Colombia - AI Regulation Framework (Senate 442/25)

By means of which artificial intelligence is regulated in Colombia to guarantee its ethical and responsible development

Por medio de la cual se regula la inteligencia artificial en Colombia para garantizar su desarrollo ético y responsable

Colombia

RAI-CO-NA-PMDLCXX-2025
Stalled(Stalled)
BillGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

This government bill (Senate 442/25), radicated on 7 May 2025, proposed a comprehensive, risk‑based regulatory framework for artificial intelligence in Colombia led by the Ministry of Science, Technology and Innovation (MinCiencias) and the Ministry of Information and Communications Technologies (MinTIC). The draft set out risk classifications (unacceptable, high, limited, low), mandatory impact assessments and registries for high‑risk systems, transparency and human oversight rules, data‑protection alignment, sectoral safeguards for health and finance, and administrative sanctions; the bill was archived in the Senate and did not become law.

Summary

The government bill titled "Por medio de la cual se regula la inteligencia artificial en Colombia para garantizar su desarrollo ético y responsable" (Senate No. 442/25), radicated on 7 May 2025 by MinCiencias and MinTIC with multiple congressional co‑sponsors, proposed an overarching legal framework for the design, development, deployment and use of artificial intelligence (AI) across public and private spheres in Colombia. Drawing clearly on international instruments (notably the EU approach, UNESCO and OECD guidance) and the national AI policy architecture (CONPES 4144, CONPES 3975 and related guidance), the bill adopted a risk‑based regulatory architecture. It defined key terms (e.g., "AI system", "operator", "developer", "risk of discrimination", "meaningful human oversight") and established a four‑tier risk classification: unacceptable (prohibited systems), high risk (subject to strict requirements and registration), limited risk (transparency obligations), and low risk (general principles).

Under the proposal, the Ministry of Science, Technology and Innovation (MinCiencias) would be designated as the national coordinating authority for AI governance, with MinTIC and sectoral regulators responsible for enforcement in their areas of competence. The bill mandated algorithmic risk assessments and AI impact assessments (AIA) for high‑risk systems, technical documentation and model cards, conformity assessments, cybersecurity and robustness requirements, mechanisms for human oversight and redress, and obligations to align with Colombia's data protection regime (Law 1581/2012) and other fundamental rights protections. It proposed market surveillance powers, a national registry for high‑risk AI systems, and public transparency obligations (including user notices when interacting with certain AI systems).

The draft also listed prohibited uses (e.g., social scoring, indiscriminate biometric identification in public spaces, automated decisions without effective human review in immigration/justice contexts) and provided for transitional provisions for research, public sector procurement rules, capacity building and incentives to foster an ecosystem of trustworthy AI. Enforcement measures included administrative fines, corrective orders, suspension of deployment, and public disclosure of sanctions; the bill envisioned cooperation with data protection and competition authorities on enforcement. Although the draft sought to position Colombia as a regional leader in ethical, responsible, competitive and innovative AI, Senate records indicate the bill was archived (no ponencia presented for first debate) and therefore did not enter into force. The initiative has, however, influenced public debate and subsequent drafts and sectoral rulemaking, reflecting Colombia’s CONPES 4144 national AI policy and international alignment efforts.

Full article

Read full text ↗

Overview

The bill "Por medio de la cual se regula la inteligencia artificial en Colombia para garantizar su desarrollo ético y responsable" (Senate 442/25), radicated on 7 May 2025, sought to create a unified, risk‑based legal framework for AI in Colombia. The proposal assigned a national coordinating role to the Ministry of Science, Technology and Innovation and proposed coordinated oversight with the Ministry of Information and Communications Technologies and relevant sectoral regulators. Drawing on international best practice (including the OECD and the EU approach) and Colombia’s national AI policy (CONPES 4144), the draft established risk tiers (unacceptable, high, limited, low), mandatory impact assessments and registries for high‑risk systems, transparency duties, and alignment obligations with data protection law. Although widely covered by national media and legal commentary, the bill was archived in the Senate and did not become law; nevertheless, it shaped regulatory dialogue and downstream sectoral guidance.

