Kazakhstan - AI Regulation (2025)
Draft Law 'On Artificial Intelligence'
Проект Закона «Об искусственном интеллекте»
Kazakhstan
RAI-KZ-NA-DAIPSXX-2025In May 2025 the Mazhilis (lower chamber) of the Parliament of Kazakhstan approved in first reading a dedicated Draft Law "On Artificial Intelligence" establishing a national, risk-based legal framework for AI. The bill (7 chapters, 28 articles) sets out principles (legality, transparency, human-centredness), a three-tier risk classification, prohibitions on certain autonomous and manipulative systems, requirements for labelling synthetic content, documentation and risk-management obligations for owners and operators, and foundations for a national AI platform and conformity mechanisms.
Summary
Read full text ↗Plain English
Overview
The Draft Law "On Artificial Intelligence" establishes a unified national legal framework for the development, deployment and use of artificial intelligence (AI) systems across the Republic of Kazakhstan. The statute treats AI as an object of informatization and sets out foundational legal principles — including responsibility, safety, transparency and human oversight — intended to guide both public and private actors engaged with AI technologies. The text creates specific obligations for owners, operators, developers and users of AI systems, and provides legal bases for the creation and operation of a National AI Platform, for sectoral governance instruments, and for conformity and supervisory mechanisms to verify compliance. The legislative package follows a risk-based approach to differentiate duties according to the potential impact of particular systems on safety, rights and public interests. The finalized law was passed by Parliament and signed by the President in 2025; the consolidated text is published in the national legal information system (primary legal text available at: https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai).
Definitions
The law introduces and clarifies the principal legal concepts required to determine the scope of regulatory coverage and to trigger specific statutory obligations. Key defined terms include, among others, "artificial intelligence", "model", "system", "data library" (defined as a library of data used for training), and "synthetic result" (AI-generated content). The statute also provides related technical and operational notions necessary to delimit which products and services fall within scope. These definitions operate as legal thresholds: whether an instrument is captured as an AI system under the law determines the applicability of duties such as documentation, transparency, labelling of synthetic outputs, and registration or conformity requirements. For the exact statutory language and comprehensive list of defined terms, see the consolidated text at: https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai.
Governance and Institutional Framework
The bill defines roles and responsibilities for central government authorities in AI policy-making, oversight and enforcement. It designates a competent authority (or authorities) charged with supervision, grants powers to expand government competence to form and execute AI policy, and envisages inter-agency coordination mechanisms to address sectoral risks such as safety, personal data protection and national security. The statute provides legal foundations for establishing a National AI Platform intended to serve as controlled infrastructure for model development, testing and deployment under prescribed conditions. Delegated authority is provided to competent bodies to adopt secondary regulations, technical standards and operational rules necessary to implement substantive obligations, including supervisory procedures and conformity assessment regimes. For statutory details and enumerated powers, consult the official consolidated text at: https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai.
Key Focus Areas
- Risk-based classification — the law establishes a three-tier framework to categorise AI systems according to their potential impact on safety, fundamental rights and public interests. Obligations are differentiated by risk tier so that higher-risk systems are subject to more stringent controls and oversight.
- Prohibited functionalities — the statute specifies explicit prohibitions on certain AI uses, including manipulative or covert behavioural influence technologies and particular forms of biometric surveillance in public spaces absent a lawful basis; such prohibitions aim to mitigate systemic harms and protect civil liberties.
- Transparency and labelling — the bill mandates labelling of synthetic content and AI-generated goods or services. For specified outputs, machine‑readable labelling requirements are introduced alongside human‑readable disclosure obligations to ensure users can recognise when content or decisions are produced by AI systems.
- Documentation and technical records — developers, owners and operators must maintain technical documentation and records (technical specifications, data provenance logs, summaries of model architecture, testing reports and other materials) to enable supervisory review, audits and conformity assessments.
- Risk management and testing — owners and operators are required to implement lifecycle risk‑management systems, conduct risk assessments, carry out pre‑deployment testing and, for systems assessed as higher risk, submit to audits or conformity assessments prior to and during deployment.
- Governance instruments — the law establishes registration or listing regimes for specified categories of systems, sets out conformity assessment mechanisms, confers supervisory powers on competent authorities and provides the legal basis for operating a National AI Platform to support controlled development and verification activities.
Implementation Framework
The statute applies to systems and products that meet the statutory definition of AI and to natural and legal persons who develop, own, deploy or operate such systems within Kazakhstan’s jurisdiction. It covers both the public and private sectors and sets differentiated obligations according to a system’s risk classification and its context of use, with particular emphasis on public services, critical infrastructure and mass media applications. Mandatory measures include maintaining up-to-date documentation and technical records, performing risk assessments, completing pre-deployment testing and subjecting certain systems to audits and conformity assessments. Where required by the law or by delegated rules, specified systems must be registered or listed with competent authorities. The law grants delegated authority to competent bodies to issue implementing regulations, technical standards and operational guidance (including procedures governing access to and use of the National AI Platform). Full procedural and operational details are to be developed through the secondary regulations referenced in the consolidated legal text: https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai.
