Kazakhstan Digital Code
Digital Code of the Republic of Kazakhstan
Цифровой кодекс Республики Казахстан
Kazakhstan
RAI-KZ-NA-DIGITAL-2026Digital Code
Kazakhstan Digital Code is Adopted in Kazakhstan, according to gov.kz. We have not yet been able to confirm the status.
ActGovernance and OversightData Protection and PrivacyA unified legislative framework consolidating Kazakhstan's digital laws and establishing a risk-based governance model for artificial intelligence.
Summary
The Digital Code of the Republic of Kazakhstan is a landmark legislative framework that consolidates digital laws into a single instrument. It introduces a human-centric approach to digitalization, focusing on risk-based AI governance, the platform economy, and the protection of digital rights. The Code aims to foster innovation while ensuring national digital sovereignty and alignment with international standards.
Full article
Read full text ↗Overview
The Digital Code of the Republic of Kazakhstan represents a landmark legislative initiative designed to consolidate and modernize the nation's legal framework for the digital era. Often referred to by Kazakh officials as the "Digital Constitution," this comprehensive document integrates various disparate laws—including the Law on Informatization, the Law on Electronic Documents, and the Law on Digital Signatures—into a single, unified regulatory instrument. Its primary objective is to establish a clear, predictable, and human-centric legal environment that fosters digital innovation while ensuring the protection of fundamental rights and national digital sovereignty. The Code is a direct response to the rapid evolution of technologies such as artificial intelligence (AI), big data, and blockchain, which had previously outpaced the existing sectoral regulations. By creating a holistic framework, Kazakhstan aims to position itself as a leading digital hub in Central Asia and the broader Eurasian region, aligning its domestic standards with international best practices like those of the OECD and the European Union. The development of the Code was characterized by an extensive consultative process involving the Ministry of Digital Development, Innovations and Aerospace Industry, the Parliament, and the expert community. The Code moves away from a purely technical approach to digitalization, instead adopting a "human-centric" philosophy where digital services and infrastructure are designed to serve the citizen's needs and protect their privacy. Key pillars of the legislation include the regulation of the platform economy, the establishment of a National AI Platform, and the formalization of digital rights. Furthermore, the Code introduces the concept of "Digital Sovereignty," ensuring that the state maintains control over its critical digital infrastructure and the data of its citizens, particularly in the face of global technological dependencies. This strategic shift is intended to drive the "Digital Kazakhstan" program to its next phase, focusing on total digitalization of public administration and the economy by 2026-2029.
Definitions
The Digital Code introduces a sophisticated set of definitions that provide the necessary legal clarity for the operation of digital systems and the use of emerging technologies. Central to the Code is the definition of "Digital Objects," which encompasses data, digital assets, software, and information systems. The Code distinguishes between "Administrative Data," which is generated through the performance of state functions, and "Open Data," which must be published in machine-readable formats for public use. A critical addition is the definition of "Artificial Intelligence" (AI), described as an information and communication technology that imitates or exceeds human cognitive functions to perform intellectual tasks. The Code further defines "Generative AI" as systems capable of creating synthetic content, including the alteration of biometric data and the distortion of reality, which triggers specific transparency and labeling requirements. Another innovative concept introduced is "Digital Maturity," a metric used to assess the readiness and effectiveness of state bodies and private organizations in adopting and utilizing digital technologies. The Code also formalizes the "Digital Twin," referring to a virtual representation of physical objects or processes used for simulation and optimization. In the realm of digital rights, the Code defines the "Right to be Forgotten" and "Digital Confirmation," a simplified form of expressing will for actions with low legal significance. These definitions are designed to be technology-neutral where possible, allowing the legal framework to remain relevant as specific technical implementations evolve. By standardizing these terms, the Code eliminates the ambiguity that previously hindered the enforcement of digital laws and the development of cross-sectoral digital services.
