Costa Rica - AI Regulation Law (23.771)

Law for the Regulation of Artificial Intelligence in Costa Rica

Ley para la Regulación de la Inteligencia Artificial en Costa Rica

Costa Rica

RAI-CR-NA-EXPEDIE-2023

Expediente 23.771

Under Review(Under Review)
BillGovernance and OversightFundamental RightsRisk Management
Export PDF

A legislative proposal to regulate AI development and use in Costa Rica through ethical standards and institutional oversight.

Summary

Bill No. 23.771 establishes a comprehensive legal framework for AI in Costa Rica, focusing on ethical development, safety, and human rights. It designates the Ministry of Science, Innovation, Technology, and Telecommunications (MICITT) as the primary oversight authority for high-risk systems.

Full article

Read full text ↗

Overview

Bill No. 23.771, officially titled the 'Ley para la Regulación de la Inteligencia Artificial en Costa Rica,' represents a significant legislative effort by the Republic of Costa Rica to establish a comprehensive legal framework for the development and use of artificial intelligence. Introduced to the Legislative Assembly on May 30, 2023, the bill gained international attention for being one of the first legislative proposals globally to be drafted with the direct assistance of an AI model, specifically ChatGPT-4. The primary objective of the bill is to ensure that AI technologies are developed and implemented in a manner that is ethical, safe, and sustainable, while strictly adhering to the constitutional principles and human rights protections established in the Costa Rican Constitution of 1949. The bill was proposed by a cross-party group of deputies, including Vanessa Castro and José Joaquín Hernández, reflecting a broad political consensus on the need for regulation. It seeks to position Costa Rica as a regional leader in digital governance by balancing the promotion of technological innovation with the protection of individual liberties. The legislation is designed to be principles-based, focusing on transparency, accountability, and the prevention of discrimination. As of late 2024, the bill has progressed through the committee stage, receiving a 'Dictamen Afirmativo de Mayoría' (Positive Majority Report) from the Commission on Science, Technology, and Education, signaling its movement toward a full plenary debate. This regulatory initiative is part of a broader national strategy that includes the National Artificial Intelligence Strategy (ENIA) led by the executive branch, which aims to modernize the state and foster a digital economy that is inclusive and secure for all citizens.

Definitions

The legislation provides a robust set of definitions intended to clarify the scope of the law and the responsibilities of various actors within the AI ecosystem. Article 2 of the bill defines 'Artificial Intelligence' as a set of technologies and algorithms that enable systems to perform tasks and make decisions autonomously by emulating human cognitive functions such as perception and learning. This broad definition is intended to encompass current machine learning models as well as future advancements in the field. The bill also introduces the concept of an 'AI Agent,' referring to the specific software or system performing the tasks, and the 'Developer,' defined as the natural or legal person responsible for the design, construction, and maintenance of the system. Furthermore, the bill defines critical ethical and technical concepts that form the basis of its regulatory requirements. 'Algorithmic Responsibility' is established as the legal obligation of developers and operators to answer for the outcomes of AI-driven decisions. 'Algorithmic Bias' is defined as systematic errors that lead to unfair treatment of certain groups, which the law explicitly seeks to prohibit. Other key terms include 'Explainability,' which requires that AI outputs be understandable to human users, and 'Transparency,' ensuring that the internal logic and data usage of AI systems are not opaque. These definitions are closely aligned with international standards, such as those proposed by the OECD and the European Union's AI Act, to ensure cross-border legal compatibility and to provide a clear vocabulary for the Costa Rican legal system as it adapts to the digital age.

