Colombia - AI Regulation Framework (Senate 442/25)
By means of which artificial intelligence is regulated in Colombia to guarantee its ethical and responsible development
Por medio de la cual se regula la inteligencia artificial en Colombia para garantizar su desarrollo ético y responsable
Colombia
RAI-CO-NA-PMDLCXX-2025This government bill (Senate 442/25), radicated on 7 May 2025, proposed a comprehensive, risk‑based regulatory framework for artificial intelligence in Colombia led by the Ministry of Science, Technology and Innovation (MinCiencias) and the Ministry of Information and Communications Technologies (MinTIC). The draft set out risk classifications (unacceptable, high, limited, low), mandatory impact assessments and registries for high‑risk systems, transparency and human oversight rules, data‑protection alignment, sectoral safeguards for health and finance, and administrative sanctions; the bill was archived in the Senate and did not become law.
Summary
The government bill titled "Por medio de la cual se regula la inteligencia artificial en Colombia para garantizar su desarrollo ético y responsable" (Senate No. 442/25), radicated on 7 May 2025 by MinCiencias and MinTIC with multiple congressional co‑sponsors, proposed an overarching legal framework for the design, development, deployment and use of artificial intelligence (AI) across public and private spheres in Colombia. Drawing clearly on international instruments (notably the EU approach, UNESCO and OECD guidance) and the national AI policy architecture (CONPES 4144, CONPES 3975 and related guidance), the bill adopted a risk‑based regulatory architecture. It defined key terms (e.g., "AI system", "operator", "developer", "risk of discrimination", "meaningful human oversight") and established a four‑tier risk classification: unacceptable (prohibited systems), high risk (subject to strict requirements and registration), limited risk (transparency obligations), and low risk (general principles).
Under the proposal, the Ministry of Science, Technology and Innovation (MinCiencias) would be designated as the national coordinating authority for AI governance, with MinTIC and sectoral regulators responsible for enforcement in their areas of competence. The bill mandated algorithmic risk assessments and AI impact assessments (AIA) for high‑risk systems, technical documentation and model cards, conformity assessments, cybersecurity and robustness requirements, mechanisms for human oversight and redress, and obligations to align with Colombia's data protection regime (Law 1581/2012) and other fundamental rights protections. It proposed market surveillance powers, a national registry for high‑risk AI systems, and public transparency obligations (including user notices when interacting with certain AI systems).
The draft also listed prohibited uses (e.g., social scoring, indiscriminate biometric identification in public spaces, automated decisions without effective human review in immigration/justice contexts) and provided for transitional provisions for research, public sector procurement rules, capacity building and incentives to foster an ecosystem of trustworthy AI. Enforcement measures included administrative fines, corrective orders, suspension of deployment, and public disclosure of sanctions; the bill envisioned cooperation with data protection and competition authorities on enforcement. Although the draft sought to position Colombia as a regional leader in ethical, responsible, competitive and innovative AI, Senate records indicate the bill was archived (no ponencia presented for first debate) and therefore did not enter into force. The initiative has, however, influenced public debate and subsequent drafts and sectoral rulemaking, reflecting Colombia’s CONPES 4144 national AI policy and international alignment efforts.
Full article
Read full text ↗Overview
The bill "Por medio de la cual se regula la inteligencia artificial en Colombia para garantizar su desarrollo ético y responsable" (Senate 442/25), radicated on 7 May 2025, sought to create a unified, risk‑based legal framework for AI in Colombia. The proposal assigned a national coordinating role to the Ministry of Science, Technology and Innovation and proposed coordinated oversight with the Ministry of Information and Communications Technologies and relevant sectoral regulators. Drawing on international best practice (including the OECD and the EU approach) and Colombia’s national AI policy (CONPES 4144), the draft established risk tiers (unacceptable, high, limited, low), mandatory impact assessments and registries for high‑risk systems, transparency duties, and alignment obligations with data protection law. Although widely covered by national media and legal commentary, the bill was archived in the Senate and did not become law; nevertheless, it shaped regulatory dialogue and downstream sectoral guidance.
Definitions
The bill defined core concepts to provide legal precision: "artificial intelligence" as software and computational systems able to perform tasks that ordinarily require human cognition; "AI system" as any algorithmic system generating outputs that inform, recommend or make decisions; "operator" and "provider" as entities that deploy or commercially make available AI systems; "high risk" as systems whose output can significantly affect rights, safety or fundamental freedoms; and terms such as "meaningful human oversight", "bias", "explainability" and "AI impact assessment". These definitions anchored obligations for documentation, testing and risk mitigation across the lifecycle of AI systems and aligned with language used in CONPES 4144 and comparable international texts.