Governance and Institutional Framework
The institutional framework established by the Digital Code is centered on the newly created Ministry of Artificial Intelligence and Digital Development. This specialized authority is tasked with overseeing the implementation of the Code, coordinating the national digital policy, and regulating the AI ecosystem. The Ministry acts as the "authorized body" with broad powers to set technical standards, conduct audits, and manage the National Data Register. A significant component of this framework is the National AI Platform, which serves as a centralized infrastructure for the development, training, and testing of AI models, particularly for use in public administration, healthcare, and education. This platform is intended to provide domestic developers with the computing power and datasets necessary to compete globally, while ensuring that AI development remains under state oversight. Beyond the central ministry, the Code defines the roles of various stakeholders, including the Bureau of National Statistics, which is designated as the authorized body for digital data quality. The governance model also incorporates a multi-tier audit system for digital systems. This system includes functional verification, cybersecurity audits, and regulatory audits. For high-risk AI systems and critical infrastructure, these audits are mandatory and must be conducted by certified independent entities or state-authorized bodies. This decentralized yet rigorous oversight mechanism is designed to balance the need for innovation with the necessity of maintaining public safety and national security in an increasingly interconnected digital environment. The framework also establishes the Digital Government Support Center, which provides technical assistance to state agencies in their transition to the new standards mandated by the Code.
Key Focus Areas
One of the most significant focus areas of the Digital Code is the risk-based regulation of Artificial Intelligence. Inspired by global trends, the Code categorizes AI systems into risk levels: low, medium, and high. High-risk systems—those affecting human life, health, safety, or fundamental rights—are subject to stringent transparency, explainability, and human-oversight requirements. The Code explicitly prohibits certain AI practices, such as the use of subconscious manipulative techniques that distort human behavior or systems that perform social scoring. Furthermore, the Code addresses the rise of deepfakes and generative AI by requiring that synthetic content be clearly labeled, ensuring that citizens can distinguish between human-generated and machine-generated information. Another key focus is the modernization of the platform economy and digital services. The Code provides a unified legal regime for digital documents, granting them the same legal force as paper documents and ensuring their machine-readability for long-term storage. It regulates digital intermediaries, including marketplaces, service aggregators, and labor platforms, establishing clear rights and obligations for both platform operators and users. In the realm of data management, the Code emphasizes "Digital Sovereignty" through data localization requirements for critical systems and the establishment of the National Data Register as the "single source of truth" for administrative information. This focus ensures that the state can provide proactive, "invisible" public services where the government anticipates the needs of citizens based on life events, rather than requiring citizens to navigate complex bureaucratic processes.
Implementation Framework
The implementation of the Digital Code follows a phased approach intended to minimize disruption to existing digital services while rapidly upgrading the legal environment. The transition involves the repeal of several legacy laws and the migration of their provisions into the unified structure of the Code. To support this transition, the Code formalizes "Experimental Legal Regimes" (often called regulatory sandboxes). These regimes allow companies and state bodies to test innovative technologies, such as autonomous vehicles or blockchain-based financial services, in a controlled environment with relaxed regulatory requirements. The results of these experiments are then used to inform future amendments to the Code or the development of secondary legislation. A critical part of the implementation framework is the "Digital Maturity" assessment of state agencies. The Ministry of Artificial Intelligence and Digital Development is responsible for monitoring the progress of various sectors in adopting the Code's standards. This includes the rollout of the National AI Platform and the integration of the "Digital ID" system across all public and private services. The Code also mandates the creation of a comprehensive ecosystem for digital assets, including the potential integration of the "Digital Tenge" (Kazakhstan's central bank digital currency) into state procurement and social payment systems. This integrated approach ensures that the legal, technical, and economic aspects of digitalization are aligned, providing a stable foundation for the country's long-term technological development. The implementation strategy also includes a massive digital literacy campaign to ensure that citizens are aware of their new digital rights and the mechanisms available for their protection.
Monitoring and Evaluation
Monitoring and evaluation under the Digital Code are conducted through a rigorous, data-driven process overseen by the authorized ministry. The Code introduces a three-tier system of state control and supervision. The first tier involves the continuous monitoring of digital systems through automated tools that track performance, data quality, and security incidents. The second tier consists of periodic audits, which are mandatory for operators of critical information infrastructure and high-risk AI systems. These audits assess not only technical compliance but also the ethical implications of AI-driven decisions, ensuring that algorithms do not exhibit bias or violate human rights. The third tier involves the evaluation of the "Digital Maturity" of economic sectors and government bodies, with the results published in an annual national report on the state of digitalization. To ensure transparency, the Code requires that the results of cybersecurity audits and the status of experimental legal regimes be made available to the public. The Ministry also maintains a registry of AI systems used in the public sector, detailing their purpose, the data they process, and the risk mitigation measures in place. Evaluation is not limited to domestic metrics; the Code explicitly links Kazakhstan's digital progress to international indices, such as the UN E-Government Development Index and the Global Cybersecurity Index. This external benchmarking ensures that the implementation of the Code remains competitive on a global scale and that any gaps in the regulatory framework are identified and addressed through timely legislative updates.