Governance and Institutional Framework

The governance structure proposed in Bill 23.771 centers on the Ministry of Science, Innovation, Technology, and Telecommunications (MICITT) as the primary oversight authority. Under the proposed framework, MICITT is tasked with the supervision, auditing, and authorization of AI systems deployed within the country. This institutional choice leverages MICITT's existing expertise in digital policy while granting it new powers to enforce ethical standards. The ministry would be responsible for maintaining a registry of high-risk AI applications and ensuring that developers comply with the mandatory administrative evaluations required before a system can be brought to market. In addition to MICITT's role, the bill envisions a collaborative governance model involving other state institutions and potentially a specialized advisory committee. This committee would provide technical guidance on evolving AI trends and help update regulatory standards as the technology matures. The framework emphasizes a 'preventative' approach to governance, where the state acts as a gatekeeper for systems that could impact public safety or fundamental rights. Critics of the bill have noted that for this framework to be effective, MICITT will require significant increases in technical staffing and budgetary resources to handle the complex task of auditing sophisticated algorithms and managing the proposed authorization process. The bill also suggests that the regulator must work in coordination with the Data Protection Agency (Prodhab) to ensure that AI governance does not overlap or conflict with existing privacy protections, creating a unified front for digital oversight.

Key Focus Areas and Prohibitions

The bill focuses heavily on the protection of fundamental rights and the mitigation of socio-technical risks. A central pillar of the legislation is the requirement for 'Human Rights Impact Assessments.' Developers must conduct these evaluations to identify potential negative effects on privacy, equality, and non-discrimination. The bill explicitly prohibits AI applications that violate human dignity, such as those used for social scoring or mass surveillance that does not meet strict judicial criteria. By prioritizing human-centric AI, the bill aims to prevent the automation of prejudice and ensure that technology serves the well-being of the population. Another key focus area is transparency and consumer protection. The bill mandates that any product or service incorporating AI must clearly disclose this fact to the user. This 'right to know' is intended to empower citizens to make informed decisions when interacting with automated systems. Furthermore, the bill emphasizes the importance of 'Explainability' in sensitive sectors such as healthcare, justice, and education. In these fields, the logic behind an AI-generated decision must be accessible to human regulators and affected individuals, ensuring that the 'black box' problem of AI does not undermine the right to due process or administrative transparency. The bill also addresses the protection of vulnerable populations, requiring stricter scrutiny for AI systems that interact with children or individuals with disabilities, ensuring that these systems do not exploit cognitive vulnerabilities or reinforce existing social inequalities.

Implementation Framework and Sandboxes

The implementation of Bill 23.771 is designed to be phased, starting with the establishment of the regulatory authority's guidelines. The bill proposes the use of 'Regulatory Sandboxes,' which are controlled environments where developers can test innovative AI systems under the supervision of MICITT. This mechanism is intended to foster innovation by allowing companies to experiment with new technologies while ensuring that potential risks are identified and mitigated before a full commercial launch. The sandboxes also provide the regulator with valuable data to refine future rules and standards. For systems already in development or deployment, the bill sets out a transition period during which entities must register their AI applications and perform the required impact assessments. The implementation framework also includes the development of technical standards for data quality and model validation. Developers are required to ensure that the data used for training AI models is representative and free from illegal biases. This focus on the 'data lifecycle' is a critical component of the implementation strategy, as it addresses the root causes of algorithmic unfairness and system failure at the foundational level of development. The bill encourages the adoption of international technical standards, such as those from ISO/IEC, to facilitate the integration of Costa Rican AI products into the global market while maintaining high safety benchmarks.

Monitoring, Evaluation, and Auditing

Continuous monitoring is a core requirement under Article 6 of the bill, which empowers the competent authority to conduct periodic audits of AI systems. These audits are not limited to the initial deployment phase but are intended to be ongoing to detect 'model drift' or the emergence of new biases over time. Developers and operators are required to maintain detailed logs of their systems' performance and decision-making processes, which must be made available to MICITT upon request. This level of oversight is designed to ensure that AI systems remain compliant with ethical standards throughout their entire operational life. Evaluation also extends to the effectiveness of the law itself. The bill suggests that the regulatory framework should be reviewed periodically to ensure it remains relevant in the face of rapid technological change. This 'agile regulation' approach allows the government to adjust its oversight mechanisms based on the outcomes of previous audits and the evolution of international best practices. By establishing a feedback loop between the regulator, the private sector, and civil society, Costa Rica aims to create a dynamic regulatory environment that can adapt to the complexities of generative AI and other emerging technologies. The auditing process will also look at the environmental impact of AI systems, encouraging developers to optimize their models for energy efficiency, aligning with Costa Rica's national commitment to environmental sustainability and carbon neutrality.