Monitoring and Evaluation
The law creates supervisory powers for the designated competent authority(ies) to monitor compliance with statutory obligations, to require submission of documentation and technical records, and to conduct conformity assessments and audits where necessary. Supervisory measures include the ability to inspect systems, demand corrective actions, and mandate periodic reporting. Enforcement is designed to ensure transparency, data protection and safety obligations are observed throughout the lifecycle of AI systems. The statute foresees inter‑agency coordination to monitor systemic risks affecting national security, information security and public safety, and anticipates the issuance of delegated rules and standards to allow technical verification and ongoing evaluation of AI system performance and safety. The legislative process included stakeholder consultations, public hearings and expert panels; the law foresees continuation of stakeholder engagement during implementation to inform secondary regulations and standards.
Penalties, Liability, and Appeals
The statutory package establishes administrative liability for statutory violations and provides competent authorities with supervisory enforcement powers to secure compliance. Amendments to the Administrative Offences Code have been processed alongside the AI law to specify administrative sanctions and enforcement modalities. The law also contemplates civil liability pathways and mechanisms for redress in cases where AI systems cause harm, and it includes provisions encouraging or mandating insurance arrangements to cover potential damages arising from AI use (the Senate recommended strengthening insurance measures during parliamentary review). Procedures for appealing administrative decisions and modalities for civil claims are framed by references to existing administrative and civil liability regimes; detailed procedural rules and sanction scales are set out in the consolidated text and in delegated implementing acts (see consolidated law: https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai).
Relationship to Other Instruments
The law interacts with and requires harmonisation across multiple existing legal regimes, including data protection and privacy law, information and media regulation, consumer protection statutes, administrative offences and civil liability frameworks. It interfaces with broader government strategic initiatives such as the national AI development concept (AI Concept 2024–2029). The legislative package contains cross‑references and accompanying amendments to related codes and statutes intended to align responsibilities among regulators and to eliminate conflicts; many of these harmonising amendments were processed as part of the overall legislative package. Additional related acts and harmonising amendments are reflected in the official legislative materials and secondary instruments referenced in the consolidated text: https://adilet.zan.kz/rus/docs/P2400000592?utm_source=openai.
International Alignment
The statute has been drafted to align with prevailing international AI regulatory trends while reflecting Kazakhstan’s national policy priorities. In shaping the bill, drafters sought to balance objectives of safety, fundamental rights protection and innovation‑friendly governance. The law’s risk‑based approach, transparency and conformity mechanisms correspond to common elements found in international AI policy discussions and standards-setting processes. Implementing regulations are expected to take international technical standards and cooperative arrangements into account where appropriate to facilitate interoperability, cross‑border verification and technical harmonisation.
Implementation Timeline
| Date | Event |
|---|---|
| 2025-03-03 | Public presentation of draft law in Majilis |
| 2025-05-14 | Majilis — first reading (approved) |
| 2025-09-24 | Majilis — second reading (approved) |
| 2025-10-23 | Senate returned bill to Majilis with amendments |
| 2025-11-17 | Presidential signature (reported) |
Compliance Checklist
| Requirement | Description |
|---|---|
| Risk classification | Determine the AI system's risk category under the three‑tier framework and apply differentiated obligations accordingly, taking into account safety implications, potential rights impacts and broader public‑interest considerations. |
| Risk management | Implement and maintain an enterprise risk‑management system covering lifecycle risks, mitigation measures, continuous monitoring, incident response and periodic updates demonstrating safety and reliability. |
| Documentation and records | Maintain mandatory technical documentation and records, including technical specifications, data provenance logs, summaries of model architecture, testing reports and operational logs to support audits and supervisory review. |
| Pre-deployment testing and conformity | Conduct pre‑deployment testing, engage in conformity assessments or audits for higher‑risk systems, and register or list systems where required by statute or delegated rules prior to operation in regulated contexts. |
| Transparency and labelling | Label synthetic content and AI‑generated outputs in accordance with statutory requirements (including machine‑readable labelling where mandated) and ensure users are informed when outputs or decisions are produced or influenced by AI systems. |
| User rights and remedies | Ensure mechanisms enabling users to obtain information about automated processing, to challenge automated decisions where legally available or required, and to access redress and remediation for harms caused by AI systems. |
| Incident response and insurance | Prepare incident‑response procedures, maintain user‑support capabilities, report incidents as required by supervisory rules, and, where applicable, arrange insurance or other financial coverage in line with statutory or supervisory requirements. |
Sources and References
| Source | URL |
|---|---|
| National legal information system — consolidated law text (Kazakhstan) | https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai |
| National legal information system — related legislative acts and cross-references | https://adilet.zan.kz/rus/docs/P2400000592?utm_source=openai |
Kazakhstan's new Artificial Intelligence Law creates a national, risk-based legal framework for AI systems, applying to anyone developing, owning, deploying, or operating AI within the country.