Penalties, Liability, and Appeals
The Digital Code establishes a robust framework for liability and redress to ensure accountability in the digital sphere. It introduces specific administrative penalties for violations of data protection standards, unauthorized processing of personal information, and the failure to label AI-generated synthetic content. For more severe infractions, such as large-scale data breaches or the deployment of prohibited AI systems that cause harm to citizens' health or safety, the Code, in conjunction with amendments to the Criminal Code, provides for significant fines and potential imprisonment. The principle of "strict liability" is applied to owners and developers of high-risk AI systems in cases where the system's actions cause direct damage, shifting the burden of proof to the operator to demonstrate that all safety and transparency standards were met. In addition to penalties, the Code provides clear mechanisms for citizens and businesses to appeal decisions made by digital systems or the regulatory authority. This includes the right to a human review of any automated decision that significantly affects a person's rights or legal status. The appeals process is integrated into the existing administrative justice system, but with specialized procedures for handling technical evidence and algorithmic audits. Furthermore, the Code establishes the right to compensation for damages resulting from the improper functioning of state information systems or the leakage of personal data. This comprehensive liability framework is intended to build public trust in digital technologies by ensuring that there are clear consequences for misuse and accessible avenues for redress.
Relationship to Other Instruments
As a foundational "Code," this document holds a superior position in the hierarchy of laws relative to ordinary sectoral acts. In cases of conflict between the Digital Code and other laws regarding relations in the digital environment, the provisions of the Digital Code prevail. It effectively replaces and consolidates the Law on Informatization (2015), the Law on Electronic Documents and Electronic Digital Signatures (2003), and several other specialized acts. However, it remains closely linked to the Constitution of Kazakhstan, particularly regarding the protection of the right to privacy and freedom of information. The Code also works in tandem with the Law on Personal Data and its Protection, providing the specific technical and procedural details for data handling in the digital age. The Code is designed to be the "anchor" for a vast network of secondary legislation, including ministerial orders, technical standards, and ethical guidelines. For instance, while the Code sets the high-level requirements for AI risk classification, the specific criteria for these classifications are detailed in subordinate regulations. It also interacts with the Code of Administrative Offenses and the Criminal Code to define the penalties for digital crimes. In the financial sector, the Digital Code complements the regulations of the National Bank and the Astana International Financial Centre (AIFC), particularly concerning digital assets and smart contracts. This interconnectedness ensures that the Digital Code functions as the central operating system for the nation's entire legal framework as it relates to technology.
International Alignment
Kazakhstan has explicitly designed the Digital Code to align with international standards and facilitate cross-border digital cooperation. The AI regulation sections are heavily influenced by the European Union's AI Act, particularly the risk-based approach and the ban on harmful practices. By adopting similar principles, Kazakhstan aims to ensure the interoperability of its digital systems with those of its major trading partners and to simplify compliance for international tech companies operating in the country. The Code also incorporates recommendations from the OECD on the ethical development of AI and data governance, reflecting Kazakhstan's ambition to join the organization in the near future. Within the framework of the Eurasian Economic Union (EAEU), the Digital Code serves as a model for the harmonization of digital markets, particularly regarding the mutual recognition of digital documents and electronic signatures. The Code also addresses international data transfers, establishing a regime similar to the GDPR's "adequacy decisions," where data can flow freely to countries that provide a comparable level of protection. Furthermore, the Code emphasizes cooperation with international organizations like the ITU and the UN to promote global cybersecurity standards. This commitment to international alignment is intended to attract foreign investment, foster the growth of the domestic IT export sector, and ensure that Kazakhstan remains a proactive participant in the global digital economy, including initiatives like the Digital Silk Road.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Concept Development and Public Consultation | 2023-06-15 | Initial concept approved by the Ministry of Digital Development. |
| Presentation to the Mazhilis (Lower House) | 2024-10-17 | Official presentation of the draft Code to the Parliament. |
| First Reading Approval | 2025-05-14 | Approved by the Mazhilis with amendments. |
| Final Approval by the Senate | 2025-12-25 | Passed by the upper house of Parliament. |
| Official Entry into Force | 2026-07-01 | Expected date for full implementation of primary provisions. |
Sources and References
| Source | Type |
|---|---|
| Mazhilis of the Parliament of the Republic of Kazakhstan | Primary Source |
| Ministry of Digital Development, Innovations and Aerospace Industry | Primary Source |
| Official Information Source of the Prime Minister | Primary Source |
| Open NIAs (Legal Acts) Portal of the Republic of Kazakhstan | Primary Source |
Requirements for a company
What an organisation has to do under Kazakhstan Digital Code, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.
