Kazakhstan - AI Regulatory Amendments (232-VIII)
Law of the Republic of Kazakhstan on Amendments and Additions to the Code of Administrative Offences
Закон РК о внесении изменений и дополнений в Кодекс об административных правонарушениях
Kazakhstan
RAI-KZ-NA-RKAACXX-2025This Act (No. 232-VIII), adopted 17 November 2025, amends the Code of Administrative Offences of the Republic of Kazakhstan by adding Article 641-1 to impose administrative liability for breaches of the new AI legal framework. It establishes obligations for owners/operators of AI systems (transparency labelling of synthetic outputs, risk management for high-risk systems), reporting and documentation requirements, and a graded system of administrative fines and remedial measures.
Summary
Read full text ↗Plain English
Overview
The Law of the Republic of Kazakhstan on Amendments and Additions to the Code of Administrative Offences (No. 232-VIII) was adopted by the Parliament and signed by the Head of State on 17 November 2025. It supplements the Code by adding Article 641-1, which creates an administrative offence for violations of the AI regulatory regime introduced by the companion AI Act. The amendment targets transparency and risk-management failures by owners and operators of AI systems and establishes a tiered administrative penalty framework (monetized by monthly calculation index — MRP). For the official AI law and related texts see the national legal information system at Adilet: Law on Artificial Intelligence (No. 230-VIII) and the consolidated Code at Adilet: Code of Administrative Offences.
Definitions
Article 641-1 relies on the definitions introduced by the companion AI law. Key terms include: "artificial intelligence (AI)", "AI system", "owner/owner-operator of a system", "synthetic output" (any content generated wholly or partially by AI that may be mistaken for human-created content), "high-risk AI system" (systems that because of intended purpose may cause significant harm to health, rights, or public order), and "monthly calculation index (MRP)" used to quantify fines. The amendment uses the statutory taxonomy established by the AI Act, and readers should cross-reference those definitions in the primary AI Act text available at Adilet (AI Act).
Governance and Institutional Framework
The amendment assigns administrative enforcement competence to agencies and supervisory bodies charged with AI oversight by the primary AI law. The new institutional architecture concentrates technical supervision, registration and market surveillance functions primarily within bodies referenced in the AI Act and national digital governance structures; operational coordination is expected to involve the Ministry responsible for AI and digital development, sectoral regulators, and control organs (e.g., state inspection, prosecutor’s office on procedural matters where required). For background on the executive-level architecture and the new ministry, see reporting on the formation of the Ministry of Artificial Intelligence and Digital Development (MAIDD) and government communications such as Tengrinews: MAIDD announcement. The administrative procedure for imposing fines follows the procedural rules of the Code of Administrative Offences (investigation, notice, right to defense, appeal).
Key Focus Areas
The amendment concentrates on two core areas: transparency and risk management. Transparency: owners/operators of AI systems must ensure that users are informed where outputs are synthetic or generated by an AI system in a manner that could reasonably mislead consumers or third parties; omission constitutes an administrative offence. Risk management: owners/operators of AI systems classified as high-risk under the AI Act are required to perform systematic risk identification, assessment, mitigation, testing and continuous monitoring; failure to carry out those measures — when it results in detrimental consequences to health, rights, public order, or other protected interests — is actionable under Article 641-1 provided the conduct does not amount to a criminal offense. The law therefore operationalizes supervisory reliance on documented risk management practices and transparency labeling as the threshold for administrative responsibility.
Implementation Framework
Enforcement is administrative: violations are investigated under the Code’s procedures and sanctions imposed by authorized administrative bodies. The law supports a compliance ecosystem: obligations to keep logs, retain risk assessments and test records, produce incident reports on request, and cooperate with market surveillance. For AI systems deemed high-risk, the implementing regulations (to be adopted by relevant ministries and oversight bodies) will specify technical standards for risk management, record formats, and reporting channels. Stakeholders should consult the consolidated Code at Adilet (Code) and the companion AI Act at Adilet (AI Act) for linkage and procedural rules.
Monitoring and Evaluation
Monitoring will combine routine administrative inspections, market surveillance, and reactive investigation of incidents reported by users or discovered by supervisory agencies. The law contemplates periodic review of enforcement outcomes, repeat-offender tracking (repeated breaches within 12 months trigger escalated fines and remedial actions), and the collection of compliance metrics to feed policy evaluation. Ministries and agencies are expected to publish enforcement statistics and guidance to clarify expectations for system design, documentation and labelling.
Penalties, Liability, and Appeals
Penalties are administrative fines denominated in MRP (monthly calculation indices). The statutory schedule introduced by Article 641-1 includes first‑instance fines (e.g., 15 MRP for individuals; 20 MRP for small entities; 30 MRP for medium entities; 100 MRP for large enterprises) and elevated fines on repeat violations within one year (e.g., up to 30, 50, 70 and 200 MRP respectively). Repeat or severe breaches may also attract suspension or prohibition of an AI system and other remedial measures. Administrative decisions are subject to appeal in the administrative and judicial channels prescribed by the Code of Administrative Offences, consistent with procedural safeguards and rights to defense.
Relationship to Other Instruments
The amendment is a companion enforcement instrument to the substantive AI Act (No. 230‑VIII) and supplementary legislative changes to consumer protection and data protection regimes. It does not replace criminal liability where the same act meets criminal law elements; instead it provides a calibrated administrative enforcement pathway. Entities must also comply with personal data protection laws, consumer protection rules, sectoral regulation (e.g., healthcare, finance) and any technical standards issued by sector regulators. See the AI Act and consolidated Code for cross-references: AI Act (Adilet), Code (Adilet).