Governance and Institutional Framework
The draft designated the Ministry of Science, Technology and Innovation (MinCiencias) as the national coordinating authority for AI governance, with responsibilities to issue technical guidelines, maintain the national registry for high‑risk systems, and coordinate interinstitutional oversight. The Ministry of Information and Communications Technologies (MinTIC) was tasked with supporting digital infrastructure and standards. Sectoral regulators (for example health, financial and labor regulators) would exercise delegated powers for sector‑specific enforcement and supervision. The bill also proposed an inter‑agency council to include the Superintendence of Industry and Commerce (data protection oversight), competition authorities, and representatives from academia, industry and civil society to advise on standards, conformity assessment schemes and sandboxes. The governance model emphasized public‑private coordination while reserving enforcement and sanctioning powers to public bodies. See the Senate project listing for the official registry entry: Senate project catalogue.
Key Focus Areas
Major substantive elements included: (1) a risk classification framework distinguishing unacceptable, high, limited and low risk applications; (2) prohibition of certain uses deemed unacceptable — for example, indiscriminate biometric mass surveillance and social‑scoring systems — which would be banned; (3) stringent requirements for high‑risk AI: mandatory AI impact assessments (AIAs), third‑party conformity assessments where applicable, registration in a national registry, robust data governance and documentation (model cards, dataset documentation), explainability and meaningful human oversight; (4) transparency obligations for limited‑risk systems (user notices and disclosure when content is generated or when decisions are automated); (5) data protection alignment and mandatory DPIAs where personal data are processed; (6) cybersecurity and robustness standards (secure development lifecycle, vulnerability management, resilience testing); and (7) special measures for public sector procurement, experimental sandboxes and capacity‑building incentives. The proposal emphasized protection of fundamental rights — due process, non‑discrimination, privacy, and freedom of expression — and included provisions for worker transition and re‑skilling where automation could affect employment.
Implementation Framework
Implementation relied on a combination of rulemaking, technical guidance and phased obligations. MinCiencias would publish implementing technical standards and registries; sectoral authorities would issue specific rules for regulated sectors (health, finance, justice, social services). The bill proposed regulatory sandboxes and certification pathways to support innovation while ensuring safety. Compliance instruments included self‑certification for low‑risk systems, mandatory internal governance and risk management systems for operators of high‑risk AI, and third‑party conformity assessment for certain high‑risk categories. The draft required documentation (technical files, training data inventories, performance metrics) to be maintained for supervisory audits. Transitional provisions sought to protect research and academic work through narrower exemptions while ensuring that commercial deployments meet compliance thresholds.
Monitoring and Evaluation
Monitoring combined ex‑ante and ex‑post mechanisms: pre‑deployment AI impact assessments, ongoing post‑market monitoring and periodic audits by competent authorities. The bill envisaged a public registry of high‑risk systems to enable market surveillance and encourage transparency. Authorities would collect incident reports and establish reporting obligations for serious harms. MinCiencias, working with sectoral supervisors and the Superintendence of Industry and Commerce (SIC), would publish periodic evaluations of the law's effectiveness and recommend updates. The bill also contemplated indicators and reporting templates for measuring compliance, bias incidents, cybersecurity events and user complaints.
Penalties, Liability, and Appeals
The draft established an administrative enforcement regime with graduated remedies: corrective orders (remediation plans), temporary suspension of deployment, withdrawal of systems from the market, and monetary fines proportionate to the severity of the breach. It included provisions for private liability and redress mechanisms for individuals harmed by AI decisions, aligning civil liability with existing tort law and data protection remedies. The bill created procedural rules for administrative appeals and judicial review, and required authorities to publish enforcement actions to increase deterrence and transparency.
Relationship to Other Instruments
The bill explicitly referenced Colombia’s existing legal framework, including the data protection statutory regime (Law 1581 of 2012), administrative procedure rules, consumer protection statutes and sectoral regulation (health, financial supervision). It was drafted to complement — not duplicate — CONPES 4144 (the National AI Policy) and to enable the adoption of technical standards by MinTIC and sectoral regulators. The bill anticipated coordination with the Superintendence of Industry and Commerce on data protection and with competition authorities on market concentration and dominant platform practices related to AI market power.
International Alignment
The draft aligned with international standards and instruments (OECD, UNESCO, EU AI legislative approach) to facilitate interoperability and trade. It proposed to adopt recognized technical standards for testing, conformity assessment and model documentation and to promote international cooperation on enforcement and research. The bill intended to position Colombia as a regional hub for trustworthy AI by integrating international guidance while adapting rules to national priorities and territorial equity (explicit in CONPES 4144).
