Costa Rica - AI Regulation Bill

Artificial Intelligence Regulation Bill (Legislative Assembly)

Proyecto de Ley de Regulación de la Inteligencia Artificial (Asamblea Legislativa)

Costa Rica

RAI-CR-NA-AILAXXX-2023
Under Review(Under Review)
BillGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

A pioneering AI regulation bill introduced in Costa Rica's Legislative Assembly in May 2023, notably drafted with assistance from ChatGPT-4. The bill proposes establishing a regulatory authority for AI oversight and emphasizes accountability, explainability, bias prevention, and human rights protection.

Overview

The Artificial Intelligence Regulation Bill was introduced in Costa Rica's Legislative Assembly on May 30, 2023, by Congresswoman Vanessa Castro and colleagues. The bill gained international attention for its unprecedented approach: the entire text was drafted with assistance from ChatGPT-4, making it one of the first AI-generated legislative proposals in the world. The bill proposes establishing a comprehensive regulatory framework for artificial intelligence in Costa Rica, including the creation of a supervisory authority and requirements for accountability, explainability, and bias prevention. The initiative reflects Costa Rica's proactive approach to AI governance and positions the country among Latin American leaders in developing AI regulatory frameworks.

Definitions

The bill provides foundational definitions for AI regulation. Artificial Intelligence Systems refers to computer systems capable of performing tasks that typically require human intelligence, including learning, reasoning, and decision-making. The Competent Authority is the proposed regulatory body responsible for overseeing AI systems. Accountability refers to the requirement that organizations deploying AI systems take responsibility for their outcomes. Explainability means AI systems must be capable of providing understandable explanations of their decision-making processes. Bias refers to systematic errors that produce unfair outcomes, particularly discrimination against protected groups. High-Risk AI Systems are those with significant potential impacts on fundamental rights or safety.

Governance and Institutional Framework

The bill proposes establishing a new Competent Authority specifically responsible for AI oversight in Costa Rica. This regulatory body would have independence to carry out its supervisory functions without political interference. The authority would be empowered to develop implementing regulations, issue guidance on AI compliance, receive and investigate complaints about AI systems, conduct audits of AI deployments, and impose sanctions for violations. The governance structure anticipates coordination with existing regulatory bodies including data protection authorities, consumer protection agencies, and sector-specific regulators. The Legislative Assembly would maintain oversight of the authority through reporting requirements and budget approval.

Key Focus Areas

  • Establishment of Supervisory Authority: Creating an independent regulatory body with powers to oversee, audit, and enforce AI compliance.
  • Accountability Requirements: Mandating clear responsibility chains for AI system outcomes and decisions.
  • Explainability Standards: Requiring AI systems to provide understandable explanations of their decision-making processes.
  • Bias Prevention: Implementing measures to identify, assess, and mitigate algorithmic bias and discrimination.
  • Human Rights Protection: Ensuring AI development and deployment respects fundamental rights and dignities.
  • Supervision and Auditing: Establishing frameworks for regulatory oversight and compliance verification.
  • Complaint Mechanisms: Creating accessible processes for citizens to report AI-related harms or concerns.
  • Transparency Requirements: Mandating disclosure about AI use and capabilities to affected individuals.
  • Risk Assessment: Requiring evaluation of AI risks before deployment in high-stakes contexts.
  • Enforcement Powers: Granting the competent authority ability to impose sanctions for violations.

Implementation Framework

If enacted, the bill would require establishment of the competent authority within a specified timeframe following passage. The new regulatory body would then develop detailed implementing regulations and technical standards for AI compliance. Organizations deploying AI systems would have transition periods to achieve compliance with new requirements. The implementation framework anticipates phased rollout with initial focus on high-risk AI applications before expanding to broader AI governance. Capacity building within government, support for regulated entities, and public awareness campaigns would accompany regulatory implementation.

Monitoring and Evaluation

The bill establishes monitoring mechanisms through the competent authority's supervisory powers. Article 6 specifically addresses Supervision and Auditing, empowering the authority to examine AI systems for compliance with regulatory requirements. Regular reporting by AI deployers would provide ongoing visibility into AI use across sectors. The authority would maintain registers of AI systems subject to oversight. Periodic assessments would evaluate the effectiveness of the regulatory framework and identify needed adjustments. International benchmarking would compare Costa Rica's approach with evolving global best practices.

Penalties, Liability, and Appeals

The bill contemplates sanctions for non-compliance with AI regulatory requirements, though specific penalty amounts would likely be detailed in implementing regulations. Violations related to bias, lack of transparency, or failures of accountability could result in administrative fines, orders to cease AI operations, or requirements to implement corrective measures. Criminal liability might apply in cases of intentional misconduct causing significant harm. Organizations would be liable for harms caused by their AI systems, with potential for joint liability between developers and deployers. Appeals processes would allow regulated entities to challenge regulatory decisions through administrative and judicial review mechanisms.

Relationship to Other Instruments

The bill would operate alongside Costa Rica's existing legal framework including constitutional rights protections, data protection legislation, consumer protection laws, and sector-specific regulations. It complements the National Artificial Intelligence Strategy (ENIA) 2024-2027 which provides policy direction for responsible AI development. The legislation would interact with Costa Rica's digital transformation initiatives and e-government programs. International commitments under human rights conventions inform the bill's rights-protective provisions. The bill represents one of several AI-related legislative proposals under consideration in the Legislative Assembly.