Must do
14- Do not use AI systems for subconscious manipulation or social scoring.All entities developing or deploying AI systems.
- Assess and classify all AI systems based on the Code's risk criteria.All entities deploying AI systems.
- Conduct mandatory cybersecurity and regulatory audits for high-risk AI systems and critical infrastructure.Operators of high-risk AI systems and critical infrastructure.
- Ensure high-risk AI systems meet stringent transparency requirements.Providers of high-risk AI systems.
- Ensure high-risk AI systems meet stringent explainability requirements.Providers of high-risk AI systems.
- Implement human oversight mechanisms for high-risk AI systems.Providers of high-risk AI systems.
- +8 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Kazakhstan Digital Code, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | All entities developing or deploying AI systems. | Do not use AI systems for subconscious manipulation or social scoring. “The Code explicitly prohibits certain AI practices, such as the use of subconscious manipulative techniques that distort human behavior or systems that perform social scoring.” | Jul 1, 2026 | — | Critical |
| 2 | All entities deploying AI systems. | Assess and classify all AI systems based on the Code's risk criteria. “The Code categorizes AI systems into risk levels: low, medium, and high.” | Jul 1, 2026 | — | Critical |
| 3 | Operators of high-risk AI systems and critical infrastructure. | Conduct mandatory cybersecurity and regulatory audits for high-risk AI systems and critical infrastructure. “For high-risk AI systems and critical infrastructure, these audits are mandatory and must be conducted by certified independent entities.” | Jul 1, 2026 | — | Critical |
| 4 | Providers of high-risk AI systems. | Ensure high-risk AI systems meet stringent transparency requirements. “High-risk systems... are subject to stringent transparency, explainability, and human-oversight requirements.” | Jul 1, 2026 | — | Critical |
| 5 | Providers of high-risk AI systems. | Ensure high-risk AI systems meet stringent explainability requirements. “High-risk systems... are subject to stringent transparency, explainability, and human-oversight requirements.” | Jul 1, 2026 | — | Critical |
| 6 | Providers of high-risk AI systems. | Implement human oversight mechanisms for high-risk AI systems. “High-risk systems... are subject to stringent transparency, explainability, and human-oversight requirements.” | Jul 1, 2026 | — | Critical |
| 7 | Entities deploying AI systems making significant automated decisions. | Provide a human review mechanism for automated decisions significantly affecting rights. “This includes the right to a human review of any automated decision that significantly affects a person's rights or legal status.” | Jul 1, 2026 | — | Critical |
| 8 | Providers of Generative AI systems. | Clearly label all synthetic content and deepfakes generated by AI. “Generative AI... triggers specific transparency and labeling requirements.” | Jul 1, 2026 | — | Critical |
| 9 | All entities handling personal data in the digital age. | Adhere to the Law on Personal Data and its Protection for all data handling. “The Code also works in tandem with the Law on Personal Data and its Protection, providing the specific technical and procedural details for data handling.” | Jul 1, 2026 | — | Critical |
| 10 | Operators of critical systems processing Kazakh citizen data. | Store and process personal data of Kazakh citizens on servers within the Republic for critical systems. “emphasizes "Digital Sovereignty" through data localization requirements for critical systems.” | Jul 1, 2026 | — | Critical |
| 11 | Providers of public and private digital services. | Integrate the national Digital ID system across all public and private services. “the integration of the "Digital ID" system across all public and private services.” | Jul 1, 2026 | — | Important |
| 12 | Public sector entities using AI systems. | Register AI systems used in the public sector with the Ministry. “The Ministry also maintains a registry of AI systems used in the public sector, detailing their purpose, the data they process.” | Jul 1, 2026 | — | Important |
| 13 | Owners and developers of high-risk AI systems. | Maintain records to demonstrate compliance with safety and transparency standards for high-risk AI. “shifting the burden of proof to the operator to demonstrate that all safety and transparency standards were met.” | Jul 1, 2026 | — | Important |
| 14 | Entities transferring personal data internationally. | Ensure international data transfers comply with adequacy decision-like requirements. “The Code also addresses international data transfers, establishing a regime similar to the GDPR's "adequacy decisions".” | Jul 1, 2026 | — | Important |
Related Regulations
More AI regulation in Kazakhstan
© Regulations.AI using Gemini 3 Flash Preview · updated on 6 Jan 2026