Penalties, Liability, and Appeals

Bill 23.771 establishes a regime of administrative and civil liability for violations of its provisions. While the specific monetary fines are often cross-referenced with the General Law of Public Administration and the Consumer Protection Law, the bill makes it clear that developers and operators are strictly liable for damages caused by AI systems that fail to meet safety or transparency standards. Sanctions can range from formal warnings and temporary suspensions of AI services to heavy fines for repeat offenders or for the deployment of prohibited AI systems. The severity of the penalty is determined based on the scale of the harm, the intent of the developer, and the degree of cooperation with the regulatory authority. To ensure fairness, the bill provides a clear path for appeals. Entities that are subject to an adverse decision by MICITT—such as the denial of an authorization or the imposition of a fine—have the right to seek administrative review. Furthermore, the bill protects the rights of individuals to challenge AI-driven decisions that affect them. This includes the right to a human explanation and the right to have a human operator review an automated decision. These provisions are essential for maintaining public trust in AI systems and ensuring that the legal system provides adequate redress for algorithmic errors or abuses. The bill also contemplates the possibility of collective actions or class-action lawsuits in cases where an AI system causes widespread harm to a specific group of citizens.

Relationship to Other Instruments

The AI Regulation Bill is designed to complement, rather than replace, existing legal instruments in Costa Rica. Most notably, it functions in tandem with Law No. 8968, the 'Law for the Protection of the Person against the Processing of their Personal Data.' Since AI systems rely heavily on data, the bill reinforces the requirements for informed consent and data minimization already established in Costa Rican privacy law. Any processing of personal data by an AI system must comply with the standards set by the Data Protection Agency (Prodhab), and the AI bill adds specific layers of protection regarding the use of biometric and sensitive data. Additionally, the bill aligns with the 1949 Constitution, particularly the principles of human dignity (Article 1) and the right to privacy (Article 24). It also interacts with the 'National Artificial Intelligence Strategy (ENIA),' which provides the policy roadmap for AI adoption in the public sector. While ENIA focuses on promotion and ethical guidelines, Bill 23.771 provides the binding legal teeth necessary to enforce those guidelines. The bill also considers international treaties ratified by Costa Rica, ensuring that AI regulation does not conflict with international human rights obligations or trade agreements. This holistic approach ensures that the new AI regulations are integrated into the existing legal fabric of the country, avoiding legal vacuums or contradictory mandates for businesses and public institutions.

International Alignment and OECD Standards

In drafting Bill 23.771, Costa Rican lawmakers explicitly looked toward international frameworks to ensure that the country's regulations are globally compatible. The bill incorporates the OECD Principles on Artificial Intelligence, which emphasize inclusive growth, human-centered values, and transparency. By adopting these principles, Costa Rica aims to facilitate international cooperation and attract foreign investment from tech companies that are already aligning their operations with OECD standards. This alignment is also a strategic move for Costa Rica as a member of the OECD, demonstrating its commitment to the organization's digital economy goals. Furthermore, the bill draws significant inspiration from the European Union's AI Act, particularly its risk-based approach and its focus on high-risk applications. While the Costa Rican bill is currently less granular than the EU's final regulation, it shares the same fundamental philosophy of prioritizing safety and fundamental rights. This international alignment is intended to prevent 'regulatory fragmentation' in Latin America, where several countries are currently debating AI laws. By following established international norms, Costa Rica hopes to create a predictable legal environment that encourages innovation while protecting its citizens from the potential harms of unregulated AI. The bill also positions Costa Rica to participate in international forums on AI safety, contributing a Latin American perspective to the global dialogue on technology governance.

Implementation Timeline

MilestoneDateNotes
Formal Introduction to Assembly2023-05-30Presented by Vanessa Castro and other deputies under Expediente 23.771.
Publication in La Gaceta2023-06-07Official publication in Gazette No. 101, Alcance No. 104.
Committee Approval (Dictamen)2024-09-12Received a Positive Majority Report from the Science and Tech Committee.
Plenary Debate (First Reading)Expected 2025Scheduled for debate in the full Legislative Assembly.
Entry into ForceTBDPending final approval and Presidential signature.