International Alignment

The bill reflects influence from international AI governance frameworks, particularly the approach taken by the EU AI Act with its emphasis on risk-based regulation and transparency requirements. The principles of accountability and explainability align with the OECD AI Principles. Human rights provisions reflect commitments under the American Convention on Human Rights and other international instruments. The bill positions Costa Rica to participate in regional harmonization efforts for AI governance in Latin America. The innovative use of AI in drafting the legislation itself demonstrates Costa Rica's engagement with emerging technology while raising novel questions about AI governance.

Implementation Timeline

DateMilestone
2023-05-30Bill introduced in Legislative Assembly by Congresswoman Vanessa Castro
2023-2024Committee review and public consultation
TBDLegislative debate and potential amendments
TBDFinal vote in Legislative Assembly
TBDPresidential signature if passed
TBDEstablishment of competent authority
TBDDevelopment of implementing regulations

Compliance Checklist

RequirementDetails
Accountability StructuresEstablish clear responsibility chains for AI system outcomes
ExplainabilityEnsure AI systems can provide understandable decision explanations
Bias AssessmentConduct assessments to identify and mitigate algorithmic bias
Human Rights ImpactEvaluate AI impacts on fundamental rights before deployment
TransparencyDisclose AI use and capabilities to affected individuals
DocumentationMaintain records of AI development, training, and deployment
Complaint ResponseEstablish processes to receive and address AI-related complaints
Regulatory RegistrationRegister AI systems with competent authority as required

Sources and References

SourceType
Costa Rica Legislative AssemblyLegislative Body
Analytics Insight - AI Law Drafted by ChatGPT Splits ExpertsNews Analysis
World Lawyers Forum - ChatGPT Proposes AI Regulation BillLegal Analysis
Plain English

Costa Rica's proposed Artificial Intelligence Regulation Bill aims to establish a comprehensive legal framework for AI systems within the country, applying to any organization deploying these technologies. The bill, notably drafted with assistance from ChatGPT-4, seeks to create a new, independent regulatory authority to oversee AI development and use.

The legislation primarily targets organizations that deploy Artificial Intelligence Systems, defined as computer systems capable of learning, reasoning, and decision-making. A key focus is on "High-Risk AI Systems," which are those with significant potential impacts on fundamental rights or safety. Businesses using AI in Costa Rica would face several core obligations: - Ensuring accountability for AI system outcomes and decisions. - Providing understandable explanations of how AI systems make decisions. - Implementing measures to prevent and mitigate algorithmic bias and discrimination. - Protecting human rights throughout AI development and deployment.

As a bill currently under review, its effective date is unknown. If passed, it would first require the establishment of the new "Competent Authority," which would then develop detailed rules and technical standards. Organizations would be given transition periods to comply.

The proposed regulatory body would have significant enforcement powers, including the ability to conduct audits, investigate complaints, and impose sanctions for violations. Penalties could range from administrative fines and orders to cease operations to requirements for corrective measures. Criminal liability is also contemplated for intentional misconduct causing significant harm, and organizations could face joint liability for harms caused by their AI systems.

A practical consideration for businesses is the creation of this entirely new, independent regulatory body. This means navigating a fresh set of rules and a new bureaucracy, potentially leading to initial uncertainties as the authority establishes its practices and interpretations.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under Costa Rica - AI Regulation Bill. Not legal advice — verify against the official text before relying on it.

  1. #1Critical

    Applies to: Organizations deploying AI systems.

    Accountability Requirements: Mandating clear responsibility chains for AI system outcomes and decisions.
  2. #2Critical

    Applies to: Organizations deploying AI systems.

    Explainability Standards: Requiring AI systems to provide understandable explanations of their decision-making processes.
  3. #3Critical

    Applies to: Organizations deploying AI systems.

    Bias Prevention: Implementing measures to identify, assess, and mitigate algorithmic bias and discrimination.
  4. #4CriticalBefore deployment

    Applies to: Organizations deploying AI systems.

    Human Rights Protection: Ensuring AI development and deployment respects fundamental rights and dignities.
  5. #5Critical

    Applies to: Organizations deploying AI systems.

    Transparency Requirements: Mandating disclosure about AI use and capabilities to affected individuals.
  6. #6CriticalBefore deployment

    Applies to: Organizations deploying AI systems.

    Risk Assessment: Requiring evaluation of AI risks before deployment in high-stakes contexts.
  7. #7CriticalArticle 6

    Applies to: Organizations deploying AI systems.

    Article 6 specifically addresses Supervision and Auditing, empowering the authority to examine AI systems for compliance.
  8. #8Important

    Applies to: Organizations deploying AI systems.

    Complaint Response: Establish processes to receive and address AI-related complaints.
  9. #9Important

    Applies to: Organizations deploying AI systems.

    Documentation: Maintain records of AI development, training, and deployment.
  10. #10Important

    Applies to: Organizations deploying AI systems.

    Regulatory Registration: Register AI systems with competent authority as required.
  11. #11Important

    Applies to: AI deployers.

    Regular reporting by AI deployers would provide ongoing visibility into AI use across sectors.

© Regulations.AI — created on 06-Jan-2026