards, and human-readable explanations. “mandatory documentation, model cards, human-readable explanations” | — | — | Important |
| 8 | Providers of AI systems, especially high-risk ones. | Establish procedures for testing, validation, and third-party conformity assessment. “procedures for testing, validation, and third-party conformity assessment for specific categories” | — | — | Important |
| 9 | Providers and operators of AI systems. | Report AI system incidents and breaches to the oversight authority. “incident and breach reporting” | — | — | Important |
| 10 | Providers and deployers of high-risk AI systems. | Conduct periodic audits of AI systems. “periodic audits” | — | — | Important |
| 11 | Providers and operators of AI systems. | Preserve evidence and logs to facilitate investigations and remedies. “obligations to preserve evidence and logs to facilitate investigations and remedies.” | — | — | Important |
Related Regulations
Por medio de la cual se regula la inteligencia artificial en Colombia para garantizar su desarrollo ético y responsable (Government bill, Senate 442/25)
Colombia96% similar
Proyecto 05/24: Ley de inteligencia artificial ética y sostenible para el bienestar social (Ethical and sustainable AI law proposal)
Colombia94% similar
Proyecto de Ley Estatutaria No.154 de 2024: Por la cual se define y regula la Inteligencia Artificial (Statutory bill to define and regulate AI)
Colombia94% similar
Proyecto 91/23: Mediante la cual se establece el deber de información para el uso responsable de la Inteligencia Artificial (Duty of information for responsible AI)
Colombia92% similar
Proyecto 130/23: Armonización de la inteligencia artificial con el derecho al trabajo (AI and labor-rights harmonization)
Colombia92% similar
© Regulations.AI · updated on 13-Jun-2026