Definitions

The bill defined core concepts to provide legal precision: "artificial intelligence" as software and computational systems able to perform tasks that ordinarily require human cognition; "AI system" as any algorithmic system generating outputs that inform, recommend or make decisions; "operator" and "provider" as entities that deploy or commercially make available AI systems; "high risk" as systems whose output can significantly affect rights, safety or fundamental freedoms; and terms such as "meaningful human oversight", "bias", "explainability" and "AI impact assessment". These definitions anchored obligations for documentation, testing and risk mitigation across the lifecycle of AI systems and aligned with language used in CONPES 4144 and comparable international texts.

Governance and Institutional Framework

The draft designated the Ministry of Science, Technology and Innovation (MinCiencias) as the national coordinating authority for AI governance, with responsibilities to issue technical guidelines, maintain the national registry for high‑risk systems, and coordinate interinstitutional oversight. The Ministry of Information and Communications Technologies (MinTIC) was tasked with supporting digital infrastructure and standards. Sectoral regulators (for example health, financial and labor regulators) would exercise delegated powers for sector‑specific enforcement and supervision. The bill also proposed an inter‑agency council to include the Superintendence of Industry and Commerce (data protection oversight), competition authorities, and representatives from academia, industry and civil society to advise on standards, conformity assessment schemes and sandboxes. The governance model emphasized public‑private coordination while reserving enforcement and sanctioning powers to public bodies. See the Senate project listing for the official registry entry: Senate project catalogue.

Key Focus Areas

Major substantive elements included: (1) a risk classification framework distinguishing unacceptable, high, limited and low risk applications; (2) prohibition of certain uses deemed unacceptable — for example, indiscriminate biometric mass surveillance and social‑scoring systems — which would be banned; (3) stringent requirements for high‑risk AI: mandatory AI impact assessments (AIAs), third‑party conformity assessments where applicable, registration in a national registry, robust data governance and documentation (model cards, dataset documentation), explainability and meaningful human oversight; (4) transparency obligations for limited‑risk systems (user notices and disclosure when content is generated or when decisions are automated); (5) data protection alignment and mandatory DPIAs where personal data are processed; (6) cybersecurity and robustness standards (secure development lifecycle, vulnerability management, resilience testing); and (7) special measures for public sector procurement, experimental sandboxes and capacity‑building incentives. The proposal emphasized protection of fundamental rights — due process, non‑discrimination, privacy, and freedom of expression — and included provisions for worker transition and re‑skilling where automation could affect employment.

Implementation Framework

Implementation relied on a combination of rulemaking, technical guidance and phased obligations. MinCiencias would publish implementing technical standards and registries; sectoral authorities would issue specific rules for regulated sectors (health, finance, justice, social services). The bill proposed regulatory sandboxes and certification pathways to support innovation while ensuring safety. Compliance instruments included self‑certification for low‑risk systems, mandatory internal governance and risk management systems for operators of high‑risk AI, and third‑party conformity assessment for certain high‑risk categories. The draft required documentation (technical files, training data inventories, performance metrics) to be maintained for supervisory audits. Transitional provisions sought to protect research and academic work through narrower exemptions while ensuring that commercial deployments meet compliance thresholds.

Monitoring and Evaluation

Monitoring combined ex‑ante and ex‑post mechanisms: pre‑deployment AI impact assessments, ongoing post‑market monitoring and periodic audits by competent authorities. The bill envisaged a public registry of high‑risk systems to enable market surveillance and encourage transparency. Authorities would collect incident reports and establish reporting obligations for serious harms. MinCiencias, working with sectoral supervisors and the Superintendence of Industry and Commerce (SIC), would publish periodic evaluations of the law's effectiveness and recommend updates. The bill also contemplated indicators and reporting templates for measuring compliance, bias incidents, cybersecurity events and user complaints.

Penalties, Liability, and Appeals

The draft established an administrative enforcement regime with graduated remedies: corrective orders (remediation plans), temporary suspension of deployment, withdrawal of systems from the market, and monetary fines proportionate to the severity of the breach. It included provisions for private liability and redress mechanisms for individuals harmed by AI decisions, aligning civil liability with existing tort law and data protection remedies. The bill created procedural rules for administrative appeals and judicial review, and required authorities to publish enforcement actions to increase deterrence and transparency.

Relationship to Other Instruments

The bill explicitly referenced Colombia’s existing legal framework, including the data protection statutory regime (Law 1581 of 2012), administrative procedure rules, consumer protection statutes and sectoral regulation (health, financial supervision). It was drafted to complement — not duplicate — CONPES 4144 (the National AI Policy) and to enable the adoption of technical standards by MinTIC and sectoral regulators. The bill anticipated coordination with the Superintendence of Industry and Commerce on data protection and with competition authorities on market concentration and dominant platform practices related to AI market power.