This law, signed by the President in November 2025, covers both public and private sector entities, from developers to operators, who use AI systems within Kazakhstan. It defines key terms like "artificial intelligence," "model," and "synthetic result" (AI-generated content) to clarify what falls under its scope. The core of the law is its three-tier risk classification system, which categorizes AI based on its potential impact on safety, fundamental rights, and public interests. Higher-risk systems face stricter controls. The law explicitly prohibits certain AI uses, such as manipulative or covert systems designed to influence behavior, and specific types of biometric surveillance in public spaces without a legal basis.
Key obligations for those in scope include: - Maintaining comprehensive technical documentation and records, like data provenance logs and testing reports, to allow for audits and supervisory review. - Implementing lifecycle risk management systems, conducting risk assessments, and performing pre-deployment testing. Higher-risk systems may also require external audits or conformity assessments. - Ensuring transparency by mandating the labelling of synthetic content and AI-generated goods or services, often requiring both machine-readable and human-readable disclosures.
Enforcement relies on administrative liability for violations, with specific sanctions outlined in accompanying amendments to the Administrative Offences Code. The law also paves the way for civil liability and mechanisms for individuals to seek redress for harm caused by AI, even encouraging or mandating insurance for potential damages. A practical pitfall for businesses is that many detailed procedural and operational rules, including specific technical standards and conformity assessment regimes, are still to be developed through secondary regulations by designated government authorities. This means ongoing monitoring of new guidance will be crucial for compliance.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Kazakhstan - AI Regulation (2025). Not legal advice — verify against the official text before relying on it.
- #1Critical
Applies to: Developers, owners, and operators of AI systems.
“specifies explicit prohibitions on certain AI uses, including manipulative or covert behavioural influence technologies”
- #2Critical
Applies to: Developers, owners, and operators of AI systems.
“prohibitions on ... particular forms of biometric surveillance in public spaces absent a lawful basis”
- #3Critical⏰ Before deployment
Applies to: Developers, owners, and operators of AI systems.
“the law establishes a three-tier framework to categorise AI systems”
- #4Critical
Applies to: Developers, owners, and operators of AI systems.
“the bill mandates labelling of synthetic content and AI-generated goods or services.”
- #5Critical
Applies to: Developers, owners, and operators of AI systems.
“ensure users can recognise when content or decisions are produced by AI systems.”
- #6Critical
Applies to: Developers, owners, and operators of AI systems.
“developers, owners and operators must maintain technical documentation and records”
- #7Critical
Applies to: Owners and operators of AI systems.
“owners and operators are required to implement lifecycle risk‑management systems”
- #8Critical⏰ Before deployment
Applies to: Owners and operators of AI systems.
“conduct risk assessments, carry out pre‑deployment testing”
- #9Critical⏰ Prior to and during deployment
Applies to: Owners and operators of higher-risk AI systems.
“for systems assessed as higher risk, submit to audits or conformity assessments”
- #10Critical⏰ Prior to operation
Applies to: Owners and operators of specified AI systems.
“Mandatory measures include... registering or listing systems where required”
- #11Important⏰ Before deployment
Applies to: Owners and operators of AI systems.
“includes provisions encouraging or mandating insurance arrangements to cover potential damages arising from AI use”
- #12Important⏰ Upon deployment
Applies to: Owners and operators of AI systems.
“contemplates civil liability pathways and mechanisms for redress in cases where AI systems cause harm”
Related Regulations
Цифровой кодекс Республики Казахстан
Kazakhstan93% similar
Закон Республики Казахстан от 24 ноября 2015 года № 418-V «Об информатизации»
Kazakhstan93% similar
Law of the Republic of Kazakhstan on Amendments and Additions to the Code of Administrative Offences (No. 232-VIII) — related to AI/ digitization (Закон РК о внесении изменений и дополнений в Кодекс об административных правонарушениях)
Kazakhstan93% similar
Национальный этический кодекс в сфере искусственного интеллекта
Kazakhstan93% similar
Concept for the Development of Artificial Intelligence for 2024–2029 (Концепция развития искусственного интеллекта на 2024–2029 годы)
Kazakhstan92% similar
© Regulations.AI — created on 13-Jun-2026