International Alignment
The design of Article 641-1 — focusing on transparency, risk management, documentation and proportionate administrative sanctions — reflects international trends in AI governance (e.g., risk-based regulation, mandatory transparency for synthetic content, documentation and traceability). The law is intended to foster compatibility with international regulatory approaches while reflecting Kazakhstan’s domestic legal architecture. Stakeholders operating cross-border services should therefore prepare for both domestic administrative enforcement and possible international data/market compliance obligations.
Implementation Timeline
| Event | Date |
|---|---|
| Adoption by Parliament / Signature by Head of State | 2025-11-17 |
| Official publication (press/gazette) | 2025-11-18 (published in national print and legal registries) |
| Common entry-into-force (subject to law text) | Generally within statutory term (often 60 days after publication) — estimated 2026-01-15; consult official publication for exact implementation clauses |
| Start of enforcement of administrative offences (first stage) | As per entry-into-force provisions or implementing regulations (see official registry) |
Compliance Checklist
| Requirement | Yes/No (Action) |
|---|---|
| Identify whether deployed AI systems are classified as high-risk | Yes — perform classification & document |
| Implement risk management framework (assessment, mitigation, testing) | Yes — create and retain assessment records |
| Label synthetic outputs and notify users | Yes — automated or manual notification systems |
| Maintain logs, test reports and incident records | Yes — retention policy & secure storage |
| Prepare incident reporting and mitigation plans | Yes — integrate into operations |
Sources and References
| Source | Type |
|---|---|
| Law of the Republic of Kazakhstan "On Artificial Intelligence" (No. 230‑VIII) — Adilet | Primary Source |
| Code of Administrative Offences (consolidated) — Adilet | Primary Source |
| Zakon.kz legal database (listing of new acts incl. No. 232‑VIII) | Primary/Official registry |
| Government press & registry notices — gov.kz | Official announcement |
Kazakhstan's new law introduces administrative penalties for owners and operators of Artificial Intelligence (AI) systems who fail to meet specific requirements under the country's new AI regulatory framework. This measure, effective January 17, 2026, amends the Code of Administrative Offences to ensure transparency and responsible risk management in AI deployment.
The law applies to anyone owning or operating an AI system within Kazakhstan. Its primary goal is to hold these entities accountable for how their AI systems interact with users and the public. Key obligations include: - Ensuring users are clearly informed when an AI system generates "synthetic output"—any content that could be mistaken for human-created material. Failing to label such content is an administrative offense. - For "high-risk AI systems"—those with the potential to cause significant harm to health, rights, or public order—owners and operators must implement a systematic risk management framework. This involves identifying, assessing, mitigating, testing, and continuously monitoring risks. Failure to do so, especially when it leads to detrimental consequences, can trigger penalties. - Maintaining thorough documentation, including logs, risk assessments, test reports, and incident records, is also mandatory to demonstrate compliance.
Violations of these rules can result in administrative fines, calculated using a "monthly calculation index" (MRP). Fines vary significantly based on the size of the entity and whether it's a first-time or repeat offense. For instance, initial fines can range from 15 MRP for individuals to 100 MRP for large enterprises, escalating to up to 200 MRP for repeat breaches within a year. Severe or repeated non-compliance could also lead to the suspension or outright prohibition of an AI system. All administrative decisions are subject to appeal.
A practical pitfall for businesses is the emphasis on *documented* compliance. It's not enough to simply manage risks or label synthetic content; you must be able to prove these actions through comprehensive records and reports. This means establishing robust internal processes for logging, testing, and incident reporting well before the effective date.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 8 marked completePlain-English obligations under Kazakhstan - AI Regulatory Amendments (232-VIII). Not legal advice — verify against the official text before relying on it.
- #1CriticalArticle 641-1⏰ Jan 17, 2026
Applies to: Owners and operators of AI systems.
“owners/operators of AI systems must ensure that users are informed where outputs are synthetic... omission constitutes an administrative offence.”
- #2CriticalArticle 641-1⏰ Jan 17, 2026
Applies to: Owners and operators of high-risk AI systems.
“owners/operators of AI systems classified as high-risk... are required to perform systematic risk identification, assessment, mitigation, testing and continuous monitoring.”
- #3ImportantArticle 641-1⏰ Jan 17, 2026
Applies to: Owners and operators of AI systems.
“Identify whether deployed AI systems are classified as high-risk”
- #4ImportantArticle 641-1⏰ Jan 17, 2026
Applies to: Owners and operators of AI systems.
“obligations to keep logs, retain risk assessments and test records”
- #5ImportantArticle 641-1⏰ Jan 17, 2026
Applies to: Owners and operators of AI systems.
“Prepare incident reporting and mitigation plans”
- #6ImportantArticle 641-1⏰ Jan 17, 2026
Applies to: Owners and operators of AI systems.
“produce incident reports on request”
- #7ImportantArticle 641-1⏰ Jan 17, 2026
Applies to: Owners and operators of AI systems.
“cooperate with market surveillance.”
- #8ImportantArticle 641-1⏰ Jan 17, 2026
Applies to: Owners and operators of high-risk AI systems.
“implementing regulations... will specify technical standards for risk management, record formats, and reporting channels.”
Related Regulations
Draft Law (Bill) 'On Artificial Intelligence' — parliamentary bill submitted/considered (Проект Закона «Об искусственном интеллекте»)
Kazakhstan93% similar
Закон Республики Казахстан от 24 ноября 2015 года № 418-V «Об информатизации»
Kazakhstan92% similar
Цифровой кодекс Республики Казахстан
Kazakhstan92% similar
Национальный этический кодекс в сфере искусственного интеллекта
Kazakhstan91% similar
Concept for the Development of Artificial Intelligence for 2024–2029 (Концепция развития искусственного интеллекта на 2024–2029 годы)
Kazakhstan89% similar
© Regulations.AI — created on 13-Jun-2026