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Radication of bill | 2025-05-07 | Officially radicated in the Senate (Senate No. 442/25). |
| Public debate and media coverage | 2025-05 to 2025-08 | Multiple public briefings, consultations and press analyses; draft influenced subsequent iterations. |
| Archiving (Senate) | 2025-XX-XX | Senate record indicates the bill was archived (no ponencia presented for first debate); specific archival date recorded in Senate registry. |
| Follow‑on policymaking | 2025–2026 | CONPES 4144 and sectoral guidance continued to shape regulatory activity and technical rulemaking. |
Sources and References
| Source | Type |
|---|---|
| Senate project catalogue entry — Project No. 442/25 | Primary Source |
| CONPES 4144 — National AI Policy (DNP) | Primary Source |
| El Espectador — coverage of bill radication (07 May 2025) | Secondary Source |
| Semana — reporting on regulatory process and CONPES | Secondary Source |
Requirements for a company
What an organisation has to do under Colombia - AI Regulation Framework (Senate 442/25), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Stalled). These requirements apply once the instrument takes effect and may change before then.
Must do
10- Avoid developing or deploying AI systems for unacceptable uses, such as indiscriminate biometric mass surveillance.Providers and operators of AI systems
- Determine the risk tier of your AI system and document the rationale.Providers and operators of AI systems
- Conduct and retain an AI impact assessment for high-risk systems.Operators of high-risk AI systems
- Register high-risk AI systems in the national registry maintained by MinCiencias.Operators of high-risk AI systems
- Implement meaningful human review controls and escalation paths for high-risk AI systems.Operators of high-risk AI systems
- Ensure compliance with Law 1581 of 2012 and conduct DPIAs where personal data are processed.Operators of AI systems processing personal data
- +4 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Colombia - AI Regulation Framework (Senate 442/25), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers and operators of AI systems | Avoid developing or deploying AI systems for unacceptable uses, such as indiscriminate biometric mass surveillance. “prohibition of certain uses deemed unacceptable — for example, indiscriminate biometric mass surveillance and social‑scoring systems — which would be banned” | Always | — | Critical |
| 2 | Providers and operators of AI systems | Determine the risk tier of your AI system and document the rationale. “Determine risk tier; document rationale.” | Before placing on market or deployment | — | Critical |
| 3 | Operators of high-risk AI systems | Conduct and retain an AI impact assessment for high-risk systems. “Conduct and retain AIA for high‑risk systems before deployment.” | Before deployment | — | Critical |
| 4 | Operators of high-risk AI systems | Register high-risk AI systems in the national registry maintained by MinCiencias. “Register high‑risk systems in the national registry (MinCiencias).” | Before deployment | — | Critical |
| 5 | Operators of high-risk AI systems | Implement meaningful human review controls and escalation paths for high-risk AI systems. “Implement meaningful human review controls and escalation paths.” | Before deployment | — | Critical |
| 6 | Operators of AI systems processing personal data | Ensure compliance with Law 1581 of 2012 and conduct DPIAs where personal data are processed. “Ensure Law 1581 compliance and carry out DPIAs where required.” | Before processing personal data | — | Critical |
| 7 | Operators of certain high-risk AI systems | Obtain required conformity assessment or certification for certain high-risk AI systems. “Obtain required conformity assessment/certification for certain high‑risk systems.” | Before placing on market | — | Critical |
| 8 | Operators of high-risk AI systems | Maintain a technical file, dataset inventory, and model card for high-risk AI systems. “Maintain technical file, dataset inventory and model card.” | Before placing on market and ongoing | — | Important |
| 9 | Operators of AI systems | Disclose when users interact with an AI system or when content is generated or decisions are automated. “Disclose when users interact with AI and provide user‑facing explanations.” | Before user interaction | — | Important |
| 10 | Operators of AI systems | Apply secure development lifecycle, vulnerability management, and incident response procedures to AI systems. “Apply secure development lifecycle and incident response procedures.” | Ongoing | — | Important |
Related Regulations
Por medio de la cual se define y regula la inteligencia artificial (Proyecto 200/23) (Bill to define and regulate AI)
Colombia96% similar
Proyecto 05/24: Ley de inteligencia artificial ética y sostenible para el bienestar social (Ethical and sustainable AI law proposal)
Colombia95% similar
Proyecto de Ley Estatutaria No.154 de 2024: Por la cual se define y regula la Inteligencia Artificial (Statutory bill to define and regulate AI)
Colombia94% similar
Proyecto 91/23: Mediante la cual se establece el deber de información para el uso responsable de la Inteligencia Artificial (Duty of information for responsible AI)
Colombia93% similar
Proyecto 130/23: Armonización de la inteligencia artificial con el derecho al trabajo (AI and labor-rights harmonization)
Colombia93% similar
© Regulations.AI · updated on 13-Jun-2026