Requirements for a company

What an organisation has to do under Costa Rica - AI Regulation Law (23.771), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.

Must do

11
  • Do not deploy AI applications that violate human dignity, such as social scoring or mass surveillance without judicial criteria.Developers and operators of AI systems.
  • Register high-risk AI systems with MICITT.Developers of high-risk AI systems.
  • Conduct Human Rights Impact Assessments to identify potential negative effects on fundamental rights.Developers of AI systems.
  • Ensure that data used for training AI models is representative and free from illegal biases.Developers of AI systems.
  • Implement technical measures to detect and eliminate discriminatory algorithmic biases.Developers and operators of AI systems.
  • Ensure the logic behind AI-generated decisions is accessible to human users and regulators, especially in sensitive sectors.Developers and operators of AI systems, especially in sensitive sectors.
  • +5 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Optimize AI models for energy efficiency to align with national environmental sustainability goals.Developers of AI systems.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Costa Rica - AI Regulation Law (23.771), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Developers and operators of AI systems.Do not deploy AI applications that violate human dignity, such as social scoring or mass surveillance without judicial criteria.
The bill explicitly prohibits AI applications that violate human dignity, such as those used for social scoring or mass surveillance that does not meet strict judicial criteria.
Before deploymentCritical
2Developers of high-risk AI systems.Register high-risk AI systems with MICITT.
MICITT... responsible for maintaining a registry of high-risk AI applications and ensuring that developers comply with the mandatory administrative evaluations required before a system can be brought to market.
Before placing on marketCritical
3Developers of AI systems.Conduct Human Rights Impact Assessments to identify potential negative effects on fundamental rights.
A central pillar of the legislation is the requirement for 'Human Rights Impact Assessments.'
Before deploymentCritical
4Developers of AI systems.Ensure that data used for training AI models is representative and free from illegal biases.
Developers are required to ensure that the data used for training AI models is representative and free from illegal biases.
During development and trainingCritical
5Developers and operators of AI systems.Implement technical measures to detect and eliminate discriminatory algorithmic biases.
'Algorithmic Bias' is defined as systematic errors that lead to unfair treatment of certain groups, which the law explicitly seeks to prohibit.
ContinuouslyCritical
6Developers and operators of AI systems, especially in sensitive sectors.Ensure the logic behind AI-generated decisions is accessible to human users and regulators, especially in sensitive sectors.
'Explainability,' which requires that AI outputs be understandable to human users... In these fields, the logic behind an AI-generated decision must be accessible.
Before deploymentCritical
7Developers and operators of AI systems processing personal data.Comply with Law No. 8968 for personal data processing, including informed consent and data minimization.
Any processing of personal data by an AI system must comply with the standards set by the Data Protection Agency (Prodhab).
ContinuouslyCritical
8Operators of AI systems making decisions affecting individuals.Provide individuals with the right to a human explanation and review of AI-driven decisions affecting them.
This includes the right to a human explanation and the right to have a human operator review an automated decision.
Upon requestCritical
9Providers of AI-driven products or services.Clearly disclose to users when they are interacting with an AI-driven product or service.
The bill mandates that any product or service incorporating AI must clearly disclose this fact to the user.
Before offering the serviceImportant
10Developers and operators of AI systems.Maintain detailed logs of AI systems' performance and decision-making processes for regulatory review.
Developers and operators are required to maintain detailed logs of their systems' performance and decision-making processes, which must be made available to MICITT upon request.
Continuously, throughout operational lifeArticle 6Important
11Developers and operators of AI systems.Apply stricter scrutiny for AI systems interacting with children or individuals with disabilities.
The bill also addresses the protection of vulnerable populations, requiring stricter scrutiny for AI systems that interact with children or individuals with disabilities.
Before deploymentImportant
12Developers of AI systems.Optimize AI models for energy efficiency to align with national environmental sustainability goals.
The auditing process will also look at the environmental impact of AI systems, encouraging developers to optimize their models for energy efficiency.
ContinuouslyRecommended

© Regulations.AI using Gemini 3 Flash Preview · updated on 06-Jan-2026