International Alignment

The draft aligned with international standards and instruments (OECD, UNESCO, EU AI legislative approach) to facilitate interoperability and trade. It proposed to adopt recognized technical standards for testing, conformity assessment and model documentation and to promote international cooperation on enforcement and research. The bill intended to position Colombia as a regional hub for trustworthy AI by integrating international guidance while adapting rules to national priorities and territorial equity (explicit in CONPES 4144).

Implementation Timeline

MilestoneDateNotes
Radication of bill2025-05-07Officially radicated in the Senate (Senate No. 442/25).
Public debate and media coverage2025-05 to 2025-08Multiple public briefings, consultations and press analyses; draft influenced subsequent iterations.
Archiving (Senate)2025-XX-XXSenate record indicates the bill was archived (no ponencia presented for first debate); specific archival date recorded in Senate registry.
Follow‑on policymaking2025–2026CONPES 4144 and sectoral guidance continued to shape regulatory activity and technical rulemaking.

Sources and References

SourceType
Senate project catalogue entry — Project No. 442/25Primary Source
CONPES 4144 — National AI Policy (DNP)Primary Source
El Espectador — coverage of bill radication (07 May 2025)Secondary Source
Semana — reporting on regulatory process and CONPESSecondary Source

Requirements for a company

What an organisation has to do under Colombia - AI Regulation Framework (Senate 442/25), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Stalled). These requirements apply once the instrument takes effect and may change before then.

Must do

10
  • Avoid developing or deploying AI systems for unacceptable uses, such as indiscriminate biometric mass surveillance.Providers and operators of AI systems
  • Determine the risk tier of your AI system and document the rationale.Providers and operators of AI systems
  • Conduct and retain an AI impact assessment for high-risk systems.Operators of high-risk AI systems
  • Register high-risk AI systems in the national registry maintained by MinCiencias.Operators of high-risk AI systems
  • Implement meaningful human review controls and escalation paths for high-risk AI systems.Operators of high-risk AI systems
  • Ensure compliance with Law 1581 of 2012 and conduct DPIAs where personal data are processed.Operators of AI systems processing personal data
  • +4 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Colombia - AI Regulation Framework (Senate 442/25), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers and operators of AI systemsAvoid developing or deploying AI systems for unacceptable uses, such as indiscriminate biometric mass surveillance.
prohibition of certain uses deemed unacceptable — for example, indiscriminate biometric mass surveillance and social‑scoring systems — which would be banned
AlwaysCritical
2Providers and operators of AI systemsDetermine the risk tier of your AI system and document the rationale.
Determine risk tier; document rationale.
Before placing on market or deploymentCritical
3Operators of high-risk AI systemsConduct and retain an AI impact assessment for high-risk systems.
Conduct and retain AIA for high‑risk systems before deployment.
Before deploymentCritical
4Operators of high-risk AI systemsRegister high-risk AI systems in the national registry maintained by MinCiencias.
Register high‑risk systems in the national registry (MinCiencias).
Before deploymentCritical
5Operators of high-risk AI systemsImplement meaningful human review controls and escalation paths for high-risk AI systems.
Implement meaningful human review controls and escalation paths.
Before deploymentCritical
6Operators of AI systems processing personal dataEnsure compliance with Law 1581 of 2012 and conduct DPIAs where personal data are processed.
Ensure Law 1581 compliance and carry out DPIAs where required.
Before processing personal dataCritical
7Operators of certain high-risk AI systemsObtain required conformity assessment or certification for certain high-risk AI systems.
Obtain required conformity assessment/certification for certain high‑risk systems.
Before placing on marketCritical
8Operators of high-risk AI systemsMaintain a technical file, dataset inventory, and model card for high-risk AI systems.
Maintain technical file, dataset inventory and model card.
Before placing on market and ongoingImportant
9Operators of AI systemsDisclose when users interact with an AI system or when content is generated or decisions are automated.
Disclose when users interact with AI and provide user‑facing explanations.
Before user interactionImportant
10Operators of AI systemsApply secure development lifecycle, vulnerability management, and incident response procedures to AI systems.
Apply secure development lifecycle and incident response procedures.
OngoingImportant

© Regulations.AI · updated on 13-